This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Redirect virus [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I've got a pretty nasty redirect virus/malware that is redirecting all links in a browser to a gamesjobstarblack.in address and then onto a random sales site. The redirect is effecting especially Firefox . I ran FRST  and got the following:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015

Ran by [removed] (administrator) on SHIRLEYPC on 07-04-2015 16:35:14
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 Pro (X64) OS Language: Englisch (Vereinigte Staaten)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Program Files\Serviio\bin\ServiioService.exe
() C:\Program Files\Serviio\bin\ServiioService.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\vmms.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OFFICE15\CSISYNCCLIENT.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files\Andy\AndyPriorityMgr.exe
() C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
() C:\Program Files\Serviio\bin\ServiioConsole.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe
() C:\Program Files\Andy\HandyAndy.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Users\Shirley\AppData\Local\Google\Update\GoogleUpdate.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems, Incorporated) C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(AVAST Software) C:\Users\Shirley\Desktop\aswMBR.exe
(AVAST Software) C:\Users\Shirley\Desktop\aswMBR.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12937872 2012-07-27] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-07-10] (Realtek Semiconductor)
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2404296 2014-08-09] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.)
HKLM-x32\…\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-25] (Dolby Laboratories Inc.)
HKLM-x32\…\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-02-13] (Apple Inc.)
HKLM-x32\…\Run: [ASUS Ai Charger] => C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe [547984 2012-08-13] (ASUSTek Computer Inc.)
HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.)
HKLM-x32\…\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [PowerDVD13Agent] => C:\Program Files (x86)\CyberLink\PowerDVD13\PowerDVD13Agent.exe [513048 2013-03-20] (CyberLink Corp.)
HKLM-x32\…\Run: [A1Diagnose] => C:\Program Files (x86)\A1 Servicecenter\A1 Diagnose\A1Diagnose.exe [31581288 2014-05-19] (mquadr.at software engineering and consulting GmbH, web: www.mquadr.at, mail: [removed])
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKLM-x32\…\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020704 2014-08-05] (Wondershare)
HKLM-x32\…\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [1953792 2014-05-16] ()
HKLM-x32\…\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694040 2014-07-22] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\…\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe [901632 2015-01-08] ()
HKLM-x32\…\Run: [YouCam Service6] => C:\Program Files (x86)\CyberLink\YouCam6\YouCamService6.exe [504792 2014-03-28] (CyberLink Corp.)
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [MouseServer] => C:\Program Files (x86)\MouseServer\MouseServer.exe [244736 2013-08-26] (wifimouse.necta.us)
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [Google Update] => C:\Users\Shirley\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-02-01] (Google Inc.)
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [MusicManager] => C:\Users\Shirley\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7631360 2014-10-09] (Google Inc.)
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [ZedgeToneSync] => C:\Users\Shirley\AppData\Local\Apps\2.0\Data\QGRK6JHZ.6N6\T515ADT6.JJA\zedg..tion_4cd56dcfd1799009_0001.0002_ea3f01849f5e16c3\Data\ZedgeToneSync.appref-ms -startup
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [Google+ Auto Backup] => C:\Users\Shirley\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [3746120 2014-08-13] (Google Inc.)
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [Xvid] => C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] ()
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [BaiduYunGuanjia] => C:\Users\Shirley\AppData\Roaming\baidu\BaiduYunGuanjia\BaiduYunGuanjia.exe [4781000 2014-10-21] ()
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-10-20] (Apple Inc.)
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [*LABAL*] => [X]
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [VoipConnect] => C:\Program Files (x86)\VoipConnect.com\VoipConnect\VoipConnect.exe [23048288 2014-12-04] (VoipConnect)
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [Viber] => C:\Users\Shirley\AppData\Local\Viber\Viber.exe [776400 2015-02-03] ()
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {00dcc750-5388-11e4-bef4-e006e6c08ca1} - "G:\bootstrap.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {00dccdf4-5388-11e4-bef4-e006e6c08ca1} - "F:\bootstrap.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {2118b7dd-3b51-11e3-8251-e006e6c08ca1} - "E:\bootstrap.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {2118b805-3b51-11e3-8251-e006e6c08ca1} - "E:\bootstrap.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {2118be2f-3b51-11e3-8251-e006e6c08ca1} - "F:\bootstrap.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {3907c584-b1c1-11e3-bed1-005056c00008} - "E:\bootstrap.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {3dc5103d-3dd5-11e3-be8c-e006e6c08ca1} - "E:\bootstrap.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {a1239a1c-5a07-11e4-bef5-e006e6c08ca1} - "F:\bootstrap.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {d1326214-6622-11e3-bea0-e006e6c08ca1} - "E:\bootstrap.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {d1326224-6622-11e3-bea0-e006e6c08ca1} - "G:\bootstrap.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {d5bf0215-bf99-11e4-bf3f-e006e6c08ca1} - "H:\HTC_Sync_Manager_PC.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {ebb79901-722d-11e3-beb0-e006e6c08ca1} - "E:\bootstrap.exe" 
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {ebb79916-722d-11e3-beb0-e006e6c08ca1} - "E:\bootstrap.exe" 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TrayMenu.lnk
ShortcutTarget: TrayMenu.lnk -> C:\Windows\SysWOW64\C2MP\TrayMenu.exe ()
Startup: C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HandyAndy.lnk
ShortcutTarget: HandyAndy.lnk -> C:\Program Files\Andy\HandyAndy.exe ()
Startup: C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk
ShortcutTarget: PdaNet Desktop.lnk -> C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
Startup: C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Serviio.lnk
ShortcutTarget: Serviio.lnk -> C:\Program Files\Serviio\bin\ServiioConsole.exe ()
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/de-at/?ocid=iehp
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKU\S-1-5-21-4216991579-408556834-1651255799-1002\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
SearchScopes: HKLM -> DefaultScope {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-4216991579-408556834-1651255799-1002 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\OFFICE15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\OFFICE15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-4216991579-408556834-1651255799-1002 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Toolbar: HKU\S-1-5-21-4216991579-408556834-1651255799-1002 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-10-15] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 -  No File
Winsock: Catalog5 09 C:\Windows\SysWOW64\wlidNSP.dll [50176] (Microsoft Corporation)
Winsock: Catalog5 10 C:\Windows\SysWOW64\wlidNSP.dll [50176] (Microsoft Corporation)
Winsock: Catalog5-x64 09 C:\WINDOWS\system32\wlidnsp.dll [74240] (Microsoft Corporation)
Winsock: Catalog5-x64 10 C:\WINDOWS\system32\wlidnsp.dll [74240] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{CE9D39B2-C943-4BC2-BF18-E2DB62FC7F84}: [NameServer] 10.0.0.138,8.8.8.8
 
FireFox:
========
FF ProfilePath: C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734
FF SelectedSearchEngine: Trovi search
FF Homepage: hxxp://www.A1.net
FF NetworkProxy: "gopher", ""
FF NetworkProxy: "gopher_port", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-17] ()
FF Plugin: @java.com/DTPlugin,version=10.60.2 -> C:\WINDOWS\system32\npdeployJava1.dll [2014-06-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-06-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-06-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2014-07-22] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-17] ()
FF Plugin-x32: @alibaba.com/nptrademanager;version=1.0 -> C:\Program Files (x86)\TradeManager\nptrademanager.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @baidu.com/YunWebDetectPlugin -> C:\Users\Shirley\AppData\Roaming\baidu\BaiduYunGuanjia\npYunWebDetect.dll [2014-10-21] (Baidu.com, Inc.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-08-13] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-06-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-06-04] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-05-21] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2013-08-20] (Nero AG)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-08-29] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-08-29] (NVIDIA Corporation)
FF Plugin-x32: @qq.com/npchrome -> C:\Program Files (x86)\Common Files\Tencent\Npchrome\npchrome.dll [2014-11-20] (Tencent)
FF Plugin-x32: @qq.com/npqscall -> C:\Program Files (x86)\Common Files\Tencent\NPQSCALL\npqscall.dll [2014-11-20] (Tencent)
FF Plugin-x32: @qq.com/TXSSO -> C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.2.1\Bin\npSSOAxCtrlForPTLogin.dll [2013-04-08] (Tencent)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-11-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-11-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2014-07-22] (Adobe Systems)
FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: @alibaba.com/npAliSSOLogin;version=1.0 -> C:\Program Files (x86)\Trademanager\npAliSSOLogin.dll No File
FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: @alibaba.com/nptrademanager;version=1.0 -> "C:\Program Files (x86)\Trademanager\nptrademanager.dll" No File
FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: @alibaba.com/npwangwang;version=1.0 -> "C:\Program Files (x86)\Trademanager\npwangwang.dll" No File
FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: @tools.google.com/Google Update;version=3 -> C:\Users\Shirley\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-11-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: @tools.google.com/Google Update;version=9 -> C:\Users\Shirley\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-11-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: {@alibaba.com/alisetup;version=1.0} -> C:\Users\Shirley\AppData\Local\Alibaba\AliSetup\0.1.0.52\npAliSetupOneClick.dll [2011-02-22] (alibaba)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2014-05-21] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-10-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-10-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-10-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-10-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-10-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nptrademanager.dll [2014-11-11] ( )
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwangwang.dll [2011-07-29] ( )
FF Extension: German Dictionary - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed] [2015-01-04]
FF Extension: United States English Spellchecker - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed] [2015-01-04]
FF Extension: YoutubeAdBlocke - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed] [2015-01-04]
FF Extension: MEGA - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed] [2015-02-11]
FF Extension: YouTube ALL HTML5 - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed] [2015-01-04]
FF Extension: Saved Password Editor - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed] [2015-01-04]
FF Extension: YouTube High Definition - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2015-01-04]
FF Extension: Facebook Photo Zoom - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\{7c6cdf7c-8ea8-4be7-ae5a-0b3effe14d66}.xpi [2015-01-04]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2015-01-04]
FF Extension: Video DownloadHelper - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-03-14]
FF Extension: Adblock Plus - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-04]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\Wondershare\Video Converter Ultimate\[removed]
FF Extension: Wondershare Video Converter Ultimate - C:\ProgramData\Wondershare\Video Converter Ultimate\[removed] [2014-08-06]
 
Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Koji NISHIDA) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\acganlmcjehnfmehkmlimgkaloifodlf [2013-06-11]
CHR Extension: (Angry Birds) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2013-07-07]
CHR Extension: (Google Docs) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-11]
CHR Extension: (Google Drive) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-06-11]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-25]
CHR Extension: (Audiotool) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk [2013-06-11]
CHR Extension: (YouTube) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-11]
CHR Extension: (Adblock Plus) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-06-11]
CHR Extension: (Google Search) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-11]
CHR Extension: (Christmas Solitiare) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhcbjomfajlnldboplncbdhmdaagcpln [2013-07-07]
CHR Extension: (MightyText - SMS Text Messaging ⟷ Computer) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkfhfaphfkopdgpbfkebjfcblcafcmpi [2013-07-07]
CHR Extension: (Google Calendar) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2013-07-07]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2013-07-07]
CHR Extension: (Google Keep - notes and lists) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2013-11-04]
CHR Extension: (Google Voice (by Google)) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo [2013-06-11]
CHR Extension: (Drive) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfakdllpdfjjbfommlcnfkedmbigkfdo [2013-07-07]
CHR Extension: (Google Wallet) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
CHR Extension: (Gmail) - C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-11]
CHR HKLM-x32\…\Chrome\Extension: [iijmpjamifmplbakhgikofogdfackici] - C:\ProgramData\Wondershare\Video Converter Ultimate\[removed] [2014-08-06]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 417dd0a6; c:\Program Files (x86)\CutterFunc\CutterFunc.dll [2254848 2015-01-12] () [File not signed]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S3 BaiduYunUtility; C:\Users\Shirley\AppData\Roaming\baidu\BaiduYunGuanjia\YunUtilityService.exe [85224 2014-10-21] () [File not signed]
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 CyberLink PowerDVD 13 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe [77576 2013-03-20] (CyberLink)
R2 CyberLink PowerDVD 13 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe [323336 2013-03-20] (CyberLink)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1721800 2014-08-09] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18974152 2014-08-09] (NVIDIA Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R2 Serviio; C:\Program Files\Serviio\bin\ServiioService.exe [327680 2015-02-09] () [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [44856 2015-02-25] (AVG Technologies)
R2 UxTuneUp; C:\Windows\SysWOW64\uxtuneup.dll [36664 2015-02-25] (AVG Technologies)
R2 vmms; C:\Windows\system32\vmms.exe [13784576 2014-10-08] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 AiCharger; C:\Windows\SysWow64\drivers\AiCharger.sys [14848 2012-03-22] (ASUSTek Computer Inc.)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 clwvd6; C:\Windows\system32\DRIVERS\clwvd6.sys [41704 2013-10-29] (CyberLink Corporation)
S3 HtcVCom32; C:\Windows\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated)
R1 hvservice; C:\Windows\System32\drivers\hvservice.sys [68960 2015-01-24] (Microsoft Corporation)
R3 isocusb; C:\Windows\system32\drivers\isocusb.sys [261120 2012-12-06] (Intel Corp.)
S3 lunparser; C:\Windows\System32\drivers\lunparser.sys [19456 2015-01-24] (Microsoft Corporation)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [21448 2014-08-09] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 passthruparser; C:\Windows\System32\drivers\passthruparser.sys [22016 2015-01-24] (Microsoft Corporation)
S3 pvhdparser; C:\Windows\System32\drivers\pvhdparser.sys [27136 2015-01-24] (Microsoft Corporation)
S3 pwdrvio; C:\WINDOWS\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] ()
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [266896 2012-06-13] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1936088 2013-07-31] (Realtek Semiconductor Corporation                           )
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [115208 2014-11-21] (Oracle Corporation)
S3 vhdparser; C:\Windows\System32\drivers\vhdparser.sys [18944 2015-01-24] (Microsoft Corporation)
R3 VMC412; C:\Windows\System32\Drivers\VMC412.sys [232576 2012-08-22] (Vimicro Corporation)
R3 VMSMP; C:\Windows\system32\DRIVERS\vmswitch.sys [688640 2014-10-08] (Microsoft Corporation)
S3 VMSP; C:\Windows\system32\DRIVERS\vmswitch.sys [688640 2014-10-08] (Microsoft Corporation)
S3 VMSVSF; C:\Windows\system32\DRIVERS\vmswitch.sys [688640 2014-10-08] (Microsoft Corporation)
S3 VMSVSP; C:\Windows\system32\DRIVERS\vmswitch.sys [688640 2014-10-08] (Microsoft Corporation)
R3 vmuacflt; C:\Windows\System32\Drivers\vmuacflt.sys [13696 2012-05-02] (Vimicro Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
R2 {09F57980-3432-4AFC-957D-27AC45FAE1F5}; C:\Program Files (x86)\CyberLink\PowerDVD13\Common\NavFilter\000.fcl [130320 2013-03-19] (CyberLink Corp.)
U3 aswMBR; \??\C:\Users\Shirley\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Shirley\AppData\Local\Temp\aswVmm.sys [X]
S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X]
S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-07 16:35 - 2015-04-07 16:36 - 00037390 _____ () C:\Users\Shirley\Desktop\FRST.txt
2015-04-07 16:25 - 2015-04-07 16:26 - 05198336 _____ (AVAST Software) C:\Users\Shirley\Desktop\aswMBR.exe
2015-04-07 16:24 - 2015-04-07 16:25 - 09331982 _____ () C:\Users\Shirley\Downloads\qui veut gagner…psd
2015-04-05 10:26 - 2015-04-05 10:26 - 00869376 _____ () C:\Users\Shirley\Downloads\free-dvd-protection-removal-win.exe
2015-04-04 10:36 - 2015-04-04 10:38 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-04 10:36 - 2015-04-04 10:36 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-04-02 18:57 - 2015-04-02 19:25 - 00000000 ____D () C:\Users\Shirley\Desktop\Jude
2015-04-02 02:17 - 2015-04-02 02:17 - 00163840 _____ () C:\Users\Shirley\Desktop\Beamoff Tool.iso
2015-04-01 20:24 - 2015-04-01 22:44 - 1159342080 _____ () C:\Users\Shirley\Downloads\OSX-Mavericks.iso
2015-04-01 13:00 - 2015-04-01 13:00 - 00000000 ____D () C:\Users\Shirley\Desktop\Mac OS X Yosemite Niresh Intel and AMD Images
2015-04-01 05:02 - 2015-04-01 05:02 - 00050912 _____ () C:\Users\Shirley\Downloads\Addition.txt
2015-04-01 04:58 - 2015-04-07 16:35 - 00000000 ____D () C:\FRST
2015-04-01 04:58 - 2015-04-01 05:02 - 00543277 _____ () C:\Users\Shirley\Downloads\FRST.txt
2015-04-01 04:58 - 2015-04-01 04:58 - 02095616 _____ (Farbar) C:\Users\Shirley\Desktop\FRST64.exe
2015-03-26 17:27 - 2015-03-26 17:27 - 00001776 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-03-26 17:27 - 2015-03-26 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-03-26 17:26 - 2015-03-26 17:27 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-03-26 17:26 - 2015-03-26 17:27 - 00000000 ____D () C:\Program Files\iTunes
2015-03-26 17:26 - 2015-03-26 17:26 - 00000000 ____D () C:\Program Files\iPod
2015-03-26 17:26 - 2015-03-26 17:26 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-03-25 07:55 - 2015-03-11 04:38 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-03-25 07:55 - 2015-03-11 00:08 - 01107456 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-03-25 07:55 - 2015-03-11 00:08 - 00943104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-03-25 07:55 - 2015-03-11 00:08 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-03-25 07:55 - 2015-03-11 00:08 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-03-25 07:55 - 2015-03-11 00:08 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-03-25 07:55 - 2015-03-11 00:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-03-24 08:25 - 2015-03-24 08:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2015-03-23 07:27 - 2015-03-23 07:29 - 77317912 _____ (Samsung Electronics Co., Ltd.) C:\Users\Shirley\Downloads\KiesSetup.exe
2015-03-23 07:27 - 2015-03-23 07:29 - 42543488 _____ (Samsung Electronics Co., Ltd.) C:\Users\Shirley\Downloads\Kies3Setup.exe
2015-03-22 09:34 - 2015-03-22 09:34 - 00003402 _____ () C:\Windows\System32\Tasks\{62D1C3FB-E98E-4B6C-AB02-1A03E4150C4C}
2015-03-22 06:57 - 2015-03-22 07:06 - 168295156 _____ () C:\Users\Shirley\Downloads\Slim-p5100-5.0.2.alpha.1.0-UNOFFICIAL-20150224-1826.zip
2015-03-21 10:30 - 2015-03-21 10:30 - 18880558 _____ () C:\Users\Shirley\Downloads\7ad45ac2.apk
2015-03-21 10:01 - 2015-03-21 10:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2015-03-21 10:01 - 2015-03-16 18:36 - 00922704 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2015-03-21 10:01 - 2015-03-16 18:35 - 00128592 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2015-03-21 09:46 - 2015-03-21 09:48 - 111145672 _____ (Oracle Corporation) C:\Users\Shirley\Downloads\VirtualBox-4.3.26-98988-Win.exe
2015-03-19 18:09 - 2015-03-19 18:10 - 02803156 _____ () C:\Users\Shirley\Downloads\com.mobileuncle.toolbox.downloader.apk
2015-03-18 13:22 - 2015-03-18 13:22 - 00018072 _____ () C:\Users\Shirley\Downloads\Ravenna.ttf
2015-03-16 18:35 - 2015-03-16 18:35 - 00204264 _____ (Oracle Corporation) C:\Windows\system32\VBoxNetFltNobj.dll
2015-03-16 18:35 - 2015-03-16 18:35 - 00156360 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetFlt.sys
2015-03-16 18:35 - 2015-03-16 18:35 - 00141440 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetAdp.sys
2015-03-12 20:05 - 2015-03-12 20:05 - 00000000 ____D () C:\Users\Shirley\Downloads\Element3D_V2
2015-03-12 19:34 - 2015-03-12 19:34 - 00000000 ____D () C:\Users\Shirley\Downloads\VIDEO COPILOT ELEMENT 3D V2 2.0.4 +spider (Cracked)
2015-03-12 19:29 - 2015-03-12 19:29 - 00000000 ____D () C:\Users\Shirley\AppData\Local\Image Composite Editor
2015-03-12 19:29 - 2015-03-12 19:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Composite Editor
2015-03-12 19:29 - 2015-03-12 19:29 - 00000000 ____D () C:\Program Files\Microsoft Research
2015-03-12 19:25 - 2015-03-12 19:26 - 11344040 _____ (Microsoft Corporation) C:\Users\Shirley\Downloads\PhotosynthInstall.exe
2015-03-12 19:25 - 2015-03-12 19:26 - 07963136 _____ () C:\Users\Shirley\Downloads\ICE-2.0.3-for-64-bit-Windows.msi
2015-03-11 08:33 - 2015-03-06 04:53 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 08:33 - 2015-03-06 04:33 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-03-11 08:33 - 2015-02-26 01:26 - 04178944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 08:33 - 2015-02-07 01:09 - 00396419 _____ () C:\Windows\system32\ApnDatabase.xml
2015-03-11 08:33 - 2015-02-04 01:58 - 00264000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2015-03-11 08:33 - 2015-02-04 01:58 - 00114496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys
2015-03-11 08:33 - 2015-02-04 01:58 - 00044024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2015-03-11 08:33 - 2015-02-03 01:53 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\winshfhc.dll
2015-03-11 08:33 - 2015-02-03 01:53 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winshfhc.dll
2015-03-11 08:33 - 2015-01-29 03:58 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll
2015-03-11 08:33 - 2015-01-29 03:29 - 00290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\photowiz.dll
2015-03-11 08:33 - 2015-01-27 05:44 - 00933888 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe
2015-03-11 08:33 - 2015-01-24 03:51 - 00816128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe
2015-03-11 08:33 - 2015-01-23 09:17 - 00723072 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2015-03-11 08:33 - 2015-01-23 07:02 - 00560392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2015-03-11 08:32 - 2015-02-20 05:03 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 08:32 - 2015-02-20 04:58 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 08:32 - 2015-02-20 04:20 - 00301056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-03-11 08:32 - 2015-02-20 04:15 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-03-11 08:32 - 2015-02-05 22:24 - 01113920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-03-11 08:32 - 2015-01-31 01:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-03-11 08:32 - 2015-01-31 01:29 - 02484224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-03-11 08:32 - 2015-01-31 01:20 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-11 08:32 - 2015-01-30 05:01 - 00097792 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys
2015-03-11 08:32 - 2015-01-30 05:00 - 00167424 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\rfcomm.sys
2015-03-11 08:32 - 2015-01-29 03:04 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-03-11 08:32 - 2015-01-29 03:04 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2015-03-11 08:32 - 2015-01-29 02:59 - 02773504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-03-11 08:32 - 2015-01-29 02:49 - 02459136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-03-11 08:32 - 2015-01-28 17:41 - 07472960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 08:32 - 2015-01-28 17:41 - 01733440 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-03-11 08:32 - 2015-01-28 17:41 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-03-11 08:32 - 2015-01-28 04:24 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\StorageContextHandler.dll
2015-03-11 08:32 - 2015-01-28 03:47 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StorageContextHandler.dll
2015-03-11 08:32 - 2015-01-27 06:22 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-11 08:32 - 2015-01-27 04:11 - 03547648 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-11 08:31 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 08:31 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-03-11 08:31 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-03-11 08:31 - 2015-02-21 02:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-03-11 08:31 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-03-11 08:31 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 08:31 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-03-11 08:31 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 08:31 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 08:31 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 08:31 - 2015-02-20 04:35 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-03-11 08:31 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 08:31 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 08:31 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-03-11 08:31 - 2015-02-20 04:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-03-11 08:31 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-03-11 08:31 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 08:31 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-03-11 08:31 - 2015-02-20 03:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-03-11 08:31 - 2015-02-20 03:56 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-03-11 08:31 - 2015-02-20 03:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-03-11 08:31 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 08:31 - 2015-02-20 03:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 08:31 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 08:31 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 08:31 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-03-11 08:31 - 2015-02-20 03:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-03-11 08:31 - 2015-02-20 03:29 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-03-11 08:31 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 08:31 - 2015-02-20 03:26 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-03-11 08:31 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-03-11 08:31 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-03-11 08:31 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 08:31 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 08:31 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-03-11 08:31 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-03-11 08:31 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-03-11 08:31 - 2015-02-06 03:28 - 02257408 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-03-11 08:31 - 2015-02-06 03:08 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-03-11 08:31 - 2015-02-03 02:03 - 03551744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2015-03-11 08:31 - 2015-02-03 02:02 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2015-03-11 08:31 - 2015-01-30 04:03 - 01488896 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2015-03-11 08:31 - 2015-01-30 04:03 - 01464832 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2015-03-11 08:31 - 2015-01-30 04:02 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2015-03-11 08:31 - 2015-01-30 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2015-03-11 08:31 - 2015-01-30 03:42 - 01204224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2015-03-11 08:31 - 2015-01-30 03:40 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll
2015-03-11 08:31 - 2015-01-30 03:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2015-03-11 08:31 - 2015-01-30 03:29 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atlthunk.dll
2015-03-11 08:31 - 2015-01-30 03:24 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2015-03-11 08:31 - 2015-01-30 03:24 - 00250880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll
2015-03-11 08:31 - 2015-01-30 03:16 - 00266752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll
2015-03-11 08:31 - 2015-01-30 03:08 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll
2015-03-11 08:31 - 2015-01-30 03:06 - 00278016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll
2015-03-11 08:31 - 2015-01-29 03:11 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 08:31 - 2015-01-29 03:00 - 00210944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 08:31 - 2015-01-29 02:55 - 00971776 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2015-03-11 08:31 - 2015-01-29 02:50 - 00811008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2015-03-11 08:30 - 2015-02-12 19:40 - 22291584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 08:30 - 2015-02-12 19:34 - 19731824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-03-11 08:30 - 2015-02-08 01:57 - 01090048 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2015-03-11 08:30 - 2015-02-08 01:49 - 00791040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2015-03-11 08:30 - 2015-01-29 20:45 - 01763352 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 08:30 - 2015-01-29 20:34 - 01488040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-11 08:30 - 2015-01-28 03:31 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 08:30 - 2015-01-28 03:11 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2015-03-11 08:30 - 2015-01-28 01:47 - 02501368 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2015-03-11 08:30 - 2015-01-28 01:41 - 02207488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2015-03-11 08:30 - 2015-01-21 07:54 - 01384712 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-11 08:30 - 2015-01-21 07:15 - 01123848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2015-03-11 08:30 - 2014-12-11 07:36 - 00046456 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContentServer.exe
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-07 16:31 - 2013-05-30 08:05 - 02072064 ___SH () C:\Users\Shirley\Downloads\Thumbs.db
2015-04-07 16:30 - 2014-12-27 23:58 - 01316265 _____ () C:\Windows\WindowsUpdate.log
2015-04-07 16:10 - 2013-06-15 08:49 - 00003942 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{637FDB08-565A-4D4F-BB38-298843C287CF}
2015-04-07 07:25 - 2014-08-20 18:35 - 00000000 ____D () C:\Users\Shirley\AppData\Local\Adobe
2015-04-07 07:24 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2015-04-07 07:22 - 2013-05-30 02:37 - 08306688 ___SH () C:\Users\Shirley\Desktop\Thumbs.db
2015-04-06 21:53 - 2013-06-02 15:49 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-06 21:45 - 2014-02-01 12:06 - 00001148 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002UA.job
2015-04-06 20:31 - 2015-01-23 18:23 - 00004970 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for ShirleyPc-Shirley ShirleyPc
2015-04-06 11:45 - 2014-02-01 12:06 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002Core.job
2015-04-06 10:35 - 2015-01-14 12:06 - 00003758 _____ () C:\Windows\System32\Tasks\AutoKMS
2015-04-06 10:34 - 2013-10-22 22:08 - 00000000 ____D () C:\Users\Shirley\SkyDrive
2015-04-06 10:34 - 2013-06-02 23:19 - 00000922 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-06 10:28 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-04-05 23:40 - 2013-09-30 06:04 - 02012336 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-05 23:40 - 2013-06-02 21:56 - 00934014 _____ () C:\Windows\system32\perfh007.dat
2015-04-05 23:40 - 2013-06-02 21:56 - 00203940 _____ () C:\Windows\system32\perfc007.dat
2015-04-05 22:22 - 2014-12-30 13:20 - 00156875 _____ () C:\Windows\setupact.log
2015-04-05 10:28 - 2014-10-23 22:29 - 00000000 ____D () C:\Users\Shirley\AppData\Local\CrashDumps
2015-04-05 10:27 - 2014-08-06 19:46 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A}
2015-04-04 11:24 - 2013-06-02 21:43 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4216991579-408556834-1651255799-1002
2015-04-04 10:36 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2015-04-04 10:21 - 2014-07-07 07:10 - 00000000 ____D () C:\Users\Shirley\Desktop\Dossiers
2015-04-04 09:26 - 2013-03-20 19:38 - 00000000 ___HD () C:\Users\Shirley\AppData\Local\STcnXkTbNVo
2015-04-04 08:13 - 2015-03-05 21:00 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\vlc
2015-04-04 06:44 - 2014-06-11 10:28 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\Youtube Downloader HD
2015-04-02 07:32 - 2014-09-08 12:07 - 00000000 ____D () C:\Users\Shirley\.VirtualBox
2015-04-02 01:36 - 2014-09-08 12:07 - 00000000 ____D () C:\Users\Shirley\VirtualBox VMs
2015-03-30 19:06 - 2013-06-02 23:27 - 00000000 ___RD () C:\Users\Shirley\Google Drive
2015-03-30 06:31 - 2015-02-06 10:25 - 00000000 ____D () C:\Users\Shirley\AppData\Local\Viber
2015-03-30 06:31 - 2014-05-28 08:02 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\ViberPC
2015-03-27 08:10 - 2015-01-24 19:31 - 27619328 _____ () C:\Windows\system32\vmguest.iso
2015-03-26 21:32 - 2014-06-17 10:12 - 00001062 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-03-26 21:32 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-26 21:32 - 2013-06-02 21:53 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-03-26 21:31 - 2013-08-22 15:25 - 00786432 ___SH () C:\Windows\system32\config\BBI
2015-03-26 17:26 - 2013-06-12 22:20 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-03-26 08:27 - 2013-10-22 21:28 - 00000000 ____D () C:\Users\Shirley
2015-03-25 08:11 - 2014-12-11 08:16 - 00000000 ____D () C:\Windows\system32\appraiser
2015-03-25 08:11 - 2014-07-10 01:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-03-23 07:22 - 2014-01-24 11:56 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-22 15:08 - 2014-01-13 08:39 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\Skype
2015-03-22 13:15 - 2015-02-12 08:46 - 185035143 _____ () C:\Users\Shirley\Desktop\IP4 Top.psd
2015-03-22 09:47 - 2015-01-08 17:00 - 05280720 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-22 09:45 - 2012-05-04 13:32 - 00000000 ___RD () C:\Users\Shirley\Desktop\Raccourcis
2015-03-22 06:19 - 2013-05-30 09:21 - 00000000 ____D () C:\Android Roms and Files
2015-03-22 06:02 - 2013-06-02 14:50 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-17 18:00 - 2013-06-02 15:49 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-03-15 14:47 - 2014-10-11 08:10 - 00000000 ____D () C:\Users\Shirley\dwhelper
2015-03-14 06:30 - 2013-07-24 05:52 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-14 06:07 - 2013-06-21 08:45 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-13 19:50 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2015-03-13 08:38 - 2015-01-13 08:44 - 00029446 _____ () C:\Windows\PFRO.log
2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore
2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender
2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-03-12 20:24 - 2013-06-03 18:10 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\uTorrent
2015-03-12 20:19 - 2014-02-22 08:39 - 00000000 __SHD () C:\Users\Public\DRM
2015-03-12 20:18 - 2014-03-16 06:25 - 00000000 ____D () C:\ProgramData\VideoCopilot
2015-03-11 16:49 - 2013-05-30 06:57 - 00589824 ___SH () C:\Users\Shirley\Documents\Thumbs.db
2015-03-11 13:27 - 2015-01-14 11:58 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-03-11 13:27 - 2013-06-15 09:43 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-11 08:22 - 2012-07-26 07:26 - 00000167 _____ () C:\Windows\win.ini
2015-03-10 17:53 - 2014-09-23 17:10 - 00003102 _____ () C:\Windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-4216991579-408556834-1651255799-1002
2015-03-09 08:28 - 2013-08-19 06:41 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\Mp3tag
 
==================== Files in the root of some directories =======
 
2014-03-20 13:53 - 2014-03-20 13:53 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
2013-09-05 22:52 - 2013-09-05 22:52 - 0000132 _____ () C:\Users\Shirley\AppData\Roaming\Adobe BMP Format CS6 Prefs
2013-08-17 11:50 - 2014-09-18 10:25 - 0000132 _____ () C:\Users\Shirley\AppData\Roaming\Adobe PNG Format CS6 Prefs
2014-09-08 11:55 - 2014-09-08 11:55 - 1177208 _____ () C:\Users\Shirley\AppData\Roaming\AndyCleanupTool.exe
2014-09-08 11:55 - 2014-09-08 11:55 - 1176696 _____ () C:\Users\Shirley\AppData\Roaming\AndyCleanVM.exe
2014-10-07 08:48 - 2015-01-04 01:37 - 0017408 ___SH () C:\Users\Shirley\AppData\Roaming\Thumbs.db
2013-10-01 11:19 - 2014-04-28 11:08 - 0319449 _____ () C:\Users\Shirley\AppData\Roaming\UserTile.png
2014-01-24 10:41 - 2014-12-28 11:01 - 0000600 _____ () C:\Users\Shirley\AppData\Roaming\winscp.rnd
2013-08-30 21:26 - 2014-09-28 13:22 - 0055808 _____ () C:\Users\Shirley\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-09-04 06:52 - 2014-09-04 06:52 - 0000095 _____ () C:\Users\Shirley\AppData\Local\fusioncache.dat
2014-02-18 09:25 - 2014-09-04 09:57 - 0000600 _____ () C:\Users\Shirley\AppData\Local\PUTTY.RND
2014-10-13 10:22 - 2014-10-13 10:22 - 0000017 _____ () C:\Users\Shirley\AppData\Local\resmon.resmoncfg
2015-02-17 01:03 - 2015-02-17 01:03 - 0017408 _____ () C:\Users\Shirley\AppData\Local\WebpageIcons.db
2015-01-14 13:48 - 2015-01-14 13:48 - 0740775 _____ () C:\ProgramData\AndyDrivers.zip
2013-09-24 16:11 - 2014-09-28 13:20 - 0000000 _____ () C:\ProgramData\CLDShowX.ini
2013-06-02 22:05 - 2013-06-02 22:05 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-06-30 19:27 - 2014-06-30 19:27 - 0000104 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.64.bc
 
Some content of TEMP:
====================
C:\Users\Shirley\AppData\Local\Temp\avg_tuht_stf_all_2015_238.exe
C:\Users\Shirley\AppData\Local\Temp\i4jdel0.exe
C:\Users\Shirley\AppData\Local\Temp\SkypeSetup.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-04-06 10:39
 
==================== End Of Log ============================

:welcome:

 

Lets run a few tools and go from there, I see some unwanted programs like Trovi that have to go

 

 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
Do not click on any links in the top Advertisment.
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
    [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  to your desktop. 
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
      •  
        [external image: MBAMDashboard_zpsddef9b5f.gif]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished and the log pops up…select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • # AdwCleaner v4.200 - Logfile created 08/04/2015 at 17:33:00
          # Updated 29/03/2015 by Xplode
          # Database : 2015-04-08.1 [Server]
          # Operating system : Windows 8.1 Pro  (x64)
          # Username : Shirley - SHIRLEYPC
          # Running from : C:\Users\Shirley\Desktop\adwcleaner_4.200.exe
          # Option : Cleaning

          ***** [ Services ] *****

          [#] Service Deleted : 417dd0a6

          ***** [ Files / Folders ] *****

          Folder Deleted : C:\ProgramData\iWin
          Folder Deleted : C:\Program Files (x86)\BearShare Applications
          Folder Deleted : C:\Windows\SysWOW64\SearchProtect
          Folder Deleted : C:\Users\Shirley\AppData\Local\eSupport.com
          Folder Deleted : C:\Users\Shirley\AppData\Roaming\baidu
          Folder Deleted : C:\Users\Shirley\AppData\Roaming\iWin
          Folder Deleted : C:\Users\Shirley\AppData\Roaming\pdfforge
          Folder Deleted : C:\Users\Shirley\AppData\Roaming\RHEng
          [!] Folder Deleted : C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\qeh915im.defaultorg\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
          Folder Deleted : C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed]
          File Deleted : C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\qeh915im.defaultorg\Extensions\[removed]
          File Deleted : C:\END
          File Deleted : C:\Windows\System32\log\iSafeKrnlCall.log
          File Deleted : C:\Users\Shirley\Documents\Uninstall.exe
          File Deleted : C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\invalidprefs.js
          File Deleted : C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\qeh915im.defaultorg\invalidprefs.js
          File Deleted : C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\qeh915im.defaultorg\user.js

          ***** [ Scheduled tasks ] *****


          ***** [ Shortcuts ] *****


          ***** [ Registry ] *****

          Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\iijmpjamifmplbakhgikofogdfackici
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\DiscoveryHelper.DLL
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\IMTrProgress.DLL
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\IMWeb.DLL
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\Launcher.EXE
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL
          Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@qq.com/TXSSO
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
          Key Deleted : HKLM\SOFTWARE\728fb111-da31-a454-f3ca-41d22ddf43b5
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FC41815-FA4C-4F8B-B143-2C045C8EA2FC}
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{21493C1F-D071-496A-9C27-450578888291}
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7}
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48}
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{756C097C-6BDB-45DE-A8F1-83E01AB86BA4}
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415C-8A37-763AE183E7E4}
          Key Deleted : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
          Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
          Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
          Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7C3B01BC-53A5-48A0-A43B-0C67731134B9}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424C-BB9F-74C6899B9F92}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
          Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
          Key Deleted : HKCU\Software\eSupport.com
          Key Deleted : HKCU\Software\simplytech
          Key Deleted : HKCU\Software\systweak
          Key Deleted : HKCU\Software\Baidu
          Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
          Key Deleted : HKCU\Software\AppDataLow\Software\simplytech
          Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
          Key Deleted : HKLM\SOFTWARE\Baidu
          Key Deleted : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
          Key Deleted : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{842C4394-47F7-60DE-480B-C09116B63559}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}

          ***** [ Web browsers ] *****

          -\\ Internet Explorer v11.0.9600.17416


          -\\ Mozilla Firefox v37.0.1 (x86 fr)

          [13q7pa7x.default-1412919102734\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Trovi search");
          [13q7pa7x.default-1412919102734\prefs.js] - Line Deleted : user_pref("extensions.OmkFPfTj9ciNJDg6.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[…]
          [13q7pa7x.default-1412919102734\prefs.js] - Line Deleted : user_pref("extensions.SsxWwTPamWhuks5P.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[…]
          [13q7pa7x.default-1412919102734\prefs.js] - Line Deleted : user_pref("extensions.e1FP4AExkwBOIDgX.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[…]
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("aol_toolbar.default.homepage.check", false);
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("aol_toolbar.default.search.check", false);
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.516560e221976.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}c[…]
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=113403");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "149f5bc300000000000000fff966e8a1");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.id", "149f5bc300000000000000fff966e8a1");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15504");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1712:26:30");
          [qeh915im.defaultorg\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");

          -\\ Google Chrome v39.0.2171.71

          [C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851647
          [C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?ctid=CT3321459&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPB4F00168-7F87-49AA-A591-38BCF7FC58E3&q={searchTerms}&SSPV=
          [C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325580&octid=EB_ORIGINAL_CTID&ISID=M338021A7-93F9-42D3-9D7C-4E7D8716ABE5&SearchSource=58&CUI=&UM=2&UP=SP529E584C-89F2-4845-A860-5FF36C60E0AA&q={searchTerms}&SSPV=
          [C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.booking.com/searchresults.fr.html?si=ai%2Cco%2Cci%2Cre%2Cdi;ss={searchTerms};label=opensearch-plugin
          [C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Preferences] - Deleted [Extension] : iijmpjamifmplbakhgikofogdfackici
          [C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default\Preferences] - Deleted [Default_Search_Provider_Data] :

          -\\ Opera v24.0.1558.53


          *************************

          AdwCleaner[R0].txt - [38482 bytes] - [08/04/2015 17:29:45]
          AdwCleaner[S0].txt - [9712 bytes] - [08/04/2015 17:33:00]

          ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9771  bytes] ##########

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Thisisu
          Version: 6.5.3 (04.07.2015:1)
          OS: Windows 8.1 Pro x64
          Ran by [removed] on 08.04.2015 at 17:43:44,66
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




          ~~~ Services



          ~~~ Registry Values



          ~~~ Registry Keys



          ~~~ Files

          Successfully deleted: [File] "C:\Users\Shirley\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage"
          Successfully deleted: [File] "C:\Users\Shirley\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal"



          ~~~ Folders

          Successfully deleted: [Folder] "C:\Program Files (x86)\OptOin"
          Successfully deleted: [Folder] "C:\ProgramData\flexnet"
          Successfully deleted: [Folder] "C:\Users\Shirley\AppData\Roaming\tencent"
          Successfully deleted: [Folder] "C:\Program Files (x86)\tencent"



          ~~~ FireFox

          Successfully deleted the following from C:\Users\Shirley\AppData\Roaming\mozilla\firefox\profiles\13q7pa7x.default-1412919102734\prefs.js

          user_pref("extensions.UjXmqcIgit9yKL6d.scode", "(function(){try{if(window.self.location.href.indexOf(\"rjk8rja9pdrHqjY8rTwErHr8rHa\")>-1){return;}}catch(e){}try{var d=[[\"tria
          user_pref("extensions.UjXmqcIgit9yKL6d.url", "hxxp://myculturecode.net/sync2/?q=hfZ9ofV9CShEAen0rTaFqjCMg708BNmGWj8blchGheDUojw9rjsEqdsErdU9qGhIC7n0rjnFrTa9rTaFrjw4tNhVCT94tMV
          Emptied folder: C:\Users\Shirley\AppData\Roaming\mozilla\firefox\profiles\13q7pa7x.default-1412919102734\minidumps [7 files]



          ~~~ Event Viewer Logs were cleared





          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on 08.04.2015 at 17:45:34,74
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

          Malwarebytes Anti-Malware
          www.malwarebytes.org

          Scan Date: 08.04.2015
          Scan Time: 17:51:16
          Logfile: mbam.txt
          Administrator: Yes

          Version: 2.01.4.1018
          Malware Database: v2015.04.08.04
          Rootkit Database: v2015.03.31.01
          License: Trial
          Malware Protection: Enabled
          Malicious Website Protection: Enabled
          Self-protection: Disabled

          OS: Windows 8.1
          CPU: x64
          File System: NTFS
          User: Shirley

          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 387388
          Time Elapsed: 13 min, 33 sec

          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Disabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled

          Processes: 0
          (No malicious items detected)

          Modules: 0
          (No malicious items detected)

          Registry Keys: 2
          PUP.Optional.Multiplug, HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\TYPELIB\{157B1AA6-3E5C-404A-9118-C1D91F537040}, , [d64e4a202763c274356736ffd132cb35],
          PUP.Optional.Multiplug, HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\INTERFACE\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}, , [d64e4a202763c274356736ffd132cb35],

          Registry Values: 0
          (No malicious items detected)

          Registry Data: 0
          (No malicious items detected)

          Folders: 0
          (No malicious items detected)

          Files: 0
          (No malicious items detected)

          Physical Sectors: 0
          (No malicious items detected)


          (end)

          Great, go ahead and run a new scan with FRST, after you open it make sure to put a checkmark in Additions, run the scan and post both logs please

          Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
          Ran by [removed] at 2015-04-08 18:43:26
          Running from C:\Users\[removed]\Desktop
          Boot Mode: Normal
          ==========================================================


          ==================== Security Center ========================

          (If an entry is included in the fixlist, it will be removed.)

          AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

          ==================== Installed Programs ======================

          (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

          µTorrent (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\uTorrent) (Version: 3.4.2.38656 - BitTorrent Inc.)
          7-Zip 9.20 (HKLM-x32\…\7-Zip) (Version:  - )
          8oot Logo Changer version 1.2.09 (HKLM\…\{9513750B-9392-4A03-8074-9EEF890B9A41}_is1) (Version: 1.2.09 - Codigobit.info)
          A1 Servicecenter (HKLM-x32\…\A1 Servicecenter) (Version: 1.4.0.43 - A1 Telekom Austria AG)
          Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.2.443 - Adobe Systems Incorporated)
          Acrobat.com (x32 Version: 0.0.0 - Adobe Systems Incorporated) Hidden
          Adobe After Effects CC 2014 (HKLM-x32\…\{2B22C750-5C3B-4738-B621-BA786AC7A494}) (Version: 13.1.0 - Adobe Systems Incorporated)
          Adobe After Effects CS6 (HKLM-x32\…\{4817D846-700B-474E-A31B-80892B3E92E3}) (Version: 11 - Adobe Systems Incorporated)
          Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
          Adobe Anchor Service x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
          Adobe CMaps x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
          Adobe Creative Cloud (HKLM-x32\…\Adobe Creative Cloud) (Version: 2.7.1.418 - Adobe Systems Incorporated)
          Adobe Creative Suite 4 Master Collection (HKLM-x32\…\Adobe_b2d6abde968e6f277ddbfd501383e02) (Version: 4.0 - Adobe Systems Incorporated)
          Adobe CSI CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
          Adobe Drive CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
          Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
          Adobe Fonts All x64 (Version: 2.0 - Adobe Systems Incorporated) Hidden
          Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
          Adobe Linguistics CS4 x64 (Version: 4.0.0 - Adobe Systems Incorporated) Hidden
          Adobe Media Player (HKLM-x32\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
          Adobe PDF Library Files x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
          Adobe Photoshop CC 2014 (HKLM-x32\…\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.2 - Adobe Systems Incorporated)
          Adobe Photoshop CS4 (64 Bit) (Version: 11.0 - Adobe Systems Incorporated) Hidden
          Adobe Photoshop CS6 (HKLM-x32\…\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
          Adobe Premiere Pro CS6 (HKLM-x32\…\{7176B973-6011-43C1-AEBC-2D73FE7C6982}) (Version: 6.0 - Adobe Systems Incorporated)
          Adobe Type Support x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
          Adobe WinSoft Linguistics Plugin x64 (Version: 1.1 - Adobe Systems Incorporated) Hidden
          A-Men Technologies USB-to-Serial (HKLM-x32\…\{1805BD6D-C441-4A1C-802D-AFF0232DAACD}) (Version:  - )
          Andy OS (HKLM-x32\…\Andy OS) (Version: 0.42 - Andy OS, Inc)
          Apple Application Support (32-Bit) (HKLM-x32\…\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.)
          Apple Application Support (64-Bit) (HKLM\…\{0DF7096B-715A-4233-8633-C7A16ED6D616}) (Version: 3.1.2 - Apple Inc.)
          Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
          Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
          ASUS Ai Charger (HKLM-x32\…\{7FB64E72-9B0E-4460-A821-040C341E414A}) (Version: 1.03.00 - ASUSTeK Computer Inc.)
          AVG PC TuneUp 2015 (de-DE) (x32 Version: 15.0.1001.403 - AVG Technologies) Hidden
          AviSynth (HKLM-x32\…\AviSynth) (Version: 2.6.0 MT - )
          bl (x32 Version: 1.0.0 - Your Company Name) Hidden
          Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
          Boot Animation Creator (HKLM-x32\…\{1B5CD3FA-DC33-4600-BD0F-1598CF4C296C}) (Version: 1.4.0.0 - D01 MicroApps)
          Boot Animation Factory (HKLM-x32\…\{3EA00EEB-27DE-4507-AFF4-0C697A20C37B}) (Version: 1.4.1.0 - D01 MicroApps)
          Camtasia Studio 8 (HKLM-x32\…\{A7727F03-5311-4A12-9A63-2ACD20BA0497}) (Version: 8.2.1.1423 - TechSmith Corporation)
          CCleaner (HKLM\…\CCleaner) (Version: 5.00 - Piriform)
          CDBurnerXP (HKLM-x32\…\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4291 - CDBurnerXP)
          Connect (x32 Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
          ConvertHelper 2.2 (HKLM-x32\…\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1) (Version:  - DownloadHelper)
          CopyTrans Suite désinstallation uniquement (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\CopyTrans Suite) (Version: 2.37 - WindSolutions)
          CPUID CPU-Z 1.70 (HKLM\…\CPUID CPU-Z_is1) (Version:  - )
          CyberLink PowerDVD 13 (HKLM-x32\…\InstallShield_{3CFDF154-7E60-4E98-A8DF-C693A4F8E6B6}) (Version: 13.0.2720.57 - CyberLink Corp.)
          CyberLink YouCam 6 (HKLM-x32\…\{A9CEDD6E-4792-493e-BB35-D86D2E188A5A}) (Version: 6.0.2728.0 - CyberLink Corp.)
          Dolby Advanced Audio v2 (HKLM-x32\…\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.8000.16 - Dolby Laboratories Inc)
          Dropbox (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Dropbox) (Version: 2.8.4 - Dropbox, Inc.)
          EasyBCD 2.2 (HKLM-x32\…\EasyBCD) (Version: 2.2 - NeoSmart Technologies)
          ffdshow x64 v1.3.4515 [2013-06-12] (HKLM\…\ffdshow64_is1) (Version: 1.3.4515.0 - )
          FlashBoot 2.2e (HKLM\…\FlashBoot_is1) (Version:  - Mikhail Kupchik)
          GnuWin32: Gzip-1.3.12-1 (HKLM-x32\…\Gzip-1.3.12-1_is1) (Version: 1.3.12-1 - GnuWin32)
          Google Chrome (HKLM-x32\…\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
          Google Drive (HKLM-x32\…\{C60F3836-333A-4AE2-B526-CFDBA143A9BA}) (Version: 1.18.7821.2489 - Google, Inc.)
          Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
          Google+ Auto Backup (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Google+ Auto Backup) (Version: 1.0.26.151 - Google, Inc.)
          HHD Software Hex Editor Neo 6.10 (HKLM\…\{8EB85C0E-DE7D-4A53-BD66-708B8F2C80B0}) (Version: 6.10.2.5330 - HHD Software, Ltd.)
          Home Media Center x64 (HKLM\…\{BA5FF534-12B0-4E6A-A6EE-36E0E951AC0E}) (Version: 2.5.0 - Tomáš Pšenák)
          HTC Driver Installer (HKLM-x32\…\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.10.0.001 - HTC Corporation)
          iCloud (HKLM\…\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)
          iFunbox (v2.7.2386.747), iFunbox DevTeam (HKLM-x32\…\iFunbox_is1) (Version: v2.7.2386.747 - )
          Image Composite Editor (HKLM\…\{92AB5708-1AAA-4B1B-A8D5-45CF3AD77519}) (Version: 2.0.3 - Microsoft Corporation)
          Imagistik Doc2pix (HKLM-x32\…\{CF29E86C-BD82-4DF5-9C00-FB7EA8F15B28}) (Version: 1.0.0 - Informatik Inc)
          Intel Android Device USB driver (HKLM\…\Intel Android Device USB driver) (Version: 1.2.0 - Intel)
          iSocUSB Driver 1.0.2 (HKLM\…\iSocUSB Driver_is1) (Version: 1.0.1 - Intel Corporation 2012)
          iTunes (HKLM\…\{D227565A-0033-40AD-89BA-653A205CDC11}) (Version: 12.1.1.4 - Apple Inc.)
          Java 8 Update 40 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
          Java(TM) SE Development Kit 6 Update 45 (64-bit) (HKLM\…\{64A3A4F4-B792-11D6-A78A-00B0D0160450}) (Version: 1.6.0.450 - Oracle)
          kuler (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
          Lenovo K900 Device Drivers (HKLM-x32\…\{CE03FF91-455C-4C9E-AEB7-CAFE959811CD}) (Version: 5.0.18 - Lenovo)
          Lenovo USB2.0 UVC Camera (HKLM-x32\…\{70D2C5B8-EB22-45B1-9EAA-5E8C1C408A3B}) (Version: 1.00.0000 - Vimicro Corporation)
          LenovoUsbDriver 1.0.0 (HKLM-x32\…\LenovoUsbDriver) (Version: 1.0.0 - Lenovo)
          LOGO!Soft Comfort V8.0 (Demo) (HKLM\…\LOGO!Soft Comfort V8.0 (Demo)) (Version: 8.0.0.0 - Siemens AG)
          Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
          Manufacturing Flash Tool version 6.0.2 (HKLM-x32\…\Manufacturing Flash Tool_is1) (Version: 6.0.2 - Intel Corporation)
          MD5 Checksum 1.1 (HKLM-x32\…\MD5 Checksum_is1) (Version:  - Okaryn)
          MedienManager 1.5.1 (HKLM-x32\…\8781-9705-0578-2960) (Version: 1.5.1 - A1 Telekom Austria AG)
          Microsoft .NET Framework 1.1 (HKLM-x32\…\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
          Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
          Microsoft Office Korrekturhilfen 2013 - Deutsch (HKLM\…\{90150000-001F-0407-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
          Microsoft Office Korrekturhilfen 2013 - Deutsch (HKLM-x32\…\{90150000-001F-0407-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
          Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
          Microsoft OneDrive (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\OneDriveSetup.exe) (Version: 17.3.4726.0226 - Microsoft Corporation)
          Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
          Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
          Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
          Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
          Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
          MiniTool Partition Wizard Home Edition 8.1.1 (HKLM-x32\…\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version:  - MiniTool Solution Ltd.)
          Mozilla Firefox 37.0.1 (x86 fr) (HKLM-x32\…\Mozilla Firefox 37.0.1 (x86 fr)) (Version: 37.0.1 - Mozilla)
          Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
          Mp3tag v2.64 (HKLM-x32\…\Mp3tag) (Version: v2.64 - Florian Heidenreich)
          MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
          MTK_SN_Write (HKLM-x32\…\{0EEBC2F2-7436-4024-8E3D-FE33041C0AF4}) (Version: 1.0.0 - MediaTek)
          Music Manager (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MusicManager) (Version:  - Google, Inc.)
          NAVIGON Fresh 3.4.1 (HKLM-x32\…\NAVIGON Fresh) (Version: 3.4.1 - NAVIGON)
          Nero 2014 (HKLM-x32\…\{F384C1E1-3A16-4073-95C3-7271FE0ED4C2}) (Version: 15.0.02200 - Nero AG)
          Notepad++ (HKLM-x32\…\Notepad++) (Version: 6.6.8 - Notepad++ Team)
          NVIDIA 3D Vision Driver 327.02 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 327.02 - NVIDIA Corporation)
          NVIDIA GeForce Experience 2.1.1.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1.1 - NVIDIA Corporation)
          NVIDIA Graphics Driver 327.02 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.02 - NVIDIA Corporation)
          NVIDIA HD Audio Driver 1.3.26.4 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)
          Opera Stable 24.0.1558.53 (HKLM-x32\…\Opera 24.0.1558.53) (Version: 24.0.1558.53 - Opera Software ASA)
          Oracle VM VirtualBox 4.3.26 (HKLM\…\{5771F59A-BFC9-4FAF-A883-7642EF4BA3C3}) (Version: 4.3.26 - Oracle Corporation)
          Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
          Package: Galaxy Nexus ToolKit [JellyBean Edition] (HKLM-x32\…\GalaxyNexusToolKit11) (Version: 1.0.0.0 - skipsoft)
          PdaNet+ for Android 4.15 (HKLM-x32\…\PdaNet_is1) (Version:  - June Fabrics Technology Inc)
          PDF Settings CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden
          PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
          PDFCreator (HKLM\…\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.9.2 - pdfforge)
          ph (x32 Version: 1.0.0 - Your Company Name) Hidden
          Photoshop Camera Raw (x32 Version: 5.0 - Adobe Systems Incorporated) Hidden
          Photoshop Camera Raw_x64 (Version: 5.0 - Adobe Systems Incorporated) Hidden
          Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
          Pixel Bender Toolkit (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
          PL-2303 USB-to-Serial (HKLM-x32\…\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.8.12 - Prolific Technology INC)
          plist Editor Pro 2.1.0 (HKLM-x32\…\plist Editor Pro) (Version: 2.1.0 - VOWSoft, Ltd.)
          Prerequisite installer (x32 Version: 15.0.0005 - Nero AG) Hidden
          QQ International (HKLM-x32\…\{3CA54984-A14B-42FE-9FF1-7EA90151D725}) (Version: 1.91.1369.0 - Tencent Technology(Shenzhen) Company Limited)
          QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
          Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6695 - Realtek Semiconductor Corp.)
          Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.8400.29025 - Realtek Semiconductor Corp.)
          Red Giant Complete Suite (HKLM\…\{DAFB22DD-9F96-4F76-AFCC-86A0980CA737}) (Version: 11 - Red Giant Software)
          Red Giant Psunami (HKLM-x32\…\InstallShield_{97F381E0-CCC3-4F22-9078-033CBC597391}) (Version: 1.4.0 - Red Giant Software)
          Red Giant Psunami (Version: 1.4.0 - Red Giant Software) Hidden
          Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
          RW-Everything v1.6.5.9 (HKLM\…\RW-Everything_is1) (Version:  - )
          Safari (HKLM-x32\…\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
          SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.27.0 - SAMSUNG Electronics Co., Ltd.)
          Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\…\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version:  - Microsoft)
          Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version:  - Microsoft) Hidden
          Serviio (HKLM\…\Serviio) (Version:  - )
          SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden
          Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM-x32\…\SLABCOMM&10C4&EA60;) (Version:  - Silicon Laboratories)
          Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7 (HKLM-x32\…\{7BA7F29A-9F23-46A3-8BF6-4F9360BB4834}) (Version: 6.2.00 - Silicon Laboratories, Inc.)
          Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
          Sndbad Shaders 1.03 (HKLM-x32\…\Sndbad Shaders 1.03) (Version: 1.03 - Sndbad)
          SQLite Expert Personal 3.5.51 (HKLM-x32\…\SQLite Expert Personal 3_is1) (Version:  - Bogdan Ureche)
          SRS-Root (HKLM-x32\…\{24EAD272-D05D-4950-BD59-F88AB7B4C8C7}_is1) (Version:  - 123Unlock GSM Service)
          Suite Shared Configuration CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
          ToneSync for Windows (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\c2c9648a374f64d1) (Version: 1.2.3.309 - Zedge Europe AS)
          Ultra Key (HKLM-x32\…\{995237D9-6E24-45D9-9B06-C13AA62F518B}) (Version: 1.0.2077.1 - Serious Magic, Inc.)
          ULTRA Program Files (x32 Version: 1.25.2224.0 - Serious Magic, Inc.) Hidden
          VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
          Viber (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Viber) (Version: 5.0.0.2821 - Viber Media Inc)
          Virtual DJ Pro Full - Atomix Productions (HKLM-x32\…\Virtual DJ Pro Full - Atomix Productions) (Version:  - )
          VLC media player (HKLM\…\VLC media player) (Version: 2.2.0 - VideoLAN)
          VoipConnect (HKLM-x32\…\VoipConnect_is1) (Version: 4.14 build 760 - Finarea S.A. Switzerland)
          Watchtower Library 2012 - English (HKLM-x32\…\{11B5A3EB-8B76-46A9-A4B7-1C1FF5A3AAFD}) (Version: 14.0 - Watchtower Bible and Tract Society of Pennsylvania, Inc.)
          Watchtower Library 2012 - Français (HKLM-x32\…\{429C765D-42CC-4F2A-A6CA-2737630E502A}) (Version: 14.0 - Watchtower Bible and Tract Society of Pennsylvania, Inc.)
          Windows 8 Codec Pack 2.0.1 (HKLM-x32\…\Windows 8 - Codec Pack) (Version: 2.0.1 - Windows 8 Codec Pack)
          WinRAR 4.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
          WinSCP 5.5.6 (HKLM-x32\…\winscp3_is1) (Version: 5.5.6 - Martin Prikryl)
          Wondershare Video Converter Ultimate(Build 7.1.3.3) (HKLM-x32\…\Wondershare Video Converter Ultimate_is1) (Version: 7.1.3.3 - Wondershare Software)
          XBMC (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\XBMC) (Version:  - Team XBMC)
          xFSTK-Downloader 1.3.6 (HKLM-x32\…\{07E546A1-1CB6-497F-B6F4-BF5F0A4524C6}_is1) (Version: 1.3.6 - Intel Corporation 2012)
          Xilisoft Convertisseur Vidéo Ultimate (HKLM-x32\…\Xilisoft Convertisseur Vidéo Ultimate) (Version: 7.8.0.20140401 - Xilisoft)
          Xilisoft DVD Ripper Platinum (HKLM-x32\…\Xilisoft DVD Ripper Platinum) (Version: 7.8.5.20141031 - Xilisoft)
          Xilisoft DVD Ripper Ultimate (HKLM-x32\…\Xilisoft DVD Ripper Ultimate) (Version: 7.8.5.20141031 - Xilisoft)
          Xvid Video Codec (HKLM-x32\…\Xvid Video Codec 1.3.3) (Version: 1.3.3 - Xvid Team)
          Youtube Downloader HD v. 2.9.9.21 (HKLM-x32\…\Youtube Downloader HD_is1) (Version:  - YoutubeDownloaderHD.com)
          百度云管家 (HKLM-x32\…\百度云管家) (Version: 5.0.0 - 百度在线网络技术北京有限公司)

          ==================== Custom CLSID (selected items): ==========================

          (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

          CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Shirley\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{679F137C-3162-45da-BE3C-2F9C3D093F64}\InprocServer32 -> C:\Windows\system32\shdocvw.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Shirley\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.)
          CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Shirley\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.)
          CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Shirley\AppData\Local\Microsoft\OneDrive\17.3.4726.0226\amd64\FileSyncApi64.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)

          ==================== Restore Points  =========================


          ==================== Hosts content: ==========================

          (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

          2013-08-22 15:25 - 2014-11-28 13:51 - 00006914 ____R C:\Windows\system32\Drivers\etc\hosts
          127.0.0.1       localhost
          127.0.0.1 activation.cloud.techsmith.com
          127.0.0.1 lmlicenses.wip4.adobe.com
          127.0.0.1 lm.licenses.adobe.com
          127.0.0.1 na1r.services.adobe.com
          127.0.0.1 na2m-pr.licenses.adobe.com
          127.0.0.1 na4r.services.adobe.com
          127.0.0.1 ims-na1-prprod.adobelogin.com
          127.0.0.1 activate.adobe.com
          127.0.0.1 practivate.adobe.com
          127.0.0.1 practivate.adobe.de
          127.0.0.1 209-34-83-73.ood.opsource.net
          127.0.0.1 3dns.adobe.com
          127.0.0.1 3dns-1.adobe.com
          127.0.0.1 3dns-2.adobe.com
          127.0.0.1 3dns-3.adobe.com
          127.0.0.1 3dns-4.adobe.com
          127.0.0.1 3dns-5.adobe.com
          127.0.0.1 activate-sea.adobe.com
          127.0.0.1 activate-sea.adobe.de
          127.0.0.1 activate-sjc0.adobe.com
          127.0.0.1 activate-sjc0.adobe.de
          127.0.0.1 activate.adobe.de
          127.0.0.1 activate.wip.adobe.com
          127.0.0.1 activate.wip1.adobe.com
          127.0.0.1 activate.wip2.adobe.com
          127.0.0.1 activate.wip3.adobe.com
          127.0.0.1 activate.wip3.adobe.de
          127.0.0.1 activate.wip4.adobe.com

          There are 110 more lines.


          ==================== Scheduled Tasks (whitelisted) =============

          (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

          Task: {055019F0-6336-4010-9AA7-C8DBFC8F0652} - System32\Tasks\Opera scheduled Autoupdate 1409914763 => C:\Program Files (x86)\Opera\launcher.exe [2014-08-27] (Opera Software)
          Task: {08EA715B-1E50-444E-84FA-F41487EA0392} - System32\Tasks\Microsoft Office 15 Sync Maintenance for ShirleyPc-Shirley ShirleyPc => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation)
          Task: {189FC402-BA0B-41E8-A30B-80C214C0132D} - System32\Tasks\{4F4F4C32-6DEA-46A1-928E-6246C74CF74F} => pcalua.exe -a "C:\Program Files (x86)\Foxy Games\Jewel Quest Mysteries The Oracle of Ur Collectors Edition\JQM4_PremiumEdition.exe" -d "C:\Program Files (x86)\Foxy Games\Jewel Quest Mysteries The Oracle of Ur Collectors Edition"
          Task: {197AE8F0-E43C-439B-9E2E-DA1990C369CA} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
          Task: {1BB3AAE2-8657-457C-9A04-B7FE010AA94E} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-03-14] (Microsoft Corporation)
          Task: {1C4C8A12-9C8C-4E41-8AD3-6BBF975858BE} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
          Task: {1F9D90E6-6469-42F3-8BCE-51B0EE34378D} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-17] (Adobe Systems Incorporated)
          Task: {24BD1A31-4707-4F3B-A3F1-C8D1D4E25E40} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-02] (Google Inc.)
          Task: {3503F2CB-5D56-49BB-B574-17FB77F2A492} - System32\Tasks\Hotspot => C:\Users\Shirley\Desktop\Hotspot.bat [2014-12-01] ()
          Task: {37D3D033-BC9E-4C6A-925C-9385D2012795} - System32\Tasks\{80BE5F49-06DA-43D8-BB09-9872E20A8742} => pcalua.exe -a "C:\Android Roms and Files\Zopo C2\zopo 980 root\MT6589 USB VCOM drivers\installdrv.exe" -d "C:\Android Roms and Files\Zopo C2\zopo 980 root\MT6589 USB VCOM drivers"
          Task: {39FBCD69-7180-4721-A972-E1CBF98C6E9E} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
          Task: {4308D988-0874-4406-B88F-0E29CC77C501} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
          Task: {50795312-8AE0-4567-B175-68A08C416F89} - System32\Tasks\{62392E8F-62C1-4653-A05F-B0053DE921EB} => pcalua.exe -a "C:\Program Files (x86)\Nightly\uninstall\helper.exe"
          Task: {5E6A1FB4-F26F-4BD9-B278-5EB392208726} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation)
          Task: {63F92630-27C6-47AA-A1C1-5097A06526E0} - System32\Tasks\{41126E1B-8014-4F05-9AEB-BC7E6A41D857} => pcalua.exe -a "C:\Android Roms and Files\GT-I9250\Verizon_Wireless_I515_Galaxy_Nexus_USB_Driver_v1.4.6.0.exe" -d "C:\Android Roms and Files\GT-I9250"
          Task: {66D357E6-F618-4AA2-BAA1-B8094808F331} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
          Task: {722A872A-4004-477E-84CC-798B4A36531B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002Core => C:\Users\Shirley\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-01] (Google Inc.)
          Task: {7D517F94-C030-493A-AB91-31E8FE7DEEA1} - System32\Tasks\AdobeAAMUpdater-1.0-ShirleyPc-Shirley => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated)
          Task: {909451AE-83BA-4755-8081-82D5BA2DB9E9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002UA => C:\Users\Shirley\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-01] (Google Inc.)
          Task: {99254725-4827-4097-A630-AD11672697B1} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe [2015-01-14] ()
          Task: {9D92366F-3024-4D2A-BD9C-395A36301FA9} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
          Task: {A843E403-DE2F-442A-8224-3EC21F93D59C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-02] (Google Inc.)
          Task: {B79CD473-AA29-4F14-A943-15D5AD509421} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-11-21] (Piriform Ltd)
          Task: {C03FB9D1-0C9F-4760-913E-7B291C1A5346} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
          Task: {E37C89C5-7B52-47FD-B036-F2D78054FB6B} - System32\Tasks\{62D1C3FB-E98E-4B6C-AB02-1A03E4150C4C} => pcalua.exe -a "C:\Android Roms and Files\Samsung\P5100\SAMSUNG_USB_Driver_for_Mobile_Phones\SAMSUNG_USB_Driver_for_Mobile_Phones.exe" -d "C:\Android Roms and Files\Samsung\P5100\SAMSUNG_USB_Driver_for_Mobile_Phones"
          Task: {E8AD0A98-451D-46E8-9882-7468E164B98A} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
          Task: {F3AF6FA2-762C-42E7-8FF0-EC045A3F7E3D} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2013-08-20] (Nero AG)
          Task: {FCB2AB10-08FC-4C47-8D6B-95819C8DCC1B} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-4216991579-408556834-1651255799-1002 => %localappdata%\Microsoft\OneDrive\OneDrive.exe
          Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002Core.job => C:\Users\Shirley\AppData\Local\Google\Update\GoogleUpdate.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002UA.job => C:\Users\Shirley\AppData\Local\Google\Update\GoogleUpdate.exe

          ==================== Loaded Modules (whitelisted) ==============

          2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
          2015-01-20 23:35 - 2015-01-20 23:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
          2014-07-16 11:06 - 2014-07-16 11:06 - 00672416 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
          2015-01-21 16:01 - 2015-01-21 16:01 - 08898728 _____ () C:\Program Files\Microsoft Office\OFFICE15\1033\GrooveIntlResource.dll
          2014-08-06 20:08 - 2013-08-23 13:36 - 00721263 _____ () C:\WINDOWS\SysWOW64\WSCM64.dll
          2014-05-12 11:49 - 2014-05-12 11:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
          2013-10-17 16:27 - 2013-10-17 16:27 - 00166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
          2014-11-27 09:49 - 2014-11-25 08:39 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libglesv2.dll
          2014-11-27 09:49 - 2014-11-25 08:39 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libegl.dll
          2014-11-27 09:49 - 2014-11-25 08:39 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\pdf.dll
          2014-11-27 09:49 - 2014-11-25 08:39 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\ffmpegsumo.dll
          2014-11-27 09:49 - 2014-11-25 08:39 - 14910280 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\PepperFlash\pepflashplayer.dll

          ==================== Alternate Data Streams (whitelisted) =========

          (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

          AlternateDataStreams: C:\ProgramData\CLDShowX.ini:Update.CL
          AlternateDataStreams: C:\ProgramData\TEMP:C59E90A4
          AlternateDataStreams: C:\Users\Public\DRM:احتضان
          AlternateDataStreams: C:\Users\Shirley\Local Settings:OXEofcKuEKDCKMGkMwy1Z
          AlternateDataStreams: C:\Users\Shirley\Lokale Einstellungen:OXEofcKuEKDCKMGkMwy1Z
          AlternateDataStreams: C:\Users\Shirley\SkyDrive:ms-properties
          AlternateDataStreams: C:\Users\Shirley\AppData\Local:OXEofcKuEKDCKMGkMwy1Z
          AlternateDataStreams: C:\Users\Shirley\AppData\Local\Application Data:OXEofcKuEKDCKMGkMwy1Z
          AlternateDataStreams: C:\Users\Shirley\AppData\Local\STcnXkTbNVo:wU2DzwpyzrD8rYS3besrGzuu
          AlternateDataStreams: C:\Users\Shirley\AppData\Local\Temporary Internet Files:02A3eqQaBCOOu8y6CduPT
          AlternateDataStreams: C:\Users\Shirley\Documents\semena.DAT:SummaryInformation
          AlternateDataStreams: C:\Users\Shirley\Documents\semena.DAT:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

          ==================== Safe Mode (whitelisted) ===================

          (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


          ==================== EXE Association (whitelisted) ===============

          (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


          ==================== Other Areas ============================

          (Currently there is no automatic fix for this section.)

          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
          DNS Servers: 10.0.0.138 - 8.8.8.8

          ==================== MSCONFIG/TASK MANAGER disabled items ==

          (Currently there is no automatic fix for this section.)

          HKLM\…\StartupApproved\StartupFolder: => "TrayMenu.lnk"
          HKLM\…\StartupApproved\StartupFolder: => "Universal Media Server.lnk"
          HKLM\…\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
          HKLM\…\StartupApproved\Run: => "ShadowPlay"
          HKLM\…\StartupApproved\Run: => "iTunesHelper"
          HKLM\…\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
          HKLM\…\StartupApproved\Run32: => "AdobeCS6ServiceManager"
          HKLM\…\StartupApproved\Run32: => "SwitchBoard"
          HKLM\…\StartupApproved\Run32: => "Acrobat Assistant 8.0"
          HKLM\…\StartupApproved\Run32: => "Adobe Acrobat Speed Launcher"
          HKLM\…\StartupApproved\Run32: => "AdobeCS4ServiceManager"
          HKLM\…\StartupApproved\Run32: => "APSDaemon"
          HKLM\…\StartupApproved\Run32: => "iTunesHelper"
          HKLM\…\StartupApproved\Run32: => "BCSSync"
          HKLM\…\StartupApproved\Run32: => "QuickTime Task"
          HKLM\…\StartupApproved\Run32: => "PowerDVD13Agent"
          HKLM\…\StartupApproved\Run32: => "A1Diagnose"
          HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
          HKLM\…\StartupApproved\Run32: => "BlueStacks Agent"
          HKLM\…\StartupApproved\Run32: => "DelaypluginInstall"
          HKLM\…\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
          HKLM\…\StartupApproved\Run32: => "DivXMediaServer"
          HKLM\…\StartupApproved\Run32: => "DivXUpdate"
          HKLM\…\StartupApproved\Run32: => "YouCam Service6"
          HKLM\…\StartupApproved\Run32: => "Adobe Creative Cloud"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\StartupFolder: => "wandoujia_helper.lnk"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\StartupFolder: => "openSUSE-uninst.exe"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\StartupFolder: => "Dropbox.lnk"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\StartupFolder: => "Universal Media Server.lnk"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "AdobeBridge"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "aliim"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "ApplePhotoStreams"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "com.apple.dav.bookmarks.daemon"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "iCloudServices"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "MouseServer"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "Facebook Update"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "AliMessageTool96d72d182352859f0fb0f4a6b5e2fea8"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "Google Update"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "MusicManager"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "ZedgeToneSync"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "ALLMediaServer"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "Google+ Auto Backup"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "Xvid"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "BaiduYunGuanjia"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "ServUTrayIcon"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "CCleaner Monitoring"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "VoipConnect"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "iCloudDrive"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "*LABAL*"
          HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "Viber"

          ==================== Accounts: =============================

          Administrator (S-1-5-21-4216991579-408556834-1651255799-500 - Administrator - Disabled)
          ASPNET (S-1-5-21-4216991579-408556834-1651255799-1012 - Limited - Enabled)
          Gast (S-1-5-21-4216991579-408556834-1651255799-1015 - Limited - Enabled)
          Guest (S-1-5-21-4216991579-408556834-1651255799-501 - Limited - Enabled)
          HomeGroupUser$ (S-1-5-21-4216991579-408556834-1651255799-1014 - Limited - Enabled)
          Shirley (S-1-5-21-4216991579-408556834-1651255799-1002 - Administrator - Enabled) => C:\Users\Shirley

          ==================== Faulty Device Manager Devices =============

          Name: Apple iPhone
          Description: Apple iPhone
          Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
          Manufacturer: Apple Inc.
          Service: WUDFWpdMtp
          Problem: : This device cannot start. (Code10)
          Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
          On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


          ==================== Event log errors: =========================

          Application errors:
          ==================
          Error: (04/08/2015 06:38:44 PM) (Source: System Restore) (EventID: 8193) (User: )
          Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\srtasks.exe ExecuteScheduledSPPCreation; Beschreibung = Scheduled Checkpoint; Fehler = 0x80070422).


          System errors:
          =============
          Error: (04/08/2015 06:26:11 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
          Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 1205.

          Error: (04/08/2015 06:26:11 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
          Description: Eine TLS 1.2-Verbindungsanforderung wurde von einer Remoteclientanwendung übermittelt, jedoch werden keine der Verschlüsselungssammlungen, die von der Clientanwendung unterstützt werden, vom Server unterstützt. Fehler bei der SSL-Verbindungsanforderung.


          Microsoft Office Sessions:
          =========================
          Error: (04/08/2015 06:38:44 PM) (Source: System Restore) (EventID: 8193) (User: )
          Description: C:\Windows\system32\srtasks.exe ExecuteScheduledSPPCreationScheduled Checkpoint0x80070422


          CodeIntegrity Errors:
          ===================================
            Date: 2015-04-08 18:42:47.538
            Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


          ==================== Memory info ===========================

          Processor: Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz
          Percentage of memory in use: 62%
          Total physical RAM: 4056.09 MB
          Available physical RAM: 1525.88 MB
          Total Pagefile: 8152.09 MB
          Available Pagefile: 4694.11 MB
          Total Virtual: 131072 MB
          Available Virtual: 131071.83 MB

          ==================== Drives ================================

          Drive c: (Windows8_OS) (Fixed) (Total:822.57 GB) (Free:276.31 GB) NTFS ==>[System with boot components (obtained from reading drive)]
          Drive d: () (Fixed) (Total:82.35 GB) (Free:82.25 GB) NTFS
          Drive e: () (Fixed) (Total:0.34 GB) (Free:0.06 GB) NTFS
          Drive g: (CAMERA) (Removable) (Total:62.46 GB) (Free:61.71 GB) FAT32

          ==================== MBR & Partition Table ==================

          ========================================================
          Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A9400691)
          Partition 1: (Not Active) - (Size=82.3 GB) - (Type=07 NTFS)
          Partition 2: (Not Active) - (Size=350 MB) - (Type=07 NTFS)
          Partition 3: (Active) - (Size=500 MB) - (Type=0C)
          Partition 4: (Not Active) - (Size=822.6 GB) - (Type=07 NTFS)

          ========================================================
          Disk: 1 (Size: 62.5 GB) (Disk ID: 00C741A4)
          Partition 1: (Not Active) - (Size=62.5 GB) - (Type=0B)

          ==================== End Of Log ============================

          Lets do this

           

          Please download DelFix and save the file to your Desktop.
           
          [external image: DelFix_zps139e2ea1.jpg]
           
          • Windows XP Double Click DelFix.exe to run the program. 
          • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
          • Checkmark " Remove Disinfection Tools"
          • Click the Run button
          •  
            This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
             
             
             
             
             
            Then lets redownload it and run it again
             
            Please download Farbar Recovery Scan Tool and save it to your DESKTOP
             
            Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
             
            How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
            A simple way to check your system: Start –> Computer (right click) –> Properties
             
            [external image: FRST_zps5d956a1a.jpg]
             
             
            • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
            • Please make sure All Users is checked
            • Just keep the defaults as in the picture checkmarked
            • Press Scan button.
            • It will produce a log called FRST.txt in the same directory the tool is run from.
            • Please copy and paste log back here.
            • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
            • Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
              Ran by [removed] (administrator) on SHIRLEYPC on 08-04-2015 19:52:40
              Running from C:\Users\[removed]\Desktop
              [removed] Platform: Windows 8.1 Pro (X64) OS Language: Englisch (Vereinigte Staaten)
              Internet Explorer Version 11 (Default browser: FF)
              Boot Mode: Normal
              Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

              ==================== Processes (Whitelisted) =================

              (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

              (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
              (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe
              (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe
              (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
              (Microsoft Corporation) C:\Windows\System32\alg.exe
              (Microsoft Corporation) C:\Windows\System32\dasHost.exe
              () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
              (Microsoft Corporation) C:\Windows\System32\vds.exe
              (Microsoft Corporation) C:\Windows\System32\vmms.exe
              (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
              (Microsoft Corporation) C:\Windows\System32\dllhost.exe
              (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
              (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
              (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
              (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
              (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
              (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_134.exe
              (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_134.exe
              (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
              (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
              (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
              (Apple Inc.) C:\Program Files\iTunes\iTunes.exe
              (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
              (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
              (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
              (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
              (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OFFICE15\CSISYNCCLIENT.EXE
              (Microsoft Corporation) C:\Program Files\Microsoft Office\OFFICE15\MSOSYNC.EXE
              (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
              (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
              (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
              (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\ATH.exe
              (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
              (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe


              ==================== Registry (Whitelisted) ==================

              (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

              HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12937872 2012-07-27] (Realtek Semiconductor)
              HKLM\…\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-07-10] (Realtek Semiconductor)
              HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
              HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2404296 2014-08-09] (NVIDIA Corporation)
              HKLM\…\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
              HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.)
              HKLM-x32\…\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-25] (Dolby Laboratories Inc.)
              HKLM-x32\…\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
              HKLM-x32\…\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
              HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-02-13] (Apple Inc.)
              HKLM-x32\…\Run: [ASUS Ai Charger] => C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe [547984 2012-08-13] (ASUSTek Computer Inc.)
              HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated)
              HKLM-x32\…\Run: [] => [X]
              HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.)
              HKLM-x32\…\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
              HKLM-x32\…\Run: [PowerDVD13Agent] => C:\Program Files (x86)\CyberLink\PowerDVD13\PowerDVD13Agent.exe [513048 2013-03-20] (CyberLink Corp.)
              HKLM-x32\…\Run: [A1Diagnose] => C:\Program Files (x86)\A1 Servicecenter\A1 Diagnose\A1Diagnose.exe [31581288 2014-05-19] (mquadr.at software engineering and consulting GmbH, web: www.mquadr.at, mail: [removed])
              HKLM-x32\…\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020704 2014-08-05] (Wondershare)
              HKLM-x32\…\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [1953792 2014-05-16] ()
              HKLM-x32\…\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694040 2014-07-22] (Adobe Systems Incorporated)
              HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
              HKLM-x32\…\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe [901632 2015-01-08] ()
              HKLM-x32\…\Run: [YouCam Service6] => C:\Program Files (x86)\CyberLink\YouCam6\YouCamService6.exe [504792 2014-03-28] (CyberLink Corp.)
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [MouseServer] => C:\Program Files (x86)\MouseServer\MouseServer.exe [244736 2013-08-26] (wifimouse.necta.us)
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [Google Update] => C:\Users\Shirley\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-02-01] (Google Inc.)
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [MusicManager] => C:\Users\Shirley\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7631360 2014-10-09] (Google Inc.)
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [ZedgeToneSync] => C:\Users\Shirley\AppData\Local\Apps\2.0\Data\QGRK6JHZ.6N6\T515ADT6.JJA\zedg..tion_4cd56dcfd1799009_0001.0002_ea3f01849f5e16c3\Data\ZedgeToneSync.appref-ms -startup
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [Google+ Auto Backup] => C:\Users\Shirley\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [3746120 2014-08-13] (Google Inc.)
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [Xvid] => C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] ()
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [AdobeBridge] => [X]
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [BaiduYunGuanjia] => "C:\Users\Shirley\AppData\Roaming\baidu\BaiduYunGuanjia\BaiduYunGuanjia.exe" AutoRun
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-10-20] (Apple Inc.)
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [*LABAL*] => [X]
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [VoipConnect] => C:\Program Files (x86)\VoipConnect.com\VoipConnect\VoipConnect.exe [23048288 2014-12-04] (VoipConnect)
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Run: [Viber] => C:\Users\Shirley\AppData\Local\Viber\Viber.exe [776400 2015-02-03] ()
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {00dcc750-5388-11e4-bef4-e006e6c08ca1} - "G:\bootstrap.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {00dccdf4-5388-11e4-bef4-e006e6c08ca1} - "F:\bootstrap.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {2118b7dd-3b51-11e3-8251-e006e6c08ca1} - "E:\bootstrap.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {2118b805-3b51-11e3-8251-e006e6c08ca1} - "E:\bootstrap.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {2118be2f-3b51-11e3-8251-e006e6c08ca1} - "F:\bootstrap.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {3907c584-b1c1-11e3-bed1-005056c00008} - "E:\bootstrap.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {3dc5103d-3dd5-11e3-be8c-e006e6c08ca1} - "E:\bootstrap.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {a1239a1c-5a07-11e4-bef5-e006e6c08ca1} - "F:\bootstrap.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {d1326214-6622-11e3-bea0-e006e6c08ca1} - "E:\bootstrap.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {d1326224-6622-11e3-bea0-e006e6c08ca1} - "G:\bootstrap.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {d5bf0215-bf99-11e4-bf3f-e006e6c08ca1} - "H:\HTC_Sync_Manager_PC.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {ebb79901-722d-11e3-beb0-e006e6c08ca1} - "E:\bootstrap.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MountPoints2: {ebb79916-722d-11e3-beb0-e006e6c08ca1} - "E:\bootstrap.exe"
              Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TrayMenu.lnk
              ShortcutTarget: TrayMenu.lnk -> C:\Windows\SysWOW64\C2MP\TrayMenu.exe ()
              Startup: C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HandyAndy.lnk
              ShortcutTarget: HandyAndy.lnk -> C:\Program Files\Andy\HandyAndy.exe ()
              Startup: C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk
              ShortcutTarget: PdaNet Desktop.lnk -> C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
              Startup: C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Serviio.lnk
              ShortcutTarget: Serviio.lnk -> C:\Program Files\Serviio\bin\ServiioConsole.exe ()
              ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
              ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
              ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
              ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
              ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
              ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
              ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
              ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
              ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
              ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
              ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
              ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
              ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
              ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
              ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
              ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
              CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

              ==================== Internet (Whitelisted) ====================

              (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/de-at/?ocid=iehp
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
              SearchScopes: HKLM -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
              SearchScopes: HKLM-x32 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
              SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
              SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
              SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
              SearchScopes: HKU\S-1-5-21-4216991579-408556834-1651255799-1002 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
              BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
              BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\OFFICE15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
              BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
              BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-04-08] (Oracle Corporation)
              BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\OFFICE15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
              BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-04-08] (Oracle Corporation)
              Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
              Toolbar: HKU\S-1-5-21-4216991579-408556834-1651255799-1002 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
              Toolbar: HKU\S-1-5-21-4216991579-408556834-1651255799-1002 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
              Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-10-15] (Microsoft Corporation)
              Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
              Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 -  No File
              Winsock: Catalog5 09 C:\Windows\SysWOW64\wlidNSP.dll [50176] (Microsoft Corporation)
              Winsock: Catalog5 10 C:\Windows\SysWOW64\wlidNSP.dll [50176] (Microsoft Corporation)
              Winsock: Catalog5-x64 09 C:\WINDOWS\system32\wlidnsp.dll [74240] (Microsoft Corporation)
              Winsock: Catalog5-x64 10 C:\WINDOWS\system32\wlidnsp.dll [74240] (Microsoft Corporation)
              Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
              Tcpip\..\Interfaces\{CE9D39B2-C943-4BC2-BF18-E2DB62FC7F84}: [NameServer] 10.0.0.138,8.8.8.8

              FireFox:
              ========
              FF ProfilePath: C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734
              FF Homepage: hxxp://www.A1.net
              FF NetworkProxy: "gopher", ""
              FF NetworkProxy: "gopher_port", 0
              FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-17] ()
              FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
              FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
              FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
              FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
              FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2014-07-22] (Adobe Systems)
              FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-17] ()
              FF Plugin-x32: @alibaba.com/nptrademanager;version=1.0 -> C:\Program Files (x86)\TradeManager\nptrademanager.dll No File
              FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
              FF Plugin-x32: @baidu.com/YunWebDetectPlugin -> C:\Users\Shirley\AppData\Roaming\baidu\BaiduYunGuanjia\npYunWebDetect.dll No File
              FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-08-13] (Google, Inc.)
              FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-04-08] (Oracle Corporation)
              FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-04-08] (Oracle Corporation)
              FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-05-21] (Microsoft Corporation)
              FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
              FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
              FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2013-08-20] (Nero AG)
              FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-08-29] (NVIDIA Corporation)
              FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-08-29] (NVIDIA Corporation)
              FF Plugin-x32: @qq.com/npchrome -> C:\Program Files (x86)\Common Files\Tencent\Npchrome\npchrome.dll [2014-11-20] (Tencent)
              FF Plugin-x32: @qq.com/npqscall -> C:\Program Files (x86)\Common Files\Tencent\NPQSCALL\npqscall.dll [2014-11-20] (Tencent)
              FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-11-15] (Google Inc.)
              FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-11-15] (Google Inc.)
              FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
              FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
              FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
              FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
              FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2014-07-22] (Adobe Systems)
              FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: @alibaba.com/npAliSSOLogin;version=1.0 -> C:\Program Files (x86)\Trademanager\npAliSSOLogin.dll No File
              FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: @alibaba.com/nptrademanager;version=1.0 -> "C:\Program Files (x86)\Trademanager\nptrademanager.dll" No File
              FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: @alibaba.com/npwangwang;version=1.0 -> "C:\Program Files (x86)\Trademanager\npwangwang.dll" No File
              FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: @tools.google.com/Google Update;version=3 -> C:\Users\Shirley\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-11-15] (Google Inc.)
              FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: @tools.google.com/Google Update;version=9 -> C:\Users\Shirley\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-11-15] (Google Inc.)
              FF Plugin HKU\S-1-5-21-4216991579-408556834-1651255799-1002: {@alibaba.com/alisetup;version=1.0} -> C:\Users\Shirley\AppData\Local\Alibaba\AliSetup\0.1.0.52\npAliSetupOneClick.dll [2011-02-22] (alibaba)
              FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2014-05-21] (Microsoft Corporation)
              FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-10-23] (Apple Inc.)
              FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-10-23] (Apple Inc.)
              FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-10-23] (Apple Inc.)
              FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-10-23] (Apple Inc.)
              FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-10-23] (Apple Inc.)
              FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nptrademanager.dll [2014-11-11] ( )
              FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwangwang.dll [2011-07-29] ( )
              FF Extension: German Dictionary - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed] [2015-01-04]
              FF Extension: United States English Spellchecker - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed] [2015-01-04]
              FF Extension: MEGA - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed] [2015-02-11]
              FF Extension: YouTube ALL HTML5 - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed] [2015-01-04]
              FF Extension: Saved Password Editor - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\[removed] [2015-01-04]
              FF Extension: YouTube High Definition - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2015-01-04]
              FF Extension: Facebook Photo Zoom - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\{7c6cdf7c-8ea8-4be7-ae5a-0b3effe14d66}.xpi [2015-01-04]
              FF Extension: Download YouTube Videos as MP4 - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2015-01-04]
              FF Extension: Video DownloadHelper - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-03-14]
              FF Extension: Adblock Plus - C:\Users\Shirley\AppData\Roaming\Mozilla\Firefox\Profiles\13q7pa7x.default-1412919102734\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-04]
              FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\Wondershare\Video Converter Ultimate\[removed]
              FF Extension: Wondershare Video Converter Ultimate - C:\ProgramData\Wondershare\Video Converter Ultimate\[removed] [2014-08-06]

              Chrome:
              =======
              CHR dev: Chrome dev build detected! <======= ATTENTION
              CHR Profile: C:\Users\Shirley\AppData\Local\Google\Chrome\User Data\Default

              ==================== Services (Whitelisted) =================

              (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

              R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
              S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.)
              S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
              R2 CyberLink PowerDVD 13 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe [77576 2013-03-20] (CyberLink)
              R2 CyberLink PowerDVD 13 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe [323336 2013-03-20] (CyberLink)
              S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-03-17] (Malwarebytes Corporation)
              S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
              S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1721800 2014-08-09] (NVIDIA Corporation)
              S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18974152 2014-08-09] (NVIDIA Corporation)
              R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
              S2 Serviio; C:\Program Files\Serviio\bin\ServiioService.exe [327680 2015-02-09] () [File not signed]
              S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
              R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [44856 2015-02-25] (AVG Technologies)
              R2 UxTuneUp; C:\Windows\SysWOW64\uxtuneup.dll [36664 2015-02-25] (AVG Technologies)
              R2 vmms; C:\Windows\system32\vmms.exe [13784576 2014-10-08] (Microsoft Corporation)
              S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
              R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
              S3 BaiduYunUtility; C:\Users\Shirley\AppData\Roaming\baidu\BaiduYunGuanjia\YunUtilityService.exe [X]

              ==================== Drivers (Whitelisted) ====================

              (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

              R3 AiCharger; C:\Windows\SysWow64\drivers\AiCharger.sys [14848 2012-03-22] (ASUSTek Computer Inc.)
              R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.)
              R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
              R3 clwvd6; C:\Windows\system32\DRIVERS\clwvd6.sys [41704 2013-10-29] (CyberLink Corporation)
              S3 HtcVCom32; C:\Windows\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated)
              R1 hvservice; C:\Windows\System32\drivers\hvservice.sys [68960 2015-01-24] (Microsoft Corporation)
              R3 isocusb; C:\Windows\system32\drivers\isocusb.sys [261120 2012-12-06] (Intel Corp.)
              S3 lunparser; C:\Windows\System32\drivers\lunparser.sys [19456 2015-01-24] (Microsoft Corporation)
              S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
              S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-03-17] (Malwarebytes Corporation)
              R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [21448 2014-08-09] (NVIDIA Corporation)
              R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
              S3 passthruparser; C:\Windows\System32\drivers\passthruparser.sys [22016 2015-01-24] (Microsoft Corporation)
              S3 pvhdparser; C:\Windows\System32\drivers\pvhdparser.sys [27136 2015-01-24] (Microsoft Corporation)
              S3 pwdrvio; C:\WINDOWS\system32\pwdrvio.sys [19152 2013-09-30] ()
              S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] ()
              R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation)
              R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [266896 2012-06-13] (Realtek Semiconductor Corp.)
              R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1936088 2013-07-31] (Realtek Semiconductor Corporation                           )
              S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
              S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [115208 2014-11-21] (Oracle Corporation)
              S3 vhdparser; C:\Windows\System32\drivers\vhdparser.sys [18944 2015-01-24] (Microsoft Corporation)
              R3 VMC412; C:\Windows\System32\Drivers\VMC412.sys [232576 2012-08-22] (Vimicro Corporation)
              R3 VMSMP; C:\Windows\system32\DRIVERS\vmswitch.sys [688640 2014-10-08] (Microsoft Corporation)
              S3 VMSP; C:\Windows\system32\DRIVERS\vmswitch.sys [688640 2014-10-08] (Microsoft Corporation)
              S3 VMSVSF; C:\Windows\system32\DRIVERS\vmswitch.sys [688640 2014-10-08] (Microsoft Corporation)
              S3 VMSVSP; C:\Windows\system32\DRIVERS\vmswitch.sys [688640 2014-10-08] (Microsoft Corporation)
              R3 vmuacflt; C:\Windows\System32\Drivers\vmuacflt.sys [13696 2012-05-02] (Vimicro Corporation)
              S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
              R2 {09F57980-3432-4AFC-957D-27AC45FAE1F5}; C:\Program Files (x86)\CyberLink\PowerDVD13\Common\NavFilter\000.fcl [130320 2013-03-19] (CyberLink Corp.)
              S3 aswVmm; \??\C:\Users\Shirley\AppData\Local\Temp\aswVmm.sys [X]
              S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X]
              S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]

              ==================== NetSvcs (Whitelisted) ===================

              (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


              ==================== One Month Created Files and Folders ========

              (If an entry is included in the fixlist, the file\folder will be moved.)

              2015-04-08 19:52 - 2015-04-08 19:53 - 00032384 _____ () C:\Users\Shirley\Desktop\FRST.txt
              2015-04-08 19:52 - 2015-04-08 19:52 - 02095616 _____ (Farbar) C:\Users\Shirley\Desktop\FRST64.exe
              2015-04-08 19:52 - 2015-04-08 19:52 - 00000000 ____D () C:\FRST
              2015-04-08 19:51 - 2015-04-08 19:51 - 00000903 _____ () C:\DelFix.txt
              2015-04-08 18:07 - 2015-04-08 18:07 - 00001355 _____ () C:\Users\Shirley\Desktop\mbam.txt
              2015-04-08 17:49 - 2015-04-08 17:49 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
              2015-04-08 17:49 - 2015-04-08 17:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
              2015-04-08 17:49 - 2015-04-08 17:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
              2015-04-08 17:43 - 2015-04-08 17:43 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-SHIRLEYPC-Windows-8.1-Pro-(64-bit).dat
              2015-04-08 17:43 - 2015-04-08 17:43 - 00000000 ____D () C:\RegBackup
              2015-04-08 17:27 - 2015-04-08 17:27 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Shirley\Desktop\mbam-setup-2.1.4.1018.exe
              2015-04-08 16:48 - 2015-04-08 16:49 - 00561064 _____ (Oracle Corporation) C:\Users\Shirley\Downloads\jxpiinstall(1).exe
              2015-04-08 16:48 - 2015-04-08 16:48 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\Oracle
              2015-04-07 16:52 - 2015-04-07 16:52 - 00000000 ____D () C:\NVIDIA
              2015-04-07 16:46 - 2015-04-07 16:46 - 00297360 _____ () C:\Windows\Minidump\040715-31093-01.dmp
              2015-04-07 16:24 - 2015-04-07 16:25 - 09331982 _____ () C:\Users\Shirley\Downloads\qui veut gagner…psd
              2015-04-05 10:26 - 2015-04-05 10:26 - 00869376 _____ () C:\Users\Shirley\Downloads\free-dvd-protection-removal-win.exe
              2015-04-04 10:36 - 2015-04-04 10:38 - 00000000 ___SD () C:\Windows\system32\GWX
              2015-04-04 10:36 - 2015-04-04 10:36 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
              2015-04-02 18:57 - 2015-04-02 19:25 - 00000000 ____D () C:\Users\Shirley\Desktop\Jude
              2015-04-02 02:17 - 2015-04-02 02:17 - 00163840 _____ () C:\Users\Shirley\Desktop\Beamoff Tool.iso
              2015-04-01 20:24 - 2015-04-01 22:44 - 1159342080 _____ () C:\Users\Shirley\Downloads\OSX-Mavericks.iso
              2015-04-01 13:00 - 2015-04-01 13:00 - 00000000 ____D () C:\Users\Shirley\Desktop\Mac OS X Yosemite Niresh Intel and AMD Images
              2015-03-26 17:27 - 2015-03-26 17:27 - 00001776 _____ () C:\Users\Public\Desktop\iTunes.lnk
              2015-03-26 17:27 - 2015-03-26 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
              2015-03-26 17:26 - 2015-03-26 17:27 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
              2015-03-26 17:26 - 2015-03-26 17:27 - 00000000 ____D () C:\Program Files\iTunes
              2015-03-26 17:26 - 2015-03-26 17:26 - 00000000 ____D () C:\Program Files\iPod
              2015-03-26 17:26 - 2015-03-26 17:26 - 00000000 ____D () C:\Program Files (x86)\iTunes
              2015-03-25 07:55 - 2015-03-11 04:38 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
              2015-03-25 07:55 - 2015-03-11 00:08 - 01107456 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
              2015-03-25 07:55 - 2015-03-11 00:08 - 00943104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
              2015-03-25 07:55 - 2015-03-11 00:08 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
              2015-03-25 07:55 - 2015-03-11 00:08 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
              2015-03-25 07:55 - 2015-03-11 00:08 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
              2015-03-25 07:55 - 2015-03-11 00:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
              2015-03-24 08:25 - 2015-03-24 08:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
              2015-03-23 07:27 - 2015-03-23 07:29 - 77317912 _____ (Samsung Electronics Co., Ltd.) C:\Users\Shirley\Downloads\KiesSetup.exe
              2015-03-23 07:27 - 2015-03-23 07:29 - 42543488 _____ (Samsung Electronics Co., Ltd.) C:\Users\Shirley\Downloads\Kies3Setup.exe
              2015-03-22 09:34 - 2015-03-22 09:34 - 00003402 _____ () C:\Windows\System32\Tasks\{62D1C3FB-E98E-4B6C-AB02-1A03E4150C4C}
              2015-03-22 06:57 - 2015-03-22 07:06 - 168295156 _____ () C:\Users\Shirley\Downloads\Slim-p5100-5.0.2.alpha.1.0-UNOFFICIAL-20150224-1826.zip
              2015-03-21 10:30 - 2015-03-21 10:30 - 18880558 _____ () C:\Users\Shirley\Downloads\7ad45ac2.apk
              2015-03-21 10:01 - 2015-03-21 10:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
              2015-03-21 10:01 - 2015-03-16 18:36 - 00922704 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
              2015-03-21 10:01 - 2015-03-16 18:35 - 00128592 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
              2015-03-21 09:46 - 2015-03-21 09:48 - 111145672 _____ (Oracle Corporation) C:\Users\Shirley\Downloads\VirtualBox-4.3.26-98988-Win.exe
              2015-03-19 18:09 - 2015-03-19 18:10 - 02803156 _____ () C:\Users\Shirley\Downloads\com.mobileuncle.toolbox.downloader.apk
              2015-03-18 13:22 - 2015-03-18 13:22 - 00018072 _____ () C:\Users\Shirley\Downloads\Ravenna.ttf
              2015-03-16 18:35 - 2015-03-16 18:35 - 00204264 _____ (Oracle Corporation) C:\Windows\system32\VBoxNetFltNobj.dll
              2015-03-16 18:35 - 2015-03-16 18:35 - 00156360 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetFlt.sys
              2015-03-16 18:35 - 2015-03-16 18:35 - 00141440 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxNetAdp.sys
              2015-03-12 20:05 - 2015-03-12 20:05 - 00000000 ____D () C:\Users\Shirley\Downloads\Element3D_V2
              2015-03-12 19:34 - 2015-03-12 19:34 - 00000000 ____D () C:\Users\Shirley\Downloads\VIDEO COPILOT ELEMENT 3D V2 2.0.4 +spider (Cracked)
              2015-03-12 19:29 - 2015-03-12 19:29 - 00000000 ____D () C:\Users\Shirley\AppData\Local\Image Composite Editor
              2015-03-12 19:29 - 2015-03-12 19:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Composite Editor
              2015-03-12 19:29 - 2015-03-12 19:29 - 00000000 ____D () C:\Program Files\Microsoft Research
              2015-03-12 19:25 - 2015-03-12 19:26 - 11344040 _____ (Microsoft Corporation) C:\Users\Shirley\Downloads\PhotosynthInstall.exe
              2015-03-12 19:25 - 2015-03-12 19:26 - 07963136 _____ () C:\Users\Shirley\Downloads\ICE-2.0.3-for-64-bit-Windows.msi
              2015-03-11 08:33 - 2015-03-06 04:53 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
              2015-03-11 08:33 - 2015-03-06 04:33 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
              2015-03-11 08:33 - 2015-02-26 01:26 - 04178944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
              2015-03-11 08:33 - 2015-02-07 01:09 - 00396419 _____ () C:\Windows\system32\ApnDatabase.xml
              2015-03-11 08:33 - 2015-02-04 01:58 - 00264000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
              2015-03-11 08:33 - 2015-02-04 01:58 - 00114496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys
              2015-03-11 08:33 - 2015-02-04 01:58 - 00044024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
              2015-03-11 08:33 - 2015-02-03 01:53 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\winshfhc.dll
              2015-03-11 08:33 - 2015-02-03 01:53 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winshfhc.dll
              2015-03-11 08:33 - 2015-01-29 03:58 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll
              2015-03-11 08:33 - 2015-01-29 03:29 - 00290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\photowiz.dll
              2015-03-11 08:33 - 2015-01-27 05:44 - 00933888 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe
              2015-03-11 08:33 - 2015-01-24 03:51 - 00816128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe
              2015-03-11 08:33 - 2015-01-23 09:17 - 00723072 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
              2015-03-11 08:33 - 2015-01-23 07:02 - 00560392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
              2015-03-11 08:32 - 2015-02-20 05:03 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
              2015-03-11 08:32 - 2015-02-20 04:58 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
              2015-03-11 08:32 - 2015-02-20 04:20 - 00301056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
              2015-03-11 08:32 - 2015-02-20 04:15 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
              2015-03-11 08:32 - 2015-02-05 22:24 - 01113920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
              2015-03-11 08:32 - 2015-01-31 01:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
              2015-03-11 08:32 - 2015-01-31 01:29 - 02484224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
              2015-03-11 08:32 - 2015-01-31 01:20 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
              2015-03-11 08:32 - 2015-01-30 05:01 - 00097792 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys
              2015-03-11 08:32 - 2015-01-30 05:00 - 00167424 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\rfcomm.sys
              2015-03-11 08:32 - 2015-01-29 03:04 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
              2015-03-11 08:32 - 2015-01-29 03:04 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
              2015-03-11 08:32 - 2015-01-29 02:59 - 02773504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
              2015-03-11 08:32 - 2015-01-29 02:49 - 02459136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
              2015-03-11 08:32 - 2015-01-28 17:41 - 07472960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
              2015-03-11 08:32 - 2015-01-28 17:41 - 01733440 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
              2015-03-11 08:32 - 2015-01-28 17:41 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
              2015-03-11 08:32 - 2015-01-28 04:24 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\StorageContextHandler.dll
              2015-03-11 08:32 - 2015-01-28 03:47 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StorageContextHandler.dll
              2015-03-11 08:32 - 2015-01-27 06:22 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
              2015-03-11 08:32 - 2015-01-27 04:11 - 03547648 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
              2015-03-11 08:31 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
              2015-03-11 08:31 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
              2015-03-11 08:31 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
              2015-03-11 08:31 - 2015-02-21 02:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
              2015-03-11 08:31 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
              2015-03-11 08:31 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
              2015-03-11 08:31 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
              2015-03-11 08:31 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
              2015-03-11 08:31 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
              2015-03-11 08:31 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
              2015-03-11 08:31 - 2015-02-20 04:35 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
              2015-03-11 08:31 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
              2015-03-11 08:31 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
              2015-03-11 08:31 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
              2015-03-11 08:31 - 2015-02-20 04:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
              2015-03-11 08:31 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
              2015-03-11 08:31 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
              2015-03-11 08:31 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
              2015-03-11 08:31 - 2015-02-20 03:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
              2015-03-11 08:31 - 2015-02-20 03:56 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
              2015-03-11 08:31 - 2015-02-20 03:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
              2015-03-11 08:31 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
              2015-03-11 08:31 - 2015-02-20 03:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
              2015-03-11 08:31 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
              2015-03-11 08:31 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
              2015-03-11 08:31 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
              2015-03-11 08:31 - 2015-02-20 03:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
              2015-03-11 08:31 - 2015-02-20 03:29 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
              2015-03-11 08:31 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
              2015-03-11 08:31 - 2015-02-20 03:26 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
              2015-03-11 08:31 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
              2015-03-11 08:31 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
              2015-03-11 08:31 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
              2015-03-11 08:31 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
              2015-03-11 08:31 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
              2015-03-11 08:31 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
              2015-03-11 08:31 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
              2015-03-11 08:31 - 2015-02-06 03:28 - 02257408 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
              2015-03-11 08:31 - 2015-02-06 03:08 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
              2015-03-11 08:31 - 2015-02-03 02:03 - 03551744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
              2015-03-11 08:31 - 2015-02-03 02:02 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
              2015-03-11 08:31 - 2015-01-30 04:03 - 01488896 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
              2015-03-11 08:31 - 2015-01-30 04:03 - 01464832 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
              2015-03-11 08:31 - 2015-01-30 04:02 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
              2015-03-11 08:31 - 2015-01-30 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
              2015-03-11 08:31 - 2015-01-30 03:42 - 01204224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
              2015-03-11 08:31 - 2015-01-30 03:40 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll
              2015-03-11 08:31 - 2015-01-30 03:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
              2015-03-11 08:31 - 2015-01-30 03:29 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atlthunk.dll
              2015-03-11 08:31 - 2015-01-30 03:24 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
              2015-03-11 08:31 - 2015-01-30 03:24 - 00250880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll
              2015-03-11 08:31 - 2015-01-30 03:16 - 00266752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll
              2015-03-11 08:31 - 2015-01-30 03:08 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll
              2015-03-11 08:31 - 2015-01-30 03:06 - 00278016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll
              2015-03-11 08:31 - 2015-01-29 03:11 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
              2015-03-11 08:31 - 2015-01-29 03:00 - 00210944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
              2015-03-11 08:31 - 2015-01-29 02:55 - 00971776 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
              2015-03-11 08:31 - 2015-01-29 02:50 - 00811008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
              2015-03-11 08:30 - 2015-02-12 19:40 - 22291584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
              2015-03-11 08:30 - 2015-02-12 19:34 - 19731824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
              2015-03-11 08:30 - 2015-02-08 01:57 - 01090048 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
              2015-03-11 08:30 - 2015-02-08 01:49 - 00791040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
              2015-03-11 08:30 - 2015-01-29 20:45 - 01763352 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
              2015-03-11 08:30 - 2015-01-29 20:34 - 01488040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
              2015-03-11 08:30 - 2015-01-28 03:31 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
              2015-03-11 08:30 - 2015-01-28 03:11 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
              2015-03-11 08:30 - 2015-01-28 01:47 - 02501368 _____ (Microsoft Corporation) C:\Windows\explorer.exe
              2015-03-11 08:30 - 2015-01-28 01:41 - 02207488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
              2015-03-11 08:30 - 2015-01-21 07:54 - 01384712 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
              2015-03-11 08:30 - 2015-01-21 07:15 - 01123848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
              2015-03-11 08:30 - 2014-12-11 07:36 - 00046456 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContentServer.exe

              ==================== One Month Modified Files and Folders =======

              (If an entry is included in the fixlist, the file\folder will be moved.)

              2015-04-08 19:53 - 2013-06-02 15:49 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
              2015-04-08 19:51 - 2013-05-30 02:37 - 08306688 ___SH () C:\Users\Shirley\Desktop\Thumbs.db
              2015-04-08 19:49 - 2015-01-23 18:23 - 00004970 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for ShirleyPc-Shirley ShirleyPc
              2015-04-08 19:49 - 2013-10-22 22:08 - 00000000 ___RD () C:\Users\Shirley\SkyDrive
              2015-04-08 19:49 - 2013-05-30 08:05 - 02072064 ___SH () C:\Users\Shirley\Downloads\Thumbs.db
              2015-04-08 19:45 - 2014-02-01 12:06 - 00001148 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002UA.job
              2015-04-08 19:39 - 2014-12-27 23:58 - 01725715 _____ () C:\Windows\WindowsUpdate.log
              2015-04-08 19:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
              2015-04-08 18:23 - 2013-06-02 21:43 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4216991579-408556834-1651255799-1002
              2015-04-08 17:49 - 2015-02-12 11:24 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
              2015-04-08 17:49 - 2015-01-24 19:31 - 27619328 _____ () C:\Windows\system32\vmguest.iso
              2015-04-08 17:44 - 2013-06-02 23:19 - 00000922 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
              2015-04-08 17:38 - 2015-01-14 12:06 - 00003758 _____ () C:\Windows\System32\Tasks\AutoKMS
              2015-04-08 17:36 - 2014-06-17 10:12 - 00001062 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
              2015-04-08 17:35 - 2014-12-30 13:20 - 00242677 _____ () C:\Windows\setupact.log
              2015-04-08 17:35 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
              2015-04-08 17:35 - 2013-08-22 15:25 - 00786432 ___SH () C:\Windows\system32\config\BBI
              2015-04-08 17:35 - 2013-06-02 21:53 - 00000000 ____D () C:\ProgramData\NVIDIA
              2015-04-08 17:35 - 2013-06-02 14:50 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
              2015-04-08 17:33 - 2014-10-23 22:29 - 00000000 ____D () C:\Users\Shirley\AppData\Local\CrashDumps
              2015-04-08 17:33 - 2014-10-07 00:39 - 00000000 ____D () C:\Windows\system32\log
              2015-04-08 17:32 - 2014-02-01 12:06 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002Core.job
              2015-04-08 17:06 - 2013-06-15 08:49 - 00003942 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{637FDB08-565A-4D4F-BB38-298843C287CF}
              2015-04-08 16:53 - 2014-01-24 11:56 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
              2015-04-08 16:53 - 2013-11-13 21:47 - 00000000 ____D () C:\ProgramData\Oracle
              2015-04-08 16:52 - 2014-06-04 17:10 - 00000000 ____D () C:\Program Files (x86)\Java
              2015-04-08 16:52 - 2013-11-13 21:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
              2015-04-08 16:52 - 2013-09-08 17:17 - 00000000 ____D () C:\Program Files\Java
              2015-04-08 16:50 - 2014-06-04 17:10 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
              2015-04-08 16:50 - 2013-11-13 21:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
              2015-04-08 15:55 - 2013-06-02 23:27 - 00000000 ___RD () C:\Users\Shirley\Google Drive
              2015-04-08 11:53 - 2013-09-30 06:04 - 02012336 _____ () C:\Windows\system32\PerfStringBackup.INI
              2015-04-08 11:53 - 2013-06-02 21:56 - 00934014 _____ () C:\Windows\system32\perfh007.dat
              2015-04-08 11:53 - 2013-06-02 21:56 - 00203940 _____ () C:\Windows\system32\perfc007.dat
              2015-04-08 02:00 - 2014-08-20 18:35 - 00000000 ____D () C:\Users\Shirley\AppData\Local\Adobe
              2015-04-07 18:37 - 2014-09-08 12:07 - 00000000 ____D () C:\Users\Shirley\.VirtualBox
              2015-04-07 18:37 - 2014-05-28 08:02 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\ViberPC
              2015-04-07 18:35 - 2015-02-06 10:25 - 00000000 ____D () C:\Users\Shirley\AppData\Local\Viber
              2015-04-07 16:58 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
              2015-04-07 16:52 - 2013-10-22 21:28 - 00000000 ____D () C:\Users\Shirley
              2015-04-07 16:46 - 2015-02-21 14:51 - 536137995 _____ () C:\Windows\MEMORY.DMP
              2015-04-07 16:46 - 2015-02-21 14:51 - 00000000 ____D () C:\Windows\Minidump
              2015-04-06 10:28 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
              2015-04-05 10:27 - 2014-08-06 19:46 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A}
              2015-04-04 10:36 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
              2015-04-04 10:21 - 2014-07-07 07:10 - 00000000 ____D () C:\Users\Shirley\Desktop\Dossiers
              2015-04-04 09:26 - 2013-03-20 19:38 - 00000000 ___HD () C:\Users\Shirley\AppData\Local\STcnXkTbNVo
              2015-04-04 08:13 - 2015-03-05 21:00 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\vlc
              2015-04-04 06:44 - 2014-06-11 10:28 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\Youtube Downloader HD
              2015-04-02 01:36 - 2014-09-08 12:07 - 00000000 ____D () C:\Users\Shirley\VirtualBox VMs
              2015-03-26 17:26 - 2013-06-12 22:20 - 00000000 ____D () C:\Program Files\Common Files\Apple
              2015-03-25 08:11 - 2014-12-11 08:16 - 00000000 ____D () C:\Windows\system32\appraiser
              2015-03-25 08:11 - 2014-07-10 01:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
              2015-03-22 15:08 - 2014-01-13 08:39 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\Skype
              2015-03-22 13:15 - 2015-02-12 08:46 - 185035143 _____ () C:\Users\Shirley\Desktop\IP4 Top.psd
              2015-03-22 09:47 - 2015-01-08 17:00 - 05280720 _____ () C:\Windows\system32\FNTCACHE.DAT
              2015-03-22 09:45 - 2012-05-04 13:32 - 00000000 ___RD () C:\Users\Shirley\Desktop\Raccourcis
              2015-03-22 06:19 - 2013-05-30 09:21 - 00000000 ____D () C:\Android Roms and Files
              2015-03-17 18:00 - 2013-06-02 15:49 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
              2015-03-17 06:15 - 2015-02-12 11:24 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
              2015-03-17 06:15 - 2015-02-12 11:24 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
              2015-03-17 06:15 - 2015-02-12 11:24 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
              2015-03-15 14:47 - 2014-10-11 08:10 - 00000000 ____D () C:\Users\Shirley\dwhelper
              2015-03-14 06:30 - 2013-07-24 05:52 - 00000000 ____D () C:\Windows\system32\MRT
              2015-03-14 06:07 - 2013-06-21 08:45 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
              2015-03-13 19:50 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
              2015-03-13 08:38 - 2015-01-13 08:44 - 00029446 _____ () C:\Windows\PFRO.log
              2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
              2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
              2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
              2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
              2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore
              2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
              2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender
              2015-03-12 22:31 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
              2015-03-12 20:24 - 2013-06-03 18:10 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\uTorrent
              2015-03-12 20:19 - 2014-02-22 08:39 - 00000000 __SHD () C:\Users\Public\DRM
              2015-03-12 20:18 - 2014-03-16 06:25 - 00000000 ____D () C:\ProgramData\VideoCopilot
              2015-03-11 16:49 - 2013-05-30 06:57 - 00589824 ___SH () C:\Users\Shirley\Documents\Thumbs.db
              2015-03-11 13:27 - 2015-01-14 11:58 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
              2015-03-11 13:27 - 2013-06-15 09:43 - 00000000 ____D () C:\ProgramData\Microsoft Help
              2015-03-11 08:22 - 2012-07-26 07:26 - 00000167 _____ () C:\Windows\win.ini
              2015-03-10 17:53 - 2014-09-23 17:10 - 00003102 _____ () C:\Windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-4216991579-408556834-1651255799-1002
              2015-03-09 08:28 - 2013-08-19 06:41 - 00000000 ____D () C:\Users\Shirley\AppData\Roaming\Mp3tag

              ==================== Files in the root of some directories =======

              2014-03-20 13:53 - 2014-03-20 13:53 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
              2013-09-05 22:52 - 2013-09-05 22:52 - 0000132 _____ () C:\Users\Shirley\AppData\Roaming\Adobe BMP Format CS6 Prefs
              2013-08-17 11:50 - 2014-09-18 10:25 - 0000132 _____ () C:\Users\Shirley\AppData\Roaming\Adobe PNG Format CS6 Prefs
              2014-09-08 11:55 - 2014-09-08 11:55 - 1177208 _____ () C:\Users\Shirley\AppData\Roaming\AndyCleanupTool.exe
              2014-09-08 11:55 - 2014-09-08 11:55 - 1176696 _____ () C:\Users\Shirley\AppData\Roaming\AndyCleanVM.exe
              2014-10-07 08:48 - 2015-01-04 01:37 - 0017408 ___SH () C:\Users\Shirley\AppData\Roaming\Thumbs.db
              2013-10-01 11:19 - 2014-04-28 11:08 - 0319449 _____ () C:\Users\Shirley\AppData\Roaming\UserTile.png
              2014-01-24 10:41 - 2014-12-28 11:01 - 0000600 _____ () C:\Users\Shirley\AppData\Roaming\winscp.rnd
              2013-08-30 21:26 - 2014-09-28 13:22 - 0055808 _____ () C:\Users\Shirley\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
              2014-09-04 06:52 - 2014-09-04 06:52 - 0000095 _____ () C:\Users\Shirley\AppData\Local\fusioncache.dat
              2014-02-18 09:25 - 2014-09-04 09:57 - 0000600 _____ () C:\Users\Shirley\AppData\Local\PUTTY.RND
              2014-10-13 10:22 - 2014-10-13 10:22 - 0000017 _____ () C:\Users\Shirley\AppData\Local\resmon.resmoncfg
              2015-02-17 01:03 - 2015-02-17 01:03 - 0017408 _____ () C:\Users\Shirley\AppData\Local\WebpageIcons.db
              2015-01-14 13:48 - 2015-01-14 13:48 - 0740775 _____ () C:\ProgramData\AndyDrivers.zip
              2013-09-24 16:11 - 2014-09-28 13:20 - 0000000 _____ () C:\ProgramData\CLDShowX.ini
              2013-06-02 22:05 - 2013-06-02 22:05 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
              2014-06-30 19:27 - 2014-06-30 19:27 - 0000104 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.64.bc

              Some content of TEMP:
              ====================
              C:\Users\Shirley\AppData\Local\Temp\avg_tuht_stf_all_2015_238.exe
              C:\Users\Shirley\AppData\Local\Temp\i4jdel0.exe
              C:\Users\Shirley\AppData\Local\Temp\Quarantine.exe
              C:\Users\Shirley\AppData\Local\Temp\SkypeSetup.exe
              C:\Users\Shirley\AppData\Local\Temp\sqlite3.dll


              ==================== Bamital & volsnap Check =================

              (There is no automatic fix for files that do not pass verification.)

              C:\Windows\System32\winlogon.exe => File is digitally signed
              C:\Windows\System32\wininit.exe => File is digitally signed
              C:\Windows\explorer.exe => File is digitally signed
              C:\Windows\SysWOW64\explorer.exe => File is digitally signed
              C:\Windows\System32\svchost.exe => File is digitally signed
              C:\Windows\SysWOW64\svchost.exe => File is digitally signed
              C:\Windows\System32\services.exe => File is digitally signed
              C:\Windows\System32\User32.dll => File is digitally signed
              C:\Windows\SysWOW64\User32.dll => File is digitally signed
              C:\Windows\System32\userinit.exe => File is digitally signed
              C:\Windows\SysWOW64\userinit.exe => File is digitally signed
              C:\Windows\System32\rpcss.dll => File is digitally signed
              C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


              LastRegBack: 2015-04-08 18:23

              ==================== End Of Log ============================

              Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
              Ran by [removed] at 2015-04-08 19:53:33
              Running from C:\Users\[removed]\Desktop
              Boot Mode: Normal
              ==========================================================


              ==================== Security Center ========================

              (If an entry is included in the fixlist, it will be removed.)

              AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
              AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

              ==================== Installed Programs ======================

              (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

              µTorrent (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\uTorrent) (Version: 3.4.2.38656 - BitTorrent Inc.)
              7-Zip 9.20 (HKLM-x32\…\7-Zip) (Version:  - )
              8oot Logo Changer version 1.2.09 (HKLM\…\{9513750B-9392-4A03-8074-9EEF890B9A41}_is1) (Version: 1.2.09 - Codigobit.info)
              A1 Servicecenter (HKLM-x32\…\A1 Servicecenter) (Version: 1.4.0.43 - A1 Telekom Austria AG)
              Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.2.443 - Adobe Systems Incorporated)
              Acrobat.com (x32 Version: 0.0.0 - Adobe Systems Incorporated) Hidden
              Adobe After Effects CC 2014 (HKLM-x32\…\{2B22C750-5C3B-4738-B621-BA786AC7A494}) (Version: 13.1.0 - Adobe Systems Incorporated)
              Adobe After Effects CS6 (HKLM-x32\…\{4817D846-700B-474E-A31B-80892B3E92E3}) (Version: 11 - Adobe Systems Incorporated)
              Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
              Adobe Anchor Service x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
              Adobe CMaps x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
              Adobe Creative Cloud (HKLM-x32\…\Adobe Creative Cloud) (Version: 2.7.1.418 - Adobe Systems Incorporated)
              Adobe Creative Suite 4 Master Collection (HKLM-x32\…\Adobe_b2d6abde968e6f277ddbfd501383e02) (Version: 4.0 - Adobe Systems Incorporated)
              Adobe CSI CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
              Adobe Drive CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
              Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
              Adobe Fonts All x64 (Version: 2.0 - Adobe Systems Incorporated) Hidden
              Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
              Adobe Linguistics CS4 x64 (Version: 4.0.0 - Adobe Systems Incorporated) Hidden
              Adobe Media Player (HKLM-x32\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
              Adobe PDF Library Files x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
              Adobe Photoshop CC 2014 (HKLM-x32\…\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.2 - Adobe Systems Incorporated)
              Adobe Photoshop CS4 (64 Bit) (Version: 11.0 - Adobe Systems Incorporated) Hidden
              Adobe Photoshop CS6 (HKLM-x32\…\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
              Adobe Premiere Pro CS6 (HKLM-x32\…\{7176B973-6011-43C1-AEBC-2D73FE7C6982}) (Version: 6.0 - Adobe Systems Incorporated)
              Adobe Type Support x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
              Adobe WinSoft Linguistics Plugin x64 (Version: 1.1 - Adobe Systems Incorporated) Hidden
              A-Men Technologies USB-to-Serial (HKLM-x32\…\{1805BD6D-C441-4A1C-802D-AFF0232DAACD}) (Version:  - )
              Andy OS (HKLM-x32\…\Andy OS) (Version: 0.42 - Andy OS, Inc)
              Apple Application Support (32-Bit) (HKLM-x32\…\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.)
              Apple Application Support (64-Bit) (HKLM\…\{0DF7096B-715A-4233-8633-C7A16ED6D616}) (Version: 3.1.2 - Apple Inc.)
              Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
              Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
              ASUS Ai Charger (HKLM-x32\…\{7FB64E72-9B0E-4460-A821-040C341E414A}) (Version: 1.03.00 - ASUSTeK Computer Inc.)
              AVG PC TuneUp 2015 (de-DE) (x32 Version: 15.0.1001.403 - AVG Technologies) Hidden
              AviSynth (HKLM-x32\…\AviSynth) (Version: 2.6.0 MT - )
              bl (x32 Version: 1.0.0 - Your Company Name) Hidden
              Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
              Boot Animation Creator (HKLM-x32\…\{1B5CD3FA-DC33-4600-BD0F-1598CF4C296C}) (Version: 1.4.0.0 - D01 MicroApps)
              Boot Animation Factory (HKLM-x32\…\{3EA00EEB-27DE-4507-AFF4-0C697A20C37B}) (Version: 1.4.1.0 - D01 MicroApps)
              Camtasia Studio 8 (HKLM-x32\…\{A7727F03-5311-4A12-9A63-2ACD20BA0497}) (Version: 8.2.1.1423 - TechSmith Corporation)
              CCleaner (HKLM\…\CCleaner) (Version: 5.00 - Piriform)
              CDBurnerXP (HKLM-x32\…\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4291 - CDBurnerXP)
              Connect (x32 Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
              ConvertHelper 2.2 (HKLM-x32\…\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1) (Version:  - DownloadHelper)
              CopyTrans Suite désinstallation uniquement (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\CopyTrans Suite) (Version: 2.37 - WindSolutions)
              CPUID CPU-Z 1.70 (HKLM\…\CPUID CPU-Z_is1) (Version:  - )
              CyberLink PowerDVD 13 (HKLM-x32\…\InstallShield_{3CFDF154-7E60-4E98-A8DF-C693A4F8E6B6}) (Version: 13.0.2720.57 - CyberLink Corp.)
              CyberLink YouCam 6 (HKLM-x32\…\{A9CEDD6E-4792-493e-BB35-D86D2E188A5A}) (Version: 6.0.2728.0 - CyberLink Corp.)
              Dolby Advanced Audio v2 (HKLM-x32\…\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.8000.16 - Dolby Laboratories Inc)
              Dropbox (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Dropbox) (Version: 2.8.4 - Dropbox, Inc.)
              EasyBCD 2.2 (HKLM-x32\…\EasyBCD) (Version: 2.2 - NeoSmart Technologies)
              ffdshow x64 v1.3.4515 [2013-06-12] (HKLM\…\ffdshow64_is1) (Version: 1.3.4515.0 - )
              FlashBoot 2.2e (HKLM\…\FlashBoot_is1) (Version:  - Mikhail Kupchik)
              GnuWin32: Gzip-1.3.12-1 (HKLM-x32\…\Gzip-1.3.12-1_is1) (Version: 1.3.12-1 - GnuWin32)
              Google Chrome (HKLM-x32\…\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
              Google Drive (HKLM-x32\…\{C60F3836-333A-4AE2-B526-CFDBA143A9BA}) (Version: 1.18.7821.2489 - Google, Inc.)
              Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
              Google+ Auto Backup (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Google+ Auto Backup) (Version: 1.0.26.151 - Google, Inc.)
              HHD Software Hex Editor Neo 6.10 (HKLM\…\{8EB85C0E-DE7D-4A53-BD66-708B8F2C80B0}) (Version: 6.10.2.5330 - HHD Software, Ltd.)
              Home Media Center x64 (HKLM\…\{BA5FF534-12B0-4E6A-A6EE-36E0E951AC0E}) (Version: 2.5.0 - Tomáš Pšenák)
              HTC Driver Installer (HKLM-x32\…\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.10.0.001 - HTC Corporation)
              iCloud (HKLM\…\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)
              iFunbox (v2.7.2386.747), iFunbox DevTeam (HKLM-x32\…\iFunbox_is1) (Version: v2.7.2386.747 - )
              Image Composite Editor (HKLM\…\{92AB5708-1AAA-4B1B-A8D5-45CF3AD77519}) (Version: 2.0.3 - Microsoft Corporation)
              Imagistik Doc2pix (HKLM-x32\…\{CF29E86C-BD82-4DF5-9C00-FB7EA8F15B28}) (Version: 1.0.0 - Informatik Inc)
              Intel Android Device USB driver (HKLM\…\Intel Android Device USB driver) (Version: 1.2.0 - Intel)
              iSocUSB Driver 1.0.2 (HKLM\…\iSocUSB Driver_is1) (Version: 1.0.1 - Intel Corporation 2012)
              iTunes (HKLM\…\{D227565A-0033-40AD-89BA-653A205CDC11}) (Version: 12.1.1.4 - Apple Inc.)
              Java 8 Update 40 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
              Java(TM) SE Development Kit 6 Update 45 (64-bit) (HKLM\…\{64A3A4F4-B792-11D6-A78A-00B0D0160450}) (Version: 1.6.0.450 - Oracle)
              kuler (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
              Lenovo K900 Device Drivers (HKLM-x32\…\{CE03FF91-455C-4C9E-AEB7-CAFE959811CD}) (Version: 5.0.18 - Lenovo)
              Lenovo USB2.0 UVC Camera (HKLM-x32\…\{70D2C5B8-EB22-45B1-9EAA-5E8C1C408A3B}) (Version: 1.00.0000 - Vimicro Corporation)
              LenovoUsbDriver 1.0.0 (HKLM-x32\…\LenovoUsbDriver) (Version: 1.0.0 - Lenovo)
              LOGO!Soft Comfort V8.0 (Demo) (HKLM\…\LOGO!Soft Comfort V8.0 (Demo)) (Version: 8.0.0.0 - Siemens AG)
              Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
              Manufacturing Flash Tool version 6.0.2 (HKLM-x32\…\Manufacturing Flash Tool_is1) (Version: 6.0.2 - Intel Corporation)
              MD5 Checksum 1.1 (HKLM-x32\…\MD5 Checksum_is1) (Version:  - Okaryn)
              MedienManager 1.5.1 (HKLM-x32\…\8781-9705-0578-2960) (Version: 1.5.1 - A1 Telekom Austria AG)
              Microsoft .NET Framework 1.1 (HKLM-x32\…\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
              Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
              Microsoft Office Korrekturhilfen 2013 - Deutsch (HKLM\…\{90150000-001F-0407-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
              Microsoft Office Korrekturhilfen 2013 - Deutsch (HKLM-x32\…\{90150000-001F-0407-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
              Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
              Microsoft OneDrive (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\OneDriveSetup.exe) (Version: 17.3.4726.0226 - Microsoft Corporation)
              Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
              Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
              Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
              Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
              Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
              Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
              Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
              Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
              Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
              Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
              Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
              Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
              MiniTool Partition Wizard Home Edition 8.1.1 (HKLM-x32\…\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version:  - MiniTool Solution Ltd.)
              Mozilla Firefox 37.0.1 (x86 fr) (HKLM-x32\…\Mozilla Firefox 37.0.1 (x86 fr)) (Version: 37.0.1 - Mozilla)
              Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
              Mp3tag v2.64 (HKLM-x32\…\Mp3tag) (Version: v2.64 - Florian Heidenreich)
              MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
              MTK_SN_Write (HKLM-x32\…\{0EEBC2F2-7436-4024-8E3D-FE33041C0AF4}) (Version: 1.0.0 - MediaTek)
              Music Manager (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\MusicManager) (Version:  - Google, Inc.)
              NAVIGON Fresh 3.4.1 (HKLM-x32\…\NAVIGON Fresh) (Version: 3.4.1 - NAVIGON)
              Nero 2014 (HKLM-x32\…\{F384C1E1-3A16-4073-95C3-7271FE0ED4C2}) (Version: 15.0.02200 - Nero AG)
              Notepad++ (HKLM-x32\…\Notepad++) (Version: 6.6.8 - Notepad++ Team)
              NVIDIA 3D Vision Driver 327.02 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 327.02 - NVIDIA Corporation)
              NVIDIA GeForce Experience 2.1.1.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1.1 - NVIDIA Corporation)
              NVIDIA Graphics Driver 327.02 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.02 - NVIDIA Corporation)
              NVIDIA HD Audio Driver 1.3.26.4 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)
              Opera Stable 24.0.1558.53 (HKLM-x32\…\Opera 24.0.1558.53) (Version: 24.0.1558.53 - Opera Software ASA)
              Oracle VM VirtualBox 4.3.26 (HKLM\…\{5771F59A-BFC9-4FAF-A883-7642EF4BA3C3}) (Version: 4.3.26 - Oracle Corporation)
              Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
              Package: Galaxy Nexus ToolKit [JellyBean Edition] (HKLM-x32\…\GalaxyNexusToolKit11) (Version: 1.0.0.0 - skipsoft)
              PdaNet+ for Android 4.15 (HKLM-x32\…\PdaNet_is1) (Version:  - June Fabrics Technology Inc)
              PDF Settings CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden
              PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
              PDFCreator (HKLM\…\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.9.2 - pdfforge)
              ph (x32 Version: 1.0.0 - Your Company Name) Hidden
              Photoshop Camera Raw (x32 Version: 5.0 - Adobe Systems Incorporated) Hidden
              Photoshop Camera Raw_x64 (Version: 5.0 - Adobe Systems Incorporated) Hidden
              Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
              Pixel Bender Toolkit (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
              PL-2303 USB-to-Serial (HKLM-x32\…\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.8.12 - Prolific Technology INC)
              plist Editor Pro 2.1.0 (HKLM-x32\…\plist Editor Pro) (Version: 2.1.0 - VOWSoft, Ltd.)
              Prerequisite installer (x32 Version: 15.0.0005 - Nero AG) Hidden
              QQ International (HKLM-x32\…\{3CA54984-A14B-42FE-9FF1-7EA90151D725}) (Version: 1.91.1369.0 - Tencent Technology(Shenzhen) Company Limited)
              QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
              Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6695 - Realtek Semiconductor Corp.)
              Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.8400.29025 - Realtek Semiconductor Corp.)
              Red Giant Complete Suite (HKLM\…\{DAFB22DD-9F96-4F76-AFCC-86A0980CA737}) (Version: 11 - Red Giant Software)
              Red Giant Psunami (HKLM-x32\…\InstallShield_{97F381E0-CCC3-4F22-9078-033CBC597391}) (Version: 1.4.0 - Red Giant Software)
              Red Giant Psunami (Version: 1.4.0 - Red Giant Software) Hidden
              Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
              RW-Everything v1.6.5.9 (HKLM\…\RW-Everything_is1) (Version:  - )
              Safari (HKLM-x32\…\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
              SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.27.0 - SAMSUNG Electronics Co., Ltd.)
              Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\…\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version:  - Microsoft)
              Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version:  - Microsoft) Hidden
              Serviio (HKLM\…\Serviio) (Version:  - )
              SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden
              Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM-x32\…\SLABCOMM&10C4&EA60;) (Version:  - Silicon Laboratories)
              Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7 (HKLM-x32\…\{7BA7F29A-9F23-46A3-8BF6-4F9360BB4834}) (Version: 6.2.00 - Silicon Laboratories, Inc.)
              Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
              Sndbad Shaders 1.03 (HKLM-x32\…\Sndbad Shaders 1.03) (Version: 1.03 - Sndbad)
              SQLite Expert Personal 3.5.51 (HKLM-x32\…\SQLite Expert Personal 3_is1) (Version:  - Bogdan Ureche)
              SRS-Root (HKLM-x32\…\{24EAD272-D05D-4950-BD59-F88AB7B4C8C7}_is1) (Version:  - 123Unlock GSM Service)
              Suite Shared Configuration CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
              ToneSync for Windows (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\c2c9648a374f64d1) (Version: 1.2.3.309 - Zedge Europe AS)
              Ultra Key (HKLM-x32\…\{995237D9-6E24-45D9-9B06-C13AA62F518B}) (Version: 1.0.2077.1 - Serious Magic, Inc.)
              ULTRA Program Files (x32 Version: 1.25.2224.0 - Serious Magic, Inc.) Hidden
              VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
              Viber (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\Viber) (Version: 5.0.0.2821 - Viber Media Inc)
              Virtual DJ Pro Full - Atomix Productions (HKLM-x32\…\Virtual DJ Pro Full - Atomix Productions) (Version:  - )
              VLC media player (HKLM\…\VLC media player) (Version: 2.2.0 - VideoLAN)
              VoipConnect (HKLM-x32\…\VoipConnect_is1) (Version: 4.14 build 760 - Finarea S.A. Switzerland)
              Watchtower Library 2012 - English (HKLM-x32\…\{11B5A3EB-8B76-46A9-A4B7-1C1FF5A3AAFD}) (Version: 14.0 - Watchtower Bible and Tract Society of Pennsylvania, Inc.)
              Watchtower Library 2012 - Français (HKLM-x32\…\{429C765D-42CC-4F2A-A6CA-2737630E502A}) (Version: 14.0 - Watchtower Bible and Tract Society of Pennsylvania, Inc.)
              Windows 8 Codec Pack 2.0.1 (HKLM-x32\…\Windows 8 - Codec Pack) (Version: 2.0.1 - Windows 8 Codec Pack)
              WinRAR 4.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
              WinSCP 5.5.6 (HKLM-x32\…\winscp3_is1) (Version: 5.5.6 - Martin Prikryl)
              Wondershare Video Converter Ultimate(Build 7.1.3.3) (HKLM-x32\…\Wondershare Video Converter Ultimate_is1) (Version: 7.1.3.3 - Wondershare Software)
              XBMC (HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\XBMC) (Version:  - Team XBMC)
              xFSTK-Downloader 1.3.6 (HKLM-x32\…\{07E546A1-1CB6-497F-B6F4-BF5F0A4524C6}_is1) (Version: 1.3.6 - Intel Corporation 2012)
              Xilisoft Convertisseur Vidéo Ultimate (HKLM-x32\…\Xilisoft Convertisseur Vidéo Ultimate) (Version: 7.8.0.20140401 - Xilisoft)
              Xilisoft DVD Ripper Platinum (HKLM-x32\…\Xilisoft DVD Ripper Platinum) (Version: 7.8.5.20141031 - Xilisoft)
              Xilisoft DVD Ripper Ultimate (HKLM-x32\…\Xilisoft DVD Ripper Ultimate) (Version: 7.8.5.20141031 - Xilisoft)
              Xvid Video Codec (HKLM-x32\…\Xvid Video Codec 1.3.3) (Version: 1.3.3 - Xvid Team)
              Youtube Downloader HD v. 2.9.9.21 (HKLM-x32\…\Youtube Downloader HD_is1) (Version:  - YoutubeDownloaderHD.com)
              百度云管家 (HKLM-x32\…\百度云管家) (Version: 5.0.0 - 百度在线网络技术北京有限公司)

              ==================== Custom CLSID (selected items): ==========================

              (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

              CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Shirley\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
              CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{679F137C-3162-45da-BE3C-2F9C3D093F64}\InprocServer32 -> C:\Windows\system32\shdocvw.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Shirley\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.)
              CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Shirley\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.)
              CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Shirley\AppData\Local\Microsoft\OneDrive\17.3.4726.0226\amd64\FileSyncApi64.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
              CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
              CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
              CustomCLSID: HKU\S-1-5-21-4216991579-408556834-1651255799-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shirley\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)

              ==================== Restore Points  =========================


              ==================== Hosts content: ==========================

              (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

              2013-08-22 15:25 - 2014-11-28 13:51 - 00006914 ____R C:\Windows\system32\Drivers\etc\hosts
              127.0.0.1       localhost
              127.0.0.1 activation.cloud.techsmith.com
              127.0.0.1 lmlicenses.wip4.adobe.com
              127.0.0.1 lm.licenses.adobe.com
              127.0.0.1 na1r.services.adobe.com
              127.0.0.1 na2m-pr.licenses.adobe.com
              127.0.0.1 na4r.services.adobe.com
              127.0.0.1 ims-na1-prprod.adobelogin.com
              127.0.0.1 activate.adobe.com
              127.0.0.1 practivate.adobe.com
              127.0.0.1 practivate.adobe.de
              127.0.0.1 209-34-83-73.ood.opsource.net
              127.0.0.1 3dns.adobe.com
              127.0.0.1 3dns-1.adobe.com
              127.0.0.1 3dns-2.adobe.com
              127.0.0.1 3dns-3.adobe.com
              127.0.0.1 3dns-4.adobe.com
              127.0.0.1 3dns-5.adobe.com
              127.0.0.1 activate-sea.adobe.com
              127.0.0.1 activate-sea.adobe.de
              127.0.0.1 activate-sjc0.adobe.com
              127.0.0.1 activate-sjc0.adobe.de
              127.0.0.1 activate.adobe.de
              127.0.0.1 activate.wip.adobe.com
              127.0.0.1 activate.wip1.adobe.com
              127.0.0.1 activate.wip2.adobe.com
              127.0.0.1 activate.wip3.adobe.com
              127.0.0.1 activate.wip3.adobe.de
              127.0.0.1 activate.wip4.adobe.com

              There are 110 more lines.


              ==================== Scheduled Tasks (whitelisted) =============

              (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

              Task: {055019F0-6336-4010-9AA7-C8DBFC8F0652} - System32\Tasks\Opera scheduled Autoupdate 1409914763 => C:\Program Files (x86)\Opera\launcher.exe [2014-08-27] (Opera Software)
              Task: {08EA715B-1E50-444E-84FA-F41487EA0392} - System32\Tasks\Microsoft Office 15 Sync Maintenance for ShirleyPc-Shirley ShirleyPc => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation)
              Task: {189FC402-BA0B-41E8-A30B-80C214C0132D} - System32\Tasks\{4F4F4C32-6DEA-46A1-928E-6246C74CF74F} => pcalua.exe -a "C:\Program Files (x86)\Foxy Games\Jewel Quest Mysteries The Oracle of Ur Collectors Edition\JQM4_PremiumEdition.exe" -d "C:\Program Files (x86)\Foxy Games\Jewel Quest Mysteries The Oracle of Ur Collectors Edition"
              Task: {197AE8F0-E43C-439B-9E2E-DA1990C369CA} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
              Task: {1C4C8A12-9C8C-4E41-8AD3-6BBF975858BE} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
              Task: {1F9D90E6-6469-42F3-8BCE-51B0EE34378D} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-17] (Adobe Systems Incorporated)
              Task: {24BD1A31-4707-4F3B-A3F1-C8D1D4E25E40} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-02] (Google Inc.)
              Task: {3503F2CB-5D56-49BB-B574-17FB77F2A492} - System32\Tasks\Hotspot => C:\Users\Shirley\Desktop\Hotspot.bat [2014-12-01] ()
              Task: {37D3D033-BC9E-4C6A-925C-9385D2012795} - System32\Tasks\{80BE5F49-06DA-43D8-BB09-9872E20A8742} => pcalua.exe -a "C:\Android Roms and Files\Zopo C2\zopo 980 root\MT6589 USB VCOM drivers\installdrv.exe" -d "C:\Android Roms and Files\Zopo C2\zopo 980 root\MT6589 USB VCOM drivers"
              Task: {39FBCD69-7180-4721-A972-E1CBF98C6E9E} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
              Task: {4308D988-0874-4406-B88F-0E29CC77C501} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
              Task: {50795312-8AE0-4567-B175-68A08C416F89} - System32\Tasks\{62392E8F-62C1-4653-A05F-B0053DE921EB} => pcalua.exe -a "C:\Program Files (x86)\Nightly\uninstall\helper.exe"
              Task: {5E6A1FB4-F26F-4BD9-B278-5EB392208726} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation)
              Task: {63F92630-27C6-47AA-A1C1-5097A06526E0} - System32\Tasks\{41126E1B-8014-4F05-9AEB-BC7E6A41D857} => pcalua.exe -a "C:\Android Roms and Files\GT-I9250\Verizon_Wireless_I515_Galaxy_Nexus_USB_Driver_v1.4.6.0.exe" -d "C:\Android Roms and Files\GT-I9250"
              Task: {66D357E6-F618-4AA2-BAA1-B8094808F331} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
              Task: {722A872A-4004-477E-84CC-798B4A36531B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002Core => C:\Users\Shirley\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-01] (Google Inc.)
              Task: {7D517F94-C030-493A-AB91-31E8FE7DEEA1} - System32\Tasks\AdobeAAMUpdater-1.0-ShirleyPc-Shirley => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated)
              Task: {909451AE-83BA-4755-8081-82D5BA2DB9E9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002UA => C:\Users\Shirley\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-01] (Google Inc.)
              Task: {99254725-4827-4097-A630-AD11672697B1} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe [2015-01-14] ()
              Task: {9D92366F-3024-4D2A-BD9C-395A36301FA9} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
              Task: {A843E403-DE2F-442A-8224-3EC21F93D59C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-02] (Google Inc.)
              Task: {B2E63838-BDA9-4996-AE18-6909097AEC74} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-03-14] (Microsoft Corporation)
              Task: {B79CD473-AA29-4F14-A943-15D5AD509421} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-11-21] (Piriform Ltd)
              Task: {C03FB9D1-0C9F-4760-913E-7B291C1A5346} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
              Task: {E37C89C5-7B52-47FD-B036-F2D78054FB6B} - System32\Tasks\{62D1C3FB-E98E-4B6C-AB02-1A03E4150C4C} => pcalua.exe -a "C:\Android Roms and Files\Samsung\P5100\SAMSUNG_USB_Driver_for_Mobile_Phones\SAMSUNG_USB_Driver_for_Mobile_Phones.exe" -d "C:\Android Roms and Files\Samsung\P5100\SAMSUNG_USB_Driver_for_Mobile_Phones"
              Task: {E8AD0A98-451D-46E8-9882-7468E164B98A} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
              Task: {F3AF6FA2-762C-42E7-8FF0-EC045A3F7E3D} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2013-08-20] (Nero AG)
              Task: {FCB2AB10-08FC-4C47-8D6B-95819C8DCC1B} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-4216991579-408556834-1651255799-1002 => %localappdata%\Microsoft\OneDrive\OneDrive.exe
              Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
              Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
              Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
              Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002Core.job => C:\Users\Shirley\AppData\Local\Google\Update\GoogleUpdate.exe
              Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4216991579-408556834-1651255799-1002UA.job => C:\Users\Shirley\AppData\Local\Google\Update\GoogleUpdate.exe

              ==================== Loaded Modules (whitelisted) ==============

              2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
              2015-01-20 23:35 - 2015-01-20 23:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
              2014-07-16 11:06 - 2014-07-16 11:06 - 00672416 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
              2015-01-21 16:01 - 2015-01-21 16:01 - 08898728 _____ () C:\Program Files\Microsoft Office\OFFICE15\1033\GrooveIntlResource.dll
              2014-08-06 20:08 - 2013-08-23 13:36 - 00721263 _____ () C:\WINDOWS\SysWOW64\WSCM64.dll
              2014-05-12 11:49 - 2014-05-12 11:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
              2013-10-17 16:27 - 2013-10-17 16:27 - 00166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
              2015-01-20 23:35 - 2015-01-20 23:35 - 00306984 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll
              2014-11-25 10:24 - 2014-11-25 10:24 - 00183296 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\ErrorReporting.dll
              2014-11-27 09:49 - 2014-11-25 08:39 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libglesv2.dll
              2014-11-27 09:49 - 2014-11-25 08:39 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libegl.dll
              2014-11-27 09:49 - 2014-11-25 08:39 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\pdf.dll
              2014-11-27 09:49 - 2014-11-25 08:39 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\ffmpegsumo.dll
              2014-11-27 09:49 - 2014-11-25 08:39 - 14910280 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\PepperFlash\pepflashplayer.dll
              2015-01-20 23:35 - 2015-01-20 23:35 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
              2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

              ==================== Alternate Data Streams (whitelisted) =========

              (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

              AlternateDataStreams: C:\ProgramData\CLDShowX.ini:Update.CL
              AlternateDataStreams: C:\ProgramData\TEMP:C59E90A4
              AlternateDataStreams: C:\Users\Public\DRM:احتضان
              AlternateDataStreams: C:\Users\Shirley\Local Settings:OXEofcKuEKDCKMGkMwy1Z
              AlternateDataStreams: C:\Users\Shirley\Lokale Einstellungen:OXEofcKuEKDCKMGkMwy1Z
              AlternateDataStreams: C:\Users\Shirley\SkyDrive:ms-properties
              AlternateDataStreams: C:\Users\Shirley\AppData\Local:OXEofcKuEKDCKMGkMwy1Z
              AlternateDataStreams: C:\Users\Shirley\AppData\Local\Application Data:OXEofcKuEKDCKMGkMwy1Z
              AlternateDataStreams: C:\Users\Shirley\AppData\Local\STcnXkTbNVo:wU2DzwpyzrD8rYS3besrGzuu
              AlternateDataStreams: C:\Users\Shirley\AppData\Local\Temporary Internet Files:02A3eqQaBCOOu8y6CduPT
              AlternateDataStreams: C:\Users\Shirley\Documents\semena.DAT:SummaryInformation
              AlternateDataStreams: C:\Users\Shirley\Documents\semena.DAT:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

              ==================== Safe Mode (whitelisted) ===================

              (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


              ==================== EXE Association (whitelisted) ===============

              (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


              ==================== Other Areas ============================

              (Currently there is no automatic fix for this section.)

              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
              DNS Servers: 10.0.0.138 - 8.8.8.8

              ==================== MSCONFIG/TASK MANAGER disabled items ==

              (Currently there is no automatic fix for this section.)

              HKLM\…\StartupApproved\StartupFolder: => "TrayMenu.lnk"
              HKLM\…\StartupApproved\StartupFolder: => "Universal Media Server.lnk"
              HKLM\…\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
              HKLM\…\StartupApproved\Run: => "ShadowPlay"
              HKLM\…\StartupApproved\Run: => "iTunesHelper"
              HKLM\…\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
              HKLM\…\StartupApproved\Run32: => "AdobeCS6ServiceManager"
              HKLM\…\StartupApproved\Run32: => "SwitchBoard"
              HKLM\…\StartupApproved\Run32: => "Acrobat Assistant 8.0"
              HKLM\…\StartupApproved\Run32: => "Adobe Acrobat Speed Launcher"
              HKLM\…\StartupApproved\Run32: => "AdobeCS4ServiceManager"
              HKLM\…\StartupApproved\Run32: => "APSDaemon"
              HKLM\…\StartupApproved\Run32: => "iTunesHelper"
              HKLM\…\StartupApproved\Run32: => "BCSSync"
              HKLM\…\StartupApproved\Run32: => "QuickTime Task"
              HKLM\…\StartupApproved\Run32: => "PowerDVD13Agent"
              HKLM\…\StartupApproved\Run32: => "A1Diagnose"
              HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
              HKLM\…\StartupApproved\Run32: => "BlueStacks Agent"
              HKLM\…\StartupApproved\Run32: => "DelaypluginInstall"
              HKLM\…\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
              HKLM\…\StartupApproved\Run32: => "DivXMediaServer"
              HKLM\…\StartupApproved\Run32: => "DivXUpdate"
              HKLM\…\StartupApproved\Run32: => "YouCam Service6"
              HKLM\…\StartupApproved\Run32: => "Adobe Creative Cloud"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\StartupFolder: => "wandoujia_helper.lnk"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\StartupFolder: => "openSUSE-uninst.exe"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\StartupFolder: => "Dropbox.lnk"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\StartupFolder: => "Universal Media Server.lnk"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "AdobeBridge"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "aliim"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "ApplePhotoStreams"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "com.apple.dav.bookmarks.daemon"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "iCloudServices"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "MouseServer"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "Facebook Update"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "AliMessageTool96d72d182352859f0fb0f4a6b5e2fea8"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "Google Update"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "MusicManager"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "ZedgeToneSync"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "ALLMediaServer"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "Google+ Auto Backup"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "Xvid"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "BaiduYunGuanjia"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "ServUTrayIcon"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "CCleaner Monitoring"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "VoipConnect"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "iCloudDrive"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "*LABAL*"
              HKU\S-1-5-21-4216991579-408556834-1651255799-1002\…\StartupApproved\Run: => "Viber"

              ==================== Accounts: =============================

              Administrator (S-1-5-21-4216991579-408556834-1651255799-500 - Administrator - Disabled)
              ASPNET (S-1-5-21-4216991579-408556834-1651255799-1012 - Limited - Enabled)
              Gast (S-1-5-21-4216991579-408556834-1651255799-1015 - Limited - Enabled)
              Guest (S-1-5-21-4216991579-408556834-1651255799-501 - Limited - Enabled)
              HomeGroupUser$ (S-1-5-21-4216991579-408556834-1651255799-1014 - Limited - Enabled)
              Shirley (S-1-5-21-4216991579-408556834-1651255799-1002 - Administrator - Enabled) => C:\Users\Shirley

              ==================== Faulty Device Manager Devices =============

              Name: Apple iPhone
              Description: Apple iPhone
              Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
              Manufacturer: Apple Inc.
              Service: WUDFWpdMtp
              Problem: : This device cannot start. (Code10)
              Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
              On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


              ==================== Event log errors: =========================

              Application errors:
              ==================
              Error: (04/08/2015 06:38:44 PM) (Source: System Restore) (EventID: 8193) (User: )
              Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\srtasks.exe ExecuteScheduledSPPCreation; Beschreibung = Scheduled Checkpoint; Fehler = 0x80070422).


              System errors:
              =============
              Error: (04/08/2015 07:24:55 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
              Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 1205.

              Error: (04/08/2015 07:24:55 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
              Description: Eine TLS 1.2-Verbindungsanforderung wurde von einer Remoteclientanwendung übermittelt, jedoch werden keine der Verschlüsselungssammlungen, die von der Clientanwendung unterstützt werden, vom Server unterstützt. Fehler bei der SSL-Verbindungsanforderung.

              Error: (04/08/2015 06:26:11 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
              Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 1205.

              Error: (04/08/2015 06:26:11 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
              Description: Eine TLS 1.2-Verbindungsanforderung wurde von einer Remoteclientanwendung übermittelt, jedoch werden keine der Verschlüsselungssammlungen, die von der Clientanwendung unterstützt werden, vom Server unterstützt. Fehler bei der SSL-Verbindungsanforderung.


              Microsoft Office Sessions:
              =========================
              Error: (04/08/2015 06:38:44 PM) (Source: System Restore) (EventID: 8193) (User: )
              Description: C:\Windows\system32\srtasks.exe ExecuteScheduledSPPCreationScheduled Checkpoint0x80070422


              CodeIntegrity Errors:
              ===================================
                Date: 2015-04-08 18:42:47.538
                Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


              ==================== Memory info ===========================

              Processor: Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz
              Percentage of memory in use: 69%
              Total physical RAM: 4056.09 MB
              Available physical RAM: 1234.46 MB
              Total Pagefile: 8152.09 MB
              Available Pagefile: 4379.01 MB
              Total Virtual: 131072 MB
              Available Virtual: 131071.79 MB

              ==================== Drives ================================

              Drive c: (Windows8_OS) (Fixed) (Total:822.57 GB) (Free:275.7 GB) NTFS ==>[System with boot components (obtained from reading drive)]
              Drive d: () (Fixed) (Total:82.35 GB) (Free:82.25 GB) NTFS
              Drive e: () (Fixed) (Total:0.34 GB) (Free:0.06 GB) NTFS
              Drive g: (CAMERA) (Removable) (Total:62.46 GB) (Free:61.71 GB) FAT32

              ==================== MBR & Partition Table ==================

              ========================================================
              Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A9400691)
              Partition 1: (Not Active) - (Size=82.3 GB) - (Type=07 NTFS)
              Partition 2: (Not Active) - (Size=350 MB) - (Type=07 NTFS)
              Partition 3: (Active) - (Size=500 MB) - (Type=0C)
              Partition 4: (Not Active) - (Size=822.6 GB) - (Type=07 NTFS)

              ========================================================
              Disk: 1 (Size: 62.5 GB) (Disk ID: 00C741A4)
              Partition 1: (Not Active) - (Size=62.5 GB) - (Type=0B)

              ==================== End Of Log ============================

              FF NetworkProxy: "gopher", ""
              FF NetworkProxy: "gopher_port", 0

               

              Do use these Firefox Proxies ???

               

               

              Also wondershare comes with bundled programs, do you use it

              Ask AI

              AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

              Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI