This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Adware and popups on every website [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

For about a week or so I have been getting terrible pop ups and redirects on my clicks that will open new tabs that I didn't even open. My home page has also been altered and I am unable to reliably use the computer unless it is in safe mode.

Any help is greatly appreciated to help fix this problem!

 

Here are the logs from the two scanning programs:

 

 

aswMBR

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-02-21 12:42:08
—————————–
12:42:08.888    OS Version: Windows x64 6.3.9600
12:42:08.888    Number of processors: 8 586 0x3C03
12:42:08.889    ComputerName: NATHAN  UserName:
12:42:10.506    Initialize success
12:47:10.355    AVAST engine defs: 15022100
12:47:37.934    The log file has been saved successfully to "C:\Users\nathanw\Desktop\aswMBR.txt"
12:48:44.025    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000003e
12:48:44.026    Disk 0 Vendor: HGST_HTS721010A9E630 JB0OA3J0 Size: 953869MB BusType: 11
12:48:44.216    Disk 0 MBR read successfully
12:48:44.218    Disk 0 MBR scan
12:48:44.236    Disk 0 unknown MBR code
12:48:44.244    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
12:48:44.387    Disk 0 scanning C:\Windows\system32\drivers
12:48:55.435    Service scanning
12:49:09.913    Service serverca C:\Users\nathanw\AppData\Local\ConvertAd\CASrv.exe **INFECTED** Win32:Rootkit-gen [Rtk]
12:49:09.975    Service serverig C:\Users\nathanw\AppData\Local\igs\IGSrv.exe **INFECTED** Win32:Rootkit-gen [Rtk]
12:49:10.076    Service serversu C:\Users\nathanw\AppData\Roaming\SoftwareUpdater\SUsrv.exe **INFECTED** Win32:Rootkit-gen [Rtk]
12:49:16.546    Modules scanning
12:49:16.550    Disk 0 trace - called modules:
12:49:16.565    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll iaStorA.sys
12:49:16.568    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe00025ae5060]
12:49:16.570    3 CLASSPNP.SYS[fffff800b431727b] -> nt!IofCallDriver -> [0xffffe00023425e50]
12:49:16.572    5 ACPI.sys[fffff800b40ea7aa] -> nt!IofCallDriver -> \Device\0000003e[0xffffe00023423060]
12:49:18.439    AVAST engine scan C:\Windows
12:49:20.105    AVAST engine scan C:\Windows\system32
12:51:22.369    AVAST engine scan C:\Windows\system32\drivers
12:51:35.470    AVAST engine scan C:\Users\nathanw
12:51:36.398    File: C:\Users\nathanw\AppData\Local\ConvertAd\carunasu.exe  **INFECTED** Win32:Malware-gen
12:51:36.425    File: C:\Users\nathanw\AppData\Local\ConvertAd\CASrv.exe  **INFECTED** Win32:Rootkit-gen [Rtk]
12:52:47.402    File: C:\Users\nathanw\AppData\Local\igs\igs.exe  **INFECTED** Win32:Dropper-gen [Drp]
12:52:47.440    File: C:\Users\nathanw\AppData\Local\igs\IGSrv.exe  **INFECTED** Win32:Rootkit-gen [Rtk]
12:53:04.244    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\2PXWKNAU\dl[1].htm  **INFECTED** Win32:Adware-gen [Adw]
12:53:25.521    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\BA4B78XG\dl[1].htm  **INFECTED** Win32:Adware-gen [Adw]
12:53:35.202    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\BBGWMW46\dl[1].htm  **INFECTED** Win32:Rootkit-gen [Rtk]
12:53:39.102    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\BBGWMW46\Setup[1].exe  **INFECTED** Win32:Malware-gen
12:53:39.195    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\BBGWMW46\Setup[2].exe  **INFECTED** Win32:Malware-gen
12:53:55.629    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\OD0H28WA\dl[2].htm  **INFECTED** Win32:Rootkit-gen [Rtk]
12:54:03.607    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\PK09Y7LZ\carunasu[1].exe  **INFECTED** Win32:Malware-gen
12:54:23.225    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\SLBT3JQL\ConvertAdSetup[1].exe  **INFECTED** Win32:Adware-gen [Adw]
12:54:27.444    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\SLBT3JQL\VOPackage[1].exe  **INFECTED** Win32:Dropper-gen [Drp]
12:54:30.590    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\WZ32XHW5\count_wp_ign[1].htm  **INFECTED** Win32:Dropper-gen [Drp]
12:54:38.376    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\ZEFNFT72\CASrv[1].exe  **INFECTED** Win32:Rootkit-gen [Rtk]
12:54:43.424    File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\ZEFNFT72\WinCheckSetup[1].exe  **INFECTED** Win32:Dropper-gen [Drp]
12:56:46.124    File: C:\Users\nathanw\AppData\Local\Temp\5E138365-D139-D924-E7D3-05D364FB07C1.exe  **INFECTED** Win32:Adware-gen [Adw]
12:57:00.005    File: C:\Users\nathanw\AppData\Local\Temp\ICReinstall_nsmB328.tmp  **INFECTED** Win32:Malware-gen
12:57:00.394    File: C:\Users\nathanw\AppData\Local\Temp\is45637729\74847631_stp\Generic_vo.exe  **INFECTED** Win32:Dropper-gen [Drp]
12:57:02.319    File: C:\Users\nathanw\AppData\Local\Temp\n4028\VOPackage.exe  **INFECTED** Win32:Dropper-gen [Drp]
12:57:03.975    File: C:\Users\nathanw\AppData\Local\Temp\nsa8472.tmp  **INFECTED** Win32:Dropper-gen [Drp]
12:57:04.140    File: C:\Users\nathanw\AppData\Local\Temp\nsiD5.tmp  **INFECTED** Win32:Malware-gen
12:57:04.193    File: C:\Users\nathanw\AppData\Local\Temp\nsmB328.tmp  **INFECTED** Win32:Malware-gen
12:57:04.397    File: C:\Users\nathanw\AppData\Local\Temp\nsoF5FD.tmp  **INFECTED** Win32:Malware-gen
12:57:04.453    File: C:\Users\nathanw\AppData\Local\Temp\nsoF5FE.tmp  **INFECTED** Win32:Dropper-gen [Drp]
12:57:04.828    File: C:\Users\nathanw\AppData\Local\Temp\nsxDD4B.tmp  **INFECTED** Win32:Adware-gen [Adw]
12:57:04.881    File: C:\Users\nathanw\AppData\Local\Temp\nsy37B8.tmp  **INFECTED** Win32:Dropper-gen [Drp]
12:58:43.892    File: C:\Users\nathanw\AppData\Local\Temp\TDIR542F7706\SI.exe  **INFECTED** Win32:Adware-gen [Adw]
12:58:43.983    File: C:\Users\nathanw\AppData\Local\Temp\TDIR542F7740\SI.exe  **INFECTED** Win32:Adware-gen [Adw]
12:58:44.185    File: C:\Users\nathanw\AppData\Local\Temp\TDIR542F7751\SI.exe  **INFECTED** Win32:Adware-gen [Adw]
12:59:01.771    File: C:\Users\nathanw\AppData\Local\wincheck\Uninstall.exe  **INFECTED** Win32:Adware-gen [Adw]
12:59:01.820    File: C:\Users\nathanw\AppData\Local\wincheck\wincheck.exe  **INFECTED** Win32:Adware-gen [Adw]
13:00:56.214    File: C:\Users\nathanw\AppData\Roaming\SoftwareUpdater\SUsrv.exe  **INFECTED** Win32:Rootkit-gen [Rtk]
13:00:56.267    File: C:\Users\nathanw\AppData\Roaming\SoftwareUpdater\UpdateNotifier.exe  **INFECTED** Win32:Adware-gen [Adw]
13:01:01.089    File: C:\Users\nathanw\AppData\Roaming\VOPackage\VOPackage.exe  **INFECTED** Win32:Dropper-gen [Drp]
13:01:01.133    File: C:\Users\nathanw\AppData\Roaming\VOPackage\VOsrv.exe  **INFECTED** Win32:Adware-gen [Adw]
13:01:01.632    File: C:\Users\nathanw\AppData\Roaming\WSE_Vosteran\UpdateProc\UpdateTask.exe  **INFECTED** Win32:Dropper-gen [Drp]
13:01:11.331    File: C:\Users\nathanw\Downloads\Adobe_Reader_Setup.exe  **INFECTED** Win32:Adware-gen [Adw]
13:01:20.867    File: C:\Users\nathanw\Downloads\Setup.exe  **INFECTED** Win32:SoftPulse-DC [Adw]
13:01:29.827    AVAST engine scan C:\ProgramData
13:04:01.109    Disk 0 statistics 4498395/0/0 @ 2.93 MB/s
13:04:01.113    Scan finished successfully
13:13:00.724    Disk 0 MBR has been saved successfully to "C:\Users\nathanw\Desktop\MBR.dat"
13:13:00.727    The log file has been saved successfully to "C:\Users\nathanw\Desktop\aswMBR.txt"
 

FRST64

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-02-2015
Ran by [removed] (administrator) on NATHAN on 21-02-2015 13:17:18
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(OptimizerMonitor Inc.) C:\Program Files (x86)\IGS\OptimizerMonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-04-23] (Realtek Semiconductor)
HKLM\…\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2014-04-23] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-30] (Intel Corporation)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891568 2014-04-23] (ELAN Microelectronics Corp.)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\…\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2014-01-02] (MSI)
HKLM\…\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [407720 2014-01-02] (MSI)
HKLM\…\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM-x32\…\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2013-08-16] (Creative Technology Ltd)
HKLM-x32\…\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\…\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\…\Run: [SUPER CHARGER] => C:\Program Files (x86)\MSI\SUPER CHARGER\SUPER CHARGER.exe [1047536 2014-02-21] (MSI)
HKLM-x32\…\Run: [PerforMax Cleaner] => C:\Program Files (x86)\PerforMax Cleaner\PerforMax Cleaner.exe [1490944 2014-09-08] ()
HKLM-x32\…\Run: [BService] => C:\Program Files (x86)\Bench\BService\1.1\bservice.exe
HKLM-x32\…\Run: [BService64] => C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe
HKLM-x32\…\Run: [Wd] => C:\Program Files (x86)\Bench\Wd\wd.exe
HKLM-x32\…\Run: [Bench Communicator Watcher] => C:\Program Files (x86)\Bench\Proxy\pwdg.exe
HKLM-x32\…\Run: [Bench Settings Cleaner] => C:\Program Files (x86)\Bench\Proxy\cl.exe
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\…\Run: [gmsd_us_163] => C:\Program Files (x86)\gmsd_us_163\gmsd_us_163.exe [3977576 2015-01-30] ()
HKLM-x32\…\Run: [WinCheck] => C:\Users\nathanw\AppData\Local\wincheck\wincheck.exe [415744 2015-01-31] ()
HKLM-x32\…\Run: [gmsd_us_165] => C:\Program Files (x86)\gmsd_us_165\gmsd_us_165.exe [3978088 2015-01-31] ()
HKLM-x32\…\Run: [SmartWeb] => C:\Users\nathanw\AppData\Local\SmartWeb\SmartWebHelper.exe [270696 2014-12-31] (SoftBrain Technologies Ltd.)
HKLM-x32\…\RunOnce: [upgmsd_us_163.exe] => C:\Users\nathanw\AppData\Local\gmsd_us_163\upgmsd_us_163.exe [3306464 2015-01-30] ()
HKLM-x32\…\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\nathanw\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat"
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [SteelSeries Engine] => C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe [249856 2014-01-23] (SteelSeries ApS)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [CyberGhost] => C:\Program Files\CyberGhost 5\CyberGhost.EXE [404080 2014-06-12] (CyberGhost S.R.L.)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [Driver Support] => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [5673824 2014-08-07] (PC Drivers Headquarters)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [Gameo] => C:\Users\nathanw\AppData\Roaming\Gameo\gameo.exe [42482176 2015-01-18] ()
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [SpeedTray] => C:\Users\nathanw\AppData\Roaming\SpeedTray\speedtray.exe [725518 2014-12-25] ()
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [TheAnswerFinder] => C:\Users\nathanw\AppData\Roaming\TheAnswerFinder\TheAnswerFinder.exe [1786312 2015-01-31] (Mime Ventures)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.38\OptProLauncher.exe [148024 2015-01-29] (PC Utilities Software Limited)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [GoogleChromeAutoLaunch_E51A917143CE60DF87C6800984BEEDC2] => C:\Users\nathanw\AppData\Local\Vosteran\Application\vosteran.exe [1014272 2015-01-24] ()
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\nathanw\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat"
AppInit_DLLs-x32: C:/PROGRA~3/{A6374~1/191~1.1/dota.dll => C:/PROGRA~3/{A6374~1/191~1.1/dota.dll [964608 2015-02-01] ()
AppInit_DLLs-x32:  C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [188224 2014-11-10] (Search Protect)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{29CDA0F1-A6DA-44CC-9ABB-131A7D3D77AE}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SafeConnect.lnk
ShortcutTarget: SafeConnect.lnk -> C:\Program Files (x86)\SafeConnect\SCClient.exe (Impulse Point, LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe ()
Startup: C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
Startup: C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OptimizerProInstaller.lnk
ShortcutTarget: OptimizerProInstaller.lnk -> C:\ProgramData\{2b6e2981-fd67-657c-2b6e-e2981fd6a607}\OptimizerProInstaller.exe (PC Utilities Software Limited)
Startup: C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
ShortcutTarget: SmartWeb.lnk -> C:\Users\nathanw\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.protectedio.com
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msi13.msn.com
SearchScopes: HKLM -> DefaultScope {AEAA03CB-A063-46DD-8F9D-9C73CB30B790} URL = http://astromenda.com/results.php?f=4&q;={searchTerms}&a;=ast_dnldstr_14_40_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtDtDyCtN1L2XzutAtFyDtFtCtFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FtA0DtD0EtB0BtG0BtC0B0FtG0AyDtC0AtGyD0E0EzztGyE0F0A0DzzyD0BzytA0FzzyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0DyCyEyE0AyEzztG0CyBtCzytGyE0D0F0BtGzytD0AyDtGtD0D0FyC0Ezzzy0DtA0FzzyE2Q&cr;=1440908205&ir;=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
SearchScopes: HKLM -> {AEAA03CB-A063-46DD-8F9D-9C73CB30B790} URL = http://astromenda.com/results.php?f=4&q;={searchTerms}&a;=ast_dnldstr_14_40_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtDtDyCtN1L2XzutAtFyDtFtCtFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FtA0DtD0EtB0BtG0BtC0B0FtG0AyDtC0AtGyD0E0EzztGyE0F0A0DzzyD0BzytA0FzzyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0DyCyEyE0AyEzztG0CyBtCzytGyE0D0F0BtGzytD0AyDtGtD0D0FyC0Ezzzy0DtA0FzzyE2Q&cr;=1440908205&ir;=
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid;=CT3330557&octid;=EB_ORIGINAL_CTID&ISID;=M05A97C27-B11B-4A1F-9195-35A3807ABEA1&SearchSource;=58&CUI;=&UM;=6&UP;=SP96CAD07F-DE2B-40FD-A8F7-F76C24BCEE5C&q;={searchTerms}&SSPV;=
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL =
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> {AEAA03CB-A063-46DD-8F9D-9C73CB30B790} URL = http://astromenda.com/results.php?f=4&q;={searchTerms}&a;=ast_dnldstr_14_40_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtDtDyCtN1L2XzutAtFyDtFtCtFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FtA0DtD0EtB0BtG0BtC0B0FtG0AyDtC0AtGyD0E0EzztGyE0F0A0DzzyD0BzytA0FzzyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0DyCyEyE0AyEzztG0CyBtCzytGyE0D0F0BtGzytD0AyDtGtD0D0FyC0Ezzzy0DtA0FzzyE2Q&cr;=1440908205&ir;=
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = http://www.bing.com/search?FORM=U270DF&PC;=U270&q;={searchTerms}&src;=IE-SearchBox
BHO: Browser Warden BHO -> {2C09954F-CDA8-4BD1-8794-1D543E050378} -> C:\Program Files (x86)\Browser Warden\FrameworkBHO64.dll ()
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: SpeedChecker -> {3D9400B3-E14A-2220-608E-DE76BDA6A3AB} -> C:\Program Files (x86)\ver0SpeedChecker\187_x64.dll ()
BHO: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\dca-bho.dll (Compete, Inc.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Browser Warden BHO -> {2C09954F-CDA8-4BD1-8794-1D543E050378} -> C:\Program Files (x86)\Browser Warden\FrameworkBHO.dll No File
BHO-x32: SpeedChecker -> {3D9400B3-E14A-2220-608E-DE76BDA6A3AB} -> C:\Program Files (x86)\ver0SpeedChecker\187.dll ()
BHO-x32: Dolphin Deals -> {7c1ec179-be4e-4bee-b5a7-4596884bbc8d} -> C:\Program Files (x86)\Dolphin Deals\DolphinDealsbho.dll (Dolphin Deals)
BHO-x32: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-bho.dll (Compete, Inc.)
BHO-x32: SecureWebBHO Class -> {D3C24E2B-C820-4492-9B69-11BF7163F998} -> C:\Program Files (x86)\Jelbrus Secure Web\jsie.dll (Jelbrus)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Winsock: Catalog9 01 C:\Windows\SysWOW64\OptimizerMonitor.dll [301152] (OptimizerMonitor Inc.)
Winsock: Catalog9 02 C:\Windows\SysWOW64\OptimizerMonitor.dll [301152] (OptimizerMonitor Inc.)
Winsock: Catalog9 03 C:\Windows\SysWOW64\OptimizerMonitor.dll [301152] (OptimizerMonitor Inc.)
Winsock: Catalog9 04 C:\Windows\SysWOW64\OptimizerMonitor.dll [301152] (OptimizerMonitor Inc.)
Winsock: Catalog9 16 C:\Windows\SysWOW64\OptimizerMonitor.dll [301152] (OptimizerMonitor Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] [removed] [removed] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\nathanw\AppData\Roaming\Mozilla\Firefox\Profiles\frc79gxm.default
FF Homepage: search.protectedio.com
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\nathanw\AppData\Roaming\Mozilla\Firefox\Profiles\frc79gxm.default\user.js
FF Extension: Firefox Helper - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\52f49536d77819bae6f4abd24dce4dfb [2015-02-07]
FF HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Firefox\Extensions: [{57FC8B03-13E5-70AC-4016-0DB57BA53BDF}] - C:\Program Files (x86)\ver0SpeedChecker\187.xpi
FF Extension: SpeedChecker - C:\Program Files (x86)\ver0SpeedChecker\187.xpi [2015-01-31]
FF HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Firefox\Extensions: [ConsumerInput@Compete] - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12099.xpi
FF Extension: Consumer Input - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12099.xpi [2015-01-21]
FF HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]

Chrome:
=======
CHR HomePage: Default -> hxxp://vosteran.com/?f=1&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
CHR StartupUrls: Default -> "hxxp://vosteran.com/?f=7&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=", "hxxp://www.trovi.com/?gd=&ctid;=CT3330557&octid;=EB_ORIGINAL_CTID&ISID;=M05A97C27-B11B-4A1F-9195-35A3807ABEA1&SearchSource;=55&CUI;=&UM;=6&UP;=SP96CAD07F-DE2B-40FD-A8F7-F76C24BCEE5C&SSPV;="
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR Profile: C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-01]
CHR Extension: (Adblock Plus) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-08]
CHR Extension: (Google Wallet) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-01]
CHR Extension: (oaepeijninfcgjdnighjnlgdkkgpnaen) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaepeijninfcgjdnighjnlgdkkgpnaen [2015-02-08]
CHR HKLM\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [pfkfdlcdbajamklbneflfbcmfgddmpae] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [pfkfdlcdbajamklbneflfbcmfgddmpae] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [pfkfdlcdbajamklbneflfbcmfgddmpae] - https://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - chrome.exe

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 4ef60154; c:\Program Files (x86)\Optimizer Pro 3.38\OptProMon.dll [1633848 2015-01-31] ()
S2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64624 2014-06-12] (CyberGhost S.R.L)
S2 ChromeEnhancer; C:\Program Files\ChromeEnhancer\ChromeEnhancer.exe [44544 2015-01-28] () [File not signed]
S2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
S2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [3056960 2014-11-10] (Search Protect)
S2 consumerinput_update; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [106296 2015-02-03] (ConsumerInput)
S3 consumerinput_updatem; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [106296 2015-02-03] (ConsumerInput)
S2 CrUwvroQ; C:\ProgramData\UDDNuLHc\CrUwvroQ.exe [2734864 2015-01-31] (Mathematical Applications)
S2 ETDService; C:\Program Files\Elantech\ETDService.exe [101680 2014-04-23] (ELAN Microelectronics Corp.)
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-01-31] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-01-31] (globalUpdate) [File not signed]
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-30] (Intel Corporation)
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-04-23] (Intel Corporation)
S2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
S2 itsvc_1.10.0.8; C:\Program Files (x86)\IntelliTerm_1.10.0.8\Service\itsvc.exe [278608 2015-01-21] (Intelli Term)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
S2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2014-01-02] (Micro-Star International Co., Ltd.) [File not signed]
S2 MSI_SuperCharger; C:\Program Files (x86)\MSI\SUPER CHARGER\ChargeService.exe [162800 2014-02-21] (MSI)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-10-11] ()
S2 NAT; C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\NAT.exe [232424 2013-10-11] (Symantec Corporation)
S2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4362056 2014-11-18] (Symantec Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2014-04-23] (NVIDIA Corporation)
R2 OptimizerMonitor; C:\Program Files (x86)\IGS\OptimizerMonitor.exe [1820240 2015-01-29] (OptimizerMonitor Inc.) [File not signed]
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-10-28] ()
S2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [344576 2014-03-04] (Qualcomm Atheros) [File not signed]
S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-04-23] (Realtek Semiconductor)
S2 SCManager; C:\Program Files (x86)\SafeConnect\scManager.sys [176520 2012-11-19] (Impulse Point, LLC)
S2 serverca; C:\Users\nathanw\AppData\Local\ConvertAd\CASrv.exe [93184 2015-02-01] () [File not signed]
S2 serverig; C:\Users\nathanw\AppData\Local\igs\IGSrv.exe [93696 2015-02-01] () [File not signed]
S2 serversu; C:\Users\nathanw\AppData\Roaming\SoftwareUpdater\SUsrv.exe [120832 2015-01-31] () [File not signed]
S2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [126568 2015-02-01] (RaMMicHaeL)
S2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [179200 2014-09-13] (Company) [File not signed]
S2 Wajam Web Enhancer; C:\Program Files\Wajam Web Enhancer\wajam_64.exe [2486272 2015-01-28] (Wajam_Internet Technologies Inc.) [File not signed] <==== ATTENTION
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-21] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-21] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3671792 2013-10-11] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [81072 2014-02-20] (Qualcomm Atheros, Inc.)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [63488 2014-04-24] (Microsoft Corporation) [File not signed]
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-11-07] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1411384 2013-11-07] (Motorola Solutions, Inc.)
S3 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0405000.009\ccSetx64.sys [150104 2013-07-29] (Symantec Corporation)
S1 ccSet_NAT; C:\Windows\system32\drivers\NATx64\010A000.009\ccSetx64.sys [150104 2013-07-29] (Symantec Corporation)
S3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [160464 2014-04-23] (Intel Corporation)
R1 itnfd_1_10_0_8; C:\Windows\System32\drivers\itnfd_1_10_0_8.sys [58232 2015-01-21] (Intelli Term)
R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [163536 2013-03-20] (Qualcomm Atheros, Inc.)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3607520 2013-10-14] (Intel Corporation)
S3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\SUPER CHARGER\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
S3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2014-04-23] (NVIDIA Corporation)
S3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [466648 2014-04-23] (Realsil Semiconductor Corporation)
S3 SAlphamBth; C:\Windows\System32\drivers\SAlphabt64.sys [31232 2012-10-16] (SteelSeries Corporation)
S3 SAlphamHid; C:\Windows\System32\drivers\SAlpham64.sys [38016 2013-05-31] (SteelSeries Corporation)
R3 SAlphaPS2; C:\Windows\System32\drivers\SAlphaPS264.sys [26496 2013-12-12] (SteelSeries Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-21] (Microsoft Corporation)
S3 WINIO; C:\Program Files (x86)\MSI\Dragon Gaming Center\winio64.sys [15160 2010-06-07] ()
S3 SPPD; \??\C:\Windows\system32\drivers\SPPD.sys [X]
U3 aswMBR; \??\C:\Users\nathanw\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\nathanw\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-21 13:17 - 2015-02-21 13:17 - 00029662 _____ () C:\Users\nathanw\Desktop\FRST.txt
2015-02-21 13:15 - 2015-02-21 13:17 - 00000000 ____D () C:\FRST
2015-02-21 13:15 - 2015-02-21 13:15 - 00000000 ____D () C:\Users\nathanw\Desktop\FRST-OlderVersion
2015-02-21 13:13 - 2015-02-21 13:13 - 00007124 _____ () C:\Users\nathanw\Desktop\aswMBR.txt
2015-02-21 13:13 - 2015-02-21 13:13 - 00000512 _____ () C:\Users\nathanw\Desktop\MBR.dat
2015-02-21 12:40 - 2015-02-21 13:15 - 02086912 _____ (Farbar) C:\Users\nathanw\Desktop\FRST64.exe
2015-02-21 12:39 - 2015-02-21 12:40 - 05198336 _____ (AVAST Software) C:\Users\nathanw\Desktop\aswMBR.exe
2015-02-15 15:40 - 2015-02-15 15:40 - 00002068 _____ () C:\Windows\SysWOW64\errordetails.xml
2015-02-13 13:27 - 2015-02-15 17:49 - 00000000 ____D () C:\Windows\pss
2015-02-12 15:32 - 2015-01-19 13:42 - 01487976 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2015-02-12 15:31 - 2015-02-03 18:38 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-12 15:31 - 2015-02-03 18:08 - 00761856 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-12 15:31 - 2015-02-03 18:08 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-12 15:31 - 2015-02-02 18:11 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-12 15:31 - 2015-02-02 18:11 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-12 15:31 - 2015-02-02 18:11 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-11 22:42 - 2015-01-10 03:22 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-10 17:29 - 2015-02-10 17:30 - 00015907 _____ () C:\Users\nathanw\Documents\nutritionlog.nathanwatts.xlsx
2015-02-10 17:29 - 2015-02-10 17:29 - 00081920 _____ () C:\Users\nathanw\Documents\nutrientreport.nathanwatts.xls
2015-02-09 21:39 - 2015-02-09 21:40 - 00081920 _____ () C:\Users\nathanw\Downloads\NutrientsReport.xls
2015-02-09 19:08 - 2015-02-09 21:39 - 00015877 _____ () C:\Users\nathanw\Documents\nutrition log.xlsx
2015-02-06 14:51 - 2015-02-07 15:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-06 14:51 - 2015-02-06 14:51 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-06 14:51 - 2015-02-06 14:51 - 00001173 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Mozilla
2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Mozilla
2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\ProgramData\Mozilla
2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-06 14:50 - 2015-02-06 14:50 - 00243440 _____ () C:\Users\nathanw\Downloads\Firefox Setup Stub 35.0.1.exe
2015-02-05 01:27 - 2015-02-05 01:27 - 01246384 _____ () C:\Users\nathanw\Downloads\Installation.exe
2015-02-03 18:59 - 2015-02-03 18:59 - 00000000 ____D () C:\ProgramData\Browser
2015-02-03 18:53 - 2015-02-15 17:49 - 00000378 _____ () C:\Windows\Tasks\CIMT_S-1-5-21-3104748373-4178966826-1034322177-1002.job
2015-02-03 18:53 - 2015-02-12 18:53 - 00000412 _____ () C:\Windows\Tasks\CIMT_daily_S-1-5-21-3104748373-4178966826-1034322177-1002.job
2015-02-03 18:53 - 2015-02-03 18:53 - 00003384 _____ () C:\Windows\System32\Tasks\CIMT_daily_S-1-5-21-3104748373-4178966826-1034322177-1002
2015-02-03 18:53 - 2015-02-03 18:53 - 00003274 _____ () C:\Windows\System32\Tasks\CIMT_S-1-5-21-3104748373-4178966826-1034322177-1002
2015-02-03 18:53 - 2015-02-03 18:53 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Compete
2015-02-03 18:52 - 2015-02-15 17:47 - 00000982 _____ () C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job
2015-02-03 18:52 - 2015-02-13 14:57 - 00000986 _____ () C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job
2015-02-03 18:52 - 2015-02-03 18:53 - 00000000 ____D () C:\Program Files (x86)\Consumer Input
2015-02-03 18:52 - 2015-02-03 18:52 - 00003856 _____ () C:\Windows\System32\Tasks\ConsumerInputUpdateTaskMachineUA
2015-02-03 18:52 - 2015-02-03 18:52 - 00003620 _____ () C:\Windows\System32\Tasks\ConsumerInputUpdateTaskMachineCore
2015-02-03 18:52 - 2015-02-03 18:52 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Consumer Input
2015-02-01 18:23 - 2015-02-15 17:48 - 00383280 _____ () C:\Windows\system32\errordetails.xml
2015-02-01 00:21 - 2015-02-01 00:21 - 00000000 ____D () C:\BreakingNewsAlert
2015-02-01 00:06 - 2015-02-01 17:15 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vosteran
2015-02-01 00:06 - 2015-02-01 00:06 - 00000000 ____D () C:\Users\nathanw\AppData\Local\SmartWeb
2015-02-01 00:06 - 2015-02-01 00:06 - 00000000 ____D () C:\Users\nathanw\AppData\Local\gmsd_us_165
2015-02-01 00:06 - 2015-02-01 00:06 - 00000000 ____D () C:\Program Files (x86)\gmsd_us_165
2015-02-01 00:05 - 2015-02-13 15:06 - 00000314 _____ () C:\Windows\Tasks\WSE_Vosteran.job
2015-02-01 00:05 - 2015-02-13 13:34 - 00004904 _____ () C:\Windows\SysWOW64\OptimizerMonitor.ini
2015-02-01 00:05 - 2015-02-13 13:34 - 00002688 _____ () C:\Windows\SysWOW64\OptimizerMonitorOff.ini
2015-02-01 00:05 - 2015-02-13 13:34 - 00002688 _____ () C:\Windows\system32\OptimizerMonitorOff.ini
2015-02-01 00:05 - 2015-02-01 00:06 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Vosteran
2015-02-01 00:05 - 2015-02-01 00:05 - 00002652 _____ () C:\Windows\System32\Tasks\WSE_Vosteran
2015-02-01 00:05 - 2015-02-01 00:05 - 00000000 ____D () C:\Program Files (x86)\IGS
2015-02-01 00:05 - 2015-01-29 08:22 - 00301152 _____ (OptimizerMonitor Inc.) C:\Windows\SysWOW64\OptimizerMonitor.dll
2015-02-01 00:04 - 2015-02-13 15:04 - 00000782 _____ () C:\Windows\Tasks\Vosteran dota.job
2015-02-01 00:04 - 2015-02-01 17:16 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pirates
2015-02-01 00:04 - 2015-02-01 00:05 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\WSE_Vosteran
2015-02-01 00:04 - 2015-02-01 00:05 - 00000000 ____D () C:\Program Files (x86)\WSE_Vosteran
2015-02-01 00:04 - 2015-02-01 00:04 - 00003788 _____ () C:\Windows\System32\Tasks\Vosteran dota
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Pirates854
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Pirates
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Users\nathanw\AppData\Local\igs
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\ProgramData\Unchecky
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\ProgramData\{A6374EF4-F6B5-9F72-4733-EFF097B13C7E}
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Program Files (x86)\Unchecky
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Program Files (x86)\IntelliTerm_1.10.0.8
2015-01-31 23:58 - 2015-02-15 15:49 - 00003258 _____ () C:\Windows\System32\Tasks\Optimizer Pro Schedule
2015-01-31 23:58 - 2015-01-31 23:58 - 00000000 ____D () C:\Users\nathanw\Documents\Optimizer Pro
2015-01-31 23:58 - 2015-01-31 23:58 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Optimizer Pro
2015-01-31 23:56 - 2015-02-12 23:57 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\SoftwareUpdater
2015-01-31 23:56 - 2015-02-01 00:07 - 00000000 ____D () C:\Users\nathanw\AppData\Local\ConvertAd
2015-01-31 23:54 - 2015-02-15 17:47 - 00002466 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5_user.job
2015-01-31 23:54 - 2015-02-15 17:47 - 00002466 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5.job
2015-01-31 23:54 - 2015-02-11 22:59 - 00000000 ____D () C:\Users\nathanw\AppData\Local\BreakingNewsAlert
2015-01-31 23:54 - 2015-01-31 23:54 - 00005470 _____ () C:\Windows\System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5
2015-01-31 23:53 - 2015-02-15 17:47 - 00003494 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7.job
2015-01-31 23:53 - 2015-02-15 17:47 - 00003158 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6.job
2015-01-31 23:53 - 2015-02-01 00:07 - 00000000 ____D () C:\Users\nathanw\AppData\Local\wincheck
2015-01-31 23:53 - 2015-01-31 23:53 - 00006498 _____ () C:\Windows\System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7
2015-01-31 23:53 - 2015-01-31 23:53 - 00006162 _____ () C:\Windows\System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6
2015-01-31 23:52 - 2015-02-15 17:49 - 00002132 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-10_user.job
2015-01-31 23:52 - 2015-02-15 17:49 - 00000442 _____ () C:\Windows\Tasks\SpeedChecker Update.job
2015-01-31 23:52 - 2015-02-15 17:47 - 00005538 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-7.job
2015-01-31 23:52 - 2015-02-15 17:47 - 00005538 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-6.job
2015-01-31 23:52 - 2015-02-15 17:47 - 00001018 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-01-31 23:52 - 2015-02-15 17:47 - 00000000 ____D () C:\Users\nathanw\AppData\Local\gmsd_us_163
2015-01-31 23:52 - 2015-02-13 13:32 - 00002085 _____ () C:\Windows\patsearch.bin
2015-01-31 23:52 - 2015-02-12 23:57 - 00001022 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-01-31 23:52 - 2015-02-03 18:46 - 00000000 ____D () C:\ProgramData\{2b6e2981-fd67-657c-2b6e-e2981fd6a607}
2015-01-31 23:52 - 2015-01-31 23:54 - 00000000 ____D () C:\ProgramData\UDDNuLHc
2015-01-31 23:52 - 2015-01-31 23:54 - 00000000 ____D () C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01
2015-01-31 23:52 - 2015-01-31 23:53 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\VOPackage
2015-01-31 23:52 - 2015-01-31 23:53 - 00000000 ____D () C:\Program Files (x86)\7d294cc7-8e3e-446e-9a9d-234f73b47a8d
2015-01-31 23:52 - 2015-01-31 23:52 - 00008542 _____ () C:\Windows\System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-7
2015-01-31 23:52 - 2015-01-31 23:52 - 00008542 _____ () C:\Windows\System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-6
2015-01-31 23:52 - 2015-01-31 23:52 - 00003994 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2015-01-31 23:52 - 2015-01-31 23:52 - 00003758 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2015-01-31 23:52 - 2015-01-31 23:52 - 00003086 _____ () C:\Windows\System32\Tasks\SpeedChecker Update
2015-01-31 23:52 - 2015-01-31 23:52 - 00003078 _____ () C:\Windows\System32\Tasks\RPC
2015-01-31 23:52 - 2015-01-31 23:52 - 00001125 _____ () C:\Users\nathanw\Desktop\Optimizer Pro.lnk
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNHKT_01009.Wdf
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GU Player
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Users\nathanw\AppData\Local\globalUpdate
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\ProgramData\BreakingNewsAlert
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Program Files (x86)\ver0SpeedChecker
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 3.38
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Program Files (x86)\GU Player
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Program Files (x86)\gmsd_us_163
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2015-01-31 23:51 - 2015-02-01 18:23 - 00000000 ____D () C:\Program Files (x86)\Regprocleaner
2015-01-31 23:51 - 2015-01-31 23:54 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\TheAnswerFinder
2015-01-31 23:51 - 2015-01-31 23:51 - 00001197 _____ () C:\Users\Public\Desktop\Reg Pro Cleaner.lnk
2015-01-31 23:51 - 2015-01-31 23:51 - 00001179 _____ () C:\Users\Public\Desktop\Regprocleaner.lnk
2015-01-31 23:51 - 2015-01-31 23:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Regprocleaner
2015-01-31 23:51 - 2015-01-31 23:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reg Pro Cleaner
2015-01-31 23:51 - 2015-01-31 23:51 - 00000000 ____D () C:\Program Files (x86)\Reg Pro Cleaner
2015-01-31 15:48 - 2015-01-31 15:48 - 00000001 _____ () C:\Users\Public\Documents\dgc.txt
2015-01-31 00:09 - 2015-01-31 00:09 - 00000000 ____D () C:\Program Files (x86)\Dolphin Deals
2015-01-31 00:06 - 2015-02-12 22:37 - 00003278 _____ () C:\Windows\System32\Tasks\Jelbrus Secure Web Task
2015-01-28 23:28 - 2015-01-28 23:28 - 00000000 ____D () C:\Program Files\ChromeEnhancer
2015-01-24 22:23 - 2015-01-24 22:23 - 00000000 ____D () C:\Users\nathanw\Desktop\New folder

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-21 12:47 - 2014-06-17 00:51 - 01126066 _____ () C:\Windows\WindowsUpdate.log
2015-02-21 12:29 - 2014-07-25 18:04 - 00000000 ____D () C:\Users\nathanw
2015-02-15 19:42 - 2013-11-13 12:03 - 00865408 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-15 19:41 - 2014-07-28 11:13 - 00000000 ____D () C:\Users\nathanw\AppData\Local\CrashDumps
2015-02-15 17:49 - 2013-08-22 09:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-15 17:47 - 2014-07-25 18:19 - 00000916 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-15 17:47 - 2013-08-22 09:46 - 00039837 _____ () C:\Windows\setupact.log
2015-02-15 15:49 - 2014-10-02 23:06 - 00003090 _____ () C:\Windows\System32\Tasks\RegClean Pro
2015-02-15 15:36 - 2014-07-25 18:19 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-13 15:25 - 2014-07-25 18:12 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3104748373-4178966826-1034322177-1002
2015-02-13 15:12 - 2014-10-02 23:07 - 00000314 _____ () C:\Windows\Tasks\UpdaterEX.job
2015-02-13 15:03 - 2014-10-02 23:10 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Gameo
2015-02-13 15:02 - 2014-10-02 23:06 - 00000276 _____ () C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2015-02-13 13:41 - 2013-08-22 10:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-02-13 13:39 - 2013-11-13 15:06 - 00000000 ____D () C:\ProgramData\boost_interprocess
2015-02-13 13:34 - 2014-10-05 01:36 - 00073728 _____ () C:\Windows\SysWOW64\tasks.dll
2015-02-13 00:01 - 2014-11-02 00:50 - 00000362 _____ () C:\Windows\Tasks\bench-S-1-5-21-3104748373-4178966826-1034322177-1002.job
2015-02-12 22:56 - 2013-08-22 09:44 - 00481880 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-12 22:55 - 2013-08-22 08:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-02-12 22:54 - 2014-12-14 16:33 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-12 22:54 - 2014-07-31 07:11 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-12 22:54 - 2014-07-28 11:16 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-12 22:54 - 2014-04-24 15:48 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-12 22:47 - 2014-07-28 11:16 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-12 22:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-02-12 22:38 - 2014-07-25 18:17 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{62839BE3-D084-47BD-A73F-8EB4F8423EF9}
2015-02-12 16:05 - 2014-10-03 00:06 - 00000079 _____ () C:\Users\nathanw\AppData\Roaming\WB.CFG
2015-02-12 15:13 - 2014-08-15 15:31 - 00000000 ____D () C:\Program Files (x86)\SafeConnect
2015-02-10 17:52 - 2014-07-25 18:39 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-10 17:44 - 2014-07-25 18:05 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Packages
2015-02-09 16:43 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-02-03 18:45 - 2014-09-25 22:41 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Skype
2015-02-03 14:31 - 2014-08-02 10:51 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-03 14:31 - 2014-08-02 10:51 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-01 18:20 - 2013-11-13 11:53 - 01195148 _____ () C:\Windows\PFRO.log
2015-02-01 00:03 - 2014-09-09 16:40 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Adobe
2015-01-31 23:53 - 2014-07-26 09:26 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2015-01-31 00:05 - 2014-07-25 18:19 - 00002285 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-28 23:06 - 2014-10-02 23:06 - 00000284 _____ () C:\Windows\Tasks\RegClean Pro_UPDATES.job
2015-01-28 15:44 - 2014-09-25 22:38 - 00000000 ____D () C:\Program Files\Wajam Web Enhancer
2015-01-24 22:16 - 2014-10-02 23:10 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Gameo
2015-01-22 21:18 - 2014-07-25 18:06 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Adobe

==================== Files in the root of some directories =======

2014-10-03 00:06 - 2015-02-12 16:05 - 0000079 _____ () C:\Users\nathanw\AppData\Roaming\WB.CFG
2014-11-02 20:31 - 2014-12-27 14:47 - 0000003 _____ () C:\Users\nathanw\AppData\Local\proxy.log
2014-09-01 22:04 - 2014-09-01 22:04 - 0000000 _____ () C:\Users\nathanw\AppData\Local\{C03E1153-99E9-4E26-8BFE-471025ABE5FF}

Some content of TEMP:
====================
C:\Users\nathanw\AppData\Local\Temp\5E138365-D139-D924-E7D3-05D364FB07C1.dll
C:\Users\nathanw\AppData\Local\Temp\5E138365-D139-D924-E7D3-05D364FB07C1.exe
C:\Users\nathanw\AppData\Local\Temp\7675_.exe
C:\Users\nathanw\AppData\Local\Temp\8658_.exe
C:\Users\nathanw\AppData\Local\Temp\9686FB06-6AC9-7F61-45F2-378B0915C505.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup0216__7675.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup2481__7675.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup4018__7675.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup4390__8658.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup5092__7675.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup5140__8658.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup5683__9288.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup5731__7675.exe
C:\Users\nathanw\AppData\Local\Temp\CloudBackup83.exe
C:\Users\nathanw\AppData\Local\Temp\ConsumerInputSetup.exe
C:\Users\nathanw\AppData\Local\Temp\cubfmglb.0eo.exe
C:\Users\nathanw\AppData\Local\Temp\hotzenplotz.exe
C:\Users\nathanw\AppData\Local\Temp\nsf2140.exe
C:\Users\nathanw\AppData\Local\Temp\optprosetup.exe
C:\Users\nathanw\AppData\Local\Temp\SpOrder.dll
C:\Users\nathanw\AppData\Local\Temp\vcredist_x64.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-12 23:30

==================== End Of Log ============================

 

Addition.txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-02-2015
Ran by [removed] at 2015-02-21 13:17:57
Running from C:\Users\[removed]\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\uTorrent) (Version: 3.4.2.36802 - BitTorrent Inc.)
Adobe Reader XI (11.0.10) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Battery Calibration (HKLM-x32\…\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.1402.2101 - Micro-Star International Co., Ltd.)
BioShock Infinite (HKLM-x32\…\Steam App 8870) (Version:  - Irrational Games)
Bitcoin Core (64-bit) (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Bitcoin Core (64-bit)) (Version: 0.9.2 - Bitcoin Core project)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Boot Configure (HKLM\…\{5DEFD958-7239-4FA0-8B4E-3B532D7A14BF}) (Version: 10.014.02075 - Application)
Browser Warden (HKLM-x32\…\39012_Browser Warden) (Version: 1.0 - Gratifying Apps) <==== ATTENTION
BurnRecovery (HKLM-x32\…\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 4.0.1309.301 - )
Chivalry: Medieval Warfare (HKLM-x32\…\Steam App 219640) (Version:  - Torn Banner Studios)
CinPlus-Pro 2.5pV31.01 (HKLM-x32\…\CinPlus-Pro 2.5pV31.01) (Version: 1.36.01.22 - CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Consumer Input (remove only) (HKLM-x32\…\Consumer Input Installer) (Version:  - Compete Inc.) <==== ATTENTION
ConvertAd (HKLM-x32\…\ConvertAd) (Version: 1.0.0.0 - ConvertAd) <==== ATTENTION
Counter-Strike: Global Offensive (HKLM-x32\…\Steam App 730) (Version:  - Valve)
CyberGhost 5 (HKLM\…\CyberGhost 5_is1) (Version:  - CyberGhost S.R.L.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5509.52 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dolphin Deals (HKLM\…\Dolphin Deals) (Version: 2014.08.12.215047 - Dolphin Deals) <==== ATTENTION
download-free-soft bundle uninstaller (HKLM-x32\…\download-free-soft bundle uninstaller) (Version: 2.0.1.0 - download-free-soft)
Dragon Gaming Center (HKLM-x32\…\InstallShield_{965B16C7-0778-4C45-B7D1-83A59E6FBBCB}) (Version: 1.0.1403.0501 - Micro-Star International Co., Ltd.)
Dragon Gaming Center (x32 Version: 1.0.1403.0501 - Micro-Star International Co., Ltd.) Hidden
Driver Support (HKLM-x32\…\{597FB4A5-DD86-4316-A410-7E8074CC2CCE}) (Version: 9.1.4.4 - PC Drivers Headquarters, LP)
ETDWare PS/2-X64 11.13.6.2_WHQL (HKLM\…\Elantech) (Version: 11.13.6.2 - ELAN Microelectronic Corp.)
Extended Update (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\UpdaterEX) (Version:  - Extended Update) <==== ATTENTION
FlacSquisher 1.3.4 (HKLM-x32\…\FlacSquisher) (Version: 1.3.4 - FlacSquisher)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galeria de Fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Gameo (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Gameo) (Version: 0.10.5 - Fried Cookie Software) <==== ATTENTION!
GamesDesktop 025.163 (HKLM-x32\…\gmsd_us_163_is1) (Version:  - GAMESDESKTOP) <==== ATTENTION
GamesDesktop 025.165 (HKLM-x32\…\gmsd_us_165_is1) (Version:  - GAMESDESKTOP) <==== ATTENTION
GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 40.0.2214.94 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
GU Player (remove only) (HKLM-x32\…\GU Player) (Version:  - )
Hitman: Absolution (HKLM-x32\…\Steam App 203140) (Version:  - IO Interactive)
IGS (HKLM-x32\…\IGS) (Version:  - ) <==== ATTENTION!
igsc (HKLM-x32\…\igsc) (Version: 1.0.0.0 - igs) <==== ATTENTION!
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\…\{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}) (Version: 1.1.0.36960 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 17.0.1405.3) (HKLM\…\{302600C1-6BDF-4FD1-1312-148929CC1385}) (Version: 17.0.1312.0414 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.2.1000 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{105fa5c4-72e1-41f2-a82c-884d8aa4b381}) (Version: 16.6.0 - Intel Corporation)
Intelli Term 1.10.0.8 (HKLM-x32\…\IntelliTerm_1.10.0.8) (Version: 1.10.0.8 - Intelli Term)
iTunes (HKLM\…\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Just Cause 2 (HKLM-x32\…\Steam App 8190) (Version:  - Avalanche Studios)
Just Cause 2: Multiplayer Mod (HKLM-x32\…\Steam App 259080) (Version:  - Avalanche Studios)
KB9X Radio Switch Driver (HKLM\…\5AADE1068CF70DD983F763B20CF2CAAB72883915) (Version: 1.1.0.0 - ENE TECHNOLOGY INC.)
K-Lite Codec Pack 10.6.5 Basic (HKLM-x32\…\KLiteCodecPack_is1) (Version: 10.6.5 - )
Left 4 Dead 2 (HKLM-x32\…\Steam App 550) (Version:  - Valve)
MAGIX MX Suite (HKLM-x32\…\MAGIX_{43136332-880B-458A-966C-900C18752B66}) (Version: 1.13.0.121 - MAGIX AG)
MAGIX MX Suite (Version: 1.13.0.121 - MAGIX AG) Hidden
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\…\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
Microsoft Office 365 - en-us (HKLM\…\O365HomePremRetail - en-us) (Version: 15.0.4675.1003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 35.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla)
MSI Remind Manager (HKLM-x32\…\InstallShield_{3E23F267-3E35-40F9-B6BF-BC034D214717}) (Version: 1.0.1404.1101 - Micro-Star International Co., Ltd.)
MSI Remind Manager (x32 Version: 1.0.1404.1101 - Micro-Star International Co., Ltd.) Hidden
MSI Social Media Collection (HKLM-x32\…\{7ADEC426-BE95-48EF-84D4-086BD0F4D331}) (Version: 1.14.2251 - Micro-Star International Co., Ltd.)
MyPC Backup  (HKLM\…\MyPC Backup) (Version:  - JDi Backup Ltd) <==== ATTENTION
News Alert (HKLM-x32\…\BreakingNewsAlert) (Version: 2.7.56 - Mathematical Applications)
Norton Anti-Theft (HKLM-x32\…\NAT) (Version: 1.10.0.9 - Symantec Corporation)
Norton Online Backup (HKLM-x32\…\{652C1CDF-C61D-4525-9348-8C272CC2DB24}) (Version: 2.10.1.3 - Symantec Corporation)
Norton Online Backup (x32 Version: 4.5.0.9 - Symantec Corporation) Hidden
NVIDIA GeForce Experience 1.7.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.7.1 - NVIDIA Corporation)
NVIDIA Graphics Driver 332.35 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.35 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\…\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA Virtual Audio 1.2.9 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.9 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Optimizer Pro v3.2 (HKLM-x32\…\Optimizer Pro_is1) (Version: 3.2.0.3 - PC Utilities Software Limited) <==== ATTENTION
PAYDAY 2 (HKLM-x32\…\Steam App 218620) (Version:  - OVERKILL - a Starbreeze Studio.)
PerforMax Cleaner (HKLM-x32\…\{e37dc69e-51a7-48de-bbc9-d0f300dbe5e0}) (Version: 1.0.0.0 - OneBit IT)
PerforMax Cleaner (x32 Version: 1.0.0.0 - OneBit IT) Hidden
Pirates (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Pirates) (Version:  - Pirates) <==== ATTENTION!
Popcorn Time (HKLM-x32\…\Popcorn Time_is1) (Version: Beta 4.3 - Popcorn Time)
PunkBuster Services (HKLM-x32\…\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
Qualcomm Atheros Bandwidth Control Filter Driver (Version: 1.1.41.1283 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer E220x Drivers (Version: 1.1.41.1283 - Qualcomm Atheros) Hidden
Qualcomm Atheros Network Manager (Version: 1.1.41.1283 - Qualcomm Atheros) Hidden
Qualcomm Atheros Performance Suite (HKLM-x32\…\{68DD86DD-8E02-4921-926B-B358D51EAF3A}) (Version: 1.1.41.1283 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21249 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7179 - Realtek Semiconductor Corp.)
RegClean-Pro (HKLM-x32\…\RegClean-Pro_is1) (Version: 6.21 - Systweak Inc) <==== ATTENTION
Regprocleaner version 2.0 (HKLM-x32\…\{6406DF9F-E9C8-4C2E-AB48-80352BDF5099}_is1) (Version: 2.0 - Regprocleaner)
Remote Desktop Access (VuuPC) (HKLM-x32\…\VOPackage) (Version: 1.0.0.0 - CMI Limited) <==== ATTENTION
Rising Storm/Red Orchestra 2 Multiplayer (HKLM-x32\…\Steam App 35450) (Version:  - Tripwire Interactive)
SafeConnect (HKLM-x32\…\SafeConnect) (Version:  - )
SCM (HKLM\…\{6692DCAF-A445-4C6B-AF31-3DD85FC06FBA}) (Version: 13.014.01026 - Application)
Search Protect (HKLM-x32\…\SearchProtect) (Version: 2.18.20.209 - Search Protect) <==== ATTENTION
SHIELD Streaming (Version: 1.6.53 - NVIDIA Corporation) Hidden
Skype™ 6.21 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
SmartWeb (HKLM-x32\…\SmartWeb) (Version: 8.0.6 - SoftBrain Technologies Ltd.) <==== ATTENTION
Sniper Elite V2 (HKLM-x32\…\Steam App 63380) (Version:  - Rebellion)
Software Updater (HKLM-x32\…\SoftwareUpdater) (Version: 1.0.0.0 - Software Updater Ltd)
Sophos Virus Removal Tool (HKLM-x32\…\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.3 - Sophos Limited)
Sound Blaster Cinema (HKLM-x32\…\{8801CA65-921A-4CCC-9D63-879D1D0BAA97}) (Version: 1.00.05 - Creative Technology Limited)
SpeedChecker (HKLM-x32\…\04B239F6-D435-4A0C-F65E-9F1C99811569) (Version:  - SpeedChecker-software) <==== ATTENTION
Steam (HKLM-x32\…\Steam) (Version:  - Valve Corporation)
SteelSeries Engine (HKLM\…\SteelSeries Engine) (Version: 2.8.417.28061 - SteelSeries)
SteelSeries Engine 3.2.6 (HKLM\…\SteelSeries Engine 3) (Version: 3.2.6 - SteelSeries ApS)
SUPER CHARGER (HKLM-x32\…\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.024 - MSI)
TAP-Windows 9.9.2 (HKLM\…\TAP-Windows) (Version: 9.9.2 - )
TheAnswerFinder (HKLM\…\TheAnswerFinder) (Version: 1.0.7 - TheAnswerFinder)
Unchecky v0.3.6 (HKLM-x32\…\Unchecky) (Version: 0.3.6 - RaMMicHaeL)
Vosteran (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Vosteran) (Version: 31.0.1650.23 - Vosteran) <==== ATTENTION!
Wajam (HKLM-x32\…\Wajam Web Enhancer) (Version: 1.0.6.38 (i1.0) - Wajam) <==== ATTENTION
WinCheck (HKLM-x32\…\wincheck) (Version: 1.0.0.0 - WinCheck) <==== ATTENTION!
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinZip 17.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DD}) (Version: 17.5.10562 - WinZip Computing, S.L. )
WSE_Astromenda (HKLM-x32\…\WSE_Astromenda) (Version:  - WSE_Astromenda) <==== ATTENTION!
WSE_Vosteran (HKLM-x32\…\WSE_Vosteran) (Version:  - WSE_Vosteran) <==== ATTENTION!
XSplit Gamecaster (HKLM-x32\…\{9C3D0D0D-3983-4C18-91EE-C6976D5AA349}) (Version: 1.5.1403.1907 - SplitMediaLabs)
フォト ギャラリー (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
معرض الصور (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
사진 갤러리 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
影像中心 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
照片库 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\nathanw\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points  =========================

10-01-2015 13:20:58 Scheduled Checkpoint
15-01-2015 17:11:02 Windows Update
23-01-2015 16:25:18 Windows Update
27-01-2015 14:22:22 Windows Update
08-02-2015 02:44:12 Windows Update
12-02-2015 22:46:25 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 08:25 - 2015-02-13 13:32 - 00002034 ____A C:\Windows\system32\Drivers\etc\hosts
0.0.0.0         .psf
0.0.0.0         psf
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
0.0.0.0 cdn.appround.biz

There are 6 more lines.


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {01837989-FBD1-4B28-9DB4-B919FD74211D} - System32\Tasks\Driver Support-RTMUpdater => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {0A149050-CB32-4D8F-B30C-F6EBB0DD48B7} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {0D149001-107B-426A-B29D-652D7F68E53E} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-08-29] () <==== ATTENTION
Task: {1148FEDC-2318-4CE0-B90A-1D8A08101811} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-11-04] (Microsoft Corporation)
Task: {21360565-4733-4D63-93D2-C480E8948889} - System32\Tasks\gameo_update => C:\Users\nathanw\AppData\Roaming\Gameo\gameo.exe [2015-01-18] ()
Task: {221BCF22-52D9-40FB-80E7-59972D7D690A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-25] (Google Inc.)
Task: {27902362-EB83-4D3D-A103-522639358B67} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {2C4C7E11-034E-4C87-A73F-5BAA2A50817F} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-7 => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-7.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {33751216-1BFC-4DBC-8F1C-5FBE754275FD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {33D088CC-A6F3-49A3-B1E2-9F5A631F3C01} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-11-11] (Microsoft Corporation)
Task: {3AA138B5-2D43-4CCF-B530-AA2BE0364E46} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {3CCC02E7-A999-41B8-B111-65B81F7FB907} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-08-29] () <==== ATTENTION
Task: {3CEA15DE-E282-446C-93E4-12AAECAA30E8} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-01-31] (globalUpdate) <==== ATTENTION
Task: {42FF6DEB-DB25-445D-ACE8-946FC119E710} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7 => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {4B2A101F-F713-4145-AF2D-14B52C40F02C} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-6 => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-6.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {5B3FA51C-0D53-486D-8077-2D67E97B2BE8} - System32\Tasks\Optimum_LogOn => C:\Program Files (x86)\Optimum PC Boost\OptimumPCBoost.exe <==== ATTENTION
Task: {60B406F7-0FF1-4EAD-904D-A915A8D63734} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro 3.38\OptProLauncher.exe [2015-01-29] (PC Utilities Software Limited) <==== ATTENTION
Task: {6AF3C44A-B687-4298-BA15-C041A9EE5D7C} - System32\Tasks\ConsumerInputUpdateTaskMachineUA => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2015-02-03] (ConsumerInput) <==== ATTENTION
Task: {6B36B481-0B04-4132-8F67-A468A957B017} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6 => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {6BB4F7C5-4D82-4704-873D-60122B8F9C8E} - System32\Tasks\ConsumerInputUpdateTaskMachineCore => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2015-02-03] (ConsumerInput) <==== ATTENTION
Task: {6EC4FC81-6C4A-4002-AC2A-F0DA1CBBC6E5} - System32\Tasks\SpeedChecker Update => C:\Program Files (x86)\ver0SpeedChecker\s5SpeedCheckerI55.exe [2015-01-31] () <==== ATTENTION
Task: {76E2425C-A76D-474B-849F-A0559AF55CEC} - System32\Tasks\MSI_Reminder => C:\Program Files (x86)\MSI\MSI Remind Manager\MSI Reminder.exe [2014-04-09] ()
Task: {791B7F10-DCBF-4F2A-B026-735AF13704B9} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5_user => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-5.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {7A748A39-6A0C-4183-8156-DDAE70169665} - System32\Tasks\MSI_Dragon Gaming Center => C:\Program Files (x86)\MSI\Dragon Gaming Center\mDispatch.exe [2014-01-23] (TODO: <公司名稱>)
Task: {7A9873FE-94CC-4F5E-BC45-EB736D672BF9} - System32\Tasks\Optimum_Daily => C:\Program Files (x86)\Optimum PC Boost\OptimumPCBoost.exe <==== ATTENTION
Task: {7CAB2EFE-2186-46C1-A3CE-97EF4BD8545A} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\SymErr.exe [2013-08-01] (Symantec Corporation)
Task: {873D1A12-5B57-4F11-B9E1-B6F4D9E7B361} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5 => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-5.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {88A5AFC4-DC21-4E20-89E3-98A157FBEAC1} - System32\Tasks\Vosteran dota => Wscript.exe "C:\ProgramData\{A6374EF4-F6B5-9F72-4733-EFF097B13C7E}\1.9.1.1\fiber.js" "433a2f50726f6772616d446174612f7b41363337344546342d463642352d394637322d343733332d4546463039374231334337457d2f312e392e312e312f646f74612e646c6c" "687474703a2f2f73616f2e766f7367722e636f6d2f" "–IsErIk" <==== ATTENTION
Task: {890E34F8-EA5D-4682-9E70-A6DF41CD48DC} - System32\Tasks\Driver Support-RTMRules => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {919C7BC8-ECD6-43B9-992C-F773CD90DD4C} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\SymErr.exe [2013-08-01] (Symantec Corporation)
Task: {91DE0F2C-1E27-4DF4-8DE1-7610BDC96319} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-10_user => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-10.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {96E4EE60-C87A-4CCE-BB71-262D540089FD} - System32\Tasks\WSE_Vosteran => C:\Users\nathanw\AppData\Roaming\WSE_Vosteran\UpdateProc\UpdateTask.exe [2015-02-01] () <==== ATTENTION
Task: {A794D80B-4551-461A-B1A4-B6F820D9221E} - System32\Tasks\CIMT_daily_S-1-5-21-3104748373-4178966826-1034322177-1002 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe [2015-01-19] () <==== ATTENTION
Task: {B3F4C5ED-7D51-4CE2-8982-ACEDA14BB5D8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-02-12] (Microsoft Corporation)
Task: {B64F17F9-AF2D-4B1F-A85F-F7ACAE2354C2} - System32\Tasks\GPUP => C:\Program Files (x86)\GetPrivate\gpup.exe [2014-10-03] () <==== ATTENTION
Task: {BF34D6C7-3234-4712-B542-FA825002455A} - System32\Tasks\Driver Support-RTMScan => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {C7662A70-7764-4CF7-B866-F5B2306DC242} - System32\Tasks\Jelbrus Secure Web Task => C:\Program Files (x86)\Jelbrus Secure Web\jswtask.exe [2014-11-12] (Jelbrus)
Task: {CFCA9BE6-17E8-41A4-96E5-411ADBABFB4C} - System32\Tasks\CIMT_S-1-5-21-3104748373-4178966826-1034322177-1002 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe [2015-01-19] () <==== ATTENTION
Task: {D069AC4D-3961-45D9-91A7-663AD5EF9DBF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-25] (Google Inc.)
Task: {D2099157-2EFE-4715-893A-18FAC41D294D} - System32\Tasks\RPC => C:\Program Files (x86)\Regprocleaner\Regprocleaner.exe [2015-01-22] ()
Task: {E3D2EB48-2F88-4B4F-906D-C0D87A7CEA6D} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-01-31] (globalUpdate) <==== ATTENTION
Task: {E755D892-7CF4-425C-83B9-0E69CE2FF3A1} - System32\Tasks\UpdaterEX => C:\Users\nathanw\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {FA114C47-16F5-4EA9-BA09-99233431A606} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-08-29] () <==== ATTENTION
Task: {FDB10BD5-63D5-499D-8F5B-9F1C39533065} - System32\Tasks\bench-S-1-5-21-3104748373-4178966826-1034322177-1002 => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: {FF72D8AC-2CB8-4CDA-8C41-73EC2C1FD75D} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-3104748373-4178966826-1034322177-1002 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-10_user.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5_user.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-6.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-7.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-S-1-5-21-3104748373-4178966826-1034322177-1002.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_daily_S-1-5-21-3104748373-4178966826-1034322177-1002.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_S-1-5-21-3104748373-4178966826-1034322177-1002.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\SpeedChecker Update.job => C:\Program Files (x86)\ver0SpeedChecker\s5SpeedCheckerI55.exe <==== ATTENTION
Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\nathanw\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE/CheckNathan\nathanw0Ò¥< <==== ATTENTION
Task: C:\Windows\Tasks\Vosteran dota.job => Wscript.exe C:\ProgramData\{A6374EF4-F6B5-9F72-4733-EFF097B13C7E}\1.9.1.1\fiber.js <==== ATTENTION
Task: C:\Windows\Tasks\WSE_Vosteran.job => C:\Users\nathanw\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE/CheckNathan\nathanw0Ö    ¥< <==== ATTENTION

==================== Loaded Modules (whitelisted) ==============

2014-11-21 23:40 - 2014-09-23 08:36 - 08897696 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-02-06 14:51 - 2015-01-23 05:37 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\OptimizerMonitor => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\nathanw\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
DNS Servers: [removed] - [removed]

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-3104748373-4178966826-1034322177-500 - Administrator - Disabled)
Guest (S-1-5-21-3104748373-4178966826-1034322177-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3104748373-4178966826-1034322177-1004 - Limited - Enabled)
nathanw (S-1-5-21-3104748373-4178966826-1034322177-1002 - Administrator - Enabled) => C:\Users\nathanw
UpdatusUser (S-1-5-21-3104748373-4178966826-1034322177-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Faulty Device Manager Devices =============

Name: Radio Switch Device
Description: Radio Switch Device
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: ENE TECHNOLOGY INC.
Service: mshidumdf
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/15/2015 07:40:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Explorer.EXE, version: 6.3.9600.17284, time stamp: 0x53f816dc
Faulting module name: ntdll.dll, version: 6.3.9600.17278, time stamp: 0x53eebd22
Exception code: 0xc0000005
Fault offset: 0x0000000000038299
Faulting process id: 0x420
Faulting application start time: 0xExplorer.EXE0
Faulting application path: Explorer.EXE1
Faulting module path: Explorer.EXE2
Report Id: Explorer.EXE3
Faulting package full name: Explorer.EXE4
Faulting package-relative application ID: Explorer.EXE5

Error: (02/13/2015 01:33:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program s5SpeedCheckerI55.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1314

Start Time: 01d047bb640ba655

Termination Time: 0

Application Path: C:\Program Files (x86)\ver0SpeedChecker\s5SpeedCheckerI55.exe

Report Id: b89470e5-b3ae-11e4-8298-303a6412db7f

Faulting package full name:

Faulting package-relative application ID:

Error: (02/12/2015 11:18:54 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcFailed to kill already running streamer. [6]

Error: (02/12/2015 11:18:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: nvstreamsvc.exe, version: 1.6.53.0, time stamp: 0x527cf301
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17278, time stamp: 0x53eebd22
Exception code: 0xc0000142
Fault offset: 0x00000000000ec0b4
Faulting process id: 0x1ed0
Faulting application start time: 0xnvstreamsvc.exe0
Faulting application path: nvstreamsvc.exe1
Faulting module path: nvstreamsvc.exe2
Report Id: nvstreamsvc.exe3
Faulting package full name: nvstreamsvc.exe4
Faulting package-relative application ID: nvstreamsvc.exe5

Error: (02/12/2015 10:54:30 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8

Error: (02/12/2015 03:18:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: gpup.exe, version: 0.0.0.0, time stamp: 0x541ffff6
Faulting module name: tasks.dll, version: 0.0.0.0, time stamp: 0x541fffca
Exception code: 0xc0000005
Fault offset: 0x000010ad
Faulting process id: 0x92c4
Faulting application start time: 0xgpup.exe0
Faulting application path: gpup.exe1
Faulting module path: gpup.exe2
Report Id: gpup.exe3
Faulting package full name: gpup.exe4
Faulting package-relative application ID: gpup.exe5

Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8719

Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8719

Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/11/2015 11:17:48 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7625


System errors:
=============
Error: (02/21/2015 01:18:05 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (02/21/2015 01:18:05 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (02/21/2015 01:18:04 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (02/21/2015 01:18:04 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (02/21/2015 01:18:00 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (02/21/2015 01:18:00 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (02/21/2015 01:17:58 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (02/21/2015 01:17:58 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (02/21/2015 01:17:55 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

Error: (02/21/2015 01:17:55 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}


Microsoft Office Sessions:
=========================
Error: (02/15/2015 07:40:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.3.9600.1728453f816dcntdll.dll6.3.9600.1727853eebd22c0000005000000000003829942001d04971ca78ecf0C:\Windows\Explorer.EXEC:\Windows\SYSTEM32\ntdll.dll6fe2a889-b574-11e4-82a0-97886234adad

Error: (02/13/2015 01:33:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: s5SpeedCheckerI55.exe0.0.0.0131401d047bb640ba6550C:\Program Files (x86)\ver0SpeedChecker\s5SpeedCheckerI55.exeb89470e5-b3ae-11e4-8298-303a6412db7f

Error: (02/12/2015 11:18:54 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcFailed to kill already running streamer. [6]

Error: (02/12/2015 11:18:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nvstreamsvc.exe1.6.53.0527cf301KERNELBASE.dll6.3.9600.1727853eebd22c000014200000000000ec0b41ed001d047442d1d2ef2C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeKERNELBASE.dll6ae3fbab-b337-11e4-8294-303a6412db7f

Error: (02/12/2015 10:54:30 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8

Error: (02/12/2015 03:18:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: gpup.exe0.0.0.0541ffff6tasks.dll0.0.0.0541fffcac0000005000010ad92c401d04700c290ddc7C:\Program Files (x86)\GetPrivate\gpup.exeC:\Program Files (x86)\GetPrivate\tasks.dll4ab2ba4e-b2f4-11e4-8291-303a6412db7f

Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8719

Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8719

Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/11/2015 11:17:48 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7625


CodeIntegrity Errors:
===================================
  Date: 2015-02-12 23:32:20.312
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-02-12 19:28:05.730
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-02-12 19:28:05.623
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-02-12 19:28:05.515
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-02-12 19:28:04.571
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-02-12 19:28:04.408
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-02-12 19:28:04.262
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-02-12 19:28:04.118
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-02-12 19:28:03.973
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-02-12 19:28:03.785
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-4710HQ CPU @ 2.50GHz
Percentage of memory in use: 28%
Total physical RAM: 8111.19 MB
Available physical RAM: 5836.1 MB
Total Pagefile: 10287.19 MB
Available Pagefile: 8125.87 MB
Total Virtual: 131072 MB
Available Virtual: 131071.83 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:580.74 GB) (Free:378.85 GB) NTFS
Drive d: (Data) (Fixed) (Total:334.57 GB) (Free:293.13 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: BF003083)

Partition: GPT Partition Type.

==================== End Of Log ============================

:welcome:

 

You have an awful lot going on  :(

 

Lets run a few tools to start the clean up and go from there

 

 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
Do not click on any links in the top Advertisment.
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
    [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  to your desktop. 
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
      •  
        [external image: MBAMDashboard_zpsddef9b5f.gif]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished and the log pops up…select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • I thought it looked bad too :(

           

          If it is any help to you, I am booting into safe mode. I don't know if that will alter the results of these scans.

           

          MalewareBytes also was unable to update the database for some reason.

           

          When I looked for the text file for AdwCleaner there were two files, so I figured it was best to include both just to be safe.

           

          AdwCleaner[R0]

           

          # AdwCleaner v4.111 - Logfile created 21/02/2015 at 22:46:16
          # Updated 18/02/2015 by Xplode
          # Database : 2015-02-18.3 [Server]
          # Operating system : Windows 8.1  (x64)
          # Username : nathanw - NATHAN
          # Running from : C:\Users\nathanw\Desktop\AdwCleaner.exe
          # Option : Scan

          ***** [ Services ] *****

          Service Found : CltMngSvc
          Service Found : globalUpdate
          Service Found : globalUpdatem
          Service Found : SPPD
          Service Found : Wajam Web Enhancer
          Service Found : consumerinput_update
          Service Found : consumerinput_updatem
          Service Found : serverca
          Service Found : serversu
          Service Found : OptimizerMonitor
          Service Found : serverig
          Service Found : itnfd_1_10_0_8
          Service Found : itsvc_1.10.0.8

          ***** [ Files / Folders ] *****

          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.select-n-go00.select-n-go.com_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.select-n-go00.select-n-go.com_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.best-deals-products.com_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.best-deals-products.com_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.plyrics.com_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.plyrics.com_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovi.com_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovi.com_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wajam.com_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wajam.com_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_inst.shoppingate.info_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_inst.shoppingate.info_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
          File Found : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
          File Found : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\gameo.lnk
          File Found : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
          File Found : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OptimizerProInstaller.lnk
          File Found : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
          File Found : C:\Users\nathanw\AppData\Roaming\Mozilla\Firefox\Profiles\frc79gxm.default\user.js
          File Found : C:\Users\nathanw\Desktop\MyPC Backup.lnk
          File Found : C:\Users\nathanw\Desktop\Optimizer Pro.lnk
          File Found : C:\Users\nathanw\Desktop\Sync Folder.lnk
          File Found : C:\Windows\patsearch.bin
          File Found : C:\Windows\System32\drivers\Msft_Kernel_webinstrNHKT_01009.Wdf
          File Found : C:\Windows\System32\OptimizerMonitorOff.ini
          File Found : C:\Windows\System32\roboot64.exe
          File Found : C:\Windows\SysWOW64\OptimizerMonitor.dll
          File Found : C:\Windows\SysWOW64\OptimizerMonitor.ini
          File Found : C:\Windows\SysWOW64\OptimizerMonitorOff.ini
          Folder Found : C:\BreakingNewsAlert
          Folder Found : C:\Program Files (x86)\Browser Warden
          Folder Found : C:\Program Files (x86)\Consumer Input
          Folder Found : C:\Program Files (x86)\Dolphin Deals
          Folder Found : C:\Program Files (x86)\Driver Support
          Folder Found : C:\Program Files (x86)\GetPrivate
          Folder Found : C:\Program Files (x86)\globalUpdate
          Folder Found : C:\Program Files (x86)\gmsd_us_163
          Folder Found : C:\Program Files (x86)\gmsd_us_165
          Folder Found : C:\Program Files (x86)\GU Player
          Folder Found : C:\Program Files (x86)\igs
          Folder Found : C:\Program Files (x86)\IntelliTerm_1.10.0.8
          Folder Found : C:\Program Files (x86)\MyPC Backup
          Folder Found : C:\Program Files (x86)\Optimizer Pro 3.38
          Folder Found : C:\Program Files (x86)\RCP
          Folder Found : C:\Program Files (x86)\SearchProtect
          Folder Found : C:\Program Files (x86)\ver0SpeedChecker
          Folder Found : C:\Program Files (x86)\wse_astromenda
          Folder Found : C:\Program Files (x86)\WSE_Vosteran
          Folder Found : C:\Program Files\Wajam Web Enhancer
          Folder Found : C:\ProgramData\BreakingNewsAlert
          Folder Found : C:\ProgramData\Browser
          Folder Found : C:\ProgramData\Driver Support
          Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Support
          Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
          Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
          Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
          Folder Found : C:\Users\nathanw\AppData\Local\Astromenda
          Folder Found : C:\Users\nathanw\AppData\Local\BreakingNewsAlert
          Folder Found : C:\Users\nathanw\AppData\Local\Consumer Input
          Folder Found : C:\Users\nathanw\AppData\Local\ConvertAd
          Folder Found : C:\Users\nathanw\AppData\Local\CrashRpt
          Folder Found : C:\Users\nathanw\AppData\Local\Gameo
          Folder Found : C:\Users\nathanw\AppData\Local\globalUpdate
          Folder Found : C:\Users\nathanw\AppData\Local\gmsd_us_163
          Folder Found : C:\Users\nathanw\AppData\Local\gmsd_us_165
          Folder Found : C:\Users\nathanw\AppData\Local\igs
          Folder Found : C:\Users\nathanw\AppData\Local\SearchProtect
          Folder Found : C:\Users\nathanw\AppData\Local\SmartWeb
          Folder Found : C:\Users\nathanw\AppData\Local\Temp\AdvanceElite
          Folder Found : C:\Users\nathanw\AppData\Local\Temp\Dolphin Deals
          Folder Found : C:\Users\nathanw\AppData\Local\Vosteran
          Folder Found : C:\Users\nathanw\AppData\Local\wincheck
          Folder Found : C:\Users\nathanw\AppData\LocalLow\SmartWeb
          Folder Found : C:\Users\nathanw\AppData\Roaming\Astromenda
          Folder Found : C:\Users\nathanw\AppData\Roaming\Gameo
          Folder Found : C:\Users\nathanw\AppData\Roaming\GetPrivate
          Folder Found : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Warden
          Folder Found : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo
          Folder Found : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GU Player
          Folder Found : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
          Folder Found : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
          Folder Found : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vosteran
          Folder Found : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer
          Folder Found : C:\Users\nathanw\AppData\Roaming\Optimizer Pro
          Folder Found : C:\Users\nathanw\AppData\Roaming\SoftwareUpdater
          Folder Found : C:\Users\nathanw\AppData\Roaming\Systweak
          Folder Found : C:\Users\nathanw\AppData\Roaming\TheAnswerFinder
          Folder Found : C:\Users\nathanw\AppData\Roaming\UpdaterEX
          Folder Found : C:\Users\nathanw\AppData\Roaming\VOPackage
          Folder Found : C:\Users\nathanw\AppData\Roaming\wse_astromenda
          Folder Found : C:\Users\nathanw\AppData\Roaming\WSE_Vosteran
          Folder Found : C:\Users\nathanw\Documents\Optimizer Pro

          ***** [ Scheduled tasks ] *****

          Task Found : Driver Support-RTMRules
          Task Found : Driver Support-RTMScan
          Task Found : Driver Support-RTMUpdater
          Task Found : globalUpdateUpdateTaskMachineCore
          Task Found : globalUpdateUpdateTaskMachineUA
          Task Found : Optimizer Pro Schedule
          Task Found : RegClean Pro
          Task Found : RegClean Pro_DEFAULT
          Task Found : RegClean Pro_UPDATES
          Task Found : SpeedChecker Update
          Task Found : UpdaterEX
          Task Found : Optimum_Daily
          Task Found : Optimum_LogOn
          Task Found : WSE_Vosteran
          Task Found : gameo_update
          Task Found : ConsumerInputUpdateTaskMachineCore
          Task Found : ConsumerInputUpdateTaskMachineUA
          Task Found : Pirates WW1
          Task Found : Pirates WW2
          Task Found : Pirates W1
          Task Found : Pirates W2
          Task Found : 846bb3df-d697-4cbc-b53f-963ee89ca784-1-6
          Task Found : 846bb3df-d697-4cbc-b53f-963ee89ca784-1-7
          Task Found : 846bb3df-d697-4cbc-b53f-963ee89ca784-10_user
          Task Found : 846bb3df-d697-4cbc-b53f-963ee89ca784-5
          Task Found : 846bb3df-d697-4cbc-b53f-963ee89ca784-5_user
          Task Found : 846bb3df-d697-4cbc-b53f-963ee89ca784-6
          Task Found : 846bb3df-d697-4cbc-b53f-963ee89ca784-7
          Task Found : bench-S-1-5-21-3104748373-4178966826-1034322177-1002
          Task Found : UpdaterEX

          ***** [ Shortcuts ] *****

          ***** [ Registry ] *****

          Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
          Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll
          Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
          Key Found : HKCU\Software\AppDataLow\Software\Compete
          Key Found : HKCU\Software\AppDataLow\Software\DynConIE
          Key Found : HKCU\Software\AppDataLow\Software\SmartWeb
          Key Found : HKCU\Software\BRS
          Key Found : HKCU\Software\Compete
          Key Found : HKCU\Software\Dolphin Deals
          Key Found : HKCU\Software\DriverSupport
          Key Found : HKCU\Software\gameo
          Key Found : HKCU\Software\GlobalUpdate
          Key Found : HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
          Key Found : HKCU\Software\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce
          Key Found : HKCU\Software\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae
          Key Found : HKCU\Software\IM
          Key Found : HKCU\Software\InstallCore
          Key Found : HKCU\Software\InstalledBrowserExtensions
          Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
          Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\trovi.com
          Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
          Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.trovi.com
          Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
          Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
          Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AEAA03CB-A063-46DD-8F9D-9C73CB30B790}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\gameo
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\UpdaterEX
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran
          Key Found : HKCU\Software\Optimizer Pro
          Key Found : HKCU\Software\Proxy
          Key Found : HKCU\Software\SweetIM
          Key Found : HKCU\Software\systweak
          Key Found : HKCU\Software\Tutorials
          Key Found : HKCU\Software\TutoTag
          Key Found : HKCU\Software\UpdaterEX
          Key Found : HKCU\Software\Vosteran
          Key Found : HKCU\Software\Vosteran Browser
          Key Found : HKCU\Software\Wajam
          Key Found : HKCU\Software\WSE_Astromenda
          Key Found : HKCU\Software\WSE_Vosteran
          Key Found : [x64] HKCU\Software\BRS
          Key Found : [x64] HKCU\Software\Compete
          Key Found : [x64] HKCU\Software\Dolphin Deals
          Key Found : [x64] HKCU\Software\DriverSupport
          Key Found : [x64] HKCU\Software\gameo
          Key Found : [x64] HKCU\Software\GlobalUpdate
          Key Found : [x64] HKCU\Software\IM
          Key Found : [x64] HKCU\Software\InstallCore
          Key Found : [x64] HKCU\Software\InstalledBrowserExtensions
          Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
          Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
          Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
          Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
          Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AEAA03CB-A063-46DD-8F9D-9C73CB30B790}
          Key Found : [x64] HKCU\Software\Optimizer Pro
          Key Found : [x64] HKCU\Software\Proxy
          Key Found : [x64] HKCU\Software\SweetIM
          Key Found : [x64] HKCU\Software\systweak
          Key Found : [x64] HKCU\Software\Tutorials
          Key Found : [x64] HKCU\Software\TutoTag
          Key Found : [x64] HKCU\Software\UpdaterEX
          Key Found : [x64] HKCU\Software\Vosteran
          Key Found : [x64] HKCU\Software\Vosteran Browser
          Key Found : [x64] HKCU\Software\Wajam
          Key Found : [x64] HKCU\Software\WSE_Astromenda
          Key Found : [x64] HKCU\Software\WSE_Vosteran
          Key Found : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
          Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
          Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
          Key Found : HKLM\SOFTWARE\AdvertisingSupport
          Key Found : HKLM\SOFTWARE\Bench
          Key Found : HKLM\SOFTWARE\Browser Warden
          Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
          Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
          Key Found : HKLM\SOFTWARE\Classes\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
          Key Found : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
          Key Found : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
          Key Found : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
          Key Found : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
          Key Found : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor
          Key Found : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor.1
          Key Found : HKLM\SOFTWARE\Classes\dcabho.Dca
          Key Found : HKLM\SOFTWARE\Classes\dcabho.Dca.1
          Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
          Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
          Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
          Key Found : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
          Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
          Key Found : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
          Key Found : HKLM\SOFTWARE\CompeteInc
          Key Found : HKLM\SOFTWARE\Dolphin Deals
          Key Found : HKLM\SOFTWARE\GAMESDESKTOP
          Key Found : HKLM\SOFTWARE\GlobalUpdate
          Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
          Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce
          Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae
          Key Found : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.bench.nmhost
          Key Found : HKLM\SOFTWARE\InstallCore
          Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{597FB4A5-DD86-4316-A410-7E8074CC2CCE}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\04B239F6-D435-4A0C-F65E-9F1C99811569
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\39012_Browser Warden
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ASPackage
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BreakingNewsAlert
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Consumer Input Installer
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ConvertAd
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_us_163_is1
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_us_165_is1
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IGS
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\igsc
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean-Pro_is1
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartWeb
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam Web Enhancer
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wincheck
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WSE_Astromenda
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WSE_Vosteran
          Key Found : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
          Key Found : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
          Key Found : HKLM\SOFTWARE\Proxy
          Key Found : HKLM\SOFTWARE\SearchProtect
          Key Found : HKLM\SOFTWARE\SPPDCOM
          Key Found : HKLM\SOFTWARE\SweetIM
          Key Found : HKLM\SOFTWARE\systweak
          Key Found : HKLM\SOFTWARE\Tutorials
          Key Found : HKLM\SOFTWARE\Wajam Web Enhancer
          Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
          Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
          Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
          Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
          Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
          Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
          Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
          Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
          Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
          Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
          Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
          Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
          Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
          Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
          Key Found : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce
          Key Found : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae
          Key Found : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
          Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
          Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
          Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AEAA03CB-A063-46DD-8F9D-9C73CB30B790}
          Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dolphin Deals
          Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
          Key Found : [x64] HKLM\SOFTWARE\Wajam Web Enhancer
          Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Gameo]
          Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Optimizer Pro]
          Value Found : HKCU\Software\Mozilla\Firefox\Extensions [{57FC8B03-13E5-70AC-4016-0DB57BA53BDF}]
          Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Bench Communicator Watcher]
          Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Bench Settings Cleaner]
          Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BService]
          Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BService64]
          Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_us_163]
          Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_us_165]
          Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SmartWeb]
          Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Wd]
          Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [WinCheck]

          ***** [ Web browsers ] *****

          -\\ Internet Explorer v11.0.9600.17416

          -\\ Mozilla Firefox v35.0.1 (x86 en-US)

          -\\ Google Chrome v40.0.2214.94

          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource;=49&ctid;=CT3072253
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://astromenda.com/results.php?f=4&q;={searchTerms}&a;=ast_dnldstr_14_40_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtDtDyCtN1L2XzutAtFyDtFtCtFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FtA0DtD0EtB0BtG0BtC0B0FtG0AyDtC0AtGyD0E0EzztGyE0F0A0DzzyD0BzytA0FzzyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0DyCyEyE0AyEzztG0CyBtCzytGyE0D0F0BtGzytD0AyDtGtD0D0FyC0Ezzzy0DtA0FzzyE2Q&cr;=1440908205&ir;=
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid;=CT3326582&octid;=EB_ORIGINAL_CTID&ISID;=M7F3484E9-DA35-489B-938C-F37B8655B977&SearchSource;=58&CUI;=&UM;=6&UP;=SP96CAD07F-DE2B-40FD-A8F7-F76C24BCEE5C&q;={searchTerms}&SSPV;=
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
          *************************

          AdwCleaner[R0].txt - [31376 bytes] - [21/02/2015 22:46:16]

          ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [31436 bytes] ##########

           

          AdwCleaner[S0]

           

           

          # AdwCleaner v4.111 - Logfile created 21/02/2015 at 22:49:09
          # Updated 18/02/2015 by Xplode
          # Database : 2015-02-18.3 [Server]
          # Operating system : Windows 8.1  (x64)
          # Username : nathanw - NATHAN
          # Running from : C:\Users\nathanw\Desktop\AdwCleaner.exe
          # Option : Cleaning

          ***** [ Services ] *****

          [#] Service Deleted : CltMngSvc
          [#] Service Deleted : globalUpdate
          [#] Service Deleted : globalUpdatem
          [#] Service Deleted : SPPD
          [#] Service Deleted : Wajam Web Enhancer
          [#] Service Deleted : consumerinput_update
          [#] Service Deleted : consumerinput_updatem
          [#] Service Deleted : serverca
          [#] Service Deleted : serversu
          Service Deleted : OptimizerMonitor
          [#] Service Deleted : serverig
          [#] Service Deleted : itnfd_1_10_0_8
          [#] Service Deleted : itsvc_1.10.0.8

          ***** [ Files / Folders ] *****

          Folder Deleted : C:\BreakingNewsAlert
          Folder Deleted : C:\ProgramData\Browser
          Folder Deleted : C:\ProgramData\Driver Support
          Folder Deleted : C:\ProgramData\BreakingNewsAlert
          Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
          Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Support
          Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
          Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
          Folder Deleted : C:\Program Files (x86)\GetPrivate
          Folder Deleted : C:\Program Files (x86)\globalUpdate
          Folder Deleted : C:\Program Files (x86)\MyPC Backup
          Folder Deleted : C:\Program Files (x86)\SearchProtect
          Folder Deleted : C:\Program Files (x86)\wse_astromenda
          Folder Deleted : C:\Program Files (x86)\Driver Support
          Folder Deleted : C:\Program Files (x86)\RCP
          Folder Deleted : C:\Program Files (x86)\Browser Warden
          Folder Deleted : C:\Program Files (x86)\Consumer Input
          Folder Deleted : C:\Program Files (x86)\WSE_Vosteran
          Folder Deleted : C:\Program Files (x86)\Dolphin Deals
          Folder Deleted : C:\Program Files (x86)\GU Player
          Folder Deleted : C:\Program Files (x86)\igs
          Folder Deleted : C:\Program Files (x86)\IntelliTerm_1.10.0.8
          Folder Deleted : C:\Program Files (x86)\Optimizer Pro 3.38
          Folder Deleted : C:\Program Files (x86)\ver0SpeedChecker
          Folder Deleted : C:\Program Files (x86)\gmsd_us_163
          Folder Deleted : C:\Program Files (x86)\gmsd_us_165
          Folder Deleted : C:\Users\nathanw\AppData\Local\Temp\AdvanceElite
          Folder Deleted : C:\Users\nathanw\AppData\Local\Temp\Dolphin Deals
          Folder Deleted : C:\Program Files\Wajam Web Enhancer
          Folder Deleted : C:\Users\nathanw\AppData\Local\Astromenda
          Folder Deleted : C:\Users\nathanw\AppData\Local\ConvertAd
          Folder Deleted : C:\Users\nathanw\AppData\Local\Gameo
          Folder Deleted : C:\Users\nathanw\AppData\Local\globalUpdate
          Folder Deleted : C:\Users\nathanw\AppData\Local\SearchProtect
          Folder Deleted : C:\Users\nathanw\AppData\Local\CrashRpt
          Folder Deleted : C:\Users\nathanw\AppData\Local\SmartWeb
          Folder Deleted : C:\Users\nathanw\AppData\Local\Consumer Input
          Folder Deleted : C:\Users\nathanw\AppData\Local\Vosteran
          Folder Deleted : C:\Users\nathanw\AppData\Local\BreakingNewsAlert
          Folder Deleted : C:\Users\nathanw\AppData\Local\wincheck
          Folder Deleted : C:\Users\nathanw\AppData\Local\igs
          Folder Deleted : C:\Users\nathanw\AppData\Local\gmsd_us_163
          Folder Deleted : C:\Users\nathanw\AppData\Local\gmsd_us_165
          Folder Deleted : C:\Users\nathanw\AppData\LocalLow\SmartWeb
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\Astromenda
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\Gameo
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\GetPrivate
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\Optimizer Pro
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\SoftwareUpdater
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\Systweak
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\UpdaterEX
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\VOPackage
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\wse_astromenda
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\WSE_Vosteran
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\TheAnswerFinder
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Warden
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vosteran
          Folder Deleted : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GU Player
          Folder Deleted : C:\Users\nathanw\Documents\Optimizer Pro
          File Deleted : C:\Windows\patsearch.bin
          File Deleted : C:\Windows\SysWOW64\OptimizerMonitorOff.ini
          File Deleted : C:\Windows\SysWOW64\OptimizerMonitor.dll
          File Deleted : C:\Windows\SysWOW64\OptimizerMonitor.ini
          File Deleted : C:\Windows\System32\roboot64.exe
          File Deleted : C:\Windows\System32\drivers\Msft_Kernel_webinstrNHKT_01009.Wdf
          File Deleted : C:\Windows\System32\OptimizerMonitorOff.ini
          File Deleted : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\gameo.lnk
          File Deleted : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
          File Deleted : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
          File Deleted : C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OptimizerProInstaller.lnk
          File Deleted : C:\Users\nathanw\Desktop\MyPC Backup.lnk
          File Deleted : C:\Users\nathanw\Desktop\Optimizer Pro.lnk
          File Deleted : C:\Users\nathanw\Desktop\Sync Folder.lnk
          File Deleted : C:\Users\nathanw\AppData\Roaming\Mozilla\Firefox\Profiles\frc79gxm.default\user.js
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.plyrics.com_0.localstorage
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.plyrics.com_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovi.com_0.localstorage
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovi.com_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wajam.com_0.localstorage
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wajam.com_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_inst.shoppingate.info_0.localstorage
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_inst.shoppingate.info_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.best-deals-products.com_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.best-deals-products.com_0.localstorage
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.select-n-go00.select-n-go.com_0.localstorage
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.select-n-go00.select-n-go.com_0.localstorage-journal
          File Deleted : C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage

          ***** [ Scheduled tasks ] *****

          Task Deleted : Driver Support-RTMRules
          Task Deleted : Driver Support-RTMScan
          Task Deleted : Driver Support-RTMUpdater
          Task Deleted : globalUpdateUpdateTaskMachineCore
          Task Deleted : globalUpdateUpdateTaskMachineUA
          Task Deleted : Optimizer Pro Schedule
          Task Deleted : RegClean Pro
          Task Deleted : RegClean Pro_DEFAULT
          Task Deleted : RegClean Pro_UPDATES
          Task Deleted : SpeedChecker Update
          Task Deleted : UpdaterEX
          Task Deleted : Optimum_Daily
          Task Deleted : Optimum_LogOn
          Task Deleted : WSE_Vosteran
          Task Deleted : gameo_update
          Task Deleted : ConsumerInputUpdateTaskMachineCore
          Task Deleted : ConsumerInputUpdateTaskMachineUA
          Task Deleted : Pirates WW1
          Task Deleted : Pirates WW2
          Task Deleted : Pirates W1
          Task Deleted : Pirates W2
          Task Deleted : 846bb3df-d697-4cbc-b53f-963ee89ca784-1-6
          Task Deleted : 846bb3df-d697-4cbc-b53f-963ee89ca784-1-7
          Task Deleted : 846bb3df-d697-4cbc-b53f-963ee89ca784-10_user
          Task Deleted : 846bb3df-d697-4cbc-b53f-963ee89ca784-5
          Task Deleted : 846bb3df-d697-4cbc-b53f-963ee89ca784-5_user
          Task Deleted : 846bb3df-d697-4cbc-b53f-963ee89ca784-6
          Task Deleted : 846bb3df-d697-4cbc-b53f-963ee89ca784-7
          Task Deleted : bench-S-1-5-21-3104748373-4178966826-1034322177-1002
          Task Deleted : UpdaterEX

          ***** [ Shortcuts ] *****

          Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\download-free-soft bundle uninstaller\download-free-soft bundle uninstaller.lnk
          Shortcut Disinfected : C:\Users\nathanw\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Pirates.lnk

          ***** [ Registry ] *****

          Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{57FC8B03-13E5-70AC-4016-0DB57BA53BDF}]
          Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
          Key Deleted : HKCU\Software\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae
          Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae
          Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae
          Key Deleted : HKCU\Software\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce
          Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce
          Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce
          Key Deleted : HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
          Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
          Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
          Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Optimizer Pro]
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
          Key Deleted : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor
          Key Deleted : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor.1
          Key Deleted : HKLM\SOFTWARE\Classes\dcabho.Dca
          Key Deleted : HKLM\SOFTWARE\Classes\dcabho.Dca.1
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
          Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
          Key Deleted : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.bench.nmhost
          Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Bench Communicator Watcher]
          Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Bench Settings Cleaner]
          Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BService]
          Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Wd]
          Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
          Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
          Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BService64]
          Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [WinCheck]
          Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SmartWeb]
          Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Gameo]
          Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_us_163]
          Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_us_165]
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
          Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}
          Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
          Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
          Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2C09954F-CDA8-4BD1-8794-1D543E050378}
          Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3D9400B3-E14A-2220-608E-DE76BDA6A3AB}
          Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
          Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
          Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
          Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
          Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AEAA03CB-A063-46DD-8F9D-9C73CB30B790}
          Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
          Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AEAA03CB-A063-46DD-8F9D-9C73CB30B790}
          Key Deleted : HKCU\Software\BRS
          Key Deleted : HKCU\Software\Compete
          Key Deleted : HKCU\Software\GlobalUpdate
          Key Deleted : HKCU\Software\IM
          Key Deleted : HKCU\Software\InstallCore
          Key Deleted : HKCU\Software\InstalledBrowserExtensions
          Key Deleted : HKCU\Software\Optimizer Pro
          Key Deleted : HKCU\Software\Proxy
          Key Deleted : HKCU\Software\SweetIM
          Key Deleted : HKCU\Software\systweak
          Key Deleted : HKCU\Software\Tutorials
          Key Deleted : HKCU\Software\TutoTag
          Key Deleted : HKCU\Software\UpdaterEX
          Key Deleted : HKCU\Software\Wajam
          Key Deleted : HKCU\Software\WSE_Astromenda
          Key Deleted : HKCU\Software\DriverSupport
          Key Deleted : HKCU\Software\Vosteran Browser
          Key Deleted : HKCU\Software\WSE_Vosteran
          Key Deleted : HKCU\Software\Vosteran
          Key Deleted : HKCU\Software\Dolphin Deals
          Key Deleted : HKCU\Software\gameo
          Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
          Key Deleted : HKCU\Software\AppDataLow\Software\Compete
          Key Deleted : HKCU\Software\AppDataLow\Software\DynConIE
          Key Deleted : HKCU\Software\AppDataLow\Software\SmartWeb
          Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
          Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
          Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
          Key Deleted : HKLM\SOFTWARE\AdvertisingSupport
          Key Deleted : HKLM\SOFTWARE\Bench
          Key Deleted : HKLM\SOFTWARE\CompeteInc
          Key Deleted : HKLM\SOFTWARE\GlobalUpdate
          Key Deleted : HKLM\SOFTWARE\InstallCore
          Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
          Key Deleted : HKLM\SOFTWARE\Proxy
          Key Deleted : HKLM\SOFTWARE\SearchProtect
          Key Deleted : HKLM\SOFTWARE\SweetIM
          Key Deleted : HKLM\SOFTWARE\systweak
          Key Deleted : HKLM\SOFTWARE\Tutorials
          Key Deleted : HKLM\SOFTWARE\Browser Warden
          Key Deleted : HKLM\SOFTWARE\Wajam Web Enhancer
          Key Deleted : HKLM\SOFTWARE\Dolphin Deals
          Key Deleted : HKLM\SOFTWARE\GAMESDESKTOP
          Key Deleted : HKLM\SOFTWARE\SPPDCOM
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\UpdaterEX
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\gameo
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean-Pro_is1
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WSE_Astromenda
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{597FB4A5-DD86-4316-A410-7E8074CC2CCE}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ConvertAd
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam Web Enhancer
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartWeb
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WSE_Vosteran
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BreakingNewsAlert
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\39012_Browser Warden
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wincheck
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Consumer Input Installer
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\igsc
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IGS
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ASPackage
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\04B239F6-D435-4A0C-F65E-9F1C99811569
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_us_163_is1
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_us_165_is1
          Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
          Key Deleted : [x64] HKLM\SOFTWARE\Wajam Web Enhancer
          Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
          Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dolphin Deals
          Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll
          Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\trovi.com
          Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.trovi.com
          Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>

          ***** [ Web browsers ] *****

          -\\ Internet Explorer v11.0.9600.17416

          -\\ Mozilla Firefox v35.0.1 (x86 en-US)

          -\\ Google Chrome v40.0.2214.94

          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource;=49&ctid;=CT3072253
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://astromenda.com/results.php?f=4&q;={searchTerms}&a;=ast_dnldstr_14_40_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtDtDyCtN1L2XzutAtFyDtFtCtFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FtA0DtD0EtB0BtG0BtC0B0FtG0AyDtC0AtGyD0E0EzztGyE0F0A0DzzyD0BzytA0FzzyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0DyCyEyE0AyEzztG0CyBtCzytGyE0D0F0BtGzytD0AyDtGtD0D0FyC0Ezzzy0DtA0FzzyE2Q&cr;=1440908205&ir;=
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid;=CT3326582&octid;=EB_ORIGINAL_CTID&ISID;=M7F3484E9-DA35-489B-938C-F37B8655B977&SearchSource;=58&CUI;=&UM;=6&UP;=SP96CAD07F-DE2B-40FD-A8F7-F76C24BCEE5C&q;={searchTerms}&SSPV;=
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
          [C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=

          *************************

          AdwCleaner[R0].txt - [31736 bytes] - [21/02/2015 22:46:16]
          AdwCleaner[S0].txt - [31238 bytes] - [21/02/2015 22:49:09]

          ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [31298  bytes] ##########

           

          JRT (As luck would have it my computer died halfway through the first time running this program so that might explain why this is pretty empty)

           

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Thisisu
          Version: 6.4.2 (02.02.2015:1)
          OS: Windows 8.1 x64
          Ran by [removed] on Sat 02/21/2015 at 23:02:07.13
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

           

          ~~~ Services

           

          ~~~ Registry Values

           

          ~~~ Registry Keys

           

          ~~~ Files

           

          ~~~ Folders

           

          ~~~ Event Viewer Logs were cleared

           

           

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Sat 02/21/2015 at 23:03:19.68
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

           

          Malewarebytes

           

          Malwarebytes Anti-Malware
          www.malwarebytes.org

          Scan Date: 2/21/2015
          Scan Time: 11:06:50 PM
          Logfile:
          Administrator: Yes

          Version: 2.00.4.1028
          Malware Database: v2014.11.20.06
          Rootkit Database: v2014.11.18.01
          License: Free
          Malware Protection: Disabled
          Malicious Website Protection: Disabled
          Self-protection: Disabled

          OS: Windows 8.1
          CPU: x64
          File System: NTFS
          User: nathanw

          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 385001
          Time Elapsed: 9 min, 32 sec

          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Disabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled

          Processes: 0
          (No malicious items detected)

          Modules: 0
          (No malicious items detected)

          Registry Keys: 62
          PUP.Optional.BreakingNewsAlert.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CrUwvroQ, , [f610231b6616082e1eb607df7f82e41c],
          PUP.Optional.DolphinDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7c1ec179-be4e-4bee-b5a7-4596884bbc8d}, , [bb4bce7090ec201615b09622669c06fa],
          PUP.Optional.DolphinDeals.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{3f378102-99be-422d-8bf2-bd5c96567032}, , [bb4bce7090ec201615b09622669c06fa],
          PUP.Optional.DolphinDeals.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{500D7297-28BC-4999-96DC-688C23F3C347}, , [bb4bce7090ec201615b09622669c06fa],
          PUP.Optional.DolphinDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{500D7297-28BC-4999-96DC-688C23F3C347}, , [bb4bce7090ec201615b09622669c06fa],
          PUP.Optional.DolphinDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{3f378102-99be-422d-8bf2-bd5c96567032}, , [bb4bce7090ec201615b09622669c06fa],
          PUP.Optional.DolphinDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{7C1EC179-BE4E-4BEE-B5A7-4596884BBC8D}, , [bb4bce7090ec201615b09622669c06fa],
          PUP.Optional.Consumer.Input.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}, , [dc2af549413bad89e440c7fa0ff3d52b],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoCreateAsync, , [a264330b7b01c175acddf97e08fb8e72],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoCreateAsync.1.0, , [41c5142ade9ec27419707cfb010229d7],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreClass, , [917595a9a4d852e48bfe5621e320649c],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreClass.1, , [63a32a14c8b4290ddfaa81f624df6b95],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreMachineClass, , [26e0ac92a7d5b97dccbd1a5d5ea555ab],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreMachineClass.1, , [c0467ac4d7a5290df09997e040c3ac54],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine, , [7f87e25c0c70a88e1e6b3e3935ce34cc],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine.1.0, , [a5617ac48cf01323cbbe1c5b6f9457a9],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine, , [59ad9ea0681438fe0485512609faef11],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0, , [b25415298bf1bd79a0e9babd659e16ea],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback, , [3cca7ec02d4fcb6b91f8a3d4020131cf],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0, , [e026261879034beb7b0ede9909faef11],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc, , [76903e0083f946f051386b0c9e6560a0],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0, , [30d62d11dca0072fb1d8e09782815ca4],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.ProcessLauncher, , [927459e53d3f44f2b8d19fd87291af51],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.ProcessLauncher.1.0, , [48be0d315824fe383158136435cec937],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3COMClassService, , [7f87003e2a52082edfaa057263a04bb5],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3COMClassService.1.0, , [897d083605771d190485086f50b32dd3],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachine, , [788e9da17dffe84e5336f7800ff49e62],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachine.1.0, , [1ceab08e0c70e05611787afdc83b09f7],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback, , [739341fd9fdddb5b9eebbcbb1de6d729],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback.1.0, , [29dd77c78def290d07820f680bf8de22],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebSvc, , [bc4a3509ee8efc3a17723443fe05c23e],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebSvc.1.0, , [61a5a6984b31191d6c1dd99e9172d62a],
          PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, , [f313de601369e15564fd327e8282ab55],
          PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, , [47bfa9956b1181b5a1bf5e5231d31be5],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoCreateAsync, , [d630a49ac0bcf73f45444b2cda297090],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoCreateAsync.1.0, , [f70f8eb0fe7e5adc6b1e680fc0430ef2],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreClass, , [f70f47f7b4c87eb81a6f383f946f9b65],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreClass.1, , [b551dc6279037abcbecb7304b44f34cc],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreMachineClass, , [7096e35bafcd6acc3455df989370728e],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreMachineClass.1, , [d92ded51f08ca096741595e2a95a11ef],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine, , [de288ab40874fc3acfba61169370d828],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine.1.0, , [16f086b8bac2fc3ae6a36c0b42c1966a],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine, , [d5311c22f88455e15b2ef582aa599b65],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0, , [c83e2b1386f696a0a1e8e88fe71c7f81],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback, , [71959aa4d6a6d36338515423da29867a],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0, , [788e82bceb9137ff7514126513f06c94],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc, , [c73fd36bbcc05dd9a0e9a9ce3ac98f71],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0, , [40c699a53448fb3b59306413d3303cc4],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.ProcessLauncher, , [7591db637c0070c6f198fb7c53b0926e],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.ProcessLauncher.1.0, , [b74fef4f7c00b383d7b2f483887b51af],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3COMClassService, , [ff07033b6b11f2442465581f58ab6997],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3COMClassService.1.0, , [66a01c22d3a960d6a2e7fb7c818225db],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachine, , [dd291e20f78540f6fc8dfd7a5ba8df21],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachine.1.0, , [b94dbc8283f9082e59306512a1622fd1],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback, , [6f9756e8d6a661d52366adca83808f71],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback.1.0, , [0501e658601c1f1753361661ae5547b9],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebSvc, , [db2b0935e7958ea8d6b3364160a34bb5],
          PUP.Optional.Consumer.Input.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebSvc.1.0, , [9c6a42fc0a72191d3356096e1de6fe02],
          PUP.Optional.Booster.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{4ef60154}, , [8f7746f83c40f2445f8f83ce5ea57f81],
          PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.SweetPacks.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\download-free-soft bundle uninstaller, , [a85e2915f48838fe36112211030017e9],

          Registry Values: 2
          PUP.Optional.Vosteran.A, HKU\S-1-5-21-3104748373-4178966826-1034322177-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|WSE_Vosteran, C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\nathanw\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat", , [b2547fbfd9a35adc5bc9377e5da7a858]
          PUP.Optional.ConsumerInput.A, HKU\S-1-5-21-3104748373-4178966826-1034322177-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|ConsumerInput@Compete, C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12099.xpi, , [b5511529304cd3635efcbe7e768d57a9]

          Registry Data: 0
          (No malicious items detected)

          Folders: 4
          PUP.Optional.Extutil.A, C:\Users\nathanw\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B, , [cf37cc722458f1456019da4638cbc33d],
          PUP.Optional.Managera.A, C:\Users\nathanw\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42, , [20e6e05e74084ee891e9be6253b07c84],
          PUP.Optional.GlobalUpdate.A, C:\Users\nathanw\AppData\Local\Temp\comh.251222, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.SweetPacks.A, C:\Program Files (x86)\sweetpacks bundle uninstaller_Skype_1966342, , [a85e2915f48838fe36112211030017e9],

          Files: 48
          PUP.Optional.BreakingNewsAlert.A, C:\ProgramData\UDDNuLHc\CrUwvroQ.exe, , [f610231b6616082e1eb607df7f82e41c],
          PUP.Optional.BreakingNewsAlert.A, C:\ProgramData\UDDNuLHc\dat\NpYlTxdCgO.exe, , [699df04e8def84b250840bdbd62b4eb2],
          PUP.Optional.BreakingNewsAlert.A, C:\ProgramData\UDDNuLHc\dat\TgUtlvA.exe, , [f511e45a84f88fa75381cc1ac8390ef2],
          PUP.Optional.CrossRider.A, C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\utils.exe, , [7294bc82720a52e4bd773715639db24e],
          PUP.Optional.MyPCBackup.A, C:\Users\nathanw\AppData\Local\Temp\CloudBackup83.exe, , [8a7c98a6a6d6b77f46ee17c8a25f857b],
          PUP.Optional.BrowserWarden.A, C:\Users\nathanw\AppData\Local\Temp\cubfmglb.0eo.exe, , [060048f697e53bfb4a8ca1b702feb947],
          PUP.Optional.CrossRider.A, C:\Users\nathanw\AppData\Local\Temp\n4028\HQVideo-USInstaller.exe, , [60a6bd817ffda0966e7fb624629f3fc1],
          PUP.Optional.BreakingNewsAlert.A, C:\Users\nathanw\AppData\Local\Temp\n4028\Setup.exe, , [976fc67873094de912c238ae6f92728e],
          PUP.Optional.SmartInstaller, C:\Users\nathanw\AppData\Local\Temp\TDIR542F7706\SI.exe, , [28de1a2455271422ec7c3522dd2315eb],
          PUP.Optional.SmartInstaller, C:\Users\nathanw\AppData\Local\Temp\TDIR542F7740\SI.exe, , [4db9f34bcab2082ee0889fb87888936d],
          PUP.Optional.SmartInstaller, C:\Users\nathanw\AppData\Local\Temp\TDIR542F7751\SI.exe, , [020493ab6d0f7bbba0c860f7d03008f8],
          PUP.Optional.MyPCBackup.A, C:\Windows\Temp\tmp4BB2.tmp, , [9d699da1d5a752e4b1837e611ae7cf31],
          PUP.Optional.ClientConnect, C:\Users\nathanw\Downloads\Skype_TSV3D4S9X.exe, , [4abcbd8188f47bbb4c8b03b6f60b13ed],
          PUP.Optional.Amonetize, C:\Users\nathanw\Downloads\FlashPlayersetup__10596_i1374127722_il2510.exe, , [7f877cc2ef8d053128029b2627da48b8],
          PUP.Optional.SmartInstaller, C:\Users\nathanw\Downloads\Wilfred.US.S04.Season.4.Complete.720p.HDTV.x264-[maximersk]-}ý.exe, , [00064fef1d5fc1750b894c8632cf04fc],
          PUP.Optional.DomaIQ, C:\Users\nathanw\Downloads\Setup.exe, , [39cd8faf6e0edd59abfc1d3d6f91c63a],
          PUP.Optional.GetPrivateVPN, C:\Windows\System32\Tasks\GPUP, , [43c32f0f2d4ffe38d33879c67a899769],
          PUP.Optional.SpeedChecker.A, C:\Windows\Tasks\SpeedChecker Update.job, , [16f0b18dccb06cca89d31d2537cc19e7],
          PUP.Optional.Proxy.A, C:\Users\nathanw\AppData\Local\proxy.log, , [75918ab46c10e155d5c485c416ed619f],
          PUP.Optional.RegCleanerPro.J, C:\Windows\Tasks\RegClean Pro_UPDATES.job, , [b45251ed1a6265d1123b93e532d102fe],
          PUP.Optional.RegCleanPro.A, C:\Windows\Tasks\RegClean Pro_DEFAULT.job, , [c73fbd818af2b383a5342763b2528d73],
          PUP.Optional.CrossRider.T, C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6.job, , [3dc9de609ddfac8a6567affde321f40c],
          PUP.Optional.CrossRider.T, C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7.job, , [cb3b53ebfb8136007755cedee61e738d],
          PUP.Optional.CrossRider.T, C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-10_user.job, , [38ce0c32fa822313646859533bc9f30d],
          PUP.Optional.CrossRider.T, C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5_user.job, , [0bfb3d01067649ed6c603d6fb252e41c],
          PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, , [b15592ac5c2055e133afebc1d3310ff1],
          PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, , [62a4c17da7d577bf63813973bb49c63a],
          PUP.Optional.BrowserWarden.A, C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hjjjegfhiceggepdokloeepnhlfnedkk_0.localstorage, , [fe08a995720a3105e3a401ac14f052ae],
          PUP.Optional.SearchProtect, C:\Windows\apppatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, , [fc0aea544735de58352f2a867d87738d],
          PUP.Optional.Vosteran.A, C:\Windows\Tasks\Vosteran dota.job, , [947280be750780b6b16f45702bd9758b],
          PUP.Optional.Vosteran.A, C:\Windows\Tasks\WSE_Vosteran.job, , [61a580be225aef4741df961fb94b847c],
          PUP.Optional.Vosteran.A, C:\Windows\System32\Tasks\Vosteran dota, , [3cca9ba33f3d989ed849585d17edb947],
          PUP.Optional.Extutil.A, C:\Users\nathanw\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\bk.js, , [cf37cc722458f1456019da4638cbc33d],
          PUP.Optional.Extutil.A, C:\Users\nathanw\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\cs.js, , [cf37cc722458f1456019da4638cbc33d],
          PUP.Optional.Extutil.A, C:\Users\nathanw\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\manifest.json, , [cf37cc722458f1456019da4638cbc33d],
          PUP.Optional.Managera.A, C:\Users\nathanw\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\cs.js, , [20e6e05e74084ee891e9be6253b07c84],
          PUP.Optional.Managera.A, C:\Users\nathanw\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\manifest.json, , [20e6e05e74084ee891e9be6253b07c84],
          PUP.Optional.GlobalUpdate.A, C:\Users\nathanw\AppData\Local\Temp\comh.251222\GoogleCrashHandler.exe, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.GlobalUpdate.A, C:\Users\nathanw\AppData\Local\Temp\comh.251222\GoogleUpdate.exe, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.GlobalUpdate.A, C:\Users\nathanw\AppData\Local\Temp\comh.251222\GoogleUpdateBroker.exe, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.GlobalUpdate.A, C:\Users\nathanw\AppData\Local\Temp\comh.251222\GoogleUpdateHelper.msi, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.GlobalUpdate.A, C:\Users\nathanw\AppData\Local\Temp\comh.251222\GoogleUpdateOnDemand.exe, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.GlobalUpdate.A, C:\Users\nathanw\AppData\Local\Temp\comh.251222\goopdate.dll, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.GlobalUpdate.A, C:\Users\nathanw\AppData\Local\Temp\comh.251222\goopdateres_en.dll, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.GlobalUpdate.A, C:\Users\nathanw\AppData\Local\Temp\comh.251222\npGoogleUpdate4.dll, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.GlobalUpdate.A, C:\Users\nathanw\AppData\Local\Temp\comh.251222\psmachine.dll, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.GlobalUpdate.A, C:\Users\nathanw\AppData\Local\Temp\comh.251222\psuser.dll, , [19ed45f91c60fe386116101239ca7e82],
          PUP.Optional.SweetPacks.A, C:\Program Files (x86)\sweetpacks bundle uninstaller_Skype_1966342\uninstaller.exe, , [a85e2915f48838fe36112211030017e9],

          Physical Sectors: 0
          (No malicious items detected)

          (end)

          I got a tell ya that everything your computer is infected with was not done by just one bad mouse click, either you or someone you authorize to use this computer needs to start practicing some better online habits, I am only saying this because of what i see and know about what threats are going around and some are not pretty, threats like stealing all your usernames and passwords for sites you frequent including credit card data, also log ins for any online banking you may do , there are some now that even lock you out of your computer unless you pay a ransom, its its not cheap.

           

          When you ran Malwarebytes did it remove all those bad entries, if not run it again and make sure there all gone

           

          Then run a new scan with FRST, with all that garbage removed you should be able to run it from normal windows, make sure to put a checkmark in Additions and post both new logs please

          You are right about that. This is my brother's computer and I know he definitely hasn't been the safest in regards to computer security and browsing habits. I have definitely given him hell about this and I'm glad you're also scolding him! I'll make sure he reads what you have to say to hopefully strike some fear into him about safety online.

           

          I ran Malewarebytes again to remove all the entries.

           

          FRST

           

          Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-02-2015
          Ran by [removed] (administrator) on NATHAN on 22-02-2015 13:36:26
          Running from C:\Users\[removed]\Desktop
          [removed] Platform: Windows 8.1 (X64) OS Language: English (United States)
          Internet Explorer Version 11 (Default browser: FF)
          Boot Mode: Normal
          Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

          ==================== Processes (Whitelisted) =================

          (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

          (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
          (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
          (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
          (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
          (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
          (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
          (Microsoft Corporation) C:\Windows\System32\wlanext.exe
          (Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\Dragon Gaming Center\Dragon Gaming Center.exe
          (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
          () C:\Program Files\ChromeEnhancer\ChromeEnhancer.exe
          (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
          (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
          (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
          (Microsoft Corporation) C:\Windows\System32\dasHost.exe
          (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
          (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
          (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
          (Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
          (MSI) C:\Program Files (x86)\MSI\SUPER CHARGER\ChargeService.exe
          (Symantec Corporation) C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\NAT.exe
          (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
          (Symantec Corporation) C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\NAT.exe
          () C:\Program Files\ChromeEnhancer\ChromeEnhancerMonitor32.exe
          () C:\Windows\SysWOW64\PnkBstrA.exe
          (Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
          (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
          (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
          (Impulse Point, LLC) C:\Program Files (x86)\SafeConnect\scManager.sys
          (RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
          (Company) C:\Program Files (x86)\Popcorn Time\Updater.exe
          (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
          (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
          (RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
          (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
          (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
          (Intel Corporation) C:\Windows\System32\igfxEM.exe
          (Intel Corporation) C:\Windows\System32\igfxHK.exe
          (Intel Corporation) C:\Windows\System32\igfxTray.exe
          (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
          (Microsoft Corporation) C:\Windows\System32\dllhost.exe
          (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
          (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
          (Microsoft Corporation) C:\Windows\System32\rundll32.exe
          (MSI) C:\Program Files (x86)\SCM\Radio Manager.exe
          (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
          (MSI) C:\Program Files (x86)\SCM\SCM.exe
          (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
          (Microsoft Corporation) C:\Windows\System32\rundll32.exe
          (SteelSeries ApS) C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe
          () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
          (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
          (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
          (Impulse Point, LLC) C:\Program Files (x86)\SafeConnect\SafeConnectClient.exe
          (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
          (MSI) C:\Program Files (x86)\MSI\SUPER CHARGER\SUPER CHARGER.exe
          (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
          (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
          (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
          (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
          (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
          (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
          (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
          (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
          (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
          (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
          (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe

          ==================== Registry (Whitelisted) ==================

          (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

          HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-04-23] (Realtek Semiconductor)
          HKLM\…\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2014-04-23] (NVIDIA Corporation)
          HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
          HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-30] (Intel Corporation)
          HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891568 2014-04-23] (ELAN Microelectronics Corp.)
          HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
          HKLM\…\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2014-01-02] (MSI)
          HKLM\…\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [407720 2014-01-02] (MSI)
          HKLM\…\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
          HKLM-x32\…\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2013-08-16] (Creative Technology Ltd)
          HKLM-x32\…\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
          HKLM-x32\…\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
          HKLM-x32\…\Run: [SUPER CHARGER] => C:\Program Files (x86)\MSI\SUPER CHARGER\SUPER CHARGER.exe [1047536 2014-02-21] (MSI)
          HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
          HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [SteelSeries Engine] => C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe [249856 2014-01-23] (SteelSeries ApS)
          HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [CyberGhost] => C:\Program Files\CyberGhost 5\CyberGhost.EXE [404080 2014-06-12] (CyberGhost S.R.L.)
          HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
          HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [SpeedTray] => C:\Users\nathanw\AppData\Roaming\SpeedTray\speedtray.exe [725518 2014-12-25] ()
          HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [TheAnswerFinder] => "C:\Users\nathanw\AppData\Roaming\TheAnswerFinder\TheAnswerFinder.exe"
          HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [GoogleChromeAutoLaunch_E51A917143CE60DF87C6800984BEEDC2] => "C:\Users\nathanw\AppData\Local\Vosteran\Application\vosteran.exe" –no-startup-window –auto-launch-at-startup –profile-directory="Default"
          AppInit_DLLs-x32: C:/PROGRA~3/{A6374~1/191~1.1/dota.dll => C:\ProgramData\{A6374EF4-F6B5-9F72-4733-EFF097B13C7E}\1.9.1.1\dota.dll [964608 2015-02-01] ()
          Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk
          ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{29CDA0F1-A6DA-44CC-9ABB-131A7D3D77AE}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
          Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
          ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
          Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SafeConnect.lnk
          ShortcutTarget: SafeConnect.lnk -> C:\Program Files (x86)\SafeConnect\SCClient.exe (Impulse Point, LLC)
          Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk
          ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe ()
          ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
          ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
          ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
          ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
          ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
          ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
          ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
          CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

          ==================== Internet (Whitelisted) ====================

          (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

          HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://msi13.msn.com/
          HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msi13.msn.com
          SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
          SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
          SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
          SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
          SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = http://www.bing.com/search?FORM=U270DF&PC;=U270&q;={searchTerms}&src;=IE-SearchBox
          BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
          BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
          BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
          BHO-x32: SecureWebBHO Class -> {D3C24E2B-C820-4492-9B69-11BF7163F998} -> C:\Program Files (x86)\Jelbrus Secure Web\jsie.dll (Jelbrus)
          Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
          Winsock: Catalog9 01 C:\Windows\system32\OptimizerMonitor.dll File Not found ()
          Winsock: Catalog9 02 C:\Windows\system32\OptimizerMonitor.dll File Not found ()
          Winsock: Catalog9 03 C:\Windows\system32\OptimizerMonitor.dll File Not found ()
          Winsock: Catalog9 04 C:\Windows\system32\OptimizerMonitor.dll File Not found ()
          Winsock: Catalog9 16 C:\Windows\system32\OptimizerMonitor.dll File Not found ()
          Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
          Tcpip\Parameters: [DhcpNameServer] 192.168.1.127
          StartMenuInternet: IEXPLORE.EXE - iexplore.exe

          FireFox:
          ========
          FF ProfilePath: C:\Users\nathanw\AppData\Roaming\Mozilla\Firefox\Profiles\frc79gxm.default
          FF Homepage: search.protectedio.com
          FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
          FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
          FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
          FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
          FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
          FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
          FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
          FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
          FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
          FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
          FF Extension: Firefox Helper - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\52f49536d77819bae6f4abd24dce4dfb [2015-02-07]
          FF Extension: Firefox Helper - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\8e30d17213b45506dd5ae9d34dce4dfb [2015-02-22]
          FF HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
          FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]

          Chrome:
          =======
          CHR HomePage: Default -> hxxp://vosteran.com/?f=1&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
          CHR StartupUrls: Default -> "hxxp://vosteran.com/?f=7&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=", "hxxp://www.trovi.com/?gd=&ctid;=CT3330557&octid;=EB_ORIGINAL_CTID&ISID;=M05A97C27-B11B-4A1F-9195-35A3807ABEA1&SearchSource;=55&CUI;=&UM;=6&UP;=SP96CAD07F-DE2B-40FD-A8F7-F76C24BCEE5C&SSPV;="
          CHR DefaultSearchKeyword: Default -> vosteran.com
          CHR DefaultSearchURL: Default -> http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
          CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
          CHR Profile: C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default
          CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-01]
          CHR Extension: (Adblock Plus) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-08]
          CHR Extension: (Google Wallet) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-01]
          CHR Extension: (oaepeijninfcgjdnighjnlgdkkgpnaen) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaepeijninfcgjdnighjnlgdkkgpnaen [2015-02-08]
          StartMenuInternet: Google Chrome - chrome.exe

          ==================== Services (Whitelisted) =================

          (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

          S2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64624 2014-06-12] (CyberGhost S.R.L)
          R2 ChromeEnhancer; C:\Program Files\ChromeEnhancer\ChromeEnhancer.exe [44544 2015-01-28] () [File not signed]
          R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
          R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101680 2014-04-23] (ELAN Microelectronics Corp.)
          R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-30] (Intel Corporation)
          R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-04-23] (Intel Corporation)
          R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
          S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
          R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
          S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
          S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
          R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2014-01-02] (Micro-Star International Co., Ltd.) [File not signed]
          R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\SUPER CHARGER\ChargeService.exe [162800 2014-02-21] (MSI)
          S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-10-11] ()
          R2 NAT; C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\NAT.exe [232424 2013-10-11] (Symantec Corporation)
          R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4362056 2014-11-18] (Symantec Corporation)
          R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2014-04-23] (NVIDIA Corporation)
          R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-10-28] ()
          R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [344576 2014-03-04] (Qualcomm Atheros) [File not signed]
          R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-04-23] (Realtek Semiconductor)
          R2 SCManager; C:\Program Files (x86)\SafeConnect\scManager.sys [176520 2012-11-19] (Impulse Point, LLC)
          R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [126568 2015-02-01] (RaMMicHaeL)
          R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [179200 2014-09-13] (Company) [File not signed]
          R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-21] (Microsoft Corporation)
          R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-21] (Microsoft Corporation)
          R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3671792 2013-10-11] (Intel® Corporation)
          S2 4ef60154; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\Optimizer Pro 3.38\OptProMon.dll",ENT

          ==================== Drivers (Whitelisted) ====================

          (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

          R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [81072 2014-02-20] (Qualcomm Atheros, Inc.)
          R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
          S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [63488 2014-04-24] (Microsoft Corporation) [File not signed]
          R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-11-07] (Motorola Solutions, Inc.)
          R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1411384 2013-11-07] (Motorola Solutions, Inc.)
          S3 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0405000.009\ccSetx64.sys [150104 2013-07-29] (Symantec Corporation)
          R1 ccSet_NAT; C:\Windows\system32\drivers\NATx64\010A000.009\ccSetx64.sys [150104 2013-07-29] (Symantec Corporation)
          R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [160464 2014-04-23] (Intel Corporation)
          R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [163536 2013-03-20] (Qualcomm Atheros, Inc.)
          R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
          R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3607520 2013-10-14] (Intel Corporation)
          R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\SUPER CHARGER\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
          R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2014-04-23] (NVIDIA Corporation)
          R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [466648 2014-04-23] (Realsil Semiconductor Corporation)
          S3 SAlphamBth; C:\Windows\System32\drivers\SAlphabt64.sys [31232 2012-10-16] (SteelSeries Corporation)
          S3 SAlphamHid; C:\Windows\System32\drivers\SAlpham64.sys [38016 2013-05-31] (SteelSeries Corporation)
          R3 SAlphaPS2; C:\Windows\System32\drivers\SAlphaPS264.sys [26496 2013-12-12] (SteelSeries Corporation)
          R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-21] (Microsoft Corporation)
          R3 WINIO; C:\Program Files (x86)\MSI\Dragon Gaming Center\winio64.sys [15160 2010-06-07] ()

          ==================== NetSvcs (Whitelisted) ===================

          (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

          ==================== One Month Created Files and Folders ========

          (If an entry is included in the fixlist, the file\folder will be moved.)

          2015-02-22 13:36 - 2015-02-22 13:36 - 00023300 _____ () C:\Users\nathanw\Desktop\FRST.txt
          2015-02-21 23:24 - 2015-02-21 23:24 - 00000000 ____D () C:\Users\nathanw\Desktop\virus removal stuff
          2015-02-21 23:05 - 2015-02-22 12:57 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
          2015-02-21 23:05 - 2015-02-22 12:56 - 00001128 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
          2015-02-21 23:05 - 2015-02-22 12:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
          2015-02-21 23:05 - 2015-02-22 12:56 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
          2015-02-21 23:05 - 2015-02-21 23:05 - 00000000 ____D () C:\ProgramData\Malwarebytes
          2015-02-21 23:05 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
          2015-02-21 23:05 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
          2015-02-21 23:05 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
          2015-02-21 22:46 - 2015-02-21 22:49 - 00000000 ____D () C:\AdwCleaner
          2015-02-21 13:15 - 2015-02-22 13:36 - 00000000 ____D () C:\Users\nathanw\Desktop\FRST-OlderVersion
          2015-02-21 13:15 - 2015-02-22 13:36 - 00000000 ____D () C:\FRST
          2015-02-21 13:13 - 2015-02-21 13:13 - 00000512 _____ () C:\Users\nathanw\Desktop\MBR.dat
          2015-02-21 12:40 - 2015-02-22 13:36 - 02087424 _____ (Farbar) C:\Users\nathanw\Desktop\FRST64.exe
          2015-02-15 15:40 - 2015-02-15 15:40 - 00002068 _____ () C:\Windows\SysWOW64\errordetails.xml
          2015-02-13 13:27 - 2015-02-22 12:44 - 00000000 ____D () C:\Windows\pss
          2015-02-12 15:32 - 2015-01-19 13:42 - 01487976 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
          2015-02-12 15:31 - 2015-02-03 18:38 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
          2015-02-12 15:31 - 2015-02-03 18:08 - 00761856 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
          2015-02-12 15:31 - 2015-02-03 18:08 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
          2015-02-12 15:31 - 2015-02-02 18:11 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
          2015-02-12 15:31 - 2015-02-02 18:11 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
          2015-02-12 15:31 - 2015-02-02 18:11 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
          2015-02-11 22:42 - 2015-01-10 03:22 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
          2015-02-10 17:29 - 2015-02-10 17:30 - 00015907 _____ () C:\Users\nathanw\Documents\nutritionlog.nathanwatts.xlsx
          2015-02-10 17:29 - 2015-02-10 17:29 - 00081920 _____ () C:\Users\nathanw\Documents\nutrientreport.nathanwatts.xls
          2015-02-09 21:39 - 2015-02-09 21:40 - 00081920 _____ () C:\Users\nathanw\Downloads\NutrientsReport.xls
          2015-02-09 19:08 - 2015-02-09 21:39 - 00015877 _____ () C:\Users\nathanw\Documents\nutrition log.xlsx
          2015-02-06 14:51 - 2015-02-07 15:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
          2015-02-06 14:51 - 2015-02-06 14:51 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
          2015-02-06 14:51 - 2015-02-06 14:51 - 00001173 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
          2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Mozilla
          2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Mozilla
          2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\ProgramData\Mozilla
          2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
          2015-02-06 14:50 - 2015-02-06 14:50 - 00243440 _____ () C:\Users\nathanw\Downloads\Firefox Setup Stub 35.0.1.exe
          2015-02-05 01:27 - 2015-02-05 01:27 - 01246384 _____ () C:\Users\nathanw\Downloads\Installation.exe
          2015-02-03 18:53 - 2015-02-03 18:53 - 00003384 _____ () C:\Windows\System32\Tasks\CIMT_daily_S-1-5-21-3104748373-4178966826-1034322177-1002
          2015-02-03 18:53 - 2015-02-03 18:53 - 00003274 _____ () C:\Windows\System32\Tasks\CIMT_S-1-5-21-3104748373-4178966826-1034322177-1002
          2015-02-03 18:53 - 2015-02-03 18:53 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Compete
          2015-02-01 18:23 - 2015-02-15 17:48 - 00383280 _____ () C:\Windows\system32\errordetails.xml
          2015-02-01 00:04 - 2015-02-01 17:16 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pirates
          2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Pirates854
          2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Pirates
          2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\ProgramData\Unchecky
          2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\ProgramData\{A6374EF4-F6B5-9F72-4733-EFF097B13C7E}
          2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Program Files (x86)\Unchecky
          2015-01-31 23:52 - 2015-02-03 18:46 - 00000000 ____D () C:\ProgramData\{2b6e2981-fd67-657c-2b6e-e2981fd6a607}
          2015-01-31 23:52 - 2015-01-31 23:54 - 00000000 ____D () C:\ProgramData\UDDNuLHc
          2015-01-31 23:52 - 2015-01-31 23:54 - 00000000 ____D () C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01
          2015-01-31 23:52 - 2015-01-31 23:53 - 00000000 ____D () C:\Program Files (x86)\7d294cc7-8e3e-446e-9a9d-234f73b47a8d
          2015-01-31 23:51 - 2015-02-22 12:50 - 00000000 ____D () C:\Program Files (x86)\Regprocleaner
          2015-01-31 23:51 - 2015-01-31 23:51 - 00001197 _____ () C:\Users\Public\Desktop\Reg Pro Cleaner.lnk
          2015-01-31 23:51 - 2015-01-31 23:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reg Pro Cleaner
          2015-01-31 23:51 - 2015-01-31 23:51 - 00000000 ____D () C:\Program Files (x86)\Reg Pro Cleaner
          2015-01-31 15:48 - 2015-01-31 15:48 - 00000001 _____ () C:\Users\Public\Documents\dgc.txt
          2015-01-31 00:06 - 2015-02-22 12:49 - 00003278 _____ () C:\Windows\System32\Tasks\Jelbrus Secure Web Task
          2015-01-28 23:28 - 2015-01-28 23:28 - 00000000 ____D () C:\Program Files\ChromeEnhancer
          2015-01-24 22:23 - 2015-01-24 22:23 - 00000000 ____D () C:\Users\nathanw\Desktop\New folder

          ==================== One Month Modified Files and Folders =======

          (If an entry is included in the fixlist, the file\folder will be moved.)

          2015-02-22 13:36 - 2014-07-25 18:19 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
          2015-02-22 13:28 - 2014-07-25 18:12 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3104748373-4178966826-1034322177-1002
          2015-02-22 13:27 - 2014-06-17 00:51 - 01843550 _____ () C:\Windows\WindowsUpdate.log
          2015-02-22 13:24 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\AppReadiness
          2015-02-22 13:23 - 2013-08-22 10:20 - 00000000 ____D () C:\Windows\CbsTemp
          2015-02-22 12:54 - 2014-07-28 11:13 - 00000000 ____D () C:\Users\nathanw\AppData\Local\CrashDumps
          2015-02-22 12:53 - 2013-11-13 12:03 - 00865408 _____ () C:\Windows\system32\PerfStringBackup.INI
          2015-02-22 12:52 - 2014-04-24 15:48 - 00000000 ____D () C:\ProgramData\Package Cache
          2015-02-22 12:51 - 2014-10-18 23:20 - 00000000 ____D () C:\ProgramData\Sophos
          2015-02-22 12:51 - 2014-09-25 22:41 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Skype
          2015-02-22 12:50 - 2014-07-25 18:17 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{62839BE3-D084-47BD-A73F-8EB4F8423EF9}
          2015-02-22 12:49 - 2013-11-13 15:06 - 00000000 ____D () C:\ProgramData\boost_interprocess
          2015-02-22 12:46 - 2014-08-15 15:31 - 00000000 ____D () C:\Program Files (x86)\SafeConnect
          2015-02-22 12:46 - 2013-08-22 09:46 - 00040185 _____ () C:\Windows\setupact.log
          2015-02-22 12:45 - 2014-07-25 18:19 - 00000916 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
          2015-02-22 12:45 - 2013-08-22 09:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
          2015-02-22 12:43 - 2013-11-13 11:53 - 01209128 _____ () C:\Windows\PFRO.log
          2015-02-22 12:42 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\WinStore
          2015-02-21 18:26 - 2013-08-22 08:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
          2015-02-21 12:29 - 2014-07-25 18:04 - 00000000 ____D () C:\Users\nathanw
          2015-02-13 13:34 - 2014-10-05 01:36 - 00073728 _____ () C:\Windows\SysWOW64\tasks.dll
          2015-02-12 22:56 - 2013-08-22 09:44 - 00481880 _____ () C:\Windows\system32\FNTCACHE.DAT
          2015-02-12 22:54 - 2014-12-14 16:33 - 00000000 ____D () C:\Windows\system32\appraiser
          2015-02-12 22:54 - 2014-07-31 07:11 - 00000000 ___SD () C:\Windows\system32\CompatTel
          2015-02-12 22:54 - 2014-07-28 11:16 - 00000000 ____D () C:\Windows\system32\MRT
          2015-02-12 22:47 - 2014-07-28 11:16 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
          2015-02-12 22:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
          2015-02-12 16:05 - 2014-10-03 00:06 - 00000079 _____ () C:\Users\nathanw\AppData\Roaming\WB.CFG
          2015-02-10 17:52 - 2014-07-25 18:39 - 00000000 ____D () C:\Program Files (x86)\Steam
          2015-02-10 17:44 - 2014-07-25 18:05 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Packages
          2015-02-03 14:31 - 2014-08-02 10:51 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
          2015-02-03 14:31 - 2014-08-02 10:51 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
          2015-02-01 00:03 - 2014-09-09 16:40 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Adobe
          2015-01-31 23:53 - 2014-07-26 09:26 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
          2015-01-31 00:05 - 2014-07-25 18:19 - 00002285 _____ () C:\Users\Public\Desktop\Google Chrome.lnk

          ==================== Files in the root of some directories =======

          2014-10-03 00:06 - 2015-02-12 16:05 - 0000079 _____ () C:\Users\nathanw\AppData\Roaming\WB.CFG
          2014-09-01 22:04 - 2014-09-01 22:04 - 0000000 _____ () C:\Users\nathanw\AppData\Local\{C03E1153-99E9-4E26-8BFE-471025ABE5FF}

          Some content of TEMP:
          ====================
          C:\Users\nathanw\AppData\Local\Temp\5E138365-D139-D924-E7D3-05D364FB07C1.dll
          C:\Users\nathanw\AppData\Local\Temp\5E138365-D139-D924-E7D3-05D364FB07C1.exe
          C:\Users\nathanw\AppData\Local\Temp\7675_.exe
          C:\Users\nathanw\AppData\Local\Temp\8658_.exe
          C:\Users\nathanw\AppData\Local\Temp\9686FB06-6AC9-7F61-45F2-378B0915C505.exe
          C:\Users\nathanw\AppData\Local\Temp\amisetup0216__7675.exe
          C:\Users\nathanw\AppData\Local\Temp\amisetup2481__7675.exe
          C:\Users\nathanw\AppData\Local\Temp\amisetup4018__7675.exe
          C:\Users\nathanw\AppData\Local\Temp\amisetup4390__8658.exe
          C:\Users\nathanw\AppData\Local\Temp\amisetup5092__7675.exe
          C:\Users\nathanw\AppData\Local\Temp\amisetup5140__8658.exe
          C:\Users\nathanw\AppData\Local\Temp\amisetup5683__9288.exe
          C:\Users\nathanw\AppData\Local\Temp\amisetup5731__7675.exe
          C:\Users\nathanw\AppData\Local\Temp\ConsumerInputSetup.exe
          C:\Users\nathanw\AppData\Local\Temp\hotzenplotz.exe
          C:\Users\nathanw\AppData\Local\Temp\nsf2140.exe
          C:\Users\nathanw\AppData\Local\Temp\optprosetup.exe
          C:\Users\nathanw\AppData\Local\Temp\SpOrder.dll
          C:\Users\nathanw\AppData\Local\Temp\vcredist_x64.exe

          ==================== Bamital & volsnap Check =================

          (There is no automatic fix for files that do not pass verification.)

          C:\Windows\System32\winlogon.exe => File is digitally signed
          C:\Windows\System32\wininit.exe => File is digitally signed
          C:\Windows\explorer.exe => File is digitally signed
          C:\Windows\SysWOW64\explorer.exe => File is digitally signed
          C:\Windows\System32\svchost.exe => File is digitally signed
          C:\Windows\SysWOW64\svchost.exe => File is digitally signed
          C:\Windows\System32\services.exe => File is digitally signed
          C:\Windows\System32\User32.dll => File is digitally signed
          C:\Windows\SysWOW64\User32.dll => File is digitally signed
          C:\Windows\System32\userinit.exe => File is digitally signed
          C:\Windows\SysWOW64\userinit.exe => File is digitally signed
          C:\Windows\System32\rpcss.dll => File is digitally signed
          C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

          LastRegBack: 2015-02-12 23:30

          ==================== End Of Log ============================

           

          Addition

           

          Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-02-2015
          Ran by [removed] at 2015-02-22 13:36:48
          Running from C:\Users\[removed]\Desktop
          Boot Mode: Normal
          ==========================================================

          ==================== Security Center ========================

          (If an entry is included in the fixlist, it will be removed.)

          AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

          ==================== Installed Programs ======================

          (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

          µTorrent (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\uTorrent) (Version: 3.4.2.36802 - BitTorrent Inc.)
          Adobe Reader XI (11.0.10) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
          Apple Application Support (HKLM-x32\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
          Apple Mobile Device Support (HKLM\…\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
          Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
          Battery Calibration (HKLM-x32\…\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.1402.2101 - Micro-Star International Co., Ltd.)
          BioShock Infinite (HKLM-x32\…\Steam App 8870) (Version:  - Irrational Games)
          Bitcoin Core (64-bit) (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Bitcoin Core (64-bit)) (Version: 0.9.2 - Bitcoin Core project)
          Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
          Boot Configure (HKLM\…\{5DEFD958-7239-4FA0-8B4E-3B532D7A14BF}) (Version: 10.014.02075 - Application)
          BurnRecovery (HKLM-x32\…\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 4.0.1309.301 - )
          Chivalry: Medieval Warfare (HKLM-x32\…\Steam App 219640) (Version:  - Torn Banner Studios)
          CinPlus-Pro 2.5pV31.01 (HKLM-x32\…\CinPlus-Pro 2.5pV31.01) (Version: 1.36.01.22 - CinPlus-Pro 2.5pV31.01) <==== ATTENTION
          Counter-Strike: Global Offensive (HKLM-x32\…\Steam App 730) (Version:  - Valve)
          CyberGhost 5 (HKLM\…\CyberGhost 5_is1) (Version:  - CyberGhost S.R.L.)
          CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5509.52 - CyberLink Corp.)
          D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
          Dragon Gaming Center (HKLM-x32\…\InstallShield_{965B16C7-0778-4C45-B7D1-83A59E6FBBCB}) (Version: 1.0.1403.0501 - Micro-Star International Co., Ltd.)
          Dragon Gaming Center (x32 Version: 1.0.1403.0501 - Micro-Star International Co., Ltd.) Hidden
          ETDWare PS/2-X64 11.13.6.2_WHQL (HKLM\…\Elantech) (Version: 11.13.6.2 - ELAN Microelectronic Corp.)
          FlacSquisher 1.3.4 (HKLM-x32\…\FlacSquisher) (Version: 1.3.4 - FlacSquisher)
          Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
          Galeria de Fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
          Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
          Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
          GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
          Google Chrome (HKLM-x32\…\Google Chrome) (Version: 40.0.2214.94 - Google Inc.)
          Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
          GU Player (remove only) (HKLM-x32\…\GU Player) (Version:  - )
          Hitman: Absolution (HKLM-x32\…\Steam App 203140) (Version:  - IO Interactive)
          Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\…\{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}) (Version: 1.1.0.36960 - Intel Corporation)
          Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
          Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
          Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 17.0.1405.3) (HKLM\…\{302600C1-6BDF-4FD1-1312-148929CC1385}) (Version: 17.0.1312.0414 - Intel Corporation)
          Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.2.1000 - Intel Corporation)
          Intel® PROSet/Wireless Software (HKLM-x32\…\{105fa5c4-72e1-41f2-a82c-884d8aa4b381}) (Version: 16.6.0 - Intel Corporation)
          Intelli Term 1.10.0.8 (HKLM-x32\…\IntelliTerm_1.10.0.8) (Version: 1.10.0.8 - Intelli Term)
          iTunes (HKLM\…\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
          Just Cause 2 (HKLM-x32\…\Steam App 8190) (Version:  - Avalanche Studios)
          Just Cause 2: Multiplayer Mod (HKLM-x32\…\Steam App 259080) (Version:  - Avalanche Studios)
          KB9X Radio Switch Driver (HKLM\…\5AADE1068CF70DD983F763B20CF2CAAB72883915) (Version: 1.1.0.0 - ENE TECHNOLOGY INC.)
          K-Lite Codec Pack 10.6.5 Basic (HKLM-x32\…\KLiteCodecPack_is1) (Version: 10.6.5 - )
          Left 4 Dead 2 (HKLM-x32\…\Steam App 550) (Version:  - Valve)
          MAGIX MX Suite (HKLM-x32\…\MAGIX_{43136332-880B-458A-966C-900C18752B66}) (Version: 1.13.0.121 - MAGIX AG)
          MAGIX MX Suite (Version: 1.13.0.121 - MAGIX AG) Hidden
          Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
          McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
          Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\…\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
          Microsoft Office 365 - en-us (HKLM\…\O365HomePremRetail - en-us) (Version: 15.0.4675.1003 - Microsoft Corporation)
          Microsoft OneDrive (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
          Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
          Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
          Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
          Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
          Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
          Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
          Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
          Mozilla Firefox 35.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla)
          Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla)
          MSI Remind Manager (HKLM-x32\…\InstallShield_{3E23F267-3E35-40F9-B6BF-BC034D214717}) (Version: 1.0.1404.1101 - Micro-Star International Co., Ltd.)
          MSI Remind Manager (x32 Version: 1.0.1404.1101 - Micro-Star International Co., Ltd.) Hidden
          MSI Social Media Collection (HKLM-x32\…\{7ADEC426-BE95-48EF-84D4-086BD0F4D331}) (Version: 1.14.2251 - Micro-Star International Co., Ltd.)
          Norton Anti-Theft (HKLM-x32\…\NAT) (Version: 1.10.0.9 - Symantec Corporation)
          Norton Online Backup (HKLM-x32\…\{652C1CDF-C61D-4525-9348-8C272CC2DB24}) (Version: 2.10.1.3 - Symantec Corporation)
          Norton Online Backup (x32 Version: 4.5.0.9 - Symantec Corporation) Hidden
          NVIDIA GeForce Experience 1.7.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.7.1 - NVIDIA Corporation)
          NVIDIA Graphics Driver 332.35 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.35 - NVIDIA Corporation)
          NVIDIA PhysX (HKLM-x32\…\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
          NVIDIA Virtual Audio 1.2.9 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.9 - NVIDIA Corporation)
          Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
          Office 15 Click-to-Run Licensing Component (Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
          Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
          PAYDAY 2 (HKLM-x32\…\Steam App 218620) (Version:  - OVERKILL - a Starbreeze Studio.)
          Pirates (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Pirates) (Version:  - Pirates) <==== ATTENTION!
          Popcorn Time (HKLM-x32\…\Popcorn Time_is1) (Version: Beta 4.3 - Popcorn Time)
          PunkBuster Services (HKLM-x32\…\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
          Qualcomm Atheros Bandwidth Control Filter Driver (Version: 1.1.41.1283 - Qualcomm Atheros) Hidden
          Qualcomm Atheros Killer E220x Drivers (Version: 1.1.41.1283 - Qualcomm Atheros) Hidden
          Qualcomm Atheros Network Manager (Version: 1.1.41.1283 - Qualcomm Atheros) Hidden
          Qualcomm Atheros Performance Suite (HKLM-x32\…\{68DD86DD-8E02-4921-926B-B358D51EAF3A}) (Version: 1.1.41.1283 - Qualcomm Atheros)
          Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21249 - Realtek Semiconductor Corp.)
          Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7179 - Realtek Semiconductor Corp.)
          Rising Storm/Red Orchestra 2 Multiplayer (HKLM-x32\…\Steam App 35450) (Version:  - Tripwire Interactive)
          SafeConnect (HKLM-x32\…\SafeConnect) (Version:  - )
          SCM (HKLM\…\{6692DCAF-A445-4C6B-AF31-3DD85FC06FBA}) (Version: 13.014.01026 - Application)
          SHIELD Streaming (Version: 1.6.53 - NVIDIA Corporation) Hidden
          Skype™ 6.21 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
          Sniper Elite V2 (HKLM-x32\…\Steam App 63380) (Version:  - Rebellion)
          Sound Blaster Cinema (HKLM-x32\…\{8801CA65-921A-4CCC-9D63-879D1D0BAA97}) (Version: 1.00.05 - Creative Technology Limited)
          Steam (HKLM-x32\…\Steam) (Version:  - Valve Corporation)
          SteelSeries Engine (HKLM\…\SteelSeries Engine) (Version: 2.8.417.28061 - SteelSeries)
          SteelSeries Engine 3.2.6 (HKLM\…\SteelSeries Engine 3) (Version: 3.2.6 - SteelSeries ApS)
          SUPER CHARGER (HKLM-x32\…\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.024 - MSI)
          TAP-Windows 9.9.2 (HKLM\…\TAP-Windows) (Version: 9.9.2 - )
          TheAnswerFinder (HKLM\…\TheAnswerFinder) (Version: 1.0.7 - TheAnswerFinder)
          Unchecky v0.3.6 (HKLM-x32\…\Unchecky) (Version: 0.3.6 - RaMMicHaeL)
          Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
          WinZip 17.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DD}) (Version: 17.5.10562 - WinZip Computing, S.L. )
          XSplit Gamecaster (HKLM-x32\…\{9C3D0D0D-3983-4C18-91EE-C6976D5AA349}) (Version: 1.5.1403.1907 - SplitMediaLabs)
          フォト ギャラリー (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
          معرض الصور (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
          사진 갤러리 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
          影像中心 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
          照片库 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden

          ==================== Custom CLSID (selected items): ==========================

          (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

          CustomCLSID: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
          CustomCLSID: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\nathanw\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation)

          ==================== Restore Points  =========================

          10-01-2015 13:20:58 Scheduled Checkpoint
          15-01-2015 17:11:02 Windows Update
          23-01-2015 16:25:18 Windows Update
          27-01-2015 14:22:22 Windows Update
          08-02-2015 02:44:12 Windows Update
          12-02-2015 22:46:25 Windows Update
          22-02-2015 12:50:36 Removed Sophos Virus Removal Tool.

          ==================== Hosts content: ==========================

          (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

          2013-08-22 08:25 - 2015-02-22 12:46 - 00002034 ____A C:\Windows\system32\Drivers\etc\hosts
          0.0.0.0         .psf
          0.0.0.0         psf
          0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
          0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
          0.0.0.0 media.opencandy.com
          0.0.0.0 cdn.opencandy.com
          0.0.0.0 tracking.opencandy.com
          0.0.0.0 api.opencandy.com
          0.0.0.0 installer.betterinstaller.com
          0.0.0.0 installer.filebulldog.com
          0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
          0.0.0.0 inno.bisrv.com
          0.0.0.0 nsis.bisrv.com
          0.0.0.0 cdn.file2desktop.com
          0.0.0.0 cdn.goateastcach.us
          0.0.0.0 cdn.guttastatdk.us
          0.0.0.0 cdn.inskinmedia.com
          0.0.0.0 cdn.insta.oibundles2.com
          0.0.0.0 cdn.insta.playbryte.com
          0.0.0.0 cdn.llogetfastcach.us
          0.0.0.0 cdn.montiera.com
          0.0.0.0 cdn.msdwnld.com
          0.0.0.0 cdn.mypcbackup.com
          0.0.0.0 cdn.ppdownload.com
          0.0.0.0 cdn.riceateastcach.us
          0.0.0.0 cdn.shyapotato.us
          0.0.0.0 cdn.solimba.com
          0.0.0.0 cdn.tuto4pc.com
          0.0.0.0 cdn.appround.biz

          There are 6 more lines.

          ==================== Scheduled Tasks (whitelisted) =============

          (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

          Task: {0A149050-CB32-4D8F-B30C-F6EBB0DD48B7} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
          Task: {1148FEDC-2318-4CE0-B90A-1D8A08101811} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-11-04] (Microsoft Corporation)
          Task: {1D2EEDB0-5261-49E9-BB5E-16C39A65F68A} - System32\Tasks\Jelbrus Secure Web Task => C:\Program Files (x86)\Jelbrus Secure Web\jswtask.exe [2014-11-12] (Jelbrus)
          Task: {221BCF22-52D9-40FB-80E7-59972D7D690A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-25] (Google Inc.)
          Task: {27902362-EB83-4D3D-A103-522639358B67} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
          Task: {33751216-1BFC-4DBC-8F1C-5FBE754275FD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
          Task: {33D088CC-A6F3-49A3-B1E2-9F5A631F3C01} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-11-11] (Microsoft Corporation)
          Task: {3AA138B5-2D43-4CCF-B530-AA2BE0364E46} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
          Task: {76E2425C-A76D-474B-849F-A0559AF55CEC} - System32\Tasks\MSI_Reminder => C:\Program Files (x86)\MSI\MSI Remind Manager\MSI Reminder.exe [2014-04-09] ()
          Task: {7A748A39-6A0C-4183-8156-DDAE70169665} - System32\Tasks\MSI_Dragon Gaming Center => C:\Program Files (x86)\MSI\Dragon Gaming Center\mDispatch.exe [2014-01-23] (TODO: <公司名稱>)
          Task: {7CAB2EFE-2186-46C1-A3CE-97EF4BD8545A} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\SymErr.exe [2013-08-01] (Symantec Corporation)
          Task: {88A5AFC4-DC21-4E20-89E3-98A157FBEAC1} - \Vosteran dota No Task File <==== ATTENTION
          Task: {919C7BC8-ECD6-43B9-992C-F773CD90DD4C} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\SymErr.exe [2013-08-01] (Symantec Corporation)
          Task: {9F864D16-AF45-449F-AE4D-8FCDDD9207A2} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-02-12] (Microsoft Corporation)
          Task: {A794D80B-4551-461A-B1A4-B6F820D9221E} - System32\Tasks\CIMT_daily_S-1-5-21-3104748373-4178966826-1034322177-1002 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
          Task: {B64F17F9-AF2D-4B1F-A85F-F7ACAE2354C2} - \GPUP No Task File <==== ATTENTION
          Task: {CFCA9BE6-17E8-41A4-96E5-411ADBABFB4C} - System32\Tasks\CIMT_S-1-5-21-3104748373-4178966826-1034322177-1002 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
          Task: {D069AC4D-3961-45D9-91A7-663AD5EF9DBF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-25] (Google Inc.)
          Task: {FF72D8AC-2CB8-4CDA-8C41-73EC2C1FD75D} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-3104748373-4178966826-1034322177-1002 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

          ==================== Loaded Modules (whitelisted) ==============

          2014-04-24 15:50 - 2014-01-07 19:48 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
          2014-11-21 23:40 - 2014-09-23 08:36 - 08897696 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
          2014-01-22 12:44 - 2014-01-22 12:44 - 00075912 _____ () C:\Program Files (x86)\MSI\Dragon Gaming Center\WinIo64.dll
          2013-05-23 11:15 - 2013-05-23 11:15 - 00025600 _____ () C:\Program Files (x86)\MSI\Dragon Gaming Center\CoreAudioApi.dll
          2015-01-28 23:28 - 2015-01-28 23:28 - 00044544 _____ () C:\Program Files\ChromeEnhancer\ChromeEnhancer.exe
          2014-08-10 22:01 - 2014-05-20 08:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
          2015-01-28 23:28 - 2015-01-28 23:28 - 00010240 _____ () C:\Program Files\ChromeEnhancer\ChromeEnhancerMonitor32.exe
          2014-09-11 17:22 - 2014-10-28 19:21 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
          2014-04-24 16:09 - 2012-11-01 13:23 - 00089600 _____ () C:\Windows\SYSTEM32\CmdRtr64.DLL
          2014-04-24 16:09 - 2012-11-01 13:21 - 00325120 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL
          2014-01-23 10:15 - 2014-01-23 10:15 - 00758784 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\SSEngineLib.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00175104 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\DBUtils.dll
          2014-07-25 18:07 - 2014-07-25 18:07 - 00089915 _____ () C:\Users\nathanw\AppData\Local\Temp\fcaa5f9b-83be-462f-bb26-c1541883b2c0\CliSecureRT64.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00287744 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\DriverCommunication.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00140288 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\ISSPlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00148480 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\Localization.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00145408 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\Utilities.dll
          2013-01-10 00:46 - 2013-01-10 00:46 - 00047616 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesDrivers\x2api.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 09633280 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\SSEngineWinGui.dll
          2013-01-10 00:46 - 2013-01-10 00:46 - 01102336 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\System.Data.SQLite.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00209408 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\CustomWPFColorPicker.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00349696 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\MousePlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00171008 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\D3MousePlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00173056 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\KKMousePlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00171008 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\SRawPlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00307200 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\MLGSenseiPlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00154624 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\WoWGoldPlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00170496 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\GW2MousePlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00169472 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\CSGOMousePlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00169984 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\DOTA2MousePlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00157184 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\WoWWirelessPlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00170496 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\CODMousePlugin.dll
          2014-01-23 10:15 - 2014-01-23 10:15 - 00169984 _____ () C:\Program Files\SteelSeries\SteelSeries Engine\WoTMousePlugin.dll
          2014-03-04 15:16 - 2014-03-04 15:16 - 00300544 _____ () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
          2015-01-28 23:28 - 2015-01-28 23:28 - 00053248 _____ () C:\Program Files\ChromeEnhancer\bhelper.dll
          2015-02-01 00:04 - 2015-02-01 00:04 - 00058880 _____ () C:\Program Files (x86)\Unchecky\bin\collector.dll
          2014-07-03 13:20 - 2014-07-03 13:20 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
          2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
          2014-04-24 15:46 - 2013-09-16 14:17 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
          2010-12-17 14:56 - 2010-12-17 14:56 - 02603520 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll
          2013-03-07 14:53 - 2013-03-07 14:53 - 00015872 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll
          2010-12-17 14:56 - 2010-12-17 14:56 - 01006592 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll
          2010-12-17 14:56 - 2010-12-17 14:56 - 00382464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll
          2010-01-12 18:55 - 2010-01-12 18:55 - 00400384 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll
          2010-01-12 18:55 - 2010-01-12 18:55 - 00322048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll
          2010-12-16 14:16 - 2010-12-16 14:16 - 00195584 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll
          2010-01-18 01:34 - 2010-01-18 01:34 - 00062464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll
          2013-03-07 14:55 - 2013-03-07 14:55 - 00472576 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll
          2013-03-07 14:58 - 2013-03-07 14:58 - 00499488 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll
          2013-03-07 14:54 - 2013-03-07 14:54 - 00013824 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll

          ==================== Alternate Data Streams (whitelisted) =========

          (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

          ==================== Safe Mode (whitelisted) ===================

          (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\OptimizerMonitor => ""="service"

          ==================== EXE Association (whitelisted) ===============

          (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

          ==================== Other Areas ============================

          (Currently there is no automatic fix for this section.)

          HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\nathanw\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
          DNS Servers: 192.168.1.127

          ==================== MSCONFIG/TASK MANAGER disabled items ==

          (Currently there is no automatic fix for this section.)

          ==================== Accounts: =============================

          Administrator (S-1-5-21-3104748373-4178966826-1034322177-500 - Administrator - Disabled)
          Guest (S-1-5-21-3104748373-4178966826-1034322177-501 - Limited - Disabled)
          HomeGroupUser$ (S-1-5-21-3104748373-4178966826-1034322177-1004 - Limited - Enabled)
          nathanw (S-1-5-21-3104748373-4178966826-1034322177-1002 - Administrator - Enabled) => C:\Users\nathanw
          UpdatusUser (S-1-5-21-3104748373-4178966826-1034322177-1001 - Limited - Enabled) => C:\Users\UpdatusUser

          ==================== Faulty Device Manager Devices =============

          Name: TAP-Windows Adapter V9
          Description: TAP-Windows Adapter V9
          Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
          Manufacturer: TAP-Windows Provider V9
          Service: tap0901
          Problem: : This device is disabled. (Code 22)
          Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

          ==================== Event log errors: =========================

          Application errors:
          ==================
          Error: (02/22/2015 01:22:09 PM) (Source: SideBySide) (EventID: 9) (User: )
          Description: Activation context generation failed for "1".Error in manifest or policy file "2" on line 3.
          The manifest file root element must be assembly.

          Error: (02/22/2015 00:55:57 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
          Description: Subscription licensing service failed: -2143485919

          Error: (02/22/2015 00:55:57 PM) (Source: Microsoft Office 15) (EventID: 2011) (User: )
          Description: Office Subscription licensing exception: Error Code: 0x803D0021; CorrelationId: {7C110DA5-22E6-4416-A30B-5AAE6F1893B3}

          Error: (02/22/2015 00:52:42 PM) (Source: Application Error) (EventID: 1000) (User: )
          Description: Faulting application name: speedtray.exe, version: 0.0.0.0, time stamp: 0x548a3236
          Faulting module name: speedtray.exe, version: 0.0.0.0, time stamp: 0x548a3236
          Exception code: 0xc0000005
          Fault offset: 0x00026c73
          Faulting process id: 0xc40
          Faulting application start time: 0xspeedtray.exe0
          Faulting application path: speedtray.exe1
          Faulting module path: speedtray.exe2
          Report Id: speedtray.exe3
          Faulting package full name: speedtray.exe4
          Faulting package-relative application ID: speedtray.exe5

          Error: (02/22/2015 00:49:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
          Description: The program PerforMax Cleaner.exe version 1.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

          Process ID: 15c4

          Start Time: 01d04ec7aa3534c0

          Termination Time: 4294967295

          Application Path: C:\Program Files (x86)\PerforMax Cleaner\PerforMax Cleaner.exe

          Report Id: 1fc45dc1-babb-11e4-82ab-303a6412db7f

          Faulting package full name:

          Faulting package-relative application ID:

          Error: (02/22/2015 00:48:45 PM) (Source: IntelDalJhi) (EventID: 11) (User: )
          Description: Intel(R) Dynamic Application Loader Host Interface Service has encountered an internal connection problem.

          Error: (02/22/2015 00:45:57 PM) (Source: PerfNet) (EventID: 2004) (User: )
          Description:

          Error: (02/22/2015 00:45:56 PM) (Source: Perflib) (EventID: 1008) (User: )
          Description: BITSC:\Windows\System32\bitsperf.dll8

          System errors:
          =============
          Error: (02/22/2015 01:19:18 PM) (Source: DCOM) (EventID: 10010) (User: Nathan)
          Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

          Error: (02/22/2015 01:18:48 PM) (Source: DCOM) (EventID: 10010) (User: Nathan)
          Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

          Error: (02/22/2015 00:46:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
          Description: The CyberGhost 5 Client Service service failed to start due to the following error:
          %%1053

          Error: (02/22/2015 00:46:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
          Description: A timeout was reached (30000 milliseconds) while waiting for the CyberGhost 5 Client Service service to connect.

          Error: (02/22/2015 00:45:59 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
          Description: A timeout was reached (30000 milliseconds) while waiting for the Optimizer Pro Crash Monitor service to connect.

          Error: (02/22/2015 00:44:47 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
          Description: 1084WSearchUnavailable{9E175B68-F52A-11D8-B9A5-505054503030}

          Error: (02/22/2015 00:44:47 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
          Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}

          Error: (02/22/2015 00:44:18 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
          Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}

          Error: (02/22/2015 00:44:13 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
          Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}

          Error: (02/22/2015 00:44:03 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
          Description: 1084WSearchUnavailable{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

          Microsoft Office Sessions:
          =========================
          Error: (02/22/2015 01:22:09 PM) (Source: SideBySide) (EventID: 9) (User: )
          Description: C:\Program Files\WinZip\adxloader.dll.ManifestC:\Program Files\WinZip\adxloader.dll.Manifest2

          Error: (02/22/2015 00:55:57 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
          Description: Subscription licensing service failed: -2143485919

          Error: (02/22/2015 00:55:57 PM) (Source: Microsoft Office 15) (EventID: 2011) (User: )
          Description: Office Subscription licensing exception: Error Code: 0x803D0021; CorrelationId: {7C110DA5-22E6-4416-A30B-5AAE6F1893B3}

          Error: (02/22/2015 00:52:42 PM) (Source: Application Error) (EventID: 1000) (User: )
          Description: speedtray.exe0.0.0.0548a3236speedtray.exe0.0.0.0548a3236c000000500026c73c4001d04ec7a8219fd5C:\Users\nathanw\AppData\Roaming\SpeedTray\speedtray.exeC:\Users\nathanw\AppData\Roaming\SpeedTray\speedtray.exe98ca4ed0-babb-11e4-82ab-303a6412db7f

          Error: (02/22/2015 00:49:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
          Description: PerforMax Cleaner.exe1.0.0.015c401d04ec7aa3534c04294967295C:\Program Files (x86)\PerforMax Cleaner\PerforMax Cleaner.exe1fc45dc1-babb-11e4-82ab-303a6412db7f

          Error: (02/22/2015 00:48:45 PM) (Source: IntelDalJhi) (EventID: 11) (User: )
          Description:

          Error: (02/22/2015 00:45:57 PM) (Source: PerfNet) (EventID: 2004) (User: )
          Description:

          Error: (02/22/2015 00:45:56 PM) (Source: Perflib) (EventID: 1008) (User: )
          Description: BITSC:\Windows\System32\bitsperf.dll8

          CodeIntegrity Errors:
          ===================================
            Date: 2015-02-22 13:32:15.164
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

            Date: 2015-02-22 13:32:15.070
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

            Date: 2015-02-22 13:32:14.976
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

            Date: 2015-02-22 13:32:14.867
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

            Date: 2015-02-22 13:32:14.773
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

            Date: 2015-02-22 13:32:14.679
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

            Date: 2015-02-22 13:32:14.460
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

            Date: 2015-02-22 13:32:14.351
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

            Date: 2015-02-22 13:32:14.257
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

            Date: 2015-02-22 13:32:14.085
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

          ==================== Memory info ===========================

          Processor: Intel(R) Core(TM) i7-4710HQ CPU @ 2.50GHz
          Percentage of memory in use: 32%
          Total physical RAM: 8111.19 MB
          Available physical RAM: 5455.68 MB
          Total Pagefile: 10287.19 MB
          Available Pagefile: 7321.68 MB
          Total Virtual: 131072 MB
          Available Virtual: 131071.84 MB

          ==================== Drives ================================

          Drive c: (OS_Install) (Fixed) (Total:580.74 GB) (Free:377.86 GB) NTFS
          Drive d: (Data) (Fixed) (Total:334.57 GB) (Free:293.13 GB) NTFS

          ==================== MBR & Partition Table ==================

          ========================================================
          Disk: 0 (Size: 931.5 GB) (Disk ID: BF003083)

          Partition: GPT Partition Type.

          ==================== End Of Log ============================

          I am attaching a FIXLIST file, you need to save it to your desktop where you have FRST64 or the fix wont work, after you download it open up FRST64 and click on FIX ( Not Scan ), it wont take long, after it reboots your system you will find a FIXLOG file on your desktop, post it please

          Attachments:

          Ask AI

          AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

          Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI