This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Attacked By CryptoWall 3.0. - Files Cannot Be De-crypted [Solved]

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Virus encrypted every folder.  Each folder has the attacker's message of asking for $$$ by linking to their website.  Sample of the message as attachedπŸ“ŽHELP_DECRYPT.TXT

 

aswMBR & FRST scan results as below:-

 

 

aswMBR version 1.0.1.2252 CopyrightΒ© 2014 AVAST Software
Run date: 2015-06-24 15:45:57
—————————–
15:45:57.220    OS Version: Windows x64 6.1.7601 Service Pack 1
15:45:57.225    Number of processors: 4 586 0x2A07
15:45:57.235    ComputerName: L125  UserName:
15:46:11.420    Initialize success
15:46:13.495    VM: initialized successfully
15:46:13.495    VM: Intel CPU supported
15:46:37.390    VM: not used
15:49:45.651    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
15:49:45.771    Disk 0 Vendor: ST950032 0001 Size: 476940MB BusType: 3
15:49:46.326    Disk 0 MBR read successfully
15:49:46.336    Disk 0 MBR scan
15:49:46.341    Disk 0 Windows 7 default MBR code
15:49:46.381    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        17000 MB offset 2048
15:49:46.411    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 34818048
15:49:46.431    Disk 0 default boot code
15:49:46.511    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       459838 MB offset 35022848
15:49:46.926    Disk 0 scanning C:\Windows\system32\drivers
15:50:12.541    Service scanning
15:50:43.816    Modules scanning
15:50:43.841    Disk 0 trace - called modules:
15:50:43.861    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys
15:50:43.876    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80059df060]
15:50:43.886    3 CLASSPNP.SYS[fffff880013c643f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8003eff050]
15:50:43.896    Disk 0 statistics 104559/0/0 @ 2.37 MB/s
15:50:43.911    Scan finished successfully
15:51:08.571    Disk 0 MBR has been saved successfully to "C:\Users\L125-User\Desktop\MBR.dat"
15:51:08.651    The log file has been saved successfully to "C:\Users\L125-User\Desktop\aswMBR_Log_24062015.txt"

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:21-06-2015 01
Ran by [removed] (administrator) on L125 on 24-06-2015 16:05:54
Running from C:\Users\[removed]\Downloads\Applications
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Juniper Networks) C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\n360.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2264168 2011-07-14] (Realtek Semiconductor)
HKLM\…\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [976032 2011-09-17] (Atheros Commnucations)
HKLM\…\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [799904 2011-09-17] (Atheros Commnucations)
HKLM\…\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831016 2011-08-03] (Acer Incorporated)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-24] (NTI Corporation)
HKLM-x32\…\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-18] (Renesas Electronics Corporation)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-15] (Dritek System Inc.)
HKLM-x32\…\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-21] (Egis Technology Inc.)
HKLM-x32\…\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [2005896 2015-03-26] (APN)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\Run: [Google Update] => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-10-01] (Google Inc.)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\Run: [uTorrent] => C:\Users\L125-User\AppData\Roaming\uTorrent\uTorrent.exe [1694560 2015-05-07] (BitTorrent Inc.)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\Run: [Office Timeline Performance Helper] => C:\Program Files (x86)\Office Timeline\Current\OfficeTimelineStartup.exe [13056 2014-12-19] (OfficeTimeline LLC)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\Run: [GoogleChromeAutoLaunch_051EAC4AE0499CBFED74E720976D3C62] => C:\Users\L125-User\AppData\Local\Google\Chrome\Application\chrome.exe [813896 2015-06-20] (Google Inc.)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\MountPoints2: {96387663-87c0-11e3-a661-7ce9d3415466} - E:\AutoRun.exe
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\MountPoints2: {96387672-87c0-11e3-a661-7ce9d3415466} - E:\AutoRun.exe
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\MountPoints2: {abfdd583-0df3-11e3-9964-7ce9d3415466} - E:\StartUse.exe
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [477696 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [241984 2011-11-28] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [203072 2011-11-28] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [1aCopyShExtError] -> {83BEA36E-7680-4598-A4DF-994426F6E78D} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [2aCopyShExtSynced] -> {845B7388-6F85-4F32-9FD5-F02DC7882B89} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [3aCopyShExtSyncing] -> {F6378A7A-F753-449B-AE1B-997A96132E61} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [4aCopyShExtSyncingProg1] -> {3A511828-777D-46F8-82F4-5B530C1B3D9E} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [5aCopyShExtSyncingProg2] -> {C8C88204-5B14-40EC-BA72-8AEBC762047E} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [6aCopyShExtSyncingProg3] -> {ACFF45C3-3EEB-4351-86C2-6696BA264239} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [7aCopyShExtSyncingProg4] -> {29AF997F-488B-46F0-AE78-7146F1B89CC3} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [8aCopyShExtSyncingProg5] -> {03F9AD29-1C78-4B66-8890-B177B5430C53} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\buShell.dll [2014-02-27] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\buShell.dll [2014-02-27] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\buShell.dll [2014-02-27] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll [2012-11-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll [2012-11-14] (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-2850245000-3638546127-566686928-1004] => internet.bernas.com.my:8080
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
URLSearchHook: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
URLSearchHook: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> DefaultScope {8ADEA77F-0B0A-43C8-9A51-5E81E645DAB1} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {1ACB839D-54D8-4E6E-BE51-203DD8AC7D51} URL = https://malaysia.search.yahoo.com/search?fr=chr-greentree_ie&ei;=utf-8&ilc;=12&type;=523694&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {6797A420-6EE4-4C54-A46C-05E0AFC65624} URL = http://www.search.ask.com/web?tpid=BTRSP-C&o;=APN11818&pf;=V7&p2;=^BVK^YYYYYY^YY^MY&gct;=&itbv;=12.23.0.200&apn;_uid=FA94CA64-AF74-4212-A5EA-AE35B7579139&apn;_ptnrs=^BVK&apn;_dtid=^YYYYYY^YY^MY&apn;_dbr=iexplore.exe_6_11.0.9600.17496&doi;=2015-01-27&trgb;=IE&q;={searchTerms}&psv;=&pt;=crx
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {8ADEA77F-0B0A-43C8-9A51-5E81E645DAB1} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {A13956EF-1354-45FF-9F83-14602E789106} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3220468
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Javaβ„’ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2013-01-01] (Sun Microsystems, Inc.)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\IPS\IPSBHO.DLL [2014-07-23] (Symantec Corporation)
BHO-x32: uTorrentControl_v2 Toolbar -> {7473b6bd-4691-4744-a82b-7854eb3d70b6} -> C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09] (Conduit Ltd.)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-09-17] (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Javaβ„’ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-06] (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
Toolbar: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09] (Conduit Ltd.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> No Name - {7473B6BD-4691-4744-A82B-7854EB3D70B6} -  No File
Toolbar: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
DPF: HKLM {AA570693-00E2-4907-B6F1-60A1199B030C} https://juniper.net/dana-cached/sc/JuniperSetupClient64.cab
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: HKLM-x32 {1FAF427B-1EE5-43D3-A023-3009142AFCE1} https://www2.pbebank.com/ebroking/wecos/control/csoex_pbb.cab
DPF: HKLM-x32 {B9B2EE1A-E314-4338-A305-BE845EACB113} https://www2.pbebank.com/ebroking/wecos/control/csw25.cab
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.webex.com/client/WBXclient-T28L10NSP11-16469/webex/ieatgpc1.cab
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://175.143.72.146/dana-cached/sc/JuniperSetupClient.cab
Handler: qvp - {4BA78E3D-CA25-4BFF-B8F0-8A3359E4B520} - C:\Program Files\QlikView\QvProtocol\qvp.dll [2013-12-04] (QlikTech AB)
Handler-x32: qvp - {4BA78E3D-CA25-4BFF-B8F0-8A3359E4B520} - C:\Program Files (x86)\QlikView\QvProtocol\qvp.dll [2013-12-04] (QlikTech AB)
Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 208.67.220.220
Tcpip\..\Interfaces\{173178E3-F0E6-4285-9A89-9931024E8A11}: [NameServer] 58.71.136.10 58.71.132.10

FireFox:
========
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2013-01-01] (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-09-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=10.7.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2012-09-06] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-08] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2850245000-3638546127-566686928-1004: @tools.google.com/Google Update;version=3 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-2850245000-3638546127-566686928-1004: @tools.google.com/Google Update;version=9 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\coFFPlgn [2014-10-01]
FF HKLM-x32\…\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\IPSFF [2014-04-17]

Chrome:
=======
CHR Profile: C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (uTorrentControl_v2) - C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda [2012-11-01]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-18]
CHR Extension: (Google Wallet) - C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-04]
CHR HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\L125-U~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-02]
CHR HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\L125-User\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-08-26]
CHR HKLM-x32\…\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\L125-User\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-08-26]
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\Exts\Chrome.crx [Not Found]
StartMenuInternet: Google Chrome.NWXNVHEFLZDMPKGIU56VFXSQHE - C:\Users\L125-User\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [180632 2015-03-26] (APN LLC.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [105120 2011-09-17] (Atheros Commnucations) [File not signed]
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [145920 2010-10-25] (HP) [File not signed]
R2 N360; C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\N360.exe [265040 2014-08-01] (Symantec Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2012-02-08] (Hewlett-Packard) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2012-02-08] (Hewlett-Packard) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S1 BHDrvx64; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\BASHDefs\20140912.003\BHDrvx64.sys [1586904 2014-09-13] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1505000.013\ccSetx64.sys [162392 2014-02-25] (Symantec Corporation)
R3 dsNcAdpt; C:\Windows\System32\DRIVERS\dsNcAdX64.sys [29184 2008-05-01] (Juniper Networks)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-09-09] (Symantec Corporation)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
R1 IDSVia64; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\IPSDefs\20140930.001\IDSvia64.sys [633560 2014-09-02] (Symantec Corporation)
S3 jnprva; C:\Windows\System32\DRIVERS\jnprva.sys [26480 2012-08-02] (Juniper Networks, Inc.)
S3 JnprVaMgr; C:\Windows\System32\DRIVERS\jnprvamgr.sys [45352 2012-08-02] (Juniper Networks, Inc.)
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2011-04-04] (Marvell Semiconductor, Inc.)
S3 NAVENG; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\VirusDefs\20140930.018\ENG64.SYS [129752 2014-08-27] (Symantec Corporation)
S3 NAVEX15; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\VirusDefs\20140930.018\EX64.SYS [2137304 2014-08-27] (Symantec Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S1 SRTSP; C:\Windows\System32\Drivers\N360x64\1505000.013\SRTSP64.SYS [875736 2014-02-13] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1505000.013\SRTSPX64.SYS [36952 2013-10-30] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1505000.013\SYMDS64.SYS [493656 2013-10-30] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1505000.013\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-04-16] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1505000.013\Ironx64.SYS [264280 2013-10-30] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1505000.013\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
S3 JNPRNA; system32\DRIVERS\jnprna6.sys [X]
U3 aswMBR; \??\C:\Users\L125-U~1\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\L125-U~1\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-24 16:05 - 2015-06-24 16:06 - 00000000 ____D C:\FRST
2015-06-24 15:51 - 2015-06-24 15:51 - 00000512 _____ C:\Users\L125-User\Desktop\MBR.dat
2015-06-24 15:33 - 2015-06-24 15:33 - 00000000 ___RD C:\Users\L125-User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2015-06-23 18:15 - 2015-06-23 18:15 - 00000000 ____D C:\Program Files (x86)\ESET
2015-06-23 17:06 - 2015-06-23 17:06 - 00000000 _____ C:\autoexec.bat
2015-06-23 16:22 - 2015-06-23 19:26 - 00000000 ____D C:\Users\L125-User\AppData\Local\TorrentUnlocker
2015-06-23 16:04 - 2015-06-23 16:04 - 00000000 ____D C:\NPE
2015-06-23 16:02 - 2015-06-23 16:17 - 00000000 ____D C:\Users\L125-User\AppData\Local\NPE
2015-06-23 13:54 - 2015-06-23 13:54 - 00000000 ____D C:\Users\L125-User\AppData\Local\VirtualStore
2015-06-23 11:46 - 2015-06-23 11:46 - 00008614 _____ C:\Users\L125-User\Documents\HELP_DECRYPT.HTML
2015-06-23 11:46 - 2015-06-23 11:46 - 00004250 _____ C:\Users\L125-User\Documents\HELP_DECRYPT.TXT
2015-06-23 11:46 - 2015-06-23 11:46 - 00000284 _____ C:\Users\L125-User\Documents\HELP_DECRYPT.URL
2015-06-23 11:34 - 2015-06-23 11:34 - 00008614 _____ C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.HTML
2015-06-23 11:34 - 2015-06-23 11:34 - 00008614 _____ C:\Users\L125-User\AppData\HELP_DECRYPT.HTML
2015-06-23 11:34 - 2015-06-23 11:34 - 00004250 _____ C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.TXT
2015-06-23 11:34 - 2015-06-23 11:34 - 00004250 _____ C:\Users\L125-User\AppData\HELP_DECRYPT.TXT
2015-06-23 11:34 - 2015-06-23 11:34 - 00000284 _____ C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.URL
2015-06-23 11:34 - 2015-06-23 11:34 - 00000284 _____ C:\Users\L125-User\AppData\HELP_DECRYPT.URL
2015-06-23 11:33 - 2015-06-23 11:33 - 00008614 _____ C:\Users\L125-User\AppData\Local\HELP_DECRYPT.HTML
2015-06-23 11:33 - 2015-06-23 11:33 - 00004250 _____ C:\Users\L125-User\AppData\Local\HELP_DECRYPT.TXT
2015-06-23 11:33 - 2015-06-23 11:33 - 00000284 _____ C:\Users\L125-User\AppData\Local\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\Users\Default\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\Users\Default\AppData\Local\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\Users\Default\AppData\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\Users\Default User\AppData\Local\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\Users\Default User\AppData\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00008614 _____ C:\ProgramData\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\Users\Default\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\Users\Default\AppData\Local\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\Users\Default\AppData\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\Users\Default User\AppData\Local\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\Users\Default User\AppData\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00004250 _____ C:\ProgramData\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\Users\Default\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\Users\Default\AppData\Local\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\Users\Default\AppData\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\Users\Default User\AppData\Local\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\Users\Default User\AppData\HELP_DECRYPT.URL
2015-06-23 11:32 - 2015-06-23 11:32 - 00000284 _____ C:\ProgramData\HELP_DECRYPT.URL
2015-06-16 12:47 - 2015-06-23 11:32 - 00000000 ____D C:\Users\L125-User\AppData\Local\Evernote
2015-06-04 12:53 - 2015-06-04 12:53 - 00000000 ____D C:\Program Files (x86)\RICOH
2015-06-04 12:51 - 2015-06-04 12:56 - 00000000 ____D C:\ProgramData\RICOH
2015-05-26 11:05 - 2015-06-04 12:56 - 00000510 _____ C:\Windows\system32\ricdb.ini
2015-05-26 11:04 - 2015-06-23 14:10 - 00000000 ___HD C:\ProgramData\RICOH_DRV
2015-05-26 11:04 - 2013-06-01 01:42 - 00027648 _____ (RICOH CO.,Ltd.) C:\Windows\system32\rica6Olm.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-24 16:05 - 2012-10-31 17:37 - 00000000 ____D C:\Users\L125-User\Downloads\Applications
2015-06-24 16:00 - 2012-04-03 09:38 - 00000384 _____ C:\Windows\Tasks\Acer Registration - Reminder Recall task.job
2015-06-24 15:57 - 2009-07-14 12:45 - 00024656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-24 15:57 - 2009-07-14 12:45 - 00024656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-24 15:49 - 2012-01-29 10:21 - 01195912 _____ C:\Windows\WindowsUpdate.log
2015-06-24 15:46 - 2012-10-01 12:45 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004UA.job
2015-06-24 15:41 - 2012-10-31 19:32 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\vlc
2015-06-24 15:34 - 2012-10-12 12:37 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\uTorrent
2015-06-24 15:34 - 2012-10-01 10:46 - 00000000 ____D C:\Users\L125-User\Documents\Outlook Files
2015-06-24 15:33 - 2013-08-07 11:20 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Copy
2015-06-24 15:33 - 2012-01-29 10:54 - 00000000 ____D C:\ProgramData\clear.fi
2015-06-24 15:32 - 2014-08-18 21:50 - 00031777 _____ C:\Windows\setupact.log
2015-06-24 15:32 - 2013-02-21 11:14 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-24 15:32 - 2012-04-09 09:19 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-24 15:32 - 2010-11-21 11:47 - 00419496 _____ C:\Windows\PFRO.log
2015-06-24 15:32 - 2009-07-14 13:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-24 15:26 - 2014-04-23 10:07 - 00000000 ____D C:\Users\dub_cm_auto
2015-06-24 15:26 - 2013-02-21 11:14 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-24 15:16 - 2012-04-09 09:19 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-24 15:16 - 2012-04-09 09:19 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-06-24 15:16 - 2011-10-19 09:47 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-24 13:43 - 2015-01-27 20:00 - 00000000 ____D C:\ProgramData\YTD Video Downloader
2015-06-24 13:37 - 2015-01-27 21:57 - 00000000 ____D C:\Users\L125-User\Downloads\Cycle Training
2015-06-23 19:28 - 2011-10-19 09:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Online Backup
2015-06-23 18:01 - 2014-10-01 11:56 - 00000000 ____D C:\Users\L125-User\Desktop\Ironman 70.3 Cebu
2015-06-23 16:36 - 2012-10-01 12:45 - 00000000 ____D C:\Users\L125-User\AppData\Local\Deployment
2015-06-23 16:02 - 2013-03-20 16:33 - 00000000 ____D C:\ProgramData\Norton
2015-06-23 14:27 - 2014-11-13 18:27 - 00000000 __SHD C:\Users\L125-User\AppData\Local\EmieBrowserModeList
2015-06-23 14:27 - 2014-04-21 09:54 - 00000000 __SHD C:\Users\L125-User\AppData\Local\EmieUserList
2015-06-23 14:27 - 2014-04-21 09:54 - 00000000 __SHD C:\Users\L125-User\AppData\Local\EmieSiteList
2015-06-23 14:21 - 2012-07-23 08:56 - 00000000 ____D C:\Users\PKFadmin
2015-06-23 14:20 - 2013-01-29 10:32 - 00000000 ____D C:\Users\L125-User\Documents\TEMP
2015-06-23 14:20 - 2012-10-01 12:46 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-23 14:20 - 2012-09-27 15:32 - 00000000 ____D C:\Users\L125-User\AppData\Local\PowerCinema
2015-06-23 14:20 - 2011-10-19 10:24 - 00000000 ____D C:\Program Files\Windows Journal
2015-06-23 14:20 - 2011-10-19 10:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\NDF
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\Dism
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\rescache
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\AppCompat
2015-06-23 14:19 - 2015-01-27 19:33 - 00000000 ____D C:\Users\L125-User\AppData\Local\AskPartnerNetwork
2015-06-23 14:19 - 2015-01-27 19:32 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2015-06-23 14:19 - 2012-01-29 10:42 - 00000000 ____D C:\ProgramData\Atheros
2015-06-23 14:19 - 2011-10-19 10:02 - 00000000 ____D C:\ProgramData\BackupManager
2015-06-23 14:19 - 2009-07-14 11:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-06-23 14:18 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\registration
2015-06-23 14:13 - 2012-10-31 13:50 - 00000000 ____D C:\Users\L125-User\Downloads\Movies
2015-06-23 14:12 - 2014-07-19 21:46 - 00000000 ____D C:\Users\L125-User\AppData\Local\Skype
2015-06-23 14:12 - 2013-09-05 12:38 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\NesterSoft
2015-06-23 14:12 - 2012-10-31 11:26 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Mozilla
2015-06-23 14:12 - 2012-10-01 12:01 - 00000000 ____D C:\Users\L125-User\AppData\Local\TechSmith
2015-06-23 14:12 - 2012-10-01 11:17 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Skype
2015-06-23 14:12 - 2012-09-27 17:06 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Adobe
2015-06-23 14:10 - 2015-04-28 22:47 - 00000000 ____D C:\Users\L125-User\AppData\Local\LINE
2015-06-23 14:10 - 2013-07-09 16:30 - 00000000 ____D C:\ProgramData\WebEx
2015-06-23 14:10 - 2012-09-27 15:33 - 00000000 ____D C:\Users\L125-User\AppData\Local\Google
2015-06-23 14:10 - 2012-03-29 20:03 - 00000000 ____D C:\ProgramData\OEM_E471269A730D
2015-06-23 14:10 - 2012-01-29 10:45 - 00000000 ____D C:\ProgramData\CyberLink
2015-06-23 14:10 - 2011-10-19 10:22 - 00000000 ____D C:\ProgramData\Acer
2015-06-23 14:10 - 2011-10-19 09:54 - 00000000 ____D C:\ProgramData\Symantec
2015-06-23 14:10 - 2009-07-14 11:20 - 00000000 __RHD C:\Users\Default
2015-06-23 14:09 - 2013-03-06 17:33 - 00000000 ____D C:\d7b624e545e9df63a34dfbb0cf76149c
2015-06-23 14:09 - 2012-04-02 11:40 - 00000000 ____D C:\HP_P2055_default_install_v6.1_ww
2015-06-23 14:09 - 2012-03-29 20:10 - 00000000 __RHD C:\MSOCache
2015-06-23 14:09 - 2011-10-19 10:08 - 00000000 ____D C:\Program Files (x86)\Evernote
2015-06-23 14:09 - 2011-10-19 10:04 - 00000000 __SHD C:\OEM
2015-06-23 14:02 - 2015-04-20 09:54 - 00000000 ____D C:\Users\L125-User\Desktop\KOM Taiwan
2015-06-23 11:46 - 2015-05-06 17:16 - 00000000 ____D C:\Users\L125-User\Documents\Income Tax Filing For 2014
2015-06-23 11:46 - 2014-04-07 11:47 - 00000000 ____D C:\Users\L125-User\Documents\Symantec
2015-06-23 11:46 - 2013-03-15 09:15 - 00000000 ____D C:\Users\L125-User\Documents\Bluetooth Folder
2015-06-23 11:35 - 2013-09-25 16:33 - 00000000 ____D C:\Users\L125-User\Desktop\Chords
2015-06-23 11:35 - 2013-04-24 00:25 - 00000000 ____D C:\Users\L125-User\Desktop\Baguio Phillipines
2015-06-23 11:34 - 2014-11-10 13:42 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\DoneEx
2015-06-23 11:34 - 2013-08-22 15:02 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2015-06-23 11:33 - 2013-03-01 17:40 - 00000000 ____D C:\Users\L125-User\AppData\Local\SAS
2015-06-23 11:32 - 2014-04-07 15:36 - 00000000 ____D C:\ProgramData\QlikTech
2015-06-23 11:32 - 2013-03-27 11:22 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2015-06-23 11:32 - 2013-03-27 11:22 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2015-06-23 11:32 - 2013-03-01 17:42 - 00000000 ____D C:\ProgramData\SAS
2015-06-23 11:31 - 2015-01-14 12:39 - 00000000 ____D C:\ProgramData\IsolatedStorage
2015-06-23 11:30 - 2012-01-29 10:52 - 00000000 ___HD C:\BOOK
2015-06-22 10:44 - 2012-10-05 16:17 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\PrimoPDF
2015-06-16 12:32 - 2012-10-04 11:20 - 00000000 ____D C:\Users\L125-User\Desktop\Project Management Framework
2015-06-12 19:20 - 2014-07-03 17:19 - 00000000 ____D C:\Users\L125-User\Desktop\Program Project Governanace & Audit Sharing Session
2015-06-12 16:12 - 2015-01-13 10:48 - 00000000 ____D C:\Users\L125-User\Desktop\GST Projects
2015-06-12 10:32 - 2015-04-28 22:47 - 00000961 _____ C:\ProgramData\Microsoft\Windows\Start Menu\LINE.lnk
2015-06-12 10:32 - 2015-04-28 22:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LINE
2015-06-12 10:04 - 2015-02-17 18:00 - 00003926 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{D65C931D-1A32-4701-9D5F-4287B325A776}
2015-06-11 12:44 - 2012-10-01 12:45 - 00000872 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004Core.job
2015-06-09 09:31 - 2013-02-21 11:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-06-08 11:33 - 2012-11-14 09:58 - 00000000 ____D C:\Users\L125-User\Claims
2015-06-01 08:34 - 2009-07-14 13:08 - 00032614 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-29 21:11 - 2013-03-15 08:47 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-05-29 21:11 - 2013-03-15 08:47 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-05-29 14:04 - 2013-03-15 08:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-26 14:06 - 2015-03-07 12:33 - 00000000 ____D C:\Users\L125-User\Downloads\Recipes

==================== Files in the root of some directories =======

2015-06-23 11:34 - 2015-06-23 11:34 - 0008614 _____ () C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.HTML
2015-06-23 11:34 - 2015-06-23 11:34 - 0045586 _____ () C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.PNG
2015-06-23 11:34 - 2015-06-23 11:34 - 0004250 _____ () C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.TXT
2015-06-23 11:34 - 2015-06-23 11:34 - 0000284 _____ () C:\Users\L125-User\AppData\Roaming\HELP_DECRYPT.URL
2015-06-23 11:33 - 2015-06-23 11:33 - 0008614 _____ () C:\Users\L125-User\AppData\Local\HELP_DECRYPT.HTML
2015-06-23 11:33 - 2015-06-23 11:33 - 0045586 _____ () C:\Users\L125-User\AppData\Local\HELP_DECRYPT.PNG
2015-06-23 11:33 - 2015-06-23 11:33 - 0004250 _____ () C:\Users\L125-User\AppData\Local\HELP_DECRYPT.TXT
2015-06-23 11:33 - 2015-06-23 11:33 - 0000284 _____ () C:\Users\L125-User\AppData\Local\HELP_DECRYPT.URL
2014-11-10 13:42 - 2014-11-10 13:42 - 0000082 _____ () C:\Users\L125-User\AppData\Local\{vO5T0cEfJ7FeZhpfKQxAPLaadYgK9UftD5
2012-11-25 17:54 - 2012-11-25 17:54 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-01-29 10:45 - 2012-01-29 10:47 - 0015027 _____ () C:\ProgramData\ArcadeDeluxe5.log
2015-06-23 11:32 - 2015-06-23 11:32 - 0008614 _____ () C:\ProgramData\HELP_DECRYPT.HTML
2015-06-23 11:32 - 2015-06-23 11:32 - 0045586 _____ () C:\ProgramData\HELP_DECRYPT.PNG
2015-06-23 11:32 - 2015-06-23 11:32 - 0004250 _____ () C:\ProgramData\HELP_DECRYPT.TXT
2015-06-23 11:32 - 2015-06-23 11:32 - 0000284 _____ () C:\ProgramData\HELP_DECRYPT.URL
2012-04-02 11:41 - 2012-04-02 11:46 - 0000359 _____ () C:\ProgramData\hpzinstall.log

Some files in TEMP:
====================
C:\Users\L125-User\AppData\Local\Temp\DataCard_Setup64.exe
C:\Users\L125-User\AppData\Local\Temp\GUR77D8.exe
C:\Users\L125-User\AppData\Local\Temp\ResetDevice.exe
C:\Users\L125-User\AppData\Local\Temp\siinst.exe
C:\Users\L125-User\AppData\Local\Temp\SkypeSetup.exe
C:\Users\L125-User\AppData\Local\Temp\strings.dll
C:\Users\L125-User\AppData\Local\Temp\utt45A3.tmp.exe
C:\Users\L125-User\AppData\Local\Temp\utt69A0.tmp.exe
C:\Users\L125-User\AppData\Local\Temp\utt8694.tmp.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-06-23 00:08

==================== End of log ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:21-06-2015 01
Ran by [removed] at 2015-06-24 16:07:51
Running from C:\Users\[removed]\Downloads\Applications
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-2850245000-3638546127-566686928-500 - Administrator - Disabled)
Guest (S-1-5-21-2850245000-3638546127-566686928-501 - Limited - Disabled)
L125-User (S-1-5-21-2850245000-3638546127-566686928-1004 - Administrator - Enabled) => C:\Users\L125-User
PKFadmin (S-1-5-21-2850245000-3638546127-566686928-1002 - Administrator - Enabled) => C:\Users\PKFadmin
UpdatusUser (S-1-5-21-2850245000-3638546127-566686928-1000 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton 360 Premier Edition (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton 360 Premier Edition (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton 360 Premier Edition (Disabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Β΅Torrent (HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.)
192.168.0.8-64bits_RICOH MP 3353 PCL 6_64bits [RICOH MP 3353 PCL 6] (HKLM\…\{AF4633AC-C8D6-4B23-B06F-0837E1844606}) (Version: 1.0.0 - RICOH)
64 Bit HP CIO Components Installer (Version: 13.2.1 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.4 - Hewlett-Packard) Hidden
Acer Backup Manager (HKLM-x32\…\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.99 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1904 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.0.1904 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3008 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Acer Incorporated)
Acer Games (HKLM-x32\…\WildTangent acer Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.04.3504 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\…\Acer Screensaver) (Version: 1.1.0902.2011 - Acer Incorporated)
Acer Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3500 - Acer Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 2.7.1.19610 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM-x32\…\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.6 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 17.0.0.190 - Adobe Systems Incorporated)
Adobe Reader X (10.1.14) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.14 - Adobe Systems Incorporated)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden
AP Tuner 3.08 (HKLM-x32\…\AP Tuner 3.08) (Version:  - )
Backup Manager V3 (x32 Version: 3.0.0.99 - NTI Corporation) Hidden
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bluetooth Win7 Suite (64) (HKLM\…\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.96 - Atheros)
Broadcom Card Reader Driver Installer (HKLM\…\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 14.4.9.2 - Broadcom Corporation)
Broadcom NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 15.0.3.2 - Broadcom Corporation)
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cisco WebEx Meetings (HKLM-x32\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
clear.fi (HKLM-x32\…\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 1.0.2228.00 - CyberLink Corp.)
clear.fi (x32 Version: 1.0.1517_36458 - CyberLink Corp.) Hidden
clear.fi (x32 Version: 1.0.2228.00 - CyberLink Corp.) Hidden
clear.fi (x32 Version: 9.0.8228 - CyberLink Corp.) Hidden
clear.fi Client (HKLM-x32\…\{43AAE145-83CF-4C96-9A5E-756CEFCE879F}) (Version: 1.00.3500 - Acer Incorporated)
Copy (HKLM\…\{BF1346D9-2622-4913-86A6-6B63536B1AEB}) (Version: 1.34.508.0 - Barracuda Networks, Inc.)
Crazy Chicken Kart 2 (x32 Version: 2.2.0.97 - WildTangent) Hidden
CustomerResearchQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dolby Advanced Audio v2 (HKLM-x32\…\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.7000.7 - Dolby Laboratories Inc)
Dropbox (HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\Dropbox) (Version: 1.6.16 - Dropbox, Inc.)
eBay Worldwide (HKLM-x32\…\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
Email Templates Collection 1 1.0.5 (HKLM-x32\…\B341F1D4-72BA-4C1B-A8FD-2FCCDDB3888E_is1) (Version: 1.0.5 - DeliveryTech)
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
Evernote v. 4.5.1 (HKLM-x32\…\{28921580-E4BB-11E0-9FD7-1CC1DEF07CBE}) (Version: 4.5.1.5451 - Evernote Corp.)
FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsΕ‚ugΔ™ poΕ‚Δ…czeΕ„ zdalnych (HKLM-x32\…\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
Free MP3 Cutter 2.0 (HKLM-x32\…\{847E0734-4457-4B48-BF49-998D1CF2CFA1}_is1) (Version: 2.0 - PolySoft Solutions)
Free PDF Converter (HKLM-x32\…\Free PDF Converter_is1) (Version:  - Baltsoft)
Google Chrome (HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\Google Chrome) (Version: 43.0.2357.130 - Google Inc.)
Google Drive (HKLM-x32\…\{CBC9F5FD-5CFA-4A33-81CD-369EAB77E3A6}) (Version: 1.22.9403.0223 - Google, Inc.)
Google Talk (remove only) (HKLM-x32\…\{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk) (Version:  - )
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
HP Customer Participation Program 10.0 (HKLM\…\HPExtendedCapabilities) (Version: 10.0 - HP)
HP Deskjet 2050 J510 series Basic Device Software (HKLM\…\{73B1AC18-614F-42CD-A798-4BA214586406}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP FWUpdateEDO3 (HKLM-x32\…\{A82D0C46-EBDF-4B27-A731-D06EF2056E81}) (Version: 1.0.0.0 - Hewlett-Packard Company)
HP LaserJet P2050 Series 6.0 (HKLM\…\{6F801026-6AF0-4520-9153-4C9B4CAAB361}) (Version: 6.0 - HP)
HP LaserJet Professional CM1410 Series (HKLM-x32\…\{0EF0EA0D-F945-4958-85CC-60FF1E86D216}) (Version:  - Hewlett-Packard)
HP LaserJet Professional M1130-M1210 MFP Series (HKLM\…\HP LaserJet Professional M1130-M1210 MFP Series) (Version:  - )
HP LaserJet Professional M1530 MFP Series (HKLM-x32\…\{74280B5D-A0AF-46c5-9C85-D9EA078262F1}) (Version:  - Hewlett-Packard)
HP LaserJet Professional P1100-P1560-P1600 Series (HKLM\…\HP LaserJet Professional P1100-P1560-P1600 Series) (Version:  - )
HP LJ CM1410 MFP Series HP Scan (HKLM-x32\…\{21749F4E-02A1-4828-9A1E-BBDF5929C5D0}) (Version: 1.0.302.0 - Hewlett-Packard Co.)
HP LJ M1530 MFP Series HP Scan (HKLM-x32\…\{C05002F1-06F8-4A15-B6F8-E4DC655C28AA}) (Version: 1.0.302.0 - Hewlett-Packard Co.)
HP Update (HKLM-x32\…\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
HPLaserJetHelp_LearnCenter (HKLM-x32\…\{22FE3793-5961-4ADE-AE66-69D9291C22B1}) (Version: 1.03.0000 - Hewlett-Packard)
HPLaserJetHelp_LearnCenter (HKLM-x32\…\{B2AA0F22-E167-4C4A-BAE2-E0025028E61B}) (Version: 1.01.0000 - Hewlett-Packard)
HPLJUT (HKLM-x32\…\{229D6185-BD7E-494B-A73B-C5215BE0690E}) (Version: 1.00.0007 - HP)
hppCM1410LaserJetService (x32 Version: 001.008.00477 - Hewlett-Packard) Hidden
hppFaxDrvCM1410 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppFaxDrvM1530 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppFaxUtilityCM1410 (x32 Version: 000.002.00001 - Hewlett-Packard) Hidden
hppFaxUtilityM1530 (x32 Version: 000.002.00001 - Hewlett-Packard) Hidden
hppFonts (x32 Version: 001.001.00061 - Hewlett-Packard) Hidden
hppLaserJetService (x32 Version: 002.015.00599 - Hewlett-Packard) Hidden
hppM1530LaserJetService (x32 Version: 001.007.00319 - Hewlett-Packard) Hidden
hppQFolderP2050 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
hppSendFaxCM1410 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppSendFaxM1530 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppTLBXFXCM1410 (x32 Version: 001.012.00948 - Hewlett-Packard) Hidden
hppTLBXFXM1530 (x32 Version: 001.007.00647 - Hewlett-Packard) Hidden
hppusgP2050 (x32 Version: 1.1.0.1 - Hewlett-Packard) Hidden
hpzTLBXFX (x32 Version: 006.015.01163 - Hewlett-Packard) Hidden
I.R.I.S. OCR (HKLM-x32\…\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4 - HP)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
Insaniquarium Deluxe (x32 Version: 2.2.0.97 - WildTangent) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2538 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\…\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel)
Java 7 Update 7 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217007FF}) (Version: 7.0.70 - Oracle)
Java(TM) 6 Update 24 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86416024FF}) (Version: 6.0.240 - Oracle)
Java(TM) 6 Update 24 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83216024FF}) (Version: 6.0.240 - Oracle)
Java(TM) SE Development Kit 6 Update 24 (64-bit) (HKLM\…\{64A3A4F4-B792-11D6-A78A-00B0D0160240}) (Version: 1.6.0.240 - Oracle)
JavaFX 2.1.1 (HKLM-x32\…\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jewel Match 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Juniper Networks Network Connect 6.0.0 (HKLM-x32\…\Juniper Network Connect 6.0.0) (Version: 6.0.0.13073 - Juniper Networks)
Juniper Networks Setup Client (HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\JuniperSetupClient) (Version: 1.1.0.0 - Juniper Networks)
Juniper Networks, Inc. Setup Client 64-bit Activex Control (HKLM\…\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks, Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.4 - Acer Inc.)
LINE (HKLM-x32\…\LINE) (Version: 4.0.3.367 - LINE Corporation)
MarketResearch (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden
Maxis Broadband (HKLM-x32\…\Maxis Broadband) (Version: 11.302.06.10.99 - Huawei Technologies Co.,Ltd)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Business 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0401-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0402-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0403-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0404-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0405-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0406-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0407-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0408-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-040B-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-040C-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-040D-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-040E-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0410-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0413-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0414-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0415-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0416-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0418-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0419-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-041A-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-041B-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-041D-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-041E-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-041F-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0424-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0816-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0C0A-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Facebook 32-bit (HKLM-x32\…\{95140000-007C-0409-0000-0000000FF1CE}) (Version: 14.0.6114.5003 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\…\{95140000-007D-0409-0000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Project Standard 2010 (HKLM-x32\…\Office14.PRJSTDR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\…\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.19 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 4.0.14.19 - Egis Technology Inc.) Hidden
Norton 360 (HKLM-x32\…\N360) (Version: 21.5.0.19 - Symantec Corporation)
Norton Online Backup (HKLM-x32\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
NTI Media Maker 9 (HKLM-x32\…\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9002 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.9002 - NTI Corporation) Hidden
NVIDIA Graphics Driver 285.90 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 285.90 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\…\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
Office Timeline (HKLM-x32\…\{DAE585BA-546F-4684-9592-6EA2D0DF071E}) (Version: 3.1.3 - Office Timeline)
PDFBinder (HKLM-x32\…\{8BA03AC2-579F-41CD-A250-740137D86F7A}) (Version: 1.0.0 - Malamute.dk)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
PrimoPDF – brought to you by Nitro PDF Software (HKLM-x32\…\PrimoPDF) (Version: 5 - Nitro PDF Software)
QlikView Desktop Documentation and Tutorial English (HKLM-x32\…\{C5E37ACB-E2DA-4704-BE99-8781CC187B28}) (Version: 11.20.12235.0 - QlikTech International AB)
QlikView x64 (HKLM\…\{1ED3B75E-BED2-4863-9763-098DE00590B3}) (Version: 11.20.12235.0 - QlikTech International AB)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6423 - Realtek Semiconductor Corp.)
RegClean-Pro (HKLM-x32\…\RegClean-Pro_is1) (Version: 6.21 - Systweak Inc)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\…\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Scan To (HKLM\…\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP)
Search App by Ask (HKLM-x32\…\{42545253-502D-4300-76A7-A75C790C1B00}) (Version: 12.27.0.1060 - APN, LLC) <==== ATTENTION
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-003A-0000-0000-0000000FF1CE}_Office14.PRJSTDR_{58FA40EF-ABA9-4FED-AD3D-318A6073934D}) (Version:  - Microsoft)
Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Skypeβ„’ 6.21 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Snagit 11 (HKLM-x32\…\{F8E3C768-71F3-11E1-9DF7-70804824019B}) (Version: 11.0.1 - TechSmith Corporation)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.3.26.2 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.24482 - TeamViewer)
TimeLeft (HKLM-x32\…\TIMELEFT3_is1) (Version: 3.62 - NesterSoft Inc.)
Torchlight (x32 Version: 2.2.0.97 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
uTorrentControl_v2 Toolbar (HKLM-x32\…\uTorrentControl_v2 Toolbar) (Version: 6.9.0.16 - uTorrentControl_v2) <==== ATTENTION
VC8 CRT (Version: 8.0.50727.762 - Juniper Networks) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.97 - WildTangent) Hidden
VLC media player 2.0.4 (HKLM-x32\…\VLC media player) (Version: 2.0.4 - VideoLAN)
WebReg (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden
Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.02.3505 - Acer Incorporated)
WildTangent Games App (Acer Games) (x32 Version: 4.0.5.14 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\…\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
YTD Video Downloader 4.9 (HKLM-x32\…\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.9 - GreenTree Applications SRL) <==== ATTENTION
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\L125-User\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\L125-User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File

==================== Restore Points =========================

11-06-2015 13:59:11 Scheduled Checkpoint
12-06-2015 11:00:18 Windows Update
16-06-2015 12:42:52 Installed Evernote v. 5.8.8
23-06-2015 12:19:38 Restore Operation

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 10:34 - 2013-08-20 14:42 - 00001074 ____N C:\Windows\system32\Drivers\etc\hosts
 192.168.63.247  sasmetadata  
 192.168.63.248  sasdi   
 192.168.63.249  sasebi   
 192.168.63.250  sasmidtier  

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0BC16753-E239-4BAD-83D1-94467D1E9BAC} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-29] (Egis Technology Inc.)
Task: {0D8FAA7E-7208-44E6-B098-C2D81C665B4F} - System32\Tasks\{6121D0CC-8ADE-49A7-BE34-70F07D198D54} => C:\Users\L125-User\Downloads\b98be66f7073436ab3a8ecd9ae11ee6a_Pod8_en-GB.exe
Task: {1AAEAA7C-9286-4833-BF5F-373F29EF4383} - System32\Tasks\clear.fiAgent => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe [2011-10-29] (CyberLink Corp.)
Task: {27E3A400-46BC-4148-A9A1-DC411554478D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {3B7E8DA3-21FE-4B77-BC44-72B82CD6833A} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2012-10-03] (Microsoft Corporation)
Task: {412BCB9E-6F4F-44BE-92F2-1C05D308F78B} - System32\Tasks\DMREngine => C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe [2011-10-29] (CyberLink)
Task: {4A6B2FEA-929F-4EAC-A005-6FF6E76858C4} - System32\Tasks\Acer Registration - Reminder Recall task => C:\Program Files (x86)\Acer\Registration\GREG.exe [2011-05-11] (Acer Incorporated)
Task: {4F84BA1A-0677-4D7B-909A-F58947433359} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-15] (Google Inc.)
Task: {58C776A6-76BD-4683-A30C-E40FBE782383} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\SymErr.exe [2014-01-31] (Symantec Corporation)
Task: {5E643F74-3CDD-4CAE-BF6F-9EA7EFE5565C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-15] (Google Inc.)
Task: {7CEC44E8-B2A4-4FB5-B804-A7FF682162FF} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-29] (Egis Technology Inc.)
Task: {7D38031B-DBB6-49D8-B351-F0D4B8719D63} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004UA => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-01] (Google Inc.)
Task: {867EB48A-DD34-4C11-AE76-D9DB6DB62E13} - System32\Tasks\{7D397F49-7B53-4BB8-B80F-205656218F21} => C:\Users\L125-User\Downloads\b98be66f7073436ab3a8ecd9ae11ee6a_Pod8_en-GB.exe
Task: {8C306857-3EB9-4D91-92FB-0CFA9E0E712E} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [2010-04-13] (Hewlett Packard)
Task: {8D4391C2-F842-4366-B7D8-F3E1D62FC62E} - System32\Tasks\{19A2A0B9-C3F4-4691-A68D-4B87A00CCA36} => Iexplore.exe http://ui.skype.com/ui/0/6.0.0.126/en/abandoninstall?page=tsProgressBar
Task: {943E23DE-41D8-4D3A-B1A2-22762EE9A62E} - System32\Tasks\clear.fi => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe [2011-10-29] (Acer Incorporated)
Task: {9CA31130-BD48-4DB3-A0BB-979AA0FDB08F} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\WSCStub.exe [2014-08-01] (Symantec Corporation)
Task: {9DE84380-5ADB-4A32-A355-2DE713603F4A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004Core => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-01] (Google Inc.)
Task: {BC47B473-942A-4821-B770-F55DCA02BAF0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-24] (Adobe Systems Incorporated)
Task: {D4F00EF3-FB53-44AB-8BE0-922EF36EF248} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\SymErr.exe [2014-01-31] (Symantec Corporation)
Task: C:\Windows\Tasks\Acer Registration - Reminder Recall task.job => C:\Program Files (x86)\Acer\Registration\GREG.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004Core.job => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004UA.job => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2012-08-02 10:31 - 2011-04-02 16:05 - 00290304 _____ () C:\Windows\System32\HP1100LM.DLL
2015-01-07 18:45 - 2010-03-31 11:51 - 00407040 _____ () C:\Windows\System32\HPM1210LM.DLL
2012-10-05 15:57 - 2011-03-01 06:37 - 00095008 _____ () C:\Windows\System32\Primomonnt.dll
2012-08-02 10:32 - 2011-04-02 16:04 - 00074240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\HP1100PP.DLL
2015-01-07 18:57 - 2010-03-31 11:51 - 00074240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\HPM1210PP.dll
2013-08-07 11:20 - 2014-06-12 10:44 - 08212480 _____ () C:\Users\L125-User\AppData\Roaming\Copy\overlay\Brt.dll
2012-01-29 10:06 - 2011-09-26 16:36 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-04-24 09:29 - 2011-04-24 09:29 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2011-04-24 09:29 - 2011-04-24 09:29 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2011-04-24 09:29 - 2011-04-24 09:29 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2011-10-29 07:04 - 2011-10-29 07:04 - 00206216 _____ () C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLNetMediaDMA.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-02-14 15:46 - 2013-02-14 15:46 - 01044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00111616 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlc.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 02286592 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlccore.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00219648 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdshow_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00049664 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libaout_directx_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00051200 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00070144 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirectx_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00037376 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmxext\libmemcpymmxext_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00157696 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\liblibbluray_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00093696 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_bd_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00258560 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdvdnav_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00047616 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_vdr_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00043520 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libfilesystem_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00440320 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libstream_filter_httplive_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00724992 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libstream_filter_dash_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00038912 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libstream_filter_rar_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00083968 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libzip_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00035840 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libstream_filter_record_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00106496 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libplaylist_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01544192 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libtaglib_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00310784 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\lua\liblua_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01238016 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\misc\libxml_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00051200 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libhotkeys_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00037888 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libglobalhotkeys_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 11998208 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\gui\libqt4_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00288768 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libupnp_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00085504 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libsap_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00041984 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libpodcast_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00038400 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libmediadirs_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00036352 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libwindrive_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00044544 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libes_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00198656 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmp4_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00386560 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libtheora_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00092160 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libavi_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00037376 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\librawvideo_plugin.dll
2012-10-16 04:27 - 2012-10-16 04:27 - 00073728 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libasf_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00045568 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libflacsys_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00154624 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspeex_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01719296 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libvorbis_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00037376 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaes3_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00043008 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblpcm_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00044032 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_flac_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00051712 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_dirac_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00042496 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mlp_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00057344 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpeg4audio_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00046592 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_vc1_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00038912 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libsvcdsub_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00042496 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspudec_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00043008 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpeg4video_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00045568 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpegvideo_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00040960 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcvdsub_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00087040 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_h264_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00041472 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libmpeg_audio_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00185856 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libpng_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00038400 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01318912 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libschroedinger_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00051200 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaraw_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00043008 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libdts_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00372224 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libfaad_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00265216 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libflac_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01887232 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblibass_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00310784 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libopus_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00182272 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdtstofloat32_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00068608 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\liba52tofloat32_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00135168 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libmpgatofixed32_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 01518080 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsamplerate_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00036864 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libconverter_fixed_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00034816 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\liba52tospdif_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00038400 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsimple_channel_mixer_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00036864 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdtstospdif_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00036352 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdolby_surround_decoder_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00035328 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libugly_resampler_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00045568 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libaudio_format_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00033792 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_mixer\libfloat32_mixer_plugin.dll
2012-10-16 04:28 - 2012-10-16 04:28 - 00040960 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libscaletempo_plugin.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\L125-User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 208.67.222.222 - 208.67.220.220

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^Users^L125-User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP Deskjet 2050 J510 series.lnk => C:\Windows\pss\Monitor Ink Alerts - HP Deskjet 2050 J510 series.lnk.Startup
MSCONFIG\startupfolder: C:^Users^L125-User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TimeLeft.lnk => C:\Windows\pss\TimeLeft.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: ArcadeMovieService => "C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe"
MSCONFIG\startupreg: Copy => "C:\Users\L125-User\AppData\Roaming\Copy\CopyAgent.exe"
MSCONFIG\startupreg: Dolby Advanced Audio v2 => "C:\Dolby PCEE4\pcee4.exe" -autostart
MSCONFIG\startupreg: Google Update => "C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
MSCONFIG\startupreg: googletalk => C:\Program Files (x86)\Google\Google Talk\googletalk.exe /autostart
MSCONFIG\startupreg: HP LaserJet Professional CM1410 Series Fax => C:\Program Files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe "HP LaserJet Professional CM1410 Series Fax"
MSCONFIG\startupreg: HP LaserJet Professional M1530 MFP Series Fax => C:\Program Files\HP\HP LaserJet Professional M1530 MFP Series\Fax Driver\hppfaxprintersrv.exe "HP LaserJet Professional M1530 MFP Series Fax"
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: HPUsageTracking => "C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT\"
MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
MSCONFIG\startupreg: ToolboxFX => "C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{7CE85EF5-8332-4262-AB8A-D63339F059F0}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{29D9110F-687E-4E1C-A3CF-9B5260BF25BF}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{D7379D53-D9A0-4889-AF79-5A07231B3042}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{134F1FF7-B217-4B6B-9E8C-A36D61F893A9}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{906ADC2D-FEF9-457F-BFB4-E23B1737C5CF}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe
FirewallRules: [{DEC4F025-5E99-4F03-97AA-7CCD76E3466C}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
FirewallRules: [{91FFC9C7-B47F-41A7-AED2-C2535A33FC15}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\CLML\CLMLSvc.exe
FirewallRules: [{B47CD000-178D-47F8-9B33-709EB90C858E}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{627DFA4F-6595-42FC-8F60-03D104D2CCB9}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{F3E895E6-B372-43AC-A3D1-4E5017934514}] => (Block) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{4F81DFA8-005A-45CD-8376-C43423E9E068}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovie.exe
FirewallRules: [{06CC5013-0BB6-4A17-B288-3A579136DC43}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovieService.exe
FirewallRules: [{B88D13D9-4332-498D-8D7B-EDF0C09E9897}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9AED157C-5393-4F0E-913D-61F39F5696E4}] => (Allow) LPort=2869
FirewallRules: [{3928A412-C9E3-45F2-9605-0E370B981019}] => (Allow) LPort=1900
FirewallRules: [{6E81CDD4-4898-46D6-92D4-3B7FBDA7167F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{DD0BC37B-E1F6-437E-BEEA-2E24CA0F0A34}] => (Allow) C:\Program Files (x86)\Google\Google Talk\googletalk.exe
FirewallRules: [{EA1915FA-315A-40EF-9389-C2EB392E712C}] => (Allow) C:\Program Files (x86)\Google\Google Talk\googletalk.exe
FirewallRules: [{EE3FF0AD-A633-417F-871A-40F9537C6A1A}] => (Allow) C:\Users\L125-User\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{77F02A37-F1D9-49D5-A0B1-4731E0CA0934}] => (Allow) C:\Users\L125-User\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{148241BF-2246-4137-8885-89CA89AAF291}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{0C005419-F759-438F-8D0B-B99F2754367B}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{A5983858-55E5-496F-98A2-273EB6BAF97D}] => (Allow) C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe
FirewallRules: [{F36F44C8-CA09-4CCA-AA59-C5F1C2F2C2D9}] => (Allow) C:\Users\L125-User\AppData\Roaming\Copy\CopyAgent.exe
FirewallRules: [{5A208310-1D07-458E-A777-D3D088B981E2}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{084BDD71-A3E7-4AC1-85E7-AC24D0DBF232}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{D0042F2A-8BBD-44C9-8E56-9BDE1AEFA417}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{29E483E6-CF6A-401A-A5A6-A2221CFD8419}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{FB7F288C-5DC7-4F93-9FBD-6A5B442D7A08}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [TCP Query User{1BB47B53-D534-45C3-A142-D57A493908A2}C:\users\l125-user\appdata\roaming\copy\copyagent.exe] => (Allow) C:\users\l125-user\appdata\roaming\copy\copyagent.exe
FirewallRules: [UDP Query User{DE51D2A7-0CB1-49BB-A464-A83A923C8621}C:\users\l125-user\appdata\roaming\copy\copyagent.exe] => (Allow) C:\users\l125-user\appdata\roaming\copy\copyagent.exe
FirewallRules: [{9AB42673-534D-4520-BD39-0F25022177DE}] => (Allow) C:\Users\L125-User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{04A3B277-C12A-476A-BC78-71708DCA6826}] => (Allow) C:\Users\L125-User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{09F4B518-A622-4A4E-BB08-3B3BC0CC720E}] => (Allow) C:\Program Files (x86)\LINE\LINE.exe
FirewallRules: [{F4CE7436-A595-4873-8949-20D359C3D3FD}] => (Allow) C:\Program Files (x86)\LINE\LINE.exe
FirewallRules: [{BDC4D034-A9E1-48EC-A31A-A686F9F7393A}] => (Allow) C:\Users\L125-User\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: BHDrvx64
Description: BHDrvx64
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: BHDrvx64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

==================== Event log errors: =========================

Application errors:
==================
Error: (06/24/2015 04:04:53 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/24/2015 03:59:02 PM) (Source: MsiInstaller) (EventID: 10005) (User: L125)
Description: Product: Search App by Ask – Error 25001. The following applications must be closed before continuing the uninstall:

Internet Explorer

Error: (06/24/2015 03:44:42 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/24/2015 03:44:41 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/24/2015 00:56:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Spyhunter4.exe version 4.20.9.4533 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: f5c

Start Time: 01d0ae390505bc4e

Termination Time: 16

Application Path: C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe

Report Id: 68b4a54a-1a2d-11e5-b45f-7ce9d3415466

Error: (06/24/2015 08:55:18 AM) (Source: MsiInstaller) (EventID: 1023) (User: NT AUTHORITY)
Description: Product: Kaspersky Internet Security 2014 - Update 'Kaspersky Internet Security 2014 (Patch B)' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI1ebfb.LOG.

Error: (06/24/2015 08:55:18 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
Description: Application: Kaspersky Internet Security 2014 – Internal Error 2761.

Error: (06/24/2015 08:54:51 AM) (Source: MsiInstaller) (EventID: 1041) (User: NT AUTHORITY)
Description: Failed to begin a Windows Installer transaction {6F6873E3-5C92-4049-B511-231A138DD090}. Error 1618 occurred while beginning the transaction.

Error: (06/24/2015 08:54:51 AM) (Source: MsiInstaller) (EventID: 1041) (User: NT AUTHORITY)
Description: Failed to begin a Windows Installer transaction {6F6873E3-5C92-4049-B511-231A138DD090}. Error 1618 occurred while beginning the transaction.

Error: (06/23/2015 07:12:47 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

System errors:
=============
Error: (06/24/2015 03:32:49 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
BHDrvx64
SRTSP

Error: (06/24/2015 03:32:10 PM) (Source: SRTSP) (EventID: 4) (User: )
Description: Error loading virus definitions.

Error: (06/24/2015 03:31:14 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}

Error: (06/24/2015 03:25:44 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer L133-WONG
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{D75985F7-EE80-4C5B-91C4-90645002486D}.
The master browser is stopping or an election is being forced.

Error: (06/24/2015 00:59:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
BHDrvx64
SRTSP

Error: (06/24/2015 00:58:34 PM) (Source: SRTSP) (EventID: 4) (User: )
Description: Error loading virus definitions.

Error: (06/24/2015 00:48:07 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
BHDrvx64
SRTSP

Error: (06/24/2015 00:47:27 PM) (Source: SRTSP) (EventID: 4) (User: )
Description: Error loading virus definitions.

Error: (06/24/2015 09:46:41 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (06/24/2015 07:48:34 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The NVIDIA Update Service Daemon service hung on starting.

Microsoft Office:
=========================
Error: (06/24/2015 04:04:53 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\L125-User\Downloads\Applications\esetsmartinstaller_enu.exe

Error: (06/24/2015 03:59:02 PM) (Source: MsiInstaller) (EventID: 10005) (User: L125)
Description: Product: Search App by Ask – Error 25001. The following applications must be closed before continuing the uninstall:

Internet Explorer (NULL)(NULL)(NULL)(NULL)(NULL)

Error: (06/24/2015 03:44:42 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\L125-User\Downloads\Applications\esetsmartinstaller_enu.exe

Error: (06/24/2015 03:44:41 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\L125-User\Downloads\Applications\esetsmartinstaller_enu.exe

Error: (06/24/2015 00:56:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Spyhunter4.exe4.20.9.4533f5c01d0ae390505bc4e16C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe68b4a54a-1a2d-11e5-b45f-7ce9d3415466

Error: (06/24/2015 08:55:18 AM) (Source: MsiInstaller) (EventID: 1023) (User: NT AUTHORITY)
Description: Kaspersky Internet Security 2014Kaspersky Internet Security 2014 (Patch b)1603C:\Windows\TEMP\MSI1ebfb.LOG(NULL)(NULL)

Error: (06/24/2015 08:55:18 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
Description: Application: Kaspersky Internet Security 2014 – Internal Error 2761. (NULL)(NULL)(NULL)(NULL)(NULL)

Error: (06/24/2015 08:54:51 AM) (Source: MsiInstaller) (EventID: 1041) (User: NT AUTHORITY)
Description: {6F6873E3-5C92-4049-B511-231A138DD090}1618(NULL)(NULL)(NULL)(NULL)

Error: (06/24/2015 08:54:51 AM) (Source: MsiInstaller) (EventID: 1041) (User: NT AUTHORITY)
Description: {6F6873E3-5C92-4049-B511-231A138DD090}1618(NULL)(NULL)(NULL)(NULL)

Error: (06/23/2015 07:12:47 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\L125-User\Downloads\Applications\esetsmartinstaller_enu.exe

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-2450M CPU @ 2.50GHz
Percentage of memory in use: 70%
Total physical RAM: 1859.19 MB
Available physical RAM: 541.22 MB
Total Pagefile: 3718.38 MB
Available Pagefile: 1741.61 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive a: (Test Volume) (Network) (Total:97.66 GB) (Free:62.69 GB) NTFS
Drive b: () (Network) (Total:232.85 GB) (Free:137.11 GB) NTFS
Drive c: (ACER) (Fixed) (Total:449.06 GB) (Free:321.97 GB) NTFS
Drive l: (New Volume) (Network) (Total:2794.39 GB) (Free:2689.98 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 098D8F98)
Partition 1: (Not Active) - (Size=16.6 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=449.1 GB) - (Type=07 NTFS)

==================== End of log ============================

 

Hello FallenChink! :adios:

Welcome to What the Tech.
I am Marie Curie and will gladly help you with any malware-related problems.

I am currently in training at WhatTheTech and every post of mine will be approved by a teacher. I will return as soon as possible with instructions. Please familiarize yourself with the following ground rules in the meanwhile.

  • Read my instructions thoroughly, carry out each step in the given order.
  • Do not make any changes to your system, or run any tools other than those I provided. Do not delete, fix, uninstall, or install anything unless I tell you to.
  • If you are unsure about anything or if you encounter any problems, please stop and inform me about it.
  • Stick with me until I tell you that your computer is clean. Absence of symptoms does not mean that your computer is free of malware.
  • Back up important files before we start.

 

 

Hello FallenChick
 
Unfortunately there is currently no way to decrypt files that have been encrypted by CryptoWall 3.0, but we can try a few file recovery methods. At first we need to clean up your computer, otherwise we would risk that your files get encrypted again.
 
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”

[external image: goGMWSt.gif]P2P Warning

β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”

I see you have peer-to-peer (P2P) file sharing software installed on your computer (uTorrent). I advise you avoid P2P file sharing programmes; they are a security risk which can make your computer susceptible to malware. File sharing networks are thoroughly infested with malware - worms, backdoor Trojans, IRCBots, and rootkits propagate via P2P file sharing networks, gaming, and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install malware. The best way to reduce the risk of infection is to avoid these types of web sites and P2P programmes. Please read the following articles for more information.

  • Risks of File-Sharing Technology
  • P2P Software User Advisories
  • More malware is traveling on P2P networks these days

Your P2P software can be removed by following the instructions below.

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for the aforementioned programme(s), right-click and click Uninstall. Follow the prompts.

If you choose not to, please refrain from using the programme(s) during this process.
 
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
 
[external image: goGMWSt.gif]Registry Cleaner Warning
 
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
 
I see you have registry cleaner/optimization software (RegClean Pro) installed on your computer. Registry cleaners and optimization tools that claim to speed up your computer should be avoided, and are potentially dangerous. By running a registry cleaner you risk rendering your machine unbootable. There is no statistical evidence to back claims that cleaning the registry will improve performance. Advertisements to do so are borderline scams intended to goad users into using an unnecessary and potential dangerous product.

  • Some registry cleaners employ aggressive cleaning routines that may cause substantial damage to your system, and could render your machine unbootable.
  • Not all registry cleaners backup the registry. If an issue arises you may not have a backup to rely on.
  • The usefulness of cleaning the registry is disputable; there is no statistical evidence to support the claim that cleaning the registry will improve system performance. 

Please refer to the following article on why you should not use registry cleaner software. I suggest reading why Microsoft does not support the use of registry cleaners as well.
 
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
 
You have a few programs on your computer that are seen as potentially unwanted.
 
Question 1:
You have a lot of games by WildTangent Games, which came possibly preinstalled. The privacy policy of WildTangent Games shows that you agree to advertisments (by WildTangent and third parties) and brand studies. You also allow WildTangent Games to collect certain personal information.
Do you want to keep these games?
 
Question 2:
You have installed uTorrent Toolbar which is also known as Conduit Community Toolbar. Did you install it on purpose and do you want to keep it?

 

Question 3:

You have Search App by Ask, which often comes bundled with other software and might be installed without your consent. Do you want to keep it?

 

 

STEP 1
[external image: nSymGHK.png]Folder Options

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Control Folders and click OK.
  • Click View. Under Hidden files and folders:
  • Place a checkmark next to Show hidden files, folders and drives.
  • Remove the checkmark next to Hide extensions for known file types.
  • Remove the checkmark next to Hide protected operating system Files (Recommended).
  • Click Apply followed by OK.
     

STEP 2
[external image: nWhGEI3.png]VirusTotal Upload

  • Please go to VirusTotal.com.
  • Click Choose File and locate the following file:
    • C:\Users\L125-User\Downloads\b98be66f7073436ab3a8ecd9ae11ee6a_Pod8_en-GB.exe
  • Click Scan it!.
  • If you receive the following notification: File already analysed click Reanalyse.
  • Once the file has been analyzed, copy the page URL at the top of the window and paste in your next reply.
  • Please do the same for the files below:
    • C:\Users\L125-User\AppData\Local\{vO5T0cEfJ7FeZhpfKQxAPLaadYgK9UftD5
    • C:\Users\L125-User\AppData\Local\Temp\GUR77D8.exe

STEP 3
[external image: xlK5Hdb.png]Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.

    start
    Folder: C:\BOOK
    Folder: C:\d7b624e545e9df63a34dfbb0cf76149c
    end
  • Click File, Save As and type fixlist.txt as the File Name.
  • Important: The file must be saved in the same location as FRST64.exe.

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.

  • Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.

==============================================================================

 

STEP 4
[external image: xpfNZP4A.png.pagespeed.ic.bp5cRl1pJg.jpg]Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • answer to questions 1 - 3
  • 3 Virustotal links
  • Fixlog.txt by FRST

Hola Marie!!! :adios:

 

Q1,Q2,Q3 = No

 

Couldn't find C:\Users\L125-User\Downloads\b98be66f7073436ab3a8ecd9ae11ee6a_Pod8_en-GB.exe

C:\Users\L125-User\AppData\Local\{vO5T0cEfJ7FeZhpfKQxAPLaadYgK9UftD5  = https://www.virustotal.com/en/file/cc99e50c72fb3a01dafd788679ae3a0e0e2fcbc48dd40123b3d715d403c646ff/analysis/1435219569/

Couldn't find C:\Users\L125-User\AppData\Local\Temp\GUR77D8.exe

 

Fix result of Farbar Recovery Scan Tool (x64) Version:24-06-2015
Ran by [removed] at 2015-06-25 16:14:55 Run:1
Running from C:\Users\[removed]\Downloads\Applications
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
start
Folder: C:\BOOK
Folder: C:\d7b624e545e9df63a34dfbb0cf76149c
end
*****************

========================= Folder: C:\BOOK ========================

2012-01-29 10:52 - 2011-11-09 11:01 - 40924560 _____ () C:\BOOK\Generic_User_Guide.pdf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\BOOK\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\BOOK\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\BOOK\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\BOOK\HELP_DECRYPT.URL
2012-01-29 10:52 - 2011-08-31 11:24 - 41396752 _____ () C:\BOOK\Quick_Guide.pdf

====== End of Folder: ======

========================= Folder: C:\d7b624e545e9df63a34dfbb0cf76149c ========================

2011-03-22 18:06 - 2011-03-22 18:06 - 0016118 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\DHtmlHeader.html
2011-03-22 17:34 - 2011-03-22 17:34 - 0003628 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\header.bmp
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\HELP_DECRYPT.URL
2011-04-07 11:12 - 2011-04-07 11:12 - 194340864 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\NDP40-KB2468871.msp
2011-04-07 11:25 - 2011-04-07 11:25 - 0026806 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\ParameterInfo.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0078152 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\Setup.exe
2011-04-07 07:16 - 2011-04-07 07:16 - 0809304 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\SetupEngine.dll
2011-04-07 07:16 - 2011-04-07 07:16 - 0295248 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\SetupUi.dll
2011-03-22 18:06 - 2011-03-22 18:06 - 0030120 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\SetupUi.xsd
2011-03-22 18:07 - 2011-03-22 18:07 - 0196662 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\SplashScreen.bmp
2011-03-22 17:48 - 2011-03-22 17:48 - 0144416 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\sqmapi.dll
2011-03-22 18:07 - 2011-03-22 18:07 - 0013606 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Strings.xml
2011-03-22 18:07 - 2011-03-22 18:07 - 0036180 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\UiInfo.xml
2011-03-22 17:34 - 2011-03-22 17:34 - 0104072 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\watermark.bmp
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1025
2011-03-22 19:44 - 2011-03-22 19:44 - 0123312 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1025\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1025\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1025\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1025\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1025\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0034090 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1025\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0016728 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1025\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1028
2011-03-22 19:44 - 2011-03-22 19:44 - 0128608 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1028\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1028\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1028\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1028\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1028\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0027954 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1028\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0013656 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1028\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1029
2011-03-22 19:44 - 2011-03-22 19:44 - 0101424 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1029\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1029\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1029\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1029\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1029\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0036826 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1029\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0017752 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1029\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1030
2011-03-22 19:44 - 2011-03-22 19:44 - 0109744 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1030\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1030\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1030\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1030\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1030\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0036054 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1030\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0017752 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1030\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1031
2011-03-22 19:44 - 2011-03-22 19:44 - 0092000 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1031\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1031\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1031\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1031\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1031\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0038054 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1031\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0018264 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1031\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1032
2011-03-22 19:44 - 2011-03-22 19:44 - 0102336 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1032\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1032\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1032\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1032\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1032\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0038962 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1032\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0018776 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1032\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1033
2011-03-22 19:44 - 2011-03-22 19:44 - 0138880 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1033\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1033\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1033\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1033\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1033\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0035806 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1033\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0016728 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1033\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1035
2011-03-22 19:44 - 2011-03-22 19:44 - 0111456 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1035\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1035\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1035\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1035\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1035\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0036034 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1035\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0017752 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1035\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1036
2011-03-22 19:44 - 2011-03-22 19:44 - 0133456 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1036\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1036\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1036\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1036\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1036\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0037836 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1036\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0018264 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1036\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1037
2011-03-22 19:44 - 2011-03-22 19:44 - 0125632 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1037\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1037\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1037\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1037\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1037\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0032916 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1037\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0016216 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1037\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1038
2011-03-22 19:44 - 2011-03-22 19:44 - 0111152 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1038\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1038\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1038\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1038\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1038\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0037826 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1038\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0018264 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1038\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1040
2011-03-22 19:44 - 2011-03-22 19:44 - 0125248 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1040\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1040\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1040\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1040\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1040\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0037196 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1040\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0017752 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1040\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1041
2011-03-22 19:44 - 2011-03-22 19:44 - 0112240 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1041\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1041\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1041\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1041\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1041\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0031112 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1041\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0015192 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1041\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1042
2011-03-22 19:44 - 2011-03-22 19:44 - 0149776 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1042\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1042\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1042\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1042\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1042\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0030198 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1042\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0014680 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1042\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1043
2011-03-22 19:44 - 2011-03-22 19:44 - 0035568 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1043\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1043\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1043\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1043\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1043\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0036966 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1043\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0018776 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1043\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1044
2011-03-22 19:44 - 2011-03-22 19:44 - 0036368 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1044\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1044\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1044\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1044\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1044\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0036518 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1044\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0017240 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1044\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1045
2011-03-22 19:44 - 2011-03-22 19:44 - 0126816 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1045\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1045\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1045\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1045\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1045\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0037226 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1045\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0017752 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1045\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1046
2011-03-22 19:44 - 2011-03-22 19:44 - 0109856 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1046\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1046\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1046\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1046\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1046\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0036742 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1046\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0017752 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1046\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1049
2011-03-22 19:44 - 2011-03-22 19:44 - 0049600 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1049\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1049\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1049\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1049\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1049\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0037660 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1049\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0018264 ____N (ΠšΠΎΡ€ΠΏΠΎΡ€Π°Ρ†ΠΈΡ ΠœΠ°ΠΉΠΊΡ€ΠΎΡΠΎΡ„Ρ‚) C:\d7b624e545e9df63a34dfbb0cf76149c\1049\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1053
2011-03-22 19:44 - 2011-03-22 19:44 - 0125360 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1053\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1053\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1053\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1053\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1053\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0036024 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1053\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0017240 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1053\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\1055
2011-03-22 19:44 - 2011-03-22 19:44 - 0113232 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1055\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1055\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1055\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1055\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\1055\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0036278 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\1055\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0017240 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\1055\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\2052
2011-03-22 19:44 - 2011-03-22 19:44 - 0111040 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\2052\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\2052\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\2052\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\2052\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\2052\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0027926 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\2052\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0013656 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\2052\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\2070
2011-03-22 19:44 - 2011-03-22 19:44 - 0125472 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\2070\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\2070\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\2070\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\2070\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\2070\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0037408 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\2070\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0018264 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\2070\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\3076
2011-03-22 19:44 - 2011-03-22 19:44 - 0002336 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\3076\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\3076\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\3076\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\3076\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\3076\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0027954 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\3076\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0013656 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\3076\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\3082
2011-03-22 19:44 - 2011-03-22 19:44 - 0108448 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\3082\eula.rtf
2015-06-23 11:30 - 2015-06-23 11:30 - 0008614 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\3082\HELP_DECRYPT.HTML
2015-06-23 11:30 - 2015-06-23 11:30 - 0045586 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\3082\HELP_DECRYPT.PNG
2015-06-23 11:30 - 2015-06-23 11:30 - 0004250 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\3082\HELP_DECRYPT.TXT
2015-06-23 11:30 - 2015-06-23 11:30 - 0000284 _____ () C:\d7b624e545e9df63a34dfbb0cf76149c\3082\HELP_DECRYPT.URL
2011-04-07 11:25 - 2011-04-07 11:25 - 0037318 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\3082\LocalizedData.xml
2011-04-07 07:16 - 2011-04-07 07:16 - 0018264 ____N (Microsoft Corporation) C:\d7b624e545e9df63a34dfbb0cf76149c\3082\SetupResources.dll
2013-03-06 17:33 - 2013-03-06 17:33 - 0000000 ____D () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics
2011-03-22 18:06 - 2011-03-22 18:06 - 0001150 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\Print.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0000894 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\Rotate1.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0000894 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\Rotate2.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0000894 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\Rotate3.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0000894 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\Rotate4.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0000894 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\Rotate5.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0000894 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\Rotate6.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0000894 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\Rotate7.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0000894 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\Rotate8.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0001150 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\Save.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0036710 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\Setup.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0010134 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\stop.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0001150 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\SysReqMet.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0001150 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\SysReqNotMet.ico
2011-03-22 18:06 - 2011-03-22 18:06 - 0010134 ____N () C:\d7b624e545e9df63a34dfbb0cf76149c\Graphics\warn.ico

====== End of Folder: ======

==== End of Fixlog 16:15:03 ====

STEP 1
[external image: EtQetiM.png] Uninstall Software

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for the following programmes, right-click and click Uninstall.
    • Acer Games
    • Java 7 Update 7
    • Javaβ„’ 6 Update 24
    • Javaβ„’ 6 Update 24 (64-bit)
    • YTD Video Downloader 4.9
    • uTorrentControl_v2 Toolbar
    • Search App by Ask
  • Follow the prompts.
  • Note: If you are offered the choice to install additional software, ensure you decline.
  • Reboot if necessary.

STEP 2
[external image: xlK5Hdb.png]Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document. start
    start
    CreateRestorePoint:
    2015-06-24 13:43 - 2015-01-27 20:00 - 00000000 ____D C:\ProgramData\YTD Video Downloader
    R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [180632 2015-03-26] (APN LLC.)
    URLSearchHook: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
    URLSearchHook: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
    SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {A13956EF-1354-45FF-9F83-14602E789106} URL = http://search.condui…&ctid=CT3220468
    BHO-x32: uTorrentControl_v2 Toolbar -> {7473b6bd-4691-4744-a82b-7854eb3d70b6} -> C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09] (Conduit Ltd.)
    Toolbar: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09] (Conduit Ltd.)
    BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
    Toolbar: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> No Name - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - No File
    Toolbar: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
    FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
    StartMenuInternet: Google Chrome.NWXNVHEFLZDMPKGIU56VFXSQHE - C:\Users\L125-User\AppData\Local\Google\Chrome\Application\chrome.exe
    EmptyTemp:
    end
  • Click File, Save As and type fixlist.txt as the File Name.
  • Important: The file must be saved in the same location as FRST64.exe.

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.


  • Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.

 

STEP 3
[external image: MgeHyNE.png] Batch File

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    @echo off
    cd\
    (
    del /f /s /q "HELP_DECRYPT.*"
    ) 1> "%userprofile%\desktop\delresults.txt" 2>&1
    del %0
  • Click Format. Ensure Wordwrap is unchecked. 
  • Click File, Save As and name the file batchfile.bat. 
  • Select All Files as the Save as type.
  • Save the file to your Desktop. 
  • Locate batchfile.bat [external image: lmRDSkT.png] (W8/7/Vista) on your Desktop. Right-Click the file and click [external image: AVOiBNU.jpg] Run as administrator.
  • When the black Command Prompt disappears, attach delresults.txt (found on your Desktop) in your next post. Please be patient.

 

STEP 4
[external image: GfiJrQ9.png]Malwarebytes Anti-Malware (MBAM)

  • Open Malwarebytes Anti-Malware and click Update Now.
  • Once updated, click the Settings tab, followed by Detection and Protection and tick Scan for rootkits.
  • Click the Scan tab, ensure Threat Scan is selected and click Start Scan.
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
  • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs and double-click the Scan Log.
  • Click Copy to Clipboard and paste the log in your next reply.

================================================================================================

STEP 5
[external image: pfNZP4A.png]Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • Did you successfully uninstall the programs?
  • Fixlog.txt
  • delresults.txt
  • MBAM log

26/06/2015

 

Uninstalled all except:- Acer Games :Jewel Match 3, Jewel Quest Solitaire, Zuma Deluxe –> cannot be removed.  Received error message
Java 7 Update –> cannot be found
Utorrent –> cannot be found

 

Fix result of Farbar Recovery Scan Tool (x64) Version:24-06-2015
Ran by [removed] at 2015-06-26 12:54:39 Run:2
Running from C:\Users\[removed]\Downloads\Applications
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
β€’ start
β€’ CreateRestorePoint:
β€’ 2015-06-24 13:43 - 2015-01-27 20:00 - 00000000 ____D C:\ProgramData\YTD Video Downloader
β€’ R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [180632 2015-03-26] (APN LLC.)
β€’ URLSearchHook: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
β€’ URLSearchHook: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit
β€’ Ltd.)
β€’ SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {A13956EF-1354-45FF-9F83-14602E789106} URL = http://search.condui…&ctid=CT3220468
β€’ BHO-x32: uTorrentControl_v2 Toolbar -> {7473b6bd-4691-4744-a82b-7854eb3d70b6} -> C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09] (Conduit Ltd.)
β€’ Toolbar: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09] (Conduit Ltd.)
β€’ BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
β€’ Toolbar: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> No Name - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - No File
β€’ Toolbar: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
β€’ FF Plugin: @microsoft.com/GENUINE -> disabled No File
β€’ FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common
β€’ Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
β€’ FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
β€’ FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
β€’ FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
β€’ FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
β€’ StartMenuInternet: Google Chrome.NWXNVHEFLZDMPKGIU56VFXSQHE - C:\Users\L125-User\AppData\Local\Google\Chrome\Application\chrome.exe
β€’ EmptyTemp:
end

*****************

β€’ start => Error: No automatic fix found for this entry.
Restore point was successfully created.
β€’ 2015-06-24 13:43 - 2015-01-27 20:00 - 00000000 ____D C:\ProgramData\YTD Video Downloader => Error: No automatic fix found for this entry.
β€’ R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [180632 2015-03-26] (APN LLC.) => Error: No automatic fix found for this entry.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\β€’ {7473b6bd-4691-4744-a82b-7854eb3d70b6} => value not found.
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\β€’ {7473b6bd-4691-4744-a82b-7854eb3d70b6} => value not found.
β€’ Ltd.) => Error: No automatic fix found for this entry.
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\β€’ {A13956EF-1354-45FF-9F83-14602E789106} => key not found.
HKCR\CLSID\β€’ {A13956EF-1354-45FF-9F83-14602E789106} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}" => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => value removed successfully
HKCR\Wow6432Node\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}" => key removed successfully
HKCR\Wow6432Node\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => key not found.
HKU\β€’ S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => value not found.
HKCR\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => key not found.
HKU\β€’ S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => value not found.
HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => key not found.
HKLM\Software\MozillaPlugins\β€’ @microsoft.com/GENUINE => key not found.
HKLM\Software\MozillaPlugins\β€’ adobe.com/AdobeAAMDetect => key not found.
"β€’ FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common" => not found.
β€’ Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File => Error: No automatic fix found for this entry.
HKLM\Software\Wow6432Node\MozillaPlugins\β€’ @java.com/JavaPlugin => key not found.
HKLM\Software\Wow6432Node\MozillaPlugins\β€’ @microsoft.com/GENUINE => key not found.
HKLM\Software\Wow6432Node\MozillaPlugins\β€’ @microsoft.com/WLPG,version=15.4.3502.0922 => key not found.
HKLM\Software\Wow6432Node\MozillaPlugins\β€’ @microsoft.com/WLPG,version=15.4.3538.0513 => key not found.
HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => value restored successfully
β€’ EmptyTemp: => Error: No automatic fix found for this entry.

==== End of Fixlog 12:55:15 ====

 

'β€’' is not recognized as an internal or external command,
operable program or batch file.

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 26-Jun-15
Scan Time: 1:09:06 PM
Logfile: Malwarebytes Scan Log.txt
Administrator: Yes

Version: 2.01.6.1022
Malware Database: v2015.06.26.01
Rootkit Database: v2015.06.22.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: L125-User

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 492832
Time Elapsed: 2 hr, 53 min, 21 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 15
PUP.Optional.UTorrentControl.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{7473b6bd-4691-4744-a82b-7854eb3d70b6}, Quarantined, [70d95b64cfbb93a3514433436a9935cb],
PUP.Optional.UTorrentControl.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{7473B6BD-4691-4744-A82B-7854EB3D70B6}, Quarantined, [70d95b64cfbb93a3514433436a9935cb],
PUP.Optional.ConduitTB.Gen.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}, Quarantined, [95b4a01faddd4aec6a6b642c16efd42c],
PUP.Optional.ConduitTB.Gen.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}, Quarantined, [95b4a01faddd4aec6a6b642c16efd42c],
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\Toolbar.CT3220468, Quarantined, [e76256690e7c6dc9d6e59001d82de917],
PUP.Optional.uTorrentControl.A, HKLM\SOFTWARE\WOW6432NODE\uTorrentControl_v2, Quarantined, [1336dce3afdb3cfafeaaa8904fb559a7],
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Toolbar.CT3220468, Quarantined, [fd4ce2ddcbbf7bbba01b5d3410f5857b],
PUP.Optional.ConduitTB.Gen.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F3023089-BC8F-46DB-A747-E1750707C886}, Quarantined, [c881be015337a393696e8b050ff68b75],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, Quarantined, [ff4a417ec7c320169c25869ed43008f8],
PUP.Optional.APNToolBar.Gen, HKU\S-1-5-18\SOFTWARE\AskPartnerNetwork, Quarantined, [f5549b24e4a694a28ea36492b54eea16],
PUP.Optional.Conduit.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\APPDATALOW\SOFTWARE\ConduitSearchScopes, Quarantined, [1336c8f7f991a0965d56d73711f34db3],
PUP.Optional.Spigot.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{1ACB839D-54D8-4E6E-BE51-203DD8AC7D51}, Quarantined, [d376f1ce761430064d533cbdd62d0cf4],
PUP.Optional.Ask.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6797A420-6EE4-4C54-A46C-05E0AFC65624}, Quarantined, [5fea338c0a80e2542717375b43c2da26],
PUP.Optional.Conduit.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A13956EF-1354-45FF-9F83-14602E789106}, Quarantined, [fa4fe4dbc4c6cc6a16a2e3179d66619f],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\SYSTWEAK\ssd, Quarantined, [cb7ea41b05856ccaf6ca59cbd1339769],

Registry Values: 11
PUP.Optional.UTorrentControl.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{7473B6BD-4691-4744-A82B-7854EB3D70B6}, ½¢stΓ’??FDG¨+xTë=p¢, Quarantined, [70d95b64cfbb93a3514433436a9935cb]
PUP.Optional.UTorrentControl.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{7473B6BD-4691-4744-A82B-7854EB3D70B6}, Quarantined, [70d95b64cfbb93a3514433436a9935cb],
PUP.Optional.UTorrentControl.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{7473B6BD-4691-4744-A82B-7854EB3D70B6}, Quarantined, [70d95b64cfbb93a3514433436a9935cb],
PUP.Optional.UTorrentControl.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{7473B6BD-4691-4744-A82B-7854EB3D70B6}, Quarantined, [490006b9098131052471a1d59c677d83],
PUP.Optional.UTorrentControl.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{7473b6bd-4691-4744-a82b-7854eb3d70b6}, Quarantined, [0f3a06b9cdbd72c465300d6924dfab55],
PUP.Optional.UTorrentControl.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{7473b6bd-4691-4744-a82b-7854eb3d70b6}, Quarantined, [33164877d3b763d3a7ee31453fc42fd1],
PUP.Optional.ConduitTB.Gen.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F3023089-BC8F-46DB-A747-E1750707C886}|AppPath, C:\Users\L125-User\AppData\Local\Conduit\CT3220468, Quarantined, [c881be015337a393696e8b050ff68b75]
PUP.Optional.Spigot.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{1ACB839D-54D8-4E6E-BE51-203DD8AC7D51}|URL, https://malaysia.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=523694&p={searchTerms}, Quarantined, [d376f1ce761430064d533cbdd62d0cf4]
PUP.Optional.Ask.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6797A420-6EE4-4C54-A46C-05E0AFC65624}|SuggestionsURL_JSON, http://ss.websearch.ask.com/query?li=ff&sstype=prefix&q={searchTerms}, Quarantined, [5fea338c0a80e2542717375b43c2da26]
PUP.Optional.Conduit.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A13956EF-1354-45FF-9F83-14602E789106}|URL, http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468, Quarantined, [fa4fe4dbc4c6cc6a16a2e3179d66619f]
PUP.Optional.Conduit.A, HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{A13956EF-1354-45FF-9F83-14602E789106}|FaviconURL, http://search.conduit.com/favicon.ico, Quarantined, [0742e0dfc1c90f27ceead921ff040bf5]

Registry Data: 0
(No malicious items detected)

Folders: 45
PUP.Optional.ConduitTB.Gen.A, C:\Users\L125-User\AppData\Local\Conduit\CT3220468, Quarantined, [57f2d0ef1773d75f2a405a9cb25137c9],
PUP.Optional.ConduitTB.Gen.A, C:\Users\L125-User\AppData\Local\Conduit, Quarantined, [57f2d0ef1773d75f2a405a9cb25137c9],
PUP.Optional.ConduitTB.Gen, C:\Users\L125-User\AppData\Local\CRE, Quarantined, [70d9417e3c4e57dfdd299a5e679c22de],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.ConduitTB.Gen.A, C:\Program Files (x86)\Conduit\Community Alerts, Quarantined, [95b4a01faddd4aec6a6b642c16efd42c],
PUP.Optional.ConduitTB.Gen.A, C:\Program Files (x86)\Conduit, Quarantined, [95b4a01faddd4aec6a6b642c16efd42c],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\AddedAppDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\DefualtImages, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\DetectedAppDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\EngineFirstTimeDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\images, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\Images, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarUntrustedAppsApprovalDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\UninstallDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAddedAppDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppApprovalDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppPendingDialog, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\EmailNotifier, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\ExternalComponent, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Logs, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\MyStuffApps, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\AppsMetaData, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\DynamicDialogs, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenLogin, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenSettings, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarLogin, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarSettings, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\ToolbarTranslation, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\SearchInNewTab, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.Conduit.A, C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0, Quarantined, [b594932cbad068ce5faceceb26dda858],
PUP.Optional.APNToolBar.Gen, C:\ProgramData\APN\APN-Stub, Quarantined, [89c08639bccee155a352a54eb44ff60a],

Files: 232
PUP.Optional.APNToolBar.A, C:\Users\L125-User\AppData\Local\Temp\utt8694.tmp.exe, Quarantined, [d574e8d72565b38355086103f012b050],
PUP.Optional.APNToolBar.A, C:\Users\L125-User\AppData\Local\Temp\utt69A0.tmp.exe, Quarantined, [f059c1fee2a8dd59da83cb996f93cc34],
PUP.Optional.Spigot.SID, C:\Users\L125-User\AppData\Local\Temp\~sp647F.tmp, Quarantined, [1039348b6e1c41f5a0b8c3c3b0564bb5],
PUP.Optional.ConduitTB.Gen.A, C:\Users\L125-User\AppData\Local\Conduit\CT3220468\uTorrentControl_v2AutoUpdateHelper.exe, Quarantined, [57f2d0ef1773d75f2a405a9cb25137c9],
PUP.Optional.ConduitTB.Gen, C:\Users\L125-User\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx, Quarantined, [70d9417e3c4e57dfdd299a5e679c22de],
PUP.Optional.Conduit.A, C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0.localstorage, Quarantined, [df6a734c92f80b2b788be042b84cae52],
PUP.Optional.Conduit.A, C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0.localstorage-journal, Quarantined, [67e2556a4f3b1620be458c96f31119e7],
PUP.Optional.Conduit.A, C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_facebook.conduitapps.com_0.localstorage, Quarantined, [94b5d6e98406ce68f15e949abb49817f],
PUP.Optional.Conduit.A, C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_facebook.conduitapps.com_0.localstorage-journal, Quarantined, [6cdd0db2d5b53501fe51d45a2cd8d729],
PUP.Optional.Conduit.A, C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.conduit.com_0.localstorage, Quarantined, [d277bc037a1000366091b37dcd37f010],
PUP.Optional.Conduit.A, C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.conduit.com_0.localstorage-journal, Quarantined, [81c89827f09a3df93fb2ca663aca8779],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Chinese_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Finnish_rcp_fi.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Chinese_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Danish_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Danish_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Dutch_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Dutch_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\eng_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\eng_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Japanese_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Japanese_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\korean_rcp_ko.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\korean_uninst_ko.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Norwegian_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Norwegian_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\polish_rcp_pl.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\polish_uninst_pl.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\portugese_rcp_pt.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\portugese_uninst_pt.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Portuguese_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Portuguese_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Finnish_uninst_fi.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\French_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\French_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\German_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\German_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\greek_rcp_el.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\greek_uninst_el.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\install_left_image.bmp, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Italian_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Italian_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\russian_rcp_ru.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\russian_uninst_ru.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Spanish_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\spanish_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Swedish_rcp.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\swedish_uninst.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\systweakasp.exe, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\TPS.ico, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\TraditionalCn_rcp_zh-tw.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\traditionalcn_uninst_zh-tw.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\turkish_rcp_tr.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Turkish_uninst_tr.ini, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\unins000.dat, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\unins000.msg, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\xmllite.dll, Quarantined, [e2674679602ad85ee8969edd49bcb44c],
PUP.Optional.ConduitTB.Gen.A, C:\Program Files (x86)\Conduit\Community Alerts\Alert.dll, Quarantined, [95b4a01faddd4aec6a6b642c16efd42c],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\ldrtbuTor.dll, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\tbuTor.dll, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\ThirdPartyComponents.xml, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\toolbar.cfg, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_53_307_CT3072253_images_634514692184142958_20PX_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_options_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_privacy_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_refresh_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_shrink_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_tell_a_friend_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_upgrade_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_SearchEngines_images_search_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_SearchEngines_news_icon_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_searchengines_search_icon_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_searchengines_softonic_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_SearchEngines_tfd_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_SearchEngines_video_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_About_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Browse_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Contact_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Hide_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_LikeIcon_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_MoreFromPublisher_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_More_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Options_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Privacy_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Refresh_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Upgrade_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_eula_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_about_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_clear_history_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_contact_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_help_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_53_307_CT3072253_Images_634520779497696087_png.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_home_page_gif.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\RoundedCornersIE9.css, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\DialogsAPI.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\excanvas.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\generalDialogStyle.css, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\PIE.htc, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\RoundedCorners.css, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\settings.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\version.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\AddedAppDialog\app-added.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\AddedAppDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\DefualtImages\icon.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\DetectedAppDialog\app-2go.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\DetectedAppDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\EngineFirstTimeDialog\EngineFirstTimeDialog.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\EngineFirstTimeDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\EngineFirstTimeDialog\right-click.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\SearchProtector.css, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\SearchProtector.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\images\ok-button.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\images\separation-line.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\images\warning.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\bubble.css, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\bubble.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images\information.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images\x-default-LTR.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images\x-default-RTL.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-LTR.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-RTL.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\SearchProtector.css, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\SearchProtector.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\Images\info.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\Images\ok-on.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\Images\ok.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\SearchProtectorRetakeover.css, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\SearchProtectorRetakeover.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\Icon.jpg, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\Icon.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\info.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\ok-on.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\ok.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.css, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\app-store-icon.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\arrow.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\divider.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\emailNotifier.gif, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\facebook.png, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\radio.GIF, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\Thumbs.db, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\truste_welcome.GIF, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\weather.GIF, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarUntrustedAppsApprovalDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarUntrustedAppsApprovalDialog\ToolbarUntrustedAppsApprovalDialog.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAddedAppDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAddedAppDialog\UT-app-dialog-added.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppApprovalDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppApprovalDialog\UT-app-dialog-needs-your-approval.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppPendingDialog\main.html, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppPendingDialog\UT-app-dialog-is-waiting.js, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=GottenApps&locale=en.xml, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=OtherApps&locale=en.xml, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=SharedApps&locale=en.xml, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=Toolbar&locale=en.xml, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\AppsMetaData\data.bck.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\AppsMetaData\data.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\AppsMetaData\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\AppsMetaData\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\AppsMetaData\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\AppsMetaData\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\DynamicDialogs\data.bck.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\DynamicDialogs\data.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\DynamicDialogs\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\DynamicDialogs\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\DynamicDialogs\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\DynamicDialogs\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenLogin\data.bck.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenLogin\data.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenLogin\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenLogin\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenLogin\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenLogin\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenSettings\data.bck.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenSettings\data.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenSettings\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenSettings\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenSettings\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarHiddenSettings\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarLogin\data.bck.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarLogin\data.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarLogin\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarLogin\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarLogin\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarLogin\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarSettings\data.bck.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarSettings\data.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarSettings\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarSettings\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarSettings\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarSettings\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\ToolbarTranslation\data.bck.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\ToolbarTranslation\data.txt, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\ToolbarTranslation\HELP_DECRYPT.HTML, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\ToolbarTranslation\HELP_DECRYPT.PNG, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\ToolbarTranslation\HELP_DECRYPT.TXT, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.UTorrentControl.A, C:\Users\L125-User\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\ToolbarTranslation\HELP_DECRYPT.URL, Quarantined, [0d3c4f70abdfbd79b37f6b5dfa0925db],
PUP.Optional.Conduit.A, C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0\1, Quarantined, [b594932cbad068ce5faceceb26dda858],

Physical Sectors: 0
(No malicious items detected)

(end)

 

Hello FallenChink.

 

The fix did not work properly, so please try the following.

 

STEP 1
[external image: xlK5Hdb.png]Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Download [external image: txt.gif]  fixlist.txt   3.5KB   3 downloads to your desktop.
  • Important: The file must be saved in the same location as FRST64.exe.

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.


  • Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.

 

STEP 2
[external image: EtQetiM.png] Uninstall Software

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for the following programmes, and if still present, right-click and click Uninstall.
    • Acer Games
    • Agatha Christie - Death on the Nile
    • Bejeweled 2 Deluxe
    • Chuzzle Deluxe
    • Crazy Chicken Kart 2
    • FATE
    • Final Drive: Nitro
    • Insaniquarium Deluxe
    • Jewel Match 3
    • Jewel Quest Solitaire
    • John Deere Drive Green
    • Mystery of Mortlake Mansion
    • Penguins!
    • Plants vs. Zombies - Game of the Year
    • Polar Bowler
    • Slingo Deluxe
    • Torchlight
    • Update Installer for WildTangent Games App
    • Virtual Villagers 4 - The Tree of Life
    • Wedding Dash
    • WildTangent Games App
    • Zuma Deluxe
  • Follow the prompts.
  • Note: If you are offered the choice to install additional software, ensure you decline.
  • Reboot if necessary.

 

STEP 3
[external image: MgeHyNE.png] Batch File

  • Download πŸ“Žbatchfile.txt and save the file to your Desktop. 
  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Drag batchfile.txt from your desktop to the open Notepad window.
  • Click Format. Ensure Wordwrap is unchecked. 
  • Click File, Save As and name the file batchfile.bat. 
  • Select All Files as the Save as type.
  • Save the file to your Desktop.
  • Locate batchfile.bat [external image: lmRDSkT.png] (W8/7/Vista) on your Desktop. Right-Click the file and click [external image: AVOiBNU.jpg] Run as administrator.
  • When the black Command Prompt disappears, attach delresults.txt (found on your Desktop) in your next post. Please be patient.

 

================================================================================================

STEP 4
[external image: pfNZP4A.png]Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • Fixlog.txt
  • Did you successfully uninstall the programs?
  • delresults.txt
  • How is your computer doing?

Fix result of Farbar Recovery Scan Tool (x64) Version:24-06-2015
Ran by [removed] at 2015-06-27 17:39:39 Run:3
Running from C:\Users\[removed]\Downloads\Applications
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
2015-06-24 13:43 - 2015-01-27 20:00 - 00000000 ____D C:\ProgramData\YTD Video Downloader
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [180632 2015-03-26] (APN LLC.)
URLSearchHook: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
URLSearchHook: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {A13956EF-1354-45FF-9F83-14602E789106} URL = http://search.condui…&ctid=CT3220468
BHO-x32: uTorrentControl_v2 Toolbar -> {7473b6bd-4691-4744-a82b-7854eb3d70b6} -> C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09] (Conduit Ltd.)
Toolbar: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09] (Conduit Ltd.)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
Toolbar: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> No Name - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - No File
Toolbar: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
StartMenuInternet: Google Chrome.NWXNVHEFLZDMPKGIU56VFXSQHE - C:\Users\L125-User\AppData\Local\Google\Chrome\Application\chrome.exe
EmptyTemp:
end
*****************

Restore point was successfully created.
"C:\ProgramData\YTD Video Downloader" => File/Folder not found.
APNMCP => Service not found.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => value not found.
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => value not found.
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A13956EF-1354-45FF-9F83-14602E789106} => key not found.
HKCR\CLSID\{A13956EF-1354-45FF-9F83-14602E789106} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => key not found.
HKCR\Wow6432Node\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => value not found.
HKCR\Wow6432Node\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670} => key not found.
HKCR\Wow6432Node\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => key not found.
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => value not found.
HKCR\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => key not found.
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => value removed successfully
HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => key not found.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513" => key removed successfully
HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => value restored successfully
EmptyTemp: => 1.7 GB temporary data Removed.

The system needed a reboot..

==== End of Fixlog 17:46:03 ====

 

No.  Acer Games -  Jewel Match 3, Jewel Quest Solitaire, Zuma Deluxe –> cannot be removed still

 


 

STEP 1
[external image: E3feWj5.png]Junkware Removal Tool (JRT)

  • Please download Junkware Removal Tool and save the file to your Desktop.
  • Create a System Restore Point. For instructions, please refer to the following link (W8) | link (W7) | link (Vista).
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Right-Click JRT.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts and allow the scan to run uninterrupted.
  • Upon completion, a log (JRT.txt) will open on your desktop.
  • Re-enable your anti-virus software.
  • Copy the contents of JRT.txt and paste in your next reply.
     

STEP 2
[external image: BY4dvz9.png]AdwCleaner

  • Please download AdwCleaner and save the file to your Desktop.
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click Scan.
  • Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
  • Follow the prompts and allow your computer to reboot.
  • After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.

– File and folder backups are made for items removed using this tool. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.

 
======================================================

STEP 3
[external image: pfNZP4A.png]Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • JRT.txt
  • AdwCleaner[S0].txt

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.2.1 (06.28.2015:2)
OS: Windows 7 Home Premium x64
Ran by [removed] on 29-Jun-15 at 10:00:03.53
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

~~~ Services

 

~~~ Tasks

 

~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_051EAC4AE0499CBFED74E720976D3C62

 

~~~ Registry Keys

 

~~~ Files

 

~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\apn
Successfully deleted: [Folder] C:\Users\L125-User\appdata\locallow\conduit
Successfully deleted: [Folder] C:\Users\L125-User\AppData\Roaming\getrighttogo
Successfully deleted: [Folder] C:\Users\L125-User\AppData\Roaming\systweak
Successfully deleted: [Folder] C:\Windows\syswow64\ai_recyclebin

 

~~~ Chrome

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk

[C:\Users\L125-User\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\L125-User\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\L125-User\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\L125-User\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
  mkfokfffehpeedafpekjeddnmnjhmcmk
]

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29-Jun-15 at 10:05:46.59
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

# AdwCleaner v4.207 - Logfile created 29/06/2015 at 10:12:28
# Updated 21/06/2015 by Xplode
# Database : 2015-06-23.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : L125-User - L125
# Running from : C:\Users\L125-User\Desktop\AdwCleaner.exe
# Option : Cleaning

***** [ Services ] *****

***** [ Files / Folders ] *****

***** [ Scheduled tasks ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - internet.bernas.com.my:8080
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.bernas.com.my;*.ebernas.com.my;10.10.*;

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17631

-\\ Google Chrome v

[C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

*************************

AdwCleaner[R0].txt - [2465 bytes] - [29/06/2015 10:08:56]
AdwCleaner[S0].txt - [2046 bytes] - [29/06/2015 10:12:28]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2105  bytes] ##########

STEP 1
[external image: GzlsbnV.png] ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

  • Please download ESET Online Scan and save the file to your Desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Double-click esetsmartinstaller_enu.exe to run the programme. 
  • Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
  • Agree to the Terms of Use once more and click Start. Allow components to download.
  • Place a checkmark next to Enable detection of potentially unwanted applications.
  • Click Advanced settings. Place a checkmark next to:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Ensure Remove found threats is unchecked.
  • Click Start.
  • Wait for the scan to finish. Please be patient as this can take some time.
  • Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points. 
  • Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
  • Push the Back button.
  • Place a checkmark next to [external image: xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png] and click [external image: SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png].
  • Re-enable your anti-virus software.
  • Copy the contents of the log and paste in your next reply.

 

STEP 2
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan

  • Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

 

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • ESET Online Scan log
  • FRST.txt, Addition.txt

C:\Program Files (x86)\uTorrent\uTorrent.exe a variant of Win32/Bunndle potentially unsafe application
C:\Users\L125-User\AppData\Local\Adobe\GTB.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\L125-User\AppData\Roaming\uTorrent\updates\3.4.2_37754.exe a variant of Win32/OpenCandy.C potentially unsafe application
C:\Users\L125-User\Downloads\Applications\SoftonicDownloader_for_free-mp3-cutter-and-editor.exe a variant of Win32/SoftonicDownloader.G potentially unwanted application
C:\Users\L125-User\Downloads\Applications\uTorrent.exe a variant of Win32/Bunndle potentially unsafe application

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-06-2015
Ran by [removed] (administrator) on L125 on 29-06-2015 19:38:21
Running from C:\Users\[removed]\Downloads\Applications
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Juniper Networks) C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\n360.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(LINE Corporation) C:\Program Files (x86)\LINE\LINE.exe
(VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2264168 2011-07-14] (Realtek Semiconductor)
HKLM\…\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [976032 2011-09-17] (Atheros Commnucations)
HKLM\…\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [799904 2011-09-17] (Atheros Commnucations)
HKLM\…\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831016 2011-08-03] (Acer Incorporated)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-24] (NTI Corporation)
HKLM-x32\…\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-18] (Renesas Electronics Corporation)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-15] (Dritek System Inc.)
HKLM-x32\…\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-21] (Egis Technology Inc.)
HKLM-x32\…\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\Run: [Google Update] => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-10-01] (Google Inc.)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\Run: [Office Timeline Performance Helper] => C:\Program Files (x86)\Office Timeline\Current\OfficeTimelineStartup.exe [13056 2014-12-19] (OfficeTimeline LLC)
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\MountPoints2: {96387663-87c0-11e3-a661-7ce9d3415466} - E:\AutoRun.exe
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\MountPoints2: {96387672-87c0-11e3-a661-7ce9d3415466} - E:\AutoRun.exe
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\MountPoints2: {abfdd583-0df3-11e3-9964-7ce9d3415466} - E:\StartUse.exe
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [477696 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [241984 2011-11-28] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [203072 2011-11-28] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [1aCopyShExtError] -> {83BEA36E-7680-4598-A4DF-994426F6E78D} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [2aCopyShExtSynced] -> {845B7388-6F85-4F32-9FD5-F02DC7882B89} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [3aCopyShExtSyncing] -> {F6378A7A-F753-449B-AE1B-997A96132E61} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [4aCopyShExtSyncingProg1] -> {3A511828-777D-46F8-82F4-5B530C1B3D9E} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [5aCopyShExtSyncingProg2] -> {C8C88204-5B14-40EC-BA72-8AEBC762047E} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [6aCopyShExtSyncingProg3] -> {ACFF45C3-3EEB-4351-86C2-6696BA264239} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [7aCopyShExtSyncingProg4] -> {29AF997F-488B-46F0-AE78-7146F1B89CC3} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [8aCopyShExtSyncingProg5] -> {03F9AD29-1C78-4B66-8890-B177B5430C53} => C:\Users\L125-User\AppData\Roaming\Copy\overlay\CopyShExt.dll [2014-06-12] (Barracuda Networks, Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\buShell.dll [2014-02-27] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\buShell.dll [2014-02-27] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\buShell.dll [2014-02-27] (Symantec Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> DefaultScope {8ADEA77F-0B0A-43C8-9A51-5E81E645DAB1} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2850245000-3638546127-566686928-1004 -> {8ADEA77F-0B0A-43C8-9A51-5E81E645DAB1} URL = https://www.google.com/search?q={searchTerms}
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Javaβ„’ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\IPS\IPSBHO.DLL [2014-07-23] (Symantec Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-09-17] (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine64\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\coIEPlg.dll [2014-07-31] (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
DPF: HKLM {AA570693-00E2-4907-B6F1-60A1199B030C} https://juniper.net/dana-cached/sc/JuniperSetupClient64.cab
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: HKLM-x32 {1FAF427B-1EE5-43D3-A023-3009142AFCE1} https://www2.pbebank.com/ebroking/wecos/control/csoex_pbb.cab
DPF: HKLM-x32 {B9B2EE1A-E314-4338-A305-BE845EACB113} https://www2.pbebank.com/ebroking/wecos/control/csw25.cab
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.webex.com/client/WBXclient-T28L10NSP11-16469/webex/ieatgpc1.cab
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://175.143.72.146/dana-cached/sc/JuniperSetupClient.cab
Handler: qvp - {4BA78E3D-CA25-4BFF-B8F0-8A3359E4B520} - C:\Program Files\QlikView\QvProtocol\qvp.dll [2013-12-04] (QlikTech AB)
Handler-x32: qvp - {4BA78E3D-CA25-4BFF-B8F0-8A3359E4B520} - C:\Program Files (x86)\QlikView\QvProtocol\qvp.dll [2013-12-04] (QlikTech AB)
Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 208.67.220.220
Tcpip\..\Interfaces\{173178E3-F0E6-4285-9A89-9931024E8A11}: [NameServer] 58.71.136.10 58.71.132.10

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-06-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2015-06-24] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2850245000-3638546127-566686928-1004: @tools.google.com/Google Update;version=3 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-2850245000-3638546127-566686928-1004: @tools.google.com/Google Update;version=9 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\coFFPlgn [2014-10-01]
FF HKLM-x32\…\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\IPSFF [2014-04-17]

Chrome:
=======
CHR Profile: C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-24]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-18]
CHR Extension: (Google Wallet) - C:\Users\L125-User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-04]
CHR HKU\S-1-5-21-2850245000-3638546127-566686928-1004\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\L125-U~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-02]
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [105120 2011-09-17] (Atheros Commnucations) [File not signed]
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [145920 2010-10-25] (HP) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 N360; C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\N360.exe [265040 2014-08-01] (Symantec Corporation)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2012-02-08] (Hewlett-Packard) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation)
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2012-02-08] (Hewlett-Packard) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S1 BHDrvx64; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\BASHDefs\20140912.003\BHDrvx64.sys [1586904 2014-09-13] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1505000.013\ccSetx64.sys [162392 2014-02-25] (Symantec Corporation)
R3 dsNcAdpt; C:\Windows\System32\DRIVERS\dsNcAdX64.sys [29184 2008-05-01] (Juniper Networks)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-09-09] (Symantec Corporation)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
R1 IDSVia64; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\IPSDefs\20140930.001\IDSvia64.sys [633560 2014-09-02] (Symantec Corporation)
S3 jnprva; C:\Windows\System32\DRIVERS\jnprva.sys [26480 2012-08-02] (Juniper Networks, Inc.)
S3 JnprVaMgr; C:\Windows\System32\DRIVERS\jnprvamgr.sys [45352 2012-08-02] (Juniper Networks, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2011-04-04] (Marvell Semiconductor, Inc.)
S3 NAVENG; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\VirusDefs\20140930.018\ENG64.SYS [129752 2014-08-27] (Symantec Corporation)
S3 NAVEX15; C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.2.0.38\Definitions\VirusDefs\20140930.018\EX64.SYS [2137304 2014-08-27] (Symantec Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S1 SRTSP; C:\Windows\System32\Drivers\N360x64\1505000.013\SRTSP64.SYS [875736 2014-02-13] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1505000.013\SRTSPX64.SYS [36952 2013-10-30] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1505000.013\SYMDS64.SYS [493656 2013-10-30] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1505000.013\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-04-16] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1505000.013\Ironx64.SYS [264280 2013-10-30] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1505000.013\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
S3 JNPRNA; system32\DRIVERS\jnprna6.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-29 19:34 - 2015-06-29 19:34 - 00001260 _____ C:\Users\L125-User\Desktop\MyEsetScan.txt
2015-06-29 15:26 - 2015-06-29 15:26 - 02870984 _____ (ESET) C:\Users\L125-User\Desktop\esetsmartinstaller_enu.exe
2015-06-29 10:16 - 2015-06-29 10:16 - 00000000 ___RD C:\Users\L125-User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2015-06-29 10:08 - 2015-06-29 10:12 - 00000000 ____D C:\AdwCleaner
2015-06-29 10:07 - 2015-06-29 10:07 - 02244096 _____ C:\Users\L125-User\Desktop\AdwCleaner.exe
2015-06-29 10:00 - 2015-06-29 10:00 - 00000207 _____ C:\Windows\tweaking.com-regbackup-L125-Windows-7-Home-Premium-(64-bit).dat
2015-06-29 10:00 - 2015-06-29 10:00 - 00000000 ____D C:\RegBackup
2015-06-29 09:37 - 2015-06-29 09:38 - 02950645 _____ (Malwarebytes Corporation) C:\Users\L125-User\Desktop\JRT.exe
2015-06-26 13:06 - 2015-06-29 09:49 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-26 13:05 - 2015-06-26 13:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-26 13:05 - 2015-06-26 13:05 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-26 13:05 - 2015-06-26 13:05 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-06-26 13:05 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-26 13:05 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-26 13:05 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-26 12:47 - 2015-06-24 17:49 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2015-06-26 12:47 - 2015-06-24 17:49 - 00176040 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2015-06-26 12:47 - 2015-06-24 17:49 - 00176040 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2015-06-24 19:07 - 2015-06-24 19:07 - 00003228 _____ C:\Windows\System32\Tasks\avastBCLRestart_chrome.exe
2015-06-24 17:49 - 2015-06-24 17:49 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-06-24 17:49 - 2015-06-24 17:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2015-06-24 17:49 - 2015-06-24 17:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-06-24 17:05 - 2015-06-24 17:05 - 00000000 ____D C:\ProgramData\AVAST Software
2015-06-24 16:05 - 2015-06-29 19:38 - 00000000 ____D C:\FRST
2015-06-23 18:15 - 2015-06-23 18:15 - 00000000 ____D C:\Program Files (x86)\ESET
2015-06-23 17:06 - 2015-06-23 17:06 - 00000000 _____ C:\autoexec.bat
2015-06-23 16:22 - 2015-06-23 19:26 - 00000000 ____D C:\Users\L125-User\AppData\Local\TorrentUnlocker
2015-06-23 16:04 - 2015-06-23 16:04 - 00000000 ____D C:\NPE
2015-06-23 16:02 - 2015-06-23 16:17 - 00000000 ____D C:\Users\L125-User\AppData\Local\NPE
2015-06-23 13:54 - 2015-06-23 13:54 - 00000000 ____D C:\Users\L125-User\AppData\Local\VirtualStore
2015-06-16 12:47 - 2015-06-27 18:06 - 00000000 ____D C:\Users\L125-User\AppData\Local\Evernote
2015-06-04 12:53 - 2015-06-04 12:53 - 00000000 ____D C:\Program Files (x86)\RICOH
2015-06-04 12:51 - 2015-06-04 12:56 - 00000000 ____D C:\ProgramData\RICOH

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-29 19:37 - 2012-10-01 10:46 - 00000000 ____D C:\Users\L125-User\Documents\Outlook Files
2015-06-29 19:30 - 2012-04-03 09:38 - 00000384 _____ C:\Windows\Tasks\Acer Registration - Reminder Recall task.job
2015-06-29 19:26 - 2013-02-21 11:14 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-29 19:11 - 2012-04-09 09:19 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-29 18:44 - 2012-10-01 12:45 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004UA.job
2015-06-29 16:58 - 2012-01-29 10:21 - 01463252 _____ C:\Windows\WindowsUpdate.log
2015-06-29 16:56 - 2012-10-01 12:45 - 00000000 ____D C:\Users\L125-User\AppData\Local\Deployment
2015-06-29 16:54 - 2012-10-04 11:20 - 00000000 ____D C:\Users\L125-User\Desktop\Project Management Framework
2015-06-29 12:44 - 2012-10-01 12:45 - 00000872 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004Core.job
2015-06-29 12:26 - 2013-02-21 11:14 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-29 10:34 - 2015-02-17 18:00 - 00003926 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{D65C931D-1A32-4701-9D5F-4287B325A776}
2015-06-29 10:22 - 2009-07-14 12:45 - 00024656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-29 10:22 - 2009-07-14 12:45 - 00024656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-29 10:16 - 2013-08-07 11:20 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Copy
2015-06-29 10:15 - 2012-01-29 10:54 - 00000000 ____D C:\ProgramData\clear.fi
2015-06-29 10:14 - 2014-08-18 21:50 - 00032505 _____ C:\Windows\setupact.log
2015-06-29 10:14 - 2009-07-14 13:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-29 09:56 - 2012-10-31 17:37 - 00000000 ____D C:\Users\L125-User\Downloads\Applications
2015-06-28 14:01 - 2012-10-31 19:32 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\vlc
2015-06-28 11:15 - 2010-11-21 11:47 - 00922012 _____ C:\Windows\PFRO.log
2015-06-27 18:08 - 2015-05-06 17:16 - 00000000 ____D C:\Users\L125-User\Documents\Income Tax Filing For 2014
2015-06-27 18:08 - 2015-05-05 15:55 - 00000000 ____D C:\Users\L125-User\Desktop\Takaful Ikhlas Berhad
2015-06-27 18:08 - 2015-04-23 10:48 - 00000000 ____D C:\Users\L125-User\Desktop\Project Prospect With Frost
2015-06-27 18:08 - 2014-11-19 10:42 - 00000000 ____D C:\Users\L125-User\Desktop\Praise Sheets - Chords
2015-06-27 18:08 - 2014-10-10 15:41 - 00000000 ____D C:\Users\L125-User\Desktop\Ukulele
2015-06-27 18:08 - 2014-08-01 10:15 - 00000000 ____D C:\Users\L125-User\Desktop\PKF Tanzania SUMATRA
2015-06-27 18:08 - 2014-07-18 12:54 - 00000000 ____D C:\Users\L125-User\Desktop\Project_Icon+_Optimus
2015-06-27 18:08 - 2014-07-03 17:19 - 00000000 ____D C:\Users\L125-User\Desktop\Program Project Governanace & Audit Sharing Session
2015-06-27 18:08 - 2014-06-16 15:56 - 00000000 ____D C:\Users\L125-User\Desktop\PKF Tanzania MOI Project Bid
2015-06-27 18:08 - 2014-05-30 17:57 - 00000000 ____D C:\Users\L125-User\Desktop\Self Improvement
2015-06-27 18:08 - 2014-04-21 13:07 - 00000000 ____D C:\Users\L125-User\Desktop\PKFAE CVs
2015-06-27 18:08 - 2014-04-15 09:43 - 00000000 ____D C:\Users\L125-User\Desktop\Samsung S4 Folder
2015-06-27 18:08 - 2014-04-07 11:47 - 00000000 ____D C:\Users\L125-User\Documents\Symantec
2015-06-27 18:08 - 2013-12-22 20:21 - 00000000 ____D C:\Users\L125-User\Desktop\Pictures Last Quarter 2013
2015-06-27 18:08 - 2013-10-29 10:28 - 00000000 ____D C:\Users\L125-User\Desktop\PPA
2015-06-27 18:08 - 2013-09-23 16:10 - 00000000 ____D C:\Users\L125-User\Desktop\PDPA
2015-06-27 18:08 - 2013-07-30 17:05 - 00000000 ____D C:\Users\L125-User\Desktop\Silverbird
2015-06-27 18:08 - 2013-05-29 14:02 - 00000000 ____D C:\Users\L125-User\Desktop\Vietnam Mountain Marathon
2015-06-27 18:08 - 2013-03-15 09:15 - 00000000 ____D C:\Users\L125-User\Documents\Bluetooth Folder
2015-06-27 18:08 - 2012-10-31 10:40 - 00000000 ____D C:\Users\L125-User\Desktop\TMBT 2013
2015-06-27 18:07 - 2015-04-20 09:54 - 00000000 ____D C:\Users\L125-User\Desktop\KOM Taiwan
2015-06-27 18:07 - 2015-01-13 10:48 - 00000000 ____D C:\Users\L125-User\Desktop\GST Projects
2015-06-27 18:07 - 2014-12-09 09:08 - 00000000 ____D C:\Users\L125-User\Desktop\GIANT Bike Family Cycling 2015
2015-06-27 18:07 - 2014-11-10 13:42 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\DoneEx
2015-06-27 18:07 - 2014-10-17 15:25 - 00000000 ____D C:\Users\L125-User\Desktop\Children's Church
2015-06-27 18:07 - 2014-10-15 11:53 - 00000000 ____D C:\Users\L125-User\Desktop\GST Compliance Plan
2015-06-27 18:07 - 2014-10-01 11:56 - 00000000 ____D C:\Users\L125-User\Desktop\Ironman 70.3 Cebu
2015-06-27 18:07 - 2014-07-19 21:46 - 00000000 ____D C:\Users\L125-User\AppData\Local\Skype
2015-06-27 18:07 - 2013-09-25 16:33 - 00000000 ____D C:\Users\L125-User\Desktop\Chords
2015-06-27 18:07 - 2013-09-05 12:38 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\NesterSoft
2015-06-27 18:07 - 2013-08-22 15:02 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2015-06-27 18:07 - 2013-08-07 11:22 - 00000000 ___RD C:\Users\L125-User\Copy
2015-06-27 18:07 - 2013-04-24 00:25 - 00000000 ____D C:\Users\L125-User\Desktop\Baguio Phillipines
2015-06-27 18:07 - 2013-03-01 17:40 - 00000000 ____D C:\Users\L125-User\AppData\Local\SAS
2015-06-27 18:07 - 2013-01-31 16:31 - 00000000 ____D C:\Users\L125-User\Desktop\NLFCS
2015-06-27 18:07 - 2013-01-04 08:46 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Juniper Networks
2015-06-27 18:07 - 2012-11-14 09:58 - 00000000 ____D C:\Users\L125-User\Claims
2015-06-27 18:07 - 2012-10-31 11:26 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Mozilla
2015-06-27 18:07 - 2012-10-12 12:37 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\uTorrent
2015-06-27 18:07 - 2012-10-01 12:01 - 00000000 ____D C:\Users\L125-User\AppData\Local\TechSmith
2015-06-27 18:07 - 2012-10-01 11:17 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Skype
2015-06-27 18:07 - 2012-09-27 17:06 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Adobe
2015-06-27 18:07 - 2012-09-27 15:32 - 00000000 ____D C:\Users\L125-User\AppData\Local\PowerCinema
2015-06-27 18:06 - 2015-05-26 11:04 - 00000000 ___HD C:\ProgramData\RICOH_DRV
2015-06-27 18:06 - 2015-04-28 22:47 - 00000000 ____D C:\Users\L125-User\AppData\Local\LINE
2015-06-27 18:06 - 2015-01-14 12:39 - 00000000 ____D C:\ProgramData\IsolatedStorage
2015-06-27 18:06 - 2014-04-07 15:36 - 00000000 ____D C:\ProgramData\QlikTech
2015-06-27 18:06 - 2013-07-09 16:30 - 00000000 ____D C:\ProgramData\WebEx
2015-06-27 18:06 - 2013-03-27 11:22 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2015-06-27 18:06 - 2013-03-27 11:22 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2015-06-27 18:06 - 2013-03-20 16:33 - 00000000 ____D C:\ProgramData\Norton
2015-06-27 18:06 - 2013-03-01 17:42 - 00000000 ____D C:\ProgramData\SAS
2015-06-27 18:06 - 2012-11-25 17:54 - 00000000 ____D C:\Users\L125-User\AppData\Local\HP
2015-06-27 18:06 - 2012-09-27 15:33 - 00000000 ____D C:\Users\L125-User\AppData\Local\Google
2015-06-27 18:06 - 2012-04-02 11:45 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2015-06-27 18:06 - 2012-03-29 20:03 - 00000000 ____D C:\ProgramData\OEM_E471269A730D
2015-06-27 18:06 - 2012-01-29 10:45 - 00000000 ____D C:\ProgramData\CyberLink
2015-06-27 18:06 - 2011-10-19 10:22 - 00000000 ____D C:\ProgramData\Acer
2015-06-27 18:06 - 2011-10-19 09:54 - 00000000 ____D C:\ProgramData\Symantec
2015-06-27 18:06 - 2011-10-19 09:54 - 00000000 ____D C:\ProgramData\oem
2015-06-27 18:06 - 2009-07-14 11:20 - 00000000 __RHD C:\Users\Default
2015-06-27 18:05 - 2013-03-06 17:33 - 00000000 ____D C:\d7b624e545e9df63a34dfbb0cf76149c
2015-06-27 18:05 - 2012-04-02 11:40 - 00000000 ____D C:\HP_P2055_default_install_v6.1_ww
2015-06-27 18:05 - 2012-01-29 10:52 - 00000000 ___HD C:\BOOK
2015-06-27 18:05 - 2012-01-29 10:31 - 00000000 ____D C:\Dolby PCEE4
2015-06-27 18:05 - 2011-10-19 10:04 - 00000000 __SHD C:\OEM
2015-06-26 16:10 - 2014-12-30 09:57 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-26 12:49 - 2013-01-01 18:19 - 00000000 ____D C:\Program Files\Java
2015-06-26 12:47 - 2012-09-06 18:39 - 00000000 ____D C:\Program Files (x86)\Java
2015-06-26 12:44 - 2011-10-19 10:06 - 00000000 ____D C:\Program Files (x86)\Acer Games
2015-06-26 12:44 - 2009-07-14 13:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-06-26 12:43 - 2011-10-19 10:06 - 00000000 ____D C:\ProgramData\WildTangent
2015-06-25 12:28 - 2015-01-27 21:57 - 00000000 ____D C:\Users\L125-User\Downloads\Cycle Training
2015-06-25 10:39 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\NDF
2015-06-25 09:46 - 2012-10-17 10:36 - 00000000 ____D C:\Program Files (x86)\WinRAR
2015-06-24 18:12 - 2012-04-09 09:19 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-24 18:12 - 2012-04-09 09:19 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-06-24 18:12 - 2011-10-19 09:47 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-24 17:47 - 2012-10-17 10:36 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-06-24 17:47 - 2012-10-17 10:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-06-24 17:46 - 2011-10-19 10:08 - 00000000 ____D C:\ProgramData\Skype
2015-06-24 17:45 - 2013-10-24 15:31 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-06-24 15:26 - 2014-04-23 10:07 - 00000000 ____D C:\Users\dub_cm_auto
2015-06-23 19:28 - 2011-10-19 09:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Online Backup
2015-06-23 14:27 - 2014-11-13 18:27 - 00000000 __SHD C:\Users\L125-User\AppData\Local\EmieBrowserModeList
2015-06-23 14:27 - 2014-04-21 09:54 - 00000000 __SHD C:\Users\L125-User\AppData\Local\EmieUserList
2015-06-23 14:27 - 2014-04-21 09:54 - 00000000 __SHD C:\Users\L125-User\AppData\Local\EmieSiteList
2015-06-23 14:21 - 2012-07-23 08:56 - 00000000 ____D C:\Users\PKFadmin
2015-06-23 14:20 - 2013-01-29 10:32 - 00000000 ____D C:\Users\L125-User\Documents\TEMP
2015-06-23 14:20 - 2012-10-01 12:46 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-23 14:20 - 2011-10-19 10:24 - 00000000 ____D C:\Program Files\Windows Journal
2015-06-23 14:20 - 2011-10-19 10:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\Dism
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\rescache
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-23 14:20 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\AppCompat
2015-06-23 14:19 - 2012-01-29 10:42 - 00000000 ____D C:\ProgramData\Atheros
2015-06-23 14:19 - 2011-10-19 10:02 - 00000000 ____D C:\ProgramData\BackupManager
2015-06-23 14:19 - 2009-07-14 11:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-06-23 14:18 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\registration
2015-06-23 14:13 - 2012-10-31 13:50 - 00000000 ____D C:\Users\L125-User\Downloads\Movies
2015-06-23 14:09 - 2012-03-29 20:10 - 00000000 __RHD C:\MSOCache
2015-06-23 14:09 - 2011-10-19 10:08 - 00000000 ____D C:\Program Files (x86)\Evernote
2015-06-22 10:44 - 2012-10-05 16:17 - 00000000 ____D C:\Users\L125-User\AppData\Roaming\PrimoPDF
2015-06-12 10:32 - 2015-04-28 22:47 - 00000961 _____ C:\ProgramData\Microsoft\Windows\Start Menu\LINE.lnk
2015-06-12 10:32 - 2015-04-28 22:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LINE
2015-06-09 09:31 - 2013-02-21 11:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-06-04 12:56 - 2015-05-26 11:05 - 00000510 _____ C:\Windows\system32\ricdb.ini
2015-06-01 08:34 - 2009-07-14 13:08 - 00032614 _____ C:\Windows\Tasks\SCHEDLGU.TXT

==================== Files in the root of some directories =======

2014-11-10 13:42 - 2014-11-10 13:42 - 0000082 _____ () C:\Users\L125-User\AppData\Local\{vO5T0cEfJ7FeZhpfKQxAPLaadYgK9UftD5
2012-11-25 17:54 - 2012-11-25 17:54 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-01-29 10:45 - 2012-01-29 10:47 - 0015027 _____ () C:\ProgramData\ArcadeDeluxe5.log
2012-04-02 11:41 - 2012-04-02 11:46 - 0000359 _____ () C:\ProgramData\hpzinstall.log

Some files in TEMP:
====================
C:\Users\L125-User\AppData\Local\Temp\Quarantine.exe
C:\Users\L125-User\AppData\Local\Temp\sqlite3.dll

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-06-23 00:08

==================== End of log ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:24-06-2015
Ran by [removed] at 2015-06-29 19:40:08
Running from C:\Users\[removed]\Downloads\Applications
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-2850245000-3638546127-566686928-500 - Administrator - Disabled)
Guest (S-1-5-21-2850245000-3638546127-566686928-501 - Limited - Disabled)
L125-User (S-1-5-21-2850245000-3638546127-566686928-1004 - Administrator - Enabled) => C:\Users\L125-User
PKFadmin (S-1-5-21-2850245000-3638546127-566686928-1002 - Administrator - Enabled) => C:\Users\PKFadmin
UpdatusUser (S-1-5-21-2850245000-3638546127-566686928-1000 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton 360 Premier Edition (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton 360 Premier Edition (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton 360 Premier Edition (Disabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

192.168.0.8-64bits_RICOH MP 3353 PCL 6_64bits [RICOH MP 3353 PCL 6] (HKLM\…\{AF4633AC-C8D6-4B23-B06F-0837E1844606}) (Version: 1.0.0 - RICOH)
64 Bit HP CIO Components Installer (Version: 13.2.1 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.4 - Hewlett-Packard) Hidden
Acer Backup Manager (HKLM-x32\…\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.99 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1904 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.0.1904 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3008 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Acer Incorporated)
Acer Games (HKLM-x32\…\WildTangent acer Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.04.3504 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\…\Acer Screensaver) (Version: 1.1.0902.2011 - Acer Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 18.0.0.144 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM-x32\…\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.6 - Adobe Systems Incorporated)
Adobe Flash Player 18 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 18.0.0.194 - Adobe Systems Incorporated)
Adobe Reader X (10.1.14) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.14 - Adobe Systems Incorporated)
AP Tuner 3.08 (HKLM-x32\…\AP Tuner 3.08) (Version:  - )
Backup Manager V3 (x32 Version: 3.0.0.99 - NTI Corporation) Hidden
Bluetooth Win7 Suite (64) (HKLM\…\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.96 - Atheros)
Broadcom Card Reader Driver Installer (HKLM\…\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 14.4.9.2 - Broadcom Corporation)
Broadcom NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 15.0.3.2 - Broadcom Corporation)
Cisco WebEx Meetings (HKLM-x32\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
clear.fi (HKLM-x32\…\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 1.0.2228.00 - CyberLink Corp.)
clear.fi (x32 Version: 1.0.1517_36458 - CyberLink Corp.) Hidden
clear.fi (x32 Version: 1.0.2228.00 - CyberLink Corp.) Hidden
clear.fi (x32 Version: 9.0.8228 - CyberLink Corp.) Hidden
clear.fi Client (HKLM-x32\…\{43AAE145-83CF-4C96-9A5E-756CEFCE879F}) (Version: 1.00.3500 - Acer Incorporated)
Copy (HKLM\…\{BF1346D9-2622-4913-86A6-6B63536B1AEB}) (Version: 1.34.508.0 - Barracuda Networks, Inc.)
CustomerResearchQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dolby Advanced Audio v2 (HKLM-x32\…\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.7000.7 - Dolby Laboratories Inc)
eBay Worldwide (HKLM-x32\…\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
Email Templates Collection 1 1.0.5 (HKLM-x32\…\B341F1D4-72BA-4C1B-A8FD-2FCCDDB3888E_is1) (Version: 1.0.5 - DeliveryTech)
Evernote v. 4.5.1 (HKLM-x32\…\{28921580-E4BB-11E0-9FD7-1CC1DEF07CBE}) (Version: 4.5.1.5451 - Evernote Corp.)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsΕ‚ugΔ™ poΕ‚Δ…czeΕ„ zdalnych (HKLM-x32\…\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
Free MP3 Cutter 2.0 (HKLM-x32\…\{847E0734-4457-4B48-BF49-998D1CF2CFA1}_is1) (Version: 2.0 - PolySoft Solutions)
Free PDF Converter (HKLM-x32\…\Free PDF Converter_is1) (Version:  - Baltsoft)
Google Chrome (HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\Google Chrome) (Version: 43.0.2357.130 - Google Inc.)
Google Drive (HKLM-x32\…\{CBC9F5FD-5CFA-4A33-81CD-369EAB77E3A6}) (Version: 1.22.9403.0223 - Google, Inc.)
Google Talk (remove only) (HKLM-x32\…\{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk) (Version:  - )
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
HP Customer Participation Program 10.0 (HKLM\…\HPExtendedCapabilities) (Version: 10.0 - HP)
HP Deskjet 2050 J510 series Basic Device Software (HKLM\…\{73B1AC18-614F-42CD-A798-4BA214586406}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP FWUpdateEDO3 (HKLM-x32\…\{A82D0C46-EBDF-4B27-A731-D06EF2056E81}) (Version: 1.0.0.0 - Hewlett-Packard Company)
HP LaserJet P2050 Series 6.0 (HKLM\…\{6F801026-6AF0-4520-9153-4C9B4CAAB361}) (Version: 6.0 - HP)
HP LaserJet Professional CM1410 Series (HKLM-x32\…\{0EF0EA0D-F945-4958-85CC-60FF1E86D216}) (Version:  - Hewlett-Packard)
HP LaserJet Professional M1130-M1210 MFP Series (HKLM\…\HP LaserJet Professional M1130-M1210 MFP Series) (Version:  - )
HP LaserJet Professional M1530 MFP Series (HKLM-x32\…\{74280B5D-A0AF-46c5-9C85-D9EA078262F1}) (Version:  - Hewlett-Packard)
HP LaserJet Professional P1100-P1560-P1600 Series (HKLM\…\HP LaserJet Professional P1100-P1560-P1600 Series) (Version:  - )
HP LJ CM1410 MFP Series HP Scan (HKLM-x32\…\{21749F4E-02A1-4828-9A1E-BBDF5929C5D0}) (Version: 1.0.302.0 - Hewlett-Packard Co.)
HP LJ M1530 MFP Series HP Scan (HKLM-x32\…\{C05002F1-06F8-4A15-B6F8-E4DC655C28AA}) (Version: 1.0.302.0 - Hewlett-Packard Co.)
HP Update (HKLM-x32\…\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
HPLaserJetHelp_LearnCenter (HKLM-x32\…\{22FE3793-5961-4ADE-AE66-69D9291C22B1}) (Version: 1.03.0000 - Hewlett-Packard)
HPLaserJetHelp_LearnCenter (HKLM-x32\…\{B2AA0F22-E167-4C4A-BAE2-E0025028E61B}) (Version: 1.01.0000 - Hewlett-Packard)
HPLJUT (HKLM-x32\…\{229D6185-BD7E-494B-A73B-C5215BE0690E}) (Version: 1.00.0007 - HP)
hppCM1410LaserJetService (x32 Version: 001.008.00477 - Hewlett-Packard) Hidden
hppFaxDrvCM1410 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppFaxDrvM1530 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppFaxUtilityCM1410 (x32 Version: 000.002.00001 - Hewlett-Packard) Hidden
hppFaxUtilityM1530 (x32 Version: 000.002.00001 - Hewlett-Packard) Hidden
hppFonts (x32 Version: 001.001.00061 - Hewlett-Packard) Hidden
hppLaserJetService (x32 Version: 002.015.00599 - Hewlett-Packard) Hidden
hppM1530LaserJetService (x32 Version: 001.007.00319 - Hewlett-Packard) Hidden
hppQFolderP2050 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
hppSendFaxCM1410 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppSendFaxM1530 (x32 Version: 003.000.00001 - Hewlett-Packard) Hidden
hppTLBXFXCM1410 (x32 Version: 001.012.00948 - Hewlett-Packard) Hidden
hppTLBXFXM1530 (x32 Version: 001.007.00647 - Hewlett-Packard) Hidden
hppusgP2050 (x32 Version: 1.1.0.1 - Hewlett-Packard) Hidden
hpzTLBXFX (x32 Version: 006.015.01163 - Hewlett-Packard) Hidden
I.R.I.S. OCR (HKLM-x32\…\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4 - HP)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2538 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\…\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel)
Java 7 Update 80 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F03217080FF}) (Version: 7.0.800 - Oracle)
Java(TM) SE Development Kit 6 Update 24 (64-bit) (HKLM\…\{64A3A4F4-B792-11D6-A78A-00B0D0160240}) (Version: 1.6.0.240 - Oracle)
JavaFX 2.1.1 (HKLM-x32\…\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jewel Match 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden
Juniper Networks Network Connect 6.0.0 (HKLM-x32\…\Juniper Network Connect 6.0.0) (Version: 6.0.0.13073 - Juniper Networks)
Juniper Networks Setup Client (HKU\S-1-5-21-2850245000-3638546127-566686928-1004\…\JuniperSetupClient) (Version: 1.1.0.0 - Juniper Networks)
Juniper Networks, Inc. Setup Client 64-bit Activex Control (HKLM\…\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks, Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.4 - Acer Inc.)
LINE (HKLM-x32\…\LINE) (Version: 4.0.3.367 - LINE Corporation)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MarketResearch (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden
Maxis Broadband (HKLM-x32\…\Maxis Broadband) (Version: 11.302.06.10.99 - Huawei Technologies Co.,Ltd)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Business 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0401-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0402-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0403-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0404-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0405-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0406-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0407-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0408-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-040B-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-040C-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-040D-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-040E-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0410-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0413-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0414-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0415-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0416-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0418-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0419-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-041A-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-041B-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-041D-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-041E-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-041F-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0424-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0816-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0C0A-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Facebook 32-bit (HKLM-x32\…\{95140000-007C-0409-0000-0000000FF1CE}) (Version: 14.0.6114.5003 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\…\{95140000-007D-0409-0000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Project Standard 2010 (HKLM-x32\…\Office14.PRJSTDR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\…\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.19 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 4.0.14.19 - Egis Technology Inc.) Hidden
Norton 360 (HKLM-x32\…\N360) (Version: 21.5.0.19 - Symantec Corporation)
Norton Online Backup (HKLM-x32\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
NTI Media Maker 9 (HKLM-x32\…\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9002 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.9002 - NTI Corporation) Hidden
NVIDIA Graphics Driver 285.90 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 285.90 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\…\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
Office Timeline (HKLM-x32\…\{DAE585BA-546F-4684-9592-6EA2D0DF071E}) (Version: 3.1.3 - Office Timeline)
PDFBinder (HKLM-x32\…\{8BA03AC2-579F-41CD-A250-740137D86F7A}) (Version: 1.0.0 - Malamute.dk)
PrimoPDF – brought to you by Nitro PDF Software (HKLM-x32\…\PrimoPDF) (Version: 5 - Nitro PDF Software)
QlikView Desktop Documentation and Tutorial English (HKLM-x32\…\{C5E37ACB-E2DA-4704-BE99-8781CC187B28}) (Version: 11.20.12235.0 - QlikTech International AB)
QlikView x64 (HKLM\…\{1ED3B75E-BED2-4863-9763-098DE00590B3}) (Version: 11.20.12235.0 - QlikTech International AB)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6423 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\…\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Scan To (HKLM\…\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-003A-0000-0000-0000000FF1CE}_Office14.PRJSTDR_{58FA40EF-ABA9-4FED-AD3D-318A6073934D}) (Version:  - Microsoft)
Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Skypeβ„’ 7.6 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.103 - Skype Technologies S.A.)
Snagit 11 (HKLM-x32\…\{F8E3C768-71F3-11E1-9DF7-70804824019B}) (Version: 11.0.1 - TechSmith Corporation)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.3.26.2 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.24482 - TeamViewer)
TimeLeft (HKLM-x32\…\TIMELEFT3_is1) (Version: 3.62 - NesterSoft Inc.)
VC8 CRT (Version: 8.0.50727.762 - Juniper Networks) Hidden
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
WebReg (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.02.3505 - Acer Incorporated)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\…\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinRAR 5.21 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\L125-User\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2850245000-3638546127-566686928-1004_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\L125-User\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File

==================== Restore Points =========================

24-06-2015 17:06:42 avast! antivirus system restore point
24-06-2015 17:17:04 Device Driver Package Install: Avast Network Service
25-06-2015 12:37:43 avast! antivirus system restore point
26-06-2015 12:45:34 Removed Java(TM) 6 Update 24
26-06-2015 12:47:44 Removed Java(TM) 6 Update 24 (64-bit)
26-06-2015 12:54:41 Restore Point Created by FRST
27-06-2015 17:39:56 Restore Point Created by FRST
29-06-2015 09:40:09 Restore Point 29062015

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 10:34 - 2013-08-20 14:42 - 00001074 ____N C:\Windows\system32\Drivers\etc\hosts
 192.168.63.247  sasmetadata  
 192.168.63.248  sasdi   
 192.168.63.249  sasebi   
 192.168.63.250  sasmidtier  

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0BC16753-E239-4BAD-83D1-94467D1E9BAC} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-29] (Egis Technology Inc.)
Task: {0D8FAA7E-7208-44E6-B098-C2D81C665B4F} - System32\Tasks\{6121D0CC-8ADE-49A7-BE34-70F07D198D54} => C:\Users\L125-User\Downloads\b98be66f7073436ab3a8ecd9ae11ee6a_Pod8_en-GB.exe
Task: {1AAEAA7C-9286-4833-BF5F-373F29EF4383} - System32\Tasks\clear.fiAgent => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe [2011-10-29] (CyberLink Corp.)
Task: {2695DA62-EEC3-4E08-892E-F2341CF97E38} - System32\Tasks\avastBCLRestart_chrome.exe => Chrome.exe
Task: {3B7E8DA3-21FE-4B77-BC44-72B82CD6833A} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2012-10-03] (Microsoft Corporation)
Task: {412BCB9E-6F4F-44BE-92F2-1C05D308F78B} - System32\Tasks\DMREngine => C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe [2011-10-29] (CyberLink)
Task: {4A6B2FEA-929F-4EAC-A005-6FF6E76858C4} - System32\Tasks\Acer Registration - Reminder Recall task => C:\Program Files (x86)\Acer\Registration\GREG.exe [2011-05-11] (Acer Incorporated)
Task: {4F84BA1A-0677-4D7B-909A-F58947433359} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-15] (Google Inc.)
Task: {58C776A6-76BD-4683-A30C-E40FBE782383} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\SymErr.exe [2014-01-31] (Symantec Corporation)
Task: {5E643F74-3CDD-4CAE-BF6F-9EA7EFE5565C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-15] (Google Inc.)
Task: {7CEC44E8-B2A4-4FB5-B804-A7FF682162FF} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-29] (Egis Technology Inc.)
Task: {7D38031B-DBB6-49D8-B351-F0D4B8719D63} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004UA => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-01] (Google Inc.)
Task: {867EB48A-DD34-4C11-AE76-D9DB6DB62E13} - System32\Tasks\{7D397F49-7B53-4BB8-B80F-205656218F21} => C:\Users\L125-User\Downloads\b98be66f7073436ab3a8ecd9ae11ee6a_Pod8_en-GB.exe
Task: {8C306857-3EB9-4D91-92FB-0CFA9E0E712E} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [2010-04-13] (Hewlett Packard)
Task: {8D4391C2-F842-4366-B7D8-F3E1D62FC62E} - System32\Tasks\{19A2A0B9-C3F4-4691-A68D-4B87A00CCA36} => Iexplore.exe http://ui.skype.com/ui/0/6.0.0.126/en/abandoninstall?page=tsProgressBar
Task: {93B60A8B-FCD6-4CF5-8F8F-59D3E1481638} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated)
Task: {943E23DE-41D8-4D3A-B1A2-22762EE9A62E} - System32\Tasks\clear.fi => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe [2011-10-29] (Acer Incorporated)
Task: {9CA31130-BD48-4DB3-A0BB-979AA0FDB08F} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\WSCStub.exe [2014-08-01] (Symantec Corporation)
Task: {9DE84380-5ADB-4A32-A355-2DE713603F4A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004Core => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-01] (Google Inc.)
Task: {BC47B473-942A-4821-B770-F55DCA02BAF0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-24] (Adobe Systems Incorporated)
Task: {D4F00EF3-FB53-44AB-8BE0-922EF36EF248} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.5.0.19\SymErr.exe [2014-01-31] (Symantec Corporation)
Task: C:\Windows\Tasks\Acer Registration - Reminder Recall task.job => C:\Program Files (x86)\Acer\Registration\GREG.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004Core.job => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2850245000-3638546127-566686928-1004UA.job => C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2012-08-02 10:31 - 2011-04-02 16:05 - 00290304 _____ () C:\Windows\System32\HP1100LM.DLL
2015-01-07 18:45 - 2010-03-31 11:51 - 00407040 _____ () C:\Windows\System32\HPM1210LM.DLL
2012-10-05 15:57 - 2011-03-01 06:37 - 00095008 _____ () C:\Windows\System32\Primomonnt.dll
2012-08-02 10:32 - 2011-04-02 16:04 - 00074240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\HP1100PP.DLL
2015-01-07 18:57 - 2010-03-31 11:51 - 00074240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\HPM1210PP.dll
2013-08-07 11:20 - 2014-06-12 10:44 - 08212480 _____ () C:\Users\L125-User\AppData\Roaming\Copy\overlay\Brt.dll
2009-01-22 08:45 - 2009-01-22 08:45 - 01401856 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll
2012-01-29 10:06 - 2011-09-26 16:36 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-04-24 09:29 - 2011-04-24 09:29 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2011-04-24 09:29 - 2011-04-24 09:29 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2011-04-24 09:29 - 2011-04-24 09:29 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2011-10-29 07:04 - 2011-10-29 07:04 - 00206216 _____ () C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLNetMediaDMA.dll
2015-06-10 16:35 - 2015-06-10 16:35 - 03129368 _____ () C:\Program Files (x86)\LINE\ampkit_windows.dll
2015-06-10 10:57 - 2015-06-10 10:57 - 00123928 _____ () C:\Program Files (x86)\LINE\PlayerHelper.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00143296 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlc.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 02631616 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlccore.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00554944 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdshow_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00041920 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libdirectsound_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00039872 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll
2015-04-13 21:58 - 2015-04-13 21:58 - 00086464 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirect3d_plugin.dll
2015-04-13 21:56 - 2015-04-13 21:56 - 00070675 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirectdraw_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 02158528 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\liblibbluray_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00114112 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_bd_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00245184 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdvdnav_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00089536 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libvdr_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00055744 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libfilesystem_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00072128 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libsmooth_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00593344 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libhttplive_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00771520 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libdash_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00131520 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libzip_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00052672 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\librar_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00023488 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\librecord_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00145856 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libplaylist_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 01566656 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libtaglib_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00332736 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\lua\liblua_plugin.dll
2015-04-13 21:58 - 2015-04-13 21:58 - 01264064 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\misc\libxml_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00069568 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libhotkeys_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00048576 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libwin_hotkeys_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 12001728 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\gui\libqt4_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00127936 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libhttp_plugin.dll
2015-04-13 21:58 - 2015-04-13 21:58 - 00681408 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libupnp_plugin.dll
2015-04-13 21:58 - 2015-04-13 21:58 - 00137152 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libsap_plugin.dll
2015-04-13 21:58 - 2015-04-13 21:58 - 00030144 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libpodcast_plugin.dll
2015-04-13 21:58 - 2015-04-13 21:58 - 00026560 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libmediadirs_plugin.dll
2015-04-13 21:58 - 2015-04-13 21:58 - 00023488 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libwindrive_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00036800 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libes_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00242112 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmp4_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00344512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libtheora_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00046528 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libfolder_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00024512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\librawvideo_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00108992 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libavi_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00157632 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspeex_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00096704 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libasf_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00754624 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libvorbis_plugin.dll
2015-04-13 21:57 - 2015-04-13 21:57 - 00091584 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libflacsys_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00024512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaes3_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00031680 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblpcm_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00089024 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_h264_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00032192 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_flac_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00040384 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_dirac_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00030144 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mlp_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00078272 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpeg4audio_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00044992 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_vc1_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00026048 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libsvcdsub_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00028608 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspudec_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00035264 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpeg4video_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00037312 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpegvideo_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00028096 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcvdsub_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00025536 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_hevc_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 13522368 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libavcodec_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00028096 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libmpeg_audio_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00261056 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libjpeg_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00027072 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00304576 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libpng_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 01291200 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libschroedinger_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00028608 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libdts_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00036800 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaraw_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00052160 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libsubstx3g_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00456128 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libflac_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00035776 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libg711_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 01549248 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblibass_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00356288 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libfaad_plugin.dll
2015-04-13 22:00 - 2015-04-13 22:00 - 00028096 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liba52_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00022464 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_mixer\libfloat_mixer_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00027072 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libscaletempo_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00140224 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libmpgatofixed32_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00176576 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdtstofloat32_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00067520 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\liba52tofloat32_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 01504704 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsamplerate_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00028096 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsimple_channel_mixer_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00022464 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\liba52tospdif_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00022976 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdtstospdif_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00029632 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdolby_surround_decoder_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00022464 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libugly_resampler_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00024512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libtrivial_channel_mixer_plugin.dll
2015-04-13 21:59 - 2015-04-13 21:59 - 00034240 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libaudio_format_plugin.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2850245000-3638546127-566686928-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\L125-User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 208.67.222.222 - 208.67.220.220

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^Users^L125-User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP Deskjet 2050 J510 series.lnk => C:\Windows\pss\Monitor Ink Alerts - HP Deskjet 2050 J510 series.lnk.Startup
MSCONFIG\startupfolder: C:^Users^L125-User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TimeLeft.lnk => C:\Windows\pss\TimeLeft.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: ArcadeMovieService => "C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe"
MSCONFIG\startupreg: Copy => "C:\Users\L125-User\AppData\Roaming\Copy\CopyAgent.exe"
MSCONFIG\startupreg: Dolby Advanced Audio v2 => "C:\Dolby PCEE4\pcee4.exe" -autostart
MSCONFIG\startupreg: Google Update => "C:\Users\L125-User\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
MSCONFIG\startupreg: googletalk => C:\Program Files (x86)\Google\Google Talk\googletalk.exe /autostart
MSCONFIG\startupreg: HP LaserJet Professional CM1410 Series Fax => C:\Program Files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe "HP LaserJet Professional CM1410 Series Fax"
MSCONFIG\startupreg: HP LaserJet Professional M1530 MFP Series Fax => C:\Program Files\HP\HP LaserJet Professional M1530 MFP Series\Fax Driver\hppfaxprintersrv.exe "HP LaserJet Professional M1530 MFP Series Fax"
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: HPUsageTracking => "C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT\"
MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
MSCONFIG\startupreg: ToolboxFX => "C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{7CE85EF5-8332-4262-AB8A-D63339F059F0}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{29D9110F-687E-4E1C-A3CF-9B5260BF25BF}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{D7379D53-D9A0-4889-AF79-5A07231B3042}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{134F1FF7-B217-4B6B-9E8C-A36D61F893A9}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{906ADC2D-FEF9-457F-BFB4-E23B1737C5CF}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe
FirewallRules: [{DEC4F025-5E99-4F03-97AA-7CCD76E3466C}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
FirewallRules: [{91FFC9C7-B47F-41A7-AED2-C2535A33FC15}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\CLML\CLMLSvc.exe
FirewallRules: [{B47CD000-178D-47F8-9B33-709EB90C858E}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{627DFA4F-6595-42FC-8F60-03D104D2CCB9}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{F3E895E6-B372-43AC-A3D1-4E5017934514}] => (Block) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{4F81DFA8-005A-45CD-8376-C43423E9E068}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovie.exe
FirewallRules: [{06CC5013-0BB6-4A17-B288-3A579136DC43}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovieService.exe
FirewallRules: [{B88D13D9-4332-498D-8D7B-EDF0C09E9897}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9AED157C-5393-4F0E-913D-61F39F5696E4}] => (Allow) LPort=2869
FirewallRules: [{3928A412-C9E3-45F2-9605-0E370B981019}] => (Allow) LPort=1900
FirewallRules: [{6E81CDD4-4898-46D6-92D4-3B7FBDA7167F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{DD0BC37B-E1F6-437E-BEEA-2E24CA0F0A34}] => (Allow) C:\Program Files (x86)\Google\Google Talk\googletalk.exe
FirewallRules: [{EA1915FA-315A-40EF-9389-C2EB392E712C}] => (Allow) C:\Program Files (x86)\Google\Google Talk\googletalk.exe
FirewallRules: [{148241BF-2246-4137-8885-89CA89AAF291}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{0C005419-F759-438F-8D0B-B99F2754367B}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{A5983858-55E5-496F-98A2-273EB6BAF97D}] => (Allow) C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe
FirewallRules: [{F36F44C8-CA09-4CCA-AA59-C5F1C2F2C2D9}] => (Allow) C:\Users\L125-User\AppData\Roaming\Copy\CopyAgent.exe
FirewallRules: [{5A208310-1D07-458E-A777-D3D088B981E2}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{084BDD71-A3E7-4AC1-85E7-AC24D0DBF232}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{D0042F2A-8BBD-44C9-8E56-9BDE1AEFA417}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{29E483E6-CF6A-401A-A5A6-A2221CFD8419}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{FB7F288C-5DC7-4F93-9FBD-6A5B442D7A08}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [TCP Query User{1BB47B53-D534-45C3-A142-D57A493908A2}C:\users\l125-user\appdata\roaming\copy\copyagent.exe] => (Allow) C:\users\l125-user\appdata\roaming\copy\copyagent.exe
FirewallRules: [UDP Query User{DE51D2A7-0CB1-49BB-A464-A83A923C8621}C:\users\l125-user\appdata\roaming\copy\copyagent.exe] => (Allow) C:\users\l125-user\appdata\roaming\copy\copyagent.exe
FirewallRules: [{09F4B518-A622-4A4E-BB08-3B3BC0CC720E}] => (Allow) C:\Program Files (x86)\LINE\LINE.exe
FirewallRules: [{F4CE7436-A595-4873-8949-20D359C3D3FD}] => (Allow) C:\Program Files (x86)\LINE\LINE.exe
FirewallRules: [{BDC4D034-A9E1-48EC-A31A-A686F9F7393A}] => (Allow) C:\Users\L125-User\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: BHDrvx64
Description: BHDrvx64
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: BHDrvx64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

==================== Event log errors: =========================

Application errors:
==================
Error: (06/29/2015 07:37:31 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/29/2015 07:12:37 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/29/2015 07:12:34 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/29/2015 07:12:26 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/29/2015 07:12:24 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/29/2015 07:12:21 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/29/2015 07:12:12 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/29/2015 07:12:09 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/29/2015 07:08:55 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (06/29/2015 03:37:45 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

System errors:
=============
Error: (06/29/2015 03:40:04 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The eapihdrv service failed to start due to the following error:
%%1275

Error: (06/29/2015 03:40:04 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\L125-U~1\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (06/29/2015 03:40:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The eapihdrv service failed to start due to the following error:
%%1275

Error: (06/29/2015 03:40:03 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\L125-U~1\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (06/29/2015 03:40:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The eapihdrv service failed to start due to the following error:
%%1275

Error: (06/29/2015 03:40:02 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\L125-U~1\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (06/29/2015 03:39:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The eapihdrv service failed to start due to the following error:
%%1275

Error: (06/29/2015 03:39:16 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\L125-U~1\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (06/29/2015 03:39:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The eapihdrv service failed to start due to the following error:
%%1275

Error: (06/29/2015 03:39:15 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\L125-U~1\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Microsoft Office:
=========================
Error: (06/29/2015 07:37:31 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\L125-User\Downloads\Applications\esetsmartinstaller_enu.exe

Error: (06/29/2015 07:12:37 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\Users\l125-user\downloads\applications\esetsmartinstaller_enu.exe

Error: (06/29/2015 07:12:34 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\Users\l125-user\downloads\applications\esetsmartinstaller_enu.exe

Error: (06/29/2015 07:12:26 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\Users\l125-user\downloads\applications\esetsmartinstaller_enu.exe

Error: (06/29/2015 07:12:24 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\Users\l125-user\downloads\applications\esetsmartinstaller_enu.exe

Error: (06/29/2015 07:12:21 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\Users\l125-user\downloads\applications\esetsmartinstaller_enu.exe

Error: (06/29/2015 07:12:12 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\Users\l125-user\downloads\applications\esetsmartinstaller_enu.exe

Error: (06/29/2015 07:12:09 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\Users\l125-user\downloads\applications\esetsmartinstaller_enu.exe

Error: (06/29/2015 07:08:55 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe

Error: (06/29/2015 03:37:45 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\L125-User\Desktop\esetsmartinstaller_enu.exe

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-2450M CPU @ 2.50GHz
Percentage of memory in use: 61%
Total physical RAM: 1859.19 MB
Available physical RAM: 723.8 MB
Total Pagefile: 3718.38 MB
Available Pagefile: 1167.13 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive a: (Test Volume) (Network) (Total:97.66 GB) (Free:62.66 GB) NTFS
Drive b: () (Network) (Total:232.85 GB) (Free:137.08 GB) NTFS
Drive c: (ACER) (Fixed) (Total:449.06 GB) (Free:329.32 GB) NTFS
Drive l: (New Volume) (Network) (Total:2794.39 GB) (Free:2690.16 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 098D8F98)
Partition 1: (Not Active) - (Size=16.6 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=449.1 GB) - (Type=07 NTFS)

==================== End of log ============================

 

Btw, it's damn irritating that I can uninstall the remaining three stupid games from WildTangent.  What can be done ? Never even knew these bloody games existed pre-installed in the machine.
 

ESET found a few programs that are bundled with potentially unwanted software. Please take care to opt-out of any additional offers if you use bundled software or installers.

 

We will take care of the Wildtangent Games and slowness issues later. Let's concentrate on file recovery for now. As I told you there is currently no way to decrypt the files that were encrypted by CryptoWall 3.0. The following methods have a low success rate, but they are still worth a try.

 

[external image: y3MMIrs.png] Previous Versions

  • Right-click the file/folder and click Properties.
  • Click Previous Versions.
  • This tab will list all copies of the file and the date they were backed up.
  • To restore a particular version of the file, click Copy and select the directory you wish to restore the file to.
  • If you wish to restore the selected file and replace the existing one, click Restore.
  • If you wish to view the contents of the file before restoring, click Open.
     

[external image: MzmiIl9.gif] ShadowExplorer

  • Please download ShadowExplorer and save the file to your Desktop.
  • Right-Click ShadowExplorer-0.9-portable.zip and click Extract All. Select your Desktop and click Extract.
  • Right-Click ShadowExplorer.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • You will see a drop-down menu with the shadow copies of all partitions and disks present.
  • Click C:\ from the drop-down menu.
  • To the right, pick a date prior to the infection from the drop-down menu.
  • To restore a whole folder, right-click on your desired folder and click Export. You will then be prompted as to where you would like to restore the contents of the folder to.
     

[external image: J8xQM97.png] File Recovery Software
File Recovery Software may be able to recover the original file deleted by the file encrypter.

  • [external image: fSA1TL4.png] R-Studio
  • [external image: C08PZmH.png] Photorec
  • [external image: uc6sByo.png] Recuva

I have done 'Previous Version' before contacting whatthetech.  Managed to salvage files that were two weeks old but it is still better than nothing.

Have moved on and not harping on file restoration.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI