This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Your Ad ExchangeTypiclayy

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Usually the first click on a new page launches the redirect. I have norton and recently spent $12 for spy hunter 4 because I thought I had removed Tikotin and Trovi and Search Protect by Conduit but I dont know.

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by [removed] at 2015-03-29 23:05:29
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Norton Internet Security (Enabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton Internet Security (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-145684943-4197250818-2869285112-1001\…\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)
4 Elements II (x32 Version: 2.2.0.98 - WildTangent) Hidden
Adobe Shockwave Player 11.6 (HKLM-x32\…\Adobe Shockwave Player) (Version: 11.6.5.635 - Adobe Systems, Inc.)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (64-bit) (HKLM\…\{28791292-D18D-42FA-AE66-3D3D20AA8618}) (Version: 3.1.1 - Apple Inc.)
Apple Application Support (HKLM-x32\…\{A83279FD-CA4B-4206-9535-90974DE76654}) (Version: 2.1.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{5ED7462B-EF58-4757-B609-53755021EC34}) (Version: 8.1.0.18 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
BitRaider Streaming Client (HKLM-x32\…\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Build-a-lot 4 - Power Source (x32 Version: 2.2.0.98 - WildTangent) Hidden
Canon MX410 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX410_series) (Version:  - )
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
CMS (HKLM-x32\…\CMS) (Version:  - )
Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
Cradle of Rome 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
CyberLink LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1.5407 - CyberLink Corp.)
CyberLink Media Suite 10 (HKLM-x32\…\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.1.1916 - CyberLink Corp.)
CyberLink PhotoDirector (HKLM-x32\…\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.1.3119 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\…\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.1.1926 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.1.1925 - CyberLink Corp.)
CyberLink PowerDVD (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.6.4319 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.4.5527 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Digital Copy (HKLM-x32\…\Digital Copy) (Version:  - )
DivX Setup (HKLM-x32\…\DivX Setup) (Version: 2.7.0.31 - DivX, LLC)
Duel of Champions (HKU\S-1-5-21-145684943-4197250818-2869285112-1001\…\MMDoC-PDCLive) (Version:  - Ubisoft)
Elevated Installer (x32 Version: 3.2.27.0 - Garmin Ltd or its subsidiaries) Hidden
Energy Star (HKLM\…\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard)
Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden
FATE: The Cursed King (x32 Version: 2.2.0.97 - WildTangent) Hidden
Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden
FlatOut 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Garmin Communicator Plugin x64 (HKLM\…\{70A381F1-C161-4D61-A20C-BE12FC6777DF}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\…\{855d8086-4275-4bd3-a7a8-b44da3a56d7a}) (Version: 3.2.27.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 3.2.27.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 3.2.27.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 41.0.2272.101 - Google Inc.)
Google Earth Plug-in (HKLM-x32\…\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Talk Plugin (HKLM-x32\…\{C77CC230-7417-3F01-B70D-52583DC9FEC9}) (Version: 5.40.2.0 - Google)
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
Hoyle Card Games (x32 Version: 2.2.0.95 - WildTangent) Hidden
HP 3D DriveGuard (HKLM\…\{F244D07D-1876-4CDD-914D-214E15A8D327}) (Version: 4.2.5.1 - Hewlett-Packard Company)
HP Connected Music (Meridian - installer) (HKLM-x32\…\StartHPConnectedMusic) (Version: v1.0 - Meridian Audio Ltd)
HP CoolSense (HKLM-x32\…\{16B7BDA1-B967-4D2D-8B27-E12727C28350}) (Version: 2.10.3 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\…\{18DE31AE-70D0-43A7-9E3C-2ED7283ECE8A}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.3.0 - WildTangent)
HP MyRoom (HKLM-x32\…\{9C35EDE5-4B0F-45E7-A438-314BA889948E}) (Version: 9.0.0.0 - Hewlett-Packard Company)
HP Quick Launch (HKLM-x32\…\{E5823036-6F09-4D0A-B05C-E2BAA129288A}) (Version: 3.0.6 - Hewlett-Packard Company)
HP Registration Service (HKLM\…\{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}) (Version: 1.0.5976.4186 - Hewlett-Packard)
HP Software Framework (HKLM-x32\…\{835B275B-F29B-464B-BD4B-097FD55FAB0A}) (Version: 4.6.8.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\…\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
HP Utility Center (HKLM-x32\…\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.7 - Hewlett-Packard)
HP Wireless Button Driver (HKLM-x32\…\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3958 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
iTunes (HKLM\…\{7B8D4E8A-EA2B-4A71-BFEB-A4AAAB87C5D0}) (Version: 12.1.0.71 - Apple Inc.)
Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Mahjongg Dimensions Deluxe: Tiles in Time (x32 Version: 2.2.0.98 - WildTangent) Hidden
Media Go (HKLM-x32\…\{AF06B8FA-B916-4001-AE51-6645488DEF09}) (Version: 2.8.303 - Sony)
Media Go Network Downloader (HKLM-x32\…\{5562F05F-908C-4F15-9B3C-98D5FD32DCAB}) (Version: 1.5.19.0 - Sony)
Media Go Video Playback Engine 2.12.103.06300 (HKLM-x32\…\{CB7048B4-5D1F-E24E-41FC-2AB7AAFE6597}) (Version: 2.12.103.06300 - Sony)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\…\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{3bcf8c72-b231-4d28-9f39-3405c22d8b5a}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Mortimer Beckett and the Crimson Thief Premium Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
Mystery P.I. - Curious Case of Counterfeit Cove (x32 Version: 2.2.0.98 - WildTangent) Hidden
NetSurveillance (HKLM-x32\…\NetSurveillance) (Version:  - )
Next Generation Visualisations (HKLM-x32\…\{2E376AD9-5C49-4F7D-A0BA-6A44E8FA5A3B}) (Version: 1.0.0 -  Microsoft)
Norton Internet Security (HKLM-x32\…\NIS) (Version: 21.7.0.11 - Symantec Corporation)
NWZ-E380 WALKMAN Guide (HKLM-x32\…\{D98ED583-338D-4425-B2EF-A4C7FB93CE88}) (Version: 2.2.0.05230 - Sony Corporation)
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
PlayStation(R)Store (HKLM-x32\…\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.18.0.15698 - Sony Computer Entertainment Inc.)
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.98 - WildTangent) Hidden
Popcorn Time (HKLM-x32\…\Popcorn Time_is1) (Version: Beta 5.1 - Popcorn Time)
QuickTime (HKLM-x32\…\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)
Ralink Bluetooth Stack64 (HKLM\…\{58BC91D0-42E7-125D-F9B6-F2F5C0CDB096}) (Version: 9.0.715.0 - Ralink Corporation)
Ralink RT3290 802.11bgn Wi-Fi Adapter (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.2.0 - Ralink)
RealDownloader (x32 Version: 17.0.15.4 - RealNetworks, Inc.) Hidden
RealDownloader (x32 Version: 17.0.15.7 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2005 Runtime (x32 Version: 8.0 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\…\RealPlayer 17.0) (Version: 17.0.15 - RealNetworks)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Remote Control Server (HKLM-x32\…\{755C6515-9FEA-490C-B15E-22BB6519E57E}) (Version: 2.2.3.24 - Steppschuh)
Roads of Rome 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.2 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
SmartShare (HKLM-x32\…\{BAB337AE-DD9E-45C3-BED6-0EE4732AEC60}) (Version: 2.2.1312.1201 - LG Electronics Inc.)
SpyHunter 4 (HKLM-x32\…\SpyHunter) (Version: 4.19.13.4482 - Enigma Software Group, LLC)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 16.5.3.3 - Synaptics Incorporated)
Tales of Lagoona (x32 Version: 2.2.0.110 - WildTangent) Hidden
Unity Web Player (HKU\S-1-5-21-145684943-4197250818-2869285112-1001\…\UnityWebPlayer) (Version: 4.6.2f1 - Unity Technologies ApS)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
Uplay (HKLM-x32\…\Uplay) (Version: 4.9 - Ubisoft)
Vacation Quest™ - Australia (x32 Version: 2.2.0.98 - WildTangent) Hidden
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Video Downloader (x32 Version: 1.0.0 - RealNetworks) Hidden
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.9.6 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-145684943-4197250818-2869285112-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\matt\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-145684943-4197250818-2869285112-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-145684943-4197250818-2869285112-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\matt\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-145684943-4197250818-2869285112-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\matt\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-145684943-4197250818-2869285112-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\matt\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.)
 
==================== Restore Points  =========================
 
12-03-2015 15:16:10 Removed QuickTime
16-03-2015 21:04:56 Installed QuickTime
26-03-2015 19:20:55 Scheduled Checkpoint
29-03-2015 11:17:39 HPSF Applying updates
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {091F4265-842B-4EFE-BB4F-7A5802847F66} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {1D5C4DE2-D79A-4C1E-BB1A-187EAB443145} - System32\Tasks\HPCeeScheduleFormatt => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {29A9328D-0A0D-4020-887A-31FD1EB26984} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {2B198AFB-CA4F-4301-AA82-22DA7E88750D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-145684943-4197250818-2869285112-1001Core => C:\Users\matt\AppData\Local\Google\Update\GoogleUpdate.exe [2014-12-24] (Google Inc.)
Task: {3E3AE978-E740-409E-B4F8-8AE8C8A8D12B} - System32\Tasks\VQEXDJD => C:\Users\matt\AppData\Roaming\VQEXDJD.exe <==== ATTENTION
Task: {3EF4EDAA-76AB-4D9E-B917-6DA5DA22E0D3} - System32\Tasks\Selection Tools Update => C:\Users\matt\AppData\Roaming\WTools\Selection Tools\Selection Tools Update.exe
Task: {4419994C-6CE9-4D5B-9A31-DB4E86C709AF} - System32\Tasks\{F274882A-00B4-4C49-B385-8D6C6841A899} => pcalua.exe -a "H:\Porn\porn\Sunny Leone And Tori Black - Sensual Love\Jenna is wearing fishnet _s.exe" -d "H:\Porn\porn\Sunny Leone And Tori Black - Sensual Love"
Task: {45CE1614-DA4F-4DCA-8F33-61905F416AFB} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-145684943-4197250818-2869285112-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-10-26] (RealNetworks, Inc.)
Task: {4F6A34DD-10AF-4465-9579-763FB5E9A274} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {52D0F590-D689-46FB-9849-BB0675CB0CC3} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {57DBEA26-381A-4639-BE29-1F3C09D5316D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {598630E2-4E74-4790-9041-D19257417DB8} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-145684943-4197250818-2869285112-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: {60D8B1B5-2022-467A-AEC0-28DE12619ABF} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe [2014-12-31] ()
Task: {6FD592B2-4F8C-488E-991B-FEBE56EE0A05} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-03-10] (Microsoft Corporation)
Task: {769CDE51-3763-4B80-9B1B-312E15081EE2} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {77500AB5-211C-47A3-B15C-2CC64C04E93E} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\WSCStub.exe [2015-03-07] (Symantec Corporation)
Task: {786CC5D3-69EF-4672-8058-8F6640865A02} - \ProPCCleaner_Popup No Task File <==== ATTENTION
Task: {79BF678E-3849-4F3B-819A-F834B03A0F71} - System32\Tasks\CGVW => C:\Users\matt\AppData\Roaming\CGVW.exe <==== ATTENTION
Task: {7A01E24C-A8BA-4204-A895-916D1F9AC49F} - System32\Tasks\RealDownloader Update Check => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [2014-10-29] ()
Task: {7B7D3733-9F68-4ACB-A74A-59A1C89456ED} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2015-03-10] (Hewlett-Packard)
Task: {84DC2E9D-0F0F-4B83-A2CE-81FE6ED6E0FA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-29] (Google Inc.)
Task: {8660C243-EF22-47D5-ACC2-352570E75AFE} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-12-22] (Synaptics Incorporated)
Task: {8C4D5FE8-CF6E-4D5D-91CF-B64DE8F96D47} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-07-27] (CyberLink)
Task: {9F6A1791-5D5A-478F-B9C4-D5524CE5CECF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {A17A99B0-994D-4510-A6B9-510A0A0255DC} - System32\Tasks\KAXQH => C:\ProgramData\6ef8a1b652f14522bd519ac00ef26c65\6ef8a1b652f14522bd519ac00ef26c65.exe
Task: {A6E67CF2-45E6-4BF1-BC10-E478C7E04C6D} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {ABD19D65-3F61-4A0E-887D-E53C25D526D6} - System32\Tasks\SmartShare => C:\Program Files (x86)\LG Software\LG Smart Share\SmartShareStart.exe [2013-12-03] (LG Electronics Inc.)
Task: {AD32A94F-D4F3-463D-BF62-2ED5C3E9DD4E} - System32\Tasks\{EBD79A38-CE43-4221-95AC-DD106601C1FB} => pcalua.exe -a "C:\Program Files (x86)\Origin\OriginUninstall.exe"
Task: {AE063D5C-1BFF-4662-AC9E-ADD7185B34AD} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {BC348AD2-1E69-411D-81A9-2D91BC29943F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {CE3D0C2D-B36A-489F-8936-3B7F0F039F71} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-145684943-4197250818-2869285112-1001UA => C:\Users\matt\AppData\Local\Google\Update\GoogleUpdate.exe [2014-12-24] (Google Inc.)
Task: {D42FCFB5-CE33-4794-A232-6AFE85DB0FF6} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {DFFB4D95-5ACD-4B19-9558-9679C010E04C} - \ProPCCleaner_Start No Task File <==== ATTENTION
Task: {E1AD0B48-ACE1-47C9-8F00-73498FC65D00} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {E270027C-F1A7-4253-B40F-5AD3183CB798} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {F77EFE43-D624-47AE-A105-59B2FEA444D7} - \WindApp Update No Task File <==== ATTENTION
Task: {F9CC76D8-621E-4081-BE50-BCE29C4A1B78} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-07] (CyberLink)
Task: {FAC9A473-2A07-4D2B-B420-115414ADFFAE} - System32\Tasks\PNLISMX => C:\Users\matt\AppData\Roaming\PNLISMX.exe <==== ATTENTION
Task: {FE996D17-301B-4C3D-A244-8149DB62A189} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-29] (Google Inc.)
Task: {FF83E5E3-2F53-4959-AF6A-88003CD138F7} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-145684943-4197250818-2869285112-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: C:\WINDOWS\Tasks\CGVW.job => C:\Users\matt\AppData\Roaming\CGVW.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-145684943-4197250818-2869285112-1001Core.job => C:\Users\matt\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-145684943-4197250818-2869285112-1001UA.job => C:\Users\matt\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleFormatt.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\WINDOWS\Tasks\PNLISMX.job => C:\Users\matt\AppData\Roaming\PNLISMX.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\VQEXDJD.job => C:\Users\matt\AppData\Roaming\VQEXDJD.exe <==== ATTENTION
 
==================== Loaded Modules (whitelisted) ==============
 
2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-02-04 13:20 - 2015-02-04 13:20 - 00076152 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe
2014-10-26 23:59 - 2014-10-26 23:59 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-10-30 06:41 - 2014-10-30 06:41 - 00031856 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
2012-07-10 21:11 - 2012-07-10 21:11 - 00009728 _____ () C:\Windows\system32\BsHelpCSps.dll
2012-07-10 21:09 - 2012-07-10 21:09 - 00022528 _____ () C:\Windows\system32\BsTrace.dll
2014-10-29 20:06 - 2014-10-29 20:06 - 00560192 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe
2015-03-12 21:40 - 2015-03-12 21:41 - 00051712 _____ () C:\Program Files\WindowsApps\Disney.StarWarsCommander_2.5.1.1_x86__6rarf9sa4v8jt\Template.exe
2015-03-01 12:41 - 2015-03-01 12:41 - 01724928 _____ () C:\Program Files\WindowsApps\6918E89D.AquaFish_2.0.1.1_x64__66n08swfvvka0\AquaFishS.exe
2015-01-24 18:45 - 2015-01-24 18:45 - 05185024 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.UI.Xaml\873b701d9b42e91132f08a6f05c4361a\Windows.UI.Xaml.ni.dll
2015-01-15 09:24 - 2015-01-15 09:24 - 00363520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\6382e6f5ad8b7a9db4f5cd4817e70319\Windows.Foundation.ni.dll
2015-01-15 09:25 - 2015-01-15 09:25 - 01782784 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\3f4dc590466037f015f65bc07d1ea923\Windows.ApplicationModel.ni.dll
2015-03-02 16:55 - 2015-03-02 16:55 - 00034304 _____ () C:\Users\matt\AppData\Local\Packages\6918E89D.AquaFish_66n08swfvvka0\AC\Microsoft\CLR_v4.0\NativeImages\AquaFishS\648132d2444c6711deed85353f63618e\AquaFishS.ni.dll
2015-01-15 09:24 - 2015-01-15 09:24 - 01278464 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Storage\f9ac074d298db459c5eff6d3256861c8\Windows.Storage.ni.dll
2015-01-15 09:24 - 2015-01-15 09:24 - 00632320 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Security\c7f6d022c5d5aec4891cb6b3b9934336\Windows.Security.ni.dll
2015-01-15 09:25 - 2015-01-15 09:25 - 00347136 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\94e2bc13589233f9d2cc54292717b8cf\Windows.Globalization.ni.dll
2015-01-15 09:24 - 2015-01-15 09:24 - 00207872 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.System\a4efa88b742703220e527956d8ab4e84\Windows.System.ni.dll
2015-02-12 06:29 - 2015-02-12 06:29 - 01259520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Networking\8f0dd293f95c402613c49fb2fac85bdd\Windows.Networking.ni.dll
2015-01-15 09:25 - 2015-01-15 09:25 - 01459712 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.UI\4bd80968bf666252841ca7792faaff11\Windows.UI.ni.dll
2015-01-15 09:25 - 2015-01-15 09:25 - 00521216 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Data\fae2b750f87849ca11806d20b2504bf2\Windows.Data.ni.dll
2014-12-08 09:50 - 2014-12-08 09:50 - 02019840 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Devices\0b4b3f23bdebd1d056b32b31e2f746bb\Windows.Devices.ni.dll
2015-02-12 06:29 - 2015-02-12 06:29 - 00467456 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Graphics\ea818a24554fc2db9a73de1e79afb286\Windows.Graphics.ni.dll
2012-07-10 21:09 - 2012-07-10 21:09 - 00022528 _____ () C:\Windows\SYSTEM32\BsTrace.dll
2014-12-08 11:13 - 2014-12-08 11:13 - 00865880 _____ () C:\Program Files (x86)\Real\RealPlayer\RPDS\Plugins\cldplin.dll
2014-10-30 06:41 - 2014-10-30 06:41 - 00035976 _____ () C:\Program Files (x86)\Real\UpdateService\DL2UpdatePlugin.dll
2014-10-30 06:41 - 2014-10-30 06:41 - 00039560 _____ () C:\Program Files (x86)\Real\UpdateService\RealDownloaderUpdatePlugin.dll
2014-10-30 06:41 - 2014-10-30 06:41 - 00032888 _____ () C:\Program Files (x86)\Real\UpdateService\RPDSUpdatePlugin.dll
2012-12-06 17:13 - 2012-06-25 13:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2012-07-10 21:09 - 2012-07-10 21:09 - 00022528 _____ () C:\WINDOWS\SYSTEM32\BsTrace.dll
2012-07-10 21:14 - 2012-07-10 21:14 - 00072192 _____ () C:\WINDOWS\SYSTEM32\BsProfilefunc.dll
2012-07-27 17:51 - 2012-07-27 17:51 - 00346112 _____ () C:\WINDOWS\SYSTEM32\BsExtendFunc.dll
2012-07-10 21:11 - 2012-07-10 21:11 - 00009728 _____ () C:\Windows\SYSTEM32\BsHelpCSps.dll
2012-07-10 21:11 - 2012-07-10 21:11 - 00052736 _____ () C:\Windows\SYSTEM32\BlueSoleilCSps.dll
2012-12-06 17:32 - 2012-06-07 22:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2012-06-08 14:34 - 2012-06-08 14:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2014-10-29 20:07 - 2014-10-29 20:07 - 00065600 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\dtvhooks.dll
2015-03-22 01:18 - 2015-03-14 05:12 - 01174856 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\libglesv2.dll
2015-03-22 01:18 - 2015-03-14 05:12 - 00080200 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\libegl.dll
2015-03-22 01:18 - 2015-03-14 05:12 - 09278792 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\pdf.dll
2015-03-22 01:18 - 2015-03-14 05:12 - 14974280 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\PepperFlash\pepflashplayer.dll
2014-10-29 20:01 - 2014-10-29 20:01 - 01382048 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\cpprest100_1_2.dll
2015-03-13 20:17 - 2015-03-13 20:17 - 00252928 _____ () C:\Users\matt\AppData\Local\Packages\Disney.StarWarsCommander_6rarf9sa4v8jt\AC\Microsoft\CLR_v4.0_32\NativeImages\Template\da8f4e71c9006826da48cc1389eb4ea4\Template.ni.exe
2015-01-31 06:01 - 2015-01-31 06:01 - 03530752 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.UI.Xaml\90a4331ab5b5bb3ead23d75d4349a491\Windows.UI.Xaml.ni.dll
2015-02-12 06:33 - 2015-02-12 06:33 - 00044544 _____ () C:\Users\matt\AppData\Local\Packages\Disney.StarWarsCommander_6rarf9sa4v8jt\AC\Microsoft\CLR_v4.0_32\NativeImages\UnityPlayer\f19c198346501fad31e8de4d32621a92\UnityPlayer.ni.dll
2015-03-13 20:18 - 2015-03-13 20:18 - 13230080 _____ () C:\Users\matt\AppData\Local\Packages\Disney.StarWarsCommander_6rarf9sa4v8jt\AC\Microsoft\CLR_v4.0_32\NativeImages\Assembly-CSharp\602ace8147700d3925edc870b59f812e\Assembly-CSharp.ni.dll
2015-03-13 20:18 - 2015-03-13 20:18 - 05116416 _____ () C:\Users\matt\AppData\Local\Packages\Disney.StarWarsCommander_6rarf9sa4v8jt\AC\Microsoft\CLR_v4.0_32\NativeImages\UnityEngine\f15c7a8d65d3a0e88cc405c55b77a13c\UnityEngine.ni.dll
2014-12-23 15:25 - 2014-12-23 15:25 - 09583616 _____ () C:\Program Files\WindowsApps\Disney.StarWarsCommander_2.5.1.1_x86__6rarf9sa4v8jt\UnityPlayer.dll
2015-01-31 06:01 - 2015-01-31 06:01 - 01130496 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.App640a3541#\6e37f358bf8363dad51e2333292d61a9\Windows.ApplicationModel.ni.dll
2015-02-12 17:48 - 2015-02-12 17:48 - 00247296 _____ () C:\Users\matt\AppData\Local\Packages\Disney.StarWarsCommander_6rarf9sa4v8jt\AC\Microsoft\CLR_v4.0_32\NativeImages\WinRTBridge\62d1df0491deb7b0844fadbc6148b5e0\WinRTBridge.ni.dll
2015-02-12 17:48 - 2015-02-12 17:48 - 00091136 _____ () C:\Users\matt\AppData\Local\Packages\Disney.StarWarsCommander_6rarf9sa4v8jt\AC\Microsoft\CLR_v4.0_32\NativeImages\BridgeInterface\0be095569bc5be436f25be441f271b6a\BridgeInterface.ni.dll
2015-01-31 06:01 - 2015-01-31 06:01 - 00960000 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.UI\6c2169e34bfb3814fa44f267572335f6\Windows.UI.ni.dll
2015-01-31 06:01 - 2015-01-31 06:01 - 00808448 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Storage\f0a2c10499402eff632a7a7df0b4afef\Windows.Storage.ni.dll
2015-01-31 06:01 - 2015-01-31 06:01 - 00228864 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Foundation\f7e726805e56676bd7b8662a3d842b0e\Windows.Foundation.ni.dll
2015-02-12 17:48 - 2015-02-12 17:48 - 01372672 _____ () C:\Users\matt\AppData\Local\Packages\Disney.StarWarsCommander_6rarf9sa4v8jt\AC\Microsoft\CLR_v4.0_32\NativeImages\UnityEngineProxy\2cd67a34b8c3a2faec166a13a86323ee\UnityEngineProxy.ni.dll
2015-02-12 17:48 - 2015-02-12 17:48 - 00013824 _____ () C:\Users\matt\AppData\Local\Packages\Disney.StarWarsCommander_6rarf9sa4v8jt\AC\Microsoft\CLR_v4.0_32\NativeImages\ICSharpCoded64bfd68#\d4d516f6be92a3a776c3422e792a28e6\ICSharpCode.SharpZipLib.ni.dll
2014-12-23 15:25 - 2014-12-23 15:25 - 00402944 _____ () C:\Program Files\WindowsApps\Disney.StarWarsCommander_2.5.1.1_x86__6rarf9sa4v8jt\UnityEngineDelegates.dll
2015-02-12 17:48 - 2015-02-12 17:48 - 00080384 _____ () C:\Users\matt\AppData\Local\Packages\Disney.StarWarsCommander_6rarf9sa4v8jt\AC\Microsoft\CLR_v4.0_32\NativeImages\KochavaLibrfa7a1879#\2c947f0cc858845e0dda9766856cf00e\KochavaLibraryDesktop80.ni.dll
2015-01-31 06:01 - 2015-01-31 06:01 - 00337920 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Data\fe565d34d4335337c06264bb0d85e3b0\Windows.Data.ni.dll
2015-03-13 20:18 - 2015-03-13 20:18 - 01583104 _____ () C:\Users\matt\AppData\Local\Packages\Disney.StarWarsCommander_6rarf9sa4v8jt\AC\Microsoft\CLR_v4.0_32\NativeImages\msdk\eec43dcfe8549245bd4f52347f7f44e5\msdk.ni.dll
2014-12-01 19:41 - 2014-12-01 19:41 - 00402432 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Security\ade4f25e9d8384f190ede9eb090281cb\Windows.Security.ni.dll
2015-01-31 06:01 - 2015-01-31 06:01 - 00133120 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.System\7819e306c2c55c42f35a5fa10b93710f\Windows.System.ni.dll
2014-12-08 11:13 - 2014-12-08 11:13 - 00573528 _____ () C:\Program Files (x86)\Real\RealPlayer\RPDS\Lib\r1api.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\Users\matt\OneDrive:ms-properties
AlternateDataStreams: C:\Users\matt\OneDrive.old:ms-properties
AlternateDataStreams: C:\Users\matt\SkyDrive:ms-properties
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-145684943-4197250818-2869285112-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\matt\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\…\StartupApproved\StartupFolder: => "RealPlayer Cloud Service UI.lnk"
HKLM\…\StartupApproved\Run32: => "DivXUpdate"
HKLM\…\StartupApproved\Run32: => "iTunesHelper"
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-145684943-4197250818-2869285112-500 - Administrator - Disabled) => C:\Users\Administrator
AtxCyco (S-1-5-21-145684943-4197250818-2869285112-1008 - Limited - Enabled)
Guest (S-1-5-21-145684943-4197250818-2869285112-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-145684943-4197250818-2869285112-1007 - Limited - Enabled)
matt (S-1-5-21-145684943-4197250818-2869285112-1001 - Administrator - Enabled) => C:\Users\matt
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/29/2015 06:33:19 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: LATTAVOSLAPTOP)
Description: Package LucasArts.StarWarsAssaultTeam_1.3.0.162_x86__0b4270ybzrpx8+App was terminated because it took too long to suspend.
 
Error: (03/29/2015 05:12:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BlueSoleilCS.exe, version: 9.0.709.0, time stamp: 0x5019fa79
Faulting module name: tl_filter.dll, version: 0.0.0.0, time stamp: 0x50247825
Exception code: 0xc0000094
Fault offset: 0x0000d53d
Faulting process id: 0x1d9c
Faulting application start time: 0xBlueSoleilCS.exe0
Faulting application path: BlueSoleilCS.exe1
Faulting module path: BlueSoleilCS.exe2
Report Id: BlueSoleilCS.exe3
Faulting package full name: BlueSoleilCS.exe4
Faulting package-relative application ID: BlueSoleilCS.exe5
 
Error: (03/29/2015 11:19:20 AM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: LATTAVOSLAPTOP)
Description: Application or service 'HPWMISVC' could not be restarted.
 
Error: (03/29/2015 10:09:27 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/29/2015 09:57:38 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/29/2015 09:44:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BlueSoleilCS.exe, version: 9.0.709.0, time stamp: 0x5019fa79
Faulting module name: tl_filter.dll, version: 0.0.0.0, time stamp: 0x50247825
Exception code: 0xc0000094
Fault offset: 0x0000d53d
Faulting process id: 0xf84
Faulting application start time: 0xBlueSoleilCS.exe0
Faulting application path: BlueSoleilCS.exe1
Faulting module path: BlueSoleilCS.exe2
Report Id: BlueSoleilCS.exe3
Faulting package full name: BlueSoleilCS.exe4
Faulting package-relative application ID: BlueSoleilCS.exe5
 
Error: (03/29/2015 09:42:13 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BlueSoleilCS.exe, version: 9.0.709.0, time stamp: 0x5019fa79
Faulting module name: tl_filter.dll, version: 0.0.0.0, time stamp: 0x50247825
Exception code: 0xc0000094
Fault offset: 0x0000d53d
Faulting process id: 0x700
Faulting application start time: 0xBlueSoleilCS.exe0
Faulting application path: BlueSoleilCS.exe1
Faulting module path: BlueSoleilCS.exe2
Report Id: BlueSoleilCS.exe3
Faulting package full name: BlueSoleilCS.exe4
Faulting package-relative application ID: BlueSoleilCS.exe5
 
Error: (03/29/2015 03:04:32 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/29/2015 02:43:42 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/29/2015 01:14:04 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program backgroundTaskHost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 2064
 
Start Time: 01d069e6d4f37e76
 
Termination Time: 4294967295
 
Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe
 
Report Id: c8d8befd-d5da-11e4-beb7-1c3e8463f8fc
 
Faulting package full name: YanFlex.Craigslist_1.5.1.6_x64__xqdm6kn4nxgd2
 
Faulting package-relative application ID: App
 
 
System errors:
=============
Error: (03/29/2015 08:30:12 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205.
 
Error: (03/29/2015 08:30:12 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
 
Error: (03/29/2015 05:13:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The BlueSoleilCS service terminated unexpectedly.  It has done this 3 time(s).
 
Error: (03/29/2015 11:19:25 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The HPWMISVC service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
 
Error: (03/29/2015 09:44:29 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The BlueSoleilCS service terminated unexpectedly.  It has done this 2 time(s).
 
Error: (03/29/2015 09:42:39 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The BlueSoleilCS service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/29/2015 02:56:36 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205.
 
Error: (03/29/2015 02:56:36 AM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
 
Error: (03/28/2015 10:53:06 PM) (Source: DCOM) (EventID: 10016) (User: LATTAVOSLAPTOP)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}LattavosLaptopmattS-1-5-21-145684943-4197250818-2869285112-1001LocalHost (Using LRPC)Microsoft.MicrosoftJackpot_1.3.1501.2301_x86__8wekyb3d8bbweS-1-15-2-2162314911-3279664781-1988602246-1568615701-4287328547-3722558685-3292250991
 
Error: (03/28/2015 10:53:06 PM) (Source: DCOM) (EventID: 10016) (User: LATTAVOSLAPTOP)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}LattavosLaptopmattS-1-5-21-145684943-4197250818-2869285112-1001LocalHost (Using LRPC)Microsoft.MicrosoftJackpot_1.3.1501.2301_x86__8wekyb3d8bbweS-1-15-2-2162314911-3279664781-1988602246-1568615701-4287328547-3722558685-3292250991
 
 
Microsoft Office Sessions:
=========================
Error: (03/29/2015 06:33:19 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: LATTAVOSLAPTOP)
Description: LucasArts.StarWarsAssaultTeam_1.3.0.162_x86__0b4270ybzrpx8+App
 
Error: (03/29/2015 05:12:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: BlueSoleilCS.exe9.0.709.05019fa79tl_filter.dll0.0.0.050247825c00000940000d53d1d9c01d06a6d6fa13d6fC:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exeC:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\Driver\USB\tl_filter.dllb5fd32bb-d660-11e4-beb7-1c3e8463f8fc
 
Error: (03/29/2015 11:19:20 AM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: LATTAVOSLAPTOP)
Description: 0C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exeHPWMISVC03026217819720
 
Error: (03/29/2015 10:09:27 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{6FCD4D5A-20B9-4D79-ABA5-4E7048944025}\recordingmanager.exe
 
Error: (03/29/2015 09:57:38 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{6FCD4D5A-20B9-4D79-ABA5-4E7048944025}\recordingmanager.exe
 
Error: (03/29/2015 09:44:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: BlueSoleilCS.exe9.0.709.05019fa79tl_filter.dll0.0.0.050247825c00000940000d53df8401d06a2ed4fadca2C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exeC:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\Driver\USB\tl_filter.dll19e8fbae-d622-11e4-beb7-1c3e8463f8fc
 
Error: (03/29/2015 09:42:13 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: BlueSoleilCS.exe9.0.709.05019fa79tl_filter.dll0.0.0.050247825c00000940000d53d70001d068055f9820e7C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exeC:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\Driver\USB\tl_filter.dllc942d7af-d621-11e4-beb7-1c3e8463f8fc
 
Error: (03/29/2015 03:04:32 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{6FCD4D5A-20B9-4D79-ABA5-4E7048944025}\recordingmanager.exe
 
Error: (03/29/2015 02:43:42 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{6FCD4D5A-20B9-4D79-ABA5-4E7048944025}\recordingmanager.exe
 
Error: (03/29/2015 01:14:04 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: backgroundTaskHost.exe6.3.9600.17415206401d069e6d4f37e764294967295C:\WINDOWS\system32\backgroundTaskHost.exec8d8befd-d5da-11e4-beb7-1c3e8463f8fcYanFlex.Craigslist_1.5.1.6_x64__xqdm6kn4nxgd2App
 
 
CodeIntegrity Errors:
===================================
  Date: 2015-03-19 21:15:33.321
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-19 21:15:33.016
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-19 21:15:32.734
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-19 21:15:32.536
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-19 21:15:32.313
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-19 21:15:32.119
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-19 21:15:31.862
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-19 21:15:31.652
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-19 21:15:31.458
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-03-19 21:15:31.265
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i3-3110M CPU @ 2.40GHz
Percentage of memory in use: 62%
Total physical RAM: 6036.27 MB
Available physical RAM: 2289.21 MB
Total Pagefile: 8412.69 MB
Available Pagefile: 4009.67 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:672.62 GB) (Free:523.04 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVERY) (Fixed) (Total:24.8 GB) (Free:2.92 GB) NTFS ==>[System with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: AD62557C)
 
Partition: GPT Partition Type.
 
==================== End Of Log ============================
 
This is the results of the other scan
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-03-29 17:53:38
—————————–
17:53:38.252    OS Version: Windows x64 6.2.9200 
17:53:38.252    Number of processors: 4 586 0x3A09
17:53:38.253    ComputerName: LATTAVOSLAPTOP  UserName: matt
17:53:40.016    Initialize success
17:53:41.026    VM: initialized successfully
17:53:41.027    VM: Intel CPU BiosDisabled 
18:03:30.296    AVAST engine defs: 15032901
18:05:56.060    The log file has been saved successfully to "C:\Users\matt\Documents\YOURADEXCHANGE BS\aswMBR.txt"
18:07:53.747    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002d
18:07:53.749    Disk 0 Vendor: ST750LM022_HN-M750MBB 2AR20002 Size: 715404MB BusType: 11
18:07:53.913    Disk 0 MBR read successfully
18:07:53.916    Disk 0 MBR scan
18:07:53.920    Disk 0 unknown MBR code
18:07:53.924    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
18:07:53.946    Disk 0 scanning C:\WINDOWS\system32\drivers
18:08:07.179    Service scanning
18:08:09.650    Service BHDrvx64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.6.0.32\Definitions\BASHDefs\20150321.001\BHDrvx64.sys **LOCKED** 5
18:08:12.980    Service eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys **LOCKED** 5
18:08:13.157    Service EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys **LOCKED** 5
18:08:16.667    Service IDSVia64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.6.0.32\Definitions\IPSDefs\20150327.001\IDSvia64.sys **LOCKED** 5
18:08:20.397    Service NAVENG C:\Program Files (x86)\Norton Internet Security\NortonData\21.6.0.32\Definitions\VirusDefs\20150328.002\ENG64.SYS **LOCKED** 5
18:08:20.547    Service NAVEX15 C:\Program Files (x86)\Norton Internet Security\NortonData\21.6.0.32\Definitions\VirusDefs\20150328.002\EX64.SYS **LOCKED** 5
18:08:35.872    Modules scanning
18:08:35.879    Disk 0 trace - called modules:
18:08:35.949    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys storport.sys hal.dll iaStorA.sys 
18:08:35.954    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe000a2835060]
18:08:35.958    3 CLASSPNP.SYS[fffff8003a739170] -> nt!IofCallDriver -> [0xffffe000a2836960]
18:08:35.962    5 hpdskflt.sys[fffff8003b57e339] -> nt!IofCallDriver -> \Device\0000002d[0xffffe000a0fdc7f0]
18:08:37.185    AVAST engine scan C:\WINDOWS
18:08:40.435    AVAST engine scan C:\WINDOWS\system32
18:12:53.905    AVAST engine scan C:\WINDOWS\system32\drivers
18:13:10.491    AVAST engine scan C:\Users\matt
18:47:25.390    File: C:\Users\matt\AppData\Local\Temp\nsdD7B5.tmp  **INFECTED** Win32:Dropper-gen [Drp]
18:47:25.558    File: C:\Users\matt\AppData\Local\Temp\nsfDD81.tmp  **INFECTED** Win32:Dropper-gen [Drp]
19:02:32.644    AVAST engine scan C:\ProgramData
19:10:05.071    Disk 0 statistics 4843681/0/0 @ 0.84 MB/s
19:10:05.077    Scan finished successfully
22:49:36.567    Disk 0 MBR has been saved successfully to "C:\Users\matt\Documents\YOURADEXCHANGE BS\MBR.dat"
22:49:36.572    The log file has been saved successfully to "C:\Users\matt\Documents\YOURADEXCHANGE BS\aswMBR2.txt"

I hope this is all you needed from me for now and thank you for helping me. Please let me know what is needed from me.

OK. This should be everything you need now.

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by [removed] (administrator) on LATTAVOSLAPTOP on 29-03-2015 23:04:29
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\nis.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
(Company) C:\Program Files (x86)\Popcorn Time\Updater.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\nis.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\conathst.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\nacl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.101\nacl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Users\matt\Downloads\aswMBR.exe
() C:\Program Files\WindowsApps\Disney.StarWarsCommander_2.5.1.1_x86__6rarf9sa4v8jt\Template.exe
() C:\Program Files\WindowsApps\6918E89D.AquaFish_2.0.1.1_x64__66n08swfvvka0\AquaFishS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(RealNetworks, Inc.) C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [HotKeysCmds] => C:\Windows\system32\hkcmd.exe
HKLM\…\Run: [Persistence] => C:\Windows\system32\igfxpers.exe
HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2014-12-22] (IDT, Inc.)
HKLM-x32\…\Run: [BtTray] => C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [363520 2012-08-02] (IVT Corporation)
HKLM-x32\…\Run: [CMS] => C:\Program Files (x86)\CMS\CMS.exe [2539520 2013-09-06] ()
HKU\S-1-5-21-145684943-4197250818-2869285112-1001\…\Run: [Google Update] => C:\Users\matt\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-12-24] (Google Inc.)
HKU\S-1-5-21-145684943-4197250818-2869285112-1001\…\Run: [Nero MediaHome 4] => "C:\Program Files (x86)\Nero\Nero MediaHome 4\NeroMediaHome.exe" /AUTORUN
HKU\S-1-5-21-145684943-4197250818-2869285112-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31344744 2015-02-26] (Skype Technologies S.A.)
HKU\S-1-5-21-145684943-4197250818-2869285112-1001\…\MountPoints2: {29462f4c-81f9-11e4-be7b-1c3e8463f8fc} - "F:\HTC_Sync_Manager_PC.exe" 
HKU\S-1-5-21-145684943-4197250818-2869285112-1001\…\MountPoints2: {936af775-a033-11e4-be90-1c3e8463f8fc} - "F:\ZTE_Handset_USB_Driver.exe" 
HKU\S-1-5-21-145684943-4197250818-2869285112-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Mystify.scr [133632 2014-10-28] (Microsoft Corporation)
HKU\S-1-5-18\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-12-31] (Garmin Ltd or its subsidiaries)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
HKU\S-1-5-21-145684943-4197250818-2869285112-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
HKU\S-1-5-21-145684943-4197250818-2869285112-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://tikotin.com
SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.com/web?q={searchterms}&l;=dis&o;=HPNTDF
SearchScopes: HKLM -> {8621D76B-511F-4041-8473-223542C58346} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us2-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo.com/search?p={searchTerms}&ei;={inputEncoding}&fr;=chr-hp-psg&type;=HPNTDF
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-154371-11896-2/4?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.com/web?q={searchterms}&l;=dis&o;=HPNTDF
SearchScopes: HKLM-x32 -> {8621D76B-511F-4041-8473-223542C58346} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us2-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo.com/search?p={searchTerms}&ei;={inputEncoding}&fr;=chr-hp-psg&type;=HPNTDF
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-154371-11896-2/4?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
SearchScopes: HKU\S-1-5-21-145684943-4197250818-2869285112-1001 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.com/web?q={searchterms}&l;=dis&o;=HPNTDF
SearchScopes: HKU\S-1-5-21-145684943-4197250818-2869285112-1001 -> {8621D76B-511F-4041-8473-223542C58346} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us2-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKU\S-1-5-21-145684943-4197250818-2869285112-1001 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo.com/search?p={searchTerms}&ei;={inputEncoding}&fr;=chr-hp-psg&type;=HPNTDF
SearchScopes: HKU\S-1-5-21-145684943-4197250818-2869285112-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-154371-11896-2/4?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-10-27] (RealDownloader)
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine64\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-10-27] (RealDownloader)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\IPS\IPSBHO.DLL [2015-03-04] (Symantec Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Winsock: Catalog5 08 C:\WINDOWS\SysWOW64\wlidNSP.dll [50176] (Microsoft Corporation)
Winsock: Catalog5 09 C:\WINDOWS\SysWOW64\wlidNSP.dll [50176] (Microsoft Corporation)
Winsock: Catalog5-x64 08 C:\WINDOWS\system32\wlidnsp.dll [74240] (Microsoft Corporation)
Winsock: Catalog5-x64 09 C:\WINDOWS\system32\wlidnsp.dll [74240] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw.dll [2012-04-26] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=17.0.15.10 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2014-12-08] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.15 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-10-27] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.15.10 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [2014-12-08] (RealPlayer Cloud)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files (x86)\Sony\Media Go\npmediago.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-05-11] ()
FF Plugin-x32: JFGuide -> C:\Program Files (x86)\NetSurveillance\CMS\npGuide.dll [2015-01-09] ()
FF Plugin-x32: JFWeb -> C:\Program Files (x86)\NetSurveillance\CMS\npWebPlugin.dll [2015-01-09] ()
FF Plugin HKU\S-1-5-21-145684943-4197250818-2869285112-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\matt\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-01-27] (Google)
FF Plugin HKU\S-1-5-21-145684943-4197250818-2869285112-1001: @talk.google.com/O1DPlugin -> C:\Users\matt\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-01-27] (Google)
FF Plugin HKU\S-1-5-21-145684943-4197250818-2869285112-1001: @tools.google.com/Google Update;version=3 -> C:\Users\matt\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin HKU\S-1-5-21-145684943-4197250818-2869285112-1001: @tools.google.com/Google Update;version=9 -> C:\Users\matt\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin HKU\S-1-5-21-145684943-4197250818-2869285112-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\matt\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-01-26] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-145684943-4197250818-2869285112-1001: sony.com/MediaGoDetector -> C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll [2014-07-10] (Sony Network Entertainment International LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\matt\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-01-27] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\matt\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-01-27] (Google)
FF HKLM-x32\…\Firefox\Extensions: [{338950EA-82DB-44C1-930D-0C28E023C9F0}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-12-08]
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.6.0.32\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.6.0.32\coFFPlgn [2015-03-26]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.yahoo.com/
CHR StartupUrls: Default -> "hxxp://www.yahoo.com/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs;_ri={google:suggestRid}&xssi;=t&q;={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-29]
CHR Extension: (Yahoo Web) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\acjpdakpjonkfmggcmanlhdakfkhloii [2015-03-09]
CHR Extension: (Bejeweled) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm [2015-03-09]
CHR Extension: (Ancient History Encyclopedia) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahggffalhoajbhlaogbplamaaghnncle [2015-03-09]
CHR Extension: (Duolingo on the Web) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiahmijlpehemcpleichkcokhegllfjl [2015-03-09]
CHR Extension: (Angry Birds) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2015-03-09]
CHR Extension: (Forge of Empires) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\anaphblkfplenhkephgneolhnmjminjg [2015-03-09]
CHR Extension: (Google Docs) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-29]
CHR Extension: (Google Drive) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-29]
CHR Extension: (Rhapsody) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\bchmkapadehcjeefcedoagboglpakpkk [2015-03-09]
CHR Extension: (People Search) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcmfaldcdcpemjjdnngplmkknajikakj [2015-03-09]
CHR Extension: (TV) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2015-03-09]
CHR Extension: (Send to Google Maps) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhggankplfegmjjngfmhfajedmiikolo [2015-03-09]
CHR Extension: (YOUZEEK Free Music) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjcgpdkighmjfjlplcighhgamlhkimce [2015-03-09]
CHR Extension: (YouTube) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-29]
CHR Extension: (Solitaire) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpebaehgfgkcmmjjknibibbjacnplim [2015-03-09]
CHR Extension: (keySharky) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmdbjbgbnoljfhkjiebkdphfikhkkopn [2015-03-09]
CHR Extension: (Play Free Online Games) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnkfbdnbpegmadgophclcijgmmlfdbkm [2015-03-09]
CHR Extension: (TV) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\bppbpeijolfcampacpljolaegibfhjph [2015-03-09]
CHR Extension: (4th of July Solitaire) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbaepbhbolaemfffalmjaafkldgcicag [2015-03-09]
CHR Extension: (Battlegrounds of Eldhelm) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdkaddpgikmbnfpahgkjabeniopnhmjj [2015-03-09]
CHR Extension: (Pool) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\cedbddnnmhgnedpamoenmdkhnpnfbpjb [2015-03-09]
CHR Extension: (Frontline Defense 2) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgkkjbfndmkjfoichfgkgkpcillielpe [2015-03-09]
CHR Extension: (Pyramid Solitaire) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckibdpgohpfkaadcpnhhfgodfmicbnen [2015-03-09]
CHR Extension: (Slacker Radio) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckngegfcpnbbcejpfnakcdcjgigaiole [2015-03-09]
CHR Extension: (STRATEGO - Official) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckpgdjbodiacocpojlgipgkphcihfbdo [2015-03-09]
CHR Extension: (Thesaurus.com - Synonyms and Antonyms) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\clljlcapeomdokpgadmegpabakieebci [2015-03-09]
CHR Extension: (Spotify - Music for every moment) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2015-03-09]
CHR Extension: (Google Search) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-29]
CHR Extension: (Pandora Listener) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\danjmbbdjabpapehlajpomcignjnoidp [2015-03-09]
CHR Extension: (VUDU Movies) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\daomabnenlgkenegngdblacoobnncgib [2015-03-09]
CHR Extension: (Solitaire) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkelcbhdkpcdiiancfjhjcpdinbbfolp [2015-03-09]
CHR Extension: (Google+) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2015-03-09]
CHR Extension: (Word Search) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnjkggjhcbohgnikmegjkodmakmimlkj [2015-03-09]
CHR Extension: (World Wars) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebkpkhgokgepcifhefodkkfehfnhhnbi [2015-03-09]
CHR Extension: (Reverse Phone Lookup) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\eccacjpoadkkkichonipjpkjoklpdacg [2015-03-09]
CHR Extension: (Timer) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\edebbhkhcaafmolanelponjjanocpacd [2015-03-09]
CHR Extension: (Google Calendar) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2015-03-09]
CHR Extension: (Pandora) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl [2015-03-09]
CHR Extension: (Google Sheets) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-10]
CHR Extension: (3D Slots) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhhcmlbglbogeijcnccfdbfnpgihgjpe [2015-03-09]
CHR Extension: (The Big Fish) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnlainpoijbdcjpdkbcggmidhignljon [2015-03-09]
CHR Extension: (UNO 3D HD) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdkfcgceminipbgjnnimdkejmlaecebj [2015-03-09]
CHR Extension: (Goodgame Empire) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggdljnjjajocmjaldkldaapkkclbaclb [2015-03-09]
CHR Extension: (Planetarium) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp [2015-03-09]
CHR Extension: (Dictionary by Dictionary.com) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\gikhgcaliglmioibbockkmjknfnepbdh [2015-03-09]
CHR Extension: (A Journey through Middle-earth) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjgkjeheegjnnmheaflhdocglkiegoni [2015-03-09]
CHR Extension: (Fairway Solitaire) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkpbdfapchjogkmfpcmnfjdimgijhdho [2015-03-09]
CHR Extension: (QuickTime for Chrome) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\glkdifongmamddfegpjkmghbmoikkjai [2015-03-16]
CHR Extension: (TU-95 - Pilot the Plane!) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbjohfoloehbkffdihkengbkjgalmabj [2015-03-09]
CHR Extension: (247 Solitaire) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdelbagmgokcoecefcaklpocihjmobcg [2015-03-09]
CHR Extension: (Longbow - Archery 3D) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\helcoidggejhedkbbgbofkfcheikaoec [2015-03-09]
CHR Extension: (JavaScript Popup Blocker) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiajdlfgbgnnjakkbnpdhmhfhklkbiol [2015-03-09]
CHR Extension: (Halloween Solitaire) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjamolccbjcinegecpmmnjkhdopehkdb [2015-03-09]
CHR Extension: (Halloween Mahjong) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ielpieklegnicibpoklcphmbonpbdknd [2015-03-09]
CHR Extension: (Crazy Shooting) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbhccdddhenjmeamogpjhicnoffdood [2015-03-09]
CHR Extension: (World of Solitaire) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbnllnaaaohekjkcpfdllhhjijnidgn [2015-03-09]
CHR Extension: (Battlestar Galactica Online) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihbmdfdhanakpfoiaomnelodiejioflb [2015-03-09]
CHR Extension: (Norton Identity Safe) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-03-22]
CHR Extension: (90`s Games) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\illbbfoihflomkbpcaaakhijinbnejom [2015-03-09]
CHR Extension: (Fish Tales 2) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaghkmcgmmageapicnkmimibjenkldkc [2015-03-09]
CHR Extension: (Windows 8 App Store) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\japaekjghocnlanfbegjmokjiinnpdfi [2015-03-09]
CHR Extension: (Command & Conquer Tiberium Alliances) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaeopgjojikeoiidmfaejkifhgjoooe [2015-03-09]
CHR Extension: (Skyrama) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlehaidnnmjjkhgbbiombcdifogolhap [2015-03-09]
CHR Extension: (Rise Of the Tower) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnhdfikkiighlicpokggnfklodfmiaph [2015-03-09]
CHR Extension: (Hangouts call) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbpgddbgniojgndnhlkjbkpknjhppkbk [2015-03-09]
CHR Extension: (Google Voice (by Google)) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo [2015-03-09]
CHR Extension: (Quick Earth) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\khodocggeplgfhppgagfdpbjkniadmdh [2015-03-09]
CHR Extension: (Google Play) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2015-03-09]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Steambirds: Survival) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcdhpokmalcfjnfkjlfncgekebcojinn [2015-03-09]
CHR Extension: (Graffiti Creator) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgmlohhjedlnljheklbjepdfikchfaoe [2015-03-09]
CHR Extension: (Solitaire) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbhppfbabandkdmgjmifahoabeodiep [2015-03-09]
CHR Extension: (Fieldrunners) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak [2015-03-09]
CHR Extension: (War Commander) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\llmmanebcflnklopeacnlgkpiehfacmd [2015-03-09]
CHR Extension: (3D Galaxy Bowling) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\llojoebfpfheijcipgokjllohccfnkoo [2015-03-09]
CHR Extension: (Google Maps) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-03-09]
CHR Extension: (12 Towers) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdkeklohckaijapmmneogbfelodgbdck [2015-03-09]
CHR Extension: (Twoo Notifications) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\mggafhpkgkfebnjfbiefbbbicikgchlf [2015-03-09]
CHR Extension: (Norton Security Toolbar) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2015-03-22]
CHR Extension: (Fishing Joy) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlonhgnjdlnjgalpdigmbpfpielpadmc [2015-03-09]
CHR Extension: (WGT Golf Game) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpedbpkelbhcbkdaglillalioeeekbpb [2015-03-09]
CHR Extension: (Hangouts) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2015-03-09]
CHR Extension: (OneDrive) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2015-03-09]
CHR Extension: (Urban Rivals) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhaipmgfdihnlnbagikdpijhkifeonbi [2015-03-09]
CHR Extension: (Frontline Defense 2 HD) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nincmkjomngcmklpdkmdkioemlhdieim [2015-03-09]
CHR Extension: (WeatherBug) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\njkkjobcechefaoknodniidfjapgfoco [2015-03-09]
CHR Extension: (MONOPOLY: The World Edition) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkedhiolniniodbokjinplhaleemnfbe [2015-03-09]
CHR Extension: (Norton Safe) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmgcfemagnogdodbambjhdcmfcpicngl [2015-03-22]
CHR Extension: (Google Wallet) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-29]
CHR Extension: (ishipdocs) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonpodjceddajpfanekkgbacloilmhpn [2015-03-09]
CHR Extension: (Picky Wallpapers) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\odklcfojpedohplkimfdpcamkjnhanaj [2015-03-09]
CHR Extension: (My Chrome Theme) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2015-03-09]
CHR Extension: (Pacific War) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojllhpjjcfijalobmoeeamchmpkfdeoi [2015-03-09]
CHR Extension: (3D Bomb Destroyer) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\okehlnjpihomkdokiiafpejniofjaoom [2015-03-09]
CHR Extension: (Sniper Games) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\onjdoagkpggaokhecdopkkffjigjhgjp [2015-03-09]
CHR Extension: (Real Punk Radio) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pajamccbffejmgdifclpofegpeipbcaa [2015-03-09]
CHR Extension: (Rdio) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pchjhmiapbbphflbgejhigbmfmmgbngn [2015-03-09]
CHR Extension: (Tower Defense Games) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcpfnceohklofdokioencgjbpgdlphpa [2015-03-09]
CHR Extension: (MegaStar Sliding) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfaogkfljpdfmodbmbogiiblppijleen [2015-03-09]
CHR Extension: (Gmail) - C:\Users\matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-29]
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\Exts\Chrome.crx [2015-03-20]
CHR HKLM-x32\…\Chrome\Extension: [ihenkjeihefokohmemphikjnjbmegdik] - "C:\Program Files (x86)\Sony\Media Go\MediaGoDetector.crx" [Not Found]
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\Exts\Chrome.crx [2015-03-20]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1544192 2012-08-02] (IVT Corporation) [File not signed]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-02-23] (BitRaider, LLC)
R3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [138752 2012-07-10] (IVT Corporation) [File not signed]
R3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [451416 2014-12-31] (Garmin Ltd or its subsidiaries)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-01] (Intel Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\NIS.exe [276336 2015-03-07] (Symantec Corporation)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76152 2015-02-04] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-10-26] ()
R2 RealPlayer Cloud Service; C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [1141848 2014-12-08] (RealNetworks, Inc.)
R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31856 2014-10-30] ()
R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [335360 2014-12-08] (Company) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-07-02] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.6.0.32\Definitions\BASHDefs\20150321.001\BHDrvx64.sys [1622744 2015-03-09] (Symantec Corporation)
S3 BlueletAudio; C:\Windows\system32\DRIVERS\blueletaudio.sys [34912 2012-06-15] (Ralink Corporation.)
S3 BlueletSCOAudio; C:\Windows\system32\DRIVERS\BlueletSCOAudio.sys [35936 2012-07-10] (Ralink Corporation)
R3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [132608 2015-01-29] (Microsoft Corporation)
S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [32768 2014-10-08] (Microsoft Corporation)
R3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-19] (Ralink Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-09-24] (Microsoft Corporation)
R3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [48736 2012-08-09] (Ralink Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1507000.00B\ccSetx64.sys [162392 2014-02-20] (Symantec Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2015-03-19] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2015-03-19] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.6.0.32\Definitions\IPSDefs\20150327.001\IDSvia64.sys [671448 2015-03-26] (Symantec Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.6.0.32\Definitions\VirusDefs\20150329.001\ENG64.SYS [129752 2015-03-19] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.6.0.32\Definitions\VirusDefs\20150329.001\EX64.SYS [2137304 2015-03-19] (Symantec Corporation)
S3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204424 2013-12-02] (Ralink Technology, Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-14] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2014-12-22] (Synaptics Incorporated)
R1 SRTSP; C:\Windows\System32\Drivers\NISx64\1507000.00B\SRTSP64.SYS [876248 2014-08-25] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1507000.00B\SRTSPX64.SYS [37592 2014-08-25] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1507000.00B\SYMDS64.SYS [493656 2014-08-25] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1507000.00B\SYMEFA64.SYS [1148120 2014-08-25] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\NISx64\1507000.00B\SymELAM.sys [23568 2014-08-25] (Symantec Corporation)
R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [177752 2015-03-20] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1507000.00B\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1507000.00B\SYMNETS.SYS [593112 2014-08-25] (Symantec Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
S3 WFMC_VAD; C:\Windows\system32\DRIVERS\wfmcvad.sys [24064 2010-02-08] (WiFi Media Connect)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)
S3 BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [X]
S1 cherimoya; system32\drivers\cherimoya.sys [X]
S3 EraserUtilDrv11411; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11411.sys [X]
U3 aswMBR; \??\C:\Users\matt\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\matt\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-03-29 23:04 - 2015-03-29 23:04 - 00043652 _____ () C:\Users\matt\Downloads\FRST.txt
2015-03-29 23:02 - 2015-03-29 23:04 - 00000000 ____D () C:\FRST
2015-03-29 23:01 - 2015-03-29 23:01 - 02095616 _____ (Farbar) C:\Users\matt\Downloads\FRST64.exe
2015-03-29 18:05 - 2015-03-29 22:49 - 00000000 ____D () C:\Users\matt\Documents\YOURADEXCHANGE BS
2015-03-29 17:51 - 2015-03-29 17:52 - 05198336 _____ (AVAST Software) C:\Users\matt\Downloads\aswMBR.exe
2015-03-22 01:18 - 2015-03-22 01:18 - 00002275 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-22 01:18 - 2015-03-22 01:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-03-21 13:56 - 2015-03-21 13:56 - 04322148 _____ () C:\Users\matt\Documents\2015 Colt Product Brochure sm.pdf.wcbaq1u.partial
2015-03-20 23:54 - 2015-03-29 17:31 - 00000000 ____D () C:\Users\matt\AppData\Roaming\Skype
2015-03-20 23:54 - 2015-03-20 23:54 - 00002713 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-03-20 23:54 - 2015-03-20 23:54 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-03-20 23:54 - 2015-03-20 23:54 - 00000000 ____D () C:\Users\matt\AppData\Local\Skype
2015-03-20 23:54 - 2015-03-20 23:54 - 00000000 ____D () C:\ProgramData\Skype
2015-03-20 23:54 - 2015-03-20 23:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-03-20 14:23 - 2015-03-20 14:23 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Norton Internet Security
2015-03-20 01:08 - 2015-03-20 14:18 - 00003234 _____ () C:\WINDOWS\System32\Tasks\Norton WSC Integration
2015-03-20 01:08 - 2015-03-20 14:18 - 00002521 _____ () C:\Users\Public\Desktop\Norton Internet Security.lnk
2015-03-20 01:08 - 2015-03-20 01:08 - 00177752 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS
2015-03-20 01:08 - 2015-03-20 01:08 - 00008222 _____ () C:\WINDOWS\system32\Drivers\SYMEVENT64x86.CAT
2015-03-20 01:08 - 2015-03-20 01:08 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared
2015-03-20 01:06 - 2015-03-20 14:18 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
2015-03-20 01:06 - 2015-03-20 14:18 - 00000000 ____D () C:\WINDOWS\system32\Drivers\NISx64
2015-03-20 01:06 - 2015-03-20 01:06 - 00000000 ____D () C:\Program Files (x86)\Norton Internet Security
2015-03-19 21:41 - 2015-03-19 21:42 - 00010474 _____ () C:\Users\matt\Documents\Uninstall STAR WARS The Old Republic.log
2015-03-19 13:09 - 2015-03-19 13:09 - 00000136 _____ () C:\WINDOWS\SysWOW64\LEDEVICE.ini
2015-03-18 14:22 - 2015-03-19 13:00 - 00000000 ____D () C:\Users\matt\AppData\Local\LogMeIn Rescue Applet
2015-03-18 14:22 - 2015-03-18 14:22 - 01528128 _____ (LogMeIn, Inc.) C:\Users\matt\Downloads\Support-LogMeInRescue.exe
2015-03-18 14:22 - 2015-03-18 14:22 - 00002266 _____ () C:\Users\matt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CoreIT.lnk
2015-03-18 08:40 - 2015-03-18 08:42 - 39401336 _____ (Apple Inc.) C:\Users\matt\Downloads\QuickTimeInstaller (2).exe
2015-03-16 21:13 - 2015-03-16 21:15 - 39401336 _____ (Apple Inc.) C:\Users\matt\Downloads\QuickTimeInstaller (1).exe
2015-03-16 21:05 - 2015-03-18 08:43 - 00001857 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk
2015-03-16 21:05 - 2015-03-18 08:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-03-16 21:02 - 2015-03-16 21:04 - 39401336 _____ (Apple Inc.) C:\Users\matt\Downloads\QuickTimeInstaller.exe
2015-03-16 10:15 - 2015-03-16 10:15 - 00001805 _____ () C:\Users\matt\Desktop\CMS.lnk
2015-03-16 10:15 - 2015-03-16 10:15 - 00000000 ____D () C:\Users\matt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CMS
2015-03-14 18:25 - 2015-03-14 18:25 - 00000000 ____D () C:\Users\matt\AppData\Local\bluesoleil voip
2015-03-14 18:24 - 2015-03-29 04:42 - 00000000 _____ () C:\WINDOWS\SysWOW64\SHORTCUT.INI
2015-03-11 04:52 - 2015-03-16 10:15 - 00000000 ____D () C:\Program Files (x86)\CMS
2015-03-10 20:15 - 2015-03-04 16:24 - 00792032 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-03-10 20:15 - 2015-03-04 16:24 - 00178144 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-10 19:56 - 2015-03-09 18:26 - 00025472 _____ () C:\WINDOWS\system32\sh4native.exe
2015-03-10 16:51 - 2015-02-03 18:58 - 00264000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2015-03-10 16:51 - 2015-02-03 18:58 - 00114496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2015-03-10 16:51 - 2015-02-03 18:58 - 00044024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2015-03-10 16:51 - 2015-02-02 18:53 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
2015-03-10 16:51 - 2015-02-02 18:53 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll
2015-03-10 16:51 - 2015-01-26 22:44 - 00933888 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-03-10 16:51 - 2015-01-23 20:51 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
2015-03-10 16:50 - 2015-03-05 21:53 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-03-10 16:50 - 2015-03-05 21:33 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2015-03-10 16:50 - 2015-02-25 18:26 - 04178944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-03-10 16:50 - 2015-02-19 22:03 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-03-10 16:50 - 2015-02-19 21:58 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-03-10 16:50 - 2015-02-19 21:20 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-03-10 16:50 - 2015-02-19 21:15 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-03-10 16:50 - 2015-02-06 18:09 - 00396419 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-03-10 16:50 - 2015-01-23 02:17 - 00723072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2015-03-10 16:50 - 2015-01-23 00:02 - 00560392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2015-03-10 16:49 - 2015-02-05 20:28 - 02257408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-03-10 16:49 - 2015-02-05 20:08 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-03-10 16:49 - 2015-02-05 15:24 - 01113920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-03-10 16:49 - 2015-02-02 19:03 - 03551744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2015-03-10 16:49 - 2015-02-02 19:02 - 04298240 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2015-03-10 16:49 - 2015-01-30 18:42 - 03097600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-03-10 16:49 - 2015-01-30 18:29 - 02484224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-03-10 16:49 - 2015-01-30 18:20 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2015-03-10 16:49 - 2015-01-29 22:01 - 00132608 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthA2DP.sys
2015-03-10 16:49 - 2015-01-29 22:01 - 00097792 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys
2015-03-10 16:49 - 2015-01-29 22:00 - 00167424 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys
2015-03-10 16:49 - 2015-01-29 21:03 - 01488896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42u.dll
2015-03-10 16:49 - 2015-01-29 21:03 - 01464832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42.dll
2015-03-10 16:49 - 2015-01-29 21:02 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2015-03-10 16:49 - 2015-01-29 20:44 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42u.dll
2015-03-10 16:49 - 2015-01-29 20:42 - 01204224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42.dll
2015-03-10 16:49 - 2015-01-29 20:40 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2015-03-10 16:49 - 2015-01-29 20:37 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2015-03-10 16:49 - 2015-01-29 20:29 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atlthunk.dll
2015-03-10 16:49 - 2015-01-29 20:24 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2015-03-10 16:49 - 2015-01-29 20:24 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2015-03-10 16:49 - 2015-01-29 20:16 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2015-03-10 16:49 - 2015-01-29 20:08 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2015-03-10 16:49 - 2015-01-29 20:06 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2015-03-10 16:49 - 2015-01-28 20:58 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\photowiz.dll
2015-03-10 16:49 - 2015-01-28 20:29 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\photowiz.dll
2015-03-10 16:49 - 2015-01-28 20:11 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-10 16:49 - 2015-01-28 20:04 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2015-03-10 16:49 - 2015-01-28 20:04 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2015-03-10 16:49 - 2015-01-28 20:00 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-10 16:49 - 2015-01-28 19:59 - 02773504 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-03-10 16:49 - 2015-01-28 19:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-03-10 16:49 - 2015-01-28 19:50 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2015-03-10 16:49 - 2015-01-28 19:49 - 02459136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-03-10 16:49 - 2015-01-28 10:41 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-03-10 16:49 - 2015-01-28 10:41 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-03-10 16:49 - 2015-01-28 10:41 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-03-10 16:49 - 2015-01-27 21:24 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageContextHandler.dll
2015-03-10 16:49 - 2015-01-27 20:47 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StorageContextHandler.dll
2015-03-10 16:49 - 2015-01-26 23:22 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2015-03-10 16:49 - 2015-01-26 21:11 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2015-03-10 16:48 - 2015-02-20 20:16 - 25021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-03-10 16:48 - 2015-02-20 19:41 - 12827648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-03-10 16:48 - 2015-02-20 19:27 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-03-10 16:48 - 2015-02-20 19:27 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-03-10 16:48 - 2015-02-20 19:25 - 19720192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-03-10 16:48 - 2015-02-20 18:58 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-03-10 16:48 - 2015-02-20 18:32 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-03-10 16:48 - 2015-02-19 21:49 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-03-10 16:48 - 2015-02-19 21:48 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-03-10 16:48 - 2015-02-19 21:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-03-10 16:48 - 2015-02-19 21:35 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-03-10 16:48 - 2015-02-19 21:34 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2015-03-10 16:48 - 2015-02-19 21:32 - 06035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-03-10 16:48 - 2015-02-19 21:09 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-03-10 16:48 - 2015-02-19 21:07 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-03-10 16:48 - 2015-02-19 21:06 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-03-10 16:48 - 2015-02-19 21:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-03-10 16:48 - 2015-02-19 21:03 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-03-10 16:48 - 2015-02-19 20:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-03-10 16:48 - 2015-02-19 20:56 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-03-10 16:48 - 2015-02-19 20:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-03-10 16:48 - 2015-02-19 20:49 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-03-10 16:48 - 2015-02-19 20:49 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-03-10 16:48 - 2015-02-19 20:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-03-10 16:48 - 2015-02-19 20:43 - 14398976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-03-10 16:48 - 2015-02-19 20:30 - 04300288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-03-10 16:48 - 2015-02-19 20:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-03-10 16:48 - 2015-02-19 20:29 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-03-10 16:48 - 2015-02-19 20:28 - 02358784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-03-10 16:48 - 2015-02-19 20:26 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-03-10 16:48 - 2015-02-19 20:24 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-03-10 16:48 - 2015-02-19 20:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-03-10 16:48 - 2015-02-19 20:16 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-03-10 16:48 - 2015-02-19 20:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-03-10 16:48 - 2015-02-19 20:01 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-03-10 16:48 - 2015-02-19 19:57 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-03-10 16:48 - 2015-02-19 19:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-03-10 16:47 - 2015-02-12 12:40 - 22291584 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-03-10 16:47 - 2015-02-12 12:34 - 19731824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-03-10 16:47 - 2015-02-07 18:57 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-03-10 16:47 - 2015-02-07 18:49 - 00791040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2015-03-10 16:47 - 2015-01-29 13:45 - 01763352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-03-10 16:47 - 2015-01-29 13:34 - 01488040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2015-03-10 16:47 - 2015-01-27 20:31 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2015-03-10 16:47 - 2015-01-27 20:11 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2015-03-10 16:47 - 2015-01-27 18:47 - 02501368 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-03-10 16:47 - 2015-01-27 18:41 - 02207488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-03-10 16:47 - 2015-01-21 00:54 - 01384712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2015-03-10 16:47 - 2015-01-21 00:15 - 01123848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2015-03-10 16:47 - 2014-12-11 00:36 - 00046456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContentServer.exe
2015-03-10 00:58 - 2015-03-10 01:00 - 00001684 _____ () C:\WINDOWS\SysWOW64\${LOGFILE}
2015-03-09 19:31 - 2015-03-09 19:31 - 00003750 _____ () C:\WINDOWS\System32\Tasks\Selection Tools Update
2015-03-09 19:31 - 2015-03-09 19:31 - 00000078 _____ () C:\Users\matt\AppData\Roaming\Selection Tools.installation.log
2015-03-09 19:30 - 2015-03-10 20:07 - 00000000 ____D () C:\Users\matt\AppData\Roaming\Store
2015-03-09 19:29 - 2015-03-10 01:00 - 00000000 ____D () C:\Users\matt\AppData\Roaming\Nosibay
2015-03-09 18:42 - 2015-03-09 18:42 - 00001136 _____ () C:\Users\matt\Desktop\Continue Live Installation.lnk
2015-03-09 18:25 - 2015-03-09 18:25 - 03109248 _____ (Enigma Software Group USA, LLC.) C:\Users\matt\Downloads\sh-remover.exe
2015-03-09 18:25 - 2015-03-09 18:25 - 00753184 _____ () C:\Users\matt\Downloads\Adware-Removal-Tool-v3.9.1.exe
2015-03-09 18:25 - 2015-03-09 18:25 - 00000000 ____D () C:\Program Files\Enigma Software Group
2015-03-08 22:23 - 2015-03-29 22:23 - 00001360 _____ () C:\WINDOWS\Tasks\CGVW.job
2015-03-08 22:23 - 2015-03-08 22:23 - 00004378 _____ () C:\WINDOWS\System32\Tasks\CGVW
2015-03-08 22:21 - 2015-03-10 20:22 - 00000000 ____D () C:\ProgramData\ea8dca76000044c1
2015-03-08 21:56 - 2015-03-09 17:34 - 00000004 _____ () C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-03-08 21:47 - 2015-03-22 21:13 - 00000000 ____D () C:\Users\matt\AppData\Local\33444335-1425851238-4830-4A43-D4C9EF606F64
2015-03-08 21:43 - 2015-03-22 21:13 - 00000000 ____D () C:\Users\matt\AppData\Roaming\33444335-1425869022-4830-4A43-D4C9EF606F64
2015-03-08 21:42 - 2015-03-08 21:42 - 00000045 _____ () C:\user.js
2015-03-08 21:42 - 2015-03-08 21:42 - 00000000 ____D () C:\ProgramData\Online
2015-03-08 21:37 - 2015-03-08 21:57 - 00000000 ____D () C:\ProgramData\{273f8052-6ae5-0027-273f-f80526ae0149}
2015-03-08 21:35 - 2015-03-08 21:56 - 00002277 _____ () C:\WINDOWS\patsearch.bin
2015-03-08 21:35 - 2015-03-08 21:35 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf
2015-03-08 21:34 - 2015-03-08 21:58 - 00000000 ____D () C:\ProgramData\{516c2665-974f-f9e4-516c-c26659749996}
2015-03-08 21:29 - 2015-03-09 22:08 - 00000000 ___HD () C:\Users\Public\Temp
2015-03-08 21:28 - 2015-03-08 21:29 - 00004726 _____ () C:\WINDOWS\System32\Tasks\PNLISMX
2015-03-08 21:28 - 2015-03-08 21:28 - 00003566 _____ () C:\WINDOWS\System32\Tasks\KAXQH
2015-03-08 21:27 - 2015-03-29 21:28 - 00001710 _____ () C:\WINDOWS\Tasks\PNLISMX.job
2015-03-08 21:27 - 2015-03-29 21:27 - 00001710 _____ () C:\WINDOWS\Tasks\VQEXDJD.job
2015-03-08 21:27 - 2015-03-08 22:02 - 00008864 _____ () C:\WINDOWS\SysWOW64\GambaliOff.ini
2015-03-08 21:27 - 2015-03-08 22:02 - 00008864 _____ () C:\WINDOWS\system32\GambaliOff.ini
2015-03-08 21:27 - 2015-03-08 21:28 - 00004726 _____ () C:\WINDOWS\System32\Tasks\VQEXDJD
2015-03-08 21:27 - 2015-02-24 18:05 - 00364120 _____ (Gambali OEM Software) C:\WINDOWS\system32\Gambali64.dll
2015-03-08 21:27 - 2015-02-24 18:05 - 00318784 _____ (Gambali OEM Software) C:\WINDOWS\SysWOW64\Gambali.dll
2015-03-08 21:26 - 2015-03-10 20:07 - 00000000 ____D () C:\ProgramData\6ef8a1b652f14522bd519ac00ef26c65
2015-03-08 21:26 - 2015-03-08 21:26 - 00000000 ____D () C:\ProgramData\0f68fcbfe11b434c93129d076ddcacb8
2015-03-03 16:55 - 2015-03-18 08:43 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2015-03-03 15:52 - 2015-03-03 15:53 - 00000000 ____D () C:\Users\matt\Documents\xmeye
2015-03-03 15:49 - 2015-03-16 10:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetSurveillance
2015-03-03 15:49 - 2015-03-03 15:49 - 00000000 ____D () C:\Users\matt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NetSurveillance
2015-03-03 15:49 - 2015-03-03 15:49 - 00000000 ____D () C:\Program Files (x86)\NetSurveillance
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-03-29 23:02 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-03-29 22:47 - 2014-11-30 12:29 - 01988583 _____ () C:\WINDOWS\WindowsUpdate.log
2015-03-29 22:47 - 2013-08-22 09:46 - 00458760 _____ () C:\WINDOWS\setupact.log
2015-03-29 22:23 - 2014-12-24 19:08 - 00000934 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-145684943-4197250818-2869285112-1001UA.job
2015-03-29 18:43 - 2014-12-25 15:41 - 00000000 ____D () C:\Program Files (x86)\Popcorn Time
2015-03-29 17:23 - 2014-12-24 19:08 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-145684943-4197250818-2869285112-1001Core.job
2015-03-29 17:12 - 2014-11-30 12:57 - 00000000 ___DO () C:\Users\matt\OneDrive
2015-03-29 17:12 - 2014-11-29 18:48 - 00000932 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-29 17:12 - 2012-12-06 17:21 - 00004524 _____ () C:\WINDOWS\SysWOW64\LOCALSERVICE.INI
2015-03-29 17:12 - 2012-08-10 20:45 - 00000821 _____ () C:\WINDOWS\SysWOW64\bscs.ini
2015-03-29 11:19 - 2014-12-22 23:32 - 00000052 _____ () C:\WINDOWS\SysWOW64\DOErrors.log
2015-03-29 11:19 - 2012-09-17 19:01 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2015-03-29 11:19 - 2012-08-03 19:02 - 00000000 ____D () C:\SWSetup
2015-03-29 10:50 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-03-29 10:02 - 2015-01-05 21:31 - 00003170 _____ () C:\WINDOWS\System32\Tasks\HPCeeScheduleFormatt
2015-03-29 10:02 - 2015-01-05 21:31 - 00000358 _____ () C:\WINDOWS\Tasks\HPCeeScheduleFormatt.job
2015-03-29 04:43 - 2014-12-08 19:43 - 00000298 _____ () C:\WINDOWS\SysWOW64\REMOTEDEVICE.INI
2015-03-29 01:18 - 2014-11-29 17:28 - 00003946 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{36CB7958-80C1-4550-8E4A-DD4BE255CA6F}
2015-03-28 22:43 - 2014-03-28 17:08 - 00000000 __SHD () C:\Users\matt\wc
2015-03-28 18:02 - 2014-11-29 17:36 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-145684943-4197250818-2869285112-1001
2015-03-28 17:23 - 2012-12-06 17:21 - 00000088 _____ () C:\WINDOWS\SysWOW64\LOCALDEVICE.INI
2015-03-26 23:11 - 2014-11-30 12:08 - 00000000 ____D () C:\Users\matt
2015-03-26 16:10 - 2014-09-24 02:15 - 00956476 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-26 15:42 - 2013-08-22 09:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-03-26 15:41 - 2014-09-24 02:03 - 01726678 _____ () C:\WINDOWS\PFRO.log
2015-03-23 21:48 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2015-03-22 01:18 - 2014-11-29 18:48 - 00000000 ____D () C:\Program Files (x86)\Google
2015-03-21 13:28 - 2014-11-29 17:26 - 00000000 ____D () C:\Users\matt\AppData\Local\Packages
2015-03-21 01:36 - 2014-12-27 03:24 - 00000000 ____D () C:\Users\matt\AppData\Local\CrashDumps
2015-03-20 20:39 - 2012-07-26 03:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
2015-03-20 01:35 - 2012-12-06 17:43 - 00000000 ____D () C:\ProgramData\Norton
2015-03-20 01:34 - 2013-08-22 08:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-03-20 01:05 - 2014-08-06 17:46 - 00001315 _____ () C:\Users\matt\Desktop\Norton Installation Files.lnk
2015-03-20 01:05 - 2014-04-23 17:13 - 00077824 ___SH () C:\Users\matt\Desktop\Thumbs.db
2015-03-19 21:40 - 2015-01-28 19:11 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2015-03-18 03:15 - 2014-12-22 21:02 - 00000000 ____D () C:\Users\matt\AppData\Local\Apple Computer
2015-03-13 19:12 - 2014-11-29 22:16 - 00000000 ____D () C:\Users\matt\AppData\Roaming\uTorrent
2015-03-12 02:49 - 2015-01-02 00:35 - 00003302 _____ () C:\WINDOWS\System32\Tasks\{F274882A-00B4-4C49-B385-8D6C6841A899}
2015-03-11 05:19 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-03-10 20:14 - 2013-08-22 09:44 - 00346800 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-03-10 20:12 - 2013-08-22 08:25 - 01310720 ___SH () C:\WINDOWS\system32\config\BBI
2015-03-10 20:09 - 2013-08-22 10:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2015-03-10 20:09 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-10 20:09 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-10 20:09 - 2013-08-22 10:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-10 20:09 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\WinStore
2015-03-10 20:09 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Defender
2015-03-10 20:09 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-03-10 17:52 - 2012-07-26 02:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-03-10 17:41 - 2014-11-29 20:29 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-03-10 17:17 - 2014-11-29 20:29 - 122905848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-03-09 17:41 - 2015-01-13 00:40 - 00000000 ____D () C:\ProgramData\Origin
2015-03-08 22:15 - 2013-08-22 08:25 - 00000194 _____ () C:\WINDOWS\win.ini
2015-03-08 21:32 - 2015-02-23 23:24 - 00000000 _____ () C:\end
2015-03-08 04:24 - 2015-02-08 05:51 - 00000000 ____D () C:\Users\matt\AppData\Roaming\BitTorrent
2015-03-02 20:45 - 2014-12-12 04:14 - 00006656 _____ () C:\Users\matt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
==================== Files in the root of some directories =======
 
2015-03-11 04:52 - 2015-03-16 10:15 - 0086116 _____ () C:\Program Files (x86)\CMS Setup Log.txt
2015-03-12 15:19 - 2015-03-12 15:19 - 0018408 _____ () C:\Program Files (x86)\CMS Uninstall Log.txt
2015-01-25 11:12 - 2015-01-25 11:12 - 0001248 _____ () C:\Users\matt\AppData\Roaming\CGVW
2015-01-25 11:12 - 2015-01-25 11:12 - 0001248 _____ () C:\Users\matt\AppData\Roaming\PNLISMX
2015-03-09 19:31 - 2015-03-09 19:31 - 0000078 _____ () C:\Users\matt\AppData\Roaming\Selection Tools.installation.log
2015-01-25 11:12 - 2015-01-25 11:12 - 0001248 _____ () C:\Users\matt\AppData\Roaming\VQEXDJD
2014-12-12 04:14 - 2015-03-02 20:45 - 0006656 _____ () C:\Users\matt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
Some content of TEMP:
====================
C:\Users\matt\AppData\Local\Temp\EsgInstallerx64Stub.exe
C:\Users\matt\AppData\Local\Temp\Extract.exe
C:\Users\matt\AppData\Local\Temp\SP59927.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-03-28 18:02
 
==================== End Of Log ============================
Hi and welcome

[external image: goGMWSt.gif]P2P Warning

——————————
I see you have peer-to-peer (P2P) file sharing software installed on your computer (uTorrent). I advise you avoid P2P file sharing programmes; they are a security risk which can make your computer susceptible to malware. File sharing networks are thoroughly infected and infested with malware - worms, backdoor Trojans, IRCBots, and rootkits propagate via P2P file sharing networks, gaming, and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans, and spyware. The best way to reduce the risk of infection is to avoid these types of web sites and not use P2P applications. Please read the following articles for more information.
  • Risks of File-Sharing Technology
  • P2P Software User Advisories
  • More malware is traveling on P2P networks these days
Your P2P software can be removed by following the instructions below.
  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for the aforementioned programme(s), right-click and click Uninstall.
If you choose not to, please refrain from using the programme(s) during this process.

~~~~~~~~~~~~~~`
NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.
~~~~~~~~~~~~~~~~~`

Please go to one of the below sites to scan the following files:
Virus Total (Recommended)
jotti.org
VirScan
click on Browse, and upload the following file for analysis:


~~~~~~~~~~~~~~~~~~~~

C:\Program Files (x86)\NetSurveillance\CMS\npWebPlugin.dll


Then click Submit. Allow the file to be scanned, and then please copy and paste the results link (for Virus Total) here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.


Running from C:\Users\[removed]\Downloads

It's best we move Farbar's to desktop.

Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
CustomCLSID: HKU\S-1-5-21-145684943-4197250818-2869285112-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\matt\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-145684943-4197250818-2869285112-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\matt\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
Task: {3E3AE978-E740-409E-B4F8-8AE8C8A8D12B} - System32\Tasks\VQEXDJD => C:\Users\matt\AppData\Roaming\VQEXDJD.exe <==== ATTENTION
C:\Users\matt\AppData\Roaming\VQEXDJD.exe
Task: {4F6A34DD-10AF-4465-9579-763FB5E9A274} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {52D0F590-D689-46FB-9849-BB0675CB0CC3} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {786CC5D3-69EF-4672-8058-8F6640865A02} - \ProPCCleaner_Popup No Task File <==== ATTENTION
Task: {79BF678E-3849-4F3B-819A-F834B03A0F71} - System32\Tasks\CGVW => C:\Users\matt\AppData\Roaming\CGVW.exe <==== ATTENTION
C:\Users\matt\AppData\Roaming\CGVW.exe
Task: {DFFB4D95-5ACD-4B19-9558-9679C010E04C} - \ProPCCleaner_Start No Task File <==== ATTENTION
Task: {F77EFE43-D624-47AE-A105-59B2FEA444D7} - \WindApp Update No Task File <==== ATTENTION
Task: {FAC9A473-2A07-4D2B-B420-115414ADFFAE} - System32\Tasks\PNLISMX => C:\Users\matt\AppData\Roaming\PNLISMX.exe <==== ATTENTION
C:\Users\matt\AppData\Roaming\PNLISMX.exe
Task: C:\WINDOWS\Tasks\CGVW.job => C:\Users\matt\AppData\Roaming\CGVW.exe <==== ATTENTION
C:\Users\matt\AppData\Roaming\CGVW.exe
Task: C:\WINDOWS\Tasks\PNLISMX.job => C:\Users\matt\AppData\Roaming\PNLISMX.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\VQEXDJD.job => C:\Users\matt\AppData\Roaming\VQEXDJD.exe <==== ATTENTION
C:\Users\matt\AppData\Roaming\VQEXDJD.exe
AlternateDataStreams: C:\Users\matt\OneDrive:ms-properties
AlternateDataStreams: C:\Users\matt\OneDrive.old:ms-properties
AlternateDataStreams: C:\Users\matt\SkyDrive:ms-properties
C:\Users\matt\AppData\Local\Temp\nsdD7B5.tmp
C:\Users\matt\AppData\Local\Temp\nsfDD81.tmp
HKU\S-1-5-21-145684943-4197250818-2869285112-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://tikotin.com
SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co…&l=dis&o=HPNTDF
SearchScopes: HKLM -> {8621D76B-511F-4041-8473-223542C58346} URL = http://www.amazon.co…s={searchTerms}
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo….psg&type=HPNTDF
SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co…&l=dis&o=HPNTDF
SearchScopes: HKLM-x32 -> {8621D76B-511F-4041-8473-223542C58346} URL = http://www.amazon.co…s={searchTerms}
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo….psg&type=HPNTDF
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co…54371-11896-2/4?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-145684943-4197250818-2869285112-1001 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co…&l=dis&o=HPNTDF
SearchScopes: HKU\S-1-5-21-145684943-4197250818-2869285112-1001 -> {8621D76B-511F-4041-8473-223542C58346} URL = http://www.amazon.co…s={searchTerms}
SearchScopes: HKU\S-1-5-21-145684943-4197250818-2869285112-1001 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo….psg&type=HPNTDF
SearchScopes: HKU\S-1-5-21-145684943-4197250818-2869285112-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co…54371-11896-2/4?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
CHR HKLM-x32\…\Chrome\Extension: [ihenkjeihefokohmemphikjnjbmegdik] - "C:\Program Files (x86)\Sony\Media Go\MediaGoDetector.crx" [Not Found]
S1 cherimoya; system32\drivers\cherimoya.sys [X]
2015-03-08 22:23 - 2015-03-29 22:23 - 00001360 _____ () C:\WINDOWS\Tasks\CGVW.job
2015-03-08 22:23 - 2015-03-08 22:23 - 00004378 _____ () C:\WINDOWS\System32\Tasks\CGVW
2015-03-08 21:28 - 2015-03-08 21:29 - 00004726 _____ () C:\WINDOWS\System32\Tasks\PNLISMX
2015-03-08 21:28 - 2015-03-08 21:28 - 00003566 _____ () C:\WINDOWS\System32\Tasks\KAXQH
2015-03-08 21:27 - 2015-03-29 21:28 - 00001710 _____ () C:\WINDOWS\Tasks\PNLISMX.job
2015-03-08 21:27 - 2015-03-29 21:27 - 00001710 _____ () C:\WINDOWS\Tasks\VQEXDJD.job
2015-03-08 21:27 - 2015-03-08 21:28 - 00004726 _____ () C:\WINDOWS\System32\Tasks\VQEXDJD
C:\Users\matt\AppData\Local\Temp\EsgInstallerx64Stub.exe
C:\Users\matt\AppData\Local\Temp\Extract.exe
C:\Users\matt\AppData\Local\Temp\SP59927.exe
EmptyTemp:
Hosts:
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~~~~

Please download Malwarebytes Anti-Malware and save it to your desktop.
  • Double-click on the setup file (mbam-setup.exe), then click on Run to install.
  • Malwarebytes will automatically open to it's Dashboard. If you have never run this version, you should see a red note at the top indicating "A scan has never been run on your system"
  • Click on Update Now to download the current database definitions, then click the Scan Now >> button.
  • If you have run this version before, you should see a green note at the top indicating "Your system is fully protected".
  • You will be prompted to update Malwarebytes…click on the Update Now button.
  • The THREAT SCAN will automatically begin.
  • When the scan has completed, the results will be displayed. Click on Quarantine All, then click on Apply Actions.
  • To complete any actions taken you will be prompted to restart your computer…click on Yes. Failure to reboot normally will prevent Malwarebytes from removing all the malware.
  • After rebooting the computer, copy and paste the mbam.log in your next reply.
  • To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 1)
    • Open Malwarebytes Anti-Malware.
    • Click the History Tab at the top and select Application Logs.
    • Select (check) the box next to Scan Log. Choose the most current scan.
    • Click the View button.
    • Click Copy to Clipboard at the bottom…come back to this thread, click Add Reply, then right-click and choose Paste.
    • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
    • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
    To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 2)
    • Open Malwarebytes Anti-Malware.
    • Click the Scan Tab at the top.
    • Click the View detailed log link on the right.
    • Click Copy to Clipboard at the bottom…come back to this thread, click Add Reply, then right-click and choose Paste.
    • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
    • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
    Logs are named by the date of scan in the following format: mbam-log-yyyy-mm-dd and automatically saved to the following locations:
    – XP: C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
    – Vista, Windows 7/8: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd

    Please post
    file requested scanned
    Fixlog.txt
    Malwarebytes Anti-Malware

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI