This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with pop ups. Programs listed with "" publisher [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Lots of thanks in advance helpers!!! 

I just recently noticed a rash of pop ups and some trouble getting youtube videos to load. There are some programs listed in my control panel with "" as the publisher and I can't remove them, I think they might be the culprit. Spybot isn't picking anything up. 
As per the FAQ here are the aswmbr log, the frst log, and the addition log. 
Also, I live in South Korea, so if I dont' respond promptly, it's likely due to the time difference or some sort of work hold up. I really appreciate any help!

aswmbr: 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-03-23 18:24:25
—————————–
18:24:25.597    OS Version: Windows x64 6.1.7601 Service Pack 1
18:24:25.597    Number of processors: 4 586 0x2A07
18:24:25.598    ComputerName: SS-PC  UserName: SS
18:24:26.891    Initialize success
18:24:26.967    VM: initialized successfully
18:24:26.970    VM: Intel CPU supported 
18:24:29.462    VM: supported disk I/O iaStor.sys
18:25:49.368    AVAST engine defs: 15032201
18:25:56.860    The log file has been saved successfully to "C:\Users\SS\Desktop\aswMBR.txt"
 
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-03-23 18:34:25
—————————–
18:34:25.834    OS Version: Windows x64 6.1.7601 Service Pack 1
18:34:25.834    Number of processors: 4 586 0x2A07
18:34:25.850    ComputerName: SS-PC  UserName: SS
18:34:26.505    Initialize success
18:34:26.505    VM: initialized successfully
18:34:26.521    VM: Intel CPU supported 
18:34:28.352    VM: supported disk I/O iaStor.sys
18:34:35.331    The log file has been saved successfully to "C:\Users\SS\Desktop\aswMBR.txt"
 
 
Here's the frst log:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by [removed] (administrator) on SS-PC on 23-03-2015 18:29:47
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(BitTorrent Inc.) C:\Users\SS\AppData\Roaming\BitTorrent\BitTorrent.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\MovieColorEnhancer.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\WifiManager.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\SmartSetting.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Eco Mode\SmartEco.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Daum Kakao Corp. ) C:\Program Files (x86)\Kakao\KakaoTalk\KakaoTalk.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\EasySpeedUpManager.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Gretech Corp.) C:\Program Files (x86)\GRETECH\GomPlayer\GOM.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11895400 2011-06-25] (Realtek Semiconductor)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2588968 2010-11-13] (ELAN Microelectronics Corp.)
HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-09] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [BitTorrent] => C:\Users\SS\AppData\Roaming\BitTorrent\BitTorrent.exe [1744472 2015-03-04] (BitTorrent Inc.)
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [ctfmon] => C:\windows\system32\ctfmon.exe [9728 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [Spybot-S&D; Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\MountPoints2: {9a7c915e-34b5-11e2-bdd9-806e6f6e6963} - E:\PLAY.EXE "playlist.m3u"
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\MountPoints2: {b02a9a3b-7a26-11e2-b71f-50b7c307cd39} - F:\LGAutoRun.exe
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Bubbles.scr [899584 2010-11-21] (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.samsung.com/sec
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
URLSearchHook: HKLM-x32 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
URLSearchHook: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=SMSTDF&pc;=MASM&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=SMSTDF&pc;=MASM&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001 -> DefaultScope {B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2} URL = http://www.baidu.com/s?wd={searchTerms}&ie;={inputEncoding}&oe;={outputEncoding}&abar;=2&tn;=20041099_oem_dg&ch;=33
SearchScopes: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001 -> {B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2} URL = http://www.baidu.com/s?wd={searchTerms}&ie;={inputEncoding}&oe;={outputEncoding}&abar;=2&tn;=20041099_oem_dg&ch;=33
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-02-10] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-02-10] (Microsoft Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-02-10] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler-x32: s-http - {D37E6C5F-1C0F-47C0-A3B6-403EEC555402} - C:\Program Files (x86)\Initech\SHTTP\InitechSHTTPInterface.11014.dll [2013-02-08] (© INITECH)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{83395AC7-FE87-4186-91C3-A6BE63F9820B}: [NameServer] 168.126.63.1,168.126.63.2
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=sc&ts;=1419837849&from;=smt&uid;=ST500LM012XHN-M500MBB_S2RSJ9ECA38311
 
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @qvod.com/QvodShare -> C:\Program Files (x86)\QvodPlayer\npShareModule_x64.dll No File
FF Plugin-x32: @ahnlab.com/asp/npaosmgr.1 -> C:\Program Files (x86)\AhnLab\ASP\Components\aosmgr\npaosmgr.dll [2014-08-05] (AhnLab, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-25] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-07-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @softforum.com/npxwebplugins -> C:\Program Files (x86)\SoftForum\XecureWeb\ActiveX\npxwebplugin.dll [2009-05-28] (SoftForum)
FF Plugin-x32: @softforum.com/npxwebplugins_file -> C:\Program Files (x86)\SoftForum\XecureWeb\ActiveX\npxwebplugin_file.dll [2009-05-28] (SoftForum Co., Ltd.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2015-01-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2015-01-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-10-16] (VideoLAN)
FF Plugin-x32: @wizvera.com/npVeraport20 -> C:\Program Files (x86)\Wizvera\Veraport20\npveraport20.dll [2013-11-15] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @iniline.com/npCrossWeb -> C:\Users\SS\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0AB9084F-0EF8-499a-A461-DE46D3C4A45B}\plugins\npCrossWeb.dll [2014-12-05] (INITECH Co., Ltd.)
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @initech.com/npSandBox -> C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.10052.dll [2014-11-27] (Initech Co., Ltd.)
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @qvod.com/QvodInsert -> C:\Program Files (x86)\QvodPlayer\npQvodInsert.dll No File
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\SS\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2014-10-29] (Google)
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @talk.google.com/O1DPlugin -> C:\Users\SS\AppData\Roaming\Mozilla\plugins\npo1d.dll [2014-10-29] (Google)
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @tools.google.com/Google Update;version=3 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @tools.google.com/Google Update;version=9 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin ProgramFiles/Appdata: C:\Users\SS\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2014-10-29] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\SS\AppData\Roaming\mozilla\plugins\npo1d.dll [2014-10-29] (Google)
FF Extension: INISAFE CrossWeb - C:\Users\SS\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0AB9084F-0EF8-499a-A461-DE46D3C4A45B} [2015-01-30]
FF HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.xpi
FF Extension: INISAFE SandBox - C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.xpi [2014-11-27]
 
Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Drive) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-15]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-15]
CHR Extension: (Chromebleed) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eeoekjnjgppnaegdjbcafdggilajhpic [2015-01-15]
CHR Extension: (AdBlock) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-15]
CHR Extension: (ActiveMail) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmbjhlidpnohinigphldbcffhikcill [2015-02-27]
CHR Extension: (StayFocusd) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2015-01-15]
CHR Extension: (Skype Click to Call) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-01-13]
CHR Extension: (Word CaptureX Extension) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjdepfkicdcciagbigfcmdhknnoaaegf [2014-12-29]
CHR Extension: (Youtube Preview  Is it worth watching) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nacgopecogaedhhjdfondlcobjofdhap [2015-02-27]
CHR Extension: (Google Wallet) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-15]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM-x32\…\Chrome\Extension: [mjdepfkicdcciagbigfcmdhknnoaaegf] - C:\Program Files (x86)\Deskperience\Word Capture\wcxChrome.crx [2010-07-23]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2714800 2015-02-10] (Microsoft Corporation)
R2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [498688 2011-11-21] (Red Bend Ltd.) [File not signed]
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [715656 2014-12-29] (Cherished Technololgy LIMITED)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] ()
S3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [986112 2011-11-21] (Intel(R) Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 AMonTDLH; C:\windows\system32\Drivers\AMonTDLH.sys [118072 2012-09-14] (AhnLab, Inc.)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2011-09-06] (Google Inc)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2011-09-06] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [35840 2011-09-06] (LG Electronics Inc.)
S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93184 2011-09-16] (LG Electronics Inc.)
S3 CdmDrvNt; C:\windows\system32\Drivers\CdmDrvNt.sys [25656 2009-07-21] (AhnLab, Inc.)
S3 MfFWEnt; C:\Program Files\AhnLab\ASP\MyFirewall 4.0\MfFWEnt.sys [127224 2014-07-16] (AhnLab, Inc.)
S3 MfIPSEnt; C:\Program Files\AhnLab\ASP\MyFirewall 4.0\MfIPSEnt.sys [156408 2014-07-16] (AhnLab, Inc.)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-11-23] (Windows (R) 2003 DDK 3790 provider)
S3 scsk5; C:\Windows\SysWow64\drivers\scsk5.sys [50608 2015-01-30] ()
S3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2013-05-29] (Spotflux, Inc.)
S3 AhnFlt2K; \??\C:\windows\system32\drivers\AhnFlt2K.sys [X]
S3 AhnRec2K; \??\C:\windows\system32\drivers\AhnRec2K.sys [X]
U3 aswMBR; \??\C:\Users\SS\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\SS\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-03-23 18:29 - 2015-03-23 18:30 - 00023647 _____ () C:\Users\SS\Downloads\FRST.txt
2015-03-23 18:28 - 2015-03-23 18:29 - 00000000 ____D () C:\FRST
2015-03-23 18:27 - 2015-03-23 18:27 - 02095616 _____ (Farbar) C:\Users\SS\Downloads\FRST64.exe
2015-03-23 18:25 - 2015-03-23 18:25 - 00000607 _____ () C:\Users\SS\Desktop\aswMBR.txt
2015-03-23 18:24 - 2015-03-23 18:24 - 05198336 _____ (AVAST Software) C:\Users\SS\Downloads\aswMBR.exe
2015-03-23 18:20 - 2015-03-23 18:20 - 00013540 _____ () C:\Users\SS\Downloads\hijackthis.log
2015-03-23 18:19 - 2015-03-23 18:19 - 00388608 _____ (Trend Micro Inc.) C:\Users\SS\Downloads\HijackThis.exe
2015-03-22 20:23 - 2015-03-22 20:24 - 00029419 _____ () C:\Users\SS\Downloads\C811E6A9B45648B43DCBF82059CC0E3B7E30AD39.torrent
2015-03-19 00:39 - 2015-03-19 00:39 - 00000000 ____D () C:\Users\SS\Downloads\BlowjobFridays - Yurizan Beltran - Dick Sucking at Its Finestt 720p [.mp4]
2015-03-19 00:38 - 2015-03-19 00:38 - 00024420 _____ () C:\Users\SS\Downloads\[kickass.to]blowjobfridays.yurizan.beltran.dick.sucking.at.its.finestt.720p.mp4.torrent
2015-03-18 18:38 - 2015-03-18 19:03 - 1010408247 _____ () C:\Users\SS\Downloads\chanel_preston_TT_1_JD_1080p_stream.mp4
2015-03-18 18:35 - 2015-03-18 18:36 - 00020065 _____ () C:\Users\SS\Downloads\0B8D68E97807B45D0210AE67A2B78CBF68E6EB46.torrent
2015-03-17 23:49 - 2015-03-18 17:26 - 272288145 _____ () C:\Users\SS\Downloads\BRAZZERS - Doctor Adventures - Doctors Without Bras - Kendra Lust - Rachel Starr [SM128].mkv
2015-03-17 23:48 - 2015-03-17 23:48 - 00011210 _____ () C:\Users\SS\Downloads\8524EBBAA3A6BE651BCA78519BE4F174F4FF80E3.torrent
2015-03-17 18:44 - 2015-03-17 18:44 - 00000000 ____D () C:\Users\SS\Downloads\HardX - Mia Malkova (Massive Anal Action) [.mp4]
2015-03-17 18:43 - 2015-03-17 18:43 - 00039875 _____ () C:\Users\SS\Downloads\[kickass.to]hardx.mia.malkova.massive.anal.action.mp4.torrent
2015-03-17 18:22 - 2015-03-17 18:22 - 00015500 _____ () C:\Users\SS\Downloads\9CD51BDDCDF5C3C59B9E1FFC5C99926E55925532.torrent
2015-03-17 18:22 - 2015-03-17 18:22 - 00000000 ____D () C:\Users\SS\Downloads\Blowjob Friday - Capri Cavanni (Serious BJ skills)
2015-03-16 18:51 - 2015-03-16 18:51 - 00000000 ____D () C:\Users\SS\AppData\Roaming\LavasoftStatistics
2015-03-16 18:46 - 2015-03-16 18:46 - 02057008 _____ () C:\Users\SS\Downloads\Adaware_Installer.exe
2015-03-14 11:49 - 2015-03-14 12:21 - 00000000 ____D () C:\Users\SS\Downloads\The Last Naruto The Movie 2014 720p HDCAM ENG SUBS x264 Pimp4003
2015-03-14 11:47 - 2015-03-14 11:47 - 00020522 _____ () C:\Users\SS\Downloads\[kickass.to]the.last.naruto.the.movie.2014.720p.hdcam.eng.subs.x264.pimp4003.torrent
2015-03-12 23:31 - 2015-03-12 23:58 - 480362658 _____ () C:\Users\SS\Downloads\t4k.dillion.harper.excited.little.slut.12.03.15_480.mp4
2015-03-12 23:31 - 2015-03-12 23:44 - 481824046 _____ () C:\Users\SS\Downloads\Digital_Playground_ge_34601_The_Fuck_Shop_480p_1500.mp4
2015-03-12 22:35 - 2015-03-12 22:37 - 339871297 _____ () C:\Users\SS\Downloads\BabyGotBoobs - Shawna Lenee - Up Close And Personal With Shawnas Tits  NEW (BRAZZERS  February 11, 2015) NEW.mp4
2015-03-12 21:15 - 2015-03-12 21:56 - 658123518 _____ () C:\Users\SS\Downloads\HotAndMean - Carter Cruise, Maddy Oreilly_480p.mp4
2015-03-11 21:27 - 2015-03-11 21:27 - 03471514 _____ () C:\Users\SS\Downloads\Introclass (1).pptx
2015-03-11 21:27 - 2015-03-11 21:27 - 00958942 _____ () C:\Users\SS\Downloads\Country Bingo.pptx
2015-03-11 18:28 - 2015-03-11 18:43 - 00000000 ____D () C:\Users\SS\Downloads\Sheena_Shaw_Wide_Open
2015-03-11 18:08 - 2015-02-20 13:41 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-03-11 18:08 - 2015-02-20 13:40 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-03-11 18:08 - 2015-02-20 13:40 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-03-11 18:08 - 2015-02-20 13:40 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-03-11 18:08 - 2015-02-20 13:13 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2015-03-11 18:08 - 2015-02-20 13:13 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-03-11 18:08 - 2015-02-20 13:13 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2015-03-11 18:08 - 2015-02-20 13:12 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2015-03-11 18:08 - 2015-02-20 12:29 - 00372224 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-03-11 18:08 - 2015-02-20 12:09 - 00299008 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-03-11 18:08 - 2015-02-03 12:34 - 05554104 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-03-11 18:08 - 2015-02-03 12:34 - 00094656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-03-11 18:08 - 2015-02-03 12:33 - 00616360 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2015-03-11 18:08 - 2015-02-03 12:31 - 14632960 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2015-03-11 18:08 - 2015-02-03 12:31 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2015-03-11 18:08 - 2015-02-03 12:31 - 01574400 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2015-03-11 18:08 - 2015-02-03 12:30 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-03-11 18:08 - 2015-02-03 12:30 - 01202176 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2015-03-11 18:08 - 2015-02-03 12:16 - 03973048 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-03-11 18:08 - 2015-02-03 12:16 - 03917760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-03-11 18:08 - 2015-02-03 12:12 - 11411968 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2015-03-11 18:08 - 2015-02-03 12:12 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2015-03-11 18:08 - 2015-02-03 12:12 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2015-03-11 18:08 - 2015-02-03 12:12 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2015-03-11 18:07 - 2015-02-03 12:34 - 00693176 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2015-03-11 18:07 - 2015-02-03 12:31 - 00782848 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00641024 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00432128 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00188416 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2015-03-11 18:07 - 2015-02-03 12:31 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2015-03-11 18:07 - 2015-02-03 12:30 - 01069056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00842240 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00680960 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00146944 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00126464 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
2015-03-11 18:07 - 2015-02-03 12:29 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
2015-03-11 18:07 - 2015-02-03 12:28 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-03-11 18:07 - 2015-02-03 12:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2015-03-11 18:07 - 2015-02-03 12:19 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2015-03-11 18:07 - 2015-02-03 12:12 - 01005056 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptui.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00988160 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmv2clt.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00744960 _____ (Microsoft Corporation) C:\windows\SysWOW64\blackbox.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00617984 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmdrmsdk.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscp.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00406016 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmmgrtn.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msnetobj.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00081408 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsp.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2015-03-11 18:07 - 2015-02-03 12:12 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2015-03-11 18:07 - 2015-02-03 12:11 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2015-03-11 18:07 - 2015-02-03 12:11 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2015-03-11 18:07 - 2015-02-03 12:11 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2015-03-11 18:07 - 2015-02-03 12:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2015-03-11 18:07 - 2015-02-03 12:08 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-03-11 18:07 - 2015-02-03 11:32 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2015-03-11 18:07 - 2014-11-01 07:24 - 00619056 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2015-03-11 18:06 - 2015-02-13 14:26 - 12875264 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-03-11 18:06 - 2015-02-13 14:22 - 14177280 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-03-11 18:06 - 2015-02-03 12:31 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
2015-03-11 18:06 - 2015-02-03 12:12 - 00171520 _____ (Microsoft Corporation) C:\windows\SysWOW64\ubpm.dll
2015-03-11 18:05 - 2015-03-06 14:56 - 00155576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-03-11 18:05 - 2015-03-06 14:56 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-03-11 18:05 - 2015-03-06 14:42 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-03-11 18:05 - 2015-03-06 14:41 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-03-11 18:05 - 2015-03-06 14:41 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-03-11 18:05 - 2015-03-06 14:39 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-03-11 18:05 - 2015-03-06 14:38 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-03-11 18:05 - 2015-03-06 14:36 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-03-11 18:05 - 2015-03-06 14:09 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-03-11 18:05 - 2015-03-06 14:09 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-03-11 18:05 - 2015-03-06 14:07 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-03-11 18:05 - 2015-03-06 14:07 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-03-11 18:05 - 2015-03-06 14:06 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-03-11 18:05 - 2015-02-26 12:25 - 03204096 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-03-11 18:05 - 2015-02-24 12:15 - 00389800 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-03-11 18:05 - 2015-02-24 11:32 - 00342696 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-03-11 18:05 - 2015-02-21 10:16 - 25021440 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-03-11 18:05 - 2015-02-21 09:41 - 12827648 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-03-11 18:05 - 2015-02-21 09:27 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-03-11 18:05 - 2015-02-21 09:27 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-03-11 18:05 - 2015-02-21 09:25 - 19720192 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-03-11 18:05 - 2015-02-21 08:58 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-03-11 18:05 - 2015-02-21 08:32 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-03-11 18:05 - 2015-02-20 12:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-03-11 18:05 - 2015-02-20 12:05 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-03-11 18:05 - 2015-02-20 11:50 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-03-11 18:05 - 2015-02-20 11:49 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-03-11 18:05 - 2015-02-20 11:49 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-03-11 18:05 - 2015-02-20 11:48 - 02886144 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-03-11 18:05 - 2015-02-20 11:47 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-03-11 18:05 - 2015-02-20 11:41 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-03-11 18:05 - 2015-02-20 11:40 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-03-11 18:05 - 2015-02-20 11:36 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-03-11 18:05 - 2015-02-20 11:35 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-03-11 18:05 - 2015-02-20 11:35 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-03-11 18:05 - 2015-02-20 11:34 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-03-11 18:05 - 2015-02-20 11:32 - 06035456 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-03-11 18:05 - 2015-02-20 11:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-03-11 18:05 - 2015-02-20 11:22 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-03-11 18:05 - 2015-02-20 11:22 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-03-11 18:05 - 2015-02-20 11:13 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 18:05 - 2015-02-20 11:09 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-03-11 18:05 - 2015-02-20 11:08 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-03-11 18:05 - 2015-02-20 11:08 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-03-11 18:05 - 2015-02-20 11:08 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-03-11 18:05 - 2015-02-20 11:06 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-03-11 18:05 - 2015-02-20 11:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-03-11 18:05 - 2015-02-20 11:03 - 02278400 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-03-11 18:05 - 2015-02-20 11:01 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-03-11 18:05 - 2015-02-20 11:00 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-03-11 18:05 - 2015-02-20 10:58 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-03-11 18:05 - 2015-02-20 10:56 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-03-11 18:05 - 2015-02-20 10:56 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-03-11 18:05 - 2015-02-20 10:49 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-03-11 18:05 - 2015-02-20 10:49 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-03-11 18:05 - 2015-02-20 10:47 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-03-11 18:05 - 2015-02-20 10:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-03-11 18:05 - 2015-02-20 10:43 - 14398976 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-03-11 18:05 - 2015-02-20 10:41 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-11 18:05 - 2015-02-20 10:37 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-03-11 18:05 - 2015-02-20 10:30 - 04300288 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-03-11 18:05 - 2015-02-20 10:28 - 02358784 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-03-11 18:05 - 2015-02-20 10:24 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-03-11 18:05 - 2015-02-20 10:24 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-03-11 18:05 - 2015-02-20 10:23 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-03-11 18:05 - 2015-02-20 10:16 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-03-11 18:05 - 2015-02-20 10:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-03-11 18:05 - 2015-02-20 10:01 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-03-11 18:05 - 2015-02-20 09:57 - 01311232 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-03-11 18:05 - 2015-02-20 09:55 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-03-11 18:05 - 2015-02-04 12:16 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2015-03-11 18:05 - 2015-02-04 11:54 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2015-03-11 18:05 - 2015-02-03 12:31 - 01424896 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-03-11 18:05 - 2015-02-03 12:12 - 01230848 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2015-03-11 18:05 - 2015-01-31 08:56 - 00459336 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-03-11 18:05 - 2015-01-17 11:48 - 01067520 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2015-03-11 18:05 - 2015-01-17 11:30 - 00828928 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2015-03-11 00:34 - 2015-03-11 00:34 - 00000000 ____D () C:\Users\SS\Downloads\[FuckedHard18] Morgan Layne [SD] [.wmv]
2015-03-08 20:59 - 2015-03-08 20:59 - 00147471 _____ () C:\Users\SS\Desktop\jim_aparo___batman_a_death_in_the_family_by_superman8193-d5tlylg-ben-affleck-as-batman-death-red-hood-arkham-asylum-and-hush-52c68877-489e-4ce1-a7c6-b0d2e04e2ed4.jpeg
2015-03-08 16:40 - 2015-03-08 16:40 - 00000000 ____D () C:\Users\SS\Downloads\EvilAngel.Kalina.Ryu.Sperm.Diet.mp4
2015-03-08 12:26 - 2015-03-08 23:20 - 2003577517 _____ () C:\Users\SS\Downloads\Saya_Song.mp4
2015-03-08 11:40 - 2015-03-08 11:40 - 00000000 ____D () C:\Users\SS\Downloads\[GFRevenge] Dillion Harper (Track star)[PornLeech]
2015-03-07 14:24 - 2015-03-07 14:24 - 00000000 ____D () C:\Users\SS\Downloads\James Deen - JESSIE ROGERS - Assfucked Til She Squirts [.mp4]
2015-03-07 14:22 - 2015-03-07 14:22 - 00000000 ____D () C:\Users\SS\Downloads\[Private] Tina Hot [Anal Introductions][1080p] [.mp4][PornLeech]
2015-03-06 18:04 - 2015-03-23 17:41 - 00000000 ____D () C:\Program Files (x86)\FuindBeSTDeal
2015-03-06 14:14 - 2015-03-06 14:18 - 00000000 ____D () C:\Users\SS\Downloads\BangBros - Big Mouthfuls - Simply 18 w Emma Mae HD 720p
2015-03-05 13:47 - 2015-03-05 13:47 - 00000000 ____D () C:\Users\SS\Downloads\[DigitalPlayground] Janice Griffith (50 Ways To Fuck) [.mp4]
2015-03-04 23:39 - 2015-03-04 23:48 - 03461639 _____ () C:\Users\SS\Downloads\Introclass.pptx
2015-02-27 14:34 - 2015-03-06 18:04 - 00000000 ____D () C:\Program Files (x86)\dollarkeeepper
2015-02-27 14:34 - 2015-02-27 14:34 - 00000000 ____D () C:\Program Files (x86)\ActiveMail
2015-02-27 12:13 - 2015-03-06 18:04 - 00000000 ____D () C:\Program Files (x86)\taakesavE
2015-02-27 12:12 - 2015-02-27 12:12 - 00000000 ____D () C:\Program Files (x86)\Youtube Preview  Is it worth watching
2015-02-27 11:12 - 2015-02-27 11:12 - 00000000 ____D () C:\Program Files (x86)\taKesaavve
2015-02-27 11:12 - 2015-02-27 11:12 - 00000000 ____D () C:\Program Files (x86)\coinsaove
2015-02-26 09:59 - 2015-02-26 09:59 - 00000000 ____D () C:\Program Files (x86)\Renren Album Downloader
2015-02-26 09:58 - 2015-02-27 12:13 - 00000000 ____D () C:\Program Files (x86)\DealExpREoss
2015-02-26 09:58 - 2015-02-26 09:58 - 00000000 ____D () C:\Program Files (x86)\DeealExpress
2015-02-26 09:19 - 2015-01-09 08:44 - 00419936 _____ () C:\windows\SysWOW64\locale.nls
2015-02-26 09:19 - 2015-01-09 08:43 - 00419936 _____ () C:\windows\system32\locale.nls
2015-02-23 17:37 - 2015-02-23 17:40 - 00000000 ____D () C:\Users\SS\Downloads\BaDoink.15.02.20.Marica.Haze.Mirrors.Edge.An.XXX.Parody.XXX.1080p.MP4.KTR
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-03-23 18:27 - 2012-12-05 23:35 - 00000000 ____D () C:\Users\SS\AppData\Roaming\BitTorrent
2015-03-23 18:20 - 2014-01-11 10:20 - 00000896 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA.job
2015-03-23 18:19 - 2012-12-05 21:28 - 00000000 ____D () C:\Users\SS\AppData\Local\VirtualStore
2015-03-23 17:44 - 2014-12-29 16:21 - 00000000 ____D () C:\ProgramData\2a436ad1c7d245ce
2015-03-23 17:40 - 2015-02-04 17:26 - 00000020 _____ () C:\Users\SS\AppData\Roaming\appdataFr3.bin
2015-03-23 17:34 - 2014-10-08 07:46 - 00000890 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-23 17:29 - 2012-04-21 21:43 - 01308133 _____ () C:\windows\WindowsUpdate.log
2015-03-23 17:13 - 2014-01-11 10:20 - 00000844 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core.job
2015-03-23 00:34 - 2014-10-08 07:46 - 00000886 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-22 22:14 - 2012-12-07 08:50 - 00000000 ____D () C:\Users\SS\AppData\Roaming\Skype
2015-03-21 12:21 - 2009-07-14 13:51 - 00155212 _____ () C:\windows\setupact.log
2015-03-21 11:29 - 2009-07-14 13:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-21 11:29 - 2009-07-14 13:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-20 06:19 - 2013-02-19 23:00 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-03-16 22:18 - 2009-07-14 14:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-16 19:42 - 2010-11-21 12:47 - 00661816 _____ () C:\windows\PFRO.log
2015-03-16 19:14 - 2015-01-18 11:47 - 00000000 ____D () C:\ProgramData\MiINImmumPrice
2015-03-16 19:14 - 2014-12-29 16:24 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2015-03-16 19:13 - 2014-12-29 16:21 - 00000000 ____D () C:\Program Files (x86)\Supporter
2015-03-14 15:11 - 2012-12-16 13:12 - 00000000 ____D () C:\Users\SS\AppData\Roaming\vlc
2015-03-14 01:40 - 2013-02-19 08:57 - 00000000 ____D () C:\Users\SS\Desktop\CARLOS
2015-03-12 15:41 - 2014-03-16 22:04 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-03-12 15:40 - 2012-04-21 06:13 - 00000000 ____D () C:\ProgramData\Skype
2015-03-12 15:35 - 2009-07-14 13:45 - 00370488 _____ () C:\windows\system32\FNTCACHE.DAT
2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\SysWOW64\tr-TR
2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\system32\tr-TR
2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\system32\Dism
2015-03-12 14:16 - 2013-12-09 22:51 - 00000000 ____D () C:\windows\system32\MRT
2015-03-12 14:02 - 2013-12-09 22:51 - 122905848 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-03-11 22:22 - 2012-12-05 22:00 - 00656980 _____ () C:\windows\system32\perfh01F.dat
2015-03-11 22:22 - 2012-12-05 22:00 - 00140326 _____ () C:\windows\system32\perfc01F.dat
2015-03-11 22:22 - 2012-04-21 21:15 - 00428722 _____ () C:\windows\system32\perfh012.dat
2015-03-11 22:22 - 2012-04-21 21:15 - 00120710 _____ () C:\windows\system32\perfc012.dat
2015-03-11 22:22 - 2009-07-14 14:13 - 02111596 _____ () C:\windows\system32\PerfStringBackup.INI
2015-03-11 21:29 - 2012-12-25 23:46 - 00000000 ____D () C:\Users\SS\AppData\Local\CrashDumps
2015-03-11 18:46 - 2012-12-19 23:09 - 00001173 _____ () C:\Users\SS\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2015-03-11 18:46 - 2012-12-19 23:09 - 00001149 _____ () C:\Users\Public\Desktop\GOM Player.lnk
2015-03-11 17:38 - 2015-02-06 16:05 - 00000000 ____D () C:\ProgramData\3045395222265742798
2015-02-27 12:13 - 2015-02-06 16:05 - 00000000 ____D () C:\Program Files (x86)\NewSaever
2015-02-26 10:02 - 2014-12-29 16:21 - 00000258 __RSH () C:\ProgramData\ntuser.pol
2015-02-21 01:00 - 2015-02-20 22:26 - 00000000 ____D () C:\Users\SS\Downloads\Revival [TPB]
 
==================== Files in the root of some directories =======
 
2015-02-04 17:26 - 2015-03-23 17:40 - 0000020 _____ () C:\Users\SS\AppData\Roaming\appdataFr3.bin
2013-08-20 00:12 - 2014-04-22 00:27 - 0000954 _____ () C:\Users\SS\AppData\Roaming\coreavc.ini
2012-04-21 06:07 - 2012-04-21 06:08 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2012-04-21 06:02 - 2012-04-21 06:02 - 0000113 _____ () C:\ProgramData\{34FBC7C4-CD31-4D93-A428-0E524EAC4586}.log
2012-04-21 06:05 - 2012-04-21 06:05 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2012-04-21 06:02 - 2012-04-21 06:05 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log
2012-04-21 06:05 - 2012-04-21 06:07 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
 
Some content of TEMP:
====================
C:\Users\SS\AppData\Local\Temp\SkypeSetup.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-03-15 12:54
 
==================== End Of Log ============================

And finally the addition log:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by [removed] at 2015-03-23 18:31:25
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
ActiveMail (HKLM-x32\…\{89AE616B-E500-0C2D-D0D2-F444CEEB4619}) (Version:  - "")
Adobe Flash Player 10 ActiveX (HKLM-x32\…\{48DB5914-8772-472D-B8DF-E2092BE598F6}) (Version: 10.3.181.34 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 - Korean (HKLM-x32\…\{AC76BA86-7AD7-1042-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
AhnLab Online Security (HKLM-x32\…\AhnLab Online Security) (Version:  - AhnLab, Inc)
Audacity 2.0.5 (HKLM-x32\…\Audacity_is1) (Version: 2.0.5 - Audacity Team)
BitTorrent (HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\BitTorrent) (Version: 7.9.2.38914 - BitTorrent Inc.)
calibre (HKLM-x32\…\{4BF56EFD-2F39-40F2-89BB-CF9D3550A806}) (Version: 2.17.0 - Kovid Goyal)
coinsaove (HKLM-x32\…\{C8AAF59A-6BAA-F68B-9470-A856460A8093}) (Version:  - "") <==== ATTENTION
ComicRack v0.9.156 (HKLM\…\ComicRack) (Version: v0.9.156 - cYo Soft)
CyberLink Media Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink Corp.)
CyberLink Media+ Player10 (HKLM-x32\…\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 - CyberLink Corp.)
CyberLink MediaShow (HKLM-x32\…\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1130a - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.)
CyberLink PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3306 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4417 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Easy Content Share (HKLM-x32\…\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD)
Easy Migration (HKLM-x32\…\{AD86049C-3D9C-43E1-BE73-643F57D83D50}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
EasyFileShare (HKLM-x32\…\{16880765-677F-440B-B16A-BFD9B9C00012}) (Version: 1.0.12 - Samsung)
Eco Mode (HKLM-x32\…\{9A8E4762-3331-4EDB-8E1F-B11179DDBC00}) (Version: 1.0.0.11 - Samsung Electronics Co., Ltd.)
E-POP (HKLM-x32\…\{75282161-8CAC-4071-A225-EBC95E43C7F3}) (Version: 1.00.0000 - Samsung)
ETDWare PS/2-X64 8.0.7.2_WHQL (HKLM\…\Elantech) (Version: 8.0.7.2 - ELAN Microelectronic Corp.)
GOM Player (HKLM-x32\…\GOM Player) (Version: 2.2.67.5221 - Gretech Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 39.0.2171.99 - Google Inc.)
Google Talk Plugin (HKLM-x32\…\{0C5C1177-94C5-3EFB-A8BE-3F6AF1AF887F}) (Version: 5.38.6.0 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Hanword HWP document converter for Microsoft Word (x64) (HKLM\…\{90150000-2009-0409-1000-0000000FF1CE}) (Version: 15.0.4454.1506 - Microsoft Corporation)
Hanword HWP document converter for Microsoft Word (x86) (HKLM-x32\…\{90150000-2009-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1506 - Microsoft Corporation)
INISAFE SandBox 1.0 (HKLM-x32\…\INISAFE SandBox) (Version: 1.0 - Initech, Inc.)
INISAFE Web v6.4 (HKLM-x32\…\UnINISafeWeb64) (Version: 6 - Initech ©.)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2266 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\…\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel)
Intel(R) WiDi (HKLM-x32\…\{E1B934BB-6AFA-429F-98E4-76F9CBC72BF6}) (Version: 2.2.14.0 - Intel Corporation)
Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Interactive Guide (HKLM-x32\…\{CB383BE9-7518-4ABD-826E-8FC4695F7D52}) (Version: 1.1 - )
Java 7 Update 67 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.670 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
KakaoTalk (HKLM-x32\…\KakaoTalk) (Version: 2.0.4.786 - Kakao)
LG United Mobile Drivers (HKLM-x32\…\{C2944BE7-9BFF-4EF0-A362-CB3281B7C50D}) (Version: 3.6.0.0 - LG Electronics)
Media Center 한글 입력기 (HKLM-x32\…\{BB9A1C85-8841-4755-A4D3-E3EEC3EFD3F0}) (Version: 3.1.5.0 - Samsung Electronics Co., LTD)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Home and Student 2013 - en-us (HKLM\…\HomeStudentRetail - en-us) (Version: 15.0.4701.1002 - Microsoft Corporation)
Microsoft Office 언어 교정 도구 2013 - 한국어 (HKLM-x32\…\{90150000-001F-0412-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MIniimumPricue (HKLM-x32\…\{CA1838EF-A497-194E-3850-37A62CEE398B}) (Version:  - "") <==== ATTENTION
Multimedia POP (HKLM-x32\…\{331ECF61-69AF-4F57-AC35-AFED610231C3}) (Version: 1.2 - )
NVIDIA 그래픽 드라이버 267.54 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.54 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Online Calculator (HKLM-x32\…\{B138259A-351E-33FA-2726-8D71704F1DA9}) (Version:  - "") <==== ATTENTION
PhoneShare (HKLM-x32\…\{3F50512F-53DF-46B1-8CCB-6C7E638CADD6}) (Version: 9.1.4 - Samsung)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6400 - Realtek Semiconductor Corp.)
Renren Album Downloader (HKLM-x32\…\{AF992111-52BE-832B-5882-8477E4A3C99A}) (Version:  - "") <==== ATTENTION
Samsung AnyWeb Print (HKLM-x32\…\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 2.0.67.1 - Samsung Electronics Co., Ltd.)
Samsung Control Center (HKLM-x32\…\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM-x32\…\Samsung Printer Live Update) (Version:  - Samsung Electronics Co., Ltd.)
Samsung Recovery Solution 5 (HKLM-x32\…\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.1.3 - Samsung)
Samsung Support Center (HKLM-x32\…\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.26 - Samsung)
Samsung Universal Print Driver (HKLM-x32\…\Samsung Universal Print Driver) (Version: 2.02.05.00:27 - Samsung Electronics Co., Ltd.)
Samsung Universal Scan Driver (HKLM-x32\…\Samsung Universal Scan Driver) (Version: 1.2.5.0 - Samsung Electronics Co., Ltd.)
Samsung Update Plus (HKLM-x32\…\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.0.17 - Samsung Electronics Co., Ltd.)
SISShortcut (HKLM-x32\…\{FDAE128F-A355-42B1-8422-1AF3ACEE34F4}) (Version: 1.00.000 - Samsung)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.1 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
User Guide (HKLM-x32\…\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.3 - )
Veraport20(Security module management) - 2,5,6,1 (HKLM-x32\…\{2D992E01-604B-472C-A883-1DDA105A24D5}_is1) (Version: 2,5,6,1 - Wizvera)
VLC media player 2.0.4 (HKLM-x32\…\VLC media player) (Version: 2.0.4 - VideoLAN)
Vuze Remote Toolbar (HKLM-x32\…\Vuze_Remote Toolbar) (Version: 6.9.0.16 - Vuze Remote) <==== ATTENTION
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WordCaptureX Pro (HKLM-x32\…\{139C1D95-9037-3AB3-F5F4-4A79BF6831EC}) (Version: 4.0.0 - Deskperience)
XecureWeb Control (HKLM-x32\…\XecureWeb Control) (Version:  - )
Youtube Preview  Is it worth watching (HKLM-x32\…\{CDFBAC3A-2FE1-0B77-34C9-065BBCC8B77C}) (Version:  - "") <==== ATTENTION
원격 연결을 위한 Windows Live Mesh ActiveX 컨트롤 (HKLM-x32\…\{61920449-0393-4707-B7DD-E6C0013C8B2C}) (Version: 15.4.5722.2 - Microsoft Corporation)
인텔(R) PROSet/무선 WiMAX 소프트웨어 (HKLM\…\{5C1DA3D9-F590-4317-A4FB-274F658E504B}) (Version: 6.05.0001 - Intel Corporation)
인텔® PROSet/무선 WiFi 소프트웨어 (HKLM\…\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
 
==================== Restore Points  =========================
 
16-03-2015 18:46:22 AA11
23-03-2015 17:32:33 AA11
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 11:34 - 2015-03-03 20:25 - 00450892 ____R C:\windows\system32\Drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 www.123fporn.info
127.0.0.1 123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
 
There are 1000 more lines.
 
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {03A10DB7-9071-4EEF-B9CB-F411EA94735C} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Samsung Control Center\SmartSetting.exe [2011-06-04] (Samsung Electronics Co., Ltd.)
Task: {0A384BD9-2CAB-42DF-8601-6D380A53BFEB} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Samsung Control Center\SCCSpeedBoot.exe [2011-05-18] (Samsung Electronics Co., Ltd.)
Task: {0CFBF115-D843-433D-8B12-14C46A4A3BDA} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2011-03-29] (SEC)
Task: {1645AE87-AC06-4F79-9291-63F734344ECA} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-08-17] (CyberLink)
Task: {28A63C7E-40C7-4D78-9EBE-60FB6CE6E95B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
Task: {2D03498A-F669-4E65-8297-264723A0C017} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2011-04-17] (SAMSUNG Electronics)
Task: {2DB56CE1-EAD1-4215-9D66-960A74B181F9} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {2F5C19D8-2F72-434D-9A4B-551DBD945E72} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {3468239E-CD89-4747-90F5-DCCB45BA2FCB} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {398E535C-CC80-4CF3-9698-34C0F76AD90A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {3F7881E2-661E-42EB-8913-ABFD71584BC0} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
Task: {4A805CAE-69C4-4139-A3D2-995EC8A4FEA1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-15] (Google Inc.)
Task: {6AB036E6-C87E-4750-9D49-01D6931EFB37} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Samsung Control Center\MovieColorEnhancer.exe [2011-02-17] (Samsung Electronics Co., Ltd.)
Task: {76BC4D0C-1132-487C-85F2-7120F1BF7473} - System32\Tasks\Microsoft Office 15 Sync Maintenance for SS-PC-SS SS-PC => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation)
Task: {7E430DF2-7F3D-45FC-A8E6-757D48DAC111} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe [2010-08-27] (Samsung Electronics)
Task: {A0618927-0C2F-4AB6-B49A-AECA2955850A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-15] (Google Inc.)
Task: {A957AD76-D965-4019-82E7-04133BD83B27} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Samsung Control Center\WifiManager.exe [2012-03-08] (Samsung Electronics Co., Ltd.)
Task: {BB1B4464-B9EC-4474-8C84-31A56602CAE2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {C7519AC8-6F25-4BAD-BAFE-E7D925D18572} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Samsung Control Center\dmhkcore.exe [2011-06-15] (Samsung Electronics Co., Ltd.)
Task: {DE28C41A-1C1E-46B7-9DE8-7E610E5C2B14} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Samsung Control Center\EBM\EasyBatteryMgr4.exe [2011-07-02] (SAMSUNG Electronics co., LTD.)
Task: {E924E8DA-3600-4ED2-82A9-AB458CDC5AF9} - System32\Tasks\EcoMode => C:\Program Files (x86)\Samsung\Eco Mode\SmartEco.exe [2011-06-06] (Samsung Electronics)
Task: {E937FD97-F248-4672-85D2-684AEA989A33} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {EB02381F-D652-4B1C-894A-712498C62C51} - \Microsoft\Windows\MUI\LPRemove No Task File <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core.job => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA.job => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) ==============
 
2012-04-21 21:01 - 2008-06-05 08:53 - 00027648 _____ () C:\windows\System32\spd__l.dll
2015-03-20 06:17 - 2015-01-28 00:29 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2012-04-21 20:59 - 2010-12-17 10:37 - 00094208 _____ () C:\windows\system32\IccLibDll_x64.dll
2012-04-21 21:01 - 2010-10-22 03:22 - 00709632 _____ () C:\windows\system32\SnMinDrv.dll
2014-03-21 17:29 - 2014-05-20 08:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2014-12-29 16:28 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-12-29 16:28 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-12-29 16:28 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2014-12-29 16:28 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2014-12-29 16:28 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2012-04-21 06:14 - 2011-02-17 00:03 - 00203776 _____ () C:\Program Files (x86)\Samsung\Samsung Control Center\WinCRT.dll
2012-04-21 06:14 - 2006-08-12 11:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Samsung Control Center\HookDllPS2.dll
2013-06-26 10:08 - 2014-12-22 22:08 - 00045056 _____ () C:\Program Files (x86)\Kakao\KakaoTalk\LiteUnzip.dll
2009-11-02 14:20 - 2009-11-02 14:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 14:23 - 2009-11-02 14:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2012-04-21 06:15 - 2010-05-07 23:22 - 01636864 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
2014-01-31 12:28 - 2014-01-31 12:28 - 00421520 _____ () C:\Program Files (x86)\GRETECH\GomPlayer\GomTVStrm.dll
2015-01-15 00:29 - 2015-01-09 09:35 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libglesv2.dll
2015-01-15 00:29 - 2015-01-09 09:35 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libegl.dll
2015-01-15 00:29 - 2015-01-09 09:35 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\pdf.dll
2015-01-15 00:29 - 2015-01-09 09:35 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\ffmpegsumo.dll
2015-01-15 00:29 - 2015-01-09 09:35 - 14913352 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\SS\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: [removed] - [removed]
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3476611405-1961159229-2615470741-500 - Administrator - Disabled)
Guest (S-1-5-21-3476611405-1961159229-2615470741-501 - Limited - Disabled)
SS (S-1-5-21-3476611405-1961159229-2615470741-1001 - Administrator - Enabled) => C:\Users\SS
UpdatusUser (S-1-5-21-3476611405-1961159229-2615470741-1000 - Limited - Enabled) => C:\Users\UpdatusUser
 
==================== Faulty Device Manager Devices =============
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/20/2015 06:21:17 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (03/16/2015 10:18:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (03/16/2015 07:43:41 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (03/12/2015 03:35:51 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (03/12/2015 03:33:11 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80070013, The media is write protected.
.
 
Error: (03/12/2015 03:33:11 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x80070013, The media is write protected.
]
 
Error: (03/12/2015 03:33:10 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80070013, The media is write protected.
.
 
Error: (03/12/2015 03:33:10 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x80070013, The media is write protected.
]
 
Error: (03/11/2015 09:29:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4
Faulting module name: SHELL32.dll, version: 6.1.7601.18517, time stamp: 0x53aa2e07
Exception code: 0xc0000005
Fault offset: 0x0000000000050506
Faulting process id: 0x15e8
Faulting application start time: 0xExplorer.EXE0
Faulting application path: Explorer.EXE1
Faulting module path: Explorer.EXE2
Report Id: Explorer.EXE3
 
Error: (03/11/2015 09:29:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4
Faulting module name: SHELL32.dll, version: 6.1.7601.18517, time stamp: 0x53aa2e07
Exception code: 0xc0000005
Fault offset: 0x0000000000050506
Faulting process id: 0x91c
Faulting application start time: 0xExplorer.EXE0
Faulting application path: Explorer.EXE1
Faulting module path: Explorer.EXE2
Report Id: Explorer.EXE3
 
 
System errors:
=============
Error: (03/23/2015 05:31:34 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LavasoftAdAwareService11 service.
 
Error: (03/22/2015 09:59:06 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.
 
Error: (03/18/2015 10:01:34 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.
 
Error: (03/16/2015 07:44:24 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
%%1068
 
Error: (03/16/2015 07:43:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
%%1068
 
Error: (03/16/2015 07:42:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
%%1068
 
Error: (03/16/2015 07:42:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
%%1068
 
Error: (03/16/2015 07:42:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
%%1068
 
Error: (03/16/2015 07:42:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
%%1068
 
Error: (03/16/2015 07:42:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: 
%%1068
 
 
Microsoft Office Sessions:
=========================
Error: (03/20/2015 06:21:17 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (03/16/2015 10:18:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (03/16/2015 07:43:41 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (03/12/2015 03:35:51 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (03/12/2015 03:33:11 PM) (Source: VSS) (EventID: 8193) (User: )
Description: CoCreateInstance0x80070013, The media is write protected.
 
Error: (03/12/2015 03:33:11 PM) (Source: VSS) (EventID: 13) (User: )
Description: {4e14fba2-2e22-11d1-9964-00c04fbbb345}CEventSystem0x80070013, The media is write protected.
 
Error: (03/12/2015 03:33:10 PM) (Source: VSS) (EventID: 8193) (User: )
Description: CoCreateInstance0x80070013, The media is write protected.
 
Error: (03/12/2015 03:33:10 PM) (Source: VSS) (EventID: 13) (User: )
Description: {4e14fba2-2e22-11d1-9964-00c04fbbb345}CEventSystem0x80070013, The media is write protected.
 
Error: (03/11/2015 09:29:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.1.7601.175674d672ee4SHELL32.dll6.1.7601.1851753aa2e07c0000005000000000005050615e801d05bf703240932C:\windows\Explorer.EXEC:\windows\system32\SHELL32.dll4d7d721b-c7ea-11e4-b0e8-50b7c307cd39
 
Error: (03/11/2015 09:29:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.1.7601.175674d672ee4SHELL32.dll6.1.7601.1851753aa2e07c0000005000000000005050691c01d05a6b400d0dfaC:\windows\Explorer.EXEC:\windows\system32\SHELL32.dll3871e15d-c7ea-11e4-b0e8-50b7c307cd39
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz
Percentage of memory in use: 61%
Total physical RAM: 4009.55 MB
Available physical RAM: 1530.82 MB
Total Pagefile: 8017.28 MB
Available Pagefile: 4017.8 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:179 GB) (Free:38.22 GB) NTFS
Drive d: () (Fixed) (Total:266.57 GB) (Free:253.66 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: A80DEEF6)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=179 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=266.6 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=20.1 GB) - (Type=27)
 
==================== End Of Log ============================

 

:welcome:

 

Lets do a few things and go from there

 

First, your running FRST from your Downloads folder, our tools and scanner run more efficiently from the desktop in lieu of being buried in some folder, so go to your Downloads folder and look for FRST64, right click and select CUT, come back to your desktop and right click on a blank space and select PASTE. The rest of the tools I need you to run, make sure you download them directly to the desktop

 

 

 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
Do not click on any links in the top Advertisment.
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
    [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  to your desktop. 
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
      •  
        [external image: MBAMDashboard_zpsddef9b5f.gif]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished and the log pops up…select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • Great! Thanks for the quick reply. 
          So, in order here are the logs you requested: 
          ADW
          JRT
          Maleware

          I moved frst to the desktop and ran a scan again, I wasn't sure if you needed that, but I included it at the bottom just in case. 
           

          ADW log:

          # AdwCleaner v4.113 - Logfile created 24/03/2015 at 18:26:28
          # Updated 22/03/2015 by Xplode
          # Database : 2015-03-23.1 [Server]
          # Operating system : Windows 7 Home Premium Service Pack 1 (x64)
          # Username : SS - SS-PC
          # Running from : C:\Users\SS\Desktop\AdwCleaner.exe
          # Option : Cleaning
           
          ***** [ Services ] *****
           
          Service Deleted : IePluginServices
           
          ***** [ Files / Folders ] *****
           
          Folder Deleted : C:\ProgramData\IePluginServices
          Folder Deleted : C:\ProgramData\WindowsMangerProtect
          Folder Deleted : C:\ProgramData\AdBlocker Manger
          Folder Deleted : C:\ProgramData\Browser AdBlocker
          Folder Deleted : C:\ProgramData\DDisacountiExTensi
          Folder Deleted : C:\ProgramData\DownSaveee
          Folder Deleted : C:\ProgramData\EnjoyCuoouPon
          Folder Deleted : C:\ProgramData\MiINImmumPrice
          Folder Deleted : C:\ProgramData\PriceLess
          Folder Deleted : C:\ProgramData\RobbOSaver
          Folder Deleted : C:\ProgramData\2a436ad1c7d245ce
          Folder Deleted : C:\Program Files (x86)\baidu
          Folder Deleted : C:\Program Files (x86)\Conduit
          Folder Deleted : C:\Program Files (x86)\supporter
          Folder Deleted : C:\Program Files (x86)\Vuze_Remote
          Folder Deleted : C:\Program Files (x86)\DDisacountiExTensi
          Folder Deleted : C:\Program Files (x86)\DownSaveee
          Folder Deleted : C:\Program Files (x86)\EnjoyCuoouPon
          Folder Deleted : C:\Program Files (x86)\PriceLess
          Folder Deleted : C:\Program Files (x86)\RobbOSaver
          Folder Deleted : C:\Program Files (x86)\DealExpREoss
          Folder Deleted : C:\Program Files (x86)\DeealExpress
          Folder Deleted : C:\Program Files (x86)\dollarkeeepper
          Folder Deleted : C:\Program Files (x86)\FuindBeSTDeal
          Folder Deleted : C:\Program Files (x86)\MIniimumPricue
          Folder Deleted : C:\Program Files (x86)\NewSaever
          Folder Deleted : C:\Program Files (x86)\taakesavE
          Folder Deleted : C:\Program Files (x86)\taKesaavve
          Folder Deleted : C:\Users\SS\AppData\Local\Temp\ASP
          Folder Deleted : C:\Users\Administrator\AppData\Local\Chromatic Browser
          Folder Deleted : C:\Users\Administrator\AppData\Local\torch
          Folder Deleted : C:\Users\Guest\AppData\Local\Chromatic Browser
          Folder Deleted : C:\Users\Guest\AppData\Local\torch
          Folder Deleted : C:\Users\SS\AppData\Local\Chromatic Browser
          Folder Deleted : C:\Users\SS\AppData\Local\torch
          Folder Deleted : C:\Users\SS\AppData\LocalLow\baidu
          Folder Deleted : C:\Users\SS\AppData\LocalLow\Conduit
          Folder Deleted : C:\Users\SS\AppData\LocalLow\Vuze_Remote
          Folder Deleted : C:\Users\SS\AppData\Roaming\OpenCandy
          Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Chromatic Browser
          Folder Deleted : C:\Users\UpdatusUser\AppData\Local\torch
          Folder Deleted : C:\ProgramData\null
          Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm
          Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm
          Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm
          Folder Deleted : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm
          Folder Deleted : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm
          Folder Deleted : C:\Users\SS\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm
          Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm
          Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm
          Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm
          Folder Deleted : C:\Users\SS\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm
          Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\lkbinmofildnpekbhkneobdcokkjmalm
           
          ***** [ Scheduled tasks ] *****
           
           
          ***** [ Shortcuts ] *****
           
           
          ***** [ Registry ] *****
           
          Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mjdepfkicdcciagbigfcmdhknnoaaegf
          Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
          Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
          Key Deleted : HKLM\SOFTWARE\Classes\P0f4f06d4_fb60_474f_b9a8_1b5776f79296_.P0f4f06d4_fb60_474f_b9a8_1b5776f79296_
          Key Deleted : HKLM\SOFTWARE\Classes\P0f4f06d4_fb60_474f_b9a8_1b5776f79296_.P0f4f06d4_fb60_474f_b9a8_1b5776f79296_.9
          Key Deleted : HKLM\SOFTWARE\Classes\P14a77f6c_5eaa_4bbe_950a_f117ddb74737_.P14a77f6c_5eaa_4bbe_950a_f117ddb74737_
          Key Deleted : HKLM\SOFTWARE\Classes\P14a77f6c_5eaa_4bbe_950a_f117ddb74737_.P14a77f6c_5eaa_4bbe_950a_f117ddb74737_.9
          Key Deleted : HKLM\SOFTWARE\Classes\P25bd7245_a773_4656_98bc_d5ceb79e378b_.P25bd7245_a773_4656_98bc_d5ceb79e378b_
          Key Deleted : HKLM\SOFTWARE\Classes\P25bd7245_a773_4656_98bc_d5ceb79e378b_.P25bd7245_a773_4656_98bc_d5ceb79e378b_.9
          Key Deleted : HKLM\SOFTWARE\Classes\P48e37fef_a202_48f9_8296_1edc04e83c47_.P48e37fef_a202_48f9_8296_1edc04e83c47_
          Key Deleted : HKLM\SOFTWARE\Classes\P48e37fef_a202_48f9_8296_1edc04e83c47_.P48e37fef_a202_48f9_8296_1edc04e83c47_.9
          Key Deleted : HKLM\SOFTWARE\Classes\P7003dc61_7470_42fb_ad7c_1bb2481f953a_.P7003dc61_7470_42fb_ad7c_1bb2481f953a_
          Key Deleted : HKLM\SOFTWARE\Classes\P7003dc61_7470_42fb_ad7c_1bb2481f953a_.P7003dc61_7470_42fb_ad7c_1bb2481f953a_.10
          Key Deleted : HKLM\SOFTWARE\Classes\P7a17dbfe_3794_418d_b56c_434e218df8d8_.P7a17dbfe_3794_418d_b56c_434e218df8d8_
          Key Deleted : HKLM\SOFTWARE\Classes\P7a17dbfe_3794_418d_b56c_434e218df8d8_.P7a17dbfe_3794_418d_b56c_434e218df8d8_.9
          Key Deleted : HKLM\SOFTWARE\Classes\P861ae526_9a82_4c79_9184_9bc2664a629e_.P861ae526_9a82_4c79_9184_9bc2664a629e_
          Key Deleted : HKLM\SOFTWARE\Classes\P861ae526_9a82_4c79_9184_9bc2664a629e_.P861ae526_9a82_4c79_9184_9bc2664a629e_.9
          Key Deleted : HKLM\SOFTWARE\Classes\.
          Key Deleted : HKLM\SOFTWARE\Classes\..9
          Key Deleted : HKLM\SOFTWARE\Classes\Pa9a2a7a6_ae41_4775_90aa_832c9303bb4e_.Pa9a2a7a6_ae41_4775_90aa_832c9303bb4e_
          Key Deleted : HKLM\SOFTWARE\Classes\Pa9a2a7a6_ae41_4775_90aa_832c9303bb4e_.Pa9a2a7a6_ae41_4775_90aa_832c9303bb4e_.10
          Key Deleted : HKLM\SOFTWARE\Classes\Pbc415163_0d6d_4582_ab32_ccce829e2e89_.Pbc415163_0d6d_4582_ab32_ccce829e2e89_
          Key Deleted : HKLM\SOFTWARE\Classes\Pbc415163_0d6d_4582_ab32_ccce829e2e89_.Pbc415163_0d6d_4582_ab32_ccce829e2e89_.9
          Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BA14329E-9550-4989-B3F2-9732E92D17CC}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0f4f06d4-fb60-474f-b9a8-1b5776f79296}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{14a77f6c-5eaa-4bbe-950a-f117ddb74737}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{25bd7245-a773-4656-98bc-d5ceb79e378b}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{48e37fef-a202-48f9-8296-1edc04e83c47}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7003dc61-7470-42fb-ad7c-1bb2481f953a}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7a17dbfe-3794-418d-b56c-434e218df8d8}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{861ae526-9a82-4c79-9184-9bc2664a629e}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9436318a-ef92-4fd9-a979-e5bd9e1e9371}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{a9a2a7a6-ae41-4775-90aa-832c9303bb4e}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{bc415163-0d6d-4582-ab32-ccce829e2e89}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
          Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{079E2F0F-FCA0-4163-BC82-5355B879E86E}
          Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{16851532-688E-4B05-8303-65AB36DE4369}
          Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{41F978F3-431A-4464-A789-5C0692D562FB}
          Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{89310413-97E0-4F09-AA75-390A7F4D4918}
          Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A822F6B8-C434-4233-8FE0-CA9268289C60}
          Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB07B01B-C340-4FC1-9165-BC549C02A92E}
          Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3706EE7C-3CAD-445D-8A43-03EBC3B75908}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA14329E-9550-4989-B3F2-9732E92D17CC}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48e37fef-a202-48f9-8296-1edc04e83c47}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7003dc61-7470-42fb-ad7c-1bb2481f953a}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3706EE7C-3CAD-445D-8A43-03EBC3B75908}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA14329E-9550-4989-B3F2-9732E92D17CC}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{48e37fef-a202-48f9-8296-1edc04e83c47}
          Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7003dc61-7470-42fb-ad7c-1bb2481f953a}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A7F05EE4-0426-454F-8013-C41E3596E9E9}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0f4f06d4-fb60-474f-b9a8-1b5776f79296}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{14a77f6c-5eaa-4bbe-950a-f117ddb74737}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25bd7245-a773-4656-98bc-d5ceb79e378b}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{48e37fef-a202-48f9-8296-1edc04e83c47}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7003dc61-7470-42fb-ad7c-1bb2481f953a}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7a17dbfe-3794-418d-b56c-434e218df8d8}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{861ae526-9a82-4c79-9184-9bc2664a629e}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9436318a-ef92-4fd9-a979-e5bd9e1e9371}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a9a2a7a6-ae41-4775-90aa-832c9303bb4e}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{bc415163-0d6d-4582-ab32-ccce829e2e89}
          Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
          Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
          Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{3706EE7C-3CAD-445D-8A43-03EBC3B75908}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{0f4f06d4-fb60-474f-b9a8-1b5776f79296}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{14a77f6c-5eaa-4bbe-950a-f117ddb74737}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{25bd7245-a773-4656-98bc-d5ceb79e378b}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{48e37fef-a202-48f9-8296-1edc04e83c47}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{7003dc61-7470-42fb-ad7c-1bb2481f953a}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{7a17dbfe-3794-418d-b56c-434e218df8d8}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{861ae526-9a82-4c79-9184-9bc2664a629e}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{9436318a-ef92-4fd9-a979-e5bd9e1e9371}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{a9a2a7a6-ae41-4775-90aa-832c9303bb4e}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{bc415163-0d6d-4582-ab32-ccce829e2e89}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
          Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
          Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
          Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
          Key Deleted : HKCU\Software\Conduit
          Key Deleted : HKCU\Software\SupHpUISoft
          Key Deleted : HKCU\Software\AppDataLow\Toolbar
          Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
          Key Deleted : HKCU\Software\AppDataLow\Software\adawarebp
          Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
          Key Deleted : HKCU\Software\AppDataLow\Software\Baidu
          Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
          Key Deleted : HKLM\SOFTWARE\Conduit
          Key Deleted : HKLM\SOFTWARE\SafetyNut
          Key Deleted : HKLM\SOFTWARE\SupTab
          Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
          Key Deleted : HKLM\SOFTWARE\supWPM
          Key Deleted : HKLM\SOFTWARE\mystartsearchSoftware
          Key Deleted : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
          Key Deleted : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2DF3E224-05CD-4113-AA7A-86F2F6607B46}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B138259A-351E-33FA-2726-8D71704F1DA9}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BE360B8B-0F10-CA89-FC84-A5EAB71A6AF8}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA1838EF-A497-194E-3850-37A62CEE398B}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UnINISafeWeb64
           
          ***** [ Web browsers ] *****
           
          -\\ Internet Explorer v11.0.9600.17689
           
           
          -\\ Google Chrome v39.0.2171.99
           
           
          -\\ Comodo Dragon v
           
           
          -\\ Chrome Canary v
           
           
          *************************
           
          AdwCleaner[R0].txt - [14843 bytes] - [24/03/2015 18:22:03]
          AdwCleaner[S0].txt - [14010 bytes] - [24/03/2015 18:26:28]
           
          ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14070  bytes] ##########
           

          JRT log:

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Thisisu
          Version: 6.4.6 (03.22.2015:1)
          OS: Windows 7 Home Premium x64
          Ran by [removed] on Tue 03/24/2015 at 18:32:41.50
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           
           
           
           
          ~~~ Services
           
           
           
          ~~~ Registry Values
           
          Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
           
           
           
          ~~~ Registry Keys
           
          Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2}
           
           
           
          ~~~ Files
           
          Successfully deleted: [File] "C:\windows\wininit.ini"
           
           
           
          ~~~ Folders
           
          Successfully deleted: [Folder] "C:\ai_recyclebin"
          Successfully deleted: [Folder] "C:\windows\syswow64\ai_recyclebin"
          Successfully deleted: [Empty Folder] C:\Users\SS\appdata\local\{7F0986C4-662B-4413-81D7-19826DB8843F}
           
           
           
          ~~~ Event Viewer Logs were cleared
           
           
           
           
           
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Tue 03/24/2015 at 18:38:11.56
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           

          Malware log:

          Malwarebytes Anti-Malware
          www.malwarebytes.org
           
          Scan Date: 3/24/2015
          Scan Time: 6:43:38 PM
          Logfile: 
          Administrator: Yes
           
          Version: 2.01.4.1018
          Malware Database: v2015.03.24.02
          Rootkit Database: v2015.02.25.01
          License: Trial
          Malware Protection: Enabled
          Malicious Website Protection: Enabled
          Self-protection: Disabled
           
          OS: Windows 7 Service Pack 1
          CPU: x64
          File System: NTFS
          User: SS
           
          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 424217
          Time Elapsed: 20 min, 16 sec
           
          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Disabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled
           
          Processes: 0
          (No malicious items detected)
           
          Modules: 0
          (No malicious items detected)
           
          Registry Keys: 35
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\APPID\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4}, , [3c16c0893555d26425793808699a718f], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{1DD31B76-C57E-49BA-94BC-BF53F0C82CD4}, , [3c16c0893555d26425793808699a718f], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{1DD31B76-C57E-49BA-94BC-BF53F0C82CD4}, , [3c16c0893555d26425793808699a718f], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1DD31B76-C57E-49BA-94BC-BF53F0C82CD4}, , [3c16c0893555d26425793808699a718f], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11CC93E4-0BE6-4f8f-82AA-D577FB955B05}, , [d18188c1b0da5dd9ccd11a2657ac47b9], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\AddressSearch.JsObject.1, , [d18188c1b0da5dd9ccd11a2657ac47b9], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\AddressSearch.JsObject, , [d18188c1b0da5dd9ccd11a2657ac47b9], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\CLASSES\AddressSearch.JsObject, , [d18188c1b0da5dd9ccd11a2657ac47b9], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\WOW6432NODE\AddressSearch.JsObject, , [d18188c1b0da5dd9ccd11a2657ac47b9], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\CLASSES\AddressSearch.JsObject.1, , [d18188c1b0da5dd9ccd11a2657ac47b9], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\WOW6432NODE\AddressSearch.JsObject.1, , [d18188c1b0da5dd9ccd11a2657ac47b9], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{11CC93E4-0BE6-4F8F-82AA-D577FB955B05}, , [d18188c1b0da5dd9ccd11a2657ac47b9], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{11CC93E4-0BE6-4F8F-82AA-D577FB955B05}, , [d18188c1b0da5dd9ccd11a2657ac47b9], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{91878E42-FC03-4785-B513-1F9E613D1027}, , [8ec46bdeacde72c4a1fbd769659e06fa], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\ASBarBroker.BDBroker.1, , [8ec46bdeacde72c4a1fbd769659e06fa], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\ASBarBroker.BDBroker, , [8ec46bdeacde72c4a1fbd769659e06fa], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ASBarBroker.BDBroker, , [8ec46bdeacde72c4a1fbd769659e06fa], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ASBarBroker.BDBroker, , [8ec46bdeacde72c4a1fbd769659e06fa], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ASBarBroker.BDBroker.1, , [8ec46bdeacde72c4a1fbd769659e06fa], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ASBarBroker.BDBroker.1, , [8ec46bdeacde72c4a1fbd769659e06fa], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{91878E42-FC03-4785-B513-1F9E613D1027}, , [8ec46bdeacde72c4a1fbd769659e06fa], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{FBEDBA6C-44A2-43b9-BD49-20EB6E0C4E86}, , [1e3495b4bfcb40f6aaf11b2531d226da], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\AddressSearch.SnavHttpProtocol.1, , [1e3495b4bfcb40f6aaf11b2531d226da], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\AddressSearch.SnavHttpProtocol, , [1e3495b4bfcb40f6aaf11b2531d226da], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\CLASSES\AddressSearch.SnavHttpProtocol, , [1e3495b4bfcb40f6aaf11b2531d226da], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\WOW6432NODE\AddressSearch.SnavHttpProtocol, , [1e3495b4bfcb40f6aaf11b2531d226da], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\WOW6432NODE\CLASSES\AddressSearch.SnavHttpProtocol.1, , [1e3495b4bfcb40f6aaf11b2531d226da], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\WOW6432NODE\AddressSearch.SnavHttpProtocol.1, , [1e3495b4bfcb40f6aaf11b2531d226da], 
          PUP.Optional.Funshion, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{FBEDBA6C-44A2-43B9-BD49-20EB6E0C4E86}, , [1e3495b4bfcb40f6aaf11b2531d226da], 
          Adware.BDSearch, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46}, , [430fd8712268221449afc38028dbdb25], 
          PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{89AE616B-E500-0C2D-D0D2-F444CEEB4619}, , [66ecd3760f7bfb3be6e9b95db84b4db3], 
          PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{C8AAF59A-6BAA-F68B-9470-A856460A8093}, , [db7746035436b0861cb342d4a55ef60a], 
          PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{AF992111-52BE-832B-5882-8477E4A3C99A}, , [351dec5d3654c175ad22110516ed3bc5], 
          PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{CDFBAC3A-2FE1-0B77-34C9-065BBCC8B77C}, , [85cd56f32862ef473d9234e21ce7649c], 
          PUP.Optional.VuzeRemoteTB.A, HKLM\SOFTWARE\WOW6432NODE\Vuze_Remote, , [8cc6ba8fa7e32d09eb11cd71a36229d7], 
           
          Registry Values: 0
          (No malicious items detected)
           
          Registry Data: 0
          (No malicious items detected)
           
          Folders: 0
          (No malicious items detected)
           
          Files: 6
          PUP.Optional.Multiplug, C:\Program Files (x86)\ActiveMail\ActiveMail.exe, , [66ecd3760f7bfb3be6e9b95db84b4db3], 
          PUP.Optional.Multiplug, C:\Program Files (x86)\coinsaove\coinsaove.exe, , [db7746035436b0861cb342d4a55ef60a], 
          PUP.Optional.Multiplug, C:\Program Files (x86)\Online Calculator\Online Calculator.exe, , [90c20346a1e9ca6c03cc7b9bbb48cf31], 
          PUP.Optional.Multiplug, C:\Program Files (x86)\Renren Album Downloader\Renren Album Downloader.exe, , [351dec5d3654c175ad22110516ed3bc5], 
          PUP.Optional.Multiplug, C:\Program Files (x86)\Youtube Preview  Is it worth watching\Youtube Preview  Is it worth watching.exe, , [85cd56f32862ef473d9234e21ce7649c], 
          Trojan.MSIL.Injector, C:\Users\SS\Downloads\[EvilAngel]_Chanel_Preston_(Anal_Intensity_03,_Scene_03_-_03.02.15)_rq.mp4 (1).exe, , [3f13e16881090333952ffbe7af56f30d], 
           
          Physical Sectors: 0
          (No malicious items detected)
           
           
          (end)

          frst log [from desktop]
          Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
          Ran by [removed] (administrator) on SS-PC on 24-03-2015 18:17:35
          Running from C:\Users\[removed]\Desktop
          [removed]
          Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
          Internet Explorer Version 11 (Default browser not detected!)
          Boot Mode: Normal
          Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
           
          ==================== Processes (Whitelisted) =================
           
          (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
           
          (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
          (Microsoft Corporation) C:\Windows\System32\wlanext.exe
          (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
          (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
          (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
          (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
          (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
          (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
          (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
          (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
          (Intel(R) Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
          (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
          (Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
          (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
          (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
          (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
          (BitTorrent Inc.) C:\Users\SS\AppData\Roaming\BitTorrent\BitTorrent.exe
          (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\dmhkcore.exe
          (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\MovieColorEnhancer.exe
          (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\WifiManager.exe
          (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\SmartSetting.exe
          (Microsoft Corporation) C:\Windows\System32\StikyNot.exe
          (Samsung Electronics) C:\Program Files (x86)\Samsung\Eco Mode\SmartEco.exe
          (Intel Corporation) C:\Windows\System32\igfxext.exe
          (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
          (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
          (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
          (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
          (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
          (Daum Kakao Corp. ) C:\Program Files (x86)\Kakao\KakaoTalk\KakaoTalk.exe
          (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
          (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
          (Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
          (Intel Corporation) C:\Windows\System32\hkcmd.exe
          (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
          (Intel Corporation) C:\Windows\System32\igfxpers.exe
          (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\EasySpeedUpManager.exe
          (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
          (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
          (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
          (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
          (Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe
          (Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
          (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
          (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
          (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Microsoft Corporation) C:\Windows\System32\dllhost.exe
           
           
          ==================== Registry (Whitelisted) ==================
           
          (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
           
          HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11895400 2011-06-25] (Realtek Semiconductor)
          HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2588968 2010-11-13] (ELAN Microelectronics Corp.)
          HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-09] (Adobe Systems Incorporated)
          HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
          HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
          HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
          Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
          HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [BitTorrent] => C:\Users\SS\AppData\Roaming\BitTorrent\BitTorrent.exe [1744472 2015-03-04] (BitTorrent Inc.)
          HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [ctfmon] => C:\windows\system32\ctfmon.exe [9728 2009-07-14] (Microsoft Corporation)
          HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
          HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
          HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Policies\Explorer: [NoLowDiskSpaceChecks] 1
          HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\MountPoints2: {9a7c915e-34b5-11e2-bdd9-806e6f6e6963} - E:\PLAY.EXE "playlist.m3u"
          HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\MountPoints2: {b02a9a3b-7a26-11e2-b71f-50b7c307cd39} - F:\LGAutoRun.exe
          HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Bubbles.scr [899584 2010-11-21] (Microsoft Corporation)
          GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
          CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
           
          ==================== Internet (Whitelisted) ====================
           
          (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
           
          HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
          HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
          HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
          HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
          HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
          HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
          HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
          HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.samsung.com/sec
          HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
          HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
          URLSearchHook: HKLM-x32 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
          URLSearchHook: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
          SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
          SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
          SearchScopes: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001 -> DefaultScope {B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2} URL = http://www.baidu.com/s?wd={searchTerms}&ie={inputEncoding}&oe={outputEncoding}&abar=2&tn=20041099_oem_dg&ch=33
          SearchScopes: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=210&systemid=488&v=a13277-348&apn_uid=4874403504284444&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
          SearchScopes: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001 -> {B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2} URL = http://www.baidu.com/s?wd={searchTerms}&ie={inputEncoding}&oe={outputEncoding}&abar=2&tn=20041099_oem_dg&ch=33
          BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
          BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
          BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-02-10] (Microsoft Corporation)
          BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-02-10] (Microsoft Corporation)
          BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
          BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-02-10] (Microsoft Corporation)
          Toolbar: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
          Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
          Handler-x32: s-http - {D37E6C5F-1C0F-47C0-A3B6-403EEC555402} - C:\Program Files (x86)\Initech\SHTTP\InitechSHTTPInterface.11014.dll [2013-02-08] (© INITECH)
          Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
          Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
          Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
          Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
          Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
          Tcpip\..\Interfaces\{83395AC7-FE87-4186-91C3-A6BE63F9820B}: [NameServer] 168.126.63.1,168.126.63.2
          StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=sc&ts=1419837849&from=smt&uid=ST500LM012XHN-M500MBB_S2RSJ9ECA38311
           
          FireFox:
          ========
          FF Plugin: @microsoft.com/GENUINE -> disabled No File
          FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
          FF Plugin: @qvod.com/QvodShare -> C:\Program Files (x86)\QvodPlayer\npShareModule_x64.dll No File
          FF Plugin-x32: @ahnlab.com/asp/npaosmgr.1 -> C:\Program Files (x86)\AhnLab\ASP\Components\aosmgr\npaosmgr.dll [2014-08-05] (AhnLab, Inc.)
          FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-25] (Oracle Corporation)
          FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-25] (Oracle Corporation)
          FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
          FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
          FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-07-12] (Microsoft Corporation)
          FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
          FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
          FF Plugin-x32: @softforum.com/npxwebplugins -> C:\Program Files (x86)\SoftForum\XecureWeb\ActiveX\npxwebplugin.dll [2009-05-28] (SoftForum)
          FF Plugin-x32: @softforum.com/npxwebplugins_file -> C:\Program Files (x86)\SoftForum\XecureWeb\ActiveX\npxwebplugin_file.dll [2009-05-28] (SoftForum Co., Ltd.)
          FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2015-01-15] (Google Inc.)
          FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2015-01-15] (Google Inc.)
          FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-10-16] (VideoLAN)
          FF Plugin-x32: @wizvera.com/npVeraport20 -> C:\Program Files (x86)\Wizvera\Veraport20\npveraport20.dll [2013-11-15] ()
          FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
          FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @iniline.com/npCrossWeb -> C:\Users\SS\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0AB9084F-0EF8-499a-A461-DE46D3C4A45B}\plugins\npCrossWeb.dll [2014-12-05] (INITECH Co., Ltd.)
          FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @initech.com/npSandBox -> C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.10052.dll [2014-11-27] (Initech Co., Ltd.)
          FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @qvod.com/QvodInsert -> C:\Program Files (x86)\QvodPlayer\npQvodInsert.dll No File
          FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\SS\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2014-10-29] (Google)
          FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @talk.google.com/O1DPlugin -> C:\Users\SS\AppData\Roaming\Mozilla\plugins\npo1d.dll [2014-10-29] (Google)
          FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @tools.google.com/Google Update;version=3 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
          FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @tools.google.com/Google Update;version=9 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
          FF Plugin ProgramFiles/Appdata: C:\Users\SS\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2014-10-29] (Google)
          FF Plugin ProgramFiles/Appdata: C:\Users\SS\AppData\Roaming\mozilla\plugins\npo1d.dll [2014-10-29] (Google)
          FF Extension: INISAFE CrossWeb - C:\Users\SS\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0AB9084F-0EF8-499a-A461-DE46D3C4A45B} [2015-01-30]
          FF HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.xpi
          FF Extension: INISAFE SandBox - C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.xpi [2014-11-27]
           
          Chrome: 
          =======
          CHR dev: Chrome dev build detected! <======= ATTENTION
          CHR Profile: C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1
          CHR Extension: (Google Drive) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-15]
          CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-15]
          CHR Extension: (Chromebleed) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eeoekjnjgppnaegdjbcafdggilajhpic [2015-01-15]
          CHR Extension: (AdBlock) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-15]
          CHR Extension: (ActiveMail) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmbjhlidpnohinigphldbcffhikcill [2015-02-27]
          CHR Extension: (StayFocusd) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2015-01-15]
          CHR Extension: (Skype Click to Call) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-01-13]
          CHR Extension: (Word CaptureX Extension) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjdepfkicdcciagbigfcmdhknnoaaegf [2014-12-29]
          CHR Extension: (Youtube Preview  Is it worth watching) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nacgopecogaedhhjdfondlcobjofdhap [2015-02-27]
          CHR Extension: (Google Wallet) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-15]
          CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
          CHR HKLM-x32\…\Chrome\Extension: [mjdepfkicdcciagbigfcmdhknnoaaegf] - C:\Program Files (x86)\Deskperience\Word Capture\wcxChrome.crx [2010-07-23]
           
          ==================== Services (Whitelisted) =================
           
          (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
           
          R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
          R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
          R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2714800 2015-02-10] (Microsoft Corporation)
          R2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [498688 2011-11-21] (Red Bend Ltd.) [File not signed]
          R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [715656 2014-12-29] (Cherished Technololgy LIMITED)
          S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] ()
          S3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed]
          R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
          R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
          R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
          R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [986112 2011-11-21] (Intel(R) Corporation) [File not signed]
          S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
          R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation)
           
          ==================== Drivers (Whitelisted) ====================
           
          (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
           
          R1 AMonTDLH; C:\windows\system32\Drivers\AMonTDLH.sys [118072 2012-09-14] (AhnLab, Inc.)
          S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2011-09-06] (Google Inc)
          S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2011-09-06] (LG Electronics Inc.)
          S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [35840 2011-09-06] (LG Electronics Inc.)
          S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93184 2011-09-16] (LG Electronics Inc.)
          S3 CdmDrvNt; C:\windows\system32\Drivers\CdmDrvNt.sys [25656 2009-07-21] (AhnLab, Inc.)
          S3 MfFWEnt; C:\Program Files\AhnLab\ASP\MyFirewall 4.0\MfFWEnt.sys [127224 2014-07-16] (AhnLab, Inc.)
          S3 MfIPSEnt; C:\Program Files\AhnLab\ASP\MyFirewall 4.0\MfIPSEnt.sys [156408 2014-07-16] (AhnLab, Inc.)
          S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-11-23] (Windows (R) 2003 DDK 3790 provider)
          S3 scsk5; C:\Windows\SysWow64\drivers\scsk5.sys [50608 2015-01-30] ()
          S3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2013-05-29] (Spotflux, Inc.)
          S3 AhnFlt2K; \??\C:\windows\system32\drivers\AhnFlt2K.sys [X]
          S3 AhnRec2K; \??\C:\windows\system32\drivers\AhnRec2K.sys [X]
          U3 aswMBR; \??\C:\Users\SS\AppData\Local\Temp\aswMBR.sys [X]
          U3 aswVmm; \??\C:\Users\SS\AppData\Local\Temp\aswVmm.sys [X]
           
          ==================== NetSvcs (Whitelisted) ===================
           
          (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
           
           
          ==================== One Month Created Files and Folders ========
           
          (If an entry is included in the fixlist, the file\folder will be moved.)
           
          2015-03-23 23:56 - 2015-03-23 23:56 - 00020528 _____ () C:\Users\SS\Downloads\MONOVA.ORG Armin_van_Buuren_-_Pulsar_320_2013_Kbps_(FasTor).torrent
          2015-03-23 18:34 - 2015-03-24 18:17 - 00023561 _____ () C:\Users\SS\Desktop\FRST.txt
          2015-03-23 18:33 - 2015-03-23 18:33 - 00034329 _____ () C:\Users\SS\Desktop\Addition.txt
          2015-03-23 18:31 - 2015-03-23 18:33 - 00034329 _____ () C:\Users\SS\Downloads\Addition.txt
          2015-03-23 18:29 - 2015-03-23 18:33 - 00058279 _____ () C:\Users\SS\Downloads\FRST.txt
          2015-03-23 18:28 - 2015-03-24 18:17 - 00000000 ____D () C:\FRST
          2015-03-23 18:27 - 2015-03-23 18:27 - 02095616 _____ (Farbar) C:\Users\SS\Desktop\FRST64.exe
          2015-03-23 18:25 - 2015-03-23 18:34 - 00001169 _____ () C:\Users\SS\Desktop\aswMBR.txt
          2015-03-23 18:24 - 2015-03-23 18:24 - 05198336 _____ (AVAST Software) C:\Users\SS\Downloads\aswMBR.exe
          2015-03-23 18:20 - 2015-03-23 18:20 - 00013540 _____ () C:\Users\SS\Downloads\hijackthis.log
          2015-03-23 18:19 - 2015-03-23 18:19 - 00388608 _____ (Trend Micro Inc.) C:\Users\SS\Downloads\HijackThis.exe
          2015-03-22 20:23 - 2015-03-22 20:24 - 00029419 _____ () C:\Users\SS\Downloads\C811E6A9B45648B43DCBF82059CC0E3B7E30AD39.torrent
          2015-03-19 00:39 - 2015-03-19 00:39 - 00000000 ____D () C:\Users\SS\Downloads\BlowjobFridays - Yurizan Beltran - Dick Sucking at Its Finestt 720p [.mp4]
          2015-03-19 00:38 - 2015-03-19 00:38 - 00024420 _____ () C:\Users\SS\Downloads\[kickass.to]blowjobfridays.yurizan.beltran.dick.sucking.at.its.finestt.720p.mp4.torrent
          2015-03-18 18:38 - 2015-03-18 19:03 - 1010408247 _____ () C:\Users\SS\Downloads\chanel_preston_TT_1_JD_1080p_stream.mp4
          2015-03-18 18:35 - 2015-03-18 18:36 - 00020065 _____ () C:\Users\SS\Downloads\0B8D68E97807B45D0210AE67A2B78CBF68E6EB46.torrent
          2015-03-17 23:49 - 2015-03-18 17:26 - 272288145 _____ () C:\Users\SS\Downloads\BRAZZERS - Doctor Adventures - Doctors Without Bras - Kendra Lust - Rachel Starr [SM128].mkv
          2015-03-17 23:48 - 2015-03-17 23:48 - 00011210 _____ () C:\Users\SS\Downloads\8524EBBAA3A6BE651BCA78519BE4F174F4FF80E3.torrent
          2015-03-17 18:44 - 2015-03-17 18:44 - 00000000 ____D () C:\Users\SS\Downloads\HardX - Mia Malkova (Massive Anal Action) [.mp4]
          2015-03-17 18:43 - 2015-03-17 18:43 - 00039875 _____ () C:\Users\SS\Downloads\[kickass.to]hardx.mia.malkova.massive.anal.action.mp4.torrent
          2015-03-17 18:22 - 2015-03-17 18:22 - 00015500 _____ () C:\Users\SS\Downloads\9CD51BDDCDF5C3C59B9E1FFC5C99926E55925532.torrent
          2015-03-17 18:22 - 2015-03-17 18:22 - 00000000 ____D () C:\Users\SS\Downloads\Blowjob Friday - Capri Cavanni (Serious BJ skills)
          2015-03-16 18:51 - 2015-03-16 18:51 - 00000000 ____D () C:\Users\SS\AppData\Roaming\LavasoftStatistics
          2015-03-16 18:46 - 2015-03-16 18:46 - 02057008 _____ () C:\Users\SS\Downloads\Adaware_Installer.exe
          2015-03-14 11:49 - 2015-03-14 12:21 - 00000000 ____D () C:\Users\SS\Downloads\The Last Naruto The Movie 2014 720p HDCAM ENG SUBS x264 Pimp4003
          2015-03-14 11:47 - 2015-03-14 11:47 - 00020522 _____ () C:\Users\SS\Downloads\[kickass.to]the.last.naruto.the.movie.2014.720p.hdcam.eng.subs.x264.pimp4003.torrent
          2015-03-12 23:31 - 2015-03-12 23:58 - 480362658 _____ () C:\Users\SS\Downloads\t4k.dillion.harper.excited.little.slut.12.03.15_480.mp4
          2015-03-12 23:31 - 2015-03-12 23:44 - 481824046 _____ () C:\Users\SS\Downloads\Digital_Playground_ge_34601_The_Fuck_Shop_480p_1500.mp4
          2015-03-12 22:35 - 2015-03-12 22:37 - 339871297 _____ () C:\Users\SS\Downloads\BabyGotBoobs - Shawna Lenee - Up Close And Personal With Shawnas Tits  NEW (BRAZZERS  February 11, 2015) NEW.mp4
          2015-03-12 21:15 - 2015-03-12 21:56 - 658123518 _____ () C:\Users\SS\Downloads\HotAndMean - Carter Cruise, Maddy Oreilly_480p.mp4
          2015-03-11 21:27 - 2015-03-11 21:27 - 03471514 _____ () C:\Users\SS\Downloads\Introclass (1).pptx
          2015-03-11 21:27 - 2015-03-11 21:27 - 00958942 _____ () C:\Users\SS\Downloads\Country Bingo.pptx
          2015-03-11 18:28 - 2015-03-11 18:43 - 00000000 ____D () C:\Users\SS\Downloads\Sheena_Shaw_Wide_Open
          2015-03-11 18:08 - 2015-02-20 13:41 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
          2015-03-11 18:08 - 2015-02-20 13:40 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
          2015-03-11 18:08 - 2015-02-20 13:40 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
          2015-03-11 18:08 - 2015-02-20 13:40 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
          2015-03-11 18:08 - 2015-02-20 13:13 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
          2015-03-11 18:08 - 2015-02-20 13:13 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
          2015-03-11 18:08 - 2015-02-20 13:13 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
          2015-03-11 18:08 - 2015-02-20 13:12 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
          2015-03-11 18:08 - 2015-02-20 12:29 - 00372224 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
          2015-03-11 18:08 - 2015-02-20 12:09 - 00299008 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
          2015-03-11 18:08 - 2015-02-03 12:34 - 05554104 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
          2015-03-11 18:08 - 2015-02-03 12:34 - 00094656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
          2015-03-11 18:08 - 2015-02-03 12:33 - 00616360 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
          2015-03-11 18:08 - 2015-02-03 12:31 - 14632960 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
          2015-03-11 18:08 - 2015-02-03 12:31 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
          2015-03-11 18:08 - 2015-02-03 12:31 - 01574400 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
          2015-03-11 18:08 - 2015-02-03 12:30 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
          2015-03-11 18:08 - 2015-02-03 12:30 - 01202176 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
          2015-03-11 18:08 - 2015-02-03 12:16 - 03973048 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
          2015-03-11 18:08 - 2015-02-03 12:16 - 03917760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
          2015-03-11 18:08 - 2015-02-03 12:12 - 11411968 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
          2015-03-11 18:08 - 2015-02-03 12:12 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
          2015-03-11 18:08 - 2015-02-03 12:12 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
          2015-03-11 18:08 - 2015-02-03 12:12 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
          2015-03-11 18:07 - 2015-02-03 12:34 - 00693176 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
          2015-03-11 18:07 - 2015-02-03 12:31 - 00782848 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00641024 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00432128 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00188416 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
          2015-03-11 18:07 - 2015-02-03 12:31 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
          2015-03-11 18:07 - 2015-02-03 12:31 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
          2015-03-11 18:07 - 2015-02-03 12:30 - 01069056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00842240 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00680960 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
          2015-03-11 18:07 - 2015-02-03 12:30 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00146944 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
          2015-03-11 18:07 - 2015-02-03 12:30 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00126464 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
          2015-03-11 18:07 - 2015-02-03 12:30 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
          2015-03-11 18:07 - 2015-02-03 12:30 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
          2015-03-11 18:07 - 2015-02-03 12:30 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
          2015-03-11 18:07 - 2015-02-03 12:30 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
          2015-03-11 18:07 - 2015-02-03 12:30 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
          2015-03-11 18:07 - 2015-02-03 12:30 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe
          2015-03-11 18:07 - 2015-02-03 12:30 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
          2015-03-11 18:07 - 2015-02-03 12:29 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
          2015-03-11 18:07 - 2015-02-03 12:28 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
          2015-03-11 18:07 - 2015-02-03 12:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
          2015-03-11 18:07 - 2015-02-03 12:19 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
          2015-03-11 18:07 - 2015-02-03 12:12 - 01005056 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptui.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00988160 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmv2clt.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00744960 _____ (Microsoft Corporation) C:\windows\SysWOW64\blackbox.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00617984 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmdrmsdk.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscp.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00406016 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmmgrtn.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msnetobj.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00081408 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsp.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
          2015-03-11 18:07 - 2015-02-03 12:12 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
          2015-03-11 18:07 - 2015-02-03 12:12 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
          2015-03-11 18:07 - 2015-02-03 12:11 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
          2015-03-11 18:07 - 2015-02-03 12:11 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
          2015-03-11 18:07 - 2015-02-03 12:11 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
          2015-03-11 18:07 - 2015-02-03 12:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
          2015-03-11 18:07 - 2015-02-03 12:08 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
          2015-03-11 18:07 - 2015-02-03 11:32 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
          2015-03-11 18:07 - 2014-11-01 07:24 - 00619056 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
          2015-03-11 18:06 - 2015-02-13 14:26 - 12875264 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
          2015-03-11 18:06 - 2015-02-13 14:22 - 14177280 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
          2015-03-11 18:06 - 2015-02-03 12:31 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
          2015-03-11 18:06 - 2015-02-03 12:12 - 00171520 _____ (Microsoft Corporation) C:\windows\SysWOW64\ubpm.dll
          2015-03-11 18:05 - 2015-03-06 14:56 - 00155576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
          2015-03-11 18:05 - 2015-03-06 14:56 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
          2015-03-11 18:05 - 2015-03-06 14:42 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
          2015-03-11 18:05 - 2015-03-06 14:42 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
          2015-03-11 18:05 - 2015-03-06 14:42 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
          2015-03-11 18:05 - 2015-03-06 14:42 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
          2015-03-11 18:05 - 2015-03-06 14:42 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
          2015-03-11 18:05 - 2015-03-06 14:42 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
          2015-03-11 18:05 - 2015-03-06 14:42 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
          2015-03-11 18:05 - 2015-03-06 14:42 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
          2015-03-11 18:05 - 2015-03-06 14:42 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
          2015-03-11 18:05 - 2015-03-06 14:42 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
          2015-03-11 18:05 - 2015-03-06 14:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
          2015-03-11 18:05 - 2015-03-06 14:41 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
          2015-03-11 18:05 - 2015-03-06 14:41 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
          2015-03-11 18:05 - 2015-03-06 14:39 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
          2015-03-11 18:05 - 2015-03-06 14:38 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
          2015-03-11 18:05 - 2015-03-06 14:36 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
          2015-03-11 18:05 - 2015-03-06 14:10 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
          2015-03-11 18:05 - 2015-03-06 14:10 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
          2015-03-11 18:05 - 2015-03-06 14:10 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
          2015-03-11 18:05 - 2015-03-06 14:10 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
          2015-03-11 18:05 - 2015-03-06 14:10 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
          2015-03-11 18:05 - 2015-03-06 14:10 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
          2015-03-11 18:05 - 2015-03-06 14:10 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
          2015-03-11 18:05 - 2015-03-06 14:10 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
          2015-03-11 18:05 - 2015-03-06 14:09 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
          2015-03-11 18:05 - 2015-03-06 14:09 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
          2015-03-11 18:05 - 2015-03-06 14:07 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
          2015-03-11 18:05 - 2015-03-06 14:07 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
          2015-03-11 18:05 - 2015-03-06 14:06 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
          2015-03-11 18:05 - 2015-02-26 12:25 - 03204096 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
          2015-03-11 18:05 - 2015-02-24 12:15 - 00389800 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
          2015-03-11 18:05 - 2015-02-24 11:32 - 00342696 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
          2015-03-11 18:05 - 2015-02-21 10:16 - 25021440 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
          2015-03-11 18:05 - 2015-02-21 09:41 - 12827648 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
          2015-03-11 18:05 - 2015-02-21 09:27 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
          2015-03-11 18:05 - 2015-02-21 09:27 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
          2015-03-11 18:05 - 2015-02-21 09:25 - 19720192 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
          2015-03-11 18:05 - 2015-02-21 08:58 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
          2015-03-11 18:05 - 2015-02-21 08:32 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
          2015-03-11 18:05 - 2015-02-20 12:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
          2015-03-11 18:05 - 2015-02-20 12:05 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
          2015-03-11 18:05 - 2015-02-20 11:50 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
          2015-03-11 18:05 - 2015-02-20 11:49 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
          2015-03-11 18:05 - 2015-02-20 11:49 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
          2015-03-11 18:05 - 2015-02-20 11:48 - 02886144 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
          2015-03-11 18:05 - 2015-02-20 11:47 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
          2015-03-11 18:05 - 2015-02-20 11:41 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
          2015-03-11 18:05 - 2015-02-20 11:40 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
          2015-03-11 18:05 - 2015-02-20 11:36 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
          2015-03-11 18:05 - 2015-02-20 11:35 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
          2015-03-11 18:05 - 2015-02-20 11:35 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
          2015-03-11 18:05 - 2015-02-20 11:34 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
          2015-03-11 18:05 - 2015-02-20 11:32 - 06035456 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
          2015-03-11 18:05 - 2015-02-20 11:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
          2015-03-11 18:05 - 2015-02-20 11:22 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
          2015-03-11 18:05 - 2015-02-20 11:22 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
          2015-03-11 18:05 - 2015-02-20 11:13 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
          2015-03-11 18:05 - 2015-02-20 11:09 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
          2015-03-11 18:05 - 2015-02-20 11:08 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
          2015-03-11 18:05 - 2015-02-20 11:08 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
          2015-03-11 18:05 - 2015-02-20 11:08 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
          2015-03-11 18:05 - 2015-02-20 11:06 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
          2015-03-11 18:05 - 2015-02-20 11:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
          2015-03-11 18:05 - 2015-02-20 11:03 - 02278400 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
          2015-03-11 18:05 - 2015-02-20 11:01 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
          2015-03-11 18:05 - 2015-02-20 11:00 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
          2015-03-11 18:05 - 2015-02-20 10:58 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
          2015-03-11 18:05 - 2015-02-20 10:56 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
          2015-03-11 18:05 - 2015-02-20 10:56 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
          2015-03-11 18:05 - 2015-02-20 10:49 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
          2015-03-11 18:05 - 2015-02-20 10:49 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
          2015-03-11 18:05 - 2015-02-20 10:47 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
          2015-03-11 18:05 - 2015-02-20 10:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
          2015-03-11 18:05 - 2015-02-20 10:43 - 14398976 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
          2015-03-11 18:05 - 2015-02-20 10:41 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
          2015-03-11 18:05 - 2015-02-20 10:37 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
          2015-03-11 18:05 - 2015-02-20 10:30 - 04300288 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
          2015-03-11 18:05 - 2015-02-20 10:28 - 02358784 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
          2015-03-11 18:05 - 2015-02-20 10:24 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
          2015-03-11 18:05 - 2015-02-20 10:24 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
          2015-03-11 18:05 - 2015-02-20 10:23 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
          2015-03-11 18:05 - 2015-02-20 10:16 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
          2015-03-11 18:05 - 2015-02-20 10:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
          2015-03-11 18:05 - 2015-02-20 10:01 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
          2015-03-11 18:05 - 2015-02-20 09:57 - 01311232 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
          2015-03-11 18:05 - 2015-02-20 09:55 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
          2015-03-11 18:05 - 2015-02-04 12:16 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
          2015-03-11 18:05 - 2015-02-04 11:54 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
          2015-03-11 18:05 - 2015-02-03 12:31 - 01424896 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
          2015-03-11 18:05 - 2015-02-03 12:12 - 01230848 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
          2015-03-11 18:05 - 2015-01-31 08:56 - 00459336 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
          2015-03-11 18:05 - 2015-01-17 11:48 - 01067520 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
          2015-03-11 18:05 - 2015-01-17 11:30 - 00828928 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
          2015-03-11 00:34 - 2015-03-11 00:34 - 00000000 ____D () C:\Users\SS\Downloads\[FuckedHard18] Morgan Layne [SD] [.wmv]
          2015-03-08 20:59 - 2015-03-08 20:59 - 00147471 _____ () C:\Users\SS\Desktop\jim_aparo___batman_a_death_in_the_family_by_superman8193-d5tlylg-ben-affleck-as-batman-death-red-hood-arkham-asylum-and-hush-52c68877-489e-4ce1-a7c6-b0d2e04e2ed4.jpeg
          2015-03-08 16:40 - 2015-03-08 16:40 - 00000000 ____D () C:\Users\SS\Downloads\EvilAngel.Kalina.Ryu.Sperm.Diet.mp4
          2015-03-08 12:26 - 2015-03-08 23:20 - 2003577517 _____ () C:\Users\SS\Downloads\Saya_Song.mp4
          2015-03-08 11:40 - 2015-03-08 11:40 - 00000000 ____D () C:\Users\SS\Downloads\[GFRevenge] Dillion Harper (Track star)[PornLeech]
          2015-03-07 14:24 - 2015-03-07 14:24 - 00000000 ____D () C:\Users\SS\Downloads\James Deen - JESSIE ROGERS - Assfucked Til She Squirts [.mp4]
          2015-03-07 14:22 - 2015-03-07 14:22 - 00000000 ____D () C:\Users\SS\Downloads\[Private] Tina Hot [Anal Introductions][1080p] [.mp4][PornLeech]
          2015-03-06 18:04 - 2015-03-23 17:41 - 00000000 ____D () C:\Program Files (x86)\FuindBeSTDeal
          2015-03-06 14:14 - 2015-03-06 14:18 - 00000000 ____D () C:\Users\SS\Downloads\BangBros - Big Mouthfuls - Simply 18 w Emma Mae HD 720p
          2015-03-05 13:47 - 2015-03-05 13:47 - 00000000 ____D () C:\Users\SS\Downloads\[DigitalPlayground] Janice Griffith (50 Ways To Fuck) [.mp4]
          2015-03-04 23:39 - 2015-03-04 23:48 - 03461639 _____ () C:\Users\SS\Downloads\Introclass.pptx
          2015-02-27 14:34 - 2015-03-06 18:04 - 00000000 ____D () C:\Program Files (x86)\dollarkeeepper
          2015-02-27 14:34 - 2015-02-27 14:34 - 00000000 ____D () C:\Program Files (x86)\ActiveMail
          2015-02-27 12:13 - 2015-03-06 18:04 - 00000000 ____D () C:\Program Files (x86)\taakesavE
          2015-02-27 12:12 - 2015-02-27 12:12 - 00000000 ____D () C:\Program Files (x86)\Youtube Preview  Is it worth watching
          2015-02-27 11:12 - 2015-02-27 11:12 - 00000000 ____D () C:\Program Files (x86)\taKesaavve
          2015-02-27 11:12 - 2015-02-27 11:12 - 00000000 ____D () C:\Program Files (x86)\coinsaove
          2015-02-26 09:59 - 2015-02-26 09:59 - 00000000 ____D () C:\Program Files (x86)\Renren Album Downloader
          2015-02-26 09:58 - 2015-02-27 12:13 - 00000000 ____D () C:\Program Files (x86)\DealExpREoss
          2015-02-26 09:58 - 2015-02-26 09:58 - 00000000 ____D () C:\Program Files (x86)\DeealExpress
          2015-02-26 09:19 - 2015-01-09 08:44 - 00419936 _____ () C:\windows\SysWOW64\locale.nls
          2015-02-26 09:19 - 2015-01-09 08:43 - 00419936 _____ () C:\windows\system32\locale.nls
          2015-02-23 17:37 - 2015-02-23 17:40 - 00000000 ____D () C:\Users\SS\Downloads\BaDoink.15.02.20.Marica.Haze.Mirrors.Edge.An.XXX.Parody.XXX.1080p.MP4.KTR
           
          ==================== One Month Modified Files and Folders =======
           
          (If an entry is included in the fixlist, the file\folder will be moved.)
           
          2015-03-24 18:19 - 2012-12-05 23:35 - 00000000 ____D () C:\Users\SS\AppData\Roaming\BitTorrent
          2015-03-24 17:47 - 2014-10-08 07:46 - 00000890 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
          2015-03-24 17:47 - 2014-01-11 10:20 - 00000896 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA.job
          2015-03-24 17:47 - 2014-01-11 10:20 - 00000844 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core.job
          2015-03-24 07:32 - 2012-04-21 21:43 - 01343471 _____ () C:\windows\WindowsUpdate.log
          2015-03-24 00:34 - 2014-10-08 07:46 - 00000886 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
          2015-03-23 23:58 - 2012-12-16 13:12 - 00000000 ____D () C:\Users\SS\AppData\Roaming\vlc
          2015-03-23 19:25 - 2009-07-14 13:51 - 00155268 _____ () C:\windows\setupact.log
          2015-03-23 18:19 - 2012-12-05 21:28 - 00000000 ____D () C:\Users\SS\AppData\Local\VirtualStore
          2015-03-23 17:44 - 2014-12-29 16:21 - 00000000 ____D () C:\ProgramData\2a436ad1c7d245ce
          2015-03-23 17:40 - 2015-02-04 17:26 - 00000020 _____ () C:\Users\SS\AppData\Roaming\appdataFr3.bin
          2015-03-22 22:14 - 2012-12-07 08:50 - 00000000 ____D () C:\Users\SS\AppData\Roaming\Skype
          2015-03-21 11:29 - 2009-07-14 13:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
          2015-03-21 11:29 - 2009-07-14 13:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
          2015-03-20 06:19 - 2013-02-19 23:00 - 00000000 ____D () C:\Program Files\Microsoft Office 15
          2015-03-16 22:18 - 2009-07-14 14:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
          2015-03-16 19:42 - 2010-11-21 12:47 - 00661816 _____ () C:\windows\PFRO.log
          2015-03-16 19:14 - 2015-01-18 11:47 - 00000000 ____D () C:\ProgramData\MiINImmumPrice
          2015-03-16 19:14 - 2014-12-29 16:24 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
          2015-03-16 19:13 - 2014-12-29 16:21 - 00000000 ____D () C:\Program Files (x86)\Supporter
          2015-03-14 01:40 - 2013-02-19 08:57 - 00000000 ____D () C:\Users\SS\Desktop\CARLOS
          2015-03-12 15:41 - 2014-03-16 22:04 - 00000000 ___RD () C:\Program Files (x86)\Skype
          2015-03-12 15:40 - 2012-04-21 06:13 - 00000000 ____D () C:\ProgramData\Skype
          2015-03-12 15:35 - 2009-07-14 13:45 - 00370488 _____ () C:\windows\system32\FNTCACHE.DAT
          2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\SysWOW64\tr-TR
          2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
          2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\system32\tr-TR
          2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\system32\Dism
          2015-03-12 14:16 - 2013-12-09 22:51 - 00000000 ____D () C:\windows\system32\MRT
          2015-03-12 14:02 - 2013-12-09 22:51 - 122905848 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
          2015-03-11 22:22 - 2012-12-05 22:00 - 00656980 _____ () C:\windows\system32\perfh01F.dat
          2015-03-11 22:22 - 2012-12-05 22:00 - 00140326 _____ () C:\windows\system32\perfc01F.dat
          2015-03-11 22:22 - 2012-04-21 21:15 - 00428722 _____ () C:\windows\system32\perfh012.dat
          2015-03-11 22:22 - 2012-04-21 21:15 - 00120710 _____ () C:\windows\system32\perfc012.dat
          2015-03-11 22:22 - 2009-07-14 14:13 - 02111596 _____ () C:\windows\system32\PerfStringBackup.INI
          2015-03-11 21:29 - 2012-12-25 23:46 - 00000000 ____D () C:\Users\SS\AppData\Local\CrashDumps
          2015-03-11 18:46 - 2012-12-19 23:09 - 00001173 _____ () C:\Users\SS\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
          2015-03-11 18:46 - 2012-12-19 23:09 - 00001149 _____ () C:\Users\Public\Desktop\GOM Player.lnk
          2015-03-11 17:38 - 2015-02-06 16:05 - 00000000 ____D () C:\ProgramData\3045395222265742798
          2015-02-27 12:13 - 2015-02-06 16:05 - 00000000 ____D () C:\Program Files (x86)\NewSaever
          2015-02-26 10:02 - 2014-12-29 16:21 - 00000258 __RSH () C:\ProgramData\ntuser.pol
           
          ==================== Files in the root of some directories =======
           
          2015-02-04 17:26 - 2015-03-23 17:40 - 0000020 _____ () C:\Users\SS\AppData\Roaming\appdataFr3.bin
          2013-08-20 00:12 - 2014-04-22 00:27 - 0000954 _____ () C:\Users\SS\AppData\Roaming\coreavc.ini
          2012-04-21 06:07 - 2012-04-21 06:08 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
          2012-04-21 06:02 - 2012-04-21 06:02 - 0000113 _____ () C:\ProgramData\{34FBC7C4-CD31-4D93-A428-0E524EAC4586}.log
          2012-04-21 06:05 - 2012-04-21 06:05 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
          2012-04-21 06:02 - 2012-04-21 06:05 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log
          2012-04-21 06:05 - 2012-04-21 06:07 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
           
          Some content of TEMP:
          ====================
          C:\Users\SS\AppData\Local\Temp\SkypeSetup.exe
           
           
          ==================== Bamital & volsnap Check =================
           
          (There is no automatic fix for files that do not pass verification.)
           
          C:\Windows\System32\winlogon.exe => File is digitally signed
          C:\Windows\System32\wininit.exe => File is digitally signed
          C:\Windows\SysWOW64\wininit.exe => File is digitally signed
          C:\Windows\explorer.exe => File is digitally signed
          C:\Windows\SysWOW64\explorer.exe => File is digitally signed
          C:\Windows\System32\svchost.exe => File is digitally signed
          C:\Windows\SysWOW64\svchost.exe => File is digitally signed
          C:\Windows\System32\services.exe => File is digitally signed
          C:\Windows\System32\User32.dll => File is digitally signed
          C:\Windows\SysWOW64\User32.dll => File is digitally signed
          C:\Windows\System32\userinit.exe => File is digitally signed
          C:\Windows\SysWOW64\userinit.exe => File is digitally signed
          C:\Windows\System32\rpcss.dll => File is digitally signed
          C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
           
           
          LastRegBack: 2015-03-15 12:54
           
          ==================== End Of Log ============================
          Download CKScanner by askey127 from Here & save it to your Desktop.
          • Doubleclick CKScanner.exe then click Search For Files
          • When the cursor hourglass disappears, click Save List To File
          • A message box will verify the file saved
          • Please Run this program only once
          • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
          •  
             
            Also I need to see the Additions log from FRST, it should be on your desktop

            Here's the additions log and CK files log:

            Additions:

            Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
            Ran by [removed] at 2015-03-24 21:11:06
            Running from C:\Users\[removed]\Desktop
            Boot Mode: Normal
            ==========================================================
             
             
            ==================== Security Center ========================
             
            (If an entry is included in the fixlist, it will be removed.)
             
            AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
            AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
             
            ==================== Installed Programs ======================
             
            (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
             
            ActiveMail (HKLM-x32\…\{89AE616B-E500-0C2D-D0D2-F444CEEB4619}) (Version:  - "")
            Adobe Flash Player 10 ActiveX (HKLM-x32\…\{48DB5914-8772-472D-B8DF-E2092BE598F6}) (Version: 10.3.181.34 - Adobe Systems Incorporated)
            Adobe Reader 9.5.5 - Korean (HKLM-x32\…\{AC76BA86-7AD7-1042-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
            AhnLab Online Security (HKLM-x32\…\AhnLab Online Security) (Version:  - AhnLab, Inc)
            Audacity 2.0.5 (HKLM-x32\…\Audacity_is1) (Version: 2.0.5 - Audacity Team)
            BitTorrent (HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\BitTorrent) (Version: 7.9.2.38914 - BitTorrent Inc.)
            calibre (HKLM-x32\…\{4BF56EFD-2F39-40F2-89BB-CF9D3550A806}) (Version: 2.17.0 - Kovid Goyal)
            coinsaove (HKLM-x32\…\{C8AAF59A-6BAA-F68B-9470-A856460A8093}) (Version:  - "") <==== ATTENTION
            ComicRack v0.9.156 (HKLM\…\ComicRack) (Version: v0.9.156 - cYo Soft)
            CyberLink Media Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink Corp.)
            CyberLink Media+ Player10 (HKLM-x32\…\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 - CyberLink Corp.)
            CyberLink MediaShow (HKLM-x32\…\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1130a - CyberLink Corp.)
            CyberLink Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.)
            CyberLink PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3306 - CyberLink Corp.)
            CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4417 - CyberLink Corp.)
            D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
            Easy Content Share (HKLM-x32\…\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD)
            Easy Migration (HKLM-x32\…\{AD86049C-3D9C-43E1-BE73-643F57D83D50}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
            EasyFileShare (HKLM-x32\…\{16880765-677F-440B-B16A-BFD9B9C00012}) (Version: 1.0.12 - Samsung)
            Eco Mode (HKLM-x32\…\{9A8E4762-3331-4EDB-8E1F-B11179DDBC00}) (Version: 1.0.0.11 - Samsung Electronics Co., Ltd.)
            E-POP (HKLM-x32\…\{75282161-8CAC-4071-A225-EBC95E43C7F3}) (Version: 1.00.0000 - Samsung)
            ETDWare PS/2-X64 8.0.7.2_WHQL (HKLM\…\Elantech) (Version: 8.0.7.2 - ELAN Microelectronic Corp.)
            GOM Player (HKLM-x32\…\GOM Player) (Version: 2.2.67.5221 - Gretech Corporation)
            Google Chrome (HKLM-x32\…\Google Chrome) (Version: 39.0.2171.99 - Google Inc.)
            Google Talk Plugin (HKLM-x32\…\{0C5C1177-94C5-3EFB-A8BE-3F6AF1AF887F}) (Version: 5.38.6.0 - Google)
            Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
            Hanword HWP document converter for Microsoft Word (x64) (HKLM\…\{90150000-2009-0409-1000-0000000FF1CE}) (Version: 15.0.4454.1506 - Microsoft Corporation)
            Hanword HWP document converter for Microsoft Word (x86) (HKLM-x32\…\{90150000-2009-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1506 - Microsoft Corporation)
            INISAFE SandBox 1.0 (HKLM-x32\…\INISAFE SandBox) (Version: 1.0 - Initech, Inc.)
            Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
            Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
            Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2266 - Intel Corporation)
            Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
            Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\…\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel)
            Intel(R) WiDi (HKLM-x32\…\{E1B934BB-6AFA-429F-98E4-76F9CBC72BF6}) (Version: 2.2.14.0 - Intel Corporation)
            Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
            Interactive Guide (HKLM-x32\…\{CB383BE9-7518-4ABD-826E-8FC4695F7D52}) (Version: 1.1 - )
            Java 7 Update 67 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.670 - Oracle)
            Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
            KakaoTalk (HKLM-x32\…\KakaoTalk) (Version: 2.0.4.786 - Kakao)
            LG United Mobile Drivers (HKLM-x32\…\{C2944BE7-9BFF-4EF0-A362-CB3281B7C50D}) (Version: 3.6.0.0 - LG Electronics)
            Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
            Media Center 한글 입력기 (HKLM-x32\…\{BB9A1C85-8841-4755-A4D3-E3EEC3EFD3F0}) (Version: 3.1.5.0 - Samsung Electronics Co., LTD)
            Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
            Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
            Microsoft Office Home and Student 2013 - en-us (HKLM\…\HomeStudentRetail - en-us) (Version: 15.0.4701.1002 - Microsoft Corporation)
            Microsoft Office 언어 교정 도구 2013 - 한국어 (HKLM-x32\…\{90150000-001F-0412-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
            Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
            Microsoft SkyDrive (HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
            Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
            Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
            Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
            Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
            Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
            Multimedia POP (HKLM-x32\…\{331ECF61-69AF-4F57-AC35-AFED610231C3}) (Version: 1.2 - )
            NVIDIA 그래픽 드라이버 267.54 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.54 - NVIDIA Corporation)
            Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
            Office 15 Click-to-Run Licensing Component (Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
            Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
            PhoneShare (HKLM-x32\…\{3F50512F-53DF-46B1-8CCB-6C7E638CADD6}) (Version: 9.1.4 - Samsung)
            Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek)
            Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6400 - Realtek Semiconductor Corp.)
            Renren Album Downloader (HKLM-x32\…\{AF992111-52BE-832B-5882-8477E4A3C99A}) (Version:  - "") <==== ATTENTION
            Samsung AnyWeb Print (HKLM-x32\…\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 2.0.67.1 - Samsung Electronics Co., Ltd.)
            Samsung Control Center (HKLM-x32\…\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
            Samsung Printer Live Update (HKLM-x32\…\Samsung Printer Live Update) (Version:  - Samsung Electronics Co., Ltd.)
            Samsung Recovery Solution 5 (HKLM-x32\…\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.1.3 - Samsung)
            Samsung Support Center (HKLM-x32\…\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.26 - Samsung)
            Samsung Universal Print Driver (HKLM-x32\…\Samsung Universal Print Driver) (Version: 2.02.05.00:27 - Samsung Electronics Co., Ltd.)
            Samsung Universal Scan Driver (HKLM-x32\…\Samsung Universal Scan Driver) (Version: 1.2.5.0 - Samsung Electronics Co., Ltd.)
            Samsung Update Plus (HKLM-x32\…\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.0.17 - Samsung Electronics Co., Ltd.)
            SISShortcut (HKLM-x32\…\{FDAE128F-A355-42B1-8422-1AF3ACEE34F4}) (Version: 1.00.000 - Samsung)
            Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
            Skype™ 7.1 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
            Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
            User Guide (HKLM-x32\…\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.3 - )
            Veraport20(Security module management) - 2,5,6,1 (HKLM-x32\…\{2D992E01-604B-472C-A883-1DDA105A24D5}_is1) (Version: 2,5,6,1 - Wizvera)
            VLC media player 2.0.4 (HKLM-x32\…\VLC media player) (Version: 2.0.4 - VideoLAN)
            Vuze Remote Toolbar (HKLM-x32\…\Vuze_Remote Toolbar) (Version: 6.9.0.16 - Vuze Remote) <==== ATTENTION
            Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
            Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
            WinRAR 4.20 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
            WordCaptureX Pro (HKLM-x32\…\{139C1D95-9037-3AB3-F5F4-4A79BF6831EC}) (Version: 4.0.0 - Deskperience)
            XecureWeb Control (HKLM-x32\…\XecureWeb Control) (Version:  - )
            Youtube Preview  Is it worth watching (HKLM-x32\…\{CDFBAC3A-2FE1-0B77-34C9-065BBCC8B77C}) (Version:  - "") <==== ATTENTION
            원격 연결을 위한 Windows Live Mesh ActiveX 컨트롤 (HKLM-x32\…\{61920449-0393-4707-B7DD-E6C0013C8B2C}) (Version: 15.4.5722.2 - Microsoft Corporation)
            인텔(R) PROSet/무선 WiMAX 소프트웨어 (HKLM\…\{5C1DA3D9-F590-4317-A4FB-274F658E504B}) (Version: 6.05.0001 - Intel Corporation)
            인텔® PROSet/무선 WiFi 소프트웨어 (HKLM\…\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation)
             
            ==================== Custom CLSID (selected items): ==========================
             
            (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
             
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
             
            ==================== Restore Points  =========================
             
            16-03-2015 18:46:22 AA11
            23-03-2015 17:32:33 AA11
             
            ==================== Hosts content: ==========================
             
            (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
             
            2009-07-14 11:34 - 2015-03-03 20:25 - 00450892 ____R C:\windows\system32\Drivers\etc\hosts
            127.0.0.1 www.007guard.com
            127.0.0.1 007guard.com
            127.0.0.1 008i.com
            127.0.0.1 www.008k.com
            127.0.0.1 008k.com
            127.0.0.1 www.00hq.com
            127.0.0.1 00hq.com
            127.0.0.1 010402.com
            127.0.0.1 www.032439.com
            127.0.0.1 032439.com
            127.0.0.1 www.0scan.com
            127.0.0.1 0scan.com
            127.0.0.1 www.1000gratisproben.com
            127.0.0.1 1000gratisproben.com
            127.0.0.1 1001namen.com
            127.0.0.1 www.1001namen.com
            127.0.0.1 100888290cs.com
            127.0.0.1 www.100888290cs.com
            127.0.0.1 www.100sexlinks.com
            127.0.0.1 100sexlinks.com
            127.0.0.1 www.10sek.com
            127.0.0.1 10sek.com
            127.0.0.1 www.1-2005-search.com
            127.0.0.1 1-2005-search.com
            127.0.0.1 www.123fporn.info
            127.0.0.1 123fporn.info
            127.0.0.1 123haustiereundmehr.com
            127.0.0.1 www.123haustiereundmehr.com
            127.0.0.1 123moviedownload.com
             
            There are 1000 more lines.
             
             
            ==================== Scheduled Tasks (whitelisted) =============
             
            (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
             
            Task: {03A10DB7-9071-4EEF-B9CB-F411EA94735C} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Samsung Control Center\SmartSetting.exe [2011-06-04] (Samsung Electronics Co., Ltd.)
            Task: {0A384BD9-2CAB-42DF-8601-6D380A53BFEB} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Samsung Control Center\SCCSpeedBoot.exe [2011-05-18] (Samsung Electronics Co., Ltd.)
            Task: {0CFBF115-D843-433D-8B12-14C46A4A3BDA} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2011-03-29] (SEC)
            Task: {1645AE87-AC06-4F79-9291-63F734344ECA} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-08-17] (CyberLink)
            Task: {28A63C7E-40C7-4D78-9EBE-60FB6CE6E95B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
            Task: {2D03498A-F669-4E65-8297-264723A0C017} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2011-04-17] (SAMSUNG Electronics)
            Task: {2DB56CE1-EAD1-4215-9D66-960A74B181F9} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
            Task: {2F5C19D8-2F72-434D-9A4B-551DBD945E72} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
            Task: {3468239E-CD89-4747-90F5-DCCB45BA2FCB} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
            Task: {398E535C-CC80-4CF3-9698-34C0F76AD90A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
            Task: {3F7881E2-661E-42EB-8913-ABFD71584BC0} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
            Task: {4A805CAE-69C4-4139-A3D2-995EC8A4FEA1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-15] (Google Inc.)
            Task: {6AB036E6-C87E-4750-9D49-01D6931EFB37} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Samsung Control Center\MovieColorEnhancer.exe [2011-02-17] (Samsung Electronics Co., Ltd.)
            Task: {76BC4D0C-1132-487C-85F2-7120F1BF7473} - System32\Tasks\Microsoft Office 15 Sync Maintenance for SS-PC-SS SS-PC => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation)
            Task: {7E430DF2-7F3D-45FC-A8E6-757D48DAC111} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe [2010-08-27] (Samsung Electronics)
            Task: {A0618927-0C2F-4AB6-B49A-AECA2955850A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-15] (Google Inc.)
            Task: {A957AD76-D965-4019-82E7-04133BD83B27} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Samsung Control Center\WifiManager.exe [2012-03-08] (Samsung Electronics Co., Ltd.)
            Task: {BB1B4464-B9EC-4474-8C84-31A56602CAE2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
            Task: {C7519AC8-6F25-4BAD-BAFE-E7D925D18572} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Samsung Control Center\dmhkcore.exe [2011-06-15] (Samsung Electronics Co., Ltd.)
            Task: {DE28C41A-1C1E-46B7-9DE8-7E610E5C2B14} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Samsung Control Center\EBM\EasyBatteryMgr4.exe [2011-07-02] (SAMSUNG Electronics co., LTD.)
            Task: {E924E8DA-3600-4ED2-82A9-AB458CDC5AF9} - System32\Tasks\EcoMode => C:\Program Files (x86)\Samsung\Eco Mode\SmartEco.exe [2011-06-06] (Samsung Electronics)
            Task: {E937FD97-F248-4672-85D2-684AEA989A33} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
            Task: {EB02381F-D652-4B1C-894A-712498C62C51} - \Microsoft\Windows\MUI\LPRemove No Task File <==== ATTENTION
            Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
            Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
            Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core.job => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
            Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA.job => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
             
            ==================== Loaded Modules (whitelisted) ==============
             
            2012-04-21 21:01 - 2008-06-05 08:53 - 00027648 _____ () C:\windows\System32\spd__l.dll
            2014-03-21 17:29 - 2014-05-20 08:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
            2012-04-21 20:59 - 2010-12-17 10:37 - 00094208 _____ () C:\windows\system32\IccLibDll_x64.dll
            2012-04-21 21:01 - 2010-10-22 03:22 - 00709632 _____ () C:\windows\system32\SnMinDrv.dll
            2015-03-20 06:17 - 2015-01-28 00:29 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
            2014-12-29 16:28 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
            2014-12-29 16:28 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
            2014-12-29 16:28 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
            2014-12-29 16:28 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
            2014-12-29 16:28 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
            2012-04-21 06:14 - 2011-02-17 00:03 - 00203776 _____ () C:\Program Files (x86)\Samsung\Samsung Control Center\WinCRT.dll
            2012-04-21 06:14 - 2006-08-12 11:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Samsung Control Center\HookDllPS2.dll
            2009-11-02 14:20 - 2009-11-02 14:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
            2009-11-02 14:23 - 2009-11-02 14:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
            2012-04-21 06:15 - 2010-05-07 23:22 - 01636864 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
            2015-01-15 00:29 - 2015-01-09 09:35 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libglesv2.dll
            2015-01-15 00:29 - 2015-01-09 09:35 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libegl.dll
            2015-01-15 00:29 - 2015-01-09 09:35 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\pdf.dll
            2015-01-15 00:29 - 2015-01-09 09:35 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\ffmpegsumo.dll
            2015-01-15 00:29 - 2015-01-09 09:35 - 14913352 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\PepperFlash\pepflashplayer.dll
            2014-01-31 12:28 - 2014-01-31 12:28 - 00421520 _____ () C:\Program Files (x86)\GRETECH\GomPlayer\GomTVStrm.dll
             
            ==================== Alternate Data Streams (whitelisted) =========
             
            (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
             
             
            ==================== Safe Mode (whitelisted) ===================
             
            (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
             
             
            ==================== EXE Association (whitelisted) ===============
             
            (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
             
             
            ==================== Other Areas ============================
             
            (Currently there is no automatic fix for this section.)
             
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\SS\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
            DNS Servers: [removed] - [removed]
             
            ==================== MSCONFIG/TASK MANAGER disabled items ==
             
            (Currently there is no automatic fix for this section.)
             
             
            ==================== Accounts: =============================
             
            Administrator (S-1-5-21-3476611405-1961159229-2615470741-500 - Administrator - Disabled)
            Guest (S-1-5-21-3476611405-1961159229-2615470741-501 - Limited - Disabled)
            SS (S-1-5-21-3476611405-1961159229-2615470741-1001 - Administrator - Enabled) => C:\Users\SS
            UpdatusUser (S-1-5-21-3476611405-1961159229-2615470741-1000 - Limited - Enabled) => C:\Users\UpdatusUser
             
            ==================== Faulty Device Manager Devices =============
             
            Name: Teredo Tunneling Pseudo-Interface
            Description: Microsoft Teredo Tunneling Adapter
            Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
            Manufacturer: Microsoft
            Service: tunnel
            Problem: : This device cannot start. (Code10)
            Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
            On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
             
             
            ==================== Event log errors: =========================
             
            Application errors:
            ==================
             
            System errors:
            =============
             
            Microsoft Office Sessions:
            =========================
             
            ==================== Memory info =========================== 
             
            Processor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz
            Percentage of memory in use: 75%
            Total physical RAM: 4009.55 MB
            Available physical RAM: 1001.93 MB
            Total Pagefile: 8017.28 MB
            Available Pagefile: 4102.98 MB
            Total Virtual: 8192 MB
            Available Virtual: 8191.84 MB
             
            ==================== Drives ================================
             
            Drive c: () (Fixed) (Total:179 GB) (Free:39.77 GB) NTFS
            Drive d: () (Fixed) (Total:266.57 GB) (Free:253.66 GB) NTFS
             
            ==================== MBR & Partition Table ==================
             
            ========================================================
            Disk: 0 (Size: 465.8 GB) (Disk ID: A80DEEF6)
            Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
            Partition 2: (Not Active) - (Size=179 GB) - (Type=07 NTFS)
            Partition 3: (Not Active) - (Size=266.6 GB) - (Type=OF Extended)
            Partition 4: (Not Active) - (Size=20.1 GB) - (Type=27)
             
            ==================== End Of Log ============================
             
             
            and Ckscanner:

            CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
            c:\program files\comicrack\changes.txt
            c:\program files\comicrack\comicrack.engine.display.forms.dll
            c:\program files\comicrack\comicrack.engine.dll
            c:\program files\comicrack\comicrack.exe
            c:\program files\comicrack\comicrack.exe.config
            c:\program files\comicrack\comicrack.ini
            c:\program files\comicrack\comicrack.plugins.dll
            c:\program files\comicrack\comicrack.url
            c:\program files\comicrack\cyo.common.dll
            c:\program files\comicrack\cyo.common.presentation.dll
            c:\program files\comicrack\cyo.common.windows.dll
            c:\program files\comicrack\defaultlists.txt
            c:\program files\comicrack\icsharpcode.sharpziplib.dll
            c:\program files\comicrack\ironpython.dll
            c:\program files\comicrack\ironpython.modules.dll
            c:\program files\comicrack\license.txt
            c:\program files\comicrack\microsoft.dynamic.dll
            c:\program files\comicrack\microsoft.scripting.dll
            c:\program files\comicrack\microsoft.scripting.metadata.dll
            c:\program files\comicrack\microsoft.windowsapicodepack.dll
            c:\program files\comicrack\microsoft.windowsapicodepack.shell.dll
            c:\program files\comicrack\newstemplate.html
            c:\program files\comicrack\readme.txt
            c:\program files\comicrack\sharppdf.dll
            c:\program files\comicrack\tao.opengl.dll
            c:\program files\comicrack\tao.platform.windows.dll
            c:\program files\comicrack\uninst.exe
            c:\program files\comicrack\windows7.multitouch.dll
            c:\program files\comicrack\help\comicrack introduction.djvu
            c:\program files\comicrack\help\comicrack introduction.djvu.xml
            c:\program files\comicrack\help\comicrack online manual.ini
            c:\program files\comicrack\help\comicrack wiki.ini
            c:\program files\comicrack\help\readme.txt
            c:\program files\comicrack\languages\cs-cz.zip
            c:\program files\comicrack\languages\de.zip
            c:\program files\comicrack\languages\el-gr.zip
            c:\program files\comicrack\languages\es.zip
            c:\program files\comicrack\languages\fi.zip
            c:\program files\comicrack\languages\fr.zip
            c:\program files\comicrack\languages\hr.zip
            c:\program files\comicrack\languages\hu.zip
            c:\program files\comicrack\languages\it.zip
            c:\program files\comicrack\languages\ja.zip
            c:\program files\comicrack\languages\nl-be.zip
            c:\program files\comicrack\languages\pl.zip
            c:\program files\comicrack\languages\pt-br.zip
            c:\program files\comicrack\languages\ru.zip
            c:\program files\comicrack\languages\sk-sk.zip
            c:\program files\comicrack\languages\tr.zip
            c:\program files\comicrack\languages\zh-cn.zip
            c:\program files\comicrack\languages\zh-hans.zip
            c:\program files\comicrack\languages\zh.zip
            c:\program files\comicrack\resources\7z.dll
            c:\program files\comicrack\resources\7z.exe
            c:\program files\comicrack\resources\7z64.dll
            c:\program files\comicrack\resources\c44.exe
            c:\program files\comicrack\resources\ddjvu.exe
            c:\program files\comicrack\resources\djvm.exe
            c:\program files\comicrack\resources\libdjvulibre.dll
            c:\program files\comicrack\resources\libjpeg.dll
            c:\program files\comicrack\resources\libtiff.dll
            c:\program files\comicrack\resources\libz.dll
            c:\program files\comicrack\resources\icons\ageratings.zip
            c:\program files\comicrack\resources\icons\ageratings_australia.zip
            c:\program files\comicrack\resources\icons\formats.zip
            c:\program files\comicrack\resources\icons\publishers.zip
            c:\program files\comicrack\resources\icons\special.zip
            c:\program files\comicrack\scripts\autonumber.py
            c:\program files\comicrack\scripts\commitproposed.py
            c:\program files\comicrack\scripts\newcomics.py
            c:\program files\comicrack\scripts\otherscripts.py
            c:\program files\comicrack\scripts\package.ini
            c:\program files\comicrack\scripts\sample.py
            c:\program files\comicrack\scripts\sample.xml
            c:\program files\comicrack\scripts\searchandreplace.py
            c:\users\ss\desktop\unused\new folder\adobe photoshop cs4\cs4 keygen\adobe-master-cs4pre-keygen.exe
            c:\users\ss\desktop\unused\new folder\adobe photoshop cs4\cs4 keygen\amtlib.dll
            c:\users\ss\desktop\unused\new folder\adobe photoshop cs4\cs4 keygen\crack.bat
            c:\users\ss\desktop\unused\new folder\adobe photoshop cs4\cs4 keygen\distro.ico
            c:\users\ss\desktop\unused\new folder\adobe photoshop cs4\cs4 keygen\mazuki.nfo
            c:\users\ss\desktop\unused\new folder\adobe photoshop cs4\cs4 keygen\readme.txt
            c:\users\ss\downloads\comicracksetup09156.exe
            scanner sequence 3.ZZ.11.NUNAPZ
             —– EOF —– 
             
            You have illegal software on your system, this is how you infected your computer, besides it being illegal,  cracked/keygens are one of the fastest ways of infecting your system,  100% of Cracked/KeyGen software contains some form of malicious code. This forum as well as most of the other malware removal forums do not support the use of illegal software, if I was to continue helping you it could be construed in the eyes of the law as aiding and abetting a crime.  In using the crack, the 'cracker' has broken the 'End User Licence Agreement' (EULA) of the product concerned. The distribution and use of cracked software is illegal in almost every developed country.  They are also one of the biggest causes of infection. This applies to Cracks, Keygens and Warez
             
            In the future I strongly suggest you stay away from using cracks and/or Keygens. If you want to continue, what I need you to do is to look through the CKScanner log and uninstall all the illegal software that you have downloaded and installed . After you uninstall them all, run CKScanner again and post a new log.  If I dont hear back from you in 24 hours this thread will be closed and no more help will be offered.

            Thanks a lot for the 2nd chance and the 24hr buffer. Here is the new CKScanner log. 

             

            CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
            scanner sequence 3.RP.11.DCCPJ0
             —– EOF —– 

            So now you know how you infected your computer, my advice to you is stay away from the torrents and any cracked or keygen software, there very bad news and some of the latest infections can steal your banking and credit card info, not nice, thanks for understanding our position

             

            Go ahead and run a new scan with FRST64, make sure you check mark Additions and post both new  logs

            I'll definitely take your advice. Here are the two updated logs. Due to the time difference I might not be checking in for a while, just in case it looks like I abandoned the thread. 

            FRST updated: 

            Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
            Ran by [removed] (administrator) on SS-PC on 25-03-2015 01:15:56
            Running from C:\Users\[removed]\Desktop
            [removed]
            Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
            Internet Explorer Version 11 (Default browser not detected!)
            Boot Mode: Normal
            Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
             
            ==================== Processes (Whitelisted) =================
             
            (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
             
            (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
            (Microsoft Corporation) C:\Windows\System32\wlanext.exe
            (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
            (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
            (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
            (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
            (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
            (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
            (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
            (Intel(R) Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
            (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
            (Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
            (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
            (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
            (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
            (Microsoft Corporation) C:\Windows\System32\StikyNot.exe
            (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
            (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
            (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
            (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\SmartSetting.exe
            (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
            (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\dmhkcore.exe
            (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\MovieColorEnhancer.exe
            (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\WifiManager.exe
            (Intel Corporation) C:\Windows\System32\igfxext.exe
            (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
            (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
            (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
            (Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
            (Intel Corporation) C:\Windows\System32\hkcmd.exe
            (Intel Corporation) C:\Windows\System32\igfxpers.exe
            (Samsung Electronics) C:\Program Files (x86)\Samsung\Eco Mode\SmartEco.exe
            (Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe
            (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
            (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
            (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
            (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
            (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
            (Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
            (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
            (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
            (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
            (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Gretech Corp.) C:\Program Files (x86)\GRETECH\GomPlayer\GOM.EXE
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
            (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
             
             
            ==================== Registry (Whitelisted) ==================
             
            (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
             
            HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11895400 2011-06-25] (Realtek Semiconductor)
            HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2588968 2010-11-13] (ELAN Microelectronics Corp.)
            HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-09] (Adobe Systems Incorporated)
            HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
            HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
            HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
            Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [ctfmon] => C:\windows\system32\ctfmon.exe [9728 2009-07-14] (Microsoft Corporation)
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [Spybot-S&D; Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Policies\Explorer: [NoLowDiskSpaceChecks] 1
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\MountPoints2: {9a7c915e-34b5-11e2-bdd9-806e6f6e6963} - E:\PLAY.EXE "playlist.m3u"
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\MountPoints2: {b02a9a3b-7a26-11e2-b71f-50b7c307cd39} - F:\LGAutoRun.exe
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Bubbles.scr [899584 2010-11-21] (Microsoft Corporation)
            GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
            CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
             
            ==================== Internet (Whitelisted) ====================
             
            (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
             
            HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
            HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
            HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
            HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
            HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
            HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.samsung.com/sec
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
            SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
            SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
            SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
            BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
            BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
            BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-02-10] (Microsoft Corporation)
            BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-02-10] (Microsoft Corporation)
            BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
            BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-02-10] (Microsoft Corporation)
            Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
            Handler-x32: s-http - {D37E6C5F-1C0F-47C0-A3B6-403EEC555402} - C:\Program Files (x86)\Initech\SHTTP\InitechSHTTPInterface.11014.dll [2013-02-08] (© INITECH)
            Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
            Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
            Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
            Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
            Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
            Tcpip\..\Interfaces\{83395AC7-FE87-4186-91C3-A6BE63F9820B}: [NameServer] 168.126.63.1,168.126.63.2
             
            FireFox:
            ========
            FF Plugin: @microsoft.com/GENUINE -> disabled No File
            FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
            FF Plugin: @qvod.com/QvodShare -> C:\Program Files (x86)\QvodPlayer\npShareModule_x64.dll No File
            FF Plugin-x32: @ahnlab.com/asp/npaosmgr.1 -> C:\Program Files (x86)\AhnLab\ASP\Components\aosmgr\npaosmgr.dll [2014-08-05] (AhnLab, Inc.)
            FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-25] (Oracle Corporation)
            FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-25] (Oracle Corporation)
            FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
            FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
            FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-07-12] (Microsoft Corporation)
            FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
            FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
            FF Plugin-x32: @softforum.com/npxwebplugins -> C:\Program Files (x86)\SoftForum\XecureWeb\ActiveX\npxwebplugin.dll [2009-05-28] (SoftForum)
            FF Plugin-x32: @softforum.com/npxwebplugins_file -> C:\Program Files (x86)\SoftForum\XecureWeb\ActiveX\npxwebplugin_file.dll [2009-05-28] (SoftForum Co., Ltd.)
            FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2015-01-15] (Google Inc.)
            FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2015-01-15] (Google Inc.)
            FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-10-16] (VideoLAN)
            FF Plugin-x32: @wizvera.com/npVeraport20 -> C:\Program Files (x86)\Wizvera\Veraport20\npveraport20.dll [2013-11-15] ()
            FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
            FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @iniline.com/npCrossWeb -> C:\Users\SS\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0AB9084F-0EF8-499a-A461-DE46D3C4A45B}\plugins\npCrossWeb.dll [2014-12-05] (INITECH Co., Ltd.)
            FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @initech.com/npSandBox -> C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.10052.dll [2014-11-27] (Initech Co., Ltd.)
            FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @qvod.com/QvodInsert -> C:\Program Files (x86)\QvodPlayer\npQvodInsert.dll No File
            FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\SS\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2014-10-29] (Google)
            FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @talk.google.com/O1DPlugin -> C:\Users\SS\AppData\Roaming\Mozilla\plugins\npo1d.dll [2014-10-29] (Google)
            FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @tools.google.com/Google Update;version=3 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
            FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @tools.google.com/Google Update;version=9 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
            FF Plugin ProgramFiles/Appdata: C:\Users\SS\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2014-10-29] (Google)
            FF Plugin ProgramFiles/Appdata: C:\Users\SS\AppData\Roaming\mozilla\plugins\npo1d.dll [2014-10-29] (Google)
            FF Extension: INISAFE CrossWeb - C:\Users\SS\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0AB9084F-0EF8-499a-A461-DE46D3C4A45B} [2015-01-30]
            FF HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.xpi
            FF Extension: INISAFE SandBox - C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.xpi [2014-11-27]
             
            Chrome: 
            =======
            CHR dev: Chrome dev build detected! <======= ATTENTION
            CHR Profile: C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1
            CHR Extension: (Google Drive) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-15]
            CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-15]
            CHR Extension: (Chromebleed) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eeoekjnjgppnaegdjbcafdggilajhpic [2015-01-15]
            CHR Extension: (AdBlock) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-15]
            CHR Extension: (ActiveMail) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmbjhlidpnohinigphldbcffhikcill [2015-02-27]
            CHR Extension: (StayFocusd) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2015-01-15]
            CHR Extension: (Skype Click to Call) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-01-13]
            CHR Extension: (Youtube Preview  Is it worth watching) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nacgopecogaedhhjdfondlcobjofdhap [2015-02-27]
            CHR Extension: (Google Wallet) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-15]
            CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
             
            ==================== Services (Whitelisted) =================
             
            (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
             
            R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
            R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
            R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2714800 2015-02-10] (Microsoft Corporation)
            R2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [498688 2011-11-21] (Red Bend Ltd.) [File not signed]
            R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-03-17] (Malwarebytes Corporation)
            R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
            S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] ()
            S3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed]
            R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
            R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
            R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
            R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [986112 2011-11-21] (Intel(R) Corporation) [File not signed]
            S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
            R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation)
             
            ==================== Drivers (Whitelisted) ====================
             
            (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
             
            R1 AMonTDLH; C:\windows\system32\Drivers\AMonTDLH.sys [118072 2012-09-14] (AhnLab, Inc.)
            S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2011-09-06] (Google Inc)
            S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2011-09-06] (LG Electronics Inc.)
            S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [35840 2011-09-06] (LG Electronics Inc.)
            S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93184 2011-09-16] (LG Electronics Inc.)
            S3 CdmDrvNt; C:\windows\system32\Drivers\CdmDrvNt.sys [25656 2009-07-21] (AhnLab, Inc.)
            R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
            R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-03-25] (Malwarebytes Corporation)
            R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
            S3 MfFWEnt; C:\Program Files\AhnLab\ASP\MyFirewall 4.0\MfFWEnt.sys [127224 2014-07-16] (AhnLab, Inc.)
            S3 MfIPSEnt; C:\Program Files\AhnLab\ASP\MyFirewall 4.0\MfIPSEnt.sys [156408 2014-07-16] (AhnLab, Inc.)
            S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-11-23] (Windows (R) 2003 DDK 3790 provider)
            S3 scsk5; C:\Windows\SysWow64\drivers\scsk5.sys [50608 2015-01-30] ()
            S3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2013-05-29] (Spotflux, Inc.)
            S3 AhnFlt2K; \??\C:\windows\system32\drivers\AhnFlt2K.sys [X]
            S3 AhnRec2K; \??\C:\windows\system32\drivers\AhnRec2K.sys [X]
             
            ==================== NetSvcs (Whitelisted) ===================
             
            (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
             
             
            ==================== One Month Created Files and Folders ========
             
            (If an entry is included in the fixlist, the file\folder will be moved.)
             
            2015-03-24 22:39 - 2015-03-24 22:39 - 00000127 _____ () C:\Users\SS\Desktop\ckfiles.txt
            2015-03-24 21:11 - 2015-03-24 21:12 - 00026340 _____ () C:\Users\SS\Desktop\Addition.txt
            2015-03-24 20:56 - 2015-03-24 20:56 - 00468480 _____ () C:\Users\SS\Desktop\CKScanner.exe
            2015-03-24 18:41 - 2015-03-25 01:10 - 00136408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
            2015-03-24 18:40 - 2015-03-24 18:40 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\SS\Downloads\mbam-setup-2.1.4.1018.exe
            2015-03-24 18:40 - 2015-03-24 18:40 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
            2015-03-24 18:40 - 2015-03-24 18:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
            2015-03-24 18:40 - 2015-03-24 18:40 - 00000000 ____D () C:\ProgramData\Malwarebytes
            2015-03-24 18:40 - 2015-03-24 18:40 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
            2015-03-24 18:40 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
            2015-03-24 18:40 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
            2015-03-24 18:40 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
            2015-03-24 18:38 - 2015-03-24 18:38 - 00001192 _____ () C:\Users\SS\Desktop\JRT.txt
            2015-03-24 18:31 - 2015-03-24 18:31 - 01388782 _____ (Thisisu) C:\Users\SS\Desktop\JRT.exe
            2015-03-24 18:29 - 2015-03-24 18:29 - 00014203 _____ () C:\Users\SS\Desktop\AdwCleaner[S0].txt
            2015-03-24 18:21 - 2015-03-24 18:27 - 00000000 ____D () C:\AdwCleaner
            2015-03-24 18:20 - 2015-03-24 18:20 - 02168320 _____ () C:\Users\SS\Desktop\AdwCleaner.exe
            2015-03-23 18:34 - 2015-03-25 01:16 - 00021277 _____ () C:\Users\SS\Desktop\FRST.txt
            2015-03-23 18:31 - 2015-03-23 18:33 - 00034329 _____ () C:\Users\SS\Downloads\Addition.txt
            2015-03-23 18:29 - 2015-03-23 18:33 - 00058279 _____ () C:\Users\SS\Downloads\FRST.txt
            2015-03-23 18:28 - 2015-03-25 01:16 - 00000000 ____D () C:\FRST
            2015-03-23 18:27 - 2015-03-23 18:27 - 02095616 _____ (Farbar) C:\Users\SS\Desktop\FRST64.exe
            2015-03-23 18:25 - 2015-03-23 18:34 - 00001169 _____ () C:\Users\SS\Desktop\aswMBR.txt
            2015-03-23 18:24 - 2015-03-23 18:24 - 05198336 _____ (AVAST Software) C:\Users\SS\Downloads\aswMBR.exe
            2015-03-23 18:20 - 2015-03-23 18:20 - 00013540 _____ () C:\Users\SS\Downloads\hijackthis.log
            2015-03-23 18:19 - 2015-03-23 18:19 - 00388608 _____ (Trend Micro Inc.) C:\Users\SS\Downloads\HijackThis.exe
            2015-03-19 00:39 - 2015-03-19 00:39 - 00000000 ____D () C:\Users\SS\Downloads\BlowjobFridays - Yurizan Beltran - Dick Sucking at Its Finestt 720p [.mp4]
            2015-03-18 18:38 - 2015-03-18 19:03 - 1010408247 _____ () C:\Users\SS\Downloads\chanel_preston_TT_1_JD_1080p_stream.mp4
            2015-03-17 23:49 - 2015-03-18 17:26 - 272288145 _____ () C:\Users\SS\Downloads\BRAZZERS - Doctor Adventures - Doctors Without Bras - Kendra Lust - Rachel Starr [SM128].mkv
            2015-03-17 18:44 - 2015-03-17 18:44 - 00000000 ____D () C:\Users\SS\Downloads\HardX - Mia Malkova (Massive Anal Action) [.mp4]
            2015-03-17 18:22 - 2015-03-17 18:22 - 00000000 ____D () C:\Users\SS\Downloads\Blowjob Friday - Capri Cavanni (Serious BJ skills)
            2015-03-16 18:51 - 2015-03-16 18:51 - 00000000 ____D () C:\Users\SS\AppData\Roaming\LavasoftStatistics
            2015-03-16 18:46 - 2015-03-16 18:46 - 02057008 _____ () C:\Users\SS\Downloads\Adaware_Installer.exe
            2015-03-14 11:49 - 2015-03-14 12:21 - 00000000 ____D () C:\Users\SS\Downloads\The Last Naruto The Movie 2014 720p HDCAM ENG SUBS x264 Pimp4003
            2015-03-12 23:31 - 2015-03-12 23:58 - 480362658 _____ () C:\Users\SS\Downloads\t4k.dillion.harper.excited.little.slut.12.03.15_480.mp4
            2015-03-12 23:31 - 2015-03-12 23:44 - 481824046 _____ () C:\Users\SS\Downloads\Digital_Playground_ge_34601_The_Fuck_Shop_480p_1500.mp4
            2015-03-12 22:35 - 2015-03-12 22:37 - 339871297 _____ () C:\Users\SS\Downloads\BabyGotBoobs - Shawna Lenee - Up Close And Personal With Shawnas Tits  NEW (BRAZZERS  February 11, 2015) NEW.mp4
            2015-03-12 21:15 - 2015-03-12 21:56 - 658123518 _____ () C:\Users\SS\Downloads\HotAndMean - Carter Cruise, Maddy Oreilly_480p.mp4
            2015-03-11 21:27 - 2015-03-11 21:27 - 03471514 _____ () C:\Users\SS\Downloads\Introclass (1).pptx
            2015-03-11 21:27 - 2015-03-11 21:27 - 00958942 _____ () C:\Users\SS\Downloads\Country Bingo.pptx
            2015-03-11 18:28 - 2015-03-11 18:43 - 00000000 ____D () C:\Users\SS\Downloads\Sheena_Shaw_Wide_Open
            2015-03-11 18:08 - 2015-02-20 13:41 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
            2015-03-11 18:08 - 2015-02-20 13:40 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
            2015-03-11 18:08 - 2015-02-20 13:40 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
            2015-03-11 18:08 - 2015-02-20 13:40 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
            2015-03-11 18:08 - 2015-02-20 13:13 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
            2015-03-11 18:08 - 2015-02-20 13:13 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
            2015-03-11 18:08 - 2015-02-20 13:13 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
            2015-03-11 18:08 - 2015-02-20 13:12 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
            2015-03-11 18:08 - 2015-02-20 12:29 - 00372224 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
            2015-03-11 18:08 - 2015-02-20 12:09 - 00299008 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
            2015-03-11 18:08 - 2015-02-03 12:34 - 05554104 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
            2015-03-11 18:08 - 2015-02-03 12:34 - 00094656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
            2015-03-11 18:08 - 2015-02-03 12:33 - 00616360 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
            2015-03-11 18:08 - 2015-02-03 12:31 - 14632960 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
            2015-03-11 18:08 - 2015-02-03 12:31 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
            2015-03-11 18:08 - 2015-02-03 12:31 - 01574400 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
            2015-03-11 18:08 - 2015-02-03 12:30 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
            2015-03-11 18:08 - 2015-02-03 12:30 - 01202176 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
            2015-03-11 18:08 - 2015-02-03 12:16 - 03973048 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
            2015-03-11 18:08 - 2015-02-03 12:16 - 03917760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
            2015-03-11 18:08 - 2015-02-03 12:12 - 11411968 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
            2015-03-11 18:08 - 2015-02-03 12:12 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
            2015-03-11 18:08 - 2015-02-03 12:12 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
            2015-03-11 18:08 - 2015-02-03 12:12 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
            2015-03-11 18:07 - 2015-02-03 12:34 - 00693176 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
            2015-03-11 18:07 - 2015-02-03 12:31 - 00782848 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00641024 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00432128 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00188416 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
            2015-03-11 18:07 - 2015-02-03 12:31 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
            2015-03-11 18:07 - 2015-02-03 12:31 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
            2015-03-11 18:07 - 2015-02-03 12:30 - 01069056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00842240 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00680960 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
            2015-03-11 18:07 - 2015-02-03 12:30 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00146944 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
            2015-03-11 18:07 - 2015-02-03 12:30 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00126464 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
            2015-03-11 18:07 - 2015-02-03 12:30 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
            2015-03-11 18:07 - 2015-02-03 12:30 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
            2015-03-11 18:07 - 2015-02-03 12:30 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
            2015-03-11 18:07 - 2015-02-03 12:30 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
            2015-03-11 18:07 - 2015-02-03 12:30 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
            2015-03-11 18:07 - 2015-02-03 12:30 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe
            2015-03-11 18:07 - 2015-02-03 12:30 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
            2015-03-11 18:07 - 2015-02-03 12:29 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
            2015-03-11 18:07 - 2015-02-03 12:28 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
            2015-03-11 18:07 - 2015-02-03 12:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
            2015-03-11 18:07 - 2015-02-03 12:19 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
            2015-03-11 18:07 - 2015-02-03 12:12 - 01005056 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptui.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00988160 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmv2clt.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00744960 _____ (Microsoft Corporation) C:\windows\SysWOW64\blackbox.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00617984 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmdrmsdk.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscp.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00406016 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmmgrtn.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msnetobj.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00081408 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsp.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
            2015-03-11 18:07 - 2015-02-03 12:12 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
            2015-03-11 18:07 - 2015-02-03 12:12 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
            2015-03-11 18:07 - 2015-02-03 12:11 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
            2015-03-11 18:07 - 2015-02-03 12:11 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
            2015-03-11 18:07 - 2015-02-03 12:11 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
            2015-03-11 18:07 - 2015-02-03 12:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
            2015-03-11 18:07 - 2015-02-03 12:08 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
            2015-03-11 18:07 - 2015-02-03 11:32 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
            2015-03-11 18:07 - 2014-11-01 07:24 - 00619056 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
            2015-03-11 18:06 - 2015-02-13 14:26 - 12875264 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
            2015-03-11 18:06 - 2015-02-13 14:22 - 14177280 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
            2015-03-11 18:06 - 2015-02-03 12:31 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
            2015-03-11 18:06 - 2015-02-03 12:12 - 00171520 _____ (Microsoft Corporation) C:\windows\SysWOW64\ubpm.dll
            2015-03-11 18:05 - 2015-03-06 14:56 - 00155576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
            2015-03-11 18:05 - 2015-03-06 14:56 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
            2015-03-11 18:05 - 2015-03-06 14:42 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
            2015-03-11 18:05 - 2015-03-06 14:42 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
            2015-03-11 18:05 - 2015-03-06 14:42 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
            2015-03-11 18:05 - 2015-03-06 14:42 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
            2015-03-11 18:05 - 2015-03-06 14:42 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
            2015-03-11 18:05 - 2015-03-06 14:42 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
            2015-03-11 18:05 - 2015-03-06 14:42 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
            2015-03-11 18:05 - 2015-03-06 14:42 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
            2015-03-11 18:05 - 2015-03-06 14:42 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
            2015-03-11 18:05 - 2015-03-06 14:42 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
            2015-03-11 18:05 - 2015-03-06 14:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
            2015-03-11 18:05 - 2015-03-06 14:41 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
            2015-03-11 18:05 - 2015-03-06 14:41 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
            2015-03-11 18:05 - 2015-03-06 14:39 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
            2015-03-11 18:05 - 2015-03-06 14:38 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
            2015-03-11 18:05 - 2015-03-06 14:36 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
            2015-03-11 18:05 - 2015-03-06 14:10 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
            2015-03-11 18:05 - 2015-03-06 14:10 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
            2015-03-11 18:05 - 2015-03-06 14:10 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
            2015-03-11 18:05 - 2015-03-06 14:10 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
            2015-03-11 18:05 - 2015-03-06 14:10 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
            2015-03-11 18:05 - 2015-03-06 14:10 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
            2015-03-11 18:05 - 2015-03-06 14:10 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
            2015-03-11 18:05 - 2015-03-06 14:10 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
            2015-03-11 18:05 - 2015-03-06 14:09 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
            2015-03-11 18:05 - 2015-03-06 14:09 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
            2015-03-11 18:05 - 2015-03-06 14:07 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
            2015-03-11 18:05 - 2015-03-06 14:07 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
            2015-03-11 18:05 - 2015-03-06 14:06 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
            2015-03-11 18:05 - 2015-02-26 12:25 - 03204096 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
            2015-03-11 18:05 - 2015-02-24 12:15 - 00389800 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
            2015-03-11 18:05 - 2015-02-24 11:32 - 00342696 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
            2015-03-11 18:05 - 2015-02-21 10:16 - 25021440 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
            2015-03-11 18:05 - 2015-02-21 09:41 - 12827648 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
            2015-03-11 18:05 - 2015-02-21 09:27 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
            2015-03-11 18:05 - 2015-02-21 09:27 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
            2015-03-11 18:05 - 2015-02-21 09:25 - 19720192 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
            2015-03-11 18:05 - 2015-02-21 08:58 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
            2015-03-11 18:05 - 2015-02-21 08:32 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
            2015-03-11 18:05 - 2015-02-20 12:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
            2015-03-11 18:05 - 2015-02-20 12:05 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
            2015-03-11 18:05 - 2015-02-20 11:50 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
            2015-03-11 18:05 - 2015-02-20 11:49 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
            2015-03-11 18:05 - 2015-02-20 11:49 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
            2015-03-11 18:05 - 2015-02-20 11:48 - 02886144 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
            2015-03-11 18:05 - 2015-02-20 11:47 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
            2015-03-11 18:05 - 2015-02-20 11:41 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
            2015-03-11 18:05 - 2015-02-20 11:40 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
            2015-03-11 18:05 - 2015-02-20 11:36 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
            2015-03-11 18:05 - 2015-02-20 11:35 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
            2015-03-11 18:05 - 2015-02-20 11:35 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
            2015-03-11 18:05 - 2015-02-20 11:34 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
            2015-03-11 18:05 - 2015-02-20 11:32 - 06035456 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
            2015-03-11 18:05 - 2015-02-20 11:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
            2015-03-11 18:05 - 2015-02-20 11:22 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
            2015-03-11 18:05 - 2015-02-20 11:22 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
            2015-03-11 18:05 - 2015-02-20 11:13 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
            2015-03-11 18:05 - 2015-02-20 11:09 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
            2015-03-11 18:05 - 2015-02-20 11:08 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
            2015-03-11 18:05 - 2015-02-20 11:08 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
            2015-03-11 18:05 - 2015-02-20 11:08 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
            2015-03-11 18:05 - 2015-02-20 11:06 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
            2015-03-11 18:05 - 2015-02-20 11:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
            2015-03-11 18:05 - 2015-02-20 11:03 - 02278400 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
            2015-03-11 18:05 - 2015-02-20 11:01 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
            2015-03-11 18:05 - 2015-02-20 11:00 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
            2015-03-11 18:05 - 2015-02-20 10:58 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
            2015-03-11 18:05 - 2015-02-20 10:56 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
            2015-03-11 18:05 - 2015-02-20 10:56 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
            2015-03-11 18:05 - 2015-02-20 10:49 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
            2015-03-11 18:05 - 2015-02-20 10:49 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
            2015-03-11 18:05 - 2015-02-20 10:47 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
            2015-03-11 18:05 - 2015-02-20 10:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
            2015-03-11 18:05 - 2015-02-20 10:43 - 14398976 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
            2015-03-11 18:05 - 2015-02-20 10:41 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
            2015-03-11 18:05 - 2015-02-20 10:37 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
            2015-03-11 18:05 - 2015-02-20 10:30 - 04300288 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
            2015-03-11 18:05 - 2015-02-20 10:28 - 02358784 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
            2015-03-11 18:05 - 2015-02-20 10:24 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
            2015-03-11 18:05 - 2015-02-20 10:24 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
            2015-03-11 18:05 - 2015-02-20 10:23 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
            2015-03-11 18:05 - 2015-02-20 10:16 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
            2015-03-11 18:05 - 2015-02-20 10:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
            2015-03-11 18:05 - 2015-02-20 10:01 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
            2015-03-11 18:05 - 2015-02-20 09:57 - 01311232 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
            2015-03-11 18:05 - 2015-02-20 09:55 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
            2015-03-11 18:05 - 2015-02-04 12:16 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
            2015-03-11 18:05 - 2015-02-04 11:54 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
            2015-03-11 18:05 - 2015-02-03 12:31 - 01424896 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
            2015-03-11 18:05 - 2015-02-03 12:12 - 01230848 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
            2015-03-11 18:05 - 2015-01-31 08:56 - 00459336 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
            2015-03-11 18:05 - 2015-01-17 11:48 - 01067520 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
            2015-03-11 18:05 - 2015-01-17 11:30 - 00828928 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
            2015-03-11 00:34 - 2015-03-11 00:34 - 00000000 ____D () C:\Users\SS\Downloads\[FuckedHard18] Morgan Layne [SD] [.wmv]
            2015-03-08 20:59 - 2015-03-08 20:59 - 00147471 _____ () C:\Users\SS\Desktop\jim_aparo___batman_a_death_in_the_family_by_superman8193-d5tlylg-ben-affleck-as-batman-death-red-hood-arkham-asylum-and-hush-52c68877-489e-4ce1-a7c6-b0d2e04e2ed4.jpeg
            2015-03-08 16:40 - 2015-03-08 16:40 - 00000000 ____D () C:\Users\SS\Downloads\EvilAngel.Kalina.Ryu.Sperm.Diet.mp4
            2015-03-08 12:26 - 2015-03-08 23:20 - 2003577517 _____ () C:\Users\SS\Downloads\Saya_Song.mp4
            2015-03-08 11:40 - 2015-03-08 11:40 - 00000000 ____D () C:\Users\SS\Downloads\[GFRevenge] Dillion Harper (Track star)[PornLeech]
            2015-03-07 14:24 - 2015-03-07 14:24 - 00000000 ____D () C:\Users\SS\Downloads\James Deen - JESSIE ROGERS - Assfucked Til She Squirts [.mp4]
            2015-03-07 14:22 - 2015-03-07 14:22 - 00000000 ____D () C:\Users\SS\Downloads\[Private] Tina Hot [Anal Introductions][1080p] [.mp4][PornLeech]
            2015-03-06 14:14 - 2015-03-06 14:18 - 00000000 ____D () C:\Users\SS\Downloads\BangBros - Big Mouthfuls - Simply 18 w Emma Mae HD 720p
            2015-03-05 13:47 - 2015-03-05 13:47 - 00000000 ____D () C:\Users\SS\Downloads\[DigitalPlayground] Janice Griffith (50 Ways To Fuck) [.mp4]
            2015-03-04 23:39 - 2015-03-04 23:48 - 03461639 _____ () C:\Users\SS\Downloads\Introclass.pptx
            2015-02-27 14:34 - 2015-02-27 14:34 - 00000000 ____D () C:\Program Files (x86)\ActiveMail
            2015-02-27 12:12 - 2015-02-27 12:12 - 00000000 ____D () C:\Program Files (x86)\Youtube Preview  Is it worth watching
            2015-02-27 11:12 - 2015-02-27 11:12 - 00000000 ____D () C:\Program Files (x86)\coinsaove
            2015-02-26 09:59 - 2015-02-26 09:59 - 00000000 ____D () C:\Program Files (x86)\Renren Album Downloader
            2015-02-26 09:19 - 2015-01-09 08:44 - 00419936 _____ () C:\windows\SysWOW64\locale.nls
            2015-02-26 09:19 - 2015-01-09 08:43 - 00419936 _____ () C:\windows\system32\locale.nls
            2015-02-23 17:37 - 2015-02-23 17:40 - 00000000 ____D () C:\Users\SS\Downloads\BaDoink.15.02.20.Marica.Haze.Mirrors.Edge.An.XXX.Parody.XXX.1080p.MP4.KTR
             
            ==================== One Month Modified Files and Folders =======
             
            (If an entry is included in the fixlist, the file\folder will be moved.)
             
            2015-03-25 00:34 - 2014-10-08 07:46 - 00000890 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
            2015-03-25 00:34 - 2014-10-08 07:46 - 00000886 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
            2015-03-25 00:26 - 2012-04-21 21:43 - 01364280 _____ () C:\windows\WindowsUpdate.log
            2015-03-25 00:20 - 2014-01-11 10:20 - 00000896 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA.job
            2015-03-24 22:17 - 2012-12-05 23:05 - 00000000 ____D () C:\Users\SS\Desktop\Unused
            2015-03-24 22:10 - 2012-12-05 23:35 - 00000000 ____D () C:\Users\SS\AppData\Roaming\BitTorrent
            2015-03-24 18:36 - 2009-07-14 13:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
            2015-03-24 18:36 - 2009-07-14 13:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
            2015-03-24 18:28 - 2010-11-21 12:47 - 00667664 _____ () C:\windows\PFRO.log
            2015-03-24 18:28 - 2009-07-14 14:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
            2015-03-24 18:28 - 2009-07-14 13:51 - 00155324 _____ () C:\windows\setupact.log
            2015-03-24 17:47 - 2014-01-11 10:20 - 00000844 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core.job
            2015-03-23 23:58 - 2012-12-16 13:12 - 00000000 ____D () C:\Users\SS\AppData\Roaming\vlc
            2015-03-23 18:19 - 2012-12-05 21:28 - 00000000 ____D () C:\Users\SS\AppData\Local\VirtualStore
            2015-03-23 17:40 - 2015-02-04 17:26 - 00000020 _____ () C:\Users\SS\AppData\Roaming\appdataFr3.bin
            2015-03-22 22:14 - 2012-12-07 08:50 - 00000000 ____D () C:\Users\SS\AppData\Roaming\Skype
            2015-03-20 06:19 - 2013-02-19 23:00 - 00000000 ____D () C:\Program Files\Microsoft Office 15
            2015-03-14 01:40 - 2013-02-19 08:57 - 00000000 ____D () C:\Users\SS\Desktop\CARLOS
            2015-03-12 15:41 - 2014-03-16 22:04 - 00000000 ___RD () C:\Program Files (x86)\Skype
            2015-03-12 15:40 - 2012-04-21 06:13 - 00000000 ____D () C:\ProgramData\Skype
            2015-03-12 15:35 - 2009-07-14 13:45 - 00370488 _____ () C:\windows\system32\FNTCACHE.DAT
            2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\SysWOW64\tr-TR
            2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
            2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\system32\tr-TR
            2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\system32\Dism
            2015-03-12 14:16 - 2013-12-09 22:51 - 00000000 ____D () C:\windows\system32\MRT
            2015-03-12 14:02 - 2013-12-09 22:51 - 122905848 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
            2015-03-11 22:22 - 2012-12-05 22:00 - 00656980 _____ () C:\windows\system32\perfh01F.dat
            2015-03-11 22:22 - 2012-12-05 22:00 - 00140326 _____ () C:\windows\system32\perfc01F.dat
            2015-03-11 22:22 - 2012-04-21 21:15 - 00428722 _____ () C:\windows\system32\perfh012.dat
            2015-03-11 22:22 - 2012-04-21 21:15 - 00120710 _____ () C:\windows\system32\perfc012.dat
            2015-03-11 22:22 - 2009-07-14 14:13 - 02111596 _____ () C:\windows\system32\PerfStringBackup.INI
            2015-03-11 21:29 - 2012-12-25 23:46 - 00000000 ____D () C:\Users\SS\AppData\Local\CrashDumps
            2015-03-11 18:46 - 2012-12-19 23:09 - 00001173 _____ () C:\Users\SS\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
            2015-03-11 18:46 - 2012-12-19 23:09 - 00001149 _____ () C:\Users\Public\Desktop\GOM Player.lnk
            2015-03-11 17:38 - 2015-02-06 16:05 - 00000000 ____D () C:\ProgramData\3045395222265742798
            2015-02-26 10:02 - 2014-12-29 16:21 - 00000258 __RSH () C:\ProgramData\ntuser.pol
             
            ==================== Files in the root of some directories =======
             
            2015-02-04 17:26 - 2015-03-23 17:40 - 0000020 _____ () C:\Users\SS\AppData\Roaming\appdataFr3.bin
            2013-08-20 00:12 - 2014-04-22 00:27 - 0000954 _____ () C:\Users\SS\AppData\Roaming\coreavc.ini
            2012-04-21 06:07 - 2012-04-21 06:08 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
            2012-04-21 06:02 - 2012-04-21 06:02 - 0000113 _____ () C:\ProgramData\{34FBC7C4-CD31-4D93-A428-0E524EAC4586}.log
            2012-04-21 06:05 - 2012-04-21 06:05 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
            2012-04-21 06:02 - 2012-04-21 06:05 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log
            2012-04-21 06:05 - 2012-04-21 06:07 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
             
            Some content of TEMP:
            ====================
            C:\Users\SS\AppData\Local\Temp\Quarantine.exe
            C:\Users\SS\AppData\Local\Temp\SkypeSetup.exe
            C:\Users\SS\AppData\Local\Temp\sqlite3.dll
             
             
            ==================== Bamital & volsnap Check =================
             
            (There is no automatic fix for files that do not pass verification.)
             
            C:\Windows\System32\winlogon.exe => File is digitally signed
            C:\Windows\System32\wininit.exe => File is digitally signed
            C:\Windows\SysWOW64\wininit.exe => File is digitally signed
            C:\Windows\explorer.exe => File is digitally signed
            C:\Windows\SysWOW64\explorer.exe => File is digitally signed
            C:\Windows\System32\svchost.exe => File is digitally signed
            C:\Windows\SysWOW64\svchost.exe => File is digitally signed
            C:\Windows\System32\services.exe => File is digitally signed
            C:\Windows\System32\User32.dll => File is digitally signed
            C:\Windows\SysWOW64\User32.dll => File is digitally signed
            C:\Windows\System32\userinit.exe => File is digitally signed
            C:\Windows\SysWOW64\userinit.exe => File is digitally signed
            C:\Windows\System32\rpcss.dll => File is digitally signed
            C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
             
             
            LastRegBack: 2015-03-15 12:54
             
            ==================== End Of Log ============================


            Addition updated:
             

            Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
            Ran by [removed] at 2015-03-25 01:18:05
            Running from C:\Users\[removed]\Desktop
            Boot Mode: Normal
            ==========================================================
             
             
            ==================== Security Center ========================
             
            (If an entry is included in the fixlist, it will be removed.)
             
            AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
            AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
             
            ==================== Installed Programs ======================
             
            (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
             
            ActiveMail (HKLM-x32\…\{89AE616B-E500-0C2D-D0D2-F444CEEB4619}) (Version:  - "")
            Adobe Flash Player 10 ActiveX (HKLM-x32\…\{48DB5914-8772-472D-B8DF-E2092BE598F6}) (Version: 10.3.181.34 - Adobe Systems Incorporated)
            Adobe Reader 9.5.5 - Korean (HKLM-x32\…\{AC76BA86-7AD7-1042-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
            AhnLab Online Security (HKLM-x32\…\AhnLab Online Security) (Version:  - AhnLab, Inc)
            Audacity 2.0.5 (HKLM-x32\…\Audacity_is1) (Version: 2.0.5 - Audacity Team)
            calibre (HKLM-x32\…\{4BF56EFD-2F39-40F2-89BB-CF9D3550A806}) (Version: 2.17.0 - Kovid Goyal)
            coinsaove (HKLM-x32\…\{C8AAF59A-6BAA-F68B-9470-A856460A8093}) (Version:  - "") <==== ATTENTION
            CyberLink Media Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink Corp.)
            CyberLink Media+ Player10 (HKLM-x32\…\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 - CyberLink Corp.)
            CyberLink MediaShow (HKLM-x32\…\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1130a - CyberLink Corp.)
            CyberLink Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.)
            CyberLink PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3306 - CyberLink Corp.)
            CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4417 - CyberLink Corp.)
            D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
            Easy Content Share (HKLM-x32\…\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD)
            Easy Migration (HKLM-x32\…\{AD86049C-3D9C-43E1-BE73-643F57D83D50}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
            EasyFileShare (HKLM-x32\…\{16880765-677F-440B-B16A-BFD9B9C00012}) (Version: 1.0.12 - Samsung)
            Eco Mode (HKLM-x32\…\{9A8E4762-3331-4EDB-8E1F-B11179DDBC00}) (Version: 1.0.0.11 - Samsung Electronics Co., Ltd.)
            E-POP (HKLM-x32\…\{75282161-8CAC-4071-A225-EBC95E43C7F3}) (Version: 1.00.0000 - Samsung)
            ETDWare PS/2-X64 8.0.7.2_WHQL (HKLM\…\Elantech) (Version: 8.0.7.2 - ELAN Microelectronic Corp.)
            GOM Player (HKLM-x32\…\GOM Player) (Version: 2.2.67.5221 - Gretech Corporation)
            Google Chrome (HKLM-x32\…\Google Chrome) (Version: 39.0.2171.99 - Google Inc.)
            Google Talk Plugin (HKLM-x32\…\{0C5C1177-94C5-3EFB-A8BE-3F6AF1AF887F}) (Version: 5.38.6.0 - Google)
            Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
            Hanword HWP document converter for Microsoft Word (x64) (HKLM\…\{90150000-2009-0409-1000-0000000FF1CE}) (Version: 15.0.4454.1506 - Microsoft Corporation)
            Hanword HWP document converter for Microsoft Word (x86) (HKLM-x32\…\{90150000-2009-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1506 - Microsoft Corporation)
            INISAFE SandBox 1.0 (HKLM-x32\…\INISAFE SandBox) (Version: 1.0 - Initech, Inc.)
            Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
            Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
            Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2266 - Intel Corporation)
            Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
            Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\…\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel)
            Intel(R) WiDi (HKLM-x32\…\{E1B934BB-6AFA-429F-98E4-76F9CBC72BF6}) (Version: 2.2.14.0 - Intel Corporation)
            Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
            Interactive Guide (HKLM-x32\…\{CB383BE9-7518-4ABD-826E-8FC4695F7D52}) (Version: 1.1 - )
            Java 7 Update 67 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.670 - Oracle)
            Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
            KakaoTalk (HKLM-x32\…\KakaoTalk) (Version: 2.0.4.786 - Kakao)
            LG United Mobile Drivers (HKLM-x32\…\{C2944BE7-9BFF-4EF0-A362-CB3281B7C50D}) (Version: 3.6.0.0 - LG Electronics)
            Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
            Media Center 한글 입력기 (HKLM-x32\…\{BB9A1C85-8841-4755-A4D3-E3EEC3EFD3F0}) (Version: 3.1.5.0 - Samsung Electronics Co., LTD)
            Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
            Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
            Microsoft Office Home and Student 2013 - en-us (HKLM\…\HomeStudentRetail - en-us) (Version: 15.0.4701.1002 - Microsoft Corporation)
            Microsoft Office 언어 교정 도구 2013 - 한국어 (HKLM-x32\…\{90150000-001F-0412-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
            Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
            Microsoft SkyDrive (HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
            Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
            Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
            Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
            Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
            Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
            Multimedia POP (HKLM-x32\…\{331ECF61-69AF-4F57-AC35-AFED610231C3}) (Version: 1.2 - )
            NVIDIA 그래픽 드라이버 267.54 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.54 - NVIDIA Corporation)
            Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
            Office 15 Click-to-Run Licensing Component (Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
            Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
            PhoneShare (HKLM-x32\…\{3F50512F-53DF-46B1-8CCB-6C7E638CADD6}) (Version: 9.1.4 - Samsung)
            Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek)
            Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6400 - Realtek Semiconductor Corp.)
            Renren Album Downloader (HKLM-x32\…\{AF992111-52BE-832B-5882-8477E4A3C99A}) (Version:  - "") <==== ATTENTION
            Samsung AnyWeb Print (HKLM-x32\…\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 2.0.67.1 - Samsung Electronics Co., Ltd.)
            Samsung Control Center (HKLM-x32\…\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
            Samsung Printer Live Update (HKLM-x32\…\Samsung Printer Live Update) (Version:  - Samsung Electronics Co., Ltd.)
            Samsung Recovery Solution 5 (HKLM-x32\…\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.1.3 - Samsung)
            Samsung Support Center (HKLM-x32\…\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.26 - Samsung)
            Samsung Universal Print Driver (HKLM-x32\…\Samsung Universal Print Driver) (Version: 2.02.05.00:27 - Samsung Electronics Co., Ltd.)
            Samsung Universal Scan Driver (HKLM-x32\…\Samsung Universal Scan Driver) (Version: 1.2.5.0 - Samsung Electronics Co., Ltd.)
            Samsung Update Plus (HKLM-x32\…\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.0.17 - Samsung Electronics Co., Ltd.)
            SISShortcut (HKLM-x32\…\{FDAE128F-A355-42B1-8422-1AF3ACEE34F4}) (Version: 1.00.000 - Samsung)
            Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
            Skype™ 7.1 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
            Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
            User Guide (HKLM-x32\…\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.3 - )
            Veraport20(Security module management) - 2,5,6,1 (HKLM-x32\…\{2D992E01-604B-472C-A883-1DDA105A24D5}_is1) (Version: 2,5,6,1 - Wizvera)
            VLC media player 2.0.4 (HKLM-x32\…\VLC media player) (Version: 2.0.4 - VideoLAN)
            Vuze Remote Toolbar (HKLM-x32\…\Vuze_Remote Toolbar) (Version: 6.9.0.16 - Vuze Remote) <==== ATTENTION
            Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
            Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
            WinRAR 4.20 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
            WordCaptureX Pro (HKLM-x32\…\{139C1D95-9037-3AB3-F5F4-4A79BF6831EC}) (Version: 4.0.0 - Deskperience)
            XecureWeb Control (HKLM-x32\…\XecureWeb Control) (Version:  - )
            Youtube Preview  Is it worth watching (HKLM-x32\…\{CDFBAC3A-2FE1-0B77-34C9-065BBCC8B77C}) (Version:  - "") <==== ATTENTION
            원격 연결을 위한 Windows Live Mesh ActiveX 컨트롤 (HKLM-x32\…\{61920449-0393-4707-B7DD-E6C0013C8B2C}) (Version: 15.4.5722.2 - Microsoft Corporation)
            인텔(R) PROSet/무선 WiMAX 소프트웨어 (HKLM\…\{5C1DA3D9-F590-4317-A4FB-274F658E504B}) (Version: 6.05.0001 - Intel Corporation)
            인텔® PROSet/무선 WiFi 소프트웨어 (HKLM\…\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation)
             
            ==================== Custom CLSID (selected items): ==========================
             
            (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
             
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
             
            ==================== Restore Points  =========================
             
            16-03-2015 18:46:22 AA11
            23-03-2015 17:32:33 AA11
             
            ==================== Hosts content: ==========================
             
            (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
             
            2009-07-14 11:34 - 2015-03-03 20:25 - 00450892 ____R C:\windows\system32\Drivers\etc\hosts
            127.0.0.1 www.007guard.com
            127.0.0.1 007guard.com
            127.0.0.1 008i.com
            127.0.0.1 www.008k.com
            127.0.0.1 008k.com
            127.0.0.1 www.00hq.com
            127.0.0.1 00hq.com
            127.0.0.1 010402.com
            127.0.0.1 www.032439.com
            127.0.0.1 032439.com
            127.0.0.1 www.0scan.com
            127.0.0.1 0scan.com
            127.0.0.1 www.1000gratisproben.com
            127.0.0.1 1000gratisproben.com
            127.0.0.1 1001namen.com
            127.0.0.1 www.1001namen.com
            127.0.0.1 100888290cs.com
            127.0.0.1 www.100888290cs.com
            127.0.0.1 www.100sexlinks.com
            127.0.0.1 100sexlinks.com
            127.0.0.1 www.10sek.com
            127.0.0.1 10sek.com
            127.0.0.1 www.1-2005-search.com
            127.0.0.1 1-2005-search.com
            127.0.0.1 www.123fporn.info
            127.0.0.1 123fporn.info
            127.0.0.1 123haustiereundmehr.com
            127.0.0.1 www.123haustiereundmehr.com
            127.0.0.1 123moviedownload.com
             
            There are 1000 more lines.
             
             
            ==================== Scheduled Tasks (whitelisted) =============
             
            (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
             
            Task: {03A10DB7-9071-4EEF-B9CB-F411EA94735C} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Samsung Control Center\SmartSetting.exe [2011-06-04] (Samsung Electronics Co., Ltd.)
            Task: {0A384BD9-2CAB-42DF-8601-6D380A53BFEB} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Samsung Control Center\SCCSpeedBoot.exe [2011-05-18] (Samsung Electronics Co., Ltd.)
            Task: {0CFBF115-D843-433D-8B12-14C46A4A3BDA} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2011-03-29] (SEC)
            Task: {1645AE87-AC06-4F79-9291-63F734344ECA} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-08-17] (CyberLink)
            Task: {28A63C7E-40C7-4D78-9EBE-60FB6CE6E95B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
            Task: {2D03498A-F669-4E65-8297-264723A0C017} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2011-04-17] (SAMSUNG Electronics)
            Task: {2DB56CE1-EAD1-4215-9D66-960A74B181F9} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
            Task: {2F5C19D8-2F72-434D-9A4B-551DBD945E72} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
            Task: {3468239E-CD89-4747-90F5-DCCB45BA2FCB} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
            Task: {398E535C-CC80-4CF3-9698-34C0F76AD90A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
            Task: {3F7881E2-661E-42EB-8913-ABFD71584BC0} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
            Task: {4A805CAE-69C4-4139-A3D2-995EC8A4FEA1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-15] (Google Inc.)
            Task: {6AB036E6-C87E-4750-9D49-01D6931EFB37} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Samsung Control Center\MovieColorEnhancer.exe [2011-02-17] (Samsung Electronics Co., Ltd.)
            Task: {76BC4D0C-1132-487C-85F2-7120F1BF7473} - System32\Tasks\Microsoft Office 15 Sync Maintenance for SS-PC-SS SS-PC => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation)
            Task: {7E430DF2-7F3D-45FC-A8E6-757D48DAC111} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe [2010-08-27] (Samsung Electronics)
            Task: {A0618927-0C2F-4AB6-B49A-AECA2955850A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-15] (Google Inc.)
            Task: {A957AD76-D965-4019-82E7-04133BD83B27} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Samsung Control Center\WifiManager.exe [2012-03-08] (Samsung Electronics Co., Ltd.)
            Task: {BB1B4464-B9EC-4474-8C84-31A56602CAE2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
            Task: {C7519AC8-6F25-4BAD-BAFE-E7D925D18572} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Samsung Control Center\dmhkcore.exe [2011-06-15] (Samsung Electronics Co., Ltd.)
            Task: {DE28C41A-1C1E-46B7-9DE8-7E610E5C2B14} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Samsung Control Center\EBM\EasyBatteryMgr4.exe [2011-07-02] (SAMSUNG Electronics co., LTD.)
            Task: {E924E8DA-3600-4ED2-82A9-AB458CDC5AF9} - System32\Tasks\EcoMode => C:\Program Files (x86)\Samsung\Eco Mode\SmartEco.exe [2011-06-06] (Samsung Electronics)
            Task: {E937FD97-F248-4672-85D2-684AEA989A33} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
            Task: {EB02381F-D652-4B1C-894A-712498C62C51} - \Microsoft\Windows\MUI\LPRemove No Task File <==== ATTENTION
            Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
            Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
            Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core.job => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
            Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA.job => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
             
            ==================== Loaded Modules (whitelisted) ==============
             
            2012-04-21 21:01 - 2008-06-05 08:53 - 00027648 _____ () C:\windows\System32\spd__l.dll
            2014-03-21 17:29 - 2014-05-20 08:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
            2012-04-21 20:59 - 2010-12-17 10:37 - 00094208 _____ () C:\windows\system32\IccLibDll_x64.dll
            2012-04-21 21:01 - 2010-10-22 03:22 - 00709632 _____ () C:\windows\system32\SnMinDrv.dll
            2015-03-20 06:17 - 2015-01-28 00:29 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
            2014-12-29 16:28 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
            2014-12-29 16:28 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
            2014-12-29 16:28 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
            2014-12-29 16:28 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
            2014-12-29 16:28 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
            2012-04-21 06:14 - 2011-02-17 00:03 - 00203776 _____ () C:\Program Files (x86)\Samsung\Samsung Control Center\WinCRT.dll
            2012-04-21 06:14 - 2006-08-12 11:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Samsung Control Center\HookDllPS2.dll
            2009-11-02 14:20 - 2009-11-02 14:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
            2009-11-02 14:23 - 2009-11-02 14:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
            2012-04-21 06:15 - 2010-05-07 23:22 - 01636864 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
            2015-01-15 00:29 - 2015-01-09 09:35 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libglesv2.dll
            2015-01-15 00:29 - 2015-01-09 09:35 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libegl.dll
            2015-01-15 00:29 - 2015-01-09 09:35 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\pdf.dll
            2015-01-15 00:29 - 2015-01-09 09:35 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\ffmpegsumo.dll
            2015-01-15 00:29 - 2015-01-09 09:35 - 14913352 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\PepperFlash\pepflashplayer.dll
            2014-01-31 12:28 - 2014-01-31 12:28 - 00421520 _____ () C:\Program Files (x86)\GRETECH\GomPlayer\GomTVStrm.dll
            2014-12-19 10:08 - 2014-12-19 10:08 - 01193984 _____ () C:\Program Files (x86)\GRETECH\GomPlayer\libass.dll
             
            ==================== Alternate Data Streams (whitelisted) =========
             
            (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
             
             
            ==================== Safe Mode (whitelisted) ===================
             
            (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
             
             
            ==================== EXE Association (whitelisted) ===============
             
            (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
             
             
            ==================== Other Areas ============================
             
            (Currently there is no automatic fix for this section.)
             
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\SS\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
            DNS Servers: [removed] - [removed]
             
            ==================== MSCONFIG/TASK MANAGER disabled items ==
             
            (Currently there is no automatic fix for this section.)
             
             
            ==================== Accounts: =============================
             
            Administrator (S-1-5-21-3476611405-1961159229-2615470741-500 - Administrator - Disabled)
            Guest (S-1-5-21-3476611405-1961159229-2615470741-501 - Limited - Disabled)
            SS (S-1-5-21-3476611405-1961159229-2615470741-1001 - Administrator - Enabled) => C:\Users\SS
            UpdatusUser (S-1-5-21-3476611405-1961159229-2615470741-1000 - Limited - Enabled) => C:\Users\UpdatusUser
             
            ==================== Faulty Device Manager Devices =============
             
            Name: Teredo Tunneling Pseudo-Interface
            Description: Microsoft Teredo Tunneling Adapter
            Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
            Manufacturer: Microsoft
            Service: tunnel
            Problem: : This device cannot start. (Code10)
            Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
            On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
             
             
            ==================== Event log errors: =========================
             
            Application errors:
            ==================
            Error: (03/24/2015 10:19:16 PM) (Source: Application Error) (EventID: 1000) (User: )
            Description: Faulting application name: mbamservice.exe, version: 3.0.32.0, time stamp: 0x54ff42f1
            Faulting module name: mbamcore.dll, version: 1.1.67.0, time stamp: 0x54ff372a
            Exception code: 0xc0000005
            Fault offset: 0x000cf363
            Faulting process id: 0x14dc
            Faulting application start time: 0xmbamservice.exe0
            Faulting application path: mbamservice.exe1
            Faulting module path: mbamservice.exe2
            Report Id: mbamservice.exe3
             
             
            System errors:
            =============
            Error: (03/24/2015 10:20:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
            Description: The MBAMService service terminated unexpectedly.  It has done this 1 time(s).
             
             
            Microsoft Office Sessions:
            =========================
            Error: (03/24/2015 10:19:16 PM) (Source: Application Error) (EventID: 1000) (User: )
            Description: mbamservice.exe3.0.32.054ff42f1mbamcore.dll1.1.67.054ff372ac0000005000cf36314dc01d06616ac4e454aC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exeC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamcore.dll5eca50d7-d228-11e4-96ad-50b7c307cd39
             
             
            ==================== Memory info =========================== 
             
            Processor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz
            Percentage of memory in use: 68%
            Total physical RAM: 4009.55 MB
            Available physical RAM: 1245.05 MB
            Total Pagefile: 8017.28 MB
            Available Pagefile: 4225.14 MB
            Total Virtual: 8192 MB
            Available Virtual: 8191.84 MB
             
            ==================== Drives ================================
             
            Drive c: () (Fixed) (Total:179 GB) (Free:53.44 GB) NTFS
            Drive d: () (Fixed) (Total:266.57 GB) (Free:253.66 GB) NTFS
             
            ==================== MBR & Partition Table ==================
             
            ========================================================
            Disk: 0 (Size: 465.8 GB) (Disk ID: A80DEEF6)
            Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
            Partition 2: (Not Active) - (Size=179 GB) - (Type=07 NTFS)
            Partition 3: (Not Active) - (Size=266.6 GB) - (Type=OF Extended)
            Partition 4: (Not Active) - (Size=20.1 GB) - (Type=27)
             
            ==================== End Of Log ============================

            I am attaching a FIXLIST file, you need to download it to your desktop where you have FRST64 or the fix wont work, after you download it open up FRST64 and click on FIX (Not Scan) after it reboots your computer you will find a FIXLOG on your desktop, post it please and also let me know how your system is behaving now .

             

             

             

             

             

            Attachments:

            Sorry for the late response. Here is the fixlog.txt. My system is definitely running a a bit quicker, however, right as I logged on this page I got a pop up. 
             

            Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
            Ran by [removed] at 2015-03-25 22:23:28 Run:2
            Running from C:\Users\[removed]\Desktop
            [removed]
            Boot Mode: Normal
            ==============================================
             
            Content of fixlist:
            *****************
            Start
            CreateRestorePoint: 
            CloseProcesses:
            (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
            (BitTorrent Inc.) C:\Users\SS\AppData\Roaming\BitTorrent\BitTorrent.exe
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [BitTorrent] => C:\Users\SS\AppData\Roaming\BitTorrent\BitTorrent.exe [1744472 2015-03-04] (BitTorrent Inc.)
            GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
            CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
            HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
            HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
            HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
            HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
            HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
            HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
            HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
            SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.as…q={searchTerms}
            SearchScopes: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.as…q={searchTerms}
            R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [715656 2014-12-29] (Cherished Technololgy LIMITED)
            c:\users\ss\desktop\unused\new folder\adobe photoshop cs4
            CMD: ipconfig /flushdns
            Hosts:
            EmptyTemp:
            End
             
             
             
             
             
             
             
             
             
             
            *****************
             
            Restore point was successfully created.
            Processes closed successfully.
            C:\ProgramData\IePluginServices\PluginService.exe => No running process found
            C:\Users\SS\AppData\Roaming\BitTorrent\BitTorrent.exe => No running process found
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Windows\CurrentVersion\Run\\BitTorrent => Value not found.
            "C:\windows\system32\GroupPolicy\Machine" => File/Directory not found.
            HKLM\SOFTWARE\Policies\Google => Key not found. 
            HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => Key not found. 
            HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
            HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
            HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
            HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
            HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
            HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
            HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} => Key not found. 
            HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} => Key not found. 
            HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} => Key not found. 
            HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} => Key not found. 
            IePluginServices => Service not found.
            "c:\users\ss\desktop\unused\new folder\adobe photoshop cs4" => File/Directory not found.
             
            =========  ipconfig /flushdns =========
             
             
            Windows IP Configuration
             
            Successfully flushed the DNS Resolver Cache.
             
            ========= End of CMD: =========
             
            C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
            Hosts was reset successfully.
            EmptyTemp: => Removed 15.6 MB temporary data.
             
             
            The system needed a reboot. 
             
            ==== End of Fixlog 22:24:54 ====
            Download Avast-browser-cleanup
             
            to your desktop
             
            •  
            • There is nothing to  install, just right click on it and Run As Adminstrator
            • When its finished scanning it will list Browser Add ONs
            • If if finds takeorleave or any other bogus toolbars
            • Just high light them and select REMOVE
            • Close out the program
            • Reboot your system and test your browsers
             
             
             
             

             
            •  
            • Open Chrome
            • Click the Chrome menu [external image: Clipboard01_zps2e55f676.jpg]on the browser toolbar.
            • Click on Settings
            • Then Manage Search Engines
            • Highlite takeorleave and select Delete
            • Then go to Other Search Engines and remove all you dont want
             
             
            •  
            • Click the Chrome menu [external image: Clipboard01_zps2e55f676.jpg]on the browser toolbar.
            • Click on Settings
            • Open a specific page or set of pages.
            • Set Pages
            • Remove takeorleave if present
            • You can copy and paste the url from a page you like or if you have that page open select use current
            • OK your way out and close chome.
            • Reopen Chrome and make sure your start page is the one you want
             
             
            •  
            • Open Chrome
            • Click the Chrome menu [external image: Clipboard01_zps2e55f676.jpg]on the browser toolbar.
            • Click on History
            • Click on Clear Browsing History
            • Check 
            1. Browsing History
            2. Cookies and Site Plug Ins
            3. Cached Images and Files
            • Then ok your way out and close Chrome
             
             
            •  
            • Open Chrome
            • Click the Chrome menu [external image: Clipboard01_zps2e55f676.jpg]on the browser toolbar.
            • Then go to Settings > Show Advanced Settings 
            • Then go to Privacy > Content Settings
            • Plug Ins > Manage Exceptions > Delete any reference to takeorleave
            • Pop Ups > Manage Exceptions > Remove any reference to takeorleave
            • Ok your way out and close Chome, then reopen it and see if takeorleave are gone from your pages
             
             
            If this did not work then lets set Chome back to factory defaults
             
            •  
            • Click the Chrome menu [external image: Clipboard01_zps2e55f676.jpg]on the browser toolbar.
            • Select Settings.
            • Scroll down to Show advanced settings…
            • Down on the bottom you will see an option for RESET BROWSER SETTINGS
            • Click on it and it will set Chome back to defaults
             
             
             
            I cleaned up Chrome as per your instructions and haven't had a pop up by takeorleave - oddly I didn't see anything by takeorleave in any of the places you mentioned it might appear. I've been able to use the internet today without an instance of another popup from bestwebnutfunblack.in as well. However, there are several programs in my control panel that I didn't install myself and can't uninstall. They are: outube Preview Is it worth watching coinsaove ActiveMail Renren Album Downloader

            Ask AI

            AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

            Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI