Ok, I was fianlly able to download the 2 apps.
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 10 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIHWA.EXE
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Coupons.com Inc.) C:\Program Files (x86)\Coupons\CouponPrinterService.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\1352492663\ee\aolsoftware.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\perfhost.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Viewpoint Corporation) C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.7c\waol.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.7c\shellmon.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.7c\aolbrowser.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672152 2014-08-27] (Realtek Semiconductor)
HKLM\…\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.)
HKLM-x32\…\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [HostManager] => C:\Program Files (x86)\Common Files\AOL\1352492663\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\…\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2014-12-31] (Avira Operations GmbH & Co. KG)
HKLM-x32\…\Run: [TrojanScanner] => C:\Program Files (x86)\Trojan Remover\Trjscan.exe [1791856 2015-01-28] (Simply Super Software)
HKLM-x32\…\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-11-24] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\olvbesb-x32: C:\Users\Owner\AppData\Local\olvbesb.dll [X]
HKLM\…\Policies\Explorer\Run: [1644913992] => C:\PROGRA~3\msboofb.exe No File
HKLM\…\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\…\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE [241280 2012-07-12] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Run: [ToolwizCareFree] => C:\Program Files (x86)\ToolwizCareFree\ToolwizCares.exe [5274328 2014-08-03] (Toolwiz)
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Run: [Driver Support] => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [5673824 2014-08-07] (PC Drivers Headquarters)
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\Policies\Explorer: [TaskbarNoNotification] 1
HKU\S-1-5-18\…\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE [241280 2012-07-12] (SEIKO EPSON CORPORATION)
HKU\S-1-5-18\…\Policies\Explorer\Run: [1644913992] => C:\PROGRA~3\msboofb.exe
HKU\S-1-5-18\…\Policies\Explorer: [TaskbarNoNotification] 1
HKU\S-1-5-18\…\Policies\Explorer: [HideSCAHealth] 1
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyServer: [S-1-5-21-3259929428-2434079444-325336261-1000] => http=127.0.0.1:64550
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-3259929428-2434079444-325336261-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll No File
BHO: AOL Toolbar Loader -> {3ef64538-8b54-4573-b48f-4d34b0238ab2} -> C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files\WOT\WOT.dll ()
BHO-x32: &Yahoo;! Toolbar Helper -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
BHO-x32: AOL Toolbar Loader -> {3ef64538-8b54-4573-b48f-4d34b0238ab2} -> C:\Program Files (x86)\AOL Toolbar\aoltb.dll (AOL Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
Toolbar: HKLM-x32 - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll (AOL Inc.)
Toolbar: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> No Name - {3FABEEE8-9237-CDE4-D1F2-6648F4D1C386} - No File
Toolbar: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
Toolbar: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKU\S-1-5-21-3259929428-2434079444-325336261-1000 -> AOL Toolbar - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
Handler: WSWSVCUchrome - No CLSID Value
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{398FA4FC-D7BB-4FEF-AC5D-A241C45B9E0D}: [NameServer] 208.67.222.222
FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4l2qlfqr.default-1417042319708
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @viewpoint.com/VMP -> C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll (Viewpoint Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npunagi2.dll (America Online, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll (Coupons, Inc.)
FF SearchPlugin: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4l2qlfqr.default-1417042319708\searchplugins\aolsearch.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\aolsearch.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safesearch.xml
FF Extension: AOL Toolbar - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4l2qlfqr.default-1417042319708\Extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} [2015-01-19]
FF HKLM-x32\…\Firefox\Extensions: [{635abd67-4fe9-1b23-4f01-e679fa7484c1}] - 0\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF HKLM-x32\…\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-07-18]
Chrome:
=======
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (South Park) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aoiakcboakkfknbginpmpfkcdmcmpnfm [2014-11-12]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-31]
CHR Extension: (YouTube) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-11]
CHR Extension: (Google Search) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-11]
CHR Extension: (Avira Browser Safety) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-12]
CHR Extension: (Services) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\flofdhbohbadcgnolfniillmboolleoh [2014-06-12]
CHR Extension: (Tab) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdfjhiclilbjdpeejgcgebmmihkkofji [2014-06-12]
CHR Extension: (Simple) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\joefoganpblmedgjeigepgjfikhhdnnj [2014-06-12]
CHR Extension: (Google Wallet) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR HKLM\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\…\Chrome\Extension: [eihhgekonheiliaidomffpplfhecmkag] - No Path
CHR HKLM-x32\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\…\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [178424 2014-12-31] (Avira Operations GmbH & Co. KG)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-04-20] (CyberLink)
R2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [179184 2014-10-15] (Coupons.com Inc.)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2631456 2014-12-10] (IObit)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [167936 2005-08-07] () [File not signed]
R2 Viewpoint Service; C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe [30152 2008-04-04] (Viewpoint Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 BTOWSFF; C:\Windows\System32\Drivers\BTOWSFF.sys [33024 2014-08-03] (Toolwiz.com)
R0 BTOWSVF; C:\Windows\System32\Drivers\BTOWSVF.sys [52480 2014-08-03] (Toolwiz.com)
R0 KSafeDISK; C:\Windows\System32\Drivers\KSafeDISK.sys [52992 2014-08-03] (Toolwiz.com)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-29] (Malwarebytes Corporation)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2014-07-11] ()
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-30 08:17 - 2015-01-30 08:17 - 00022420 _____ () C:\Users\Owner\Desktop\FRST.txt
2015-01-30 08:16 - 2015-01-30 08:17 - 00000000 ____D () C:\FRST
2015-01-30 08:16 - 2015-01-30 08:16 - 02130432 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe
2015-01-30 08:16 - 2015-01-30 08:16 - 02130432 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
2015-01-30 08:14 - 2015-01-30 08:14 - 01121792 _____ (Farbar) C:\Users\Owner\Downloads\FRST.exe
2015-01-30 08:06 - 2015-01-30 08:06 - 00143360 _____ () C:\Users\Owner\Downloads\tdsskiller.zip
2015-01-30 08:04 - 2015-01-30 08:05 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Owner\Desktop\tdsskiller.exe
2015-01-30 08:03 - 2015-01-30 08:05 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Owner\Downloads\tdsskiller.exe
2015-01-30 08:03 - 2015-01-30 08:03 - 00012288 _____ () C:\Users\Owner\Downloads\tdsskiller 2
2015-01-29 22:02 - 2015-01-29 22:03 - 00000000 ___SD () C:\ComboFix
2015-01-29 20:45 - 2015-01-29 20:44 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-01-29 20:44 - 2015-01-29 20:44 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Avira
2015-01-29 20:43 - 2014-11-24 10:23 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-01-29 20:43 - 2014-11-24 10:23 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-01-29 20:43 - 2014-11-24 10:23 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-01-29 20:16 - 2015-01-29 20:16 - 00279200 _____ () C:\Windows\Minidump\012915-60902-01.dmp
2015-01-29 20:15 - 2015-01-29 20:15 - 811325993 _____ () C:\Windows\MEMORY.DMP
2015-01-29 20:14 - 2015-01-29 20:14 - 00003288 ____N () C:\bootsqm.dat
2015-01-29 18:59 - 2015-01-29 18:59 - 00000000 ____D () C:\ProgramData\Licenses
2015-01-29 17:55 - 2015-01-29 18:05 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Local Store
2015-01-29 11:14 - 2015-01-29 11:14 - 19283456 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 15400960 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 14364672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 13758976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-01-29 11:14 - 2015-01-29 11:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-01-29 11:14 - 2015-01-29 11:14 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 02237952 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 02054656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 01762816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-01-29 11:14 - 2015-01-29 11:14 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-01-29 11:14 - 2015-01-29 11:14 - 01409536 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2015-01-29 11:14 - 2015-01-29 11:14 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2015-01-29 11:14 - 2015-01-29 11:14 - 01181696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-01-29 11:14 - 2015-01-29 11:14 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-01-29 11:14 - 2015-01-29 11:14 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2015-01-29 11:14 - 2015-01-29 11:14 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2015-01-29 11:14 - 2015-01-29 11:14 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2015-01-29 11:14 - 2015-01-29 11:14 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-01-29 11:14 - 2015-01-29 11:14 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2015-01-29 11:12 - 2015-01-29 11:15 - 00007168 _____ () C:\Windows\IE10_main.log
2015-01-29 10:54 - 2015-01-29 10:54 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Google
2015-01-29 08:43 - 2015-01-29 08:43 - 00000000 ____D () C:\Users\Public\Documents\Logishrd
2015-01-28 22:57 - 2015-01-28 22:59 - 00000000 ____D () C:\Program Files (x86)\Trojan Remover
2015-01-28 22:57 - 2015-01-28 22:57 - 00000000 ____D () C:\Users\Owner\Documents\Simply Super Software
2015-01-28 22:57 - 2015-01-28 22:57 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Simply Super Software
2015-01-28 22:57 - 2015-01-28 22:57 - 00000000 ____D () C:\ProgramData\Simply Super Software
2015-01-28 22:57 - 2015-01-28 22:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
2015-01-28 22:57 - 2003-02-02 20:06 - 00153088 _____ () C:\Windows\SysWOW64\UNRAR3.dll
2015-01-28 22:57 - 2002-03-06 01:00 - 00075264 _____ () C:\Windows\SysWOW64\unacev2.dll
2015-01-28 17:47 - 2015-01-28 20:17 - 00000000 ____D () C:\Windows\FrameworkUpdate
2015-01-28 17:47 - 2015-01-28 17:47 - 00008528 _____ () C:\Users\Owner\AppData\HELP_DECRYPT.HTML
2015-01-28 17:47 - 2015-01-28 17:47 - 00000272 _____ () C:\Users\Owner\AppData\HELP_DECRYPT.URL
2015-01-28 17:46 - 2015-01-28 17:46 - 00008528 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.HTML
2015-01-28 17:46 - 2015-01-28 17:46 - 00000272 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.URL
2015-01-27 13:55 - 2015-01-28 18:11 - 00000000 ____D () C:\Program Files (x86)\SmartApp
2015-01-24 18:05 - 2015-01-24 18:05 - 00002996 _____ () C:\Windows\System32\Tasks\{BDD8CB15-6C5F-4803-9B99-87E7C2FB4F16}
2015-01-24 18:05 - 2015-01-24 18:05 - 00002996 _____ () C:\Windows\System32\Tasks\{976C70B3-B968-47F2-A94F-E8244D9219A0}
2015-01-22 18:42 - 2015-01-22 18:42 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\IObit
2015-01-22 11:43 - 2015-01-22 11:48 - 00018432 ___SH () C:\Users\Owner\AppData\Thumbs.db
2015-01-21 11:09 - 2015-01-21 11:13 - 00000000 ____D () C:\Users\Owner\Documents\Fax
2015-01-19 19:42 - 2015-01-19 19:42 - 00001036 _____ () C:\Users\Public\Desktop\AOL Desktop 9.7.lnk
2015-01-19 19:42 - 2015-01-19 19:42 - 00000000 ____D () C:\Program Files\AOL Toolbar
2015-01-19 19:41 - 2015-01-19 19:42 - 00000000 ____D () C:\Program Files (x86)\AOL Toolbar
2015-01-19 19:40 - 2015-01-28 17:56 - 00000000 ____D () C:\Program Files (x86)\AOL Desktop 9.7c
2015-01-17 19:43 - 2014-12-18 19:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-17 19:37 - 2014-12-18 21:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-17 19:37 - 2014-12-11 23:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-17 19:37 - 2014-12-11 23:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-17 19:37 - 2014-12-11 23:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-17 19:37 - 2014-12-11 23:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-17 19:37 - 2014-12-11 23:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-17 19:37 - 2014-12-11 23:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-17 19:37 - 2014-12-11 23:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-17 19:37 - 2014-12-11 11:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-17 19:37 - 2014-12-05 22:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-17 19:37 - 2014-12-05 21:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-17 19:37 - 2014-12-05 21:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-16 16:10 - 2015-01-16 16:10 - 00008536 _____ () C:\ProgramData\HELP_DECRYPT.HTML
2015-01-16 16:10 - 2015-01-16 16:10 - 00000276 _____ () C:\ProgramData\HELP_DECRYPT.URL
2015-01-16 16:09 - 2015-01-29 20:48 - 00000000 ____D () C:\1d157577
2015-01-13 08:32 - 2015-01-17 19:24 - 00000000 ____D () C:\Users\Owner\Documents\CbBcolorfolder
2015-01-10 22:50 - 2015-01-10 22:50 - 00000000 ____D () C:\TDSSKiller_Quarantine
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-30 08:01 - 2013-02-11 19:42 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-30 08:01 - 2009-07-13 22:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-30 08:01 - 2009-07-13 22:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-30 07:57 - 2014-10-18 16:20 - 02054592 _____ () C:\Windows\WindowsUpdate.log
2015-01-30 07:51 - 2013-08-29 10:12 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-01-30 07:50 - 2013-02-11 19:42 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-30 07:49 - 2014-12-23 08:27 - 00999880 _____ () C:\Windows\setupact.log
2015-01-30 07:49 - 2014-12-23 08:27 - 00486344 _____ () C:\Windows\PFRO.log
2015-01-30 07:49 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-29 22:10 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\tracing
2015-01-29 22:08 - 2012-11-03 14:58 - 00000000 ____D () C:\Users\Owner\AppData\Local\AOL
2015-01-29 22:06 - 2013-02-22 18:57 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin
2015-01-29 22:06 - 2013-02-22 18:57 - 00000000 __SHD () C:\AI_RecycleBin
2015-01-29 22:05 - 2012-11-13 12:07 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-29 22:02 - 2013-02-06 11:23 - 00000000 ____D () C:\Windows\erdnt
2015-01-29 21:52 - 2009-07-13 23:13 - 00782470 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-29 21:39 - 2013-04-13 20:44 - 00226816 ___SH () C:\Users\Owner\Documents\Thumbs.db
2015-01-29 21:19 - 2012-11-02 09:23 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-29 21:13 - 2009-07-13 20:34 - 00000215 _____ () C:\Windows\system.ini
2015-01-29 21:01 - 2012-04-11 12:33 - 00000000 ____D () C:\ProgramData\Temp
2015-01-29 20:54 - 2014-09-29 19:31 - 00356864 ___SH () C:\Users\Owner\Downloads\Thumbs.db
2015-01-29 20:44 - 2012-11-06 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-01-29 20:43 - 2012-11-06 19:47 - 00000000 ____D () C:\ProgramData\Avira
2015-01-29 20:43 - 2012-11-06 19:47 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-01-29 20:16 - 2013-02-16 12:19 - 00000000 ____D () C:\Windows\Minidump
2015-01-29 19:44 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-29 19:23 - 2013-01-11 09:39 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{DE660809-D05E-4624-B975-0EBAD77AF06D}
2015-01-29 19:15 - 2014-12-26 11:53 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-29 18:16 - 2014-12-26 16:55 - 00768194 _____ () C:\ProgramData\wgbgusf.html
2015-01-29 17:55 - 2012-11-12 13:09 - 00000000 ____D () C:\Users\Owner
2015-01-29 17:51 - 2014-11-01 19:50 - 00000000 ____D () C:\Program Files (x86)\Xero
2015-01-29 17:51 - 2012-11-02 10:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2015-01-29 17:50 - 2012-11-09 13:17 - 00000000 ____D () C:\Program Files\windows xp mode
2015-01-29 17:46 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-01-29 11:20 - 2014-09-21 15:24 - 00001415 _____ () C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-29 11:16 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-01-29 10:54 - 2012-11-07 12:54 - 00000000 ____D () C:\Users\Owner\AppData\Local\Google
2015-01-28 22:02 - 2013-01-22 09:37 - 00774592 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-01-28 18:07 - 2012-11-02 09:26 - 00000000 ____D () C:\Users\Owner\AppData\Local\Apple Computer
2015-01-28 17:49 - 2014-08-27 07:09 - 00000000 ____D () C:\ProgramData\ProductData
2015-01-28 17:49 - 2014-06-19 12:14 - 00000000 ____D () C:\ProgramData\Wondershare Video Converter Ultimate
2015-01-28 17:49 - 2014-05-29 18:11 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-01-28 17:49 - 2014-01-28 11:58 - 00000000 ____D () C:\Users\Owner\AppData\Local\CouponAlert_2p
2015-01-28 17:49 - 2013-09-09 14:39 - 00000000 ____D () C:\Users\Owner\AppData\Local\AOL Toolbar
2015-01-28 17:49 - 2013-04-04 21:01 - 00000000 ____D () C:\Users\Owner\AppData\Local\Lphant
2015-01-28 17:49 - 2013-02-11 12:11 - 00000000 ____D () C:\Users\Owner\AppData\Local\Microsoft Games
2015-01-28 17:49 - 2012-11-06 11:21 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Mozilla
2015-01-28 17:49 - 2012-11-03 17:36 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Epson
2015-01-28 17:49 - 2012-11-03 14:59 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\AOL
2015-01-28 17:49 - 2012-11-03 08:18 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Roxio
2015-01-28 17:49 - 2012-11-02 09:26 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Apple Computer
2015-01-28 17:49 - 2012-11-02 09:23 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Adobe
2015-01-28 17:49 - 2012-10-31 14:14 - 00000000 ____D () C:\Users\Owner\AppData\Local\VirtualStore
2015-01-28 17:48 - 2014-12-26 11:52 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-28 17:48 - 2014-10-26 08:22 - 00000000 ____D () C:\Program Files (x86)\Cool Record Edit Pro
2015-01-28 17:48 - 2014-10-09 19:42 - 00000000 ____D () C:\Program Files (x86)\AVS4YOU
2015-01-28 17:48 - 2014-08-07 19:53 - 00000000 ____D () C:\Program Files (x86)\Sqirlz Water Reflections
2015-01-28 17:48 - 2014-07-18 08:23 - 00000000 ____D () C:\ProgramData\Logishrd
2015-01-28 17:48 - 2012-11-12 21:28 - 00000000 ____D () C:\Program Files (x86)\WavMan Pro
2015-01-28 17:48 - 2012-11-09 14:30 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-01-28 17:48 - 2012-11-06 09:27 - 00000000 ____D () C:\Program Files (x86)\NexusFont
2015-01-28 17:48 - 2012-11-03 14:58 - 00000000 ____D () C:\ProgramData\AOL
2015-01-28 17:47 - 2014-10-17 05:41 - 00000000 ____D () C:\Program Files\iPod
2015-01-28 17:47 - 2014-07-07 07:00 - 00000000 ____D () C:\Program Files (x86)\Audacity
2015-01-28 17:47 - 2014-06-20 07:34 - 00000000 ____D () C:\Program Files (x86)\Free Videos To DVD
2015-01-28 17:47 - 2014-03-02 08:17 - 00000000 ____D () C:\Program Files (x86)\ffdshow
2015-01-28 17:47 - 2013-03-07 16:57 - 00000000 ____D () C:\Program Files (x86)\InboxDollars
2015-01-28 17:47 - 2013-03-02 08:18 - 00000000 ____D () C:\Program Files\Microsoft Mouse and Keyboard Center
2015-01-28 17:47 - 2012-11-16 19:47 - 00001376 _____ () C:\Users\Owner\AppData\HELP_DECRYPT.TXT.gjhsaqj
2015-01-28 17:47 - 2012-11-13 09:45 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2015-01-28 17:46 - 2012-11-16 19:47 - 00001376 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.TXT.gjhsaqj
2015-01-24 17:19 - 2012-11-02 09:23 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-24 17:19 - 2012-11-02 09:23 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-24 17:19 - 2012-11-02 09:23 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-23 08:31 - 2014-06-20 07:35 - 00000000 ____D () C:\Users\Owner\Documents\Movies2DVDProjects
2015-01-23 08:28 - 2013-04-19 08:52 - 00000000 ____D () C:\Users\Owner\Documents\EuphoriaScript-Regular
2015-01-22 12:06 - 2012-11-16 19:47 - 00000672 _____ () C:\sc-cleaner.TXT.gjhsaqj
2015-01-22 12:02 - 2014-07-09 18:16 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\vlc
2015-01-22 11:57 - 2013-02-27 12:37 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Thinstall
2015-01-22 11:57 - 2012-11-03 17:11 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\TPA Software
2015-01-22 11:53 - 2012-11-03 19:49 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Malwarebytes
2015-01-22 11:48 - 2014-09-28 15:38 - 00023552 ___SH () C:\Users\Owner\AppData\Roaming\Thumbs.db
2015-01-22 10:11 - 2014-06-12 09:55 - 00000000 ____D () C:\Program Files (x86)\Simple
2015-01-19 19:42 - 2014-05-02 11:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-19 19:42 - 2013-09-08 13:41 - 00000968 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\AOL Desktop 9.7.lnk
2015-01-19 19:42 - 2013-05-17 08:47 - 00129898 _____ () C:\install.log
2015-01-19 19:42 - 2012-11-09 14:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL
2015-01-19 19:36 - 2012-11-03 14:59 - 00058696 _____ (AOL Inc.) C:\Windows\SysWOW64\AOLParconLink.exe
2015-01-18 16:32 - 2014-06-12 09:56 - 00000000 ____D () C:\Users\Owner\AppData\Local\NSManager
2015-01-17 20:11 - 2014-08-12 06:15 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-17 19:47 - 2013-07-25 08:05 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-17 19:43 - 2012-11-13 09:02 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-17 19:25 - 2014-08-27 07:10 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\ProductData
2015-01-17 19:25 - 2014-08-27 07:08 - 00000000 ____D () C:\ProgramData\IObit
2015-01-17 19:25 - 2014-04-26 09:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClipGrab
2015-01-17 19:25 - 2014-04-26 09:12 - 00000000 ____D () C:\Program Files (x86)\ClipGrab
2015-01-17 19:25 - 2012-11-02 09:23 - 00000000 ____D () C:\Windows\system32\Macromed
2015-01-17 19:25 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Msdtc
2015-01-17 19:24 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\registration
2015-01-17 19:23 - 2013-02-05 21:20 - 00000000 ____D () C:\Program Files (x86)\Viewpoint
2015-01-17 19:23 - 2012-11-03 16:29 - 00000000 ____D () C:\Program Files (x86)\Jasc Software Inc
2015-01-17 19:23 - 2012-11-02 09:21 - 00000000 ____D () C:\Program Files (x86)\IObit
2015-01-16 19:04 - 2012-11-16 19:47 - 00051232 _____ () C:\TDSSKiller.3.0.0.42_16.01.2015_18.28.35_log.TXT.gjhsaqj
2015-01-16 16:10 - 2012-11-16 19:47 - 00001376 _____ () C:\ProgramData\HELP_DECRYPT.TXT.gjhsaqj
2015-01-14 18:32 - 2013-04-04 21:01 - 00000000 ____D () C:\Users\Owner\Documents\My Received Files
2015-01-10 22:55 - 2012-11-16 19:47 - 00000944 _____ () C:\TDSSKiller.3.0.0.42_10.01.2015_22.55.06_log.TXT.gjhsaqj
2015-01-10 22:50 - 2012-11-16 19:47 - 00184400 _____ () C:\TDSSKiller.3.0.0.42_10.01.2015_22.44.26_log.TXT.gjhsaqj
2015-01-10 22:36 - 2012-11-16 19:47 - 00001008 _____ () C:\TDSSKiller.3.0.0.42_10.01.2015_22.35.29_log.TXT.gjhsaqj
2015-01-09 18:26 - 2013-12-16 09:04 - 00000000 ____D () C:\Users\Owner\Documents\EMPTY FILE 1
2015-01-09 18:20 - 2014-04-15 10:30 - 00000000 ____D () C:\Users\Owner\AppData\Local\com
2015-01-08 09:55 - 2010-11-20 21:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-04 14:30 - 2009-07-13 23:08 - 00032548 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-31 07:15 - 2009-07-13 22:45 - 00432488 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-31 07:14 - 2012-11-12 13:47 - 00117432 _____ () C:\Users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
==================== Files in the root of some directories =======
2012-12-31 13:44 - 2001-07-13 06:04 - 3072000 _____ (Jasc Software Inc.) C:\Program Files\anim.exe
2014-07-18 08:10 - 2014-07-18 08:04 - 6826808 _____ (Driver-Soft Inc. ) C:\Program Files (x86)\Driver_Genius_10_Professional_US_PPC.exe
2014-09-01 02:18 - 2014-09-01 02:18 - 0002086 _____ () C:\Users\Owner\AppData\Roaming\REFHBFG
2014-09-28 15:38 - 2015-01-22 11:48 - 0023552 ___SH () C:\Users\Owner\AppData\Roaming\Thumbs.db
2012-11-03 08:18 - 2014-03-05 10:23 - 0002412 _____ () C:\Users\Owner\AppData\Roaming\wklnhst.dat
2013-05-04 14:56 - 2013-05-04 15:15 - 0003584 _____ () C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-28 17:46 - 2015-01-28 17:46 - 0008528 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.HTML
2015-01-28 17:46 - 2015-01-28 17:46 - 0045504 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.PNG
2012-11-16 19:47 - 2015-01-28 17:46 - 0001376 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.TXT.gjhsaqj
2015-01-28 17:46 - 2015-01-28 17:46 - 0000272 _____ () C:\Users\Owner\AppData\Local\HELP_DECRYPT.URL
2013-08-15 18:35 - 2012-06-26 04:59 - 0940544 _____ (Apache Software Foundation) C:\Users\Owner\AppData\Local\log4cxx.dll
2014-10-16 12:57 - 2014-10-16 12:57 - 0000834 _____ () C:\Users\Owner\AppData\Local\recently-used.xbel
2015-01-16 16:10 - 2015-01-16 16:10 - 0008536 _____ () C:\ProgramData\HELP_DECRYPT.HTML
2015-01-16 16:10 - 2015-01-16 16:10 - 0045547 _____ () C:\ProgramData\HELP_DECRYPT.PNG
2012-11-16 19:47 - 2015-01-16 16:10 - 0001376 _____ () C:\ProgramData\HELP_DECRYPT.TXT.gjhsaqj
2015-01-16 16:10 - 2015-01-16 16:10 - 0000276 _____ () C:\ProgramData\HELP_DECRYPT.URL
2014-12-26 16:55 - 2015-01-29 18:16 - 0768194 _____ () C:\ProgramData\wgbgusf.html
Files to move or delete:
====================
C:\Users\Owner\CouponPrinter.exe
C:\Users\Owner\sf102.exe
Some content of TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-26 14:51
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-01-2015
Ran by [removed] at 2015-01-30 08:17:38
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 13.0.0.111 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AOL Toolbar (HKLM-x32\…\AOL Toolbar) (Version: - AOL Inc.)
AOL Toolbar (HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\AOL Toolbar) (Version: - )
AOL Uninstaller (Choose which Products to Remove) (HKLM-x32\…\AOL Uninstaller) (Version: - AOL Inc.)
Apple Application Support (HKLM-x32\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Audacity 2.0.5 (HKLM-x32\…\Audacity_is1) (Version: 2.0.5 - Audacity Team)
Avira (HKLM-x32\…\{2c18809c-4097-4b51-a4d0-3deade730ef3}) (Version: 1.1.29.22350 - Avira Operations & Co. KG)
Avira (x32 Version: 1.1.29.22350 - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\…\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira)
AVS Video Editor 6.5 (HKLM-x32\…\AVS Video Editor_is1) (Version: 6.5.1.246 - Online Media Technologies Ltd.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
ClipGrab 3.4.7 (HKLM-x32\…\{8A1033B0-EF33-4FB5-97A1-C47A7DCDD7E6}_is1) (Version: - Philipp Schmieder Medien)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Cool Record Edit Pro v8.8.3 (HKLM-x32\…\Cool Record Edit Pro_is1) (Version: - Copyright(C) 2005-2014 CoolMedia, Inc.)
Coupon Printer for Windows (HKLM-x32\…\Coupon Printer for Windows5.0.1.3) (Version: 5.0.1.3 - Coupons.com Incorporated)
Download Updater (AOL Inc.) (HKLM-x32\…\SoftwareUpdUtility) (Version: - AOL Inc.) <==== ATTENTION
Driver Booster (HKLM-x32\…\Driver Booster_is1) (Version: 1.5 - IObit)
Driver Support (HKLM-x32\…\{597FB4A5-DD86-4316-A410-7E8074CC2CCE}) (Version: 9.1.4.4 - PC Drivers Headquarters, LP)
Epson Event Manager (HKLM-x32\…\{FA9D303D-0FB2-49C7-9397-8E6B11EA892D}) (Version: - )
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version: - Seiko Epson Corporation)
EPSON WorkForce 545 Series Printer Uninstall (HKLM\…\EPSON WorkForce 545 Series) (Version: - SEIKO EPSON Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Free Videos To DVD V 4.0.0 (HKLM-x32\…\Free Videos To DVD_is1) (Version: 4.0.0.0 - Koyote soft)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
I. d. l. e . C. r. a. w. l. e. r (HKLM-x32\…\I. d. l. e . C. r. a. w. l. e. r) (Version: 98.0.0.445 - SADDLEBACK PROC LTD)
iCloud (HKLM\…\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)
Inpaint 6.0 (HKLM\…\{2AEDC172-479F-47AE-8A48-A0524D4AED5B}_is1) (Version: - Teorex)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3517 - Intel Corporation)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\…\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Logitech SetPoint 6.65 (HKLM\…\SP6) (Version: 6.65.62 - Logitech)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.1.177.0 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3259929428-2434079444-325336261-1000\…\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft VC9 runtime libraries (HKLM-x32\…\{AA027AE9-DD20-4677-AA72-D760A358320B}) (Version: - )
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710F4C1C-CC18-4C49-8CBF-51240C89A1A2}) (Version: - )
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 31.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.)
Simple 1.0 (HKLM-x32\…\Simple) (Version: 1.0 - Simple)
Snap.Do (HKLM-x32\…\{F33C8209-E8E0-49C8-8D7E-363CD346C801}) (Version: 11.117.1.19710 - ReSoft Ltd.) <==== ATTENTION
Software Updater (HKLM-x32\…\{6DFBE8A2-CDBF-453E-B34C-32F202FCEE4C}) (Version: 4.2.1 - SEIKO EPSON CORPORATION)
Sqirlz Water Reflections (HKLM-x32\…\Sqirlz Water Reflections) (Version: 2.6 - xiberpix)
Surfing Protection (HKLM-x32\…\IObit Surfing Protection_is1) (Version: 1.2 - IObit)
Toolwiz Care (HKLM-x32\…\ToolwizCareFree) (Version: 3.1.0.5500 - ToolWiz Care)
Trojan Remover 6.9.1.2932 (HKLM-x32\…\Trojan Remover_is1) (Version: 6.9.1.2932 - Simply Super Software)
v9 uninstaller (HKLM-x32\…\v9 uninstaller) (Version: - v9)
Visual Studio 2010 x64 Redistributables (HKLM\…\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
VLC media player 2.1.0 (HKLM-x32\…\VLC media player) (Version: 2.1.0 - VideoLAN)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WOT for Internet Explorer (HKLM\…\{DCAEC601-735C-41AE-B84F-D792F09FB7D1}) (Version: 12.8.2.0 - WOT Services Oy)
Yahoo! Toolbar (HKLM-x32\…\Yahoo! Companion) (Version: - Yahoo! Inc.)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3259929428-2434079444-325336261-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3259929428-2434079444-325336261-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3259929428-2434079444-325336261-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3259929428-2434079444-325336261-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3259929428-2434079444-325336261-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Owner\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)
==================== Restore Points =========================
29-01-2015 22:03:35 ComboFix created restore point
29-01-2015 22:06:03 Removed Should I Remove It
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 20:34 - 2015-01-29 21:13 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {00FBB46A-0E22-418C-AA4D-559E424D9D9D} - System32\Tasks\{61591831-4A0C-4B83-97D3-5EEC04CCBD06} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {02540430-9BB7-4D99-B255-02B4BABEF86E} - System32\Tasks\Optimum_LogOn => C:\Program Files (x86)\Optimum PC Boost\OptimumPCBoost.exe <==== ATTENTION
Task: {08D89799-CEAA-490C-BE61-FD99B205F103} - System32\Tasks\Driver Support-RTMRules => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {0A008589-F513-464A-9ABB-900960D40D35} - \RocketTab No Task File <==== ATTENTION
Task: {0CB99C9A-E4FF-4C06-AE1B-4A3EF96EC719} - System32\Tasks\{83E92520-9DF3-453E-84B8-EF29DA62691B} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {0F3294B1-D7AA-494C-B892-0F4EC4EF9988} - System32\Tasks\Driver Support-RTMScanRunOnce => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {10016D23-F02F-4D08-B721-9F77B6997C55} - System32\Tasks\{2C337EC9-5C41-4AB6-A76F-9D8693CA1C79} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {122CE953-97CA-473B-A6B2-9956E3B1602C} - System32\Tasks\{1CED7CFA-2C4B-408C-98BF-361C70F509C5} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {132AAA73-44D5-462B-AA77-1EC3F16135B2} - System32\Tasks\Driver Support-RTMScan => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {149BB75A-8C05-4DD8-9AA2-DAD532B87159} - System32\Tasks\{1975542B-357E-4DEC-8951-4A68801636F4} => C:\Users\Owner\Downloads\CouponPrinter.exe
Task: {15D96395-6500-4BD7-BB98-D4478616B880} - System32\Tasks\{24F46121-A521-4027-B46A-DDFBC8A5AF70} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {17147DEE-53AE-4452-B80F-99B0D533D9C0} - \IC Running Procedure No Task File <==== ATTENTION
Task: {17D1F95D-06E9-4D21-939C-CDDDC315B069} - System32\Tasks\{2653DBBA-5B60-47F3-AB20-3DB9376ABBD6} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {18E78768-7112-4EC4-9516-58963DBBA46D} - System32\Tasks\Optimum_Daily => C:\Program Files (x86)\Optimum PC Boost\OptimumPCBoost.exe <==== ATTENTION
Task: {1928B8C9-6A00-4536-B4ED-02A32163C444} - System32\Tasks\{B50A8EB7-E293-4EA5-88EF-EB975A0819D6} => C:\Program Files (x86)\Unlocker\Unlocker.exe
Task: {1A2E47A7-583A-4B83-84F9-84807F03CC04} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1A9C0F84-408C-438A-9EF4-A368A9A958C6} - System32\Tasks\{3BD7749A-540A-435A-B9DD-4AEDD58D22CC} => pcalua.exe -a "C:\ProgramData\AOL Downloads\waol\0.4343.1028.1\waol-0.4343.1028.1.exe" -d C:\Users\Owner\Desktop
Task: {1AA26A32-E301-4FD6-8606-4A1DB6F31965} - System32\Tasks\{47B4CF36-A913-42C7-A85D-331963B0F3F3} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {1ADFE583-0532-48A3-ACA4-191CF9A9E3D4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {1CE672C0-509C-4064-A6B6-A25DB404E933} - System32\Tasks\{4A965686-7CC8-47F7-A7A3-6C4AE241CDF8} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {203A4B67-334B-4706-93CB-A8EC6C7AAE8E} - System32\Tasks\{1DB427E2-985C-423B-A9F3-540492DB616A} => C:\Users\Owner\Downloads\CouponPrinter.exe
Task: {244310F0-3DD0-4E79-B558-6134CC82E601} - System32\Tasks\{6CAF3D22-CC6F-46D9-A1E2-1FF35E655CE5} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {2F5695ED-255B-4B16-936A-DBD31E56C63C} - System32\Tasks\{AE6D860C-077B-496E-8541-91CBFE4EE631} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {34E207A3-EBA4-4B4D-B5A0-2D789118948C} - System32\Tasks\{EC6740FB-AC03-4681-AB9E-BBDFEA09FB99} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {35862520-ED23-4F91-B177-A18236122E84} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe <==== ATTENTION
Task: {4052269D-E25E-4594-8DD6-BE63D2BFDBF8} - System32\Tasks\Test TimeTrigger => C:\Users\Owner\AppData\Local\Temp\Runner.exe <==== ATTENTION
Task: {40B15FB1-63CD-4D54-9D56-C83F71DEBCCC} - System32\Tasks\{218031F7-E4A1-4AF5-B8C6-096C3F9E3EAB} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {4465369B-E70A-47A0-832B-1D474A7D6DE1} - System32\Tasks\{88C2FBD7-0DB3-4FAD-BF6D-87F760712270} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {467E8D3C-9AED-424A-B892-1E2A203B8FE2} - System32\Tasks\{0BD12BDF-CE99-4FDC-81E4-3A934224CC66} => pcalua.exe -a "C:\ProgramData\AOL Downloads\SUD4578\waol-0.4343.1028.1.exe" -d C:\Users\Owner\Desktop
Task: {4711FA90-444E-4D03-8349-64E93888BA6A} - System32\Tasks\{E214E131-9346-43D8-A762-077639F94357} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4EQMNXW8\vmp_full_installer_.exe" -d C:\Users\Owner\Desktop
Task: {474A7B96-C5C5-4615-93F7-032C415A1DCC} - System32\Tasks\PCSpeedClean_Popup => C:\Program Files (x86)\PC Speed Clean\Splash.exe
Task: {48E71030-7A56-4709-A3C9-BC15ABC0DE2B} - System32\Tasks\{4D681F21-167E-4543-B80B-14689D80E1D1} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {4D0D99BB-D893-4F89-BB53-A757B121AE28} - System32\Tasks\{4643D3E1-75D9-4A2B-BB5D-556DDB85C537} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {4E0E2CC4-B1BF-4BA6-8ED4-F0DCAF97EDA2} - \Microsoft\Windows\Maintenance\IC Update Procedure No Task File <==== ATTENTION
Task: {5151FA97-52BC-4872-A415-5BD0B967B412} - System32\Tasks\{15EC676E-6936-446B-B265-FFC2F7EA3FF0} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {527B0C13-2FE5-48EE-A846-7D0FEFDC019C} - System32\Tasks\{8A0D4B42-8C32-44BA-B4A9-AA0E2CAD23C0} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {531E9E9C-28AC-4329-B6BD-418736D01709} - System32\Tasks\{09FFA099-8C4E-4F2C-B9A0-8820AF2AD2B5} => C:\Users\Owner\Downloads\CouponPrinter.exe
Task: {54823467-2A9A-4042-B6FF-702AE5A37575} - System32\Tasks\{7F0E8740-D5FC-4DF0-A632-803BE44D159F} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {5507F091-5B30-4CCE-A312-DE1E2D50D940} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-11] (Google Inc.)
Task: {5517E204-C1AE-4E25-8C6C-5DE34EB752B8} - System32\Tasks\{3E517D30-BA5B-4BB6-98FE-4A7A641C2165} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {5C8FC5FD-FC7A-4DF3-9B15-11A1A5BB5055} - \RocketTab Update Task No Task File <==== ATTENTION
Task: {5D7F2D94-412C-405A-B1AE-0ABFB31A9B5B} - System32\Tasks\{68074224-678D-4E2A-9E0C-A6674DA8B177} => C:\Program Files (x86)\Unlocker\Unlocker.exe
Task: {5F02DB96-DE25-4BC6-804E-89498CCA6DA8} - System32\Tasks\{5A14B04A-7866-4CD8-9258-8C64CD773F29} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {6109EF54-662F-4ADC-9CD1-79474843348D} - System32\Tasks\{82BA4989-2E62-436C-A1C4-79D1C897F04C} => pcalua.exe -a C:\Users\Owner\AppData\Local\Temp\Temp1_R244364_RoxioBurn_v1.01_120B16F.zip\setup.exe
Task: {62C41622-8960-4167-A507-55497793BE59} - System32\Tasks\{E6E5F217-E6BD-41AF-A2F2-9F09CB87204E} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {651D6F5D-541B-44E6-B5AC-39A9DD3F403C} - System32\Tasks\{258455ED-B803-4A4F-93A1-34B127BDFB2D} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {6882A4F5-98FC-4C42-A5AA-15C3D86CE816} - System32\Tasks\{36F2116C-1265-491D-AB6D-A5A746EA3F2E} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {689B96F7-C36D-4768-B0C7-AC403B02D079} - System32\Tasks\{BDD8CB15-6C5F-4803-9B99-87E7C2FB4F16} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {699212CF-A13F-40F7-886B-849EE3E10735} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-01-29] (Microsoft)
Task: {6A19F92E-493D-4017-B1D9-372A105FA8D2} - System32\Tasks\ToolwizCareFree => C:\Program Files (x86)\ToolwizCareFree\ToolwizCares.exe [2014-08-03] (Toolwiz)
Task: {6AE14D4A-BA78-419B-951C-2437EA6DDB80} - System32\Tasks\{6A46DEE1-74FF-49C5-A6BE-F404552C854D} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {6BCA733C-AC35-4267-93B5-3601964602E4} - System32\Tasks\{053AED81-EF59-42F6-9364-574A55CEFB7F} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {70677101-E86A-4F52-97F8-616C237A6B7D} - \NSManager No Task File <==== ATTENTION
Task: {73705BA1-6F72-467B-B1D9-1F196933D300} - System32\Tasks\{3D58FD61-6064-4457-A26E-7691716CD26A} => C:\Program Files (x86)\AOL 9.0\aol.exe
Task: {75D8EF51-BAA2-40E5-BA9A-EBC53D19762A} - System32\Tasks\{F8415E98-B3BE-4967-A012-2C22342FF543} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {76928155-2E59-47AA-AF34-02AEA2D8A10C} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation)
Task: {77D2D51E-D357-4989-A7A4-BF011AB4DD5B} - System32\Tasks\{D09D5D11-02BE-4CE6-A3CC-D2CDC1F64EB0} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {7BADF2E2-C621-4434-94A7-2D9E21B1CA82} - System32\Tasks\{0857F79E-C26F-4E42-BE55-A3D400315715} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {7DCB0FC4-A856-4CFF-ABC4-2E4841E75885} - System32\Tasks\{1C318A78-3F48-44A6-9671-F0284EB24FE9} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {807849F7-6935-4E73-A558-F423EB25015F} - System32\Tasks\{BDF5A42C-CB21-45A2-BD24-A1ABBC8886F5} => C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe [2014-12-03] (Adobe Systems Incorporated)
Task: {84A52CE7-BFA4-4CE1-B624-F78D87FE0067} - System32\Tasks\{F18D6B04-4EF7-4462-BBC9-EF3EB87D8ADE} => C:\ProgramData\AOL Downloads\SUD4578\waol-0.4343.1028.1.exe [2013-04-18] (AOL Inc.)
Task: {84E02CDD-B286-4976-9E98-6F323E945AD5} - System32\Tasks\{3B0C417E-8223-49A2-AC22-921A18B0842B} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {8942407A-74BA-4808-A346-8DB1056775E8} - System32\Tasks\Driver Booster SkipUAC (Owner) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2014-08-06] (IObit)
Task: {8AD995B4-7289-4F96-B71D-B991B43B5E95} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)
Task: {8DD321DD-9889-48DE-8795-72E4B50E2957} - System32\Tasks\{B61AFCC7-E855-4523-80DB-854EFBFBB600} => pcalua.exe -a "C:\Users\Owner\Documents\My Documents\backups\Jasc Animation Shop v3.04 Crack.exe" -d "C:\Users\Owner\Documents\My Documents\backups"
Task: {91BF988E-925C-411B-9D49-27A55137CC12} - System32\Tasks\{1953AE5E-1C4D-4DFE-9727-1F350871F00C} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {942475D8-3A9B-489A-9DB3-2EAEE481B755} - System32\Tasks\{976C70B3-B968-47F2-A94F-E8244D9219A0} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {94ECC31B-9856-4DBD-ADA5-551F0BDDFA3F} - System32\Tasks\{14EFB176-7C85-4F6F-A589-B841994B8B7C} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {9B019086-B8DE-464C-B3EE-E9A99EA3D736} - System32\Tasks\{D860B9DC-5F8B-4686-9FE0-94EB1B6B5149} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {9BBB3BFE-E360-498B-A42A-F00EFFF43087} - System32\Tasks\{2BD41DB5-1622-408D-9AFE-AC879803947E} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {9DD66611-2A79-49C2-994B-505DA83ECAEC} - System32\Tasks\{2322F5D4-96A1-4E04-96A1-A9E6CF172847} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {9EAF68F8-5D5F-488B-B065-0CB96FD374B7} - System32\Tasks\{6656270B-7C76-4BA7-99C0-85F9EA55D176} => C:\Users\Owner\Downloads\CouponPrinter.exe
Task: {A0408F8A-13F4-4679-B348-CDF65E3DF206} - System32\Tasks\ShouldIRemoveIt_Notifications => C:\Program Files (x86)\Reason\Should I Remove It\ShouldIRemoveIt.exe
Task: {A05062A9-EC03-4378-BE4A-C2EB4A33A2C8} - System32\Tasks\{3EE1480B-5085-4689-A1BC-DCA7FA5E4CC4} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {A06FB55D-7EE7-4099-A2B9-72147D438F6E} - System32\Tasks\{423AF14D-5DFD-497E-A69E-00122E73FE16} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {A364BABB-962F-46CE-ABD4-7024EF3970A9} - System32\Tasks\{B90B208D-BBAD-4195-843B-B6D290DFCA8D} => pcalua.exe -a D:\AOLDNLD.exe -d D:\
Task: {AF98D158-A487-47A6-893E-6078C25BB6EC} - System32\Tasks\Driver Support-RTMUpdater => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {B2494DBD-D3BC-4E85-A715-1302DF96CBA9} - System32\Tasks\{0AD17208-35DB-45D2-86CB-FC287E93C26E} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {BC4E2314-5284-4861-BF23-BA63CDF941EB} - System32\Tasks\{F428A962-838C-4655-B682-FD97EC80B894} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {C0B3EFDA-28D4-4AD5-BB82-CEE879703411} - System32\Tasks\{FA26F83A-F34F-439B-8BB1-1F3123F97EDB} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {CA7D2FAF-707B-4297-9E8D-30DCF9BAD449} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-24] (Adobe Systems Incorporated)
Task: {CBBE661D-5B9C-4224-B211-A0BDCD82A701} - System32\Tasks\{EB31CF20-7FE5-40E2-955F-89247A2ADF63} => C:\Program Files (x86)\AOL 9.0\aol.exe
Task: {CE918504-3C3D-4968-992C-1A4CBE38F538} - System32\Tasks\{02051100-F6C5-4D2D-A0A2-F7F80359385B} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {D473B51B-B530-4D95-85FA-CD0EFF24FF52} - System32\Tasks\{5AF9C177-832E-4044-A22C-FC1259396953} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {D67D7EC8-6AC7-4DBB-843E-D55D3C0963D8} - System32\Tasks\{B83E0305-76DB-4580-83C4-01E8A7BD1FA1} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {D789B35D-B67B-4B68-8399-404170363D31} - System32\Tasks\{C641C29E-FFF9-43A0-8FA7-EA6E0A2276A3} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {D97EA2ED-0055-4BB4-BA54-3DE3F47D4921} - System32\Tasks\PCSpeedClean_Start => C:\Program Files (x86)\PC Speed Clean\PCSpeedClean.exe
Task: {DD6B5E86-318C-4B45-B2D6-BFE777EBB23F} - System32\Tasks\{C80ED1D6-94E6-4208-8642-1ACE6E226045} => C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe [2014-12-03] (Adobe Systems Incorporated)
Task: {EBBC2B19-6676-4154-9E02-C4243D8991D2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-11] (Google Inc.)
Task: {EE6D1CD5-B6D1-4463-98F0-DF2194281FC0} - System32\Tasks\{0DAFC39A-6D50-40CB-B9A1-C580A061F004} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {EE8B0FD1-C34A-49D4-89C3-41437ECF7A3F} - System32\Tasks\{05ADB97B-2003-46FF-8C63-D49A9F5766C8} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {F242ECFF-092C-4315-BB68-937F0B3926DF} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation)
Task: {F31737E5-84D5-427E-91F3-F5BE83C61491} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation)
Task: {F40D4B40-7F0F-4784-87AC-581F19D459FA} - System32\Tasks\{8084B7F4-0E14-4E72-8BDC-8BDC5F454073} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: {F56FA8F8-6C24-44A0-BEB1-A0282C1CA7C7} - System32\Tasks\qfuzcuc => C:\Users\Owner\AppData\Local\Temp\qotxqyk.exe <==== ATTENTION
Task: {F9227C41-5649-472C-8C95-142F45B5929C} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation)
Task: {FDE9EF74-F3E0-4490-9F0F-F93B22B8EC1D} - System32\Tasks\{773F54BC-4E7E-4F04-A1EC-BD8D08720438} => C:\Program Files (x86)\Jasc Software Inc\Paint Shop Pro 7\psp.exe [2001-07-13] (Jasc Software, Inc.)
Task: {FF6425A2-E919-40F8-8AA9-EF1F875927AB} - System32\Tasks\{12A2DF10-56B4-4390-8335-E31946911575} => C:\Program Files (x86)\Fade It 2\fadeit.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2011-11-22 15:54 - 2011-01-07 02:57 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-11-02 10:29 - 2005-08-07 23:54 - 00167936 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-11-09 14:25 - 2009-10-28 10:38 - 00118784 _____ () c:\program files (x86)\common files\aol\1352492663\ee\services\proxyprovider\ver1_0_0_1\proxyprovider.dll
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-12-31 12:23 - 2014-12-31 12:23 - 00245760 _____ () C:\Program Files (x86)\Avira\My Avira\System.ComponentModel.Composition.dll
2014-10-17 05:28 - 2014-10-17 05:28 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\93182e9779b8be0f688fd0784df6d7fb\IsdiInterop.ni.dll
2011-11-22 15:57 - 2010-11-06 01:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 00048640 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\zlib.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 21151232 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\libcef.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 00648704 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\libglesv2.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 00122880 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\libegl.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 00094208 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\Components\Tier2Svc.dll
2014-09-16 12:17 - 2014-09-16 12:17 - 00060928 _____ () C:\Program Files (x86)\AOL Desktop 9.7c\Components\DataSvcs.dll
2015-01-24 17:19 - 2015-01-24 17:19 - 16844976 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:CB0AACC9
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SecureAssist => ""="service"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BDRegion => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: HotKeysCmds => C:\windows\system32\hkcmd.exe
MSCONFIG\startupreg: IgfxTray => C:\windows\system32\igfxtray.exe
MSCONFIG\startupreg: IObit Malware Fighter => "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Persistence => C:\windows\system32\igfxpers.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
MSCONFIG\startupreg: ROC_roc_ssl_v12 => "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: vProt => "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
========================= Accounts: ==========================
Administrator (S-1-5-21-3259929428-2434079444-325336261-500 - Administrator - Disabled)
Guest (S-1-5-21-3259929428-2434079444-325336261-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-3259929428-2434079444-325336261-1004 - Limited - Enabled)
Owner (S-1-5-21-3259929428-2434079444-325336261-1000 - Administrator - Enabled) => C:\Users\Owner
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/30/2015 07:52:39 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/29/2015 10:10:46 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={9CEFFB1B-DB14-4135-B420-3F937D34D626}: The user Owner-PC\Owner dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
Error: (01/29/2015 10:10:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 10.0.9200.17183, time stamp: 0x546ebbc7
Faulting module name: aoltb.dll, version: 5.74.1.10053, time stamp: 0x52f4ec5d
Exception code: 0xc0000005
Fault offset: 0x00000000000fa9ff
Faulting process id: 0xf5c
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
Error: (01/29/2015 09:15:09 PM) (Source: Avira Antivirus) (EventID: 4122) (User: NT AUTHORITY)
Description: Unable to load file AvShadow.
Returned error code: 0x3fa
Error: (01/29/2015 09:14:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/29/2015 08:53:02 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={0AE46BA9-9C71-466C-82BA-21A3C7934C98}: The user Owner-PC\Owner dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
Error: (01/29/2015 08:52:39 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={8E7217A8-F36F-4A98-BB59-0545E2F92EC7}: The user Owner-PC\Owner dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
Error: (01/29/2015 08:43:53 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={0444A9E8-1476-460F-A6CA-873FEA253163}: The user Owner-PC\Owner dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
Error: (01/29/2015 08:43:09 PM) (Source: System Restore) (EventID: 8209) (User: )
Description: System Restore did not run because the system was restarted, lost power, or stopped responding. Additional information: (Removed SmartApp).
Error: (01/29/2015 08:39:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (01/30/2015 07:51:44 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Net.Tcp Port Sharing Service service failed to start due to the following error:
%%1053
Error: (01/30/2015 07:51:44 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Tcp Port Sharing Service service to connect.
Error: (01/30/2015 07:51:13 AM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The Net.Tcp Listener Adapter service depends the following service: was. This service might not be installed.
Error: (01/30/2015 07:51:13 AM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The Net.Pipe Listener Adapter service depends the following service: was. This service might not be installed.
Error: (01/30/2015 07:51:13 AM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The Net.Msmq Listener Adapter service depends the following service: msmq. This service might not be installed.
Error: (01/30/2015 07:51:01 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error:
%%1053
Error: (01/30/2015 07:51:01 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect.
Error: (01/30/2015 07:50:12 AM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (01/29/2015 09:49:01 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {3C5E2B20-B911-44E2-A2DD-9F05E7B5E775}
Error: (01/29/2015 09:17:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error:
%%31
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2015-01-29 21:04:22.121
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2015-01-29 21:04:22.090
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-08-03 15:02:35.397
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-08-03 15:02:35.304
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-08-03 09:16:06.587
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-08-03 09:16:06.556
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-08-02 19:35:22.736
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-08-02 19:35:22.642
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-08-01 18:41:33.772
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-08-01 18:41:33.740
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wanatw64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz
Percentage of memory in use: 15%
Total physical RAM: 16301.12 MB
Available physical RAM: 13697.63 MB
Total Pagefile: 32600.42 MB
Available Pagefile: 29855.88 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:1862.92 GB) (Free:1610.92 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 4C5BD17E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1862.9 GB) - (Type=07 NTFS)
==================== End Of Log ============================