Virus encrypted every folder. Each folder has the attacker's message of asking for $$$ by linking to their website. Sample of the message as attachedHELP_DECRYPT.TXT
aswMBR & FRST scan results as below:-
aswMBR version 1.0.1.2252 CopyrightΒ© 2014 AVAST Software
Run date: 2015-06-24 15:45:57
ββββββββββ
15:45:57.220 OS Version: Windows x64 6.1.7601 Service Pack 1
15:45:57.225 Number of processors: 4 586 0x2A07
15:45:57.235 ComputerName: L125 UserName:
15:46:11.420 Initialize success
15:46:13.495 VM: initialized successfully
15:46:13.495 VM: Intel CPU supported
15:46:37.390 VM: not used
15:49:45.651 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
15:49:45.771 Disk 0 Vendor: ST950032 0001 Size: 476940MB BusType: 3
15:49:46.326 Disk 0 MBR read successfully
15:49:46.336 Disk 0 MBR scan
15:49:46.341 Disk 0 Windows 7 default MBR code
15:49:46.381 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 17000 MB offset 2048
15:49:46.411 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 34818048
15:49:46.431 Disk 0 default boot code
15:49:46.511 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 459838 MB offset 35022848
15:49:46.926 Disk 0 scanning C:\Windows\system32\drivers
15:50:12.541 Service scanning
15:50:43.816 Modules scanning
15:50:43.841 Disk 0 trace - called modules:
15:50:43.861 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys
15:50:43.876 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80059df060]
15:50:43.886 3 CLASSPNP.SYS[fffff880013c643f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8003eff050]
15:50:43.896 Disk 0 statistics 104559/0/0 @ 2.37 MB/s
15:50:43.911 Scan finished successfully
15:51:08.571 Disk 0 MBR has been saved successfully to "C:\Users\L125-User\Desktop\MBR.dat"
15:51:08.651 The log file has been saved successfully to "C:\Users\L125-User\Desktop\aswMBR_Log_24062015.txt"
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:21-06-2015 01
Ran by [removed] (administrator) on L125 on 24-06-2015 16:05:54
Running from C:\Users\[removed]\Downloads\Applications
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Juniper Networks) C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\n360.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\β¦\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2264168 2011-07-14] (Realtek Semiconductor)
HKLM\β¦\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [976032 2011-09-17] (Atheros Commnucations)
HKLM\β¦\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [799904 2011-09-17] (Atheros Commnucations)
HKLM\β¦\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831016 2011-08-03] (Acer Incorporated)
HKLM-x32\β¦\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-24] (NTI Corporation)
HKLM-x32\β¦\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-18] (Renesas Electronics Corporation)
HKLM-x32\β¦\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-15] (Dritek System Inc.)
HKLM-x32\β¦\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-21] (Egis Technology Inc.)
HKLM-x32\β¦\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [2005896 2015-03-26] (APN)
HKLM-x32\β¦\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\β¦\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\β¦\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\β¦\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\Run: [Google Update] => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-10-01] (Google Inc.)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\Run: [uTorrent] => C:\Users\L125-User\AppData\Roaming\uTorrent\uTorrent.exe [1694560 2015-05-07] (BitTorrent Inc.)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\Run: [Office Timeline Performance Helper] => C:\Program Files (x86)\Office Timeline\Current\OfficeTimelineStartup.exe [13056 2014-12-19] (OfficeTimeline LLC)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\Run: [GoogleChromeAutoLaunch_051EAC4AE0499CBFED74E720976D3C62] => C:\Users\L125-User\AppData\Local\Google\Chrome\Application\chrome.exe [813896 2015-06-20] (Google Inc.)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\MountPoints2: {96387663-87c0-11e3-a661-7ce9d3415466} - E:\AutoRun.exe
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\MountPoints2: {96387672-87c0-11e3-a661-7ce9d3415466} - E:\AutoRun.exe
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\MountPoints2: {abfdd583-0df3-11e3-9964-7ce9d3415466} - E:\StartUse.exe
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [477696 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-18\β¦\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [241984 2011-11-28] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [203072 2011-11-28] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [1aCopyShExtError] -> {83BEA36E-7680-4598-A4DF-994426F6E78D} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [2aCopyShExtSynced] -> {845B7388-6F85-4F32-9FD5-F02DC7882B89} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [3aCopyShExtSyncing] -> {F6378A7A-F753-449B-AE1B-997A96132E61} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [4aCopyShExtSyncingProg1] -> {3A511828-777D-46F8-82F4-5B530C1B3D9E} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [5aCopyShExtSyncingProg2] -> {C8C88204-5B14-40EC-BA72-8AEBC762047E} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [6aCopyShExtSyncingProg3] -> {ACFF45C3-3EEB-4351-86C2-6696BA264239} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [7aCopyShExtSyncingProg4] -> {29AF997F-488B-46F0-AE78-7146F1B89CC3} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [8aCopyShExtSyncingProg5] -> {03F9AD29-1C78-4B66-8890-B177B5430C53} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\buShell.dll [2014-02-27] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\buShell.dll [2014-02-27] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\buShell.dll [2014-02-27] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll [2012-11-14] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-2850245000-3638546127-566686928-1004] => internet.bernas.com.my:8080
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
URLSearchHook: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
URLSearchHook: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> DefaultScope {8ADEA77F-0B0A-43C8-9A51-5E81E645DAB1} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {1ACB839D-54D8-4E6E-BE51-203DD8AC7D51} URL = https://malaysia.search.yahoo.com/search?fr=chr-greentree_ie&ei;=utf-8&ilc;=12&type;=523694&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {6797A420-6EE4-4C54-A46C-05E0AFC65624} URL = http://www.search.ask.com/web?tpid=BTRSP-C&o;=APN11818&pf;=V7&p2;=^BVK^YYYYYY^YY^MY&gct;=&itbv;=12.23.0.200&apn;_uid=FA94CA64-AF74-4212-A5EA-AE35B7579139&apn;_ptnrs=^BVK&apn;_dtid=^YYYYYY^YY^MY&apn;_dbr=iexplore.exe_6_11.0.9600.17496&doi;=2015-01-27&trgb;=IE&q;={searchTerms}&psv;=&pt;=crx
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {8ADEA77F-0B0A-43C8-9A51-5E81E645DAB1} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {A13956EF-1354-45FF-9F83-14602E789106} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3220468
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Javaβ’ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2013-01-01] (Sun Microsystems, Inc.)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\IPS\IPSBHO.DLL [2014-07-23] (Symantec Corporation)
BHO-x32: uTorrentControl_v2 Toolbar -> {7473b6bd-4691-4744-a82b-7854eb3d70b6} -> C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09] (Conduit Ltd.)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-09-17] (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Javaβ’ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-06] (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
Toolbar: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09] (Conduit Ltd.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> No Name - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - No File
Toolbar: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
DPF: HKLM {AA570693-00E2-4907-B6F1-60A1199B030C} https://juniper.net/dana-cached/sc/JuniperSetupClient64.cab
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: HKLM-x32 {1FAF427B-1EE5-43D3-A023-3009142AFCE1} https://www2.pbebank.com/ebroking/wecos/control/csoex_pbb.cab
DPF: HKLM-x32 {B9B2EE1A-E314-4338-A305-BE845EACB113} https://www2.pbebank.com/ebroking/wecos/control/csw25.cab
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.webex.com/client/WBXclient-T28L10NSP11-16469/webex/ieatgpc1.cab
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://175.143.72.146/dana-cached/sc/JuniperSetupClient.cab
Handler: qvp - {4BA78E3D-CA25-4BFF-B8F0-8A3359E4B520} - C:\Program Files\QlikView\QvProtocol\qvp.dll [2013-12-04] (QlikTech AB)
Handler-x32: qvp - {4BA78E3D-CA25-4BFF-B8F0-8A3359E4B520} - C:\Program Files (x86)\QlikView\QvProtocol\qvp.dll [2013-12-04] (QlikTech AB)
Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 208.67.220.220
Tcpip\..\Interfaces\{173178E3-F0E6-4285-9A89-9931024E8A11}: [NameServer] 58.71.136.10 58.71.132.10
FireFox:
========
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2013-01-01] (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-09-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=10.7.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2012-09-06] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-08] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2850245000-3638546127-566686928-1004: @tools.google.com/Google Update;version=3 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-2850245000-3638546127-566686928-1004: @tools.google.com/Google Update;version=9 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF HKLM-x32\β¦\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\coFFPlgn [2014-10-01]
FF HKLM-x32\β¦\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\IPSFF [2014-04-17]
Chrome:
=======
CHR Profile: C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (uTorrentControl_v2) - C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda [2012-11-01]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-18]
CHR Extension: (Google Wallet) - C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-04]
CHR HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\Google\Chrome\Extensions\β¦\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\L125-U~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-02]
CHR HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\Google\Chrome\Extensions\β¦\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\L125-User\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-08-26]
CHR HKLM-x32\β¦\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\L125-User\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-08-26]
CHR HKLM-x32\β¦\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\β¦\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\Exts\Chrome.crx [Not Found]
StartMenuInternet: Google Chrome.NWXNVHEFLZDMPKGIU56VFXSQHE - C:\Users\L125-User\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [180632 2015-03-26] (APN LLC.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [105120 2011-09-17] (Atheros Commnucations) [File not signed]
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [145920 2010-10-25] (HP) [File not signed]
R2 N360; C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\N360.exe [265040 2014-08-01] (Symantec Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2012-02-08] (Hewlett-Packard) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2012-02-08] (Hewlett-Packard) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S1 BHDrvx64; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\BASHDefs\20140912.003\BHDrvx64.sys [1586904 2014-09-13] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1505000.013\ccSetx64.sys [162392 2014-02-25] (Symantec Corporation)
R3 dsNcAdpt; C:\Windows\System32\DRIVERS\dsNcAdX64.sys [29184 2008-05-01] (Juniper Networks)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-09-09] (Symantec Corporation)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
R1 IDSVia64; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\IPSDefs\20140930.001\IDSvia64.sys [633560 2014-09-02] (Symantec Corporation)
S3 jnprva; C:\Windows\System32\DRIVERS\jnprva.sys [26480 2012-08-02] (Juniper Networks, Inc.)
S3 JnprVaMgr; C:\Windows\System32\DRIVERS\jnprvamgr.sys [45352 2012-08-02] (Juniper Networks, Inc.)
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2011-04-04] (Marvell Semiconductor, Inc.)
S3 NAVENG; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\VirusDefs\20140930.018\ENG64.SYS [129752 2014-08-27] (Symantec Corporation)
S3 NAVEX15; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\VirusDefs\20140930.018\EX64.SYS [2137304 2014-08-27] (Symantec Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S1 SRTSP; C:\Windows\System32\Drivers\N360x64\1505000.013\SRTSP64.SYS [875736 2014-02-13] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1505000.013\SRTSPX64.SYS [36952 2013-10-30] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1505000.013\SYMDS64.SYS [493656 2013-10-30] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1505000.013\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-04-16] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1505000.013\Ironx64.SYS [264280 2013-10-30] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1505000.013\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
S3 JNPRNA; system32\DRIVERS\jnprna6.sys [X]
U3 aswMBR; \??\C:\Users\L125-U~1\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\L125-U~1\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-24 16:05 - 2015-06-24 16:06 - 00000000 ____D C:\FRST
2015-06-24 15:51 - 2015-06-24 15:51 - 00000512 _____ C:\Users\L125-User\Desktop\MBR.dat
2015-06-24 15:33 - 2015-06-24 15:33 - 00000000 ___RD C:\Users\L125-User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2015-06-23 18:15 - 2015-06-23 18:15 - 00000000 ____D C:\Program Files (x86)\ESET
2015-06-23 17:06 - 2015-06-23 17:06 - 00000000 _____ C:\autoexec.bat
2015-06-23 16:22 - 2015-06-23 19:26 - 00000000 ____D C:\Users\L125-User\AppData\Local\TorrentUnlocker
2015-06-23 16:04 - 2015-06-23 16:04 - 00000000 ____D C:\NPE
2015-06-23 16:02 - 2015-06-23 16:17 - 00000000 ____D C:\Users\L125-User\AppData\Local\NPE
2015-06-23 13:54 - 2015-06-23 13:54 - 00000000 ____D C:\Users\L125-User\AppData\Local\VirtualStore
2015-06-23 11:46 - 2015-06-23 11:46 - 00008614 _____ C:\Users\L125-User\Documents\HELP_DECRYPT.HTML
2015-06-23 11:46 - 2015-06-23 11:46 - 00004250 _____ C:\Users\L125-User\Documents\HELP_DECRYPT.TXT
2015-06-23 11:46 - 2015-06-23 11:46 - 00000284 _____ C:\Users\L125-User\Documents\HELP_DECRYPT.URL
2015-06-23 11:34 - 2015-06-23 11:34 - 00008614 _____ C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.HTML
2015-06-23 11:34 - 2015-06-23 11:34 - 00008614 _____ C:\Users\L125-User\AppData\HELP_DECRYPT.HTML
2015-06-23 11:34 - 2015-06-23 11:34 - 00004250 _____ C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.TXT
2015-06-23 11:34 - 2015-06-23 11:34 - 00004250 _____ C:\Users\L125-User\AppData\HELP_DECRYPT.TXT
2015-06-23 11:34 - 2015-06-23 11:34 - 00000284 _____ C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.URL
2015-06-23 11:34 - 2015-06-23 11:34 - 00000284 _____ C:\Users\L125-User\AppData\HELP_DECRYPT.URL
2015-06-23 11:33 - 2015-06-23 11:33 - 00008614 _____ C:\Users\L125-User\AppData\Local\HELP_DECRYPT.HTML
2015-06-23 11:33 - 2015-06-23 11:33 - 00004250 _____ C:\Users\L125-User\AppData\Local\HELP_DECRYPT.TXT
2015-06-23 11:33 - 2015-06-23 11:33 - 00000284 _____ C:\Users\L125-User\AppData\Local\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\Users\Default\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\Users\Default\AppData\Local\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\Users\Default\AppData\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\Users\Default User\AppData\Local\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\Users\Default User\AppData\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\ProgramData\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\Users\Default\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\Users\Default\AppData\Local\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\Users\Default\AppData\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\Users\Default User\AppData\Local\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\Users\Default User\AppData\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\ProgramData\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\Users\Default\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\Users\Default\AppData\Local\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\Users\Default\AppData\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\Users\Default User\AppData\Local\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\Users\Default User\AppData\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\ProgramData\HELP_DECRYPT.URL
2015-06-16 12:47 - 2015-06-23 11:32 - 00000000 ____D C:\Users\L125-User\AppData\Local\Evernote
2015-06-04 12:53 - 2015-06-04 12:53 - 00000000 ____D C:\Program Files (x86)\RICOH
2015-06-04 12:51 - 2015-06-04 12:56 - 00000000 ____D C:\ProgramData\RICOH
2015-05-26 11:05 - 2015-06-04 12:56 - 00000510 _____ C:\Windows\system32\ricdb.ini
2015-05-26 11:04 - 2015-06-23 14:10 - 00000000 ___HD C:\ProgramData\RICOH_DRV
2015-05-26 11:04 - 2013-06-01 01:42 - 00027648 _____ (RICOH CO.,Ltd.) C:\Windows\system32\rica6Olm.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-24 16:05 - 2012-10-31 17:37 - 00000000 ____D C:\Users\L125-User\Downloads\Applications
2015-06-24 16:00 - 2012-04-03 09:38 - 00000384 _____ C:\Windows\Tasks\Acer Registration - Reminder Recall task.job
2015-06-24 15:57 - 2009-07-14 12:45 - 00024656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-24 15:57 - 2009-07-14 12:45 - 00024656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-24 15:49 - 2012-01-29 10:21 - 01195912 _____ C:\Windows\WindowsUpdate.log
2015-06-24 15:46 - 2012-10-01 12:45 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004UA.job
2015-06-24 15:41 - 2012-10-31 19:32 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\vlc
2015-06-24 15:34 - 2012-10-12 12:37 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\uTorrent
2015-06-24 15:34 - 2012-10-01 10:46 - 00000000 ____D C:\Users\L125-User\Documents\Outlook Files
2015-06-24 15:33 - 2013-08-07 11:20 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Copy
2015-06-24 15:33 - 2012-01-29 10:54 - 00000000 ____D C:\ProgramData\clear.fi
2015-06-24 15:32 - 2014-08-18 21:50 - 00031777 _____ C:\Windows\setupact.log
2015-06-24 15:32 - 2013-02-21 11:14 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-24 15:32 - 2012-04-09 09:19 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-24 15:32 - 2010-11-21 11:47 - 00419496 _____ C:\Windows\PFRO.log
2015-06-24 15:32 - 2009-07-14 13:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-24 15:26 - 2014-04-23 10:07 - 00000000 ____D C:\Users\dub_cm_auto
2015-06-24 15:26 - 2013-02-21 11:14 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-24 15:16 - 2012-04-09 09:19 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-24 15:16 - 2012-04-09 09:19 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-06-24 15:16 - 2011-10-19 09:47 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-24 13:43 - 2015-01-27 20:00 - 00000000 ____D C:\ProgramData\YTD Video Downloader
2015-06-24 13:37 - 2015-01-27 21:57 - 00000000 ____D C:\Users\L125-User\Downloads\Cycle Training
2015-06-23 19:28 - 2011-10-19 09:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Online Backup
2015-06-23 18:01 - 2014-10-01 11:56 - 00000000 ____D C:\Users\L125-User\Desktop\Ironman 70.3 Cebu
2015-06-23 16:36 - 2012-10-01 12:45 - 00000000 ____D C:\Users\L125-User\AppData\Local\Deployment
2015-06-23 16:02 - 2013-03-20 16:33 - 00000000 ____D C:\ProgramData\Norton
2015-06-23 14:27 - 2014-11-13 18:27 - 00000000 __SHD C:\Users\L125-User\AppData\Local\EmieBrowserModeList
2015-06-23 14:27 - 2014-04-21 09:54 - 00000000 __SHD C:\Users\L125-User\AppData\Local\EmieUserList
2015-06-23 14:27 - 2014-04-21 09:54 - 00000000 __SHD C:\Users\L125-User\AppData\Local\EmieSiteList
2015-06-23 14:21 - 2012-07-23 08:56 - 00000000 ____D C:\Users\PKFadmin
2015-06-23 14:20 - 2013-01-29 10:32 - 00000000 ____D C:\Users\L125-User\Documents\TEMP
2015-06-23 14:20 - 2012-10-01 12:46 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-23 14:20 - 2012-09-27 15:32 - 00000000 ____D C:\Users\L125-User\AppData\Local\PowerCinema
2015-06-23 14:20 - 2011-10-19 10:24 - 00000000 ____D C:\Program Files\Windows Journal
2015-06-23 14:20 - 2011-10-19 10:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\NDF
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\Dism
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\rescache
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\AppCompat
2015-06-23 14:19 - 2015-01-27 19:33 - 00000000 ____D C:\Users\L125-User\AppData\Local\AskPartnerNetwork
2015-06-23 14:19 - 2015-01-27 19:32 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2015-06-23 14:19 - 2012-01-29 10:42 - 00000000 ____D C:\ProgramData\Atheros
2015-06-23 14:19 - 2011-10-19 10:02 - 00000000 ____D C:\ProgramData\BackupManager
2015-06-23 14:19 - 2009-07-14 11:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-06-23 14:18 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\registration
2015-06-23 14:13 - 2012-10-31 13:50 - 00000000 ____D C:\Users\L125-User\Downloads\Movies
2015-06-23 14:12 - 2014-07-19 21:46 - 00000000 ____D C:\Users\L125-User\AppData\Local\Skype
2015-06-23 14:12 - 2013-09-05 12:38 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\NesterSoft
2015-06-23 14:12 - 2012-10-31 11:26 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Mozilla
2015-06-23 14:12 - 2012-10-01 12:01 - 00000000 ____D C:\Users\L125-User\AppData\Local\TechSmith
2015-06-23 14:12 - 2012-10-01 11:17 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Skype
2015-06-23 14:12 - 2012-09-27 17:06 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Adobe
2015-06-23 14:10 - 2015-04-28 22:47 - 00000000 ____D C:\Users\L125-User\AppData\Local\LINE
2015-06-23 14:10 - 2013-07-09 16:30 - 00000000 ____D C:\ProgramData\WebEx
2015-06-23 14:10 - 2012-09-27 15:33 - 00000000 ____D C:\Users\L125-User\AppData\Local\Google
2015-06-23 14:10 - 2012-03-29 20:03 - 00000000 ____D C:\ProgramData\OEM_E471269A730D
2015-06-23 14:10 - 2012-01-29 10:45 - 00000000 ____D C:\ProgramData\CyberLink
2015-06-23 14:10 - 2011-10-19 10:22 - 00000000 ____D C:\ProgramData\Acer
2015-06-23 14:10 - 2011-10-19 09:54 - 00000000 ____D C:\ProgramData\Symantec
2015-06-23 14:10 - 2009-07-14 11:20 - 00000000 __RHD C:\Users\Default
2015-06-23 14:09 - 2013-03-06 17:33 - 00000000 ____D C:\d7b624e545e9df63a34dfbb0cf76149c
2015-06-23 14:09 - 2012-04-02 11:40 - 00000000 ____D C:\HP_P2055_default_install_v6.1_ww
2015-06-23 14:09 - 2012-03-29 20:10 - 00000000 __RHD C:\MSOCache
2015-06-23 14:09 - 2011-10-19 10:08 - 00000000 ____D C:\Program Files (x86)\Evernote
2015-06-23 14:09 - 2011-10-19 10:04 - 00000000 __SHD C:\OEM
2015-06-23 14:02 - 2015-04-20 09:54 - 00000000 ____D C:\Users\L125-User\Desktop\KOM Taiwan
2015-06-23 11:46 - 2015-05-06 17:16 - 00000000 ____D C:\Users\L125-User\Documents\Income Tax Filing For 2014
2015-06-23 11:46 - 2014-04-07 11:47 - 00000000 ____D C:\Users\L125-User\Documents\Symantec
2015-06-23 11:46 - 2013-03-15 09:15 - 00000000 ____D C:\Users\L125-User\Documents\Bluetooth Folder
2015-06-23 11:35 - 2013-09-25 16:33 - 00000000 ____D C:\Users\L125-User\Desktop\Chords
2015-06-23 11:35 - 2013-04-24 00:25 - 00000000 ____D C:\Users\L125-User\Desktop\Baguio Phillipines
2015-06-23 11:34 - 2014-11-10 13:42 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\DoneEx
2015-06-23 11:34 - 2013-08-22 15:02 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2015-06-23 11:33 - 2013-03-01 17:40 - 00000000 ____D C:\Users\L125-User\AppData\Local\SAS
2015-06-23 11:32 - 2014-04-07 15:36 - 00000000 ____D C:\ProgramData\QlikTech
2015-06-23 11:32 - 2013-03-27 11:22 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2015-06-23 11:32 - 2013-03-27 11:22 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2015-06-23 11:32 - 2013-03-01 17:42 - 00000000 ____D C:\ProgramData\SAS
2015-06-23 11:31 - 2015-01-14 12:39 - 00000000 ____D C:\ProgramData\IsolatedStorage
2015-06-23 11:30 - 2012-01-29 10:52 - 00000000 ___HD C:\BOOK
2015-06-22 10:44 - 2012-10-05 16:17 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\PrimoPDF
2015-06-16 12:32 - 2012-10-04 11:20 - 00000000 ____D C:\Users\L125-User\Desktop\Project Management Framework
2015-06-12 19:20 - 2014-07-03 17:19 - 00000000 ____D C:\Users\L125-User\Desktop\Program Project Governanace & Audit Sharing Session
2015-06-12 16:12 - 2015-01-13 10:48 - 00000000 ____D C:\Users\L125-User\Desktop\GST Projects
2015-06-12 10:32 - 2015-04-28 22:47 - 00000961 _____ C:\ProgramData\Microsoft\Windows\Start Menu\LINE.lnk
2015-06-12 10:32 - 2015-04-28 22:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LINE
2015-06-12 10:04 - 2015-02-17 18:00 - 00003926 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{D65C931D-1A32-4701-9D5F-4287B325A776}
2015-06-11 12:44 - 2012-10-01 12:45 - 00000872 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004Core.job
2015-06-09 09:31 - 2013-02-21 11:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-06-08 11:33 - 2012-11-14 09:58 - 00000000 ____D C:\Users\L125-User\Claims
2015-06-01 08:34 - 2009-07-14 13:08 - 00032614 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-29 21:11 - 2013-03-15 08:47 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-05-29 21:11 - 2013-03-15 08:47 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-05-29 14:04 - 2013-03-15 08:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-26 14:06 - 2015-03-07 12:33 - 00000000 ____D C:\Users\L125-User\Downloads\Recipes
==================== Files in the root of some directories =======
2015-06-23 11:34 - 2015-06-23 11:34 - 0008614 _____ () C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.HTML
2015-06-23 11:34 - 2015-06-23 11:34 - 0045586 _____ () C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.PNG
2015-06-23 11:34 - 2015-06-23 11:34 - 0004250 _____ () C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.TXT
2015-06-23 11:34 - 2015-06-23 11:34 - 0000284 _____ () C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.URL
2015-06-23 11:33 - 2015-06-23 11:33 - 0008614 _____ () C:\Users\L125-User\AppData\Local\HELP_DECRYPT.HTML
2015-06-23 11:33 - 2015-06-23 11:33 - 0045586 _____ () C:\Users\L125-User\AppData\Local\HELP_DECRYPT.PNG
2015-06-23 11:33 - 2015-06-23 11:33 - 0004250 _____ () C:\Users\L125-User\AppData\Local\HELP_DECRYPT.TXT
2015-06-23 11:33 - 2015-06-23 11:33 - 0000284 _____ () C:\Users\L125-User\AppData\Local\HELP_DECRYPT.URL
2014-11-10 13:42 - 2014-11-10 13:42 - 0000082 _____ () C:\Users\L125-User\AppData\Local\{vO5T0cEfJ7FeZhpfKQxAPLaadYgK9UftD5
2012-11-25 17:54 - 2012-11-25 17:54 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-01-29 10:45 - 2012-01-29 10:47 - 0015027 _____ () C:\ProgramData\ArcadeDeluxe5.log
2015-06-23 11:32 - 2015-06-23 11:32 - 0008614 _____ () C:\ProgramData\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 0045586 _____ () C:\ProgramData\HELP_DECRYPT.PNG
2015-06-23 11:32 - 2015-06-23 11:32 - 0004250 _____ () C:\ProgramData\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 0000284 _____ () C:\ProgramData\HELP_DECRYPT.URL
2012-04-02 11:41 - 2012-04-02 11:46 - 0000359 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
C:\Users\L125-User\AppData\Local\Temp\DataCard_Setup64.exe
C:\Users\L125-User\AppData\Local\Temp\GUR77D8.exe
C:\Users\L125-User\AppData\Local\Temp\ResetDevice.exe
C:\Users\L125-User\AppData\Local\Temp\siinst.exe
C:\Users\L125-User\AppData\Local\Temp\SkypeSetup.exe
C:\Users\L125-User\AppData\Local\Temp\strings.dll
C:\Users\L125-User\AppData\Local\Temp\utt45A3.tmp.exe
C:\Users\L125-User\AppData\Local\Temp\utt69A0.tmp.exe
C:\Users\L125-User\AppData\Local\Temp\utt8694.tmp.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-23 00:08
==================== End of log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version:21-06-2015 01
Ran by [removed] at 2015-06-24 16:07:51
Running from C:\Users\[removed]\Downloads\Applications
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2850245000-3638546127-566686928-500 - Administrator - Disabled)
Guest (S-1-5-21-2850245000-3638546127-566686928-501 - Limited - Disabled)
L125-User (S-1-5-21-2850245000-3638546127-566686928-1004 - Administrator - Enabled) => C:\Users\L125-User
PKFadmin (S-1-5-21-2850245000-3638546127-566686928-1002 - Administrator - Enabled) => C:\Users\PKFadmin
UpdatusUser (S-1-5-21-2850245000-3638546127-566686928-1000 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Norton 360 Premier Edition (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton 360 Premier Edition (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton 360 Premier Edition (Disabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Β΅Torrent (HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.)
192.168.0.8-64bits_RICOH MP 3353 PCL 6_64bits [RICOH MP 3353 PCL 6] (HKLM\β¦\{AF4633AC-C8D6-4B23-B06F-0837E1844606}) (Version: 1.0.0 - RICOH)
64 Bit HP CIO Components Installer (Version: 13.2.1 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.4 - Hewlett-Packard) Hidden
Acer Backup Manager (HKLM-x32\β¦\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.99 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32\β¦\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1904 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.0.1904 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\β¦\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3008 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\β¦\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Acer Incorporated)
Acer Games (HKLM-x32\β¦\WildTangent acer Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Acer Registration (HKLM-x32\β¦\Acer Registration) (Version: 1.04.3504 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\β¦\Acer Screensaver) (Version: 1.1.0902.2011 - Acer Incorporated)
Acer Updater (HKLM-x32\β¦\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3500 - Acer Incorporated)
Adobe AIR (HKLM-x32\β¦\Adobe AIR) (Version: 2.7.1.19610 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM-x32\β¦\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.6 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\β¦\Adobe Flash Player ActiveX) (Version: 17.0.0.190 - Adobe Systems Incorporated)
Adobe Reader X (10.1.14) MUI (HKLM-x32\β¦\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.14 - Adobe Systems Incorporated)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden
AP Tuner 3.08 (HKLM-x32\β¦\AP Tuner 3.08) (Version: - )
Backup Manager V3 (x32 Version: 3.0.0.99 - NTI Corporation) Hidden
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bluetooth Win7 Suite (64) (HKLM\β¦\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.96 - Atheros)
Broadcom Card Reader Driver Installer (HKLM\β¦\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 14.4.9.2 - Broadcom Corporation)
Broadcom NetLink Controller (HKLM\β¦\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 15.0.3.2 - Broadcom Corporation)
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cisco WebEx Meetings (HKLM-x32\β¦\ActiveTouchMeetingClient) (Version: - Cisco WebEx LLC)
clear.fi (HKLM-x32\β¦\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 1.0.2228.00 - CyberLink Corp.)
clear.fi (x32 Version: 1.0.1517_36458 - CyberLink Corp.) Hidden
clear.fi (x32 Version: 1.0.2228.00 - CyberLink Corp.) Hidden
clear.fi (x32 Version: 9.0.8228 - CyberLink Corp.) Hidden
clear.fi Client (HKLM-x32\β¦\{43AAE145-83CF-4C96-9A5E-756CEFCE879F}) (Version: 1.00.3500 - Acer Incorporated)
Copy (HKLM\β¦\{BF1346D9-2622-4913-86A6-6B63536B1AEB}) (Version: 1.34.508.0 - Barracuda Networks, Inc.)
Crazy Chicken Kart 2 (x32 Version: 2.2.0.97 - WildTangent) Hidden
CustomerResearchQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dolby Advanced Audio v2 (HKLM-x32\β¦\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.7000.7 - Dolby Laboratories Inc)
Dropbox (HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\Dropbox) (Version: 1.6.16 - Dropbox, Inc.)
eBay Worldwide (HKLM-x32\β¦\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
Email Templates Collection 1 1.0.5 (HKLM-x32\β¦\B341F1D4-72BA-4C1B-A8FD-2FCCDDB3888E_is1) (Version: 1.0.5 - DeliveryTech)
ESET Online Scanner v3 (HKLM-x32\β¦\ESET Online Scanner) (Version: - )
Evernote v. 4.5.1 (HKLM-x32\β¦\{28921580-E4BB-11E0-9FD7-1CC1DEF07CBE}) (Version: 4.5.1.5451 - Evernote Corp.)
FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsΕugΔ poΕΔ
czeΕ zdalnych (HKLM-x32\β¦\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
Free MP3 Cutter 2.0 (HKLM-x32\β¦\{847E0734-4457-4B48-BF49-998D1CF2CFA1}_is1) (Version: 2.0 - PolySoft Solutions)
Free PDF Converter (HKLM-x32\β¦\Free PDF Converter_is1) (Version: - Baltsoft)
Google Chrome (HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\Google Chrome) (Version: 43.0.2357.130 - Google Inc.)
Google Drive (HKLM-x32\β¦\{CBC9F5FD-5CFA-4A33-81CD-369EAB77E3A6}) (Version: 1.22.9403.0223 - Google, Inc.)
Google Talk (remove only) (HKLM-x32\β¦\{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk) (Version: - )
Google Toolbar for Internet Explorer (HKLM-x32\β¦\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
HP Customer Participation Program 10.0 (HKLM\β¦\HPExtendedCapabilities) (Version: 10.0 - HP)
HP Deskjet 2050 J510 series Basic Device Software (HKLM\β¦\{73B1AC18-614F-42CD-A798-4BA214586406}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP FWUpdateEDO3 (HKLM-x32\β¦\{A82D0C46-EBDF-4B27-A731-D06EF2056E81}) (Version: 1.0.0.0 - Hewlett-Packard Company)
HP LaserJet P2050 Series 6.0 (HKLM\β¦\{6F801026-6AF0-4520-9153-4C9B4CAAB361}) (Version: 6.0 - HP)
HP LaserJet Professional CM1410 Series (HKLM-x32\β¦\{0EF0EA0D-F945-4958-85CC-60FF1E86D216}) (Version: - Hewlett-Packard)
HP LaserJet Professional M1130-M1210 MFP Series (HKLM\β¦\HP LaserJet Professional M1130-M1210 MFP Series) (Version: - )
HP LaserJet Professional M1530 MFP Series (HKLM-x32\β¦\{74280B5D-A0AF-46c5-9C85-D9EA078262F1}) (Version: - Hewlett-Packard)
HP LaserJet Professional P1100-P1560-P1600 Series (HKLM\β¦\HP LaserJet Professional P1100-P1560-P1600 Series) (Version: - )
HP LJ CM1410 MFP Series HP Scan (HKLM-x32\β¦\{21749F4E-02A1-4828-9A1E-BBDF5929C5D0}) (Version: 1.0.302.0 - Hewlett-Packard Co.)
HP LJ M1530 MFP Series HP Scan (HKLM-x32\β¦\{C05002F1-06F8-4A15-B6F8-E4DC655C28AA}) (Version: 1.0.302.0 - Hewlett-Packard Co.)
HP Update (HKLM-x32\β¦\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
HPLaserJetHelp_LearnCenter (HKLM-x32\β¦\{22FE3793-5961-4ADE-AE66-69D9291C22B1}) (Version: 1.03.0000 - Hewlett-Packard)
HPLaserJetHelp_LearnCenter (HKLM-x32\β¦\{B2AA0F22-E167-4C4A-BAE2-E0025028E61B}) (Version: 1.01.0000 - Hewlett-Packard)
HPLJUT (HKLM-x32\β¦\{229D6185-BD7E-494B-A73B-C5215BE0690E}) (Version: 1.00.0007 - HP)
hppCM1410LaserJetService (x32 Version: 001.008.00477 - Hewlett-Packard) Hidden
hppFaxDrvCM1410 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppFaxDrvM1530 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppFaxUtilityCM1410 (x32 Version: 000.002.00001 - Hewlett-Packard) Hidden
hppFaxUtilityM1530 (x32 Version: 000.002.00001 - Hewlett-Packard) Hidden
hppFonts (x32 Version: 001.001.00061 - Hewlett-Packard) Hidden
hppLaserJetService (x32 Version: 002.015.00599 - Hewlett-Packard) Hidden
hppM1530LaserJetService (x32 Version: 001.007.00319 - Hewlett-Packard) Hidden
hppQFolderP2050 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
hppSendFaxCM1410 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppSendFaxM1530 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppTLBXFXCM1410 (x32 Version: 001.012.00948 - Hewlett-Packard) Hidden
hppTLBXFXM1530 (x32 Version: 001.007.00647 - Hewlett-Packard) Hidden
hppusgP2050 (x32 Version: 1.1.0.1 - Hewlett-Packard) Hidden
hpzTLBXFX (x32 Version: 006.015.01163 - Hewlett-Packard) Hidden
I.R.I.S. OCR (HKLM-x32\β¦\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4 - HP)
Identity Card (HKLM-x32\β¦\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
Insaniquarium Deluxe (x32 Version: 2.2.0.97 - WildTangent) Hidden
Intel(R) Control Center (HKLM-x32\β¦\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\β¦\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\β¦\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2538 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\β¦\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\β¦\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel)
Java 7 Update 7 (HKLM-x32\β¦\{26A24AE4-039D-4CA4-87B4-2F83217007FF}) (Version: 7.0.70 - Oracle)
Java(TM) 6 Update 24 (64-bit) (HKLM\β¦\{26A24AE4-039D-4CA4-87B4-2F86416024FF}) (Version: 6.0.240 - Oracle)
Java(TM) 6 Update 24 (HKLM-x32\β¦\{26A24AE4-039D-4CA4-87B4-2F83216024FF}) (Version: 6.0.240 - Oracle)
Java(TM) SE Development Kit 6 Update 24 (64-bit) (HKLM\β¦\{64A3A4F4-B792-11D6-A78A-00B0D0160240}) (Version: 1.6.0.240 - Oracle)
JavaFX 2.1.1 (HKLM-x32\β¦\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jewel Match 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Juniper Networks Network Connect 6.0.0 (HKLM-x32\β¦\Juniper Network Connect 6.0.0) (Version: 6.0.0.13073 - Juniper Networks)
Juniper Networks Setup Client (HKU\S-1-5-21-2850245000-3638546127-566686928-1004\β¦\JuniperSetupClient) (Version: 1.1.0.0 - Juniper Networks)
Juniper Networks, Inc. Setup Client 64-bit Activex Control (HKLM\β¦\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks, Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\β¦\LManager) (Version: 5.1.4 - Acer Inc.)
LINE (HKLM-x32\β¦\LINE) (Version: 4.0.3.367 - LINE Corporation)
MarketResearch (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden
Maxis Broadband (HKLM-x32\β¦\Maxis Broadband) (Version: 11.302.06.10.99 - Huawei Technologies Co.,Ltd)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\β¦\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Business 2010 (HKLM-x32\β¦\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0401-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0402-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0403-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0404-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0405-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0406-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0407-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0408-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-040B-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-040C-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-040D-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-040E-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0410-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0413-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0414-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0415-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0416-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0418-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0419-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-041A-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-041B-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-041D-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-041E-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-041F-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0424-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0816-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\β¦\{95140000-007A-0C0A-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Facebook 32-bit (HKLM-x32\β¦\{95140000-007C-0409-0000-0000000FF1CE}) (Version: 14.0.6114.5003 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\β¦\{95140000-007D-0409-0000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Project Standard 2010 (HKLM-x32\β¦\Office14.PRJSTDR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\β¦\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\β¦\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\β¦\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\β¦\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\β¦\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\β¦\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\β¦\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\β¦\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\β¦\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\β¦\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\β¦\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.19 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 4.0.14.19 - Egis Technology Inc.) Hidden
Norton 360 (HKLM-x32\β¦\N360) (Version: 21.5.0.19 - Symantec Corporation)
Norton Online Backup (HKLM-x32\β¦\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
NTI Media Maker 9 (HKLM-x32\β¦\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9002 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.9002 - NTI Corporation) Hidden
NVIDIA Graphics Driver 285.90 (HKLM\β¦\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 285.90 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\β¦\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
Office Timeline (HKLM-x32\β¦\{DAE585BA-546F-4684-9592-6EA2D0DF071E}) (Version: 3.1.3 - Office Timeline)
PDFBinder (HKLM-x32\β¦\{8BA03AC2-579F-41CD-A250-740137D86F7A}) (Version: 1.0.0 - Malamute.dk)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
PrimoPDF β brought to you by Nitro PDF Software (HKLM-x32\β¦\PrimoPDF) (Version: 5 - Nitro PDF Software)
QlikView Desktop Documentation and Tutorial English (HKLM-x32\β¦\{C5E37ACB-E2DA-4704-BE99-8781CC187B28}) (Version: 11.20.12235.0 - QlikTech International AB)
QlikView x64 (HKLM\β¦\{1ED3B75E-BED2-4863-9763-098DE00590B3}) (Version: 11.20.12235.0 - QlikTech International AB)
Realtek High Definition Audio Driver (HKLM-x32\β¦\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6423 - Realtek Semiconductor Corp.)
RegClean-Pro (HKLM-x32\β¦\RegClean-Pro_is1) (Version: 6.21 - Systweak Inc)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\β¦\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Scan To (HKLM\β¦\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP)
Search App by Ask (HKLM-x32\β¦\{42545253-502D-4300-76A7-A75C790C1B00}) (Version: 12.27.0.1060 - APN, LLC) <==== ATTENTION
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\β¦\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\β¦\{91140000-003A-0000-0000-0000000FF1CE}_Office14.PRJSTDR_{58FA40EF-ABA9-4FED-AD3D-318A6073934D}) (Version: - Microsoft)
Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Skypeβ’ 6.21 (HKLM-x32\β¦\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Snagit 11 (HKLM-x32\β¦\{F8E3C768-71F3-11E1-9DF7-70804824019B}) (Version: 11.0.1 - TechSmith Corporation)
Synaptics Pointing Device Driver (HKLM\β¦\SynTPDeinstKey) (Version: 15.3.26.2 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\β¦\TeamViewer 9) (Version: 9.0.24482 - TeamViewer)
TimeLeft (HKLM-x32\β¦\TIMELEFT3_is1) (Version: 3.62 - NesterSoft Inc.)
Torchlight (x32 Version: 2.2.0.97 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
uTorrentControl_v2 Toolbar (HKLM-x32\β¦\uTorrentControl_v2 Toolbar) (Version: 6.9.0.16 - uTorrentControl_v2) <==== ATTENTION
VC8 CRT (Version: 8.0.50727.762 - Juniper Networks) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.97 - WildTangent) Hidden
VLC media player 2.0.4 (HKLM-x32\β¦\VLC media player) (Version: 2.0.4 - VideoLAN)
WebReg (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden
Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden
Welcome Center (HKLM-x32\β¦\Acer Welcome Center) (Version: 1.02.3505 - Acer Incorporated)
WildTangent Games App (Acer Games) (x32 Version: 4.0.5.14 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\β¦\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\β¦\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\β¦\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\β¦\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM-x32\β¦\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
YTD Video Downloader 4.9 (HKLM-x32\β¦\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.9 - GreenTree Applications SRL) <==== ATTENTION
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\L125-User\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
==================== Restore Points =========================
11-06-2015 13:59:11 Scheduled Checkpoint
12-06-2015 11:00:18 Windows Update
16-06-2015 12:42:52 Installed Evernote v. 5.8.8
23-06-2015 12:19:38 Restore Operation
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 10:34 - 2013-08-20 14:42 - 00001074 ____N C:\Windows\system32\Drivers\etc\hosts
192.168.63.247 sasmetadata
192.168.63.248 sasdi
192.168.63.249 sasebi
192.168.63.250 sasmidtier
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0BC16753-E239-4BAD-83D1-94467D1E9BAC} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-29] (Egis Technology Inc.)
Task: {0D8FAA7E-7208-44E6-B098-C2D81C665B4F} - System32\Tasks\{6121D0CC-8ADE-49A7-BE34-70F07D198D54} => C:\Users\L125-User\Downloads\b98be66f7073436ab3a8ecd9ae11ee6a_Pod8_en-GB.exe
Task: {1AAEAA7C-9286-4833-BF5F-373F29EF4383} - System32\Tasks\clear.fiAgent => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe [2011-10-29] (CyberLink Corp.)
Task: {27E3A400-46BC-4148-A9A1-DC411554478D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {3B7E8DA3-21FE-4B77-BC44-72B82CD6833A} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2012-10-03] (Microsoft Corporation)
Task: {412BCB9E-6F4F-44BE-92F2-1C05D308F78B} - System32\Tasks\DMREngine => C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe [2011-10-29] (CyberLink)
Task: {4A6B2FEA-929F-4EAC-A005-6FF6E76858C4} - System32\Tasks\Acer Registration - Reminder Recall task => C:\Program Files (x86)\Acer\Registration\GREG.exe [2011-05-11] (Acer Incorporated)
Task: {4F84BA1A-0677-4D7B-909A-F58947433359} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-15] (Google Inc.)
Task: {58C776A6-76BD-4683-A30C-E40FBE782383} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\SymErr.exe [2014-01-31] (Symantec Corporation)
Task: {5E643F74-3CDD-4CAE-BF6F-9EA7EFE5565C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-15] (Google Inc.)
Task: {7CEC44E8-B2A4-4FB5-B804-A7FF682162FF} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-29] (Egis Technology Inc.)
Task: {7D38031B-DBB6-49D8-B351-F0D4B8719D63} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004UA => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-01] (Google Inc.)
Task: {867EB48A-DD34-4C11-AE76-D9DB6DB62E13} - System32\Tasks\{7D397F49-7B53-4BB8-B80F-205656218F21} => C:\Users\L125-User\Downloads\b98be66f7073436ab3a8ecd9ae11ee6a_Pod8_en-GB.exe
Task: {8C306857-3EB9-4D91-92FB-0CFA9E0E712E} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [2010-04-13] (Hewlett Packard)
Task: {8D4391C2-F842-4366-B7D8-F3E1D62FC62E} - System32\Tasks\{19A2A0B9-C3F4-4691-A68D-4B87A00CCA36} => Iexplore.exe http://ui.skype.com/ui/0/6.0.0.126/en/abandoninstall?page=tsProgressBar
Task: {943E23DE-41D8-4D3A-B1A2-22762EE9A62E} - System32\Tasks\clear.fi => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe [2011-10-29] (Acer Incorporated)
Task: {9CA31130-BD48-4DB3-A0BB-979AA0FDB08F} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\WSCStub.exe [2014-08-01] (Symantec Corporation)
Task: {9DE84380-5ADB-4A32-A355-2DE713603F4A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004Core => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-01] (Google Inc.)
Task: {BC47B473-942A-4821-B770-F55DCA02BAF0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-24] (Adobe Systems Incorporated)
Task: {D4F00EF3-FB53-44AB-8BE0-922EF36EF248} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\SymErr.exe [2014-01-31] (Symantec Corporation)
Task: C:\Windows\Tasks\Acer Registration - Reminder Recall task.job => C:\Program Files (x86)\Acer\Registration\GREG.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004Core.job => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004UA.job => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2012-08-02 10:31 - 2011-04-02 16:05 - 00290304 _____ () C:\Windows\System32\HP1100LM.DLL
2015-01-07 18:45 - 2010-03-31 11:51 - 00407040 _____ () C:\Windows\System32\HPM1210LM.DLL
2012-10-05 15:57 - 2011-03-01 06:37 - 00095008 _____ () C:\Windows\System32\Primomonnt.dll
2012-08-02 10:32 - 2011-04-02 16:04 - 00074240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\HP1100PP.DLL
2015-01-07 18:57 - 2010-03-31 11:51 - 00074240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\HPM1210PP.dll
2013-08-07 11:20 - 2014-06-12 10:44 - 08212480 _____ () C:\Users\L125-User\AppData\Roaming\Copy\overlay\Brt.dll
2012-01-29 10:06 - 2011-09-26 16:36 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-04-24 09:29 - 2011-04-24 09:29 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2011-04-24 09:29 - 2011-04-24 09:29 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2011-04-24 09:29 - 2011-04-24 09:29 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2011-10-29 07:04 - 2011-10-29 07:04 - 00206216 _____ () C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLNetMediaDMA.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-02-14 15:46 - 2013-02-14 15:46 - 01044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00111616 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlc.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 02286592 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlccore.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00219648 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdshow_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00049664 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libaout_directx_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00051200 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00070144 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirectx_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00037376 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmxext\libmemcpymmxext_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00157696 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\liblibbluray_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00093696 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_bd_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00258560 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdvdnav_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00047616 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_vdr_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00043520 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libfilesystem_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00440320 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libstream_filter_httplive_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00724992 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libstream_filter_dash_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00038912 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libstream_filter_rar_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00083968 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libzip_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00035840 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libstream_filter_record_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00106496 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libplaylist_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01544192 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libtaglib_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00310784 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\lua\liblua_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01238016 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\misc\libxml_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00051200 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libhotkeys_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00037888 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libglobalhotkeys_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 11998208 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\gui\libqt4_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00288768 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libupnp_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00085504 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libsap_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00041984 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libpodcast_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00038400 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libmediadirs_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00036352 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libwindrive_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00044544 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libes_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00198656 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmp4_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00386560 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libtheora_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00092160 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libavi_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00037376 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\librawvideo_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00073728 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libasf_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00045568 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libflacsys_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00154624 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspeex_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01719296 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libvorbis_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00037376 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaes3_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00043008 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblpcm_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00044032 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_flac_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00051712 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_dirac_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00042496 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mlp_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00057344 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpeg4audio_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00046592 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_vc1_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00038912 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libsvcdsub_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00042496 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspudec_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00043008 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpeg4video_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00045568 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpegvideo_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00040960 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcvdsub_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00087040 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_h264_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00041472 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libmpeg_audio_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00185856 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libpng_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00038400 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01318912 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libschroedinger_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00051200 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaraw_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00043008 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libdts_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00372224 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libfaad_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00265216 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libflac_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01887232 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblibass_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00310784 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libopus_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00182272 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdtstofloat32_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00068608 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\liba52tofloat32_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00135168 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libmpgatofixed32_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01518080 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsamplerate_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00036864 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libconverter_fixed_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00034816 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\liba52tospdif_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00038400 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsimple_channel_mixer_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00036864 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdtstospdif_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00036352 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdolby_surround_decoder_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00035328 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libugly_resampler_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00045568 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libaudio_format_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00033792 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_mixer\libfloat32_mixer_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00040960 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libscaletempo_plugin.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\L125-User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 208.67.222.222 - 208.67.220.220
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^Users^L125-User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP Deskjet 2050 J510 series.lnk => C:\Windows\pss\Monitor Ink Alerts - HP Deskjet 2050 J510 series.lnk.Startup
MSCONFIG\startupfolder: C:^Users^L125-User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TimeLeft.lnk => C:\Windows\pss\TimeLeft.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: ArcadeMovieService => "C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe"
MSCONFIG\startupreg: Copy => "C:\Users\L125-User\AppData\Roaming\Copy\CopyAgent.exe"
MSCONFIG\startupreg: Dolby Advanced Audio v2 => "C:\Dolby PCEE4\pcee4.exe" -autostart
MSCONFIG\startupreg: Google Update => "C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
MSCONFIG\startupreg: googletalk => C:\Program Files (x86)\Google\Google Talk\googletalk.exe /autostart
MSCONFIG\startupreg: HP LaserJet Professional CM1410 Series Fax => C:\Program Files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe "HP LaserJet Professional CM1410 Series Fax"
MSCONFIG\startupreg: HP LaserJet Professional M1530 MFP Series Fax => C:\Program Files\HP\HP LaserJet Professional M1530 MFP Series\Fax Driver\hppfaxprintersrv.exe "HP LaserJet Professional M1530 MFP Series Fax"
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: HPUsageTracking => "C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT\"
MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
MSCONFIG\startupreg: ToolboxFX => "C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{7CE85EF5-8332-4262-AB8A-D63339F059F0}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{29D9110F-687E-4E1C-A3CF-9B5260BF25BF}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{D7379D53-D9A0-4889-AF79-5A07231B3042}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{134F1FF7-B217-4B6B-9E8C-A36D61F893A9}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{906ADC2D-FEF9-457F-BFB4-E23B1737C5CF}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe
FirewallRules: [{DEC4F025-5E99-4F03-97AA-7CCD76E3466C}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
FirewallRules: [{91FFC9C7-B47F-41A7-AED2-C2535A33FC15}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\CLML\CLMLSvc.exe
FirewallRules: [{B47CD000-178D-47F8-9B33-709EB90C858E}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{627DFA4F-6595-42FC-8F60-03D104D2CCB9}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{F3E895E6-B372-43AC-A3D1-4E5017934514}] => (Block) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{4F81DFA8-005A-45CD-8376-C43423E9E068}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovie.exe
FirewallRules: [{06CC5013-0BB6-4A17-B288-3A579136DC43}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovieService.exe
FirewallRules: [{B88D13D9-4332-498D-8D7B-EDF0C09E9897}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9AED157C-5393-4F0E-913D-61F39F5696E4}] => (Allow) LPort=2869
FirewallRules: [{3928A412-C9E3-45F2-9605-0E370B981019}] => (Allow) LPort=1900
FirewallRules: [{6E81CDD4-4898-46D6-92D4-3B7FBDA7167F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{DD0BC37B-E1F6-437E-BEEA-2E24CA0F0A34}] => (Allow) C:\Program Files (x86)\Google\Google Talk\googletalk.exe
FirewallRules: [{EA1915FA-315A-40EF-9389-C2EB392E712C}] => (Allow) C:\Program Files (x86)\Google\Google Talk\googletalk.exe
FirewallRules: [{EE3FF0AD-A633-417F-871A-40F9537C6A1A}] => (Allow) C:\Users\L125-User\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{77F02A37-F1D9-49D5-A0B1-4731E0CA0934}] => (Allow) C:\Users\L125-User\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{148241BF-2246-4137-8885-89CA89AAF291}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{0C005419-F759-438F-8D0B-B99F2754367B}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{A5983858-55E5-496F-98A2-273EB6BAF97D}] => (Allow) C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe
FirewallRules: [{F36F44C8-CA09-4CCA-AA59-C5F1C2F2C2D9}] => (Allow) C:\Users\L125-User\AppData\Roaming\Copy\CopyAgent.exe
FirewallRules: [{5A208310-1D07-458E-A777-D3D088B981E2}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{084BDD71-A3E7-4AC1-85E7-AC24D0DBF232}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{D0042F2A-8BBD-44C9-8E56-9BDE1AEFA417}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{29E483E6-CF6A-401A-A5A6-A2221CFD8419}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{FB7F288C-5DC7-4F93-9FBD-6A5B442D7A08}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [TCP Query User{1BB47B53-D534-45C3-A142-D57A493908A2}C:\users\l125-user\appdata\roaming\copy\copyagent.exe] => (Allow) C:\users\l125-user\appdata\roaming\copy\copyagent.exe
FirewallRules: [UDP Query User{DE51D2A7-0CB1-49BB-A464-A83A923C8621}C:\users\l125-user\appdata\roaming\copy\copyagent.exe] => (Allow) C:\users\l125-user\appdata\roaming\copy\copyagent.exe
FirewallRules: [{9AB42673-534D-4520-BD39-0F25022177DE}] => (Allow) C:\Users\L125-User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{04A3B277-C12A-476A-BC78-71708DCA6826}] => (Allow) C:\Users\L125-User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{09F4B518-A622-4A4E-BB08-3B3BC0CC720E}] => (Allow) C:\Program Files (x86)\LINE\LINE.exe
FirewallRules: [{F4CE7436-A595-4873-8949-20D359C3D3FD}] => (Allow) C:\Program Files (x86)\LINE\LINE.exe
FirewallRules: [{BDC4D034-A9E1-48EC-A31A-A686F9F7393A}] => (Allow) C:\Users\L125-User\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
Name: BHDrvx64
Description: BHDrvx64
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: BHDrvx64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/24/2015 04:04:53 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (06/24/2015 03:59:02 PM) (Source: MsiInstaller) (EventID: 10005) (User: L125)
Description: Product: Search App by Ask β Error 25001. The following applications must be closed before continuing the uninstall:
Internet Explorer
Error: (06/24/2015 03:44:42 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (06/24/2015 03:44:41 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (06/24/2015 00:56:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Spyhunter4.exe version 4.20.9.4533 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: f5c
Start Time: 01d0ae390505bc4e
Termination Time: 16
Application Path: C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe
Report Id: 68b4a54a-1a2d-11e5-b45f-7ce9d3415466
Error: (06/24/2015 08:55:18 AM) (Source: MsiInstaller) (EventID: 1023) (User: NT AUTHORITY)
Description: Product: Kaspersky Internet Security 2014 - Update 'Kaspersky Internet Security 2014 (Patch
' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI1ebfb.LOG.
Error: (06/24/2015 08:55:18 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
Description: Application: Kaspersky Internet Security 2014 β Internal Error 2761.
Error: (06/24/2015 08:54:51 AM) (Source: MsiInstaller) (EventID: 1041) (User: NT AUTHORITY)
Description: Failed to begin a Windows Installer transaction {6F6873E3-5C92-4049-B511-231A138DD090}. Error 1618 occurred while beginning the transaction.
Error: (06/24/2015 08:54:51 AM) (Source: MsiInstaller) (EventID: 1041) (User: NT AUTHORITY)
Description: Failed to begin a Windows Installer transaction {6F6873E3-5C92-4049-B511-231A138DD090}. Error 1618 occurred while beginning the transaction.
Error: (06/23/2015 07:12:47 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
System errors:
=============
Error: (06/24/2015 03:32:49 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
BHDrvx64
SRTSP
Error: (06/24/2015 03:32:10 PM) (Source: SRTSP) (EventID: 4) (User: )
Description: Error loading virus definitions.
Error: (06/24/2015 03:31:14 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Error: (06/24/2015 03:25:44 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer L133-WONG
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{D75985F7-EE80-4C5B-91C4-90645002486D}.
The master browser is stopping or an election is being forced.
Error: (06/24/2015 00:59:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
BHDrvx64
SRTSP
Error: (06/24/2015 00:58:34 PM) (Source: SRTSP) (EventID: 4) (User: )
Description: Error loading virus definitions.
Error: (06/24/2015 00:48:07 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
BHDrvx64
SRTSP
Error: (06/24/2015 00:47:27 PM) (Source: SRTSP) (EventID: 4) (User: )
Description: Error loading virus definitions.
Error: (06/24/2015 09:46:41 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Error: (06/24/2015 07:48:34 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The NVIDIA Update Service Daemon service hung on starting.
Microsoft Office:
=========================
Error: (06/24/2015 04:04:53 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\L125-User\Downloads\Applications\esetsmartinstaller_enu.exe
Error: (06/24/2015 03:59:02 PM) (Source: MsiInstaller) (EventID: 10005) (User: L125)
Description: Product: Search App by Ask β Error 25001. The following applications must be closed before continuing the uninstall:
Internet Explorer (NULL)(NULL)(NULL)(NULL)(NULL)
Error: (06/24/2015 03:44:42 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\L125-User\Downloads\Applications\esetsmartinstaller_enu.exe
Error: (06/24/2015 03:44:41 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\L125-User\Downloads\Applications\esetsmartinstaller_enu.exe
Error: (06/24/2015 00:56:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Spyhunter4.exe4.20.9.4533f5c01d0ae390505bc4e16C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe68b4a54a-1a2d-11e5-b45f-7ce9d3415466
Error: (06/24/2015 08:55:18 AM) (Source: MsiInstaller) (EventID: 1023) (User: NT AUTHORITY)
Description: Kaspersky Internet Security 2014Kaspersky Internet Security 2014 (Patch b)1603C:\Windows\TEMP\MSI1ebfb.LOG(NULL)(NULL)
Error: (06/24/2015 08:55:18 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
Description: Application: Kaspersky Internet Security 2014 β Internal Error 2761. (NULL)(NULL)(NULL)(NULL)(NULL)
Error: (06/24/2015 08:54:51 AM) (Source: MsiInstaller) (EventID: 1041) (User: NT AUTHORITY)
Description: {6F6873E3-5C92-4049-B511-231A138DD090}1618(NULL)(NULL)(NULL)(NULL)
Error: (06/24/2015 08:54:51 AM) (Source: MsiInstaller) (EventID: 1041) (User: NT AUTHORITY)
Description: {6F6873E3-5C92-4049-B511-231A138DD090}1618(NULL)(NULL)(NULL)(NULL)
Error: (06/23/2015 07:12:47 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\L125-User\Downloads\Applications\esetsmartinstaller_enu.exe
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-2450M CPU @ 2.50GHz
Percentage of memory in use: 70%
Total physical RAM: 1859.19 MB
Available physical RAM: 541.22 MB
Total Pagefile: 3718.38 MB
Available Pagefile: 1741.61 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive a: (Test Volume) (Network) (Total:97.66 GB) (Free:62.69 GB) NTFS
Drive b: () (Network) (Total:232.85 GB) (Free:137.11 GB) NTFS
Drive c: (ACER) (Fixed) (Total:449.06 GB) (Free:321.97 GB) NTFS
Drive l: (New Volume) (Network) (Total:2794.39 GB) (Free:2689.98 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 098D8F98)
Partition 1: (Not Active) - (Size=16.6 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=449.1 GB) - (Type=07 NTFS)
==================== End of log ============================