This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Really slow laptop, birthday present to wife to make faster [Closed]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My wives laptop, Samsung NP300E5C, runs extremely slow.  I have used CCleaner to clean out cashe and junk files, I dont know what else to do to make sure its not infected.  Have Kaspersky antivirus actively ruuning.

Her birthday is this month and I told her I would see what I can do to make it run faster.

 

So I need your help

below are the text files from ASWMBR and FRST64

 

FRST TEXT FILE:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:09-08-2015
Ran by [removed] (administrator) on CARLASPC (10-08-2015 12:23:22)
Running from C:\Users\[removed]\Desktop\KevinStuff
[removed] Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe
(Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\SAMSUNG\SW Update Service\SWMAgent.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avpui.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.7\waol.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Carbonite, Inc.) C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\splwow64.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191312 2012-08-06] (Realtek Semiconductor)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2862448 2012-08-05] (ELAN Microelectronics Corp.)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [765056 2012-09-29] (Qualcomm Atheros)
HKLM-x32\…\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\…\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-07] (CyberLink)
HKLM-x32\…\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.)
HKLM-x32\…\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1064144 2015-03-06] (Carbonite, Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4204859643-4009438992-3315869148-1001\…\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2014-10-28] (Microsoft Corporation)
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7930136 2015-07-30] (SUPERAntiSpyware)
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\Run: [AOL Fast Start] => C:\Program Files (x86)\AOL Desktop 9.7\AOL.EXE [72312 2012-10-15] (AOL Inc.)
AppInit_DLLs: C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File not found
AppInit_DLLs:  C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll File not found
Startup: C:\Users\carla35758\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-09-29]
ShortcutTarget: Dropbox.lnk -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.facebook.com/
SearchScopes: HKLM -> {CC865B26-C31D-4D23-B17B-96548EEF03F6} URL =
SearchScopes: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002 -> {660B7A65-A56F-4D71-BFCF-0005860DBC96} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=UTF-8&fr;=w3i&type;=W3i_DS,136,0_0,Search,20140518,19890,0,25,0
SearchScopes: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002 -> {7B6EFEF5-D5E7-4702-9B31-BBD18869E868} URL =
BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO-x32: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{66468EF5-92A1-437E-B0FF-288E107324DF}: [DhcpNameServer] [removed] [removed]

FireFox:
========
FF ProfilePath: C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980
FF DefaultSearchEngine.US: Ask Web Search
FF Homepage: https://www.facebook.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-14] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19] ()
FF Plugin-x32: @kaspersky.com/online_banking_08806E753BE44495B44E90AA2513BDC5 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-27] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @viewpoint.com/VMP -> C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4204859643-4009438992-3315869148-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\carla35758\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS)
FF user.js: detected! => C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980\user.js [2015-05-20]
FF SearchPlugin: C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980\searchplugins\ask-web-search.xml [2015-05-17]
FF Extension: MapsGalaxy - C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980\Extensions\[removed] [2015-06-05]
FF Extension: ShopAtHome.com Toolbar - C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980\Extensions\[removed] [2014-10-14]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2013-07-03] <==== ATTENTION

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\carla35758\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (cosstminn) - C:\Users\carla35758\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig [2014-08-19]
CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-08-12] (SUPERAntiSpyware.com)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [220288 2012-09-29] (Qualcomm Atheros Commnucations) [File not signed]
R2 AVP15.0.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe [194000 2015-06-24] (Kaspersky Lab ZAO)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593976 2012-08-26] (Samsung Electronics CO., LTD.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2014-10-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-09-29] (Atheros) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-09-24] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-24] (CyberLink)
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [247016 2015-06-24] (Kaspersky Lab UK Ltd)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-24] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [64368 2015-06-24] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [159960 2015-06-24] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [226480 2015-07-03] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [831664 2015-06-24] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [39792 2015-06-24] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [40304 2015-06-24] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [39792 2015-06-24] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [24944 2015-06-24] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [77680 2015-06-24] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [85360 2015-06-24] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [190648 2015-06-24] (Kaspersky Lab ZAO)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
S3 BTATH_LWFLT; \SystemRoot\system32\DRIVERS\btath_lwflt.sys [X]
U3 aswMBR; \??\C:\Users\CARLA3~1\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\CARLA3~1\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-10 09:11 - 2015-08-10 09:11 - 00036776 _____ C:\Users\carla35758\Downloads\w4sgeen9(2).exe
2015-08-10 08:58 - 2015-08-10 08:59 - 00036776 _____ C:\Users\carla35758\Downloads\w4sgeen9(1).exe
2015-08-10 08:36 - 2015-08-10 12:23 - 00000000 ____D C:\FRST
2015-08-10 08:35 - 2015-08-10 12:23 - 00000000 ____D C:\Users\carla35758\Desktop\KevinStuff
2015-07-28 16:43 - 2015-07-28 16:43 - 00000748 _____ C:\Users\Public\Desktop\Skoolbo Common Core.lnk
2015-07-28 16:39 - 2015-07-28 16:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skoolbo Common Core
2015-07-28 16:39 - 2015-07-28 16:39 - 00000000 ____D C:\Skoolbo Common Core
2015-07-28 15:55 - 2015-07-28 16:24 - 368329728 _____ C:\Users\carla35758\Downloads\SkoolboUS.msi
2015-07-28 15:38 - 2015-07-28 15:45 - 83888551 _____ C:\Users\carla35758\Downloads\SkoolboAussie.msi.part
2015-07-28 09:18 - 2015-07-25 08:34 - 01084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-07-26 22:20 - 2015-07-26 22:29 - 00000000 ____D C:\Users\carla35758\Desktop\CourageousChurchPoolParty
2015-07-26 22:19 - 2015-07-26 22:28 - 00000000 ____D C:\Users\carla35758\Desktop\30yearHighSchoolReunion
2015-07-21 20:32 - 2015-08-01 09:15 - 00000154 _____ C:\WINDOWS\setupact.log
2015-07-21 20:32 - 2015-07-21 20:32 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-07-20 18:38 - 2015-07-14 09:14 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-07-20 18:38 - 2015-07-14 09:14 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-07-20 18:38 - 2015-07-14 09:14 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-07-20 18:38 - 2015-07-14 09:13 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-07-18 02:00 - 2015-08-10 12:17 - 01188105 _____ C:\WINDOWS\WindowsUpdate.log
2015-07-14 18:06 - 2015-06-24 21:31 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-07-14 18:06 - 2015-04-29 18:22 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-14 18:04 - 2015-06-28 00:07 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2015-07-14 18:04 - 2015-06-28 00:07 - 00178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-07-14 18:04 - 2015-06-28 00:06 - 01311960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-07-14 18:04 - 2015-06-28 00:06 - 00332120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2015-07-14 18:04 - 2015-06-27 11:42 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-07-14 18:04 - 2015-06-26 22:13 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2015-07-14 18:04 - 2015-06-26 22:12 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2015-07-14 18:04 - 2015-06-26 22:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2015-07-14 18:04 - 2015-06-26 21:05 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-07-14 18:04 - 2015-06-26 21:00 - 00989184 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-07-14 18:04 - 2015-06-26 20:26 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-07-14 18:03 - 2015-06-26 21:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-07-14 18:03 - 2015-06-26 20:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-07-14 17:55 - 2015-07-09 11:03 - 03701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-07-14 17:54 - 2015-07-09 10:54 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-07-14 17:54 - 2015-07-09 10:34 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-07-14 17:54 - 2015-06-26 21:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-07-14 17:53 - 2015-07-09 14:51 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-07-14 17:53 - 2015-07-09 13:40 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-07-14 17:53 - 2015-07-09 10:50 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-07-14 17:53 - 2015-07-09 10:48 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-07-14 17:53 - 2015-07-09 10:46 - 02229248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-07-14 17:53 - 2015-07-09 10:38 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-07-14 17:53 - 2015-07-09 10:35 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-07-14 17:52 - 2015-07-09 10:53 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-07-14 17:52 - 2015-07-09 10:50 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-14 17:52 - 2015-07-09 10:37 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-07-14 17:52 - 2015-06-26 22:08 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-07-14 17:51 - 2015-06-26 22:08 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-07-14 17:35 - 2015-06-29 10:07 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-07-14 17:35 - 2015-06-26 18:21 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-07-14 17:34 - 2015-06-29 17:43 - 00026288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-14 17:34 - 2015-06-29 10:07 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-07-14 17:34 - 2015-06-29 10:07 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-07-14 17:33 - 2015-06-29 10:07 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-07-14 17:33 - 2015-06-26 18:21 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-07-14 17:30 - 2014-11-04 14:25 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys
2015-07-14 17:30 - 2014-11-04 14:25 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys
2015-07-14 17:30 - 2014-11-04 01:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys
2015-07-14 17:30 - 2014-11-04 01:54 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys
2015-07-14 17:30 - 2014-11-04 01:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2015-07-14 17:30 - 2014-11-04 01:54 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
2015-07-14 17:29 - 2015-05-02 19:39 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-07-14 17:26 - 2015-05-07 10:21 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-14 17:26 - 2015-05-07 10:05 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll
2015-07-14 17:22 - 2015-05-07 12:50 - 22292672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-07-14 17:20 - 2015-05-07 11:53 - 19734960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-07-14 17:16 - 2015-05-07 12:00 - 03109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-14 17:16 - 2015-05-07 11:12 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-07-14 17:13 - 2015-05-11 13:17 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2015-07-14 17:11 - 2015-04-24 21:25 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys
2015-07-14 17:07 - 2015-05-03 09:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-07-14 17:07 - 2015-05-03 09:49 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2015-07-14 17:06 - 2015-05-03 10:09 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-14 17:06 - 2015-05-03 09:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-14 16:49 - 2015-06-15 17:41 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-07-14 16:49 - 2015-06-15 17:24 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-07-14 16:49 - 2015-06-15 16:16 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-07-14 16:49 - 2015-06-15 16:09 - 03607552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-07-14 16:49 - 2015-06-15 15:50 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-07-14 16:49 - 2015-06-15 14:57 - 02460160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-07-14 16:48 - 2015-05-30 16:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-14 16:48 - 2015-05-30 14:36 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-14 16:48 - 2015-05-30 14:35 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-07-14 16:46 - 2015-07-01 17:08 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-07-14 16:46 - 2015-07-01 16:14 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-07-14 16:44 - 2015-07-02 16:21 - 19877376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-07-14 16:44 - 2015-07-02 15:49 - 25193984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-07-14 16:43 - 2015-07-02 15:23 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-07-14 16:43 - 2015-07-02 15:19 - 12855296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-07-14 16:43 - 2015-07-02 14:20 - 14453248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-07-14 16:43 - 2015-07-02 13:59 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-07-14 16:42 - 2015-07-02 15:50 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-07-14 16:42 - 2015-07-02 14:55 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-07-14 16:41 - 2015-06-15 17:39 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-07-14 16:41 - 2015-06-15 17:38 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-07-14 16:41 - 2015-06-15 17:26 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-07-14 16:41 - 2015-06-15 17:24 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-07-14 16:41 - 2015-06-15 17:02 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2015-07-14 16:41 - 2015-06-15 16:58 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2015-07-14 16:41 - 2015-06-15 16:57 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-07-14 16:41 - 2015-06-15 16:56 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-07-14 16:41 - 2015-06-15 16:55 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-07-14 16:41 - 2015-06-15 16:49 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-07-14 16:41 - 2015-06-15 16:41 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-07-14 16:41 - 2015-06-15 16:38 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-07-14 16:41 - 2015-06-15 16:36 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-07-14 16:41 - 2015-06-15 16:17 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-07-14 16:41 - 2015-06-15 16:16 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-07-14 16:41 - 2015-06-15 16:15 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-07-14 16:41 - 2015-06-15 16:13 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-07-14 16:41 - 2015-06-15 16:04 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-07-14 16:41 - 2015-06-15 16:03 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-07-14 16:41 - 2015-06-15 15:52 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-07-14 16:41 - 2015-06-15 15:47 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2015-07-14 16:41 - 2015-06-15 15:44 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2015-07-14 16:41 - 2015-06-15 15:43 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-07-14 16:41 - 2015-06-15 15:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-07-14 16:41 - 2015-06-15 15:41 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-07-14 16:41 - 2015-06-15 15:37 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-07-14 16:41 - 2015-06-15 15:32 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-07-14 16:41 - 2015-06-15 15:31 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-07-14 16:41 - 2015-06-15 15:30 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-07-14 16:41 - 2015-06-15 15:30 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-07-14 16:41 - 2015-06-15 15:17 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-07-14 16:41 - 2015-06-15 15:07 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-07-14 16:41 - 2015-06-15 15:02 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-07-14 16:40 - 2015-06-10 22:49 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-07-14 16:40 - 2015-06-10 11:13 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-07-14 16:40 - 2015-05-11 11:34 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
2015-07-14 16:39 - 2015-06-16 00:36 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2015-07-14 16:39 - 2015-06-16 00:36 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2015-07-14 16:39 - 2015-05-12 08:19 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-14 16:39 - 2015-05-07 11:47 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2015-07-14 16:39 - 2015-05-03 10:07 - 07784448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-14 16:39 - 2015-05-03 09:57 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2015-07-14 16:39 - 2015-05-01 18:33 - 00410739 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-07-14 16:39 - 2015-04-28 08:13 - 00513480 _____ C:\WINDOWS\SysWOW64\locale.nls
2015-07-14 16:39 - 2015-04-28 08:13 - 00513480 _____ C:\WINDOWS\system32\locale.nls
2015-07-14 16:39 - 2015-04-23 10:47 - 03084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-07-14 16:39 - 2015-04-23 10:16 - 02471424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-07-12 23:35 - 2015-07-12 23:37 - 00000000 ____D C:\Users\carla35758\Desktop\mawmaw-papaw-7-12-15

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-10 12:16 - 2013-11-09 13:31 - 00000392 _____ C:\WINDOWS\Tasks\WpsUpdateTask_carla35758.job
2015-08-10 12:00 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-08-10 11:35 - 2015-06-14 16:48 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-08-10 11:05 - 2015-05-19 14:05 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-08-10 09:55 - 2014-11-06 12:33 - 00000538 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 0053b9ac-3feb-4519-8a4d-147b3b99a4bb.job
2015-08-10 09:41 - 2013-05-31 18:36 - 00000966 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002UA.job
2015-08-10 08:55 - 2015-02-14 09:34 - 00003946 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B265354F-4343-4044-9BBC-6323DD2FBBF9}
2015-08-10 08:37 - 2014-09-24 02:15 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-10 01:00 - 2014-11-06 12:33 - 00000538 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task da4e332b-f72c-488e-bc21-ac7a7a869ad2.job
2015-08-09 22:47 - 2012-08-22 23:11 - 00000000 ____D C:\ProgramData\Temp
2015-08-09 18:41 - 2013-05-31 18:36 - 00000944 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002Core.job
2015-08-09 14:13 - 2014-06-16 14:12 - 00000392 _____ C:\WINDOWS\Tasks\PassShow_wd.job
2015-08-07 17:02 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-08-07 16:57 - 2012-12-29 14:35 - 00000000 ____D C:\Users\carla35758\AppData\Local\Packages
2015-08-07 06:19 - 2012-12-29 15:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-07 06:19 - 2012-12-29 15:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-01 09:21 - 2012-12-29 14:44 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4204859643-4009438992-3315869148-1002
2015-08-01 09:15 - 2013-08-22 09:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-01 09:14 - 2013-08-17 09:54 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-30 09:37 - 2012-07-26 02:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-07-25 18:52 - 2015-04-03 22:13 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-07-21 20:32 - 2013-08-22 09:44 - 00481176 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-07-17 17:00 - 2013-11-24 16:13 - 00073728 ___SH C:\Users\carla35758\Desktop\Thumbs.db
2015-07-17 16:38 - 2015-04-03 22:13 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2015-07-17 16:38 - 2014-12-10 22:30 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-07-17 16:38 - 2014-09-24 04:50 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-07-17 16:38 - 2013-08-22 10:36 - 00000000 ___RD C:\WINDOWS\ToastData
2015-07-17 16:38 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\WinStore
2015-07-16 17:37 - 2013-04-11 15:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-07-16 17:19 - 2013-08-16 13:15 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-07-16 10:34 - 2014-10-23 21:30 - 00000000 ____D C:\Users\carla35758
2015-07-16 10:34 - 2013-08-22 08:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-07-16 10:33 - 2014-09-18 06:55 - 00000000 ____D C:\Users\carla35758\AppData\Roaming\v9
2015-07-14 23:35 - 2015-06-14 16:48 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-07-13 16:10 - 2015-06-11 09:03 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-07-13 16:10 - 2015-06-11 09:03 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-12 23:34 - 2015-04-24 22:58 - 00000000 ____D C:\Users\carla35758\Desktop\harrisChapelSpringfest

==================== Files in the root of some directories =======

2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\carla35758\AppData\Roaming\JOQA
2014-09-01 03:18 - 2014-09-01 03:18 - 0002086 _____ () C:\Users\carla35758\AppData\Roaming\NKO
2014-08-21 06:50 - 2014-08-21 06:50 - 0000045 _____ () C:\Users\carla35758\AppData\Roaming\WB.CFG
2013-05-22 16:45 - 2013-02-21 16:59 - 2063240 _____ (Samsung Electronics) C:\ProgramData\MakeMarkerFile.exe
2013-05-22 16:45 - 2013-01-12 23:51 - 0003004 _____ () C:\ProgramData\MakeMarkerFile.xml

Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-11 09:15

==================== End of log ============================

 

ADDITION TEXT FILE:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:09-08-2015
Ran by [removed] (2015-08-10 12:26:47)
Running from C:\Users\[removed]\Desktop\KevinStuff
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-4204859643-4009438992-3315869148-500 - Administrator - Disabled)
carla35758 (S-1-5-21-4204859643-4009438992-3315869148-1002 - Administrator - Enabled) => C:\Users\carla35758
Guest (S-1-5-21-4204859643-4009438992-3315869148-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4204859643-4009438992-3315869148-1006 - Limited - Enabled)
UpdatusUser (S-1-5-21-4204859643-4009438992-3315869148-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

12 Labours of Hercules (HKLM-x32\…\BFG-12 Labours of Hercules) (Version:  - )
12 Labours of Hercules II: The Cretan Bull (HKLM-x32\…\BFG-12 Labours of Hercules II - The Cretan Bull) (Version:  - )
12 Labours of Hercules III: Girl Power (HKLM-x32\…\BFG-12 Labours of Hercules III - Girl Power) (Version:  - )
4 Elements (HKLM-x32\…\BFG-4 Elements) (Version:  - )
4 Elements II (HKLM-x32\…\BFG-4 Elements II) (Version:  - )
Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.03) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
Allshare Play Link (HKLM-x32\…\{91786428-D4AA-476D-8AF9-A63FFAC2901F}) (Version: 1.0.0 - Samsung)
AOL Uninstaller (Choose which Products to Remove) (HKLM-x32\…\AOL Uninstaller) (Version:  - AOL Inc.)
Big Fish: Game Manager (HKLM-x32\…\BFGC) (Version: 3.3.0.2 - )
Carbonite (HKLM-x32\…\Carbonite Backup) (Version: 5.7.4 build 4814 (Mar-06-2015) - Carbonite)
CCleaner (HKLM\…\CCleaner) (Version: 4.03 - Piriform)
Cradle of Egypt (HKLM-x32\…\BFG-Cradle of Egypt) (Version:  - )
CyberLink Power2Go 8 (HKLM-x32\…\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.1912 - CyberLink Corp.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4415.02 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dropbox (HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\Dropbox) (Version: 2.10.30 - Dropbox, Inc.)
Easy File Share (HKLM-x32\…\{A7C37D4B-F37A-42E8-9B6A-B28C18AD4C12}) (Version: 1.3.4 - Samsung Electronics CO.,LTD.)
E-POP (HKLM-x32\…\{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}) (Version: 1.0.1 - Samsung Electronics CO., LTD.)
ETDWare PS/2-X64 11.7.2.1_WHQL (HKLM\…\Elantech) (Version: 11.7.2.1 - ELAN Microelectronic Corp.)
Galería de fotos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Help Desk (HKLM\…\{C85A891D-7AB4-46AE-84F0-B0C3FAC82280}) (Version: 1.0.4 - Samsung Electronics CO., LTD.)
Intel AppUp(SM) center (HKLM-x32\…\Intel AppUp(SM) center 33070) (Version: 3.6.1.33070.11 - Intel)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\…\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36702 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.2.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Internet Explorer Toolbar 4.9 by SweetPacks (HKLM-x32\…\{F4E33CE5-A7AB-4F68-A7E7-F0AA84EF2D9E}) (Version: 4.9.0000 - SweetIM Technologies Ltd.) <==== ATTENTION
Island Tribe 2 (HKLM-x32\…\BFG-Island Tribe 2) (Version:  - )
Island Tribe 3 (HKLM-x32\…\BFG-Island Tribe 3) (Version:  - )
Island Tribe 4 (HKLM-x32\…\BFG-Island Tribe 4) (Version:  - )
Island Tribe 5 (HKLM-x32\…\BFG-Island Tribe 5) (Version:  - )
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
Jewel Legends: Atlantis (HKLM-x32\…\BFG-Jewel Legends - Atlantis) (Version:  - )
Kaspersky Internet Security (HKLM-x32\…\InstallWIX_{02FECEE0-16B2-43DB-BC3B-C844477FC142}) (Version: 15.0.2.361 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 15.0.2.361 - Kaspersky Lab) Hidden
Kingdom Chronicles (HKLM-x32\…\BFG-Kingdom Chronicles) (Version:  - )
Kingsoft Office 2013 (9.1.0.4246) (HKLM-x32\…\Kingsoft Office) (Version: 9.1.0.4246 - Kingsoft Corp.)
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM-x32\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version:  - Microsoft)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUSR) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Mozilla Firefox 39.0.3 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 39.0.3 (x86 en-US)) (Version: 39.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
My Kingdom for the Princess III (HKLM-x32\…\BFG-My Kingdom for the Princess III) (Version:  - )
Northern Tale 3 (HKLM-x32\…\BFG-Northern Tale 3) (Version:  - )
NVIDIA Graphics Driver 305.46 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 305.46 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0613 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0613 - NVIDIA Corporation)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.210 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Quick Starter (HKLM\…\{EC36E2BC-86F7-44C9-84B2-93930F0FBDBF}) (Version: 1.0.0 - Samsung Electronics CO., LTD.)
QuickShare (HKLM-x32\…\{04DB50FA-EA80-4256-85F9-540C582E280D}) (Version: 1.39.60.10936 - Linkury Inc.) <==== ATTENTION
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6699 - Realtek Semiconductor Corp.)
Recovery (HKLM-x32\…\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.0.4.0 - Samsung Electronics CO., LTD.)
Rescue Team 3 (HKLM-x32\…\BFG-Rescue Team 3) (Version:  - )
Rescue Team 4 (HKLM-x32\…\BFG-Rescue Team 4) (Version:  - )
Rolling Idols (HKLM-x32\…\BFG-Rolling Idols) (Version:  - )
S Agent (Version: 1.1.47 - Samsung Electronics CO., LTD.) Hidden
Settings (HKLM-x32\…\{52E5DE60-C96B-42CC-9A37-FE04725940AE}) (Version: 2.0.0 - Samsung Electronics CO., LTD.)
Skoolbo Common Core (HKLM-x32\…\{5A4A6854-80F9-486E-994D-CB7DE54446D5}) (Version: 1.9 - Skoolbo)
Slingo Quest Egypt (HKLM-x32\…\BFG-Slingo Quest Egypt) (Version:  - )
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1032 - SUPERAntiSpyware.com)
Support Center (HKLM\…\{332518C0-0D31-4FFA-9D15-24C9C3D70B08}) (Version: 2.0.7 - Samsung Electronics CO., LTD.)
Support Center FAQ (x32 Version: 1.0.0 - Samsung Electronics CO., LTD.) Hidden
SW Update (HKLM-x32\…\{4F1936F8-82B4-437E-BC47-FAB9136A04B2}) (Version: 2.2.2 - Samsung Electronics CO., LTD.)
Unity Web Player (HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\UnityWebPlayer) (Version: 5.0.3f2 - Unity Technologies ApS)
User Guide (HKLM-x32\…\{039EA659-E421-45C6-8913-BED5D69B5536}) (Version: 1.1.00 - Samsung Electronics CO., LTD.)
Viewpoint Media Player (HKLM-x32\…\ViewpointMediaPlayer) (Version:  - )
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Driver Package - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass  (07/27/2012 20.57.1.735) (HKLM\…\9F04C462DAB591BDCCE784F77E4D4F1736010B92) (Version: 07/27/2012 20.57.1.735 - Samsung Electronics Co. Ltd.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation)
World Mosaics (HKLM-x32\…\BFG-World Mosaics) (Version:  - )
World Mosaics 2 (HKLM-x32\…\BFG-World Mosaics 2) (Version:  - )
World Mosaics 3 - Fairy Tales (HKLM-x32\…\BFG-World Mosaics 3 - Fairy Tales) (Version:  - )
World Mosaics 4 (HKLM-x32\…\BFG-World Mosaics 4) (Version:  - )
World Mosaics 5 (HKLM-x32\…\BFG-World Mosaics 5) (Version:  - )
World Mosaics 6 (HKLM-x32\…\BFG-World Mosaics 6) (Version:  - )
World Mosaics 7 (HKLM-x32\…\BFG-World Mosaics 7) (Version:  - )
Xerox PhotoCafe (HKLM-x32\…\Xerox PhotoCafe) (Version: 1.0.0.6162 - Xerox)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points =========================


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {070C494E-CD08-4707-8FED-069101CD900F} - \UNELEVATE_5431 -> No File <==== ATTENTION
Task: {096E8B75-6174-41DA-8FDF-D304073A5F4C} - System32\Tasks\{C466F0B1-0338-4A75-8344-AD12604D66EE} => pcalua.exe -a C:\Users\carla35758\AppData\Roaming\v9\UninstallManager.exe -c  -ptid=brd
Task: {18752ADC-B660-4C6F-BA15-61D22C5DD0E3} - \SPDriver -> No File <==== ATTENTION
Task: {293AD38A-4B55-4804-8242-E6284210F818} - System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} => C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe [2015-08-10] (Carbonite, Inc.)
Task: {32FCAA4B-128E-4C12-A714-0D7672270DEB} - System32\Tasks\SUPERAntiSpyware Scheduled Task da4e332b-f72c-488e-bc21-ac7a7a869ad2 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2015-06-02] (SUPERAdBlocker.com)
Task: {3B4A0561-468B-4EB0-818E-CEB4F289165A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002Core => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {3B91F900-5B7B-448F-BF2E-336E82217199} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-03-19] (Samsung Electronics CO., LTD.)
Task: {44CC3745-D2A0-4BDE-B7C4-923572E8564A} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-13] (Intel Corporation)
Task: {568F5729-80E6-4D41-9F5F-5CB1B4A7A649} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-14] (Adobe Systems Incorporated)
Task: {5ED2BD9A-B701-4A2C-A3C9-66E09507CA5D} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {63841FB8-2F7E-4FA8-9A61-F50F9A81A1E4} - System32\Tasks\Xerox PhotoCafe Communicator => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe [2011-10-26] ()
Task: {66772626-F494-4B3A-959A-3880CFFD2C07} - System32\Tasks\SMupdate1 => Rundll32.exe C:\Program Files\Common Files\System\SysMenu.dll ,Command701 update1 <==== ATTENTION
Task: {6FCA7E11-801E-47AB-A1C0-08463E6AB6FB} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\Program Files\Common Files\System\SysMenu.dll ,Command701 update2 <==== ATTENTION
Task: {73ECE52C-D3EC-4FD5-AB08-D163F22467BB} - \PassShow_wd -> No File <==== ATTENTION
Task: {77D6C834-DDD7-4093-8ED6-45A83845E4AF} - System32\Tasks\SUPERAntiSpyware Scheduled Task 0053b9ac-3feb-4519-8a4d-147b3b99a4bb => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2015-06-02] (SUPERAdBlocker.com)
Task: {7D1EC64A-AC38-4232-851D-480DA778B967} - \ShopperPro -> No File <==== ATTENTION
Task: {88046CAC-C778-49A7-ACA5-42400985CC23} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2012-08-26] (Samsung Electronics CO., LTD.)
Task: {8A86E6C1-367E-430D-82BC-116B4AB573A0} - \SMW_UpdateTask_Time_3337383035303739342d7837235a576c4a3241345041 -> No File <==== ATTENTION
Task: {90087B42-1C8E-4F64-8849-86829F63DA92} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\Program Files\Common Files\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
Task: {91890BDF-A52C-4594-9172-238D8B3CC894} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe
Task: {92D51808-34E0-4B7D-AE64-27CE43674E94} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002UA => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {A5E5FE4D-0FA4-42CB-9D42-A0761D729516} - System32\Tasks\JOQA => C:\Users\carla35758\AppData\Roaming\JOQA.exe <==== ATTENTION
Task: {A7F7D002-44F7-46AE-917F-5E05883EED9F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-07-03] (Microsoft Corporation)
Task: {AA8101C7-DE8C-46B5-A0B6-24902A843EBA} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2012-08-15] (SEC)
Task: {B323EEB2-9A31-479D-873C-30B54580EF93} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {BE6E1AFB-7517-43EB-88C9-F3499C6EF59D} - \SPBIW_UpdateTask_Time_3337383035303739342d7837235a576c4a3241345041 -> No File <==== ATTENTION
Task: {CCB32432-49F8-4C5C-BE80-19E08C6E842E} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-13] (Intel Corporation)
Task: {CD32C726-BF85-4C1D-A1CC-0E299F9DE022} - System32\Tasks\NKO => C:\Users\carla35758\AppData\Roaming\NKO.exe <==== ATTENTION
Task: {D001A4BC-EFBA-40A3-8EE0-BA67163C32E5} - \PassShow Update -> No File <==== ATTENTION
Task: {D1D33321-9002-4DAD-BB26-A3A2223F13D4} - System32\Tasks\WpsUpdateTask_carla35758 => C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsupdate.exe [2014-08-06] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {F0D408F1-3B65-4649-BA92-EE988E83FD2A} - System32\Tasks\{C6959241-77B1-456F-BA17-1EF70857F486} => pcalua.exe -a "C:\Program Files (x86)\Groovorio\\uninstall.exe"
Task: {F4B6C860-9974-47A1-AE15-70B38327297B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002Core.job => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002UA.job => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\JOQA.job => C:\Users\carla35758\AppData\Roaming\JOQA.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\NKO.job => C:\Users\carla35758\AppData\Roaming\NKO.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\PassShow_wd.job => C:\Program Files (x86)\PassShowS\PassShowl.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 0053b9ac-3feb-4519-8a4d-147b3b99a4bb.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task da4e332b-f72c-488e-bc21-ac7a7a869ad2.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\WINDOWS\Tasks\WpsUpdateTask_carla35758.job => C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsupdate.exe
Task: C:\WINDOWS\Tasks\Xerox PhotoCafe Communicator.job => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe

==================== Loaded Modules (Whitelisted) ==============

2014-01-29 23:02 - 2015-06-01 21:00 - 00102912 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-12-23 16:54 - 2014-12-23 16:54 - 01272616 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\kpcengine.2.3.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00026232 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00110712 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00029816 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00091768 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll
2012-10-15 11:45 - 2012-10-15 11:45 - 00048640 _____ () C:\Program Files (x86)\AOL Desktop 9.7\zlib.dll
2012-08-22 22:54 - 2012-06-25 13:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:0ACF1AF5
AlternateDataStreams: C:\ProgramData\Temp:0AF6266B
AlternateDataStreams: C:\ProgramData\Temp:0D01FEF7
AlternateDataStreams: C:\ProgramData\Temp:134FBDE2
AlternateDataStreams: C:\ProgramData\Temp:1409277B
AlternateDataStreams: C:\ProgramData\Temp:15E76ABF
AlternateDataStreams: C:\ProgramData\Temp:165AF2C6
AlternateDataStreams: C:\ProgramData\Temp:1968990D
AlternateDataStreams: C:\ProgramData\Temp:1A5207FA
AlternateDataStreams: C:\ProgramData\Temp:1A5CC80A
AlternateDataStreams: C:\ProgramData\Temp:2487D1DA
AlternateDataStreams: C:\ProgramData\Temp:2CB9631F
AlternateDataStreams: C:\ProgramData\Temp:2CED8825
AlternateDataStreams: C:\ProgramData\Temp:3AF262FC
AlternateDataStreams: C:\ProgramData\Temp:3DA71AE7
AlternateDataStreams: C:\ProgramData\Temp:45C55624
AlternateDataStreams: C:\ProgramData\Temp:46CBC45C
AlternateDataStreams: C:\ProgramData\Temp:52329B88
AlternateDataStreams: C:\ProgramData\Temp:5C4A588B
AlternateDataStreams: C:\ProgramData\Temp:5D40B34A
AlternateDataStreams: C:\ProgramData\Temp:61C6B926
AlternateDataStreams: C:\ProgramData\Temp:639BB5E9
AlternateDataStreams: C:\ProgramData\Temp:6641B59F
AlternateDataStreams: C:\ProgramData\Temp:67396145
AlternateDataStreams: C:\ProgramData\Temp:6DDFD746
AlternateDataStreams: C:\ProgramData\Temp:77E239B1
AlternateDataStreams: C:\ProgramData\Temp:7E4E56EA
AlternateDataStreams: C:\ProgramData\Temp:84FA02E7
AlternateDataStreams: C:\ProgramData\Temp:85376176
AlternateDataStreams: C:\ProgramData\Temp:87CA9EF8
AlternateDataStreams: C:\ProgramData\Temp:884C7316
AlternateDataStreams: C:\ProgramData\Temp:89A5891E
AlternateDataStreams: C:\ProgramData\Temp:8B3C3098
AlternateDataStreams: C:\ProgramData\Temp:8C12CFCD
AlternateDataStreams: C:\ProgramData\Temp:97CA3B9E
AlternateDataStreams: C:\ProgramData\Temp:99AC3203
AlternateDataStreams: C:\ProgramData\Temp:9D91E651
AlternateDataStreams: C:\ProgramData\Temp:9DA44E6B
AlternateDataStreams: C:\ProgramData\Temp:A31FAD21
AlternateDataStreams: C:\ProgramData\Temp:A3E34FEB
AlternateDataStreams: C:\ProgramData\Temp:A6A65B80
AlternateDataStreams: C:\ProgramData\Temp:AC83EA04
AlternateDataStreams: C:\ProgramData\Temp:B059B88E
AlternateDataStreams: C:\ProgramData\Temp:B9F8237A
AlternateDataStreams: C:\ProgramData\Temp:C36F1B98
AlternateDataStreams: C:\ProgramData\Temp:C69BA1D0
AlternateDataStreams: C:\ProgramData\Temp:CA400C1B
AlternateDataStreams: C:\ProgramData\Temp:CB959782
AlternateDataStreams: C:\ProgramData\Temp:CC386FD2
AlternateDataStreams: C:\ProgramData\Temp:D01ACC06
AlternateDataStreams: C:\ProgramData\Temp:D1713795
AlternateDataStreams: C:\ProgramData\Temp:D3A82449
AlternateDataStreams: C:\ProgramData\Temp:D5CCCBAA
AlternateDataStreams: C:\ProgramData\Temp:D92485C9
AlternateDataStreams: C:\ProgramData\Temp:DCA79AB3
AlternateDataStreams: C:\ProgramData\Temp:E153075C
AlternateDataStreams: C:\ProgramData\Temp:E2295807
AlternateDataStreams: C:\ProgramData\Temp:E5BA9ADD
AlternateDataStreams: C:\ProgramData\Temp:E6537A16
AlternateDataStreams: C:\ProgramData\Temp:ED6B6C83
AlternateDataStreams: C:\ProgramData\Temp:F72306CC
AlternateDataStreams: C:\ProgramData\Temp:F7581CE6
AlternateDataStreams: C:\ProgramData\Temp:F7B0AE93
AlternateDataStreams: C:\ProgramData\Temp:FBFC061F
AlternateDataStreams: C:\ProgramData\Temp:FC2E567F

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4204859643-4009438992-3315869148-1001\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\Samsung\Samsung_wallpaper.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: HostManager => C:\Program Files (x86)\Common Files\AOL\1356813129\ee\AOLSoftware.exe
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
HKLM\…\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\…\StartupApproved\Run: => "BtTray"
HKLM\…\StartupApproved\Run: => "RtHDVCpl"
HKLM\…\StartupApproved\Run: => "ETDCtrl"
HKLM\…\StartupApproved\Run32: => "Adobe ARM"
HKLM\…\StartupApproved\Run32: => "Adobe Reader Speed Launcher"
HKLM\…\StartupApproved\Run32: => "BCSSync"
HKLM\…\StartupApproved\Run32: => "RemoteControl10"
HKLM\…\StartupApproved\Run32: => "Intel AppUp(SM) center"
HKLM\…\StartupApproved\Run32: => "HostManager"
HKLM\…\StartupApproved\Run32: => "CLMLServer_For_P2G8"
HKLM\…\StartupApproved\Run32: => "CLVirtualDrive"
HKLM\…\StartupApproved\Run32: => "ETDCtrl"
HKLM\…\StartupApproved\Run32: => "fst_us_210"
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\StartupApproved\Run: => "Browser Infrastructure Helper"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{1C944511-C752-4493-B77A-157665E1C1C1}C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{CA550F8B-40AF-4A39-8732-ED60339734C9}C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{2BE51C0E-67C3-4554-A77B-A9910CF7D8A0}] => (Allow) C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{C912F999-8FBD-48DF-856C-9194469551B3}] => (Allow) C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{C584D5A0-0A75-4296-BC02-98DD649035FA}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe
FirewallRules: [{3A46C0B8-F73A-41E3-A45C-78A1A66D8AC4}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe
FirewallRules: [{2177685B-3B42-4E3D-B6EB-BE9BFDF89B32}] => (Allow) C:\Program Files (x86)\Common Files\AOL\System Information\sinf.exe
FirewallRules: [{ED1A5EF6-F1D7-45AE-98FC-BB52831D4916}] => (Allow) C:\Program Files (x86)\Common Files\AOL\System Information\sinf.exe
FirewallRules: [{57969852-6B9E-422E-B61D-96414191AF03}] => (Allow) C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe
FirewallRules: [{30915F87-7117-4739-853A-DEC7D0E7E21E}] => (Allow) C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe
FirewallRules: [{35D40D3A-430E-4702-89F4-6F7AA94E5226}] => (Allow) C:\Program Files (x86)\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{D771DC33-51D7-4A46-98D8-9A519549C5B2}] => (Allow) C:\Program Files (x86)\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{7835419C-0960-418B-8D70-2B0D44F8E1F3}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\waol.exe
FirewallRules: [{5813D3CA-B66F-44BF-AC77-A1264147028C}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\waol.exe
FirewallRules: [{EFEF65F3-EDFE-41D7-BD10-07C7B515BE57}] => (Allow) C:\Program Files (x86)\Common Files\AOL\1356813129\ee\aolsoftware.exe
FirewallRules: [{E3B67B5A-981A-4050-9981-40EAF70EFB0B}] => (Allow) C:\Program Files (x86)\Common Files\AOL\1356813129\ee\aolsoftware.exe
FirewallRules: [{76CBB1F3-68DA-4EEE-9312-BCD48395B1A1}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
FirewallRules: [{8B6C5983-23C6-4F9A-B86B-315874CCF55E}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
FirewallRules: [{CAF94027-B948-40D0-B2DA-9911DF3B57C6}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLDial.exe
FirewallRules: [{067EF64B-B79E-4E0A-85E3-913525CF530C}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLDial.exe
FirewallRules: [{C9BE8101-F480-4219-8D33-18631D9DAC83}] => (Allow) LPort=1900
FirewallRules: [{AC9085FB-C7DC-475E-83BD-2C4D8042D93C}] => (Allow) LPort=2869
FirewallRules: [{8B2EFA22-CB98-4A8F-868A-7808AC8BC521}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{B8732F72-F9D9-4596-8C03-073046CB1499}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{E13E5F9C-E7EB-48DB-BD40-A0E0C9890A29}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{ADC11769-653B-4AC1-8A43-CF7D98CE434B}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{4DABB302-3070-48FA-A239-8D9FB5755AA8}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{8DF1A401-119B-4D12-B731-D8C994E05C25}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{AEA6A349-7612-4EAC-961D-669F5BE63A11}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{439983AA-B322-47B5-A703-CE00E2685F24}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{6A8764C7-0C43-4328-B3D5-1CE6F11F2F67}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/10/2015 10:53:33 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wwahost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: c58

Start Time: 01d0d383f980ccda

Termination Time: 4294967295

Application Path: C:\WINDOWS\syswow64\wwahost.exe

Report Id: ee86ca77-3f77-11e5-bf7c-50b7c33d372b

Faulting package full name: Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c

Faulting package-relative application ID: App

Error: (08/10/2015 10:12:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: EasySettingsCmdServer.exe, version: 0.0.0.0, time stamp: 0x50376629
Faulting module name: MSVCR100.dll, version: 10.0.30319.460, time stamp: 0x4db13576
Exception code: 0x40000015
Fault offset: 0x0008cb95
Faulting process id: 0xe7c
Faulting application start time: 0xEasySettingsCmdServer.exe0
Faulting application path: EasySettingsCmdServer.exe1
Faulting module path: EasySettingsCmdServer.exe2
Report Id: EasySettingsCmdServer.exe3
Faulting package full name: EasySettingsCmdServer.exe4
Faulting package-relative application ID: EasySettingsCmdServer.exe5

Error: (08/09/2015 10:10:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wwahost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1c54

Start Time: 01d0d319544d5020

Termination Time: 4294967295

Application Path: C:\WINDOWS\syswow64\wwahost.exe

Report Id: 49c8b5c4-3f0d-11e5-bf7c-50b7c33d372b

Faulting package full name: Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c

Faulting package-relative application ID: App

Error: (08/07/2015 09:40:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GWXUX.exe, version: 6.3.9600.17924, time stamp: 0x55959290
Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f4336
Exception code: 0xc0000005
Fault offset: 0x000000000003d85e
Faulting process id: 0x118
Faulting application start time: 0xGWXUX.exe0
Faulting application path: GWXUX.exe1
Faulting module path: GWXUX.exe2
Report Id: GWXUX.exe3
Faulting package full name: GWXUX.exe4
Faulting package-relative application ID: GWXUX.exe5

Error: (08/05/2015 09:39:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f42c2
Exception code: 0xc0000005
Fault offset: 0x00040fb2
Faulting process id: 0x1674
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5

Error: (08/05/2015 09:39:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Exception code: 0xc0000005
Fault offset: 0x001f804f
Faulting process id: 0xa50
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5

Error: (08/05/2015 09:39:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f42c2
Exception code: 0xc0000005
Fault offset: 0x00040fb2
Faulting process id: 0x4f8
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5

Error: (08/05/2015 09:39:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Exception code: 0xc0000005
Fault offset: 0x001f804f
Faulting process id: 0xaf0
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5

Error: (08/05/2015 09:39:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f42c2
Exception code: 0xc0000005
Fault offset: 0x00040fb2
Faulting process id: 0x1550
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5

Error: (08/05/2015 09:38:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Exception code: 0xc0000005
Fault offset: 0x001f804f
Faulting process id: 0x100
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5


System errors:
=============
Error: (08/10/2015 10:23:17 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (08/10/2015 10:02:00 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (08/10/2015 09:25:33 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (08/07/2015 06:33:07 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (08/07/2015 01:48:30 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (08/07/2015 01:10:19 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (08/07/2015 12:19:59 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (08/07/2015 11:01:51 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (08/06/2015 02:53:43 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (08/05/2015 10:21:04 AM) (Source: DCOM) (EventID: 10010) (User: CarlasPC)
Description: App.AppX54xz6wnkhmw763c2y8tb018n7d71dtx7.wwa


Microsoft Office:
=========================
Error: (08/10/2015 10:53:33 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.3.9600.17415c5801d0d383f980ccda4294967295C:\WINDOWS\syswow64\wwahost.exeee86ca77-3f77-11e5-bf7c-50b7c33d372bMicrosoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5cApp

Error: (08/10/2015 10:12:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: EasySettingsCmdServer.exe0.0.0.050376629MSVCR100.dll10.0.30319.4604db13576400000150008cb95e7c01d0cc649553f140C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exeC:\Program Files (x86)\Samsung\Settings\CmdServer\MSVCR100.dll3de8a61b-3f72-11e5-bf7c-50b7c33d372b

Error: (08/09/2015 10:10:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.3.9600.174151c5401d0d319544d50204294967295C:\WINDOWS\syswow64\wwahost.exe49c8b5c4-3f0d-11e5-bf7c-50b7c33d372bMicrosoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5cApp

Error: (08/07/2015 09:40:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: GWXUX.exe6.3.9600.1792455959290ntdll.dll6.3.9600.17736550f4336c0000005000000000003d85e11801d0d1839907d523C:\WINDOWS\System32\GWX\GWXUX.exeC:\WINDOWS\SYSTEM32\ntdll.dlle50049d4-3d76-11e5-bf7c-50b7c33d372b

Error: (08/05/2015 09:39:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91ntdll.dll6.3.9600.17736550f42c2c000000500040fb2167401d0cff11bc4b598C:\Program Files (x86)\bfgclient\bfgclient.exeC:\WINDOWS\SYSTEM32\ntdll.dll5de4d618-3be4-11e5-bf7c-50b7c33d372b

Error: (08/05/2015 09:39:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91bfgclient.exe3.3.0.253179a91c0000005001f804fa5001d0cff11b08b16fC:\Program Files (x86)\bfgclient\bfgclient.exeC:\Program Files (x86)\bfgclient\bfgclient.exe5acf4758-3be4-11e5-bf7c-50b7c33d372b

Error: (08/05/2015 09:39:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91ntdll.dll6.3.9600.17736550f42c2c000000500040fb24f801d0cff11565a917C:\Program Files (x86)\bfgclient\bfgclient.exeC:\WINDOWS\SYSTEM32\ntdll.dll56e43df4-3be4-11e5-bf7c-50b7c33d372b

Error: (08/05/2015 09:39:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91bfgclient.exe3.3.0.253179a91c0000005001f804faf001d0cff11525b30aC:\Program Files (x86)\bfgclient\bfgclient.exeC:\Program Files (x86)\bfgclient\bfgclient.exe534f0929-3be4-11e5-bf7c-50b7c33d372b

Error: (08/05/2015 09:39:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91ntdll.dll6.3.9600.17736550f42c2c000000500040fb2155001d0cff1082a4bfeC:\Program Files (x86)\bfgclient\bfgclient.exeC:\WINDOWS\SYSTEM32\ntdll.dll4eab7873-3be4-11e5-bf7c-50b7c33d372b

Error: (08/05/2015 09:38:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91bfgclient.exe3.3.0.253179a91c0000005001f804f10001d0cff0f98a4e9eC:\Program Files (x86)\bfgclient\bfgclient.exeC:\Program Files (x86)\bfgclient\bfgclient.exe470e6374-3be4-11e5-bf7c-50b7c33d372b


CodeIntegrity:
===================================
  Date: 2015-05-12 12:25:00.726
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-12 12:24:59.904
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-12 12:24:56.339
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-09 19:00:37.871
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-09 19:00:36.384
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-09 19:00:34.739
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-04-22 22:00:33.049
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-04-22 22:00:32.407
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-04-22 22:00:31.725
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-04-22 22:00:29.965
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Pentium(R) CPU B950 @ 2.10GHz
Percentage of memory in use: 51%
Total physical RAM: 3795.54 MB
Available physical RAM: 1843.25 MB
Total Virtual: 4499.54 MB
Available Virtual: 2198.5 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:439.91 GB) (Free:310.34 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: B0418F27)

Partition: GPT.

==================== End of log ============================

 

 

ASWMRB Text file:

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-08-10 09:13:27
—————————–
09:13:27.305    OS Version: Windows x64 6.2.9200
09:13:27.305    Number of processors: 2 586 0x2A07
09:13:27.305    ComputerName: CARLASPC  UserName:
09:13:28.493    Initialize success
09:13:28.681    VM: initialized successfully
09:13:28.681    VM: Intel CPU virtualization not supported
09:15:17.909    AVAST engine defs: 15080901
09:26:17.327    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000030
09:26:17.327    Disk 0 Vendor: ST500LM012_HN-M500MBB 2AR10002 Size: 476940MB BusType: 11
09:26:17.897    Disk 0 MBR read successfully
09:26:17.897    Disk 0 MBR scan
09:26:17.913    Disk 0 unknown MBR code
09:26:17.944    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
09:26:18.773    Disk 0 scanning C:\WINDOWS\system32\drivers
09:27:05.119    Service scanning
09:27:50.496    Modules scanning
09:27:50.512    Disk 0 trace - called modules:
09:27:50.543    ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll iaStorA.sys
09:27:50.559    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe000679b9370]
09:27:50.574    3 CLASSPNP.SYS[fffff800fb911170] -> nt!IofCallDriver -> \Device\00000030[0xffffe00067205060]
09:27:52.324    AVAST engine scan C:\WINDOWS
09:28:24.685    AVAST engine scan C:\WINDOWS\system32
09:33:52.452    AVAST engine scan C:\WINDOWS\system32\drivers
09:34:33.923    AVAST engine scan C:\Users\carla35758
10:43:52.672    AVAST engine scan C:\ProgramData
11:10:32.752    Disk 0 statistics 4287184/0/0 @ 0.46 MB/s
11:10:32.799    Scan finished successfully
12:22:51.572    Disk 0 MBR has been saved successfully to "C:\Users\carla35758\Desktop\KevinStuff\MBR.dat"
12:22:51.603    The log file has been saved successfully to "C:\Users\carla35758\Desktop\KevinStuff\aswMBR.txt"

 

 

 

Hello kevin_czarnota! :adios:

Welcome to What the Tech.
I am Marie Curie and will gladly help you with any malware-related problems.

I am currently in training at WhatTheTech and every post of mine will be approved by a teacher. I will return as soon as possible with instructions. Please familiarize yourself with the following ground rules in the meanwhile.

  • Read my instructions thoroughly, carry out each step in the given order.
  • Do not make any changes to your system, or run any tools other than those I provided. Do not delete, fix, uninstall, or install anything unless I tell you to.
  • If you are unsure about anything or if you encounter any problems, please stop and inform me about it.
  • Stick with me until I tell you that your computer is clean. Absence of symptoms does not mean that your computer is free of malware.
  • Back up important files before we start.

Hello kevin_czarnota.

 

The computer has several programs installed that are potentially unwanted. These programs are not malicious, but they might be on your wife's computer without consent and likely cause the slowness of the system. Some of them are known to deliver advertisments, bundle additional software, have questionable privacy policies or may show other unwanted behaviour.

Please tell me for each of the following programs if you want to keep them:

  • Big Fish: Game Manager
  • MapsGalaxy
  • E-POP
  • ShopAtHome

Please tell me also if you or your wife set a custom user.js or firefox.cfg to configure Firefox (click on the link for more information).

 

Please create a system restore point:

  • Type "System Protection" at the Start screen and select Settings in the Search panel.
  • Click on Create a restore point.
  • Enter a description for the restore point
  • Press the Create button.
  • Tell me if that was successful.

I am sure she wants to keep BigFish Games, the other programs she does not use.

Do I uninstall them?

I do all of her computer service and set up, I do not ever remember using a user.js, since I don't know what that is.

What can I do about that?

Don't worry about the user.js for now. We will take care of it.

 

STEP 1
Uninstall Software

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for the following programmes, right-click and click Uninstall.
    • ​​​​E-POP
    • QuickShare
    • Internet Explorer Toolbar 4.9 by SweetPacks
  • Follow the prompts.
  • Note: If you are offered the choice to install additional software, ensure you decline.
  • Reboot if necessary.

 

STEP 2
Remove Firefox Extensions

  • Click the menu button and choose Add-ons. The Add-ons Manager tab will open.

  • In the Add-ons Manager tab, select the Extensions or Appearance panel.
  • Click the Remove button for the following Add-ons:
    • ShopAtHome.com Toolbar
    • MapsGalaxy
  • Click Restart now if it pops up. Your tabs will be saved and restored after the restart.

 

STEP 3
Junkware Removal Tool (JRT)

  • Please download Junkware Removal Tool and save the file to your Desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Right-Click JRT.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts and allow the scan to run uninterrupted. 
  • Upon completion, a log (JRT.txt) will open on your desktop.
  • Re-enable your anti-virus software.
  • Copy the contents of JRT.txt and paste in your next reply.
     

STEP 4
AdwCleaner

  • Please download AdwCleaner and save the file to your Desktop.
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts. 
  • Click Scan. 
  • Upon completion, click Report. A log (AdwCleaner[S0].txt) will open. Briefly check the log for anything you know to be legitimate. 
  • Ensure anything you know to be legitimate does not have a checkmark, and click Clean. 
  • Follow the prompts and allow your computer to reboot. 
  • After rebooting, a log (AdwCleaner[C0].txt) will open. Copy the contents of the log and paste in your next reply.

– File and folder backups are made for items removed using this tool. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[S0].txt.

 
======================================================

STEP 5
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • Did you successfully remove the software in steps 1-2?
  • JRT.txt
  • AdwCleaner[C0].txt

Step 1:

E-pop uninstalled

Quickshare and Internet Explorere toolbar 4.9 gave the following error:

The feature you are trying to use is on a network resource that is unavailable

Click ok to try again or enter an alternate path to a folder containing rthe installation package 'linkuryinstaller.msi' in the box below.
use source:
c:\users\carla35758\appdata\temp\smartbar'

 

Step 2: Complete

 

Step 3:

Text file below:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.6 (08.10.2015:1)
OS: Windows 8.1 x64
Ran by [removed] on Wed 08/19/2015 at 12:22:16.34
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks

Successfully deleted: [Task] C:\WINDOWS\system32\tasks\LaunchSignup
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\SMupdate1
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\SMupdate1
Successfully deleted: [Task] C:\WINDOWS\Tasks\PassShow_wd.job



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update ToggleMark



~~~ Files

Successfully deleted: [File] C:\Users\carla35758\Appdata\LocalLow\skwconfig.bin
Successfully deleted: [File] C:\Users\carla35758\desktop\sync folder.lnk



~~~ Folders

Failed to delete: [Folder] C:\Users\carla35758\Appdata\Local\chromatic browser
Failed to delete: [Folder] C:\Users\carla35758\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\Program Files (x86)\bench
Successfully deleted: [Folder] C:\Program Files (x86)\globalupdate
Successfully deleted: [Folder] C:\Program Files (x86)\predm
Successfully deleted: [Folder] C:\Program Files (x86)\shopperpro
Successfully deleted: [Folder] C:\Program Files (x86)\viewpoint
Successfully deleted: [Folder] C:\ProgramData\pc optimizer pro
Successfully deleted: [Folder] C:\ProgramData\viewpoint
Successfully deleted: [Folder] C:\Users\carla35758\Appdata\Local\globalupdate
Successfully deleted: [Folder] C:\Users\carla35758\Appdata\Local\torch
Successfully deleted: [Folder] C:\Users\carla35758\AppData\Roaming\alawarentertainment
Successfully deleted: [Folder] C:\Users\carla35758\AppData\Roaming\compete
Successfully deleted: [Folder] C:\Users\carla35758\AppData\Roaming\v9
Successfully deleted: [Folder] C:\WINDOWS\SysWOW64\arfc
Successfully deleted: [Folder] C:\WINDOWS\SysWOW64\wnlt
Successfully deleted: [Folder] C:\ProgramData\e34a6412197deb1e



~~~ FireFox

Successfully deleted: [File] C:\Users\carla35758\AppData\Roaming\mozilla\firefox\profiles\c634hs6v.default-1411133199980\user.js
Successfully deleted: [File] C:\Users\carla35758\AppData\Roaming\mozilla\firefox\profiles\c634hs6v.default-1411133199980\searchplugins\ask-web-search.xml
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@viewpoint.com/vmp
Successfully deleted the following from C:\Users\carla35758\AppData\Roaming\mozilla\firefox\profiles\c634hs6v.default-1411133199980\prefs.js

user_pref(browser.search.defaultenginename.US, Ask Web Search);
user_pref(extensions.toolbar.mindspark._39Members_.firstKnownVersion, 7.18.7.7656);
user_pref(extensions.toolbar.mindspark._39Members_.isCompliantUninstallImplementation, true);
user_pref(extensions.toolbar.mindspark._39Members_.lastKnownVersion, 7.18.7.19726);
user_pref(extensions.toolbar.mindspark._39Members_.toolbarCollapsed, false);
user_pref(plugin.state.npviewpoint, 0);
Emptied folder: C:\Users\carla35758\AppData\Roaming\mozilla\firefox\profiles\c634hs6v.default-1411133199980\minidumps [26 files]



~~~ Chrome


[C:\Users\carla35758\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\carla35758\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\carla35758\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\carla35758\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 08/19/2015 at 12:33:25.52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

Step 4: see next reply

Step 4 was a little difficult

Didn't understand about checking for legitimate things.  So left everything checked.

Here is a txt file but dont know if it is the right one, it says C1 not C0.

# AdwCleaner v5.002 - Logfile created 19/08/2015 at 12:47:50
# Updated 18/08/2015 by Xplode
# Database : 2015-08-18.2 [Server]
# Operating system : Windows 8.1  (x64)
# Username : carla35758 - CARLASPC
# Running from : C:\Users\carla35758\Desktop\KevinStuff\AdwCleaner.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\BitSaver
[-] Folder Deleted : C:\ProgramData\BitSaver
[-] Folder Deleted : C:\Users\carla35758\AppData\Local\Chromatic Browser
[-] Folder Deleted : C:\Users\carla35758\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kfgaibfbmkjgmimhbbaikfnpkkjkpoan
[-] Folder Deleted : C:\Users\carla35758\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mnanplinmmnjhobaliikmelmmjpoogkb
[-] Folder Deleted : C:\Users\carla35758\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig
[-] Folder Deleted : C:\Users\carla35758\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kfgaibfbmkjgmimhbbaikfnpkkjkpoan
[-] Folder Deleted : C:\Users\carla35758\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mnanplinmmnjhobaliikmelmmjpoogkb
[-] Folder Deleted : C:\Users\carla35758\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig
[-] Folder Deleted : C:\Users\carla35758\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig
[-] Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Chromatic Browser
[-] Folder Deleted : C:\Users\UpdatusUser\AppData\Local\torch
[-] Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig
[-] Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig
[-] Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig

***** [ Files ] *****

[-] File Deleted : C:\END
[-] File Deleted : C:\WINDOWS\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : ShopperPro
[-] Task Deleted : ShopperProJSUpd
[-] Task Deleted : SPDriver
[-] Task Deleted : Microsoft\Windows\Multimedia\SMupdate3
[-] Task Deleted : Microsoft\Windows\Maintenance\SMupdate2

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
[-] Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
[-] Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SysMenuExt
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\SysMenu.DLL
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
[-] Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-649636217
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{8E56A02B-46FE-4490-B169-F16E5231533B}]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{EEE6C35B-6118-11DC-9C72-001320C79847}]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{EEE6C35C-6118-11DC-9C72-001320C79847}]
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5ff362fa-2eb6-40d1-9b5c-4cc75877a0ef}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5ff362fa-2eb6-40d1-9b5c-4cc75877a0ef}
[-] Key Deleted : HKU\.DEFAULT\Software\IM
[-] Key Deleted : HKU\.DEFAULT\Software\ImInstaller
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\Object Browser
[-] Key Deleted : HKCU\Software\Compete
[-] Key Deleted : HKCU\Software\GlobalUpdate
[-] Key Deleted : HKCU\Software\IM
[-] Key Deleted : HKCU\Software\ImInstaller
[-] Key Deleted : HKCU\Software\YTDownloader
[-] Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
[!] Key Not Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Compete
[-] Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
[-] Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
[-] Key Deleted : HKLM\SOFTWARE\CompeteInc
[-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate
[-] Key Deleted : HKLM\SOFTWARE\MetaStream
[-] Key Deleted : HKLM\SOFTWARE\pc optimizer pro
[-] Key Deleted : HKLM\SOFTWARE\Viewpoint
[-] Key Deleted : HKLM\SOFTWARE\YTDownloader
[-] Key Deleted : HKLM\SOFTWARE\{F2E9660B-98AF-42c0-8258-9CDDF07BF95D}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F4E33CE5-A7AB-4F68-A7E7-F0AA84EF2D9E}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3FC46A0-9B62-0EF3-B475-743B3A2762B1}
[!] Key Not Deleted : [x64] HKCU\Software\Compete
[!] Key Not Deleted : [x64] HKCU\Software\GlobalUpdate
[!] Key Not Deleted : [x64] HKCU\Software\IM
[!] Key Not Deleted : [x64] HKCU\Software\ImInstaller
[!] Key Not Deleted : [x64] HKCU\Software\YTDownloader
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\5EC33E4FBA7A86F47A7E0FAA48FED2E9
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\5EC33E4FBA7A86F47A7E0FAA48FED2E9
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E7F552EF334C802D75A55F0F6344722
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5EC33E4FBA7A86F47A7E0FAA48FED2E9
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs]

***** [ Web browsers ] *****


*************************

:: Proxy settings cleared
:: Winsock settings cleared
:: Chrome policies deleted

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [12822 bytes] ##########
 

 

minor note, I spend a minute looking for a "report" button then selected "logfile"

STEP 1
[external image: GfiJrQ9.png] Malwarebytes Anti-Malware (MBAM)

  • Please download the Malwarebytes Anti-Malware setup file to your Desktop.
  • Open mbam-setup.x.x.xxxx.exe (x represents the version) and follow the prompts to install the programme. 
  • Open Malwarebytes Anti-Malware and click Update Now.
  • Once updated, click the Settings tab, followed by Detection and Protection and tick Scan for rootkits.
  • Click the Scan tab, ensure Threat Scan is selected and click Start Scan.
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards. 
  • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs and double-click the Scan Log.
  • Click Copy to Clipboard and paste the log in your next reply.

here is the exported scan log

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 8/21/2015
Scan Time: 9:58 AM
Logfile:
Administrator: Yes

Version: 2.1.8.1057
Malware Database: v2015.08.21.05
Rootkit Database: v2015.08.16.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: carla35758

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 452890
Time Elapsed: 1 hr, 24 min, 59 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 147
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}, Quarantined, [ccadad5e7615e056481de5b0f80a7090],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE619FF1-032D-49BB-BC46-3BEC347D6787}, Quarantined, [0871eb20f49744f2578ba502758ffb05],
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\SPVC32LDR, Quarantined, [344542c9c2c9fa3cd7fddecc45bf0000],
PUP.Optional.SearchModule.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\SMW_UpdateTask_Time_3337383035303739342d7837235a576c4a3241345041, Delete-on-Reboot, [9adf50bbe5a6082e1508bf5d04ff2dd3],
PUP.Optional.ShopperPro.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\SPBIW_UpdateTask_Time_3337383035303739342d7837235a576c4a3241345041, Delete-on-Reboot, [11681af109822a0c073759c32ed503fd],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE619FF1-032D-49BB-BC46-3BEC347D6787}, Quarantined, [3a3fb15aed9e26104d95c6e1c341e818],
PUP.Optional.Linkury.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{04DB50FA-EA80-4256-85F9-540C582E280D}, Quarantined, [6a0fe427aedd58de5c41357d659f3ac6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{111BEFDA-9EB2-48DF-BC5F-AF724F8E7B25}, Quarantined, [136687846c1fa88e3ea3e5c239cb748c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1449C14F-EC7B-4C4C-B127-C3B755A865F2}, Quarantined, [a9d038d32b6038fefee2dacd26de6b95],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1815E1A1-EE9B-44BE-AB27-242CCFD54EAB}, Quarantined, [41383fcc3e4d4bebda06367128dc21df],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{19AF3497-30B1-4E31-9B52-1DA08FE2C5D4}, Quarantined, [245515f642493bfbdf014760aa5a2cd4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1AB903B6-D677-46E4-95F3-7C3A311F5757}, Quarantined, [2950de2d008ba88ea53c04a3a65e7b85],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1AF02325-54A4-440F-ABB8-1C70D41EEB94}, Quarantined, [5029cc3f1f6c270fd20f4463dc283bc5],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1C2C0BE3-968C-4C23-B817-1A3BF0D29816}, Quarantined, [0079a8635a31082ee8f9575031d3b050],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CB9A1FC-9547-4433-B6FF-B54EA5A852A7}, Quarantined, [80f96e9deaa1cb6bdf027235d92bfc04],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CDEDDF8-376A-4531-BBC3-67D44E7E1EDE}, Quarantined, [f0892be024674aec855be2c5fd07827e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1DE66523-ABE9-4BD2-8211-3029C129EBE9}, Quarantined, [5722a16aa5e64fe7be23169142c27090],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{25167719-A1A1-4797-90AC-F1BCF5753F33}, Quarantined, [5227be4d315a0f2761800a9d669e42be],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{28624EE8-E825-4B60-9A67-EBA16EB7A7F6}, Quarantined, [2b4ea16a63284cea944c4166996b27d9],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2B42CF39-2956-454C-A0E2-AB2715135C84}, Quarantined, [32478e7df4978aac2eb31592de26966a],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2CD56E27-2B0B-427F-88BC-77C08488E98E}, Quarantined, [74057497e7a4c96d14cc1295d72d2fd1],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D8A965F-44DB-40CC-AE40-D48C58A74CB4}, Quarantined, [42377a916b2096a06977f3b4fe0604fc],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2EA24705-877D-4A2F-9311-FD692B4DB748}, Quarantined, [e099917a583356e0558b7f28778db34d],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2EFBEC8F-E20D-40B4-80D5-ACAEE0349ED8}, Quarantined, [f188e8232764c175e6fa44639371d729],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{30C7DFD6-4679-4575-8814-A35A7A98CA4D}, Quarantined, [54255eadbbd0ed49b52bb4f359abc838],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3105C3FE-7246-4407-91F0-6719B7EF418F}, Quarantined, [17625cafd3b8b284fbe58d1acd375ca4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3186ECF3-8683-44D5-BAEF-D33BB82893F1}, Quarantined, [fe7bdd2ef992e74f8a57525514f00ef2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3214B561-9B36-4B0F-AE3D-E3B9D75FD068}, Quarantined, [54251af1e1aab77fc61b8e1953b1f20e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{36DBB29E-7060-4671-BBD4-84F2E123206D}, Quarantined, [7dfc3ecddfac83b39849b7f020e4d828],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3C50A38D-E5AB-4D77-A481-A927395E1B1F}, Quarantined, [0772cc3f454620162db47730c341bd43],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3FE3DF01-9838-4CEB-9F3C-AB3CE8566174}, Quarantined, [b0c959b26724da5cf6ea1592000439c7],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{412BBF81-62F7-413F-851A-A34D1F678B90}, Quarantined, [3346da3197f406308e52485f9a6a718f],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4659EAF5-3231-42B9-8448-A0EFFB506C3B}, Quarantined, [da9f5dae0a81e155ebf62483ed179769],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4C947272-AFFD-4290-9D44-D9AEF021AD59}, Quarantined, [42378784008b68ce835d5156a262748c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4E89DCC8-8131-42B9-B0E5-1CC38F93B84D}, Quarantined, [255493781d6e74c225bbfbac8d77f808],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4FAB8325-91AF-472D-8BEB-C7898F37F036}, Quarantined, [eb8e29e26f1cbf776f711196ed17d22e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4FC7FD22-5FF0-4B31-834A-9EFA17C01A60}, Quarantined, [ceab7794cbc081b531afc2e57a8a56aa],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{50AF519B-EDDA-4427-85BD-BE1A4523E2FF}, Quarantined, [46332eddd8b3f44223be6b3c956ffa06],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5114A248-6E24-49D5-B86C-E1149786BF92}, Quarantined, [92e71bf02764ef47ae326f384aba956b],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{517CE945-1F23-4139-81F8-DE7EC014F879}, Quarantined, [49303ecd5e2d90a608d8eabd2cd830d0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{525F4D5D-7A56-4EA1-9311-13672CEABCA5}, Quarantined, [354412f9d0bb092dcf11bdea768e34cc],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{52B2C6A6-B381-4CCB-8928-4BEB6BE0B15A}, Quarantined, [0a6fbb509fecb87e9f412a7d6c980af6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{53F2E8C4-6B4B-43AA-8E84-AA88D174919B}, Quarantined, [13667596c7c4f64088598d1a7c88e31d],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5586665E-8A9A-4E41-81EA-26C0F33B7D93}, Quarantined, [64153bd0abe0c76fc917f2b56b99728e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{58BECE02-6A9F-4EC2-8E97-57179EA34FBF}, Quarantined, [1564a269b4d702340bd5ecbba65e728e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5A2A8103-2AC5-426A-A4DD-D69F23282931}, Quarantined, [ee8bed1ed8b3eb4be8f85b4c669e4eb2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5E5D918A-CD1B-491B-96C8-66BE6E9E2B1B}, Quarantined, [28517e8dacdf3ff7b8292c7bab591ae6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5FF362FA-2EB6-40D1-9B5C-4CC75877A0EF}, Quarantined, [56230902c7c483b32db4fbaca85c43bd],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{609480D3-5E86-4C4F-BCFE-3F5DC7467419}, Quarantined, [2356fb109bf0fc3aecf4d4d310f456aa],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{617CE89E-CCDD-4609-8B83-523DF3564EF7}, Quarantined, [6b0e1cef7a1167cfa33e980f5ea6857b],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{61BD51A5-455B-4415-83AE-2BD51757876E}, Quarantined, [3f3adf2c602b88aeb62b664163a19a66],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{625CDD59-D089-487B-BB90-2BAF90F4DE2A}, Quarantined, [1f5a8d7ed9b20a2c39a7683f46be9e62],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{648A3296-D395-418D-8AFE-F2E253E9FD1C}, Quarantined, [ff7aed1e602b1224f5ec8324b94b30d0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6771D20C-47E9-4240-8ECD-FEA881C960A6}, Quarantined, [2059bf4c95f63402647d416657ad30d0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68541ABF-121E-4564-822F-D8F3C4C316D1}, Quarantined, [b0c9ce3d305ba294786932757094de22],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68EACBC8-EEB9-4AF1-B877-1081B32EA8EA}, Quarantined, [7603fd0ef59645f1a140e3c44fb5718f],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6E1594ED-EE02-4F4F-8586-87E9FF26F094}, Quarantined, [73064ac1fb90b1859e427433f70d07f9],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{708193E7-B84E-4FFC-A2A7-F87BB35454DD}, Quarantined, [d4a5a76442493afc03de9f08f4101be5],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7868CA27-1430-428E-AF10-8A746E4E4A28}, Quarantined, [512839d2a3e80c2a8f52eeb9b054fe02],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7A60D8EA-B237-4C18-BFE3-317BDA4C36A3}, Quarantined, [b6c343c8484393a3d709eeb964a05ea2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7B332F24-39CB-4520-A354-746711E82A19}, Quarantined, [7cfd3ccf315a78beeef36146966e30d0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7C679316-4884-4AA2-9F49-C92B4AD2E46E}, Quarantined, [92e7a16afa912115825f6b3ce71d20e0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7F21E316-E549-4E24-A019-DFDE8C9A56AA}, Quarantined, [97e25ab16625fa3cfce4d5d27f859769],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{81982673-6D2C-4D72-BCA9-4ED29A2343DD}, Quarantined, [304954b76c1f75c17d64bceb20e4a55b],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{81B32E4E-9C46-45B4-8794-8EEDF3EE39B1}, Quarantined, [5b1ed536375465d1ac35f5b22cd86b95],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{81B83DC6-2616-4E2A-949B-E49660CA9ACD}, Quarantined, [1e5bd2393a5181b5fee3545337cd3ec2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{81C585C8-86A0-44C5-B4A7-EA628D46E3CF}, Quarantined, [f18803089dee57df7a67dfc809fb57a9],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{825ABB19-29DF-48BB-AB84-F94ADA62DEE5}, Quarantined, [da9f010a25662a0cf3ed347324e0c63a],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{83C56B7D-924B-466C-B2FC-1849FC1DC5A4}, Quarantined, [90e9ea2153388fa741a07532cb399b65],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{87010CFD-EE65-4243-86FB-8DE213CD9F1A}, Quarantined, [8eeb0407f19a7abc4a961f8827dd2cd4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{88A42C46-D2CD-4887-958F-297CCFC641AA}, Quarantined, [295029e2a3e8290db9283f68ae5652ae],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8973C92D-2102-4D16-BCE2-3C5726D755B4}, Quarantined, [f089d635701ba88e17c96c3be024ee12],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8F59FBF1-3AB1-4D16-A78F-BF7CED5F99AB}, Quarantined, [df9a52b9cac164d21fc2d7d01fe553ad],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{91B3DB21-ABD7-4302-A599-CB27E3B4725F}, Quarantined, [3643e02b9bf0fe3811d087205ea6956b],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92D39549-4964-416E-A0B6-E2D3A73D6F85}, Quarantined, [4a2f21eacac10036657c4661e2226c94],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{93E5F6BA-16E0-467D-9E64-8D825A4CCF56}, Quarantined, [ff7af01b098270c62eb3f8af9d67bb45],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{94B56CC3-8A73-4D6C-BAD6-504C1DD37B3F}, Quarantined, [a7d2a9622f5ced49835e0c9bf90b0000],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{95B0AD6B-5736-4B0D-A3F5-F1F8992259AC}, Quarantined, [36437c8f810a5bdbbf22911681834db3],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{966736D3-4748-42D1-804A-262FB6F14D31}, Quarantined, [d0a90dfe0c7f3501a53b2780f50f5ba5],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{97A16A72-73BD-4150-A84C-214E81BBB363}, Quarantined, [f683c04b2c5fd56132aef7b020e436ca],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9892C640-E9AC-4C78-8793-6D63F2384B9A}, Quarantined, [7504fc0feaa1b1851ac75c4bb45048b8],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9B5945F4-DB8E-49BC-A0FA-81DDDBB87972}, Quarantined, [fd7c1bf02f5c1f17b031b2f53ec604fc],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9CC95B20-6E80-420A-AF7B-2753D0B364DC}, Quarantined, [4f2a4dbe04873ef89a4782253fc5db25],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FD8BB52-B634-46D5-8DFA-1CDE1ADEBCD7}, Quarantined, [572260abb9d224125c843d6af90b18e8],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A2C484B7-DA07-4D04-836B-E532B8AC37F8}, Quarantined, [5a1f2be00c7fe1555c851f8855af55ab],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A37F3DF5-BBA0-4589-8D1D-E5517869AAF2}, Quarantined, [62175dae3d4e87af2eb2dec91ee627d9],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A3B58230-F333-498A-A725-9BD65CDB4E6C}, Quarantined, [364366a52a616fc7ecf564437a8a9a66],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A7BB78CE-3F30-4078-9FD2-97BC82E184F5}, Quarantined, [95e44ac1692249ed865a5f48d331e41c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A841E906-9569-44BA-949E-E5308CD3897F}, Quarantined, [1a5f18f3becdeb4bf7e96146c242bd43],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A873E44F-CA19-43A4-9AA8-981E607F25AC}, Quarantined, [33469b706f1c0c2a8f51f4b33fc58d73],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A8DC639F-F288-418A-ABFA-359070E394A4}, Quarantined, [25540ffcc0cb6ec8fce4fdaa91738080],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A8F8BE0F-58CE-42E0-A1F8-9978334D6758}, Quarantined, [e29732d97d0ef0463ca4e3c47193718f],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA6BFCE7-51B0-4C17-AC95-8034F527B140}, Quarantined, [6c0d56b579128ea805dbd9ce768e4cb4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABA0E42E-19BF-424C-B6C2-FDDCDE23A915}, Quarantined, [89f08b805d2e7eb807da1f884bb98080],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AF073E8B-F7CA-4DE6-ACE8-A189FAF4BD11}, Quarantined, [4831be4d3d4ea1959b46bceb47bdad53],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AF216ECF-BA66-427C-B9E0-55F2EE311A8A}, Quarantined, [e19807048cff6ccaecf51b8c3dc714ec],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B2ED0AAB-95B7-4E41-9A35-A11B50B1EF5A}, Quarantined, [93e6f01bcac10135627fe6c1dd272ed2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B2F0FE8B-142F-406A-B85F-858BEAAE201D}, Quarantined, [e49592794f3c3204b52bacfb60a4629e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B577EE68-B9E8-4D0B-8630-5F942DA84C91}, Quarantined, [1762c9425239c76ff5ec8c1bad576997],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B5EB5275-A153-464F-8BE0-42BB55605EB8}, Quarantined, [95e4b4578cff191d964b0b9c28dcdf21],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B6000BBB-69AC-4064-95FE-64FA56E9F024}, Quarantined, [9edb7e8d216aa195429f8720f60e6f91],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B6BBE911-713E-4282-AA3E-6DC5C9EC9BC1}, Quarantined, [1c5d6aa18ffc280e9d449f08b84cf50b],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B7C551E1-2DAD-492C-8AA1-7616359971DA}, Quarantined, [2d4cb15a2f5c44f2924ef3b426de9967],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B7D96C67-DAB9-498C-97EC-E8A36DF1FA28}, Quarantined, [522785867f0cfe38ca17c3e4d92b7090],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B9638175-5545-4393-908D-54C27D2393FA}, Quarantined, [196028e342490135ce138324ec1822de],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BAA4BB5E-AA3B-41DE-AFE9-2AB19FDD73EC}, Quarantined, [0e6b12f939520a2c934dc0e7b64ef10f],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BFA4D7F2-A0E5-4C50-B11D-6B455DF14BB1}, Quarantined, [6a0f43c8d5b637ff35ac0a9d689cc838],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C13998CC-FDA3-46CB-9CC4-41BD8C69DE66}, Quarantined, [552462a9bad1a88ea937545321e35ca4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4DB50C9-BC17-45E7-AC53-A74E30EAA3CE}, Quarantined, [0f6aec1f296296a0f5eb317633d116ea],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C5FEFC84-F8D8-40D9-8558-F7D6DB55318A}, Quarantined, [1c5d9b70f19ac96d0dd46f38d232c63a],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C8EACDAB-D04D-4C71-8E51-D195C64CA7B7}, Quarantined, [6e0bc348d2b9102636ab9a0df212be42],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CA79068A-1D4E-4ED5-80C0-137EAA7E6F22}, Quarantined, [81f8bf4c9eedf1458759f3b4ee161ce4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CBB1704B-D902-48D3-89CA-83D72DAEFDB2}, Quarantined, [3c3dc447b3d85adc34ad8324df25cb35],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CC52DD59-1ACB-4CA4-87EC-BDCAD5414F7E}, Quarantined, [5821c04be9a25adcca17812671930000],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE4623CC-3974-463C-AD9A-AED88967705A}, Quarantined, [1366d5366823e4526b768324dd2733cd],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE700A0E-8639-4486-A8B9-5C988CF53F6F}, Quarantined, [f28745c6434881b5c51be3c47193f907],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D192FF80-798A-4BB7-BC3B-7EA9B68DD430}, Quarantined, [87f23dce3f4c41f5766af4b320e450b0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D1B50222-9C13-42A3-B7D1-21E2C137AA15}, Quarantined, [73064ebd91fa979f4f9201a648bc09f7],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D2009CBA-F616-4DDB-9FE2-A56E579F5A85}, Quarantined, [97e2b2595a31e94d617fa20524e05ea2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D5048682-2EA8-4FA4-8EE7-54882CFEDA2D}, Quarantined, [0c6ded1ec4c70c2abd23c6e1bd47ad53],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D707B2F4-8DA0-4070-9492-946C91691078}, Quarantined, [afca16f5ff8c52e4edf41d8a37cd629e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DA2A825B-612A-4263-A044-C1FDB528402E}, Quarantined, [097038d3612ae25433ad089f08fc7a86],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DC2D24F6-1D9E-4839-AE32-7E12E0A23C8D}, Quarantined, [b0c98c7f7615181e766ae3c49c683ac6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DCD3D313-79BC-4F1A-A771-3A57F826ACA9}, Quarantined, [4336808b602b0f27cb15c8df6e969d63],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE619FF1-032D-49BB-BC46-3BEC347D6787}, Quarantined, [23569873bfcc8caaa9362582fc081ce4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E220C6D7-6CF0-4BCC-859C-94854F90E8B0}, Quarantined, [4930d13a07840531a23eefb8d82c738d],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4489BE6-D4EE-4FB1-B569-53FFCFDC447D}, Quarantined, [4930c249b6d579bd8d53e9bee321ad53],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4552B42-5750-4661-8F9E-E6813DC71AA6}, Quarantined, [a7d21fec82094beb6c75b6f145bff20e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4851E62-6666-47FA-B2C0-A4B6ADED2FA8}, Quarantined, [7306a368f695dd59fee234730ff529d7],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E491B5A1-5CF2-4754-85B2-E05D3AE5AE3E}, Quarantined, [aacf66a5dbb081b5845db1f6b94b946c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4F6B26C-2EF3-4488-8724-DF23C290D873}, Quarantined, [d5a4af5ccbc0d95d766a891e3cc815eb],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E707F0F3-38F6-45E4-BA22-49701DECE5F0}, Quarantined, [a9d0a566276491a5b7298225d43021df],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E97778B7-CFED-440F-A3DC-1B76459C819A}, Quarantined, [c7b2f714e4a7152148983c6b43c1cb35],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E98AF7FE-668E-4424-8350-4944C1204FCD}, Quarantined, [afca818a6e1da98d2eb2971005ff54ac],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0FD61C2-5A14-4507-BDEE-425A8CC9A64C}, Quarantined, [354475967714132326bb2e791fe5fc04],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F24D0293-565B-4030-995E-16399DB183B4}, Quarantined, [1b5eac5f3b503ff7ecf50a9d33d11ae6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F377E1BF-B7A1-49B8-92B7-5BBDF0A0D2D5}, Quarantined, [e990e8237f0ca690f6ea2c7b05ff4bb5],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F48D9AB4-1CAE-449A-9B87-527E5BBA1471}, Quarantined, [92e720eb800b1f175888acfb8d777e82],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F6C2ED0E-7E45-4443-94CF-782825BF1881}, Quarantined, [3049d734315a300689585255699b926e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F6EB9F67-2314-4B8F-A238-CFCF5C551D94}, Quarantined, [562367a42b6047efe4fd3275ba4a669a],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F805215E-EB38-4471-B397-86A4546042FD}, Quarantined, [2554ae5d0883bd794c950f98a163926e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA0DA66D-55E2-4213-A6AF-C5AAE85A7A20}, Quarantined, [3f3a26e5d7b4c67018c8188f21e317e9],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA605CF5-9A43-4233-9DFE-5EE461A6166E}, Quarantined, [e8912be0e9a2d462c9189116e024ba46],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB3AB6B7-2795-4FF6-B1D3-1E13F06CA129}, Quarantined, [0c6da96295f665d15e836d3a30d48878],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC2A4F14-D935-434F-B982-DE3654773449}, Quarantined, [a6d355b60b80003622bf2c7b719329d7],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC809524-2C7F-4797-B382-EA978F7141CD}, Quarantined, [5d1c5ab128637cba7d63bbec55afa957],
PUP.Optional.W3i.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{660B7A65-A56F-4D71-BFCF-0005860DBC96}, Quarantined, [245518f3d8b3d95d5aa85d56d82c827e],

Registry Values: 148
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{de619ff1-032d-49bb-bc46-3bec347d6787}|AppName, HQPureV1.8-bg.exe, Quarantined, [0871eb20f49744f2578ba502758ffb05]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\chrome.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130529820182308880, Quarantined, [46336ba0c8c375c1cd06b6f470946c94]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\explorer.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130529820182308880, Quarantined, [9ddce625a7e4bf778053deccf70d3ec2]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\firefox.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130529820182308880, Quarantined, [6118c14adab13303468d5c4e1be97e82]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\iexplore.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130529820182308880, Quarantined, [f5844fbcb8d368ce21b20f9bc83c6997]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\SPVC32Ldr|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130529820182308880, Quarantined, [344542c9c2c9fa3cd7fddecc45bf0000]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{de619ff1-032d-49bb-bc46-3bec347d6787}|AppName, HQPureV1.8-bg.exe, Quarantined, [3a3fb15aed9e26104d95c6e1c341e818]
PUP.Optional.Linkury.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{04DB50FA-EA80-4256-85F9-540C582E280D}|Publisher, Linkury Inc., Quarantined, [6a0fe427aedd58de5c41357d659f3ac6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{111BEFDA-9EB2-48DF-BC5F-AF724F8E7B25}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [136687846c1fa88e3ea3e5c239cb748c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1449C14F-EC7B-4C4C-B127-C3B755A865F2}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [a9d038d32b6038fefee2dacd26de6b95]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1815E1A1-EE9B-44BE-AB27-242CCFD54EAB}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [41383fcc3e4d4bebda06367128dc21df]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{19AF3497-30B1-4E31-9B52-1DA08FE2C5D4}|AppName, 9a4c0ff9-b44f-456a-ad88-722b1fa19755-2.exe-buttonutil.exe, Quarantined, [245515f642493bfbdf014760aa5a2cd4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1AB903B6-D677-46E4-95F3-7C3A311F5757}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [2950de2d008ba88ea53c04a3a65e7b85]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1AF02325-54A4-440F-ABB8-1C70D41EEB94}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [5029cc3f1f6c270fd20f4463dc283bc5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1C2C0BE3-968C-4C23-B817-1A3BF0D29816}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [0079a8635a31082ee8f9575031d3b050]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CB9A1FC-9547-4433-B6FF-B54EA5A852A7}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [80f96e9deaa1cb6bdf027235d92bfc04]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CDEDDF8-376A-4531-BBC3-67D44E7E1EDE}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [f0892be024674aec855be2c5fd07827e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1DE66523-ABE9-4BD2-8211-3029C129EBE9}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [5722a16aa5e64fe7be23169142c27090]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{25167719-A1A1-4797-90AC-F1BCF5753F33}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [5227be4d315a0f2761800a9d669e42be]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{28624EE8-E825-4B60-9A67-EBA16EB7A7F6}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [2b4ea16a63284cea944c4166996b27d9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2B42CF39-2956-454C-A0E2-AB2715135C84}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [32478e7df4978aac2eb31592de26966a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2CD56E27-2B0B-427F-88BC-77C08488E98E}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [74057497e7a4c96d14cc1295d72d2fd1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D8A965F-44DB-40CC-AE40-D48C58A74CB4}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [42377a916b2096a06977f3b4fe0604fc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2EA24705-877D-4A2F-9311-FD692B4DB748}|AppName, 18e47e3d-55e4-415c-a449-d10a60f6c72d-2.exe-buttonutil.exe, Quarantined, [e099917a583356e0558b7f28778db34d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2EFBEC8F-E20D-40B4-80D5-ACAEE0349ED8}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [f188e8232764c175e6fa44639371d729]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{30C7DFD6-4679-4575-8814-A35A7A98CA4D}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [54255eadbbd0ed49b52bb4f359abc838]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3105C3FE-7246-4407-91F0-6719B7EF418F}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [17625cafd3b8b284fbe58d1acd375ca4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3186ECF3-8683-44D5-BAEF-D33BB82893F1}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [fe7bdd2ef992e74f8a57525514f00ef2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3214B561-9B36-4B0F-AE3D-E3B9D75FD068}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [54251af1e1aab77fc61b8e1953b1f20e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{36DBB29E-7060-4671-BBD4-84F2E123206D}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [7dfc3ecddfac83b39849b7f020e4d828]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3C50A38D-E5AB-4D77-A481-A927395E1B1F}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [0772cc3f454620162db47730c341bd43]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3FE3DF01-9838-4CEB-9F3C-AB3CE8566174}|AppName, 9a4c0ff9-b44f-456a-ad88-722b1fa19755-2.exe-buttonutil.exe, Quarantined, [b0c959b26724da5cf6ea1592000439c7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{412BBF81-62F7-413F-851A-A34D1F678B90}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [3346da3197f406308e52485f9a6a718f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4659EAF5-3231-42B9-8448-A0EFFB506C3B}|AppName, 9a4c0ff9-b44f-456a-ad88-722b1fa19755-2.exe-codedownloader.exe, Quarantined, [da9f5dae0a81e155ebf62483ed179769]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4C947272-AFFD-4290-9D44-D9AEF021AD59}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [42378784008b68ce835d5156a262748c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4E89DCC8-8131-42B9-B0E5-1CC38F93B84D}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [255493781d6e74c225bbfbac8d77f808]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4FAB8325-91AF-472D-8BEB-C7898F37F036}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [eb8e29e26f1cbf776f711196ed17d22e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4FC7FD22-5FF0-4B31-834A-9EFA17C01A60}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [ceab7794cbc081b531afc2e57a8a56aa]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{50AF519B-EDDA-4427-85BD-BE1A4523E2FF}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [46332eddd8b3f44223be6b3c956ffa06]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5114A248-6E24-49D5-B86C-E1149786BF92}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [92e71bf02764ef47ae326f384aba956b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{517CE945-1F23-4139-81F8-DE7EC014F879}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [49303ecd5e2d90a608d8eabd2cd830d0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{525F4D5D-7A56-4EA1-9311-13672CEABCA5}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [354412f9d0bb092dcf11bdea768e34cc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{52B2C6A6-B381-4CCB-8928-4BEB6BE0B15A}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [0a6fbb509fecb87e9f412a7d6c980af6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{53F2E8C4-6B4B-43AA-8E84-AA88D174919B}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [13667596c7c4f64088598d1a7c88e31d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5586665E-8A9A-4E41-81EA-26C0F33B7D93}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [64153bd0abe0c76fc917f2b56b99728e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{58BECE02-6A9F-4EC2-8E97-57179EA34FBF}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [1564a269b4d702340bd5ecbba65e728e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5A2A8103-2AC5-426A-A4DD-D69F23282931}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [ee8bed1ed8b3eb4be8f85b4c669e4eb2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5E5D918A-CD1B-491B-96C8-66BE6E9E2B1B}|AppName, 18e47e3d-55e4-415c-a449-d10a60f6c72d-2.exe-codedownloader.exe, Quarantined, [28517e8dacdf3ff7b8292c7bab591ae6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5ff362fa-2eb6-40d1-9b5c-4cc75877a0ef}|AppName, HQPureV1.8-codedownloader.exe, Quarantined, [56230902c7c483b32db4fbaca85c43bd]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{609480D3-5E86-4C4F-BCFE-3F5DC7467419}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [2356fb109bf0fc3aecf4d4d310f456aa]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{617CE89E-CCDD-4609-8B83-523DF3564EF7}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [6b0e1cef7a1167cfa33e980f5ea6857b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{61BD51A5-455B-4415-83AE-2BD51757876E}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [3f3adf2c602b88aeb62b664163a19a66]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{625CDD59-D089-487B-BB90-2BAF90F4DE2A}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [1f5a8d7ed9b20a2c39a7683f46be9e62]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{648A3296-D395-418D-8AFE-F2E253E9FD1C}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [ff7aed1e602b1224f5ec8324b94b30d0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6771D20C-47E9-4240-8ECD-FEA881C960A6}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [2059bf4c95f63402647d416657ad30d0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68541ABF-121E-4564-822F-D8F3C4C316D1}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [b0c9ce3d305ba294786932757094de22]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68EACBC8-EEB9-4AF1-B877-1081B32EA8EA}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [7603fd0ef59645f1a140e3c44fb5718f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6E1594ED-EE02-4F4F-8586-87E9FF26F094}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [73064ac1fb90b1859e427433f70d07f9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{708193E7-B84E-4FFC-A2A7-F87BB35454DD}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [d4a5a76442493afc03de9f08f4101be5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7868CA27-1430-428E-AF10-8A746E4E4A28}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [512839d2a3e80c2a8f52eeb9b054fe02]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7A60D8EA-B237-4C18-BFE3-317BDA4C36A3}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [b6c343c8484393a3d709eeb964a05ea2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7B332F24-39CB-4520-A354-746711E82A19}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [7cfd3ccf315a78beeef36146966e30d0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7C679316-4884-4AA2-9F49-C92B4AD2E46E}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [92e7a16afa912115825f6b3ce71d20e0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7F21E316-E549-4E24-A019-DFDE8C9A56AA}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [97e25ab16625fa3cfce4d5d27f859769]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{81982673-6D2C-4D72-BCA9-4ED29A2343DD}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [304954b76c1f75c17d64bceb20e4a55b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{81B32E4E-9C46-45B4-8794-8EEDF3EE39B1}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [5b1ed536375465d1ac35f5b22cd86b95]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{81B83DC6-2616-4E2A-949B-E49660CA9ACD}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [1e5bd2393a5181b5fee3545337cd3ec2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{81C585C8-86A0-44C5-B4A7-EA628D46E3CF}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [f18803089dee57df7a67dfc809fb57a9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{825ABB19-29DF-48BB-AB84-F94ADA62DEE5}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [da9f010a25662a0cf3ed347324e0c63a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{83C56B7D-924B-466C-B2FC-1849FC1DC5A4}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [90e9ea2153388fa741a07532cb399b65]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{87010CFD-EE65-4243-86FB-8DE213CD9F1A}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [8eeb0407f19a7abc4a961f8827dd2cd4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{88A42C46-D2CD-4887-958F-297CCFC641AA}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [295029e2a3e8290db9283f68ae5652ae]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8973C92D-2102-4D16-BCE2-3C5726D755B4}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [f089d635701ba88e17c96c3be024ee12]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8F59FBF1-3AB1-4D16-A78F-BF7CED5F99AB}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [df9a52b9cac164d21fc2d7d01fe553ad]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{91B3DB21-ABD7-4302-A599-CB27E3B4725F}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [3643e02b9bf0fe3811d087205ea6956b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92D39549-4964-416E-A0B6-E2D3A73D6F85}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [4a2f21eacac10036657c4661e2226c94]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{93E5F6BA-16E0-467D-9E64-8D825A4CCF56}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [ff7af01b098270c62eb3f8af9d67bb45]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{94B56CC3-8A73-4D6C-BAD6-504C1DD37B3F}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [a7d2a9622f5ced49835e0c9bf90b0000]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{95B0AD6B-5736-4B0D-A3F5-F1F8992259AC}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [36437c8f810a5bdbbf22911681834db3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{966736D3-4748-42D1-804A-262FB6F14D31}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [d0a90dfe0c7f3501a53b2780f50f5ba5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{97A16A72-73BD-4150-A84C-214E81BBB363}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [f683c04b2c5fd56132aef7b020e436ca]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9892C640-E9AC-4C78-8793-6D63F2384B9A}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [7504fc0feaa1b1851ac75c4bb45048b8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9B5945F4-DB8E-49BC-A0FA-81DDDBB87972}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [fd7c1bf02f5c1f17b031b2f53ec604fc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9CC95B20-6E80-420A-AF7B-2753D0B364DC}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [4f2a4dbe04873ef89a4782253fc5db25]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FD8BB52-B634-46D5-8DFA-1CDE1ADEBCD7}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [572260abb9d224125c843d6af90b18e8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A2C484B7-DA07-4D04-836B-E532B8AC37F8}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [5a1f2be00c7fe1555c851f8855af55ab]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A37F3DF5-BBA0-4589-8D1D-E5517869AAF2}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [62175dae3d4e87af2eb2dec91ee627d9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A3B58230-F333-498A-A725-9BD65CDB4E6C}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [364366a52a616fc7ecf564437a8a9a66]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A7BB78CE-3F30-4078-9FD2-97BC82E184F5}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [95e44ac1692249ed865a5f48d331e41c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A841E906-9569-44BA-949E-E5308CD3897F}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [1a5f18f3becdeb4bf7e96146c242bd43]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A873E44F-CA19-43A4-9AA8-981E607F25AC}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [33469b706f1c0c2a8f51f4b33fc58d73]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A8DC639F-F288-418A-ABFA-359070E394A4}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [25540ffcc0cb6ec8fce4fdaa91738080]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A8F8BE0F-58CE-42E0-A1F8-9978334D6758}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [e29732d97d0ef0463ca4e3c47193718f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA6BFCE7-51B0-4C17-AC95-8034F527B140}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [6c0d56b579128ea805dbd9ce768e4cb4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABA0E42E-19BF-424C-B6C2-FDDCDE23A915}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [89f08b805d2e7eb807da1f884bb98080]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AF073E8B-F7CA-4DE6-ACE8-A189FAF4BD11}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [4831be4d3d4ea1959b46bceb47bdad53]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AF216ECF-BA66-427C-B9E0-55F2EE311A8A}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [e19807048cff6ccaecf51b8c3dc714ec]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B2ED0AAB-95B7-4E41-9A35-A11B50B1EF5A}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [93e6f01bcac10135627fe6c1dd272ed2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B2F0FE8B-142F-406A-B85F-858BEAAE201D}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [e49592794f3c3204b52bacfb60a4629e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B577EE68-B9E8-4D0B-8630-5F942DA84C91}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [1762c9425239c76ff5ec8c1bad576997]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B5EB5275-A153-464F-8BE0-42BB55605EB8}|AppName, 18e47e3d-55e4-415c-a449-d10a60f6c72d-2.exe-codedownloader.exe, Quarantined, [95e4b4578cff191d964b0b9c28dcdf21]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B6000BBB-69AC-4064-95FE-64FA56E9F024}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [9edb7e8d216aa195429f8720f60e6f91]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B6BBE911-713E-4282-AA3E-6DC5C9EC9BC1}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [1c5d6aa18ffc280e9d449f08b84cf50b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B7C551E1-2DAD-492C-8AA1-7616359971DA}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [2d4cb15a2f5c44f2924ef3b426de9967]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B7D96C67-DAB9-498C-97EC-E8A36DF1FA28}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [522785867f0cfe38ca17c3e4d92b7090]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B9638175-5545-4393-908D-54C27D2393FA}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [196028e342490135ce138324ec1822de]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BAA4BB5E-AA3B-41DE-AFE9-2AB19FDD73EC}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [0e6b12f939520a2c934dc0e7b64ef10f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BFA4D7F2-A0E5-4C50-B11D-6B455DF14BB1}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [6a0f43c8d5b637ff35ac0a9d689cc838]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C13998CC-FDA3-46CB-9CC4-41BD8C69DE66}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [552462a9bad1a88ea937545321e35ca4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4DB50C9-BC17-45E7-AC53-A74E30EAA3CE}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [0f6aec1f296296a0f5eb317633d116ea]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C5FEFC84-F8D8-40D9-8558-F7D6DB55318A}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [1c5d9b70f19ac96d0dd46f38d232c63a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C8EACDAB-D04D-4C71-8E51-D195C64CA7B7}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [6e0bc348d2b9102636ab9a0df212be42]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CA79068A-1D4E-4ED5-80C0-137EAA7E6F22}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [81f8bf4c9eedf1458759f3b4ee161ce4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CBB1704B-D902-48D3-89CA-83D72DAEFDB2}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [3c3dc447b3d85adc34ad8324df25cb35]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CC52DD59-1ACB-4CA4-87EC-BDCAD5414F7E}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [5821c04be9a25adcca17812671930000]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE4623CC-3974-463C-AD9A-AED88967705A}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [1366d5366823e4526b768324dd2733cd]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE700A0E-8639-4486-A8B9-5C988CF53F6F}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [f28745c6434881b5c51be3c47193f907]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D192FF80-798A-4BB7-BC3B-7EA9B68DD430}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [87f23dce3f4c41f5766af4b320e450b0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D1B50222-9C13-42A3-B7D1-21E2C137AA15}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [73064ebd91fa979f4f9201a648bc09f7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D2009CBA-F616-4DDB-9FE2-A56E579F5A85}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [97e2b2595a31e94d617fa20524e05ea2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D5048682-2EA8-4FA4-8EE7-54882CFEDA2D}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [0c6ded1ec4c70c2abd23c6e1bd47ad53]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D707B2F4-8DA0-4070-9492-946C91691078}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [afca16f5ff8c52e4edf41d8a37cd629e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DA2A825B-612A-4263-A044-C1FDB528402E}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [097038d3612ae25433ad089f08fc7a86]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DC2D24F6-1D9E-4839-AE32-7E12E0A23C8D}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [b0c98c7f7615181e766ae3c49c683ac6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DCD3D313-79BC-4F1A-A771-3A57F826ACA9}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [4336808b602b0f27cb15c8df6e969d63]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{de619ff1-032d-49bb-bc46-3bec347d6787}|AppName, HQPureV1.8-bg.exe, Quarantined, [23569873bfcc8caaa9362582fc081ce4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E220C6D7-6CF0-4BCC-859C-94854F90E8B0}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [4930d13a07840531a23eefb8d82c738d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4489BE6-D4EE-4FB1-B569-53FFCFDC447D}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [4930c249b6d579bd8d53e9bee321ad53]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4552B42-5750-4661-8F9E-E6813DC71AA6}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [a7d21fec82094beb6c75b6f145bff20e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4851E62-6666-47FA-B2C0-A4B6ADED2FA8}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [7306a368f695dd59fee234730ff529d7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E491B5A1-5CF2-4754-85B2-E05D3AE5AE3E}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [aacf66a5dbb081b5845db1f6b94b946c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4F6B26C-2EF3-4488-8724-DF23C290D873}|AppName, 18e47e3d-55e4-415c-a449-d10a60f6c72d-2.exe-buttonutil.exe, Quarantined, [d5a4af5ccbc0d95d766a891e3cc815eb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E707F0F3-38F6-45E4-BA22-49701DECE5F0}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [a9d0a566276491a5b7298225d43021df]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E97778B7-CFED-440F-A3DC-1B76459C819A}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [c7b2f714e4a7152148983c6b43c1cb35]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E98AF7FE-668E-4424-8350-4944C1204FCD}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [afca818a6e1da98d2eb2971005ff54ac]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0FD61C2-5A14-4507-BDEE-425A8CC9A64C}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [354475967714132326bb2e791fe5fc04]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F24D0293-565B-4030-995E-16399DB183B4}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [1b5eac5f3b503ff7ecf50a9d33d11ae6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F377E1BF-B7A1-49B8-92B7-5BBDF0A0D2D5}|AppName, 18e47e3d-55e4-415c-a449-d10a60f6c72d-2.exe-buttonutil.exe, Quarantined, [e990e8237f0ca690f6ea2c7b05ff4bb5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F48D9AB4-1CAE-449A-9B87-527E5BBA1471}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [92e720eb800b1f175888acfb8d777e82]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F6C2ED0E-7E45-4443-94CF-782825BF1881}|AppName, 18e47e3d-55e4-415c-a449-d10a60f6c72d-2.exe-codedownloader.exe, Quarantined, [3049d734315a300689585255699b926e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F6EB9F67-2314-4B8F-A238-CFCF5C551D94}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [562367a42b6047efe4fd3275ba4a669a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F805215E-EB38-4471-B397-86A4546042FD}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [2554ae5d0883bd794c950f98a163926e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA0DA66D-55E2-4213-A6AF-C5AAE85A7A20}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [3f3a26e5d7b4c67018c8188f21e317e9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA605CF5-9A43-4233-9DFE-5EE461A6166E}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [e8912be0e9a2d462c9189116e024ba46]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB3AB6B7-2795-4FF6-B1D3-1E13F06CA129}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [0c6da96295f665d15e836d3a30d48878]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC2A4F14-D935-434F-B982-DE3654773449}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-codedownloader.exe, Quarantined, [a6d355b60b80003622bf2c7b719329d7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC809524-2C7F-4797-B382-EA978F7141CD}|AppName, 8224a317-e649-462f-a935-8bec295f19a2-2.exe-buttonutil.exe, Quarantined, [5d1c5ab128637cba7d63bbec55afa957]
PUP.Optional.W3i.A, HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{660B7A65-A56F-4D71-BFCF-0005860DBC96}|URL, http://search.yahoo.com/search?p={searchTerms}&ei=UTF-8&fr=w3i&type=W3i_DS,136,0_0,Search,20140518,19890,0,25,0,Quarantined, [245518f3d8b3d95d5aa85d56d82c827e]

Registry Data: 0
(No malicious items detected)

Folders: 7
PUP.Optional.MindSpark.A, C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980\MapsGalaxy_39, Quarantined, [423786859af14beb5835e839b64daa56],
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0, Quarantined, [66135bb0bbd057df0558158d47bd13ed],
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig, Quarantined, [66135bb0bbd057df0558158d47bd13ed],
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0, Quarantined, [502913f80a81bc7a8bd28d1542c2af51],
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig, Quarantined, [502913f80a81bc7a8bd28d1542c2af51],
PUP.Optional.MultiPlug.A, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0, Quarantined, [c6b3f813ee9d23132736336f5aaabf41],
PUP.Optional.MultiPlug.A, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig, Quarantined, [c6b3f813ee9d23132736336f5aaabf41],

Files: 13
PUP.Optional.MindSpark.A, C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980\MapsGalaxy_39\2E71D3E2-CAC1-4D0A-B613-8E9F29A4E948.sqlite, Quarantined, [423786859af14beb5835e839b64daa56],
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\lsdb.js, Quarantined, [66135bb0bbd057df0558158d47bd13ed],
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\background.html, Quarantined, [66135bb0bbd057df0558158d47bd13ed],
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\content.js, Quarantined, [66135bb0bbd057df0558158d47bd13ed],
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\manifest.json, Quarantined, [66135bb0bbd057df0558158d47bd13ed],
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\lsdb.js, Quarantined, [502913f80a81bc7a8bd28d1542c2af51],
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\background.html, Quarantined, [502913f80a81bc7a8bd28d1542c2af51],
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\content.js, Quarantined, [502913f80a81bc7a8bd28d1542c2af51],
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\manifest.json, Quarantined, [502913f80a81bc7a8bd28d1542c2af51],
PUP.Optional.MultiPlug.A, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\lsdb.js, Quarantined, [c6b3f813ee9d23132736336f5aaabf41],
PUP.Optional.MultiPlug.A, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\background.html, Quarantined, [c6b3f813ee9d23132736336f5aaabf41],
PUP.Optional.MultiPlug.A, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\content.js, Quarantined, [c6b3f813ee9d23132736336f5aaabf41],
PUP.Optional.MultiPlug.A, C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig\2.0\manifest.json, Quarantined, [c6b3f813ee9d23132736336f5aaabf41],

Physical Sectors: 0
(No malicious items detected)


(end)

STEP 1
Microsoft Fixit

  • Go to the following page and click on Run Now. Click on Save File.
  • Double-click the downloaded MicrosoftFixit.ProgramInstallUninstall.Run.exe to run the programme.
  • Your computer will ask for confirmation, click Yes.
  • Accept the license agreement.
  • Choose the recommended option to automatically fix problems.
  • The programme will ask whether there is a problem with installation or deinstallation. Please choose deinstallation.
  • You will be shown a list of programmes. Choose the following programme to deinstall it:
    • QuickShare
  • Confirm your decision. Wait for the programme to finish.
  • Please repeat the steps for the following programme to deinstall it:
    • Internet Explorer Toolbar 4.9 by SweetPacks
  • Please tell me in your next reply whether deinstallation of the programmes has been successful.

I ran the program and was able to select quickshare.  The program came back saying it had fixed the problem.  I went to control panel and selected programs and quickshare was not listed so I conclude it has been removed.

Internet explorer toolbar was not listed, I selected "not listed" but it wants a product code which I do not have.

Where do we go from here?

Sorry for the late reply, my weekend was quite busy with my son's birthday party.

 

STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan

  • Double-Click FRST64.exe to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Attach both logs in your next reply.

here is the FRST text file:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-08-2015
Ran by [removed] (administrator) on CARLASPC (25-08-2015 07:22:57)
Running from C:\Users\[removed]\Desktop\KevinStuff
[removed] Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe
(Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\SAMSUNG\SW Update Service\SWMAgent.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avpui.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Carbonite, Inc.) C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Program Files (x86)\bfgclient\bfgclient.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191312 2012-08-06] (Realtek Semiconductor)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2862448 2012-08-05] (ELAN Microelectronics Corp.)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [765056 2012-09-29] (Qualcomm Atheros)
HKLM-x32\…\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\…\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-07] (CyberLink)
HKLM-x32\…\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.)
HKLM-x32\…\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1066192 2015-07-14] (Carbonite, Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4204859643-4009438992-3315869148-1001\…\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2014-10-28] (Microsoft Corporation)
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7930136 2015-07-30] (SUPERAntiSpyware)
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\Run: [AOL Fast Start] => C:\Program Files (x86)\AOL Desktop 9.7\AOL.EXE [72312 2012-10-15] (AOL Inc.)
AppInit_DLLs: C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File not found
AppInit_DLLs:  C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll File not found
Startup: C:\Users\carla35758\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-09-29]
ShortcutTarget: Dropbox.lnk -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-07-14] (Carbonite, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.facebook.com/
SearchScopes: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002 -> {7B6EFEF5-D5E7-4702-9B31-BBD18869E868} URL =
BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{66468EF5-92A1-437E-B0FF-288E107324DF}: [DhcpNameServer] [removed] [removed]

FireFox:
========
FF ProfilePath: C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980
FF Homepage: hxxps://www.facebook.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-11] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-11] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19] ()
FF Plugin-x32: @kaspersky.com/online_banking_08806E753BE44495B44E90AA2513BDC5 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-27] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4204859643-4009438992-3315869148-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\carla35758\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2013-07-03] <==== ATTENTION

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\carla35758\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-08-12] (SUPERAntiSpyware.com)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [220288 2012-09-29] (Qualcomm Atheros Commnucations) [File not signed]
R2 AVP15.0.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe [194000 2015-06-24] (Kaspersky Lab ZAO)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593976 2012-08-26] (Samsung Electronics CO., LTD.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2014-10-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-09-29] (Atheros) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-09-24] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-24] (CyberLink)
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [247016 2015-06-24] (Kaspersky Lab UK Ltd)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-24] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [64368 2015-06-24] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [159960 2015-06-24] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [226480 2015-07-03] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [831664 2015-06-24] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [39792 2015-06-24] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [40304 2015-06-24] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [39792 2015-06-24] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [24944 2015-06-24] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [77680 2015-06-24] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [85360 2015-06-24] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [190648 2015-06-24] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 BTATH_LWFLT; \SystemRoot\system32\DRIVERS\btath_lwflt.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-22 19:29 - 2015-08-22 19:29 - 00000000 ____D C:\Users\carla35758\AppData\Roaming\AlawarEntertainment
2015-08-22 17:11 - 2015-08-22 17:11 - 00347816 _____ (Microsoft Corporation) C:\Users\carla35758\Downloads\MicrosoftFixit.ProgramInstallUninstall.RNP.Run.exe
2015-08-21 09:55 - 2015-08-25 06:18 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-08-21 09:55 - 2015-08-21 09:55 - 00001118 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-08-21 09:55 - 2015-08-21 09:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-21 09:55 - 2015-08-21 09:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-21 09:55 - 2015-08-21 09:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-21 09:55 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-08-21 09:55 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-08-21 09:55 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-08-21 09:53 - 2015-08-21 09:54 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\carla35758\Downloads\mbam-setup-2.1.8.1057.exe
2015-08-19 12:40 - 2015-08-19 12:47 - 00000000 ____D C:\AdwCleaner
2015-08-18 16:42 - 2015-08-10 20:20 - 25191936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-08-18 16:42 - 2015-08-10 19:20 - 19871232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-08-13 11:17 - 2015-07-30 09:04 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 11:17 - 2015-07-30 08:48 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 01:56 - 2015-08-13 01:56 - 00002160 _____ C:\Users\Public\Desktop\Carbonite InfoCenter.lnk
2015-08-13 01:56 - 2015-08-13 01:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Carbonite
2015-08-13 01:20 - 2015-08-13 01:20 - 00000000 _____ C:\Users\Public\Desktop\CarboniteSetup.log
2015-08-12 19:19 - 2015-08-21 11:44 - 00002139 _____ C:\WINDOWS\setupact.log
2015-08-12 19:19 - 2015-08-12 19:19 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-08-12 19:17 - 2015-08-21 11:44 - 00009320 _____ C:\WINDOWS\PFRO.log
2015-08-12 18:50 - 2015-08-25 07:20 - 01168942 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-12 11:58 - 2015-08-12 12:01 - 00000000 ____D C:\Users\carla35758\Desktop\schoolyear-2015-2016
2015-08-12 07:21 - 2015-07-18 20:58 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-08-12 07:21 - 2015-07-18 13:51 - 03704320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-08-12 07:21 - 2015-07-18 13:31 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-08-12 07:21 - 2015-07-18 13:31 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-08-12 07:21 - 2015-07-18 13:31 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-08-12 07:21 - 2015-07-18 13:29 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-08-12 07:21 - 2015-07-18 13:29 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-08-12 07:21 - 2015-07-18 13:29 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-08-12 07:21 - 2015-07-18 13:28 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-08-12 07:21 - 2015-07-18 13:12 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-08-12 07:21 - 2015-07-18 13:10 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-08-12 07:21 - 2015-07-18 13:09 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-08-12 07:20 - 2015-06-09 13:27 - 00411133 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-08-12 07:19 - 2015-07-16 15:36 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-08-12 07:19 - 2015-07-16 15:36 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-08-12 07:19 - 2015-07-16 15:35 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-08-12 07:19 - 2015-07-16 15:26 - 05923328 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-08-12 07:19 - 2015-07-16 15:23 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-08-12 07:19 - 2015-07-16 15:21 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-08-12 07:19 - 2015-07-16 14:53 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-08-12 07:19 - 2015-07-16 14:51 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-08-12 07:19 - 2015-07-16 14:50 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-08-12 07:19 - 2015-07-16 14:45 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-08-12 07:19 - 2015-07-16 14:45 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-08-12 07:19 - 2015-07-16 14:41 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-08-12 07:19 - 2015-07-16 14:39 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-08-12 07:19 - 2015-07-16 14:38 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-08-12 07:19 - 2015-07-16 14:36 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-08-12 07:19 - 2015-07-16 14:34 - 14451200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-08-12 07:19 - 2015-07-16 14:32 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-08-12 07:19 - 2015-07-16 14:14 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-08-12 07:19 - 2015-07-16 14:13 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-08-12 07:19 - 2015-07-16 14:12 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-08-12 07:19 - 2015-07-16 14:12 - 02427904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-08-12 07:19 - 2015-07-16 14:10 - 12856832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-08-12 07:19 - 2015-07-16 14:06 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-08-12 07:19 - 2015-07-16 14:01 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-08-12 07:19 - 2015-07-16 13:52 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-08-12 07:19 - 2015-07-16 13:49 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-08-12 07:19 - 2015-07-16 13:42 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-08-12 07:19 - 2015-07-16 13:38 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-08-12 07:19 - 2015-07-16 13:37 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-08-12 07:17 - 2015-07-15 19:29 - 07458648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-12 07:17 - 2015-07-15 19:29 - 01735000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 07:17 - 2015-07-15 19:29 - 00101720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 07:17 - 2015-07-15 19:28 - 01499920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-08-12 07:17 - 2015-07-10 12:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-12 07:17 - 2015-06-12 12:03 - 18823680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-08-12 07:17 - 2015-06-12 11:36 - 15159296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-08-12 07:16 - 2015-07-07 04:40 - 00270168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2015-08-12 07:16 - 2015-07-07 04:40 - 00114520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2015-08-12 07:16 - 2015-07-07 04:40 - 00044560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2015-08-12 07:15 - 2015-07-28 18:24 - 00025776 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-08-12 07:15 - 2015-07-28 09:24 - 01148416 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-08-12 07:15 - 2015-07-28 09:24 - 01116160 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-08-12 07:15 - 2015-07-28 09:24 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-08-12 07:15 - 2015-07-28 09:24 - 00743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-08-12 07:15 - 2015-07-28 09:24 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-08-12 07:15 - 2015-07-28 09:24 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-08-12 07:15 - 2015-07-01 17:19 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2015-08-12 07:15 - 2015-07-01 17:16 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll
2015-08-12 07:15 - 2015-07-01 16:37 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2015-08-12 07:15 - 2015-07-01 16:35 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\davclnt.dll
2015-08-12 07:14 - 2015-07-29 09:37 - 01994752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 07:14 - 2015-07-29 09:30 - 01381888 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 07:14 - 2015-07-29 09:23 - 01559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-08-12 07:14 - 2015-07-24 13:57 - 04177408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-08-12 07:14 - 2015-07-24 13:57 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-08-12 07:14 - 2015-07-24 13:52 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-08-12 07:14 - 2015-07-24 12:27 - 00301568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-08-12 07:14 - 2015-07-24 12:23 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-08-12 07:14 - 2015-07-14 16:59 - 01113944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-08-12 07:14 - 2015-07-14 16:59 - 00487256 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll
2015-08-12 07:14 - 2015-07-14 16:59 - 00393560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcfgx.dll
2015-08-12 07:14 - 2015-07-13 22:22 - 02529880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-08-12 07:14 - 2015-07-13 22:21 - 01901776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-08-12 07:14 - 2015-07-13 14:46 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2015-08-12 07:14 - 2015-07-13 14:45 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2015-08-12 07:14 - 2015-07-10 13:19 - 01101824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2015-08-12 07:14 - 2015-07-10 12:42 - 02345472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-08-12 07:14 - 2015-07-10 12:14 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2015-08-12 07:14 - 2015-07-10 12:13 - 07032320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2015-08-12 07:14 - 2015-07-10 11:47 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-08-12 07:14 - 2015-07-10 11:31 - 06213120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2015-08-12 07:14 - 2015-07-09 12:13 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 07:14 - 2015-07-09 12:13 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 07:14 - 2015-07-09 11:30 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-08-12 07:14 - 2015-06-11 15:12 - 02476376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-08-12 07:14 - 2015-06-11 15:12 - 00428888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-08-12 07:14 - 2015-05-11 19:24 - 00536920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-08-10 12:32 - 2015-08-10 12:32 - 00036776 _____ C:\Users\carla35758\Downloads\w4sgeen9(3).exe
2015-08-10 09:11 - 2015-08-10 09:11 - 00036776 _____ C:\Users\carla35758\Downloads\w4sgeen9(2).exe
2015-08-10 08:58 - 2015-08-10 08:59 - 00036776 _____ C:\Users\carla35758\Downloads\w4sgeen9(1).exe
2015-08-10 08:36 - 2015-08-25 07:23 - 00000000 ____D C:\FRST
2015-08-10 08:35 - 2015-08-25 07:22 - 00000000 ____D C:\Users\carla35758\Desktop\KevinStuff
2015-07-28 16:43 - 2015-07-28 16:43 - 00000748 _____ C:\Users\Public\Desktop\Skoolbo Common Core.lnk
2015-07-28 16:39 - 2015-07-28 16:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skoolbo Common Core
2015-07-28 16:39 - 2015-07-28 16:39 - 00000000 ____D C:\Skoolbo Common Core
2015-07-28 15:55 - 2015-07-28 16:24 - 368329728 _____ C:\Users\carla35758\Downloads\SkoolboUS.msi
2015-07-28 15:38 - 2015-07-28 15:45 - 83888551 _____ C:\Users\carla35758\Downloads\SkoolboAussie.msi.part
2015-07-26 22:20 - 2015-07-26 22:29 - 00000000 ____D C:\Users\carla35758\Desktop\CourageousChurchPoolParty
2015-07-26 22:19 - 2015-07-26 22:28 - 00000000 ____D C:\Users\carla35758\Desktop\30yearHighSchoolReunion

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-25 07:16 - 2013-11-09 13:31 - 00000392 _____ C:\WINDOWS\Tasks\WpsUpdateTask_carla35758.job
2015-08-25 07:00 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-08-25 06:41 - 2013-05-31 18:36 - 00000966 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002UA.job
2015-08-25 06:35 - 2015-06-14 16:48 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-08-25 06:23 - 2012-08-22 23:11 - 00000000 ____D C:\ProgramData\Temp
2015-08-25 06:11 - 2015-02-14 09:34 - 00003946 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B265354F-4343-4044-9BBC-6323DD2FBBF9}
2015-08-25 04:23 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-08-25 01:55 - 2014-11-06 12:33 - 00000538 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 0053b9ac-3feb-4519-8a4d-147b3b99a4bb.job
2015-08-25 01:00 - 2014-11-06 12:33 - 00000538 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task da4e332b-f72c-488e-bc21-ac7a7a869ad2.job
2015-08-24 18:41 - 2013-05-31 18:36 - 00000944 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002Core.job
2015-08-24 17:09 - 2015-05-19 14:05 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-08-22 17:16 - 2014-05-01 18:42 - 00000000 ____D C:\MATS
2015-08-21 11:44 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\Cursors
2015-08-21 11:44 - 2013-08-22 09:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-21 11:26 - 2012-12-29 14:44 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4204859643-4009438992-3315869148-1002
2015-08-19 17:36 - 2013-04-11 16:47 - 00000000 ____D C:\Users\carla35758\AppData\Roaming\vlc
2015-08-19 12:33 - 2014-09-24 02:15 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-19 12:25 - 2014-09-17 17:41 - 00000000 ____D C:\Users\carla35758\AppData\Local\CrashRpt
2015-08-19 12:11 - 2012-12-29 15:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-19 11:56 - 2012-08-22 22:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2015-08-19 11:56 - 2012-08-22 22:26 - 00000000 ____D C:\Program Files (x86)\Samsung
2015-08-19 11:56 - 2012-08-22 22:24 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-08-18 16:43 - 2012-07-26 02:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-08-14 16:03 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\rescache
2015-08-14 14:57 - 2012-12-29 15:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-13 21:35 - 2013-08-22 08:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-08-13 01:56 - 2014-07-30 19:32 - 00004154 _____ C:\WINDOWS\System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4}
2015-08-12 19:22 - 2013-11-24 16:13 - 00073728 ___SH C:\Users\carla35758\Desktop\Thumbs.db
2015-08-12 19:19 - 2013-08-22 09:44 - 00481176 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-12 19:17 - 2014-04-29 18:15 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-12 19:17 - 2014-04-29 18:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-12 19:14 - 2014-12-10 22:30 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-08-12 19:14 - 2014-09-24 04:50 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-08-12 19:14 - 2013-08-22 10:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 19:14 - 2013-08-22 10:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 19:14 - 2013-08-22 10:36 - 00000000 ____D C:\Program Files\Windows Defender
2015-08-12 19:14 - 2013-08-22 10:36 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-08-12 19:13 - 2014-04-29 18:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-12 19:13 - 2013-08-22 10:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 19:13 - 2013-08-22 10:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 19:10 - 2013-08-16 13:15 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-12 18:56 - 2012-12-31 14:53 - 132483416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-12 18:52 - 2013-04-11 15:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-12 18:52 - 2012-07-26 00:26 - 00000167 _____ C:\WINDOWS\win.ini
2015-08-12 18:39 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\Registration
2015-08-11 15:36 - 2015-06-14 16:48 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-08-08 08:55 - 2015-06-11 09:03 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-08-08 08:55 - 2015-06-11 09:03 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-07 16:57 - 2012-12-29 14:35 - 00000000 ____D C:\Users\carla35758\AppData\Local\Packages
2015-08-01 09:14 - 2013-08-17 09:54 - 00000000 ____D C:\Program Files\SUPERAntiSpyware

==================== Files in the root of some directories =======

2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\carla35758\AppData\Roaming\JOQA
2014-09-01 03:18 - 2014-09-01 03:18 - 0002086 _____ () C:\Users\carla35758\AppData\Roaming\NKO
2014-08-21 06:50 - 2014-08-21 06:50 - 0000045 _____ () C:\Users\carla35758\AppData\Roaming\WB.CFG
2013-05-22 16:45 - 2013-02-21 16:59 - 2063240 _____ (Samsung Electronics) C:\ProgramData\MakeMarkerFile.exe
2013-05-22 16:45 - 2013-01-12 23:51 - 0003004 _____ () C:\ProgramData\MakeMarkerFile.xml

Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-08-21 12:02

==================== End of FRST.txt ============================

 

Here  is the addition text file

Additional scan result of Farbar Recovery Scan Tool (x64) Version:24-08-2015
Ran by [removed] (2015-08-25 07:25:22)
Running from C:\Users\[removed]\Desktop\KevinStuff
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-4204859643-4009438992-3315869148-500 - Administrator - Disabled)
carla35758 (S-1-5-21-4204859643-4009438992-3315869148-1002 - Administrator - Enabled) => C:\Users\carla35758
Guest (S-1-5-21-4204859643-4009438992-3315869148-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4204859643-4009438992-3315869148-1006 - Limited - Enabled)
UpdatusUser (S-1-5-21-4204859643-4009438992-3315869148-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

12 Labours of Hercules (HKLM-x32\…\BFG-12 Labours of Hercules) (Version:  - )
12 Labours of Hercules II: The Cretan Bull (HKLM-x32\…\BFG-12 Labours of Hercules II - The Cretan Bull) (Version:  - )
12 Labours of Hercules III: Girl Power (HKLM-x32\…\BFG-12 Labours of Hercules III - Girl Power) (Version:  - )
4 Elements (HKLM-x32\…\BFG-4 Elements) (Version:  - )
4 Elements II (HKLM-x32\…\BFG-4 Elements II) (Version:  - )
Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.03) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
Allshare Play Link (HKLM-x32\…\{91786428-D4AA-476D-8AF9-A63FFAC2901F}) (Version: 1.0.0 - Samsung)
AOL Uninstaller (Choose which Products to Remove) (HKLM-x32\…\AOL Uninstaller) (Version:  - AOL Inc.)
Big Fish: Game Manager (HKLM-x32\…\BFGC) (Version: 3.3.0.2 - )
Carbonite (HKLM-x32\…\Carbonite Backup) (Version: 5.7.7 build 5155 (Jul-14-2015) - Carbonite)
CCleaner (HKLM\…\CCleaner) (Version: 4.03 - Piriform)
Cradle of Egypt (HKLM-x32\…\BFG-Cradle of Egypt) (Version:  - )
CyberLink Power2Go 8 (HKLM-x32\…\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.1912 - CyberLink Corp.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4415.02 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dropbox (HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\Dropbox) (Version: 2.10.30 - Dropbox, Inc.)
Easy File Share (HKLM-x32\…\{A7C37D4B-F37A-42E8-9B6A-B28C18AD4C12}) (Version: 1.3.4 - Samsung Electronics CO.,LTD.)
ETDWare PS/2-X64 11.7.2.1_WHQL (HKLM\…\Elantech) (Version: 11.7.2.1 - ELAN Microelectronic Corp.)
Galería de fotos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Help Desk (HKLM\…\{C85A891D-7AB4-46AE-84F0-B0C3FAC82280}) (Version: 1.0.4 - Samsung Electronics CO., LTD.)
Intel AppUp(SM) center (HKLM-x32\…\Intel AppUp(SM) center 33070) (Version: 3.6.1.33070.11 - Intel)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\…\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36702 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.2.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Island Tribe 2 (HKLM-x32\…\BFG-Island Tribe 2) (Version:  - )
Island Tribe 3 (HKLM-x32\…\BFG-Island Tribe 3) (Version:  - )
Island Tribe 4 (HKLM-x32\…\BFG-Island Tribe 4) (Version:  - )
Island Tribe 5 (HKLM-x32\…\BFG-Island Tribe 5) (Version:  - )
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
Jewel Legends: Atlantis (HKLM-x32\…\BFG-Jewel Legends - Atlantis) (Version:  - )
Kaspersky Internet Security (HKLM-x32\…\InstallWIX_{02FECEE0-16B2-43DB-BC3B-C844477FC142}) (Version: 15.0.2.361 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 15.0.2.361 - Kaspersky Lab) Hidden
Kingdom Chronicles (HKLM-x32\…\BFG-Kingdom Chronicles) (Version:  - )
Kingsoft Office 2013 (9.1.0.4246) (HKLM-x32\…\Kingsoft Office) (Version: 9.1.0.4246 - Kingsoft Corp.)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM-x32\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version:  - Microsoft)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUSR) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Mozilla Firefox 40.0.2 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 40.0.2 (x86 en-US)) (Version: 40.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 40.0.2.5702 - Mozilla)
My Kingdom for the Princess III (HKLM-x32\…\BFG-My Kingdom for the Princess III) (Version:  - )
Northern Tale 3 (HKLM-x32\…\BFG-Northern Tale 3) (Version:  - )
NVIDIA Graphics Driver 305.46 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 305.46 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0613 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0613 - NVIDIA Corporation)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.210 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Quick Starter (HKLM\…\{EC36E2BC-86F7-44C9-84B2-93930F0FBDBF}) (Version: 1.0.0 - Samsung Electronics CO., LTD.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6699 - Realtek Semiconductor Corp.)
Recovery (HKLM-x32\…\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.0.4.0 - Samsung Electronics CO., LTD.)
Rescue Team 3 (HKLM-x32\…\BFG-Rescue Team 3) (Version:  - )
Rescue Team 4 (HKLM-x32\…\BFG-Rescue Team 4) (Version:  - )
Rolling Idols (HKLM-x32\…\BFG-Rolling Idols) (Version:  - )
S Agent (Version: 1.1.47 - Samsung Electronics CO., LTD.) Hidden
Settings (HKLM-x32\…\{52E5DE60-C96B-42CC-9A37-FE04725940AE}) (Version: 2.0.0 - Samsung Electronics CO., LTD.)
Skoolbo Common Core (HKLM-x32\…\{5A4A6854-80F9-486E-994D-CB7DE54446D5}) (Version: 1.9 - Skoolbo)
Slingo Quest Egypt (HKLM-x32\…\BFG-Slingo Quest Egypt) (Version:  - )
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1032 - SUPERAntiSpyware.com)
Support Center (HKLM\…\{332518C0-0D31-4FFA-9D15-24C9C3D70B08}) (Version: 2.0.7 - Samsung Electronics CO., LTD.)
Support Center FAQ (x32 Version: 1.0.0 - Samsung Electronics CO., LTD.) Hidden
SW Update (HKLM-x32\…\{4F1936F8-82B4-437E-BC47-FAB9136A04B2}) (Version: 2.2.2 - Samsung Electronics CO., LTD.)
Unity Web Player (HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\UnityWebPlayer) (Version: 5.0.3f2 - Unity Technologies ApS)
User Guide (HKLM-x32\…\{039EA659-E421-45C6-8913-BED5D69B5536}) (Version: 1.1.00 - Samsung Electronics CO., LTD.)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Driver Package - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass  (07/27/2012 20.57.1.735) (HKLM\…\9F04C462DAB591BDCCE784F77E4D4F1736010B92) (Version: 07/27/2012 20.57.1.735 - Samsung Electronics Co. Ltd.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation)
World Mosaics (HKLM-x32\…\BFG-World Mosaics) (Version:  - )
World Mosaics 2 (HKLM-x32\…\BFG-World Mosaics 2) (Version:  - )
World Mosaics 3 - Fairy Tales (HKLM-x32\…\BFG-World Mosaics 3 - Fairy Tales) (Version:  - )
World Mosaics 4 (HKLM-x32\…\BFG-World Mosaics 4) (Version:  - )
World Mosaics 5 (HKLM-x32\…\BFG-World Mosaics 5) (Version:  - )
World Mosaics 6 (HKLM-x32\…\BFG-World Mosaics 6) (Version:  - )
World Mosaics 7 (HKLM-x32\…\BFG-World Mosaics 7) (Version:  - )
Xerox PhotoCafe (HKLM-x32\…\Xerox PhotoCafe) (Version: 1.0.0.6162 - Xerox)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points =========================

22-08-2015 17:15:17 Restore Point before QuickShare was removed using Program Install and Uninstall troubleshooter

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {070C494E-CD08-4707-8FED-069101CD900F} - \UNELEVATE_5431 -> No File <==== ATTENTION
Task: {096E8B75-6174-41DA-8FDF-D304073A5F4C} - System32\Tasks\{C466F0B1-0338-4A75-8344-AD12604D66EE} => pcalua.exe -a C:\Users\carla35758\AppData\Roaming\v9\UninstallManager.exe -c  -ptid=brd
Task: {293AD38A-4B55-4804-8242-E6284210F818} - System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} => C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe
Task: {32FCAA4B-128E-4C12-A714-0D7672270DEB} - System32\Tasks\SUPERAntiSpyware Scheduled Task da4e332b-f72c-488e-bc21-ac7a7a869ad2 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2015-06-02] (SUPERAdBlocker.com)
Task: {3B4A0561-468B-4EB0-818E-CEB4F289165A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002Core => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {3B91F900-5B7B-448F-BF2E-336E82217199} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-03-19] (Samsung Electronics CO., LTD.)
Task: {3FDCAAD9-8433-4FDC-86F3-0E528DB6B9F3} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {44CC3745-D2A0-4BDE-B7C4-923572E8564A} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-13] (Intel Corporation)
Task: {568F5729-80E6-4D41-9F5F-5CB1B4A7A649} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-11] (Adobe Systems Incorporated)
Task: {63841FB8-2F7E-4FA8-9A61-F50F9A81A1E4} - System32\Tasks\Xerox PhotoCafe Communicator => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe [2011-10-26] ()
Task: {77D6C834-DDD7-4093-8ED6-45A83845E4AF} - System32\Tasks\SUPERAntiSpyware Scheduled Task 0053b9ac-3feb-4519-8a4d-147b3b99a4bb => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2015-06-02] (SUPERAdBlocker.com)
Task: {88046CAC-C778-49A7-ACA5-42400985CC23} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2012-08-26] (Samsung Electronics CO., LTD.)
Task: {8A86E6C1-367E-430D-82BC-116B4AB573A0} - \SMW_UpdateTask_Time_3337383035303739342d7837235a576c4a3241345041 -> No File <==== ATTENTION
Task: {91890BDF-A52C-4594-9172-238D8B3CC894} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe
Task: {92D51808-34E0-4B7D-AE64-27CE43674E94} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002UA => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {A5E5FE4D-0FA4-42CB-9D42-A0761D729516} - System32\Tasks\JOQA => C:\Users\carla35758\AppData\Roaming\JOQA.exe <==== ATTENTION
Task: {AA8101C7-DE8C-46B5-A0B6-24902A843EBA} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2012-08-15] (SEC)
Task: {BE6E1AFB-7517-43EB-88C9-F3499C6EF59D} - \SPBIW_UpdateTask_Time_3337383035303739342d7837235a576c4a3241345041 -> No File <==== ATTENTION
Task: {CCB32432-49F8-4C5C-BE80-19E08C6E842E} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-13] (Intel Corporation)
Task: {CD32C726-BF85-4C1D-A1CC-0E299F9DE022} - System32\Tasks\NKO => C:\Users\carla35758\AppData\Roaming\NKO.exe <==== ATTENTION
Task: {D001A4BC-EFBA-40A3-8EE0-BA67163C32E5} - \PassShow Update -> No File <==== ATTENTION
Task: {D1D33321-9002-4DAD-BB26-A3A2223F13D4} - System32\Tasks\WpsUpdateTask_carla35758 => C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsupdate.exe [2014-08-06] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {F0D408F1-3B65-4649-BA92-EE988E83FD2A} - System32\Tasks\{C6959241-77B1-456F-BA17-1EF70857F486} => pcalua.exe -a "C:\Program Files (x86)\Groovorio\\uninstall.exe"
Task: {F4B6C860-9974-47A1-AE15-70B38327297B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)
Task: {F7E43235-1DB0-4657-8F13-E4E2BB2F7D1C} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-08-12] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002Core.job => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002UA.job => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\JOQA.job => C:\Users\carla35758\AppData\Roaming\JOQA.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\NKO.job => C:\Users\carla35758\AppData\Roaming\NKO.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 0053b9ac-3feb-4519-8a4d-147b3b99a4bb.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task da4e332b-f72c-488e-bc21-ac7a7a869ad2.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\WINDOWS\Tasks\WpsUpdateTask_carla35758.job => C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsupdate.exe
Task: C:\WINDOWS\Tasks\Xerox PhotoCafe Communicator.job => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe

==================== Loaded Modules (Whitelisted) ==============

2012-08-26 04:48 - 2012-08-26 04:48 - 00076920 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
2014-01-29 23:02 - 2015-06-01 21:00 - 00102912 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-03-05 16:44 - 2014-03-05 16:44 - 04598048 _____ () C:\Program Files (x86)\bfgclient\bfgclient.exe
2014-12-23 16:54 - 2014-12-23 16:54 - 01272616 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\kpcengine.2.3.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00028280 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 01015416 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmd.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00110712 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsBase.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00056440 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\HookDllPS2.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\office.odf
2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00026232 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00110712 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00029816 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00091768 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll
2012-08-22 22:54 - 2012-06-25 13:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2014-03-05 16:44 - 2014-03-05 16:44 - 01568032 _____ () C:\Program Files (x86)\bfgclient\bfgcommon.dll
2014-01-14 14:29 - 2014-01-14 14:29 - 00059904 _____ () C:\Program Files (x86)\bfgclient\zlib1.dll
2014-01-14 14:27 - 2014-01-14 14:27 - 28768768 _____ () C:\ProgramData\Big Fish\cef\3.1180.823\libcef.dll
2014-12-23 16:54 - 2014-12-23 16:54 - 00338216 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]\nponlinebanking.dll
2014-12-23 16:54 - 2014-12-23 16:54 - 00608040 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]\npvkplugin.dll
2014-12-23 16:54 - 2014-12-23 16:54 - 00502056 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]\npcontentblocker.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:0ACF1AF5
AlternateDataStreams: C:\ProgramData\Temp:0AF6266B
AlternateDataStreams: C:\ProgramData\Temp:0D01FEF7
AlternateDataStreams: C:\ProgramData\Temp:134FBDE2
AlternateDataStreams: C:\ProgramData\Temp:1409277B
AlternateDataStreams: C:\ProgramData\Temp:15E76ABF
AlternateDataStreams: C:\ProgramData\Temp:165AF2C6
AlternateDataStreams: C:\ProgramData\Temp:1968990D
AlternateDataStreams: C:\ProgramData\Temp:1A5207FA
AlternateDataStreams: C:\ProgramData\Temp:1A5CC80A
AlternateDataStreams: C:\ProgramData\Temp:2487D1DA
AlternateDataStreams: C:\ProgramData\Temp:2CB9631F
AlternateDataStreams: C:\ProgramData\Temp:2CED8825
AlternateDataStreams: C:\ProgramData\Temp:3AF262FC
AlternateDataStreams: C:\ProgramData\Temp:3DA71AE7
AlternateDataStreams: C:\ProgramData\Temp:45C55624
AlternateDataStreams: C:\ProgramData\Temp:46CBC45C
AlternateDataStreams: C:\ProgramData\Temp:52329B88
AlternateDataStreams: C:\ProgramData\Temp:5C4A588B
AlternateDataStreams: C:\ProgramData\Temp:5D40B34A
AlternateDataStreams: C:\ProgramData\Temp:61C6B926
AlternateDataStreams: C:\ProgramData\Temp:639BB5E9
AlternateDataStreams: C:\ProgramData\Temp:6641B59F
AlternateDataStreams: C:\ProgramData\Temp:67396145
AlternateDataStreams: C:\ProgramData\Temp:6DDFD746
AlternateDataStreams: C:\ProgramData\Temp:77E239B1
AlternateDataStreams: C:\ProgramData\Temp:7E4E56EA
AlternateDataStreams: C:\ProgramData\Temp:84FA02E7
AlternateDataStreams: C:\ProgramData\Temp:85376176
AlternateDataStreams: C:\ProgramData\Temp:87CA9EF8
AlternateDataStreams: C:\ProgramData\Temp:884C7316
AlternateDataStreams: C:\ProgramData\Temp:89A5891E
AlternateDataStreams: C:\ProgramData\Temp:8B3C3098
AlternateDataStreams: C:\ProgramData\Temp:8C12CFCD
AlternateDataStreams: C:\ProgramData\Temp:97CA3B9E
AlternateDataStreams: C:\ProgramData\Temp:99AC3203
AlternateDataStreams: C:\ProgramData\Temp:9D91E651
AlternateDataStreams: C:\ProgramData\Temp:9DA44E6B
AlternateDataStreams: C:\ProgramData\Temp:A31FAD21
AlternateDataStreams: C:\ProgramData\Temp:A3E34FEB
AlternateDataStreams: C:\ProgramData\Temp:A6A65B80
AlternateDataStreams: C:\ProgramData\Temp:AC83EA04
AlternateDataStreams: C:\ProgramData\Temp:B059B88E
AlternateDataStreams: C:\ProgramData\Temp:B9F8237A
AlternateDataStreams: C:\ProgramData\Temp:C36F1B98
AlternateDataStreams: C:\ProgramData\Temp:C69BA1D0
AlternateDataStreams: C:\ProgramData\Temp:CA400C1B
AlternateDataStreams: C:\ProgramData\Temp:CB959782
AlternateDataStreams: C:\ProgramData\Temp:CC386FD2
AlternateDataStreams: C:\ProgramData\Temp:D01ACC06
AlternateDataStreams: C:\ProgramData\Temp:D1713795
AlternateDataStreams: C:\ProgramData\Temp:D3A82449
AlternateDataStreams: C:\ProgramData\Temp:D5CCCBAA
AlternateDataStreams: C:\ProgramData\Temp:D92485C9
AlternateDataStreams: C:\ProgramData\Temp:DCA79AB3
AlternateDataStreams: C:\ProgramData\Temp:E153075C
AlternateDataStreams: C:\ProgramData\Temp:E2295807
AlternateDataStreams: C:\ProgramData\Temp:E5BA9ADD
AlternateDataStreams: C:\ProgramData\Temp:E6537A16
AlternateDataStreams: C:\ProgramData\Temp:ED6B6C83
AlternateDataStreams: C:\ProgramData\Temp:F72306CC
AlternateDataStreams: C:\ProgramData\Temp:F7581CE6
AlternateDataStreams: C:\ProgramData\Temp:F7B0AE93
AlternateDataStreams: C:\ProgramData\Temp:FBFC061F
AlternateDataStreams: C:\ProgramData\Temp:FC2E567F

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4204859643-4009438992-3315869148-1001\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\Samsung\Samsung_wallpaper.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: HostManager => C:\Program Files (x86)\Common Files\AOL\1356813129\ee\AOLSoftware.exe
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
HKLM\…\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\…\StartupApproved\Run: => "BtTray"
HKLM\…\StartupApproved\Run: => "RtHDVCpl"
HKLM\…\StartupApproved\Run: => "ETDCtrl"
HKLM\…\StartupApproved\Run32: => "Adobe ARM"
HKLM\…\StartupApproved\Run32: => "Adobe Reader Speed Launcher"
HKLM\…\StartupApproved\Run32: => "BCSSync"
HKLM\…\StartupApproved\Run32: => "RemoteControl10"
HKLM\…\StartupApproved\Run32: => "Intel AppUp(SM) center"
HKLM\…\StartupApproved\Run32: => "HostManager"
HKLM\…\StartupApproved\Run32: => "CLMLServer_For_P2G8"
HKLM\…\StartupApproved\Run32: => "CLVirtualDrive"
HKLM\…\StartupApproved\Run32: => "ETDCtrl"
HKLM\…\StartupApproved\Run32: => "fst_us_210"
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\StartupApproved\Run: => "Browser Infrastructure Helper"
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\StartupApproved\Run: => "AOL Fast Start"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{1C944511-C752-4493-B77A-157665E1C1C1}C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{CA550F8B-40AF-4A39-8732-ED60339734C9}C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{2BE51C0E-67C3-4554-A77B-A9910CF7D8A0}] => (Allow) C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{C912F999-8FBD-48DF-856C-9194469551B3}] => (Allow) C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{C584D5A0-0A75-4296-BC02-98DD649035FA}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe
FirewallRules: [{3A46C0B8-F73A-41E3-A45C-78A1A66D8AC4}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe
FirewallRules: [{2177685B-3B42-4E3D-B6EB-BE9BFDF89B32}] => (Allow) C:\Program Files (x86)\Common Files\AOL\System Information\sinf.exe
FirewallRules: [{ED1A5EF6-F1D7-45AE-98FC-BB52831D4916}] => (Allow) C:\Program Files (x86)\Common Files\AOL\System Information\sinf.exe
FirewallRules: [{57969852-6B9E-422E-B61D-96414191AF03}] => (Allow) C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe
FirewallRules: [{30915F87-7117-4739-853A-DEC7D0E7E21E}] => (Allow) C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe
FirewallRules: [{35D40D3A-430E-4702-89F4-6F7AA94E5226}] => (Allow) C:\Program Files (x86)\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{D771DC33-51D7-4A46-98D8-9A519549C5B2}] => (Allow) C:\Program Files (x86)\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{7835419C-0960-418B-8D70-2B0D44F8E1F3}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\waol.exe
FirewallRules: [{5813D3CA-B66F-44BF-AC77-A1264147028C}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\waol.exe
FirewallRules: [{EFEF65F3-EDFE-41D7-BD10-07C7B515BE57}] => (Allow) C:\Program Files (x86)\Common Files\AOL\1356813129\ee\aolsoftware.exe
FirewallRules: [{E3B67B5A-981A-4050-9981-40EAF70EFB0B}] => (Allow) C:\Program Files (x86)\Common Files\AOL\1356813129\ee\aolsoftware.exe
FirewallRules: [{76CBB1F3-68DA-4EEE-9312-BCD48395B1A1}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
FirewallRules: [{8B6C5983-23C6-4F9A-B86B-315874CCF55E}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
FirewallRules: [{CAF94027-B948-40D0-B2DA-9911DF3B57C6}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLDial.exe
FirewallRules: [{067EF64B-B79E-4E0A-85E3-913525CF530C}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLDial.exe
FirewallRules: [{C9BE8101-F480-4219-8D33-18631D9DAC83}] => (Allow) LPort=1900
FirewallRules: [{AC9085FB-C7DC-475E-83BD-2C4D8042D93C}] => (Allow) LPort=2869
FirewallRules: [{8B2EFA22-CB98-4A8F-868A-7808AC8BC521}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{B8732F72-F9D9-4596-8C03-073046CB1499}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{E13E5F9C-E7EB-48DB-BD40-A0E0C9890A29}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{ADC11769-653B-4AC1-8A43-CF7D98CE434B}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{4DABB302-3070-48FA-A239-8D9FB5755AA8}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{8DF1A401-119B-4D12-B731-D8C994E05C25}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{AEA6A349-7612-4EAC-961D-669F5BE63A11}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{439983AA-B322-47B5-A703-CE00E2685F24}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{6A8764C7-0C43-4328-B3D5-1CE6F11F2F67}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/25/2015 06:24:10 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: ntdll.dll, version: 6.3.9600.17936, time stamp: 0x55a68dd1
Exception code: 0xc0000005
Fault offset: 0x00040fb2
Faulting process id: 0xf08
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5

Error: (08/25/2015 06:23:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: ntdll.dll, version: 6.3.9600.17936, time stamp: 0x55a68dd1
Exception code: 0xc0000005
Fault offset: 0x00040fb2
Faulting process id: 0x17f4
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5

Error: (08/25/2015 01:01:05 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 40.0.2.5702, time stamp: 0x55cc03bd
Faulting module name: mozglue.dll, version: 40.0.2.5702, time stamp: 0x55cbf190
Exception code: 0x80000003
Fault offset: 0x0000e631
Faulting process id: 0x43c
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Faulting package full name: plugin-container.exe4
Faulting package-relative application ID: plugin-container.exe5

Error: (08/25/2015 01:01:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 40.0.2.5702, time stamp: 0x55cc03bd
Faulting module name: mozglue.dll, version: 40.0.2.5702, time stamp: 0x55cbf190
Exception code: 0x80000003
Fault offset: 0x0000e631
Faulting process id: 0x37c
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Faulting package full name: plugin-container.exe4
Faulting package-relative application ID: plugin-container.exe5

Error: (08/25/2015 01:00:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 40.0.2.5702, time stamp: 0x55cc03bd
Faulting module name: mozglue.dll, version: 40.0.2.5702, time stamp: 0x55cbf190
Exception code: 0x80000003
Fault offset: 0x0000e631
Faulting process id: 0x1b34
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Faulting package full name: plugin-container.exe4
Faulting package-relative application ID: plugin-container.exe5

Error: (08/24/2015 09:38:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Exception code: 0xc0000005
Fault offset: 0x001f804f
Faulting process id: 0x14e0
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5

Error: (08/24/2015 01:01:14 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 40.0.2.5702, time stamp: 0x55cc03bd
Faulting module name: mozglue.dll, version: 40.0.2.5702, time stamp: 0x55cbf190
Exception code: 0x80000003
Fault offset: 0x0000e631
Faulting process id: 0x1acc
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Faulting package full name: plugin-container.exe4
Faulting package-relative application ID: plugin-container.exe5

Error: (08/24/2015 01:01:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 40.0.2.5702, time stamp: 0x55cc03bd
Faulting module name: mozglue.dll, version: 40.0.2.5702, time stamp: 0x55cbf190
Exception code: 0x80000003
Fault offset: 0x0000e631
Faulting process id: 0x1a54
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Faulting package full name: plugin-container.exe4
Faulting package-relative application ID: plugin-container.exe5

Error: (08/24/2015 01:01:08 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 40.0.2.5702, time stamp: 0x55cc03bd
Faulting module name: mozglue.dll, version: 40.0.2.5702, time stamp: 0x55cbf190
Exception code: 0x80000003
Fault offset: 0x0000e631
Faulting process id: 0x700
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Faulting package full name: plugin-container.exe4
Faulting package-relative application ID: plugin-container.exe5

Error: (08/23/2015 10:00:15 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 40.0.2.5702, time stamp: 0x55cc03bd
Faulting module name: mozglue.dll, version: 40.0.2.5702, time stamp: 0x55cbf190
Exception code: 0x80000003
Fault offset: 0x0000e631
Faulting process id: 0xa64
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Faulting package full name: plugin-container.exe4
Faulting package-relative application ID: plugin-container.exe5


System errors:
=============
Error: (08/25/2015 04:07:41 AM) (Source: DCOM) (EventID: 10010) (User: CarlasPC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (08/25/2015 04:07:01 AM) (Source: DCOM) (EventID: 10010) (User: CarlasPC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (08/24/2015 06:24:34 AM) (Source: DCOM) (EventID: 10010) (User: CarlasPC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (08/24/2015 06:24:02 AM) (Source: DCOM) (EventID: 10010) (User: CarlasPC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (08/23/2015 06:56:44 AM) (Source: DCOM) (EventID: 10010) (User: CarlasPC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (08/23/2015 06:56:14 AM) (Source: DCOM) (EventID: 10010) (User: CarlasPC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (08/22/2015 04:36:45 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (08/22/2015 06:40:21 AM) (Source: DCOM) (EventID: 10010) (User: CarlasPC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (08/22/2015 06:39:46 AM) (Source: DCOM) (EventID: 10010) (User: CarlasPC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (08/21/2015 11:49:42 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The NVIDIA Update Service Daemon service hung on starting.


Microsoft Office:
=========================
Error: (08/25/2015 06:24:10 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91ntdll.dll6.3.9600.1793655a68dd1c000000500040fb2f0801d0df28804dc456C:\Program Files (x86)\bfgclient\bfgclient.exeC:\WINDOWS\SYSTEM32\ntdll.dllcdf4b109-4b1b-11e5-bf82-50b7c33d372b

Error: (08/25/2015 06:23:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91ntdll.dll6.3.9600.1793655a68dd1c000000500040fb217f401d0dedf1a702b49C:\Program Files (x86)\bfgclient\bfgclient.exeC:\WINDOWS\SYSTEM32\ntdll.dlla50081ff-4b1b-11e5-bf82-50b7c33d372b

Error: (08/25/2015 01:01:05 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.2.570255cc03bdmozglue.dll40.0.2.570255cbf190800000030000e63143c01d0deb6fc84056aC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dllabc3593a-4aee-11e5-bf82-50b7c33d372b

Error: (08/25/2015 01:01:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.2.570255cc03bdmozglue.dll40.0.2.570255cbf190800000030000e63137c01d0deb6fbe90a22C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dlla8b45d6c-4aee-11e5-bf82-50b7c33d372b

Error: (08/25/2015 01:00:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.2.570255cc03bdmozglue.dll40.0.2.570255cbf190800000030000e6311b3401d0deb6fa7778b6C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dlla6475463-4aee-11e5-bf82-50b7c33d372b

Error: (08/24/2015 09:38:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91bfgclient.exe3.3.0.253179a91c0000005001f804f14e001d0dedf16585e1bC:\Program Files (x86)\bfgclient\bfgclient.exeC:\Program Files (x86)\bfgclient\bfgclient.exe6570165e-4ad2-11e5-bf82-50b7c33d372b

Error: (08/24/2015 01:01:14 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.2.570255cc03bdmozglue.dll40.0.2.570255cbf190800000030000e6311acc01d0ddb46cd37087C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll86968f95-4a25-11e5-bf82-50b7c33d372b

Error: (08/24/2015 01:01:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.2.570255cc03bdmozglue.dll40.0.2.570255cbf190800000030000e6311a5401d0ddb46c636083C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll858de70f-4a25-11e5-bf82-50b7c33d372b

Error: (08/24/2015 01:01:08 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.2.570255cc03bdmozglue.dll40.0.2.570255cbf190800000030000e63170001d0ddb46b8f49aaC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll82bb74f6-4a25-11e5-bf82-50b7c33d372b

Error: (08/23/2015 10:00:15 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.2.570255cc03bdmozglue.dll40.0.2.570255cbf190800000030000e631a6401d0ddb08978cdc9C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dlla885b068-49a7-11e5-bf82-50b7c33d372b


CodeIntegrity:
===================================
  Date: 2015-05-12 12:25:00.726
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-12 12:24:59.904
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-12 12:24:56.339
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-09 19:00:37.871
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-09 19:00:36.384
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-09 19:00:34.739
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-04-22 22:00:33.049
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-04-22 22:00:32.407
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-04-22 22:00:31.725
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-04-22 22:00:29.965
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Pentium(R) CPU B950 @ 2.10GHz
Percentage of memory in use: 63%
Total physical RAM: 3795.54 MB
Available physical RAM: 1366.65 MB
Total Virtual: 4819.54 MB
Available Virtual: 1710.63 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:439.91 GB) (Free:306.37 GB) NTFS
Drive d: () (CDROM) (Total:0.53 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: B0418F27)

Partition: GPT.

==================== End of FRST.txt ============================

Hello, Curie is on vacation, so I will be assisting until she returns:

Download attached fixlist.txt file and save it to the Desktop\KevinStuff folder

NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

 

📎FixList.txt

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST/FRST64 and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

NEXT


CHR dev: Chrome dev build detected! <======= ATTENTION

 


Please uninstall Chrome and re-install it, having it installed in dev build opens the program up to exploitation (there is a box that requires unchecking > so watch for this)

 

NEXT

 

Please advise how the computer is running now and if there are any outstanding issues.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI