This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Multiple Pop-ups on every new Browser Page [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

About 1 week or 10 days ago I got infected with some annoying advertisements.  Additionally certain words on any page that I open with my Browser (Google Chrome latest version) form into links that takes me to another site that is selling stuff.  My Google Search page is full of junk suggestions (more sites that want to sell me stuff).

 

I have downloaded and installed a free version of Microsoft Security Essentials (after I got infected).  My 14 day trial of Maleware Bytes had previously run out and I was unprotected.  I frequently download torrent files from KickAssTorrents.

 

Here is a picture of the problem. (see attached .jpg files)

 

Copy & Paste of aswMBR.txt

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software

Run date: 2015-04-21 04:25:07
—————————–
04:25:07.239    OS Version: Windows 6.1.7601 Service Pack 1
04:25:07.239    Number of processors: 4 586 0x3A09
04:25:07.239    ComputerName: HOME-PC  UserName: home
04:25:21.582    Initialize success
04:25:21.868    VM: initialized successfully
04:25:21.868    VM: Intel CPU supported 
04:25:30.167    VM: supported disk I/O ataport.SYS
05:13:34.135    AVAST engine defs: 15042000
05:16:34.975    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
05:16:34.978    Disk 0 Vendor: ST1000DM003-1CH162 CC49 Size: 953869MB BusType: 11
05:16:35.129    VM: Disk 0 MBR read successfully
05:16:35.133    Disk 0 MBR scan
05:16:35.197    Disk 0 Windows 7 default MBR code
05:16:35.200    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
05:16:35.202    Disk 0 default boot code
05:16:35.234    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       254655 MB offset 206848
05:16:35.279    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       310245 MB offset 521740288
05:16:35.325    Disk 0 Partition 4 00     07    HPFS/NTFS NTFS       388867 MB offset 1157122048
05:16:35.596    Disk 0 scanning sectors +1953521664
05:16:35.681    Disk 0 scanning C:\Windows\system32\drivers
05:16:47.759    Service scanning
05:16:56.754    Service MpKsl821025d2 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8870DE0B-72EA-4351-A9B5-1B88A6AA4A26}\MpKsl821025d2.sys **LOCKED** 32
05:17:10.992    Modules scanning
05:17:11.000    Disk 0 trace - called modules:
05:17:11.020    ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys 
05:17:11.026    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xc37e8030]
05:17:11.031    3 CLASSPNP.SYS[ca19559e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xc333a908]
05:17:11.712    AVAST engine scan C:\Windows
05:17:13.677    AVAST engine scan C:\Windows\system32
05:20:00.584    AVAST engine scan C:\Windows\system32\drivers
05:20:16.362    AVAST engine scan C:\Users\home
06:36:21.799    AVAST engine scan C:\ProgramData
06:39:10.616    Disk 0 statistics 5385519/0/282 @ 1.79 MB/s
06:39:10.622    Scan finished successfully
06:42:17.769    Disk 0 MBR has been saved successfully to "C:\Users\home\Documents\MBR.dat"
06:42:17.797    The log file has been saved successfully to "C:\Users\home\Documents\aswMBR.txt"
 
 

 

Copy & Paste of FRST files  Addition.txt

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-04-2015
Ran by [removed] at 2015-04-21 06:55:17
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 17 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM\…\Adobe Shockwave Player) (Version: 12.1.2.152 - Adobe Systems, Inc.)
calibre (HKLM\…\{3CA0D836-B5E7-463D-A1C5-9F49B3E3EDE6}) (Version: 2.20.0 - Kovid Goyal)
Dropbox (HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\…\Dropbox) (Version: 3.4.3 - Dropbox, Inc.)
GIMP 2.8.10 (HKLM\…\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
Google Chrome (HKLM\…\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
IrfanView (remove only) (HKLM\…\IrfanView) (Version: 4.37 - Irfan Skiljan)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\…\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 31.0 (x86 en-US) (HKLM\…\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
Network Addon Mod (HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\…\Network Addon Mod) (Version: 32 - The NAM Team)
NVIDIA 3D Vision Controller Driver 306.97 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 306.97 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 306.97 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 306.97 - NVIDIA Corporation)
NVIDIA Graphics Driver 306.97 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 306.97 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.18.0 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.18.0 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0604 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0604 - NVIDIA Corporation)
NVIDIA Update 1.10.8 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
OpenOffice 4.0.1 (HKLM\…\{24B89186-2A56-4D28-B930-6F4FCF224E2F}) (Version: 4.01.9714 - Apache Software Foundation)
SC4 Mapper 2013 (HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\…\SC4 Mapper 2013) (Version:  - )
SimCity 4 Deluxe (HKLM\…\Steam App 24780) (Version:  - EA - Maxis)
SketchUp 2015 (HKLM\…\{D0A0BE3D-8D66-4BE9-87C4-D30CA5AA93A3}) (Version: 15.3.330 - Trimble Navigation Limited)
Skype Click to Call (HKLM\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.3 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
Steam (HKLM\…\Steam) (Version:  - Valve Corporation)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 10 (HKLM\…\TeamViewer) (Version: 10.0.36897 - TeamViewer)
TerminusAppend (HKLM\…\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{b93b2efe}) (Version:  - Software Publisher) <==== ATTENTION
Vuze (HKLM\…\8461-7759-5462-8226) (Version: 5.6.0.0 - Azureus Software, Inc.)
WinRAR archiver (HKLM\…\WinRAR archiver) (Version:  - )
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{25815CC0-43F4-3C75-8C3A-A139D9ADE740}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> C:\Users\home\AppData\Local\Temp\8E20\temp\Ncis Season 5 (complete).torrent.exe No File
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
 
==================== Restore Points  =========================
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 07:34 - 2009-06-11 03:09 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {04D06349-3F21-465D-8397-7EF7380D834F} - System32\Tasks\Water Tower
Task: {0E8A3503-2BF8-4DCD-9D25-7E33D4953285} - System32\Tasks\Best Friend
Task: {1440B270-C7D4-424E-B84B-A71D16F9486D} - System32\Tasks\Crop Dryer
Task: {511670CA-0B91-4F25-8D7A-DD0873D2958D} - System32\Tasks\LaunchSignup => C:\Program Files\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {639966C3-BB7C-4A38-B2D6-BACAD5B1A319} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-04-06] (Google Inc.)
Task: {AEAF320D-C2E0-4523-A108-F1D766E4212E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
Task: {B71271FB-4A50-4E23-8269-A221F2B89133} - \ASP No Task File <==== ATTENTION
Task: {BF45FC34-B9F7-4C39-B248-9CBB6FFE822B} - System32\Tasks\Windmill
Task: {C304F390-0B07-4736-93D5-96A813A48202} - System32\Tasks\Baby Girl
Task: {D554C8C4-0378-44CD-B02D-DE64535D1D0D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-04-06] (Google Inc.)
Task: {DB3571E6-F3ED-4404-9A5A-4B951BBFE660} - System32\Tasks\{10A98203-A9AA-4459-B606-A2FDC85BF6DE} => pcalua.exe -a "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" -c /uninstall ENTERPRISE /dll OSETUP.DLL
Task: {E470D95D-A9D1-4EB3-89AE-425F305BA2B4} - System32\Tasks\Farmhands
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) ==============
 
2014-03-29 10:05 - 2012-10-03 00:58 - 00079208 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2015-04-15 15:31 - 2015-04-15 15:31 - 01614848 _____ () c:\Program Files\TerminusAppend\TerminusAppend.dll
2014-03-29 10:13 - 2006-09-14 00:20 - 00126464 _____ () C:\Program Files\WinRAR\rarext.dll
2015-04-20 14:53 - 2015-04-20 14:53 - 00043008 _____ () c:\users\home\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsvbb_e.dll
2015-03-05 03:15 - 2015-03-05 03:15 - 00750080 _____ () C:\Users\home\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-03-05 03:15 - 2015-03-05 03:15 - 00047616 _____ () C:\Users\home\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-03-05 03:15 - 2015-03-05 03:15 - 00865280 _____ () C:\Users\home\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-03-05 03:15 - 2015-03-05 03:15 - 00200704 _____ () C:\Users\home\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2014-05-27 23:31 - 2014-04-25 14:02 - 00086840 _____ () C:\Program Files\Vuze\aereg.dll
2014-05-27 23:31 - 2014-06-24 15:12 - 00176128 _____ () C:\Users\home\AppData\Roaming\Azureus\plugins\azitunes\jacob-1.17-M2-x86.dll
2014-05-27 23:31 - 2014-06-24 15:12 - 00014304 _____ () C:\Users\home\AppData\Roaming\Azureus\plugins\azitunes\libProcessAccess.dll
2015-04-16 21:47 - 2015-04-14 03:25 - 01252680 _____ () C:\Program Files\Google\Chrome\Application\42.0.2311.90\libglesv2.dll
2015-04-16 21:47 - 2015-04-14 03:25 - 00080712 _____ () C:\Program Files\Google\Chrome\Application\42.0.2311.90\libegl.dll
2015-04-16 21:47 - 2015-04-14 03:25 - 14980424 _____ () C:\Program Files\Google\Chrome\Application\42.0.2311.90\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
AlternateDataStreams: C:\Users\home\Documents\Vuze Downloads:com.dropbox.attributes
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\home\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2690002102-2696416691-3589846356-500 - Administrator - Disabled)
Guest (S-1-5-21-2690002102-2696416691-3589846356-501 - Limited - Enabled)
home (S-1-5-21-2690002102-2696416691-3589846356-1000 - Administrator - Enabled) => C:\Users\home
UpdatusUser (S-1-5-21-2690002102-2696416691-3589846356-1001 - Limited - Enabled) => C:\Users\UpdatusUser
Vijay (S-1-5-21-2690002102-2696416691-3589846356-1002 - Administrator - Enabled) => C:\Users\Vijay
 
==================== Faulty Device Manager Devices =============
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/20/2015 11:47:39 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (04/20/2015 02:55:13 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (04/20/2015 02:53:36 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x80070005.
 
Error: (04/20/2015 04:49:23 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (04/19/2015 09:45:27 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 90080108
 
Error: (04/18/2015 02:39:59 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (04/17/2015 07:15:15 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (04/17/2015 11:44:24 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x80070005.
 
Error: (04/17/2015 11:44:15 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (04/17/2015 11:24:05 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (04/21/2015 05:21:04 AM) (Source: volsnap) (EventID: 14) (User: )
Description: The shadow copies of volume C: were aborted because of an IO failure on volume C:.
 
Error: (04/21/2015 05:20:30 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
 
Error: (04/21/2015 05:20:30 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
 
Error: (04/21/2015 05:20:30 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
 
Error: (04/21/2015 05:20:30 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
 
Error: (04/20/2015 02:52:33 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
 
Error: (04/20/2015 02:08:16 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The SPP Notification Service service terminated with the following error: 
%%5
 
Error: (04/20/2015 01:08:16 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The SPP Notification Service service terminated with the following error: 
%%5
 
Error: (04/20/2015 00:08:17 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The SPP Notification Service service terminated with the following error: 
%%5
 
Error: (04/20/2015 11:52:56 AM) (Source: DCOM) (EventID: 10001) (User: )
Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}
 
 
Microsoft Office Sessions:
=========================
Error: (04/20/2015 11:47:39 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (04/20/2015 02:55:13 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (04/20/2015 02:53:36 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: 0x800700050x00000000
 
Error: (04/20/2015 04:49:23 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (04/19/2015 09:45:27 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 90080108
 
Error: (04/18/2015 02:39:59 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (04/17/2015 07:15:15 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (04/17/2015 11:44:24 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: 0x800700050x00000000
 
Error: (04/17/2015 11:44:15 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (04/17/2015 11:24:05 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-06-02 07:33:10.588
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-06-02 07:33:10.587
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-06-02 07:33:10.585
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-06-02 07:33:10.580
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-06-02 07:33:10.579
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-06-02 07:33:10.577
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-06-02 07:33:10.568
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-06-02 07:33:10.567
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-06-02 07:33:10.565
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-06-02 07:33:10.560
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-3330 CPU @ 3.00GHz
Percentage of memory in use: 71%
Total physical RAM: 3564.05 MB
Available physical RAM: 1031.14 MB
Total Pagefile: 7126.39 MB
Available Pagefile: 3785.06 MB
Total Virtual: 3071.88 MB
Available Virtual: 2911.9 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:248.69 GB) (Free:96.88 GB) NTFS
Drive d: () (Fixed) (Total:302.97 GB) (Free:287.3 GB) NTFS
Drive e: () (Fixed) (Total:379.75 GB) (Free:379.44 GB) NTFS
Drive f: (GRMCHBFREO_EN_DVD) (CDROM) (Total:2.33 GB) (Free:0 GB) UDF
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: F87F8A2F)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=248.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=303 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=379.8 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================
Copy & Paste of other FRST file FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015
Ran by [removed] (administrator) on HOME-PC on 21-04-2015 06:54:40
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft Windows 7 Home Basic  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Dropbox, Inc.) C:\Users\home\AppData\Roaming\Dropbox\bin\Dropbox.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Azureus Software, Inc) C:\Program Files\Vuze\Azureus.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Irfan Skiljan) C:\Program Files\IrfanView\i_view32.exe
(AVAST Software) C:\Users\home\Downloads\aswMBR.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\…\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [978520 2015-01-30] (Microsoft Corporation)
HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\…\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31682144 2015-03-25] (Skype Technologies S.A.)
HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\…\MountPoints2: {7aa96792-b761-11e3-a2c7-806e6f6e6963} - F:\setup.exe
HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-21] (Microsoft Corporation)
Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-03-29]
ShortcutTarget: Dropbox.lnk -> C:\Users\home\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ncis Season 5 (complete).torrent.lnk [2015-04-06]
ShortcutTarget: Ncis Season 5 (complete).torrent.lnk -> C:\ProgramData\{ab145556-8da6-98fc-ab14-455568da555a}\Ncis Season 5 (complete).torrent.exe (No File)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
SearchScopes: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000 -> {54F92226-89D2-48A4-8ED0-771683834AA6} URL = http://search.us.com/serp?guid={6E76C3BF-4D80-4E31-928C-25168F6553E1}&action;=default_search&serpv;=5&k;={searchTerms}
SearchScopes: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000 -> {76D04D07-0077-48F6-89EC-109C759AE011} URL = 
SearchScopes: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000 -> {FDB2E2A7-C95B-46D6-8426-A9F75D6A0C1D} URL = http://search.yahoo.com/search?p={searchTerms}&fr;=tightropetb&type;=10679
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF ProfilePath: C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1212152.dll [2014-05-30] (Adobe Systems, Inc.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2012-10-02] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2012-10-02] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-06] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-09-12] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\user.js [2014-08-08]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]
FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC} [Not Found]
FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7} [Not Found]
FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{DE1C78C1-2762-47f6-A1D9-1B7866FE7EB4} [Not Found]
FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{CA8C84C6-3918-41b1-BE77-049B2BDD887C} [Not Found]
 
Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxp://search.us.com/c/in/?guid={6E76C3BF-4D80-4E31-928C-25168F6553E1}&serpv;=5
CHR Profile: C:\Users\home\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-06]
CHR Extension: (Internet Speed Tracker) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\acdnhokdlhndmflmklllleemdenbikla [2015-04-06]
CHR Extension: (Torrent Search) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\afbpdhiclgghnffhkinjikglgmolhpee [2015-04-06]
CHR Extension: (Google Docs) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-06]
CHR Extension: (Google Drive) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-04-06]
CHR Extension: (Adguard AdBlocker) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2015-04-20]
CHR Extension: (YouTube) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-04-06]
CHR Extension: (Solitaire) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpebaehgfgkcmmjjknibibbjacnplim [2015-04-06]
CHR Extension: (Adblock Plus) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-04-06]
CHR Extension: (Google Search) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-06]
CHR Extension: (Google Calendar) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2015-04-06]
CHR Extension: (Mahjong Solitaire) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\eogmadihniohlnmipdhchaoagjhfnohc [2015-04-06]
CHR Extension: (Google Sheets) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-06]
CHR Extension: (Papas Pizzeria) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjaihmihhhgfofccgiboicjloaemhhfi [2015-04-15]
CHR Extension: (Bookmark Manager) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-17]
CHR Extension: (Avast Online Security) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-04-20]
CHR Extension: (Currency Converter) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\habdflddkbkcmiglihdemgpijopehham [2015-04-06]
CHR Extension: (Timer) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhclmngbkkejbdfjmicnkmoggfpehein [2015-04-06]
CHR Extension: (Kindle Cloud Reader) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2015-04-06]
CHR Extension: (Autodesk Homestyler) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2015-04-06]
CHR Extension: (Whois this!!) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\kikjpgpbpnapbimplfcbcbakjacpgceb [2015-04-06]
CHR Extension: (Popup Blocker Pro) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiodaajmphnkcajieajajinghpejdjai [2015-04-20]
CHR Extension: (Adblock Super) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\knebimhcckndhiglamoabbnifdkijidd [2015-04-20]
CHR Extension: (Currency Converter) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbhghjdcfghfhlogkgdklfgmpodeglno [2015-04-06]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-18]
CHR Extension: (Skype Click to Call) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-04-06]
CHR Extension: (Floor plans and interior design) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcafejemebbngbglfoinpoaannbihjna [2015-04-06]
CHR Extension: (Google Wallet) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-06]
CHR Extension: (Adblock Pro) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2015-04-20]
CHR Extension: (Quick start) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [2015-04-06]
CHR Extension: (Gmail) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-06]
CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 b93b2efe; c:\Program Files\TerminusAppend\TerminusAppend.dll [1614848 2015-04-15] () [File not signed]
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S3 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-02] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation)
R1 MpKsl821025d2; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8870DE0B-72EA-4351-A9B5-1B88A6AA4A26}\MpKsl821025d2.sys [39464 2015-04-21] (Microsoft Corporation)
U3 aswMBR; \??\C:\Users\home\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\home\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-21 06:54 - 2015-04-21 06:55 - 00016596 _____ () C:\Users\home\Desktop\FRST.txt
2015-04-21 06:54 - 2015-04-21 06:54 - 00000000 ____D () C:\FRST
2015-04-21 06:52 - 2015-04-21 06:53 - 01139200 _____ (Farbar) C:\Users\home\Desktop\FRST.exe
2015-04-21 06:48 - 2015-04-21 06:49 - 01139200 _____ (Farbar) C:\Users\home\Downloads\FRST.exe
2015-04-21 06:42 - 2015-04-21 06:42 - 00002486 _____ () C:\Users\home\Documents\aswMBR.txt
2015-04-21 06:42 - 2015-04-21 06:42 - 00000512 _____ () C:\Users\home\Documents\MBR.dat
2015-04-21 04:40 - 2015-04-21 04:40 - 00014296 _____ () C:\Users\home\AppData\Local\recently-used.xbel
2015-04-21 04:16 - 2015-04-21 04:17 - 05198336 _____ (AVAST Software) C:\Users\home\Downloads\aswMBR.exe
2015-04-21 03:38 - 2015-04-21 03:38 - 00010608 _____ () C:\Users\home\Documents\KIRAN BUDGET.ods
2015-04-19 00:30 - 2015-04-01 11:22 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-19 00:29 - 2015-04-19 00:30 - 44167360 _____ (Microsoft Corporation) C:\Users\home\Downloads\Windows-KB890830-V5.23.exe
2015-04-17 10:06 - 2015-04-17 10:06 - 03109248 _____ (Enigma Software Group USA, LLC.) C:\Users\home\Downloads\SpyHunter-Installer.exe
2015-04-17 10:06 - 2015-04-17 10:06 - 00000000 ____D () C:\Program Files\Enigma Software Group
2015-04-15 21:58 - 2015-04-20 07:23 - 00000020 _____ () C:\Users\home\AppData\Roaming\appdataFr3.bin
2015-04-15 15:51 - 2015-04-15 15:51 - 00000000 ____D () C:\ProgramData\AdPunisher
2015-04-15 15:31 - 2015-04-15 15:31 - 00000000 ____D () C:\Program Files\TerminusAppend
2015-04-13 09:22 - 2015-04-13 09:57 - 00130016 _____ () C:\Users\home\Documents\house.skp
2015-04-07 03:27 - 2014-07-01 03:44 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2015-04-07 03:27 - 2014-06-06 11:46 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2015-04-07 03:27 - 2014-03-10 03:17 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2015-04-07 03:27 - 2014-03-10 03:17 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2015-04-07 03:26 - 2012-03-01 11:03 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2015-04-07 03:25 - 2015-04-07 03:25 - 00055618 _____ () C:\Users\home\Downloads\[kickass.to]ncis.season.5.complete.torrent
2015-04-07 03:24 - 2015-04-07 03:25 - 00003604 _____ () C:\Windows\IE9_main.log
2015-04-07 03:05 - 2015-04-07 03:05 - 14380544 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 13768704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 02864640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-07 03:05 - 2015-04-07 03:05 - 02055680 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 01763328 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 01441280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-07 03:05 - 2015-04-07 03:05 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2015-04-07 03:05 - 2015-04-07 03:05 - 01181696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00745472 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-07 03:05 - 2015-04-07 03:05 - 00719360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00629248 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-07 03:05 - 2015-04-07 03:05 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2015-04-07 03:05 - 2015-04-07 03:05 - 00138752 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2015-04-07 03:05 - 2015-04-07 03:05 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-07 03:05 - 2015-04-07 03:05 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2015-04-07 03:05 - 2015-04-07 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2015-04-07 03:05 - 2015-04-07 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2015-04-07 03:05 - 2015-04-07 03:05 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-07 03:05 - 2015-04-07 03:05 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-04-07 03:05 - 2015-04-07 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-04-07 03:05 - 2015-04-07 03:05 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-04-07 03:03 - 2015-04-07 03:03 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 01988096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-04-07 03:03 - 2015-04-07 03:03 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-04-07 03:02 - 2015-04-07 03:02 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2015-04-07 03:01 - 2015-04-07 03:06 - 00012251 _____ () C:\Windows\IE10_main.log
2015-04-06 19:43 - 2015-04-06 19:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-04-06 19:41 - 2015-04-21 06:46 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-06 19:41 - 2015-04-20 19:46 - 00000878 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-06 19:41 - 2015-04-06 19:41 - 00000000 ____D () C:\Users\home\AppData\Local\Deployment
2015-04-06 19:41 - 2015-04-06 19:41 - 00000000 ____D () C:\Users\home\AppData\Local\Apps\2.0
2015-04-06 19:16 - 2014-09-04 10:34 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2015-04-06 19:15 - 2015-03-06 10:45 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-06 19:15 - 2015-03-06 10:45 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-06 19:15 - 2015-03-06 10:40 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-06 19:15 - 2015-03-06 10:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-06 19:15 - 2015-03-06 10:40 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-06 19:15 - 2015-03-06 10:40 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-06 19:15 - 2015-03-06 10:40 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-06 19:15 - 2015-03-06 10:40 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-06 19:15 - 2015-03-06 10:40 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-06 19:15 - 2015-03-06 10:40 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-06 19:15 - 2015-03-06 10:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-06 19:15 - 2015-03-06 10:40 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-06 19:15 - 2015-03-06 10:40 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-06 19:15 - 2015-03-06 10:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-06 19:15 - 2015-03-06 10:39 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-06 19:15 - 2015-03-06 10:37 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-06 19:15 - 2015-03-06 10:37 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-06 19:15 - 2015-03-06 10:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-06 19:15 - 2015-02-26 08:41 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-04-06 19:15 - 2015-02-20 09:43 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-04-06 19:15 - 2015-02-20 09:43 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-04-06 19:15 - 2015-02-20 09:43 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-04-06 19:15 - 2015-02-20 09:43 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-04-06 19:15 - 2015-02-20 08:39 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-04-06 19:15 - 2015-02-13 10:56 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-04-06 19:15 - 2015-02-03 08:42 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-04-06 19:15 - 2015-01-17 08:00 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-04-06 19:15 - 2014-12-19 08:13 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-04-06 19:15 - 2014-12-11 23:17 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-04-06 19:15 - 2014-10-25 07:02 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2015-04-06 19:15 - 2014-07-17 07:09 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-04-06 19:15 - 2014-07-17 07:09 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-04-06 19:15 - 2014-06-19 03:53 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2015-04-06 19:15 - 2014-06-19 03:53 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2015-04-06 19:15 - 2014-06-19 03:53 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2015-04-06 19:15 - 2014-06-18 07:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2015-04-06 19:15 - 2014-06-06 15:14 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2015-04-06 19:15 - 2014-06-03 15:00 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-04-06 19:15 - 2014-06-03 14:59 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-04-06 19:15 - 2014-06-03 14:59 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-04-06 19:15 - 2014-06-03 14:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-04-06 19:15 - 2014-05-30 12:06 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-04-06 19:15 - 2014-04-05 07:55 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2015-04-06 19:15 - 2014-04-05 07:54 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2015-04-06 19:15 - 2013-11-26 16:41 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2015-04-06 19:14 - 2015-02-03 08:46 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-06 19:14 - 2015-02-03 08:46 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-06 19:14 - 2015-02-03 08:46 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-04-06 19:14 - 2015-02-03 08:42 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-06 19:14 - 2015-02-03 08:42 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-04-06 19:14 - 2015-02-03 08:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-04-06 19:14 - 2015-02-03 08:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-04-06 19:14 - 2015-02-03 08:41 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-04-06 19:14 - 2015-02-03 08:41 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-06 19:14 - 2015-02-03 08:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-04-06 19:14 - 2015-02-03 08:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-04-06 19:14 - 2015-02-03 08:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-04-06 19:14 - 2015-02-03 08:41 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-04-06 19:14 - 2015-02-03 08:41 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-04-06 19:14 - 2015-02-03 08:41 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-04-06 19:14 - 2015-02-03 08:41 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-04-06 19:14 - 2015-02-03 08:40 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-04-06 19:14 - 2015-02-03 08:39 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-04-06 19:14 - 2015-02-03 08:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-06 19:14 - 2015-02-03 08:30 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-04-06 19:14 - 2015-02-03 07:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-04-06 19:14 - 2015-01-31 05:26 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-04-06 19:14 - 2014-12-19 07:04 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-04-06 19:14 - 2014-12-08 08:16 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-04-06 19:14 - 2014-12-06 09:20 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-04-06 19:14 - 2014-11-01 03:52 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-04-06 19:14 - 2014-10-14 07:20 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2015-04-06 19:14 - 2014-07-17 07:10 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2015-04-06 19:14 - 2014-07-17 07:09 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2015-04-06 19:14 - 2014-07-17 07:09 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-04-06 19:14 - 2014-07-17 07:09 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2015-04-06 19:14 - 2014-07-17 06:33 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2015-04-06 19:14 - 2014-07-17 06:32 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2015-04-06 19:14 - 2014-06-28 05:51 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-04-06 19:14 - 2014-06-28 05:51 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-04-06 19:14 - 2014-04-25 07:36 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2015-04-06 19:14 - 2012-10-03 22:12 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-04-06 19:14 - 2012-10-03 22:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-04-06 18:48 - 2014-05-14 21:53 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-06 18:48 - 2014-05-14 21:53 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-06 18:48 - 2014-05-14 21:53 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-06 18:48 - 2014-05-14 21:47 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-06 18:48 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-06 18:48 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-06 18:47 - 2015-04-06 18:47 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-04-06 18:46 - 2015-04-06 18:47 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-04-06 01:16 - 2015-04-15 15:31 - 00000000 ____D () C:\ProgramData\872042f600005a19
2015-04-06 00:37 - 2015-04-06 00:37 - 00000000 ____D () C:\Program Files\youtubeadblocker
2015-04-06 00:36 - 2015-04-15 23:52 - 00000000 ____D () C:\ProgramData\13485036209175509208
2015-04-06 00:36 - 2015-04-06 18:09 - 00000000 ____D () C:\Program Files\SAlePlluus
2015-04-06 00:35 - 2015-04-06 18:10 - 00000000 ____D () C:\ProgramData\{ab145556-8da6-98fc-ab14-455568da555a}
2015-04-05 19:29 - 2015-04-06 00:36 - 00000000 ____D () C:\Users\home\Documents\The Mentalist
2015-04-05 15:20 - 2015-04-05 15:20 - 00245389 _____ () C:\Users\home\Downloads\[kickass.to]the.mentalist.season.2.complete.hdtvrip.x264.mkv.by.riddlera.torrent
2015-04-05 04:37 - 2015-04-05 04:38 - 00042078 _____ () C:\Users\home\Downloads\[kickass.to]the.mentalist.season.1.torrent
2015-04-04 23:14 - 2015-04-04 23:14 - 00000000 __SHD () C:\found.000
2015-04-02 00:59 - 2015-04-02 00:59 - 00002064 _____ () C:\Users\Vijay\Desktop\FastDownload.com.lnk
2015-04-02 00:59 - 2015-04-02 00:59 - 00002064 _____ () C:\Users\UpdatusUser\Desktop\FastDownload.com.lnk
2015-04-02 00:59 - 2015-04-02 00:59 - 00002056 _____ () C:\Users\Vijay\Desktop\GameTeam.com.lnk
2015-04-02 00:59 - 2015-04-02 00:59 - 00002056 _____ () C:\Users\UpdatusUser\Desktop\GameTeam.com.lnk
2015-04-02 00:59 - 2015-04-02 00:59 - 00002054 _____ () C:\Users\Vijay\Desktop\GameTop.com.lnk
2015-04-02 00:59 - 2015-04-02 00:59 - 00002054 _____ () C:\Users\UpdatusUser\Desktop\GameTop.com.lnk
2015-03-31 02:35 - 2015-03-31 02:35 - 00001813 _____ () C:\Users\home\Downloads\[kickass.to]gray.mountain.a.novel.by.john.grisham.epub.retail.torrent
2015-03-30 01:20 - 2015-03-30 01:20 - 00000000 ____D () C:\ProgramData\Playrix Entertainment
2015-03-28 21:48 - 2015-03-28 21:48 - 00001527 _____ () C:\Users\home\Downloads\[kickass.to]ian.caldwell.the.fifth.gospel.wildwielder.epub.torrent
2015-03-28 21:35 - 2015-03-28 21:35 - 00022993 _____ () C:\Users\home\Downloads\[kickass.to]chappie.2015.cam.x264.maxillion.torrent
2015-03-27 20:19 - 2015-03-27 20:19 - 00002275 _____ () C:\Users\home\Downloads\[kickass.to]the.girl.on.the.train.paula.hawkins.torrent
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-21 06:54 - 2014-05-27 23:31 - 00000000 ____D () C:\Users\home\AppData\Roaming\Azureus
2015-04-21 06:54 - 2014-05-12 14:14 - 00000000 ____D () C:\Users\home\AppData\Roaming\Skype
2015-04-21 06:44 - 2014-03-29 19:18 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-21 06:00 - 2015-02-02 13:00 - 00059358 _____ () C:\Users\home\Network_Meter_Data.js
2015-04-21 04:41 - 2014-03-31 11:56 - 00000000 ____D () C:\Users\home\.gimp-2.8
2015-04-21 04:07 - 2014-03-31 11:59 - 00000000 ____D () C:\Users\home\AppData\Local\gtk-2.0
2015-04-20 23:30 - 2014-03-29 10:01 - 01711130 _____ () C:\Windows\WindowsUpdate.log
2015-04-20 14:54 - 2014-05-12 14:14 - 00000000 ____D () C:\ProgramData\Skype
2015-04-20 14:54 - 2014-03-29 23:43 - 00000000 ___RD () C:\Users\home\Dropbox
2015-04-20 14:54 - 2014-03-29 23:38 - 00000000 ____D () C:\Users\home\AppData\Roaming\Dropbox
2015-04-20 14:53 - 2015-02-02 12:49 - 00003837 _____ () C:\Users\home\IP_Log_Data.js
2015-04-20 14:53 - 2014-03-29 10:06 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-20 14:53 - 2009-07-14 10:23 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-20 14:53 - 2009-07-14 10:09 - 00004923 _____ () C:\Windows\setupact.log
2015-04-20 14:52 - 2015-02-04 13:44 - 00000027 _____ () C:\Users\home\AppData\Roaming\Network Meter_Usage.ini
2015-04-20 14:52 - 2009-07-14 10:04 - 00020640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-20 14:52 - 2009-07-14 10:04 - 00020640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-17 11:25 - 2014-03-29 10:18 - 00001104 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-17 11:25 - 2014-03-29 10:03 - 00001417 _____ () C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-15 07:44 - 2014-03-29 10:12 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-15 07:44 - 2014-03-29 10:12 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-13 23:33 - 2014-03-29 23:43 - 00000976 _____ () C:\Users\home\Desktop\Dropbox.lnk
2015-04-13 23:33 - 2014-03-29 23:41 - 00000000 ____D () C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-04-13 23:27 - 2010-11-21 03:18 - 01433122 _____ () C:\Windows\PFRO.log
2015-04-07 10:08 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\rescache
2015-04-07 05:02 - 2009-07-14 10:16 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-04-07 04:58 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-07 04:56 - 2010-11-21 02:31 - 00782922 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-07 04:52 - 2009-07-14 10:03 - 00432504 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-07 04:50 - 2009-07-14 10:22 - 00000000 ____D () C:\Program Files\Windows Defender
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\zh-TW
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\zh-HK
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\zh-CN
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\tr-TR
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\sv-SE
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\ru-RU
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\pt-PT
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\pt-BR
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\pl-PL
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\nl-NL
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\nb-NO
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\ko-KR
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\ja-JP
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\it-IT
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\hu-HU
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\fr-FR
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\fi-FI
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\el-GR
2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\de-DE
2015-04-07 03:09 - 2014-06-03 03:03 - 00448352 _____ () C:\Windows\msxml4-KB954430-enu.LOG
2015-04-07 03:08 - 2014-06-03 03:03 - 00446498 _____ () C:\Windows\msxml4-KB973688-enu.LOG
2015-04-06 19:43 - 2014-03-29 19:26 - 00000000 ____D () C:\Users\home\AppData\Local\Google
2015-04-06 19:43 - 2014-03-29 19:26 - 00000000 ____D () C:\Program Files\Google
2015-04-06 18:48 - 2014-06-02 20:22 - 00001945 _____ () C:\Windows\epplauncher.mif
2015-04-06 18:10 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\Registration
2015-04-06 18:09 - 2014-08-17 10:16 - 00000000 ____D () C:\Users\home\AppData\Roaming\Browser Extensions
2015-04-06 01:18 - 2014-05-15 02:47 - 00000000 ____D () C:\Program Files\SketchUp
2015-04-06 00:38 - 2014-12-21 21:39 - 00000000 ____D () C:\Users\home\AppData\Local\CrashDumps
2015-04-06 00:37 - 2014-09-10 07:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-31 02:39 - 2014-06-01 02:46 - 00000000 ____D () C:\Users\home\AppData\Roaming\calibre
2015-03-31 02:37 - 2014-06-01 02:46 - 00000000 ____D () C:\Users\home\Documents\Calibre Library
2015-03-27 20:15 - 2014-06-01 02:47 - 00000000 ____D () C:\Users\home\AppData\Local\calibre-cache
2015-03-27 19:50 - 2014-11-17 08:46 - 00000000 ____D () C:\Users\Vijay\AppData\Roaming\Adobe
2015-03-25 00:02 - 2014-03-29 10:11 - 00000000 ____D () C:\ProgramData\Adobe
2015-03-25 00:01 - 2014-09-28 21:39 - 00000000 ____D () C:\Users\home\AppData\Local\Adobe
2015-03-25 00:01 - 2014-03-29 19:18 - 00000000 ____D () C:\Users\home\AppData\Roaming\Adobe
 
==================== Files in the root of some directories =======
 
2015-02-02 12:46 - 2013-10-15 14:51 - 0351086 _____ () C:\Program Files\Network_Meter_V9.6.gadget
2015-04-15 21:58 - 2015-04-20 07:23 - 0000020 _____ () C:\Users\home\AppData\Roaming\appdataFr3.bin
2014-08-08 04:35 - 2014-08-08 04:36 - 0000318 _____ () C:\Users\home\AppData\Roaming\aps.uninstall.scan.results
2015-02-02 12:50 - 2015-03-05 16:31 - 0000812 _____ () C:\Users\home\AppData\Roaming\Network Meter_Settings.ini
2015-02-04 13:44 - 2015-04-20 14:52 - 0000027 _____ () C:\Users\home\AppData\Roaming\Network Meter_Usage.ini
2015-01-03 04:01 - 2015-01-03 04:01 - 0003584 _____ () C:\Users\home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-21 04:40 - 2015-04-21 04:40 - 0014296 _____ () C:\Users\home\AppData\Local\recently-used.xbel
2015-04-06 01:16 - 2015-04-18 10:29 - 0011346 _____ () C:\Users\home\AppData\Local\Temp-log.txt
 
Files to move or delete:
====================
C:\Users\home\IP_Log_Data.js
C:\Users\home\Network_Meter_Data.js
 
 
Some content of TEMP:
====================
C:\Users\home\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsvbb_e.dll
C:\Users\home\AppData\Local\Temp\FastDownloadTNT.exe
C:\Users\home\AppData\Local\Temp\i4jdel0.exe
C:\Users\home\AppData\Local\Temp\SkypeSetup.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-04-14 00:53
 
==================== End Of Log ============================

 

Thank you for your help.

:welcome:

 

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Please Run this program only once
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
  • Thanks for the speedy reply.  Yesterday I tried to clean with mbam but it did not help.

     

    Copy/Past of ckfiles.txt

     

    CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
    c:\program files\gimp 2\share\gimp\2.0\patterns\cracked.pat
    c:\users\home\documents\plugins\fukuda folder\naphtha cracking plant\fk_naphtha_cracker1-0x5ad0e817_0xd5ec2156_0x20000.sc4model
    c:\users\home\documents\plugins\fukuda folder\naphtha cracking plant\fk_naphtha_cracker1-0x6534284a-0xd5ec2156-0x35f16fc4.sc4desc
    c:\users\home\documents\plugins\fukuda folder\naphtha cracking plant\i-m3_2x4_naptha_cracker_b5f17114.sc4lot
    c:\users\home\documents\sc4 custom content\fukuda folder\naphtha cracking unit\fk_naphtha_cracker.zip
    c:\users\home\documents\sc4 custom content\fukuda folder\naphtha cracking unit\naphtha cracking unit.txt
    c:\users\home\documents\simcity 4\plugins\fukuda folder\naphtha cracking plant\fk_naphtha_cracker1-0x5ad0e817_0xd5ec2156_0x20000.sc4model
    c:\users\home\documents\simcity 4\plugins\fukuda folder\naphtha cracking plant\fk_naphtha_cracker1-0x6534284a-0xd5ec2156-0x35f16fc4.sc4desc
    c:\users\home\documents\simcity 4\plugins\fukuda folder\naphtha cracking plant\i-m3_2x4_naptha_cracker_b5f17114.sc4lot
    c:\windows\system32\slmgr.vbs.removewat
    scanner sequence 3.DF.11.LFAPBZ
     —– EOF —– 

    Good Morning

     

    Your using the torrents and [kickass to] to download programs, not a good idea, almost everything downloaded with them are infected. I need you to go to your downloads folder and delete anything that you downloaded with them, they need to be gone.  If we clean you up and you continue to use those programs you will be infected all over again and basically wasting our time. 

     

     
    -AdwCleaner-by Xplode
     
    Click on this link to download : ADWCleaner To your Desktop
    Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
    Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
     
     
    Do not click on any links in the top Advertisment.
     
    [external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
     
    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Scan.
    • After the scan is complete click on "Clean"
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the content of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.
    •  
       
      ===============================================================================
       
       
      [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
      • Shut down your protection software now to avoid potential conflicts.
      • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
      • The tool will open and start scanning your system.
      • Please be patient as this can take a while to complete depending on your system's specifications.
      • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
      • Post the contents of JRT.txt into your next message.
      •  
         
         
        ===============================================================================
         
        Download Malwarebytes' Anti-Malware  to your desktop. <———
         
        • Windows XP : Double click on the icon to run it.
        • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
        •  
          [external image: MBAM2.1.4_zpsnwqgubkb.jpg]
           
          • On the Dashboard click on Update Now
          • Go to the Setting Tab
          • Under Setting go to Detection and Protection
          • Under PUP and PUM make sure both are set to show Treat Detections as Malware
          • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
          • Then on the Dashboard click on Scan
          • Make sure to select THREAT SCAN
          • Then click on Scan
          • When the scan is finished and the log pops up…select Copy to Clipboard
          • Please paste the log back into this thread for review
          • Exit Malwarebytes
          • Copy/Paste of AdwCleaner.txt

             

            # AdwCleaner v4.202 - Logfile created 24/04/2015 at 14:47:39
            # Updated 23/04/2015 by Xplode
            # Database : 2015-04-23.2 [Server]
            # Operating system : Windows 7 Home Basic Service Pack 1 (x86)
            # Username : home - HOME-PC
            # Running from : C:\Users\home\Desktop\adwcleaner_4.202.exe
            # Option : Cleaning
             
            ***** [ Services ] *****
             
            [#] Service Deleted : b93b2efe
             
            ***** [ Files / Folders ] *****
             
            Folder Deleted : C:\ProgramData\Systweak
            Folder Deleted : C:\ProgramData\872042f600005a19
            Folder Deleted : C:\ProgramData\{ab145556-8da6-98fc-ab14-455568da555a}
            Folder Deleted : C:\Program Files\globalUpdate
            Folder Deleted : C:\Program Files\predm
            Folder Deleted : C:\Program Files\SAlePlluus
            Folder Deleted : C:\Users\home\AppData\Local\globalUpdate
            Folder Deleted : C:\Users\home\AppData\Roaming\ap_logs
            Folder Deleted : C:\Users\home\AppData\Roaming\Browser Extensions
            Folder Deleted : C:\Users\home\AppData\Roaming\Systweak
            File Deleted : C:\END
            File Deleted : C:\Users\home\AppData\Roaming\aps.uninstall.scan.results
            File Deleted : C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\user.js
             
            ***** [ Scheduled tasks ] *****
             
            Task Deleted : ASP
            Task Deleted : LaunchSignup
             
            ***** [ Shortcuts ] *****
             
             
            ***** [ Registry ] *****
             
            Key Deleted : HKLM\SOFTWARE\39695a6f-95f6-4b86-8d77-98be4fc0ba4b
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{b93b2efe}
            Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
            Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
            Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
            Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
            Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
            Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
            Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
            Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C1EC170E-C5ED-4100-9078-559C31AFDBF5}
            Key Deleted : HKCU\Software\Conduit
            Key Deleted : HKCU\Software\GlobalUpdate
            Key Deleted : HKCU\Software\systweak
            Key Deleted : HKCU\Software\VuuPC
            Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
            Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
            Key Deleted : HKLM\SOFTWARE\GlobalUpdate
            Key Deleted : HKLM\SOFTWARE\systweak
            Key Deleted : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
            Key Deleted : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2DF3E224-05CD-4113-AA7A-86F2F6607B46}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7223EDAC-E091-B3C1-BD91-B66CE557800F}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B138259A-351E-33FA-2726-8D71704F1DA9}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
             
            ***** [ Web browsers ] *****
             
            -\\ Internet Explorer v10.0.9200.17267
             
             
            -\\ Mozilla Firefox v31.0 (x86 en-US)
             
            [h1fqe27t.default\prefs.js] - Line Deleted : user_pref("plugin.state.npconduitfirefoxplugin", 0);
            [h1fqe27t.default\prefs.js] - Line Deleted : user_pref("startpage.ntsearch_url", "hxxps://in.search.yahoo.com/search?fr=spigot-nt-ff&ei=utf-8&ilc=12&type=994519&p={searchTerms}");
             
            -\\ Google Chrome v42.0.2311.90
             
            [C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
            [C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
            [C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma
            [C:\Users\Vijay\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
            [C:\Users\Vijay\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
            [C:\Users\Vijay\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Default_Search_Provider_Data] : 
             
            *************************
             
            AdwCleaner[R0].txt - [27035 bytes] - [24/04/2015 14:43:56]
            AdwCleaner[S0].txt - [4560 bytes] - [24/04/2015 14:47:39]
             
            ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4619  bytes] ##########
             
            Copy/Paste of JRT.txt
             
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            Junkware Removal Tool (JRT) by Thisisu
            Version: 6.6.2 (04.24.2015:1)
            OS: Windows 7 Home Basic x86
            Ran by [removed] on Fri 04/24/2015 at 15:00:59.10
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
             
             
             
             
            ~~~ Services
             
             
             
            ~~~ Tasks
             
             
             
            ~~~ Registry Values
             
             
             
            ~~~ Registry Keys
             
            Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{54F92226-89D2-48A4-8ED0-771683834AA6}
             
             
             
            ~~~ Files
             
             
             
            ~~~ Folders
             
             
             
            ~~~ FireFox
             
            Successfully deleted: [Folder] C:\Users\home\AppData\Roaming\mozilla\firefox\profiles\h1fqe27t.default\extensions\staged
            Emptied folder: C:\Users\home\AppData\Roaming\mozilla\firefox\profiles\h1fqe27t.default\minidumps [3 files]
             
             
             
             
             
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            Scan was completed on Fri 04/24/2015 at 15:01:50.71
            End of JRT log
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
             

            Copy/paste of Maleware Bytes Scan Log

             

            Malwarebytes Anti-Malware
            www.malwarebytes.org
             
            Scan Date: 4/24/2015
            Scan Time: 3:31:15 PM
            Logfile: 
            Administrator: Yes
             
            Version: 2.01.6.1022
            Malware Database: v2015.04.24.01
            Rootkit Database: v2015.04.21.01
            License: Free
            Malware Protection: Disabled
            Malicious Website Protection: Disabled
            Self-protection: Disabled
             
            OS: Windows 7 Service Pack 1
            CPU: x86
            File System: NTFS
            User: home
             
            Scan Type: Threat Scan
            Result: Completed
            Objects Scanned: 380040
            Time Elapsed: 4 min, 42 sec
             
            Memory: Enabled
            Startup: Enabled
            Filesystem: Enabled
            Archives: Enabled
            Rootkits: Disabled
            Heuristics: Enabled
            PUP: Enabled
            PUM: Enabled
             
            Processes: 0
            (No malicious items detected)
             
            Modules: 0
            (No malicious items detected)
             
            Registry Keys: 0
            (No malicious items detected)
             
            Registry Values: 0
            (No malicious items detected)
             
            Registry Data: 0
            (No malicious items detected)
             
            Folders: 0
            (No malicious items detected)
             
            Files: 0
            (No malicious items detected)
             
            Physical Sectors: 0
            (No malicious items detected)
             
             
            (end)
             
            Copy/Paste of Maleware Bytes Protection Log
             
            Malwarebytes Anti-Malware
            www.malwarebytes.org
             
             
            Error, 4/24/2015 2:35:22 PM, SYSTEM, HOME-PC, Protection, IsLicensed, 13, 
            Protection, 4/24/2015 2:35:22 PM, SYSTEM, HOME-PC, Protection, Malware Protection, Stopping, 
            Protection, 4/24/2015 2:35:22 PM, SYSTEM, HOME-PC, Protection, Malware Protection, Stopped, 
            Error, 4/24/2015 2:48:59 PM, SYSTEM, HOME-PC, Protection, IsLicensed, 13, 
            Protection, 4/24/2015 2:48:59 PM, SYSTEM, HOME-PC, Protection, Malware Protection, Stopping, 
            Protection, 4/24/2015 2:48:59 PM, SYSTEM, HOME-PC, Protection, Malware Protection, Stopped, 
            Update, 4/24/2015 3:14:32 PM, SYSTEM, HOME-PC, Manual, Rootkit Database, 2015.2.25.1, 2015.4.21.1, 
            Update, 4/24/2015 3:14:32 PM, SYSTEM, HOME-PC, Manual, Remediation Database, 2015.3.9.1, 2015.4.22.1, 
            Update, 4/24/2015 3:18:30 PM, SYSTEM, HOME-PC, Manual, Malware Database, 2015.3.9.5, 2015.4.24.1, 
            Scan, 4/24/2015 3:26:36 PM, SYSTEM, HOME-PC, Manual, Start:4/24/2015 3:20:54 PM, Duration:5 min 42 sec, Threat Scan, Completed, 0 Malware Detections, 0 Non-Malware Detections, 
            Scan, 4/24/2015 3:35:57 PM, SYSTEM, HOME-PC, Manual, Start:4/24/2015 3:31:15 PM, Duration:4 min 42 sec, Threat Scan, Completed, 0 Malware Detections, 0 Non-Malware Detections, 
             
            (end)

            Copy of Additions log

             

            Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-04-2015
            Ran by [removed] at 2015-04-24 21:50:45
            Running from C:\Users\[removed]\Desktop
            Boot Mode: Normal
            ==========================================================
             
             
            ==================== Security Center ========================
             
            (If an entry is included in the fixlist, it will be removed.)
             
            AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
             
            ==================== Installed Programs ======================
             
            (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
             
            Adobe Flash Player 17 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
            Adobe Flash Player 17 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
            Adobe Reader XI (11.0.09) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
            Adobe Shockwave Player 12.1 (HKLM\…\Adobe Shockwave Player) (Version: 12.1.2.152 - Adobe Systems, Inc.)
            calibre (HKLM\…\{3CA0D836-B5E7-463D-A1C5-9F49B3E3EDE6}) (Version: 2.20.0 - Kovid Goyal)
            Dropbox (HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\…\Dropbox) (Version: 3.4.3 - Dropbox, Inc.)
            GIMP 2.8.10 (HKLM\…\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
            Google Chrome (HKLM\…\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
            Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
            Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
            IrfanView (remove only) (HKLM\…\IrfanView) (Version: 4.37 - Irfan Skiljan)
            Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
            Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
            Microsoft .NET Framework 4 Extended (HKLM\…\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
            Mozilla Firefox 31.0 (x86 en-US) (HKLM\…\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
            Network Addon Mod (HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\…\Network Addon Mod) (Version: 32 - The NAM Team)
            NVIDIA 3D Vision Controller Driver 306.97 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 306.97 - NVIDIA Corporation)
            NVIDIA 3D Vision Driver 306.97 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 306.97 - NVIDIA Corporation)
            NVIDIA Graphics Driver 306.97 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 306.97 - NVIDIA Corporation)
            NVIDIA HD Audio Driver 1.3.18.0 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.18.0 - NVIDIA Corporation)
            NVIDIA PhysX System Software 9.12.0604 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0604 - NVIDIA Corporation)
            NVIDIA Update 1.10.8 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
            OpenOffice 4.0.1 (HKLM\…\{24B89186-2A56-4D28-B930-6F4FCF224E2F}) (Version: 4.01.9714 - Apache Software Foundation)
            SC4 Mapper 2013 (HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\…\SC4 Mapper 2013) (Version:  - )
            SimCity 4 Deluxe (HKLM\…\Steam App 24780) (Version:  - EA - Maxis)
            SketchUp 2015 (HKLM\…\{D0A0BE3D-8D66-4BE9-87C4-D30CA5AA93A3}) (Version: 15.3.330 - Trimble Navigation Limited)
            Skype Click to Call (HKLM\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
            Skype™ 7.3 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
            Steam (HKLM\…\Steam) (Version:  - Valve Corporation)
            swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
            TeamViewer 10 (HKLM\…\TeamViewer) (Version: 10.0.36897 - TeamViewer)
            Vuze (HKLM\…\8461-7759-5462-8226) (Version: 5.6.0.0 - Azureus Software, Inc.)
            WinRAR archiver (HKLM\…\WinRAR archiver) (Version:  - )
             
            ==================== Custom CLSID (selected items): ==========================
             
            (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
             
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{25815CC0-43F4-3C75-8C3A-A139D9ADE740}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> C:\Users\home\AppData\Local\Temp\8E20\temp\Ncis Season 5 (complete).torrent.exe No File
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
            CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
             
            ==================== Restore Points  =========================
             
            24-04-2015 19:29:58 Scheduled Checkpoint
             
            ==================== Hosts content: ==========================
             
            (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
             
            2009-07-14 07:34 - 2009-06-11 03:09 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
             
            ==================== Scheduled Tasks (whitelisted) =============
             
            (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
             
            Task: {04D06349-3F21-465D-8397-7EF7380D834F} - System32\Tasks\Water Tower
            Task: {0E8A3503-2BF8-4DCD-9D25-7E33D4953285} - System32\Tasks\Best Friend
            Task: {1440B270-C7D4-424E-B84B-A71D16F9486D} - System32\Tasks\Crop Dryer
            Task: {639966C3-BB7C-4A38-B2D6-BACAD5B1A319} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-04-06] (Google Inc.)
            Task: {AEAF320D-C2E0-4523-A108-F1D766E4212E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
            Task: {BF45FC34-B9F7-4C39-B248-9CBB6FFE822B} - System32\Tasks\Windmill
            Task: {C304F390-0B07-4736-93D5-96A813A48202} - System32\Tasks\Baby Girl
            Task: {D554C8C4-0378-44CD-B02D-DE64535D1D0D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-04-06] (Google Inc.)
            Task: {DB3571E6-F3ED-4404-9A5A-4B951BBFE660} - System32\Tasks\{10A98203-A9AA-4459-B606-A2FDC85BF6DE} => pcalua.exe -a "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" -c /uninstall ENTERPRISE /dll OSETUP.DLL
            Task: {E470D95D-A9D1-4EB3-89AE-425F305BA2B4} - System32\Tasks\Farmhands
             
            (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
             
            Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
            Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
            Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
             
            ==================== Loaded Modules (whitelisted) ==============
             
            2014-03-29 10:13 - 2006-09-14 00:20 - 00126464 _____ () C:\Program Files\WinRAR\rarext.dll
            2015-04-16 21:47 - 2015-04-14 03:25 - 01252680 _____ () C:\Program Files\Google\Chrome\Application\42.0.2311.90\libglesv2.dll
            2015-04-16 21:47 - 2015-04-14 03:25 - 00080712 _____ () C:\Program Files\Google\Chrome\Application\42.0.2311.90\libegl.dll
            2015-04-16 21:47 - 2015-04-14 03:25 - 14980424 _____ () C:\Program Files\Google\Chrome\Application\42.0.2311.90\PepperFlash\pepflashplayer.dll
             
            ==================== Alternate Data Streams (whitelisted) =========
             
            (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
             
            AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
            AlternateDataStreams: C:\Users\home\Documents\Vuze Downloads:com.dropbox.attributes
             
            ==================== Safe Mode (whitelisted) ===================
             
            (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
             
             
            ==================== EXE Association (whitelisted) ===============
             
            (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
             
             
            ==================== Internet Explorer trusted/restricted ===============
             
            (If an entry is included in the fixlist, the associated entry will be removed from the registry.)
             
             
            ==================== Other Areas ============================
             
            (Currently there is no automatic fix for this section.)
             
            HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\home\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
            DNS Servers: 192.168.1.1
             
            ==================== MSCONFIG/TASK MANAGER disabled items ==
             
            (Currently there is no automatic fix for this section.)
             
             
            ==================== Accounts: =============================
             
            Administrator (S-1-5-21-2690002102-2696416691-3589846356-500 - Administrator - Disabled)
            Guest (S-1-5-21-2690002102-2696416691-3589846356-501 - Limited - Enabled)
            home (S-1-5-21-2690002102-2696416691-3589846356-1000 - Administrator - Enabled) => C:\Users\home
            UpdatusUser (S-1-5-21-2690002102-2696416691-3589846356-1001 - Limited - Enabled) => C:\Users\UpdatusUser
            Vijay (S-1-5-21-2690002102-2696416691-3589846356-1002 - Administrator - Enabled) => C:\Users\Vijay
             
            ==================== Faulty Device Manager Devices =============
             
            Name: Teredo Tunneling Pseudo-Interface
            Description: Microsoft Teredo Tunneling Adapter
            Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
            Manufacturer: Microsoft
            Service: tunnel
            Problem: : This device cannot start. (Code10)
            Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
            On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
             
             
            ==================== Event log errors: =========================
             
            Application errors:
            ==================
            Error: (04/24/2015 02:50:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
            Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
             
            Error: (04/24/2015 02:49:01 PM) (Source: Winlogon) (EventID: 4103) (User: )
            Description: Windows license activation failed. Error 0x80070005.
             
            Error: (04/24/2015 02:36:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
            Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
             
            Error: (04/24/2015 02:35:03 PM) (Source: Winlogon) (EventID: 4103) (User: )
            Description: Windows license activation failed. Error 0x80070005.
             
            Error: (04/23/2015 08:43:07 AM) (Source: Winlogon) (EventID: 4103) (User: )
            Description: Windows license activation failed. Error 0x80070005.
             
            Error: (04/23/2015 04:43:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
            Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
             
            Error: (04/22/2015 11:30:19 PM) (Source: WinMgmt) (EventID: 10) (User: )
            Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
             
            Error: (04/22/2015 11:28:39 PM) (Source: Winlogon) (EventID: 4103) (User: )
            Description: Windows license activation failed. Error 0x80070005.
             
            Error: (04/22/2015 01:11:20 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
            Description: 90080108
             
            Error: (04/21/2015 06:30:06 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
            Description: 80004005
             
             
            System errors:
            =============
            Error: (04/24/2015 03:24:41 PM) (Source: volsnap) (EventID: 14) (User: )
            Description: The shadow copies of volume C: were aborted because of an IO failure on volume C:.
             
            Error: (04/24/2015 03:24:06 PM) (Source: atapi) (EventID: 11) (User: )
            Description: The driver detected a controller error on \Device\Ide\IdePort0.
             
            Error: (04/24/2015 03:24:06 PM) (Source: atapi) (EventID: 11) (User: )
            Description: The driver detected a controller error on \Device\Ide\IdePort0.
             
            Error: (04/24/2015 03:24:06 PM) (Source: atapi) (EventID: 11) (User: )
            Description: The driver detected a controller error on \Device\Ide\IdePort0.
             
            Error: (04/24/2015 03:24:06 PM) (Source: atapi) (EventID: 11) (User: )
            Description: The driver detected a controller error on \Device\Ide\IdePort0.
             
            Error: (04/24/2015 03:24:06 PM) (Source: atapi) (EventID: 11) (User: )
            Description: The driver detected a controller error on \Device\Ide\IdePort0.
             
            Error: (04/24/2015 03:24:06 PM) (Source: atapi) (EventID: 11) (User: )
            Description: The driver detected a controller error on \Device\Ide\IdePort0.
             
            Error: (04/24/2015 03:01:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
            Description: The Windows Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
             
            Error: (04/24/2015 03:01:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
            Description: The NVIDIA Update Service Daemon service terminated unexpectedly.  It has done this 1 time(s).
             
            Error: (04/24/2015 03:01:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
            Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
             
             
            Microsoft Office Sessions:
            =========================
            Error: (04/24/2015 02:50:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
            Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
             
            Error: (04/24/2015 02:49:01 PM) (Source: Winlogon) (EventID: 4103) (User: )
            Description: 0x800700050x00000000
             
            Error: (04/24/2015 02:36:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
            Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
             
            Error: (04/24/2015 02:35:03 PM) (Source: Winlogon) (EventID: 4103) (User: )
            Description: 0x800700050x00000000
             
            Error: (04/23/2015 08:43:07 AM) (Source: Winlogon) (EventID: 4103) (User: )
            Description: 0x800700050x00000000
             
            Error: (04/23/2015 04:43:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
            Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
             
            Error: (04/22/2015 11:30:19 PM) (Source: WinMgmt) (EventID: 10) (User: )
            Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
             
            Error: (04/22/2015 11:28:39 PM) (Source: Winlogon) (EventID: 4103) (User: )
            Description: 0x800700050x00000000
             
            Error: (04/22/2015 01:11:20 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
            Description: 90080108
             
            Error: (04/21/2015 06:30:06 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
            Description: 80004005
             
             
            CodeIntegrity Errors:
            ===================================
              Date: 2014-06-02 07:33:10.588
              Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
             
              Date: 2014-06-02 07:33:10.587
              Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
             
              Date: 2014-06-02 07:33:10.585
              Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
             
              Date: 2014-06-02 07:33:10.580
              Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
             
              Date: 2014-06-02 07:33:10.579
              Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
             
              Date: 2014-06-02 07:33:10.577
              Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
             
              Date: 2014-06-02 07:33:10.568
              Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
             
              Date: 2014-06-02 07:33:10.567
              Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
             
              Date: 2014-06-02 07:33:10.565
              Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
             
              Date: 2014-06-02 07:33:10.560
              Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys because the set of per-page image hashes could not be found on the system.
             
             
            ==================== Memory info =========================== 
             
            Processor: Intel(R) Core(TM) i5-3330 CPU @ 3.00GHz
            Percentage of memory in use: 39%
            Total physical RAM: 3564.05 MB
            Available physical RAM: 2154.92 MB
            Total Pagefile: 7126.39 MB
            Available Pagefile: 5058.23 MB
            Total Virtual: 3071.88 MB
            Available Virtual: 2912.05 MB
             
            ==================== Drives ================================
             
            Drive c: () (Fixed) (Total:248.69 GB) (Free:96.87 GB) NTFS
            Drive d: () (Fixed) (Total:302.97 GB) (Free:287.3 GB) NTFS
            Drive e: () (Fixed) (Total:379.75 GB) (Free:379.44 GB) NTFS
            Drive f: (GRMCHBFREO_EN_DVD) (CDROM) (Total:2.33 GB) (Free:0 GB) UDF
             
            ==================== MBR & Partition Table ==================
             
            ========================================================
            Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: F87F8A2F)
            Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
            Partition 2: (Not Active) - (Size=248.7 GB) - (Type=07 NTFS)
            Partition 3: (Not Active) - (Size=303 GB) - (Type=07 NTFS)
            Partition 4: (Not Active) - (Size=379.8 GB) - (Type=07 NTFS)
             
            ==================== End Of Log ============================
             
            Copy of FRST log
             
            Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015
            Ran by [removed] (administrator) on HOME-PC on 24-04-2015 21:50:15
            Running from C:\Users\[removed]\Desktop
            [removed]
            Platform: Microsoft Windows 7 Home Basic  Service Pack 1 (X86) OS Language: English (United States)
            Internet Explorer Version 10 (Default browser: Chrome)
            Boot Mode: Normal
            Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
             
            ==================== Processes (Whitelisted) =================
             
            (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
             
            (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
            (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
            (TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
            (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
            (Microsoft Corporation) C:\Windows\System32\dllhost.exe
            (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
            (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
             
             
            ==================== Registry (Whitelisted) ==================
             
            (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
             
            HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
            HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\…\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31682144 2015-03-25] (Skype Technologies S.A.)
            HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\…\MountPoints2: {7aa96792-b761-11e3-a2c7-806e6f6e6963} - F:\setup.exe
            HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-21] (Microsoft Corporation)
            Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-03-29]
            ShortcutTarget: Dropbox.lnk -> C:\Users\home\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
            Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ncis Season 5 (complete).torrent.lnk [2015-04-06]
            ShortcutTarget: Ncis Season 5 (complete).torrent.lnk -> C:\ProgramData\{ab145556-8da6-98fc-ab14-455568da555a}\Ncis Season 5 (complete).torrent.exe (No File)
            ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
            ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
            ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
            ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
            ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
            ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
            ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
            ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\home\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
            CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
             
            ==================== Internet (Whitelisted) ====================
             
            (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
             
            HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
            HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
            HKU\S-1-5-21-2690002102-2696416691-3589846356-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
            SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
            SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
            SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
            SearchScopes: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000 -> {76D04D07-0077-48F6-89EC-109C759AE011} URL = 
            SearchScopes: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000 -> {FDB2E2A7-C95B-46D6-8426-A9F75D6A0C1D} URL = http://search.yahoo.com/search?p={searchTerms}&fr;=tightropetb&type;=10679
            Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
            Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
            Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
            StartMenuInternet: IEXPLORE.EXE - iexplore.exe
             
            FireFox:
            ========
            FF ProfilePath: C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default
            FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
            FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1212152.dll [2014-05-30] (Adobe Systems, Inc.)
            FF Plugin: @microsoft.com/GENUINE -> disabled No File
            FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2012-10-02] (NVIDIA Corporation)
            FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2012-10-02] (NVIDIA Corporation)
            FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-06] (Google Inc.)
            FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-06] (Google Inc.)
            FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-09-12] (Adobe Systems Inc.)
            FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]
            FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC} [Not Found]
            FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7} [Not Found]
            FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{DE1C78C1-2762-47f6-A1D9-1B7866FE7EB4} [Not Found]
            FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{CA8C84C6-3918-41b1-BE77-049B2BDD887C} [Not Found]
             
            Chrome: 
            =======
            CHR dev: Chrome dev build detected! <======= ATTENTION
            CHR HomePage: Default -> hxxp://search.us.com/c/in/?guid={6E76C3BF-4D80-4E31-928C-25168F6553E1}&serpv;=5
            CHR Profile: C:\Users\home\AppData\Local\Google\Chrome\User Data\Default
            CHR Extension: (Google Slides) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-06]
            CHR Extension: (Torrent Search) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\afbpdhiclgghnffhkinjikglgmolhpee [2015-04-06]
            CHR Extension: (Google Docs) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-06]
            CHR Extension: (Google Drive) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-04-06]
            CHR Extension: (Adguard AdBlocker) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2015-04-20]
            CHR Extension: (YouTube) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-04-06]
            CHR Extension: (Solitaire) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpebaehgfgkcmmjjknibibbjacnplim [2015-04-06]
            CHR Extension: (Adblock Plus) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-04-06]
            CHR Extension: (Google Search) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-06]
            CHR Extension: (Google Calendar) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2015-04-06]
            CHR Extension: (Mahjong Solitaire) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\eogmadihniohlnmipdhchaoagjhfnohc [2015-04-06]
            CHR Extension: (Google Sheets) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-06]
            CHR Extension: (Bookmark Manager) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-17]
            CHR Extension: (Avast Online Security) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-04-20]
            CHR Extension: (Currency Converter) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\habdflddkbkcmiglihdemgpijopehham [2015-04-06]
            CHR Extension: (Timer) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhclmngbkkejbdfjmicnkmoggfpehein [2015-04-06]
            CHR Extension: (Kindle Cloud Reader) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2015-04-06]
            CHR Extension: (Autodesk Homestyler) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2015-04-06]
            CHR Extension: (Popup Blocker Pro) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiodaajmphnkcajieajajinghpejdjai [2015-04-20]
            CHR Extension: (Adblock Super) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\knebimhcckndhiglamoabbnifdkijidd [2015-04-20]
            CHR Extension: (Currency Converter) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbhghjdcfghfhlogkgdklfgmpodeglno [2015-04-06]
            CHR Extension: (Chrome Hotword Shared Module) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-24]
            CHR Extension: (Skype Click to Call) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-04-06]
            CHR Extension: (Floor plans and interior design) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcafejemebbngbglfoinpoaannbihjna [2015-04-06]
            CHR Extension: (Google Wallet) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-06]
            CHR Extension: (Adblock Pro) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2015-04-20]
            CHR Extension: (Gmail) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-06]
            CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
             
            ========================== Services (Whitelisted) =================
             
            (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
             
            R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
            R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
            S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
            R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH)
            R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
            S3 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [X]
             
            ==================== Drivers (Whitelisted) ====================
             
            (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
             
            S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
            R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-04-24] (Malwarebytes Corporation)
            S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
            R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-02] (Intel Corporation)
             
            ==================== NetSvcs (Whitelisted) ===================
             
            (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
             
             
            ==================== One Month Created Files and Folders ========
             
            (If an entry is included in the fixlist, the file\folder will be moved.)
             
            2015-04-24 17:04 - 2015-04-24 17:04 - 00015594 _____ () C:\Users\home\AppData\Local\recently-used.xbel
            2015-04-24 15:14 - 2015-04-24 15:18 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
            2015-04-24 15:14 - 2015-04-24 15:14 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
            2015-04-24 15:14 - 2015-04-24 15:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
            2015-04-24 15:14 - 2015-04-24 15:14 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
            2015-04-24 15:14 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
            2015-04-24 15:14 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
            2015-04-24 15:14 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
            2015-04-24 15:07 - 2015-04-24 15:12 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\home\Desktop\mbam-setup-2.1.6.1022 (1).exe
            2015-04-24 15:01 - 2015-04-24 15:01 - 00001004 _____ () C:\Users\home\Desktop\JRT.txt
            2015-04-24 15:01 - 2015-04-24 15:01 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-HOME-PC-Windows-7-Home-Basic-(32-bit).dat
            2015-04-24 15:01 - 2015-04-24 15:01 - 00000000 ____D () C:\RegBackup
            2015-04-24 14:57 - 2015-04-24 14:57 - 02685461 _____ (Thisisu) C:\Users\home\Desktop\JRT.exe
            2015-04-24 14:43 - 2015-04-24 14:47 - 00000000 ____D () C:\AdwCleaner
            2015-04-24 14:39 - 2015-04-24 14:40 - 02224640 _____ () C:\Users\home\Desktop\adwcleaner_4.202.exe
            2015-04-23 08:51 - 2015-04-23 08:51 - 00001208 _____ () C:\Users\home\Desktop\ckfiles.txt
            2015-04-23 08:47 - 2015-04-23 08:48 - 00468480 _____ () C:\Users\home\Desktop\CKScanner.exe
            2015-04-22 23:12 - 2015-04-22 23:18 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\home\Desktop\mbam-setup-2.1.6.1022.exe
            2015-04-21 06:55 - 2015-04-21 06:55 - 00025607 _____ () C:\Users\home\Desktop\Addition.txt
            2015-04-21 06:54 - 2015-04-24 21:50 - 00014803 _____ () C:\Users\home\Desktop\FRST.txt
            2015-04-21 06:54 - 2015-04-24 21:50 - 00000000 ____D () C:\FRST
            2015-04-21 06:52 - 2015-04-21 06:53 - 01139200 _____ (Farbar) C:\Users\home\Desktop\FRST.exe
            2015-04-21 06:42 - 2015-04-21 06:42 - 00002486 _____ () C:\Users\home\Documents\aswMBR.txt
            2015-04-21 06:42 - 2015-04-21 06:42 - 00000512 _____ () C:\Users\home\Documents\MBR.dat
            2015-04-21 03:38 - 2015-04-21 03:38 - 00010608 _____ () C:\Users\home\Documents\KIRAN BUDGET.ods
            2015-04-19 00:30 - 2015-04-01 11:22 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
            2015-04-17 10:06 - 2015-04-17 10:06 - 00000000 ____D () C:\Program Files\Enigma Software Group
            2015-04-15 21:58 - 2015-04-24 14:35 - 00000020 _____ () C:\Users\home\AppData\Roaming\appdataFr3.bin
            2015-04-15 15:31 - 2015-04-22 23:28 - 00000000 ____D () C:\Program Files\TerminusAppend
            2015-04-13 09:22 - 2015-04-13 09:57 - 00130016 _____ () C:\Users\home\Documents\house.skp
            2015-04-07 03:27 - 2014-07-01 03:44 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
            2015-04-07 03:27 - 2014-06-06 11:46 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
            2015-04-07 03:27 - 2014-03-10 03:17 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
            2015-04-07 03:27 - 2014-03-10 03:17 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
            2015-04-07 03:26 - 2012-03-01 11:03 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
            2015-04-07 03:24 - 2015-04-07 03:25 - 00003604 _____ () C:\Windows\IE9_main.log
            2015-04-07 03:05 - 2015-04-07 03:05 - 14380544 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 13768704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 02864640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
            2015-04-07 03:05 - 2015-04-07 03:05 - 02055680 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 01763328 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 01441280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
            2015-04-07 03:05 - 2015-04-07 03:05 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
            2015-04-07 03:05 - 2015-04-07 03:05 - 01181696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00745472 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
            2015-04-07 03:05 - 2015-04-07 03:05 - 00719360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00629248 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
            2015-04-07 03:05 - 2015-04-07 03:05 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
            2015-04-07 03:05 - 2015-04-07 03:05 - 00138752 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
            2015-04-07 03:05 - 2015-04-07 03:05 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
            2015-04-07 03:05 - 2015-04-07 03:05 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
            2015-04-07 03:05 - 2015-04-07 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
            2015-04-07 03:05 - 2015-04-07 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
            2015-04-07 03:05 - 2015-04-07 03:05 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
            2015-04-07 03:05 - 2015-04-07 03:05 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
            2015-04-07 03:05 - 2015-04-07 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
            2015-04-07 03:05 - 2015-04-07 03:05 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
            2015-04-07 03:03 - 2015-04-07 03:03 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 01988096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
            2015-04-07 03:03 - 2015-04-07 03:03 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
            2015-04-07 03:02 - 2015-04-07 03:02 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
            2015-04-07 03:01 - 2015-04-07 03:06 - 00012251 _____ () C:\Windows\IE10_main.log
            2015-04-06 19:43 - 2015-04-06 19:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
            2015-04-06 19:41 - 2015-04-24 21:46 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
            2015-04-06 19:41 - 2015-04-24 19:46 - 00000878 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
            2015-04-06 19:41 - 2015-04-06 19:41 - 00000000 ____D () C:\Users\home\AppData\Local\Deployment
            2015-04-06 19:41 - 2015-04-06 19:41 - 00000000 ____D () C:\Users\home\AppData\Local\Apps\2.0
            2015-04-06 19:16 - 2014-09-04 10:34 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
            2015-04-06 19:15 - 2015-03-06 10:45 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
            2015-04-06 19:15 - 2015-03-06 10:45 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
            2015-04-06 19:15 - 2015-03-06 10:40 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
            2015-04-06 19:15 - 2015-03-06 10:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
            2015-04-06 19:15 - 2015-03-06 10:40 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
            2015-04-06 19:15 - 2015-03-06 10:40 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
            2015-04-06 19:15 - 2015-03-06 10:40 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
            2015-04-06 19:15 - 2015-03-06 10:40 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
            2015-04-06 19:15 - 2015-03-06 10:40 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
            2015-04-06 19:15 - 2015-03-06 10:40 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
            2015-04-06 19:15 - 2015-03-06 10:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
            2015-04-06 19:15 - 2015-03-06 10:40 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
            2015-04-06 19:15 - 2015-03-06 10:40 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
            2015-04-06 19:15 - 2015-03-06 10:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
            2015-04-06 19:15 - 2015-03-06 10:39 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
            2015-04-06 19:15 - 2015-03-06 10:37 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
            2015-04-06 19:15 - 2015-03-06 10:37 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
            2015-04-06 19:15 - 2015-03-06 10:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
            2015-04-06 19:15 - 2015-02-26 08:41 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
            2015-04-06 19:15 - 2015-02-20 09:43 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
            2015-04-06 19:15 - 2015-02-20 09:43 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
            2015-04-06 19:15 - 2015-02-20 09:43 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
            2015-04-06 19:15 - 2015-02-20 09:43 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
            2015-04-06 19:15 - 2015-02-20 08:39 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
            2015-04-06 19:15 - 2015-02-13 10:56 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
            2015-04-06 19:15 - 2015-02-03 08:42 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
            2015-04-06 19:15 - 2015-01-17 08:00 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
            2015-04-06 19:15 - 2014-12-19 08:13 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
            2015-04-06 19:15 - 2014-12-11 23:17 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
            2015-04-06 19:15 - 2014-10-25 07:02 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
            2015-04-06 19:15 - 2014-07-17 07:09 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
            2015-04-06 19:15 - 2014-07-17 07:09 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
            2015-04-06 19:15 - 2014-06-19 03:53 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
            2015-04-06 19:15 - 2014-06-19 03:53 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
            2015-04-06 19:15 - 2014-06-19 03:53 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
            2015-04-06 19:15 - 2014-06-18 07:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
            2015-04-06 19:15 - 2014-06-06 15:14 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
            2015-04-06 19:15 - 2014-06-03 15:00 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
            2015-04-06 19:15 - 2014-06-03 14:59 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
            2015-04-06 19:15 - 2014-06-03 14:59 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
            2015-04-06 19:15 - 2014-06-03 14:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
            2015-04-06 19:15 - 2014-05-30 12:06 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
            2015-04-06 19:15 - 2014-04-05 07:55 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
            2015-04-06 19:15 - 2014-04-05 07:54 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
            2015-04-06 19:15 - 2013-11-26 16:41 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
            2015-04-06 19:14 - 2015-02-03 08:46 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
            2015-04-06 19:14 - 2015-02-03 08:46 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
            2015-04-06 19:14 - 2015-02-03 08:46 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
            2015-04-06 19:14 - 2015-02-03 08:42 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
            2015-04-06 19:14 - 2015-02-03 08:42 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
            2015-04-06 19:14 - 2015-02-03 08:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
            2015-04-06 19:14 - 2015-02-03 08:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
            2015-04-06 19:14 - 2015-02-03 08:41 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
            2015-04-06 19:14 - 2015-02-03 08:41 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
            2015-04-06 19:14 - 2015-02-03 08:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
            2015-04-06 19:14 - 2015-02-03 08:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
            2015-04-06 19:14 - 2015-02-03 08:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
            2015-04-06 19:14 - 2015-02-03 08:41 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
            2015-04-06 19:14 - 2015-02-03 08:41 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
            2015-04-06 19:14 - 2015-02-03 08:41 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
            2015-04-06 19:14 - 2015-02-03 08:41 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
            2015-04-06 19:14 - 2015-02-03 08:40 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
            2015-04-06 19:14 - 2015-02-03 08:39 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
            2015-04-06 19:14 - 2015-02-03 08:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
            2015-04-06 19:14 - 2015-02-03 08:30 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
            2015-04-06 19:14 - 2015-02-03 07:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
            2015-04-06 19:14 - 2015-01-31 05:26 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
            2015-04-06 19:14 - 2014-12-19 07:04 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
            2015-04-06 19:14 - 2014-12-08 08:16 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
            2015-04-06 19:14 - 2014-12-06 09:20 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
            2015-04-06 19:14 - 2014-11-01 03:52 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
            2015-04-06 19:14 - 2014-10-14 07:20 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
            2015-04-06 19:14 - 2014-07-17 07:10 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
            2015-04-06 19:14 - 2014-07-17 07:09 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
            2015-04-06 19:14 - 2014-07-17 07:09 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
            2015-04-06 19:14 - 2014-07-17 07:09 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
            2015-04-06 19:14 - 2014-07-17 06:33 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
            2015-04-06 19:14 - 2014-07-17 06:32 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
            2015-04-06 19:14 - 2014-06-28 05:51 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
            2015-04-06 19:14 - 2014-06-28 05:51 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
            2015-04-06 19:14 - 2014-04-25 07:36 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
            2015-04-06 19:14 - 2012-10-03 22:12 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
            2015-04-06 19:14 - 2012-10-03 22:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
            2015-04-06 18:48 - 2014-05-14 21:53 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
            2015-04-06 18:48 - 2014-05-14 21:53 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
            2015-04-06 18:48 - 2014-05-14 21:53 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
            2015-04-06 18:48 - 2014-05-14 21:47 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
            2015-04-06 18:48 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
            2015-04-06 18:48 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
            2015-04-06 00:36 - 2015-04-15 23:52 - 00000000 ____D () C:\ProgramData\13485036209175509208
            2015-04-05 19:29 - 2015-04-06 00:36 - 00000000 ____D () C:\Users\home\Documents\The Mentalist
            2015-04-04 23:14 - 2015-04-04 23:14 - 00000000 __SHD () C:\found.000
            2015-04-02 00:59 - 2015-04-02 00:59 - 00002064 _____ () C:\Users\Vijay\Desktop\FastDownload.com.lnk
            2015-04-02 00:59 - 2015-04-02 00:59 - 00002064 _____ () C:\Users\UpdatusUser\Desktop\FastDownload.com.lnk
            2015-04-02 00:59 - 2015-04-02 00:59 - 00002056 _____ () C:\Users\Vijay\Desktop\GameTeam.com.lnk
            2015-04-02 00:59 - 2015-04-02 00:59 - 00002056 _____ () C:\Users\UpdatusUser\Desktop\GameTeam.com.lnk
            2015-04-02 00:59 - 2015-04-02 00:59 - 00002054 _____ () C:\Users\Vijay\Desktop\GameTop.com.lnk
            2015-04-02 00:59 - 2015-04-02 00:59 - 00002054 _____ () C:\Users\UpdatusUser\Desktop\GameTop.com.lnk
            2015-03-30 01:20 - 2015-03-30 01:20 - 00000000 ____D () C:\ProgramData\Playrix Entertainment
             
            ==================== One Month Modified Files and Folders =======
             
            (If an entry is included in the fixlist, the file\folder will be moved.)
             
            2015-04-24 21:49 - 2014-05-12 14:14 - 00000000 ____D () C:\Users\home\AppData\Roaming\Skype
            2015-04-24 21:44 - 2014-03-29 19:18 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
            2015-04-24 17:04 - 2014-03-31 11:56 - 00000000 ____D () C:\Users\home\.gimp-2.8
            2015-04-24 15:00 - 2015-02-02 13:00 - 00061553 _____ () C:\Users\home\Network_Meter_Data.js
            2015-04-24 15:00 - 2014-06-02 20:22 - 00001945 _____ () C:\Windows\epplauncher.mif
            2015-04-24 14:51 - 2014-03-29 10:01 - 01852180 _____ () C:\Windows\WindowsUpdate.log
            2015-04-24 14:49 - 2015-02-02 12:49 - 00004185 _____ () C:\Users\home\IP_Log_Data.js
            2015-04-24 14:49 - 2014-03-29 23:43 - 00000000 ___RD () C:\Users\home\Dropbox
            2015-04-24 14:49 - 2014-03-29 23:38 - 00000000 ____D () C:\Users\home\AppData\Roaming\Dropbox
            2015-04-24 14:48 - 2014-03-29 10:06 - 00000000 ____D () C:\ProgramData\NVIDIA
            2015-04-24 14:48 - 2009-07-14 10:23 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
            2015-04-24 14:48 - 2009-07-14 10:09 - 00005147 _____ () C:\Windows\setupact.log
            2015-04-24 14:34 - 2010-11-21 03:18 - 01654860 _____ () C:\Windows\PFRO.log
            2015-04-23 04:41 - 2015-02-04 13:44 - 00000027 _____ () C:\Users\home\AppData\Roaming\Network Meter_Usage.ini
            2015-04-22 23:27 - 2014-05-27 23:31 - 00000000 ____D () C:\Users\home\AppData\Roaming\Azureus
            2015-04-22 23:27 - 2009-07-14 10:04 - 00020640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
            2015-04-22 23:27 - 2009-07-14 10:04 - 00020640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
            2015-04-21 04:07 - 2014-03-31 11:59 - 00000000 ____D () C:\Users\home\AppData\Local\gtk-2.0
            2015-04-20 14:54 - 2014-05-12 14:14 - 00000000 ____D () C:\ProgramData\Skype
            2015-04-17 11:25 - 2014-03-29 10:18 - 00001104 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
            2015-04-17 11:25 - 2014-03-29 10:03 - 00001417 _____ () C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
            2015-04-15 07:44 - 2014-03-29 10:12 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
            2015-04-15 07:44 - 2014-03-29 10:12 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
            2015-04-13 23:33 - 2014-03-29 23:43 - 00000976 _____ () C:\Users\home\Desktop\Dropbox.lnk
            2015-04-13 23:33 - 2014-03-29 23:41 - 00000000 ____D () C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
            2015-04-07 10:08 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\rescache
            2015-04-07 05:02 - 2009-07-14 10:16 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
            2015-04-07 04:58 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\Microsoft.NET
            2015-04-07 04:56 - 2010-11-21 02:31 - 00782922 _____ () C:\Windows\system32\PerfStringBackup.INI
            2015-04-07 04:52 - 2009-07-14 10:03 - 00432504 _____ () C:\Windows\system32\FNTCACHE.DAT
            2015-04-07 04:50 - 2009-07-14 10:22 - 00000000 ____D () C:\Program Files\Windows Defender
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\zh-TW
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\zh-HK
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\zh-CN
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\tr-TR
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\sv-SE
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\ru-RU
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\pt-PT
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\pt-BR
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\pl-PL
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\nl-NL
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\nb-NO
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\ko-KR
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\ja-JP
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\it-IT
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\hu-HU
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\fr-FR
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\fi-FI
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\el-GR
            2015-04-07 04:50 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\de-DE
            2015-04-07 03:09 - 2014-06-03 03:03 - 00448352 _____ () C:\Windows\msxml4-KB954430-enu.LOG
            2015-04-07 03:08 - 2014-06-03 03:03 - 00446498 _____ () C:\Windows\msxml4-KB973688-enu.LOG
            2015-04-06 19:43 - 2014-03-29 19:26 - 00000000 ____D () C:\Users\home\AppData\Local\Google
            2015-04-06 19:43 - 2014-03-29 19:26 - 00000000 ____D () C:\Program Files\Google
            2015-04-06 18:10 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\Registration
            2015-04-06 01:18 - 2014-05-15 02:47 - 00000000 ____D () C:\Program Files\SketchUp
            2015-04-06 00:38 - 2014-12-21 21:39 - 00000000 ____D () C:\Users\home\AppData\Local\CrashDumps
            2015-04-06 00:37 - 2014-09-10 07:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
            2015-03-31 02:39 - 2014-06-01 02:46 - 00000000 ____D () C:\Users\home\AppData\Roaming\calibre
            2015-03-31 02:37 - 2014-06-01 02:46 - 00000000 ____D () C:\Users\home\Documents\Calibre Library
            2015-03-27 20:15 - 2014-06-01 02:47 - 00000000 ____D () C:\Users\home\AppData\Local\calibre-cache
            2015-03-27 19:50 - 2014-11-17 08:46 - 00000000 ____D () C:\Users\Vijay\AppData\Roaming\Adobe
            2015-03-25 00:02 - 2014-03-29 10:11 - 00000000 ____D () C:\ProgramData\Adobe
            2015-03-25 00:01 - 2014-09-28 21:39 - 00000000 ____D () C:\Users\home\AppData\Local\Adobe
            2015-03-25 00:01 - 2014-03-29 19:18 - 00000000 ____D () C:\Users\home\AppData\Roaming\Adobe
             
            ==================== Files in the root of some directories =======
             
            2015-02-02 12:46 - 2013-10-15 14:51 - 0351086 _____ () C:\Program Files\Network_Meter_V9.6.gadget
            2015-04-15 21:58 - 2015-04-24 14:35 - 0000020 _____ () C:\Users\home\AppData\Roaming\appdataFr3.bin
            2015-02-02 12:50 - 2015-03-05 16:31 - 0000812 _____ () C:\Users\home\AppData\Roaming\Network Meter_Settings.ini
            2015-02-04 13:44 - 2015-04-23 04:41 - 0000027 _____ () C:\Users\home\AppData\Roaming\Network Meter_Usage.ini
            2015-01-03 04:01 - 2015-01-03 04:01 - 0003584 _____ () C:\Users\home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
            2015-04-24 17:04 - 2015-04-24 17:04 - 0015594 _____ () C:\Users\home\AppData\Local\recently-used.xbel
            2015-04-06 01:16 - 2015-04-18 10:29 - 0011346 _____ () C:\Users\home\AppData\Local\Temp-log.txt
             
            Files to move or delete:
            ====================
            C:\Users\home\IP_Log_Data.js
            C:\Users\home\Network_Meter_Data.js
             
             
            Some content of TEMP:
            ====================
            C:\Users\home\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpiauvzi.dll
            C:\Users\home\AppData\Local\Temp\FastDownloadTNT.exe
            C:\Users\home\AppData\Local\Temp\i4jdel0.exe
            C:\Users\home\AppData\Local\Temp\Quarantine.exe
            C:\Users\home\AppData\Local\Temp\SkypeSetup.exe
            C:\Users\home\AppData\Local\Temp\sqlite3.dll
             
             
            ==================== Bamital & volsnap Check =================
             
            (There is no automatic fix for files that do not pass verification.)
             
            C:\Windows\explorer.exe => File is digitally signed
            C:\Windows\system32\winlogon.exe => File is digitally signed
            C:\Windows\system32\wininit.exe => File is digitally signed
            C:\Windows\system32\svchost.exe => File is digitally signed
            C:\Windows\system32\services.exe => File is digitally signed
            C:\Windows\system32\User32.dll => MD5 is legit
            C:\Windows\system32\userinit.exe => File is digitally signed
            C:\Windows\system32\rpcss.dll => File is digitally signed
            C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
             
             
            LastRegBack: 2015-04-24 17:43
             
            ==================== End Of Log ============================

            While I am looking over your new logs, run this quick scan and post the log please

             

            Download CKScanner by askey127 from Here & save it to your Desktop.
            • Doubleclick CKScanner.exe then click Search For Files
            • When the cursor hourglass disappears, click Save List To File
            • A message box will verify the file saved
            • Please Run this program only once
            • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
            • CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
              c:\program files\gimp 2\share\gimp\2.0\patterns\cracked.pat
              c:\users\home\documents\plugins\fukuda folder\naphtha cracking plant\fk_naphtha_cracker1-0x5ad0e817_0xd5ec2156_0x20000.sc4model
              c:\users\home\documents\plugins\fukuda folder\naphtha cracking plant\fk_naphtha_cracker1-0x6534284a-0xd5ec2156-0x35f16fc4.sc4desc
              c:\users\home\documents\plugins\fukuda folder\naphtha cracking plant\i-m3_2x4_naptha_cracker_b5f17114.sc4lot
              c:\users\home\documents\sc4 custom content\fukuda folder\naphtha cracking unit\fk_naphtha_cracker.zip
              c:\users\home\documents\sc4 custom content\fukuda folder\naphtha cracking unit\naphtha cracking unit.txt
              c:\users\home\documents\simcity 4\plugins\fukuda folder\naphtha cracking plant\fk_naphtha_cracker1-0x5ad0e817_0xd5ec2156_0x20000.sc4model
              c:\users\home\documents\simcity 4\plugins\fukuda folder\naphtha cracking plant\fk_naphtha_cracker1-0x6534284a-0xd5ec2156-0x35f16fc4.sc4desc
              c:\users\home\documents\simcity 4\plugins\fukuda folder\naphtha cracking plant\i-m3_2x4_naptha_cracker_b5f17114.sc4lot
              c:\windows\system32\slmgr.vbs.removewat
              scanner sequence 3.CG.11.SVAAXB
               —– EOF —– 

              I am attaching a FIXLIST file, you need to download it to your desktop where you now have FRST or the fix wont work, use your mouse to drag FIXLIST right next to FRST, either above or below it but not right on top of it, after its downloaded open up FRST and click on FIX (Not Scan) it wont take long, after your computer reboots you will find a FIXLOG file on your desktop, post it please and let me know if there has been any improvement with your system.

              Attachments:

              Thanks you for the continued help.

               

              Copy of Fixlog.txt

               

              Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 20-04-2015
              Ran by [removed] at 2015-04-25 09:13:48 Run:1
              Running from C:\Users\[removed]\Desktop
              [removed]
              Boot Mode: Normal
               
              ==============================================
               
              Content of fixlist:
              *****************
              Start
              CreateRestorePoint: 
              CloseProcesses:
              Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ncis Season 5 (complete).torrent.lnk [2015-04-06]
              ShortcutTarget: Ncis Season 5 (complete).torrent.lnk -> C:\ProgramData\{ab145556-8da6-98fc-ab14-455568da555a}\Ncis Season 5 (complete).torrent.exe (No File)
              CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
              FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC} [Not Found]
              FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{DE1C78C1-2762-47f6-A1D9-1B7866FE7EB4} [Not Found]
              FF Extension: No Name - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{CA8C84C6-3918-41b1-BE77-049B2BDD887C} [Not Found]
              CHR HomePage: Default -> hxxp://search.us.com/c/in/?guid={6E76C3BF-4D80-4E31-928C-25168F6553E1}&serpv=5
              CHR Extension: (Torrent Search) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\afbpdhiclgghnffhkinjikglgmolhpee [2015-04-06]
              CustomCLSID: HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> C:\Users\home\AppData\Local\Temp\8E20\temp\Ncis Season 5 (complete).torrent.exe No File
              CMD: ipconfig /flushdns
              Hosts:
              EmptyTemp:
              End
               
               
               
               
               
               
               
               
               
               
              *****************
               
              Restore point was successfully created.
              Processes closed successfully.
              C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ncis Season 5 (complete).torrent.lnk => Moved successfully.
              C:\ProgramData\{ab145556-8da6-98fc-ab14-455568da555a}\Ncis Season 5 (complete).torrent.exe not found.
              "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
              C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC} => not found.
              C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{DE1C78C1-2762-47f6-A1D9-1B7866FE7EB4} => not found.
              C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\h1fqe27t.default\extensions\{CA8C84C6-3918-41b1-BE77-049B2BDD887C} => not found.
              Chrome HomePage deleted successfully.
              C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\afbpdhiclgghnffhkinjikglgmolhpee => Moved successfully.
              "HKU\S-1-5-21-2690002102-2696416691-3589846356-1000_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}" => Key deleted successfully.
               
              =========  ipconfig /flushdns =========
               
               
              Windows IP Configuration
               
              Successfully flushed the DNS Resolver Cache.
               
              ========= End of CMD: =========
               
              C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
              Hosts was reset successfully.
              EmptyTemp: => Removed 1.4 GB temporary data.
               
               
              The system needed a reboot. 
               
              ==== End of Fixlog 09:15:22 ====
               
              There are still some 'NoMoreAds' advertisements popping up and occasionally my browser opens up another page. The virus that was making individual words turn into links has gone away.  I have attached some pictures.
               

              You didn't specify what browser your having these problems with ???

               

              Download Avast-browser-cleanup to your desktop
               
              • There is nothing to  install, just right click on it and Run As Adminstrator
              • When its finished scanning it will list Browser Add ONs
              • If if finds NoMoreAds or any other bogus toolbars
              • Just high light them and select REMOVE
              • Close out the program
              • Reboot your system and test your browsers
              • Hi again.  Thank you for all the time you have spent trying to get these ads off of my browser.  I use Chrome.  I also have Firefox , but I prefer Chrome.  Mostly I go to my Gmail, then Facebook , then Farmville on zynga.com.  Then I watch YouTube.  I won't be downloading any more torrents.  In June I will be moving back to Canada.  I have been living in India since 2008.  The OS on this computer is for use in India only so I will have to get a new OS when I move to Canada.  I think wiping out the entire HD and re-installing a new OS will clear out this virus, right?  :D

                Ask AI

                AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

                Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI