[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Storage Appliance Corp.) C:\ProgramData\OfficeGuardianV2\UACProxy.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Acer Incorporated) C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
() C:\Program Files (x86)\Livedrive\VSSService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe
(ThreatTrack Security, Inc.) C:\Program Files (x86)\VIPRE\SBPIMSvc.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
(Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Skillbrains) C:\Users\Matts Windows7\AppData\Local\Skillbrains\lightshot\5.1.4.41\Lightshot.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Dropbox, Inc.) C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(ThreatTrack Security, Inc.) C:\Program Files (x86)\VIPRE\SBAMSvc.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\DataProxy.exe
(ThreatTrack Security, Inc.) C:\Program Files (x86)\VIPRE\SBAMTray.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel(R) Corporation)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2280232 2010-07-29] (Synaptics Incorporated)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11785832 2011-03-10] (Realtek Semiconductor)
HKLM\…\Run: [Power Management] => C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe [1796200 2011-02-23] (Acer Incorporated)
HKLM\…\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
HKLM\…\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [281776 2014-09-16] (Samsung Electronics Co., Ltd.)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\…\Run: [SBAMTray] => C:\Program Files (x86)\VIPRE\SBAMTray.exe [3216272 2013-09-05] (ThreatTrack Security, Inc.)
HKLM-x32\…\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2620728 2015-07-22] (Malwarebytes Corporation)
HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22344224 2015-07-29] (Google)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [LightShot] => C:\Users\Matts Windows7\AppData\Local\Skillbrains\lightshot\Lightshot.exe [226560 2014-07-01] ()
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [OneDrive] => C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\OneDrive.exe [404064 2015-08-20] (Microsoft Corporation)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [Dropbox Update] => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-15] (Dropbox, Inc.)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3903056 2015-05-20] (Tonec Inc.)
AppInit_DLLs: C:\Windows\System32\acaptuser64.dll => C:\Windows\System32\acaptuser64.dll [119160 2008-06-12] (Adobe Systems, Inc.)
AppInit_DLLs-x32: C:\PROGRA~2\Citrix\ICACLI~1\RSHook.dll => C:\Program Files (x86)\Citrix\ICA Client\RSHook.dll [257208 2012-05-23] (Citrix Systems, Inc.)
AppInit_DLLs-x32: acaptuser32.dll => "acaptuser32.dll" File not found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2014-08-09]
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-02-12]
ShortcutTarget: Dropbox.lnk -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [BackupOverlay] -> {B44A5D93-1351-41A1-BD91-5E92435D8ECD} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll [2012-11-10] (EldoS Corporation)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2014-04-21] (Tonec Inc.)
ShellIconOverlayIdentifiers: [LivedriveDownloadOverlay] -> {CBCDB610-6B68-4EE9-B7A2-1282FD0C9292} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveSharedOverlay] -> {84CEF1E4-1356-4063-845F-05047F4DD52C} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveSyncedOverlay] -> {42058329-2FBF-4B33-8E52-3BE5754DE0C1} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveUploadOverlay] -> {39A1715A-E4CD-4F1E-B5C4-36B5DB80124E} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll [2012-11-10] (EldoS Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000 -> DefaultScope {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08] (Adobe Systems Incorporated)
BHO-x32: CmjBrowserHelperObject Object -> {6FE6A929-59D1-4763-91AD-29B61CFFB35B} -> C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll [2011-09-14] (Mindjet)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-08-18] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: VIPRE Search Guard Helper -> {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} -> C:\Program Files (x86)\VIPRE\VSG.dll [2013-09-05] ()
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Lexmark Printable Web -> {D2C5E510-BE6D-42CC-9F61-E4F939078474} -> C:\Program Files\Lexmark Printable Web\bho.dll [2010-02-04] ()
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-18] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - C:\Program Files (x86)\VIPRE\VSG.dll [2013-09-05] ()
Toolbar: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} hxxps://fiserventerprise.webex.com/client/WBXclient-T27L10NSP32EP5-14362/support/ieatgpc1.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler-x32: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - C:\Program Files (x86)\VIPRE\VSG.dll [2013-09-05] ()
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{12A99469-5D32-4F0D-A147-834FA18A0312}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{74A46DCB-14BB-4752-B3FB-9562D1C5B0B1}: [NameServer] 192.168.1.254
Tcpip\..\Interfaces\{74A46DCB-14BB-4752-B3FB-9562D1C5B0B1}: [DhcpNameServer] 10.251.4.1
FireFox:
========
FF ProfilePath: C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default
FF Homepage: hxxps://www.google.com/
FF NetworkProxy: "gopher", ""
FF NetworkProxy: "gopher_port", 0
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-11] ()
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2014-08-09] (LastPass)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2013-03-21] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-11] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2012-05-23] (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-18] (Oracle Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass.dll [2014-08-09] (LastPass)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2013-03-21] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Matts Windows7\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2013-05-29] (Citrix Online)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Matts Windows7\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @talk.google.com/O1DPlugin -> C:\Users\Matts Windows7\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Matts Windows7\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Matts Windows7\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Extension: FoxyProxy Standard - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2015-06-02]
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2015-08-19]
FF Extension: LastPass - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2015-07-22]
FF Extension: SeoQuake - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74} [2015-06-05]
FF Extension: ColorZilla - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2015-05-28]
FF Extension: iMacros for Firefox - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2015-05-29]
FF Extension: Live HTTP headers - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2015-05-28]
FF Extension: Firebug - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2012-01-12]
FF Extension: VTzilla - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2012-01-12]
FF Extension: HMA! IP Checker - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2013-12-23]
FF Extension: SpyBar - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2015-08-06]
FF Extension: Multi Links - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2014-11-13]
FF Extension: Real Hide IP - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2012-04-28]
FF Extension: S3 Firefox Organizer(S3Fox) - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{7CEA821D-3DAB-4238-B424-BF7324531750}.xpi [2014-01-10]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2014-03-12]
FF Extension: Video DownloadHelper - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-08-23]
FF Extension: Web Developer - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2014-02-03]
FF Extension: Adblock Plus - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-18]
FF Extension: SearchStatus - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{d57c9ff1-6389-48fc-b770-f78bd89b6e8a}.xpi [2014-11-13]
FF Extension: Adblock Edge - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2015-08-25]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-20]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-20]
FF HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Matts Windows7\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Matts Windows7\AppData\Roaming\IDM\idmmzcc5 [2015-08-25]
FF HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\Matts Windows7\AppData\Roaming\IDM\idmmzcc5
Chrome:
=======
CHR Profile: C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-22]
CHR Extension: (Google Docs) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-01]
CHR Extension: (Google Drive) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-01]
CHR Extension: (YouTube) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-01]
CHR Extension: (Precise Interest Profits) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cboffagmdlncaldokfebdghmcfnloffa [2014-06-06]
CHR Extension: (Adblock Plus) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-10-21]
CHR Extension: (Google Search) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-01]
CHR Extension: (SpyBar) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkcihmjnfimlnmdjoddhjfiihbfpcnfk [2014-06-03]
CHR Extension: (Block site) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimnmioipafcokbfikbljfdeojpcgbh [2015-05-28]
CHR Extension: (FB Pixel Helper) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdgfkebogiimcoedlicjlajpkdmockpc [2014-07-04]
CHR Extension: (Google Sheets) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-22]
CHR Extension: (Audience Intersect) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjeffkdcbmggkbkedhbjemcpmgfccpil [2014-10-10]
CHR Extension: (Video Downloader Super) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghciphhakbampjemlfbahnhhaemoeolf [2015-02-16]
CHR Extension: (Follow) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkakfimgbmogkpmjokgnbbanmmemcdij [2014-06-26]
CHR Extension: (Pin It Button) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-08-18]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2015-08-13]
CHR Extension: (Video Downloader) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnmpgleggfcndpeflbjhpjfckfmojnpo [2015-02-10]
CHR Extension: (SocialPinSniper) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\llfojbapbcelaoniflkhioicjmlpileg [2015-02-14]
CHR Extension: (Sunrise Calendar) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\mojepfklcankkmikonjlnidiooanmpbb [2015-08-18]
CHR Extension: (EXIF Viewer) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafpfdcmppffipmhcpkbplhkoiekndck [2015-07-27]
CHR Extension: (IDM Integration Module) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-07-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-01]
CHR Extension: (Docs PDF/PowerPoint Viewer (by Google)) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbmlagghjjcbdhgmkedmbmedengocbn [2014-02-01]
CHR Extension: (Pingler) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgiehjnopebofbjkgdjenflakfaahnm [2014-12-22]
CHR Extension: (Gmail) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-01]
CHR Extension: (Headlinr) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\plhlpcokjhajajgmpbapiohjhldkjdbi [2015-05-07]
CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
CHR HKLM-x32\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService8; C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [814880 2015-04-03] (IObit)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-03-13] (BlueStack Systems, Inc.)
S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-03-13] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [770832 2014-03-13] (BlueStack Systems, Inc.)
R2 CFUACProxy_officeguardianv2; C:\ProgramData\OfficeGuardianV2\UACProxy.exe [83792 2011-07-25] (Storage Appliance Corp.)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [878912 2015-04-02] (IObit)
R2 LivedriveVSSService; C:\Program Files (x86)\Livedrive\VSSService.exe [210584 2014-07-24] ()
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-30] (IObit)
S4 lxduCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\lxduserv.exe [29184 2009-10-16] (Lexmark International, Inc.)
S4 lxdu_device; C:\Windows\system32\lxducoms.exe [1039360 2009-10-16] ( )
S4 lxdu_device; C:\Windows\SysWOW64\lxducoms.exe [589824 2009-10-16] ( )
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [713016 2015-07-22] (Malwarebytes Corporation)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
R2 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2011-01-31] (Nalpeiron Ltd.) [File not signed]
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe [256536 2012-01-05] (NTI Corporation)
S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe [244904 2010-10-27] () [File not signed]
R2 SamsungRapidSvc; C:\Windows\System32\RAPID\SamsungRapidSvc.exe [28848 2014-09-16] (Samsung Electronics Co., Ltd.)
R2 SBAMSvc; C:\Program Files (x86)\VIPRE\SBAMSvc.exe [3937472 2013-09-05] (ThreatTrack Security, Inc.)
R2 SBPIMSvc; C:\Program Files (x86)\VIPRE\SBPIMSvc.exe [176016 2013-09-05] (ThreatTrack Security, Inc.)
S4 SpliCamService; C:\Program Files (x86)\SplitCam\SplitCamService.exe [311424 2014-09-15] (SplitCam Co.)
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [121616 2014-03-13] (BlueStack Systems)
S3 catchme; no ImagePath
R3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [352008 2012-11-10] (EldoS Corporation)
S3 cpudrv64; C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [17864 2011-06-02] ()
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [63064 2015-07-22] ()
S4 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2015-03-25] (IObit)
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
S3 gfiutil; C:\Windows\System32\drivers\gfiutil.sys [31264 2013-09-04] (ThreatTrack Security)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-03-01] (REALiX™)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-08-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
R3 NETwNs64; C:\Windows\System32\DRIVERS\NETwsw01.sys [11534096 2015-08-11] (Intel Corporation)
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2015-03-25] (IObit.com)
R0 SamsungRapidDiskFltr; C:\Windows\System32\DRIVERS\SamsungRapidDiskFltr.sys [268976 2014-09-16] (Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\Windows\System32\DRIVERS\SamsungRapidFSFltr.sys [111280 2014-09-16] (Samsung Electronics Co., Ltd.)
R2 sbapifs; C:\Windows\System32\DRIVERS\sbapifs.sys [88928 2013-06-18] (ThreatTrack Security, Inc.)
S1 SBRE; no ImagePath
R3 scvad_simple; C:\Windows\System32\drivers\SplitCamAudio.sys [23552 2014-06-30] (Windows (R) Win 7 DDK provider)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
R3 splitcam_hd_driver; C:\Windows\System32\DRIVERS\splitcam_hd_driver.sys [37496 2014-06-30] (Windows (R) Win 7 DDK provider)
R3 stdpms; C:\Windows\System32\DRIVERS\stdpms.sys [28904 2013-10-22] (Splashtop Inc.)
S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2015-03-25] (IObit.com)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-25 21:19 - 2015-08-25 21:20 - 00047942 _____ C:\Users\Matts Windows7\Desktop\FRST.txt
2015-08-25 21:16 - 2015-08-25 21:16 - 02186752 _____ (Farbar) C:\Users\Matts Windows7\Desktop\FRST64.exe
2015-08-25 21:01 - 2015-08-25 21:01 - 00001885 _____ C:\AdwCleaner[C11].txt
2015-08-25 20:56 - 2015-08-25 20:57 - 00001688 _____ C:\AdwCleaner[S21].txt
2015-08-25 20:35 - 2015-08-25 20:35 - 00000000 ___HD C:\OneDriveTemp
2015-08-25 16:05 - 2015-08-25 16:05 - 00000209 _____ C:\Users\Matts Windows7\Desktop\ASAP go.txt
2015-08-25 15:18 - 2015-08-25 16:06 - 00000000 ____D C:\Users\Matts Windows7\Desktop\The Clarity Program
2015-08-25 14:48 - 2015-08-25 21:10 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Virus protection
2015-08-25 11:59 - 2015-08-25 12:41 - 00000000 __RHD C:\ESD
2015-08-25 11:58 - 2012-04-15 09:50 - 330471842 _____ C:\Users\Matts Windows7\Desktop\GRAND PALMS.avi
2015-08-24 14:02 - 2015-08-24 16:38 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Fit Pros Swipes
2015-08-24 11:05 - 2015-08-25 21:01 - 00000448 _____ C:\Windows\setupact.log
2015-08-24 11:05 - 2015-08-24 11:05 - 00000548 _____ C:\Windows\PFRO.log
2015-08-24 11:05 - 2015-08-24 11:05 - 00000000 _____ C:\Windows\setuperr.log
2015-08-23 18:20 - 2015-08-24 18:27 - 00000249 _____ C:\Users\Matts Windows7\Desktop\Do and Read.txt
2015-08-21 18:03 - 2015-08-21 18:03 - 00001497 _____ C:\Users\Matts Windows7\Desktop\Schema-Swipe-File.txt
2015-08-21 17:29 - 2015-08-21 17:34 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Superfood PLR + OTO
2015-08-21 14:58 - 2015-08-21 14:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-21 10:39 - 2015-08-21 10:39 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 01632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 00115136 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-08-21 10:39 - 2015-08-21 10:39 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 05568960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 03989952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 03934656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01390592 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-08-21 10:38 - 2015-08-21 10:38 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-08-21 10:38 - 2015-08-21 10:38 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-08-21 10:38 - 2015-08-21 10:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-08-21 10:38 - 2015-08-21 10:38 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-08-21 10:38 - 2015-08-21 10:38 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-08-21 10:36 - 2015-08-21 10:36 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-08-21 10:36 - 2015-08-21 10:36 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-08-20 23:57 - 2015-08-20 23:57 - 00000000 ____H C:\Users\Matts Windows7\Documents\Default.rdp
2015-08-20 21:50 - 2015-08-20 21:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-20 21:34 - 2015-08-20 21:34 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\Social_Multiplier
2015-08-20 21:32 - 2015-08-20 21:32 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SocialMultiplier
2015-08-20 21:32 - 2015-08-20 21:32 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\SkinSoft
2015-08-20 21:32 - 2015-08-20 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SocialMultiplier
2015-08-20 21:31 - 2015-08-20 21:32 - 00000000 ____D C:\Program Files (x86)\SocialMultiplier
2015-08-19 12:11 - 2015-08-19 12:20 - 00000000 ____D C:\ProgramData\flipBook
2015-08-19 12:11 - 2015-08-19 12:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flip PDF
2015-08-19 12:11 - 2015-08-19 12:11 - 00000000 ____D C:\ProgramData\A-PDF
2015-08-19 12:11 - 2015-08-19 12:11 - 00000000 ____D C:\Program Files (x86)\Flip PDF
2015-08-19 10:39 - 2015-08-20 20:16 - 00002932 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Matts_Windows7
2015-08-19 10:38 - 2015-08-25 21:02 - 00002902 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (Matts Windows7)
2015-08-19 10:38 - 2015-08-19 10:38 - 00003260 _____ C:\Windows\System32\Tasks\Driver Booster Scan
2015-08-19 10:38 - 2015-08-19 10:38 - 00003204 _____ C:\Windows\System32\Tasks\Driver Booster Update
2015-08-19 10:38 - 2015-08-19 10:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2
2015-08-19 09:53 - 2015-08-10 21:20 - 25191936 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-19 09:53 - 2015-08-10 21:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-19 09:53 - 2015-08-10 20:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-08-19 09:53 - 2015-08-10 20:20 - 19871232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-08-18 23:58 - 2015-08-21 10:25 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\ProductData
2015-08-18 23:58 - 2015-08-20 20:16 - 00000000 ____D C:\ProgramData\ProductData
2015-08-18 21:13 - 2015-08-18 21:13 - 00000000 ___SD C:\ComboFix
2015-08-18 18:47 - 2015-08-18 18:47 - 00281232 _____ C:\Windows\Minidump\081815-6957-01.dmp
2015-08-18 18:08 - 2015-08-18 18:08 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Sun
2015-08-18 18:08 - 2015-08-18 18:08 - 00000000 ____D C:\Users\Matts Windows7\.oracle_jre_usage
2015-08-18 17:28 - 2015-08-18 18:47 - 2085089726 _____ C:\Windows\MEMORY.DMP
2015-08-18 17:28 - 2015-08-18 17:28 - 00284984 _____ C:\Windows\Minidump\081815-8080-01.dmp
2015-08-18 11:02 - 2015-08-18 11:02 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-18 09:47 - 2015-08-18 09:49 - 134128457 _____ C:\Users\Matts Windows7\Desktop\May 7th Webinar Replay.MP4
2015-08-17 13:33 - 2008-04-07 06:38 - 00051032 ____R (Adobe Systems Inc) C:\Windows\system32\AdobePDF.dll
2015-08-17 13:33 - 2008-04-07 06:38 - 00024416 ____R (Adobe Systems Inc.) C:\Windows\system32\AdobePDFUI.dll
2015-08-17 12:32 - 2015-08-20 23:50 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Social Multiplier
2015-08-17 01:56 - 2015-08-17 01:56 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Element 3D V2.2.0.2100 (Win)
2015-08-16 00:44 - 2015-08-17 18:17 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Social Video Formula
2015-08-16 00:05 - 2015-08-16 00:06 - 00000894 _____ C:\AdwCleaner[S20].txt
2015-08-15 23:56 - 2015-08-15 23:56 - 00067456 _____ C:\ComboFix.txt
2015-08-15 23:09 - 2011-06-26 02:45 - 00256000 _____ C:\Windows\PEV.exe
2015-08-15 23:09 - 2010-11-07 13:20 - 00208896 _____ C:\Windows\MBR.exe
2015-08-15 23:09 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00098816 _____ C:\Windows\sed.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00080412 _____ C:\Windows\grep.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00068096 _____ C:\Windows\zip.exe
2015-08-15 23:08 - 2015-08-18 21:13 - 00000000 ____D C:\Qoobox
2015-08-15 23:07 - 2015-08-15 23:45 - 00000000 ____D C:\Windows\erdnt
2015-08-15 22:54 - 2015-08-15 22:54 - 00001083 _____ C:\AdwCleaner[C10].txt
2015-08-15 22:52 - 2015-08-15 22:53 - 00000900 _____ C:\AdwCleaner[S19].txt
2015-08-15 22:44 - 2015-08-15 22:44 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\LavasoftStatistics
2015-08-15 22:43 - 2015-08-15 22:43 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2015-08-15 22:37 - 2015-08-15 22:37 - 00000000 ____D C:\ProgramData\Lavasoft
2015-08-15 22:29 - 2015-08-15 22:33 - 00000000 ____D C:\AdwCleaner
2015-08-14 19:38 - 2015-08-14 19:38 - 00000027 _____ C:\Users\Matts Windows7\Desktop\BUY.txt
2015-08-14 19:01 - 2015-08-14 19:02 - 41019438 _____ C:\Users\Matts Windows7\Desktop\Element 3D V2.2 Crack.mp4
2015-08-14 18:19 - 2015-08-14 18:44 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Digital Profits Academy
2015-08-13 13:55 - 2015-08-13 13:55 - 00000060 _____ C:\Users\Matts Windows7\Desktop\DOOOOOOOOOOOOOOOO.txt
2015-08-12 17:34 - 2015-07-30 09:13 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 17:34 - 2015-07-30 09:13 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 16:41 - 2015-08-12 16:41 - 00001057 _____ C:\Users\Matts Windows7\Desktop\[BBHF VIP Sachin's Cracked] Long Tail Pro Platinum 3.0.11 Updated.txt
2015-08-12 16:34 - 2015-08-23 22:23 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Immersion Session 3
2015-08-12 13:53 - 2015-07-28 16:09 - 00017344 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-08-12 13:53 - 2015-07-28 16:05 - 01116672 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00774656 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00743424 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00437760 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-08-12 13:53 - 2015-07-28 15:55 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-08-12 13:53 - 2015-07-15 14:15 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-12 13:53 - 2015-07-15 14:10 - 01743360 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-12 13:52 - 2015-07-20 20:39 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-12 13:52 - 2015-07-20 20:12 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-08-12 13:52 - 2015-07-16 16:54 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-08-12 13:52 - 2015-07-16 16:37 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-08-12 13:52 - 2015-07-16 16:36 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-12 13:52 - 2015-07-16 16:36 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-12 13:52 - 2015-07-16 16:36 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-08-12 13:52 - 2015-07-16 16:35 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-12 13:52 - 2015-07-16 16:35 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-08-12 13:52 - 2015-07-16 16:27 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-12 13:52 - 2015-07-16 16:26 - 05923328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-12 13:52 - 2015-07-16 16:26 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-08-12 13:52 - 2015-07-16 16:23 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-12 13:52 - 2015-07-16 16:21 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-12 13:52 - 2015-07-16 16:21 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-08-12 13:52 - 2015-07-16 16:21 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-12 13:52 - 2015-07-16 16:21 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-08-12 13:52 - 2015-07-16 16:12 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-12 13:52 - 2015-07-16 16:08 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-12 13:52 - 2015-07-16 16:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-12 13:52 - 2015-07-16 15:55 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-08-12 13:52 - 2015-07-16 15:54 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-12 13:52 - 2015-07-16 15:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-08-12 13:52 - 2015-07-16 15:51 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-12 13:52 - 2015-07-16 15:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-08-12 13:52 - 2015-07-16 15:50 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-08-12 13:52 - 2015-07-16 15:50 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-08-12 13:52 - 2015-07-16 15:49 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-08-12 13:52 - 2015-07-16 15:45 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-08-12 13:52 - 2015-07-16 15:43 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-08-12 13:52 - 2015-07-16 15:43 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-08-12 13:52 - 2015-07-16 15:41 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-08-12 13:52 - 2015-07-16 15:39 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-08-12 13:52 - 2015-07-16 15:39 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-08-12 13:52 - 2015-07-16 15:38 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-08-12 13:52 - 2015-07-16 15:36 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-12 13:52 - 2015-07-16 15:35 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-08-12 13:52 - 2015-07-16 15:34 - 14451200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-12 13:52 - 2015-07-16 15:33 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-08-12 13:52 - 2015-07-16 15:32 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-12 13:52 - 2015-07-16 15:29 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-08-12 13:52 - 2015-07-16 15:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-12 13:52 - 2015-07-16 15:20 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-08-12 13:52 - 2015-07-16 15:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-08-12 13:52 - 2015-07-16 15:17 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-08-12 13:52 - 2015-07-16 15:12 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-08-12 13:52 - 2015-07-16 15:12 - 02427904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-12 13:52 - 2015-07-16 15:10 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-08-12 13:52 - 2015-07-16 15:06 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-08-12 13:52 - 2015-07-16 15:06 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-08-12 13:52 - 2015-07-16 15:05 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-08-12 13:52 - 2015-07-16 15:01 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-12 13:52 - 2015-07-16 14:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-08-12 13:52 - 2015-07-16 14:42 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-08-12 13:52 - 2015-07-16 14:38 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-08-12 13:52 - 2015-07-16 14:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-08-12 13:52 - 2015-07-14 23:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-08-12 13:51 - 2015-07-30 13:55 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-08-12 13:51 - 2015-07-30 12:56 - 03208192 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-12 13:51 - 2015-07-30 12:52 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-12 13:51 - 2015-07-30 12:49 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-08-12 13:51 - 2015-07-14 23:19 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-12 13:51 - 2015-07-14 23:19 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-12 13:51 - 2015-07-14 23:14 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-08-12 13:51 - 2015-07-14 23:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-08-12 13:51 - 2015-07-14 22:55 - 01390592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-08-12 13:51 - 2015-07-14 22:55 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-08-12 13:51 - 2015-07-14 22:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-08-12 13:51 - 2015-07-14 22:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-08-12 13:51 - 2015-07-09 13:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-12 13:51 - 2015-07-09 13:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-12 13:51 - 2015-07-09 13:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
2015-08-12 13:51 - 2015-07-01 16:49 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-12 13:51 - 2015-07-01 16:48 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-08-12 13:51 - 2015-07-01 16:30 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2015-08-12 13:51 - 2015-07-01 16:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2015-08-12 13:50 - 2015-07-16 15:12 - 04922368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-08-12 13:50 - 2015-07-16 15:12 - 00269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2015-08-12 13:50 - 2015-07-16 15:12 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-08-12 13:50 - 2015-07-16 15:11 - 05779456 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-12 13:50 - 2015-07-16 15:11 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-08-12 13:50 - 2015-07-16 15:11 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-08-12 13:50 - 2015-07-10 13:51 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-12 13:50 - 2015-07-10 13:34 - 12875776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-08-12 02:25 - 2015-08-12 02:25 - 00000042 _____ C:\Users\Matts Windows7\Desktop\get get xxxxxx.txt
2015-08-11 20:30 - 2015-08-11 20:30 - 01743626 _____ C:\Users\Matts Windows7\Desktop\WP Animator.zip
2015-08-11 14:52 - 2015-08-11 14:52 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-11 09:52 - 2015-08-11 09:52 - 11534096 _____ (Intel Corporation) C:\Windows\system32\Drivers\NETwsw01.sys
2015-08-10 14:35 - 2015-08-10 14:56 - 00000000 ____D C:\Users\Matts Windows7\Desktop\BacklinkBeast_Cracked_by_Malice
2015-08-10 13:33 - 2015-08-17 15:39 - 00000000 ____D C:\Users\Matts Windows7\Desktop\ltp
2015-08-09 22:24 - 2015-08-09 22:54 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Local Client Takeover
2015-08-09 22:03 - 2015-08-11 17:32 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\UpViral and Audience Connect
2015-08-07 22:16 - 2015-08-09 22:29 - 00000338 _____ C:\Users\Matts Windows7\Desktop\open.txt
2015-08-07 10:13 - 2015-08-07 10:14 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Immersion Session 2
2015-08-06 14:14 - 2015-08-06 14:14 - 47438474 _____ C:\Users\Matts Windows7\Desktop\The 5 Secret Steps to Creating Powerful Viral Marketing Loops.mp4
2015-08-05 16:02 - 2015-08-05 16:02 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 02606080 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-08-05 16:02 - 2015-08-05 16:02 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-08-05 16:02 - 2015-08-05 16:02 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-08-05 16:02 - 2015-08-05 16:02 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-08-04 20:43 - 2015-08-04 20:43 - 00000000 ____D C:\Program Files (x86)\LongTailPro
2015-08-04 16:49 - 2015-08-04 16:49 - 00000000 ____D C:\Program Files (x86)\GIGProspector
2015-08-04 15:50 - 2015-08-04 15:50 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\article.buddy.ArticleBuddy
2015-08-04 14:36 - 2015-08-04 14:36 - 00000000 ____D C:\Users\Matts Windows7\GPS
2015-08-04 14:36 - 2015-08-04 14:36 - 00000000 ____D C:\Users\Matts Windows7\Articles
2015-08-04 10:22 - 2015-08-24 12:33 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\IDM
2015-08-04 10:22 - 2015-08-04 10:22 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2015-08-04 10:22 - 2015-08-04 10:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2015-08-04 10:22 - 2015-08-04 10:22 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager
2015-08-03 15:01 - 2015-08-03 15:29 - 00000000 ____D C:\Users\Matts Windows7\Documents\Arclab Website Link Analyzer
2015-08-03 15:01 - 2015-08-03 15:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Website Link Analyzer
2015-08-03 15:01 - 2015-08-03 15:01 - 00000000 ____D C:\Program Files (x86)\Arclab
2015-08-03 15:00 - 2015-08-03 15:00 - 39724535 _____ C:\Users\Matts Windows7\Downloads\AutoresponderSetup-HD.zip
2015-08-01 15:36 - 2015-08-01 15:36 - 00000000 ____D C:\Users\Public\Documents\Red Giant
2015-08-01 15:36 - 2015-08-01 15:36 - 00000000 ____D C:\Users\Public\Documents\Knoll Software
2015-08-01 15:36 - 2015-07-02 15:25 - 00310272 _____ C:\Windows\system32\KLF_OGL_x64.dll
2015-08-01 15:30 - 2015-08-01 15:30 - 00000000 ____D C:\ProgramData\goodasnew
2015-08-01 15:28 - 2015-08-01 15:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant
2015-08-01 15:28 - 2015-08-01 15:30 - 00000000 ____D C:\Program Files (x86)\Red Giant Link
2015-08-01 15:28 - 2015-08-01 15:28 - 00003688 _____ C:\Windows\System32\Tasks\Red Giant Link
2015-08-01 15:28 - 2015-08-01 15:28 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Red Giant
2015-08-01 15:28 - 2015-08-01 15:28 - 00000000 ____D C:\ProgramData\Red Giant
2015-08-01 15:27 - 2015-08-01 15:27 - 00000000 ____D C:\Program Files (x86)\Red Giant
2015-08-01 15:23 - 2015-08-01 15:36 - 00000000 ____D C:\ProgramData\RedGiant
2015-07-31 16:27 - 2015-07-31 16:27 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\TeeSpy
2015-07-31 13:29 - 2015-07-31 13:37 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Community Chest
2015-07-30 21:28 - 2015-08-14 18:01 - 00002966 _____ C:\Windows\System32\Tasks\VIPRE Upgrade Task
2015-07-29 13:52 - 2015-07-29 14:00 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\PDFs Must Read
2015-07-28 23:22 - 2015-07-28 23:22 - 00000870 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AD RESPARK.lnk
2015-07-28 23:22 - 2015-07-28 23:22 - 00000000 ____D C:\Program Files (x86)\AD RESPARK
2015-07-28 23:21 - 2015-07-28 23:21 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\com.gorialogics.adrespark
2015-07-28 23:13 - 2015-07-28 23:13 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Ad-Respark
2015-07-28 16:48 - 2015-07-28 16:48 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\RoboForm
2015-07-28 16:42 - 2015-07-28 16:42 - 00000000 ____D C:\ProgramData\RoboForm
2015-07-28 16:41 - 2015-08-20 20:16 - 00000000 ____D C:\Users\Matts Windows7\Documents\My RoboForm Data
2015-07-28 15:54 - 2015-07-29 09:19 - 00000120 _____ C:\Users\Matts Windows7\Desktop\get get.txt
2015-07-28 15:49 - 2015-07-28 15:49 - 00000910 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstaBannerAIR.lnk
2015-07-28 15:49 - 2015-07-28 15:49 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\InstaBannerAIR
2015-07-28 15:49 - 2015-07-28 15:49 - 00000000 ____D C:\Program Files (x86)\InstaBannerAIR
2015-07-28 12:45 - 2015-07-28 12:45 - 00000000 ____D C:\$Windows.~BT
2015-07-27 23:29 - 2015-07-27 23:29 - 00000969 _____ C:\Users\Matts Windows7\Desktop\IrfanView.lnk
2015-07-27 23:29 - 2015-07-27 23:29 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2015-07-27 23:29 - 2015-07-27 23:29 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\IrfanView
2015-07-27 23:29 - 2015-07-27 23:29 - 00000000 ____D C:\Program Files (x86)\IrfanView
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-25 21:19 - 2015-06-08 15:10 - 00000000 ____D C:\FRST
2015-08-25 21:09 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-25 21:09 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-25 21:05 - 2011-05-24 15:02 - 01777990 _____ C:\Windows\WindowsUpdate.log
2015-08-25 21:02 - 2012-02-22 13:17 - 00000000 ___RD C:\Users\Matts Windows7\Dropbox
2015-08-25 21:02 - 2012-02-22 13:15 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Dropbox
2015-08-25 21:01 - 2014-08-28 17:56 - 00000000 ____D C:\Users\Matts Windows7\OneDrive
2015-08-25 21:01 - 2012-09-05 13:58 - 00000000 ___RD C:\Users\Matts Windows7\Google Drive
2015-08-25 21:01 - 2012-09-05 13:57 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-25 21:01 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-25 21:00 - 2015-05-18 11:25 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-25 20:58 - 2014-11-09 16:28 - 00000944 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job
2015-08-25 20:56 - 2012-09-05 13:57 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-25 20:51 - 2015-06-04 14:38 - 00000652 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job
2015-08-25 20:44 - 2012-02-29 12:46 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\CrashDumps
2015-08-25 20:43 - 2014-03-25 20:08 - 00000556 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job
2015-08-25 16:56 - 2015-07-14 17:00 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\DMCache
2015-08-25 16:24 - 2015-06-15 21:13 - 00000954 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job
2015-08-25 16:08 - 2009-07-14 01:13 - 00786622 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-25 15:51 - 2015-07-24 19:58 - 00000000 ____D C:\zxz
2015-08-25 15:51 - 2015-07-14 17:10 - 00000000 ___RD C:\Users\Matts Windows7\Downloads\Video
2015-08-25 15:51 - 2012-01-12 15:10 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\vlc
2015-08-25 15:11 - 2015-07-08 12:16 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2015-08-25 13:26 - 2012-11-27 14:03 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Media Player Classic
2015-08-24 16:46 - 2015-02-21 00:35 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Recurring Revenue Machine
2015-08-23 21:58 - 2014-11-09 16:28 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job
2015-08-23 20:38 - 2015-06-04 14:38 - 00003710 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000
2015-08-23 20:38 - 2014-03-25 20:08 - 00003614 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000
2015-08-23 18:20 - 2015-06-15 21:13 - 00000902 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job
2015-08-22 14:18 - 2015-07-15 12:03 - 00000000 ___RD C:\Users\Matts Windows7\Downloads\Compressed
2015-08-21 17:41 - 2015-06-23 00:38 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Dons RESULTS 6-23-15
2015-08-21 15:01 - 2011-10-05 23:16 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Skype
2015-08-21 14:58 - 2011-10-05 23:16 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-08-21 14:58 - 2011-04-15 09:44 - 00000000 ____D C:\ProgramData\Skype
2015-08-21 12:33 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2015-08-21 10:22 - 2012-04-28 23:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-21 00:38 - 2015-05-26 18:20 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-20 21:21 - 2014-10-29 13:29 - 00001456 _____ C:\Users\Matts Windows7\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-08-20 12:43 - 2014-02-20 11:18 - 00002200 _____ C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-08-19 12:22 - 2012-03-14 17:51 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\TOOLs
2015-08-19 10:39 - 2015-05-12 10:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 4
2015-08-19 10:39 - 2015-03-01 03:13 - 00003212 _____ C:\Windows\System32\Tasks\ASC8_PerformanceMonitor
2015-08-19 10:39 - 2015-03-01 03:12 - 00002900 _____ C:\Windows\System32\Tasks\ASC8_SkipUac_Matts Windows7
2015-08-19 10:39 - 2015-03-01 03:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8
2015-08-19 10:38 - 2015-03-01 01:59 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\IObit
2015-08-19 10:38 - 2015-03-01 01:59 - 00000000 ____D C:\ProgramData\IObit
2015-08-19 10:38 - 2015-03-01 01:59 - 00000000 ____D C:\Program Files (x86)\IObit
2015-08-18 23:32 - 2011-07-28 11:49 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\Google
2015-08-18 18:47 - 2014-05-22 12:30 - 00000000 ____D C:\Windows\Minidump
2015-08-18 18:08 - 2014-10-29 13:06 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-08-18 18:08 - 2014-10-29 13:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-08-18 18:08 - 2012-03-13 02:10 - 00000000 ____D C:\Program Files (x86)\Java
2015-08-18 18:08 - 2011-07-28 08:45 - 00000000 ____D C:\Users\Matts Windows7
2015-08-18 08:05 - 2011-07-28 08:46 - 00442592 _____ C:\Users\Matts Windows7\AppData\Local\GDIPFONTCACHEV1.DAT
2015-08-18 08:04 - 2009-07-14 00:45 - 13680664 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-17 18:13 - 2015-06-26 16:48 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Body by Matt Site
2015-08-17 13:33 - 2014-01-16 15:05 - 00002471 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 9 Pro Extended.lnk
2015-08-17 13:33 - 2014-01-16 15:05 - 00002465 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Distiller 9.lnk
2015-08-17 13:33 - 2014-01-16 15:05 - 00002235 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe 3D Reviewer.lnk
2015-08-17 13:33 - 2014-01-16 15:05 - 00002138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle Designer ES 8.2.lnk
2015-08-16 00:11 - 2011-07-28 11:49 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\Apps\2.0
2015-08-15 23:56 - 2009-07-13 23:20 - 00000000 __RHD C:\Users\Default
2015-08-15 23:31 - 2009-07-13 22:34 - 00000215 _____ C:\Windows\system.ini
2015-08-15 12:05 - 2009-07-14 01:08 - 00032544 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-15 08:54 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\Resources
2015-08-14 18:58 - 2012-09-05 13:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-08-14 15:04 - 2015-07-07 14:42 - 00000427 _____ C:\Users\Matts Windows7\Desktop\Penguin & WI-FI.txt
2015-08-13 18:39 - 2014-06-17 19:09 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\uTorrent
2015-08-13 18:39 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\registration
2015-08-13 18:19 - 2015-06-02 17:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-08-13 17:54 - 2015-05-26 18:19 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-13 13:28 - 2014-12-11 10:53 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-13 13:28 - 2014-05-07 09:41 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-12 17:34 - 2013-03-13 20:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-12 17:33 - 2013-03-13 20:05 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-12 17:33 - 2013-03-13 20:05 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-12 17:31 - 2014-06-16 19:59 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-12 17:27 - 2009-07-13 22:34 - 00000478 _____ C:\Windows\win.ini
2015-08-12 17:18 - 2013-08-15 10:46 - 00000000 ____D C:\Windows\system32\MRT
2015-08-12 17:18 - 2011-12-28 21:04 - 132483416 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-11 20:00 - 2015-05-18 11:25 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-08-11 20:00 - 2014-03-12 21:38 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-08-11 20:00 - 2014-03-12 21:38 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-10 12:38 - 2015-07-22 11:59 - 00000108 _____ C:\Users\Matts Windows7\dkKWOOj1AFxjAn8NHqWZgdFIjvrdBhZkbQ
2015-08-10 12:38 - 2015-07-20 16:33 - 00000268 _____ C:\Users\Matts Windows7\AppData\Roaming\RO39-2M3Q
2015-08-09 23:20 - 2015-02-06 17:16 - 00000000 ___RD C:\ICONS
2015-08-05 11:30 - 2012-01-17 15:00 - 00000000 ____D C:\Users\Matts Windows7\Documents\My Maps
2015-08-04 20:43 - 2015-07-22 11:58 - 00000880 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LongTailPro.lnk
2015-08-04 20:43 - 2013-04-08 12:39 - 00660720 ____H C:\Windows\SysWOW64\mlfcache.dat
2015-08-04 17:07 - 2015-01-29 15:45 - 00000222 _____ C:\Users\Matts Windows7\video2gifsett
2015-08-04 17:03 - 2015-01-29 15:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video2Gif
2015-08-04 17:03 - 2015-01-29 15:41 - 00000000 ____D C:\Program Files (x86)\ Video2Gif
2015-08-04 16:49 - 2013-05-08 12:05 - 00000900 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGProspector.lnk
2015-08-04 16:49 - 2013-05-08 12:05 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\GIGProspector
2015-08-04 16:30 - 2012-09-21 17:36 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Tin Nguyen
2015-08-04 14:42 - 2014-07-25 16:21 - 00000000 ____D C:\Users\Matts Windows7\Documents\Outlook Files
2015-08-03 14:51 - 2015-01-07 17:15 - 00000132 _____ C:\Users\Matts Windows7\AppData\Roaming\Adobe PNG Format CC Prefs
2015-07-28 14:46 - 2015-06-30 01:03 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\LABS
2015-07-28 12:45 - 2007-07-11 21:49 - 00000000 ____D C:\Windows\Panther
2015-07-28 00:36 - 2013-03-01 18:33 - 00000000 ____D C:\Users\Matts Windows7\Documents\Movie Studio Platinum 12.0 Projects
2015-07-28 00:34 - 2009-07-14 00:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-07-27 23:58 - 2013-03-17 09:42 - 00005632 _____ C:\Users\Matts Windows7\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-27 14:03 - 2015-07-08 12:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
2015-07-27 14:03 - 2015-07-08 12:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Exploit
2015-07-26 23:55 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\NDF
2015-07-26 13:46 - 2015-03-30 22:50 - 00000000 ___SD C:\Windows\system32\GWX
==================== Files in the root of some directories =======
2012-03-06 18:34 - 2012-03-06 18:34 - 0001005 _____ () C:\Program Files (x86)\Backlink Skyrocket.lnk
2012-03-06 18:37 - 2012-03-06 18:37 - 0000993 _____ () C:\Program Files (x86)\Traffic SkyRocket.lnk
2012-03-06 18:34 - 2012-03-06 18:34 - 0000960 _____ () C:\Program Files (x86)\Update Skyrocket.lnk
2014-08-09 01:42 - 2014-08-09 02:16 - 15000576 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2015-07-20 16:33 - 2015-07-20 16:33 - 0000088 _____ () C:\Users\Matts Windows7\AppData\Roaming\.95d691779473f3e03bc4b4e56319d74c.key
2015-03-12 18:12 - 2015-03-12 18:12 - 0000132 _____ () C:\Users\Matts Windows7\AppData\Roaming\Adobe GIF Format CC Prefs
2015-01-07 17:15 - 2015-08-03 14:51 - 0000132 _____ () C:\Users\Matts Windows7\AppData\Roaming\Adobe PNG Format CC Prefs
2012-08-01 15:02 - 2012-08-01 15:02 - 0000098 _____ () C:\Users\Matts Windows7\AppData\Roaming\netstat.bat
2015-07-20 16:33 - 2015-08-10 12:38 - 0000268 _____ () C:\Users\Matts Windows7\AppData\Roaming\RO39-2M3Q
2015-02-17 12:10 - 2015-02-17 12:19 - 0558080 _____ () C:\Users\Matts Windows7\AppData\Roaming\SharedSettings.ccs
2014-10-29 13:29 - 2015-08-20 21:21 - 0001456 _____ () C:\Users\Matts Windows7\AppData\Local\Adobe Save for Web 13.0 Prefs
2013-03-17 09:42 - 2015-07-27 23:58 - 0005632 _____ () C:\Users\Matts Windows7\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-25 15:25 - 2014-07-25 15:25 - 0004096 ____H () C:\Users\Matts Windows7\AppData\Local\keyfile3.drm
2014-09-17 17:26 - 2014-09-17 21:39 - 0000600 _____ () C:\Users\Matts Windows7\AppData\Local\PUTTY.RND
2013-05-29 13:03 - 2014-05-30 08:54 - 17977856 _____ () C:\Users\Matts Windows7\AppData\Local\ReputationCrusher.msi
2014-02-05 02:23 - 2014-11-05 10:53 - 0007597 _____ () C:\Users\Matts Windows7\AppData\Local\Resmon.ResmonCfg
2014-07-22 20:25 - 2014-07-22 20:25 - 0000003 _____ () C:\Users\Matts Windows7\AppData\Local\updater.log
2014-07-22 20:25 - 2014-11-22 18:18 - 0000455 _____ () C:\Users\Matts Windows7\AppData\Local\UserProducts.xml
2015-01-10 01:22 - 2015-01-10 01:22 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-05-15 10:57 - 2012-05-15 10:57 - 0000252 _____ () C:\ProgramData\FastPics.log
2013-07-15 17:43 - 2013-07-15 17:43 - 0000032 _____ () C:\ProgramData\Temp.log
2012-05-15 10:52 - 2012-05-15 10:52 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt
ZeroAccess:
C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}
C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}\@
Some files in TEMP:
====================
C:\Users\Matts Windows7\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpc86hzw.dll
C:\Users\Matts Windows7\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Matts Windows7\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-08-24 11:23
==================== End of FRST.txt ============================
ADDITION
Additional scan result of Farbar Recovery Scan Tool (x64) Version:25-08-2015 02
Ran by [removed] (2015-08-25 21:20:26)
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3123964009-4157677460-2703354282-500 - Administrator - Disabled)
Guest (S-1-5-21-3123964009-4157677460-2703354282-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3123964009-4157677460-2703354282-1004 - Limited - Enabled)
Matts Windows7 (S-1-5-21-3123964009-4157677460-2703354282-1000 - Administrator - Enabled) => C:\Users\Matts Windows7
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: ThreatTrack Security VIPRE (Enabled - Up to date) {FFE93D16-FD09-0282-C7D3-8B1731B6A051}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ThreatTrack Security VIPRE (Enabled - Up to date) {4488DCF2-DB33-0D0C-FD63-B0654A31EAEC}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\uTorrent) (Version: 3.4.2.31743 - BitTorrent Inc.)
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
AD RESPARK (HKLM-x32\…\com.gorialogics.adrespark) (Version: 1.2 - Your Marketing Tech Support, LLC)
AD RESPARK (x32 Version: 1.2 - Your Marketing Tech Support, LLC) Hidden
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch (HKLM-x32\…\{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}) (Version: 9.0.0 - Adobe Systems)
Adobe Acrobat 9 Pro Extended 64-bit Add-On (HKLM\…\{AC76BA86-1033-0000-0064-0003D0000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Adobe After Effects CS6 (HKLM-x32\…\{4817D846-700B-474E-A31B-80892B3E92E3}) (Version: 11 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated)
Adobe Anchor Service x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe CMaps x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe CSI CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe Drive CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 18 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Fonts All x64 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Illustrator CS5 (HKLM-x32\…\{9B97EC91-B3FD-4BFF-88FC-5345A26AC2E7}) (Version: 15.0 - Adobe Systems Incorporated)
Adobe Linguistics CS4 x64 (Version: 4.0.0 - Adobe Systems Incorporated) Hidden
Adobe Media Player (HKLM-x32\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
Adobe PDF Library Files x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CC (HKLM-x32\…\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated)
Adobe Photoshop CS4 (64 Bit) (Version: 11.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS4 (HKLM-x32\…\Adobe_faf656ef605427ee2f42989c3ad31b8) (Version: 11.0 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Adobe Type Support x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe WinSoft Linguistics Plugin x64 (Version: 1.1 - Adobe Systems Incorporated) Hidden
Advanced SystemCare 8 (HKLM-x32\…\Advanced SystemCare 8_is1) (Version: 8.3.0 - IObit)
AliG Social Lead Freak (HKLM-x32\…\com.aligmarketing.slf) (Version: 2.4.0 - Ali M. Gadit)
AliG Social Lead Freak (x32 Version: 2.4.0 - Ali M. Gadit) Hidden
Any Video Converter 5 5.0.3 (HKLM-x32\…\Any Video Converter 5_is1) (Version: - Any-Video-Converter.com)
Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Arclab Website Link Analyzer 1.21 (HKLM-x32\…\Arclab Website Link Analyzer_is1) (Version: 1.21 - Arclab Software GbR)
Audacity 1.2.6 (HKLM-x32\…\Audacity_is1) (Version: - )
AVCHD To MP4 Converter 1.0 (HKLM-x32\…\AVCHD To MP4 Converter) (Version: 1.0 - Mark Dulisse)
Backlink SkyRocket (HKLM-x32\…\{DA043E6D-2724-4894-8DD7-AC9020193663}) (Version: 1.4.8 - Backlink SkyRocket)
Backup Manager V3 (x32 Version: 3.0.0.100 - NTI Corporation) Hidden
BleuPage (HKLM-x32\…\{FE65FBDB-48D5-4145-8E24-3775F872F3E7}) (Version: 1.3.307 - BleuPage Software)
BlueStacks App Player (HKLM-x32\…\BlueStacks App Player) (Version: 0.8.7.3069 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\…\{FE5ABB0E-EDEA-4023-B0FB-9DEA39A98D76}) (Version: 0.8.7.3069 - BlueStack Systems, Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom Card Reader Driver Installer (HKLM\…\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 14.6.1.2 - Broadcom Corporation)
Broadcom Gigabit NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.6.1.2 - Broadcom Corporation)
Camtasia Studio 7 (HKLM-x32\…\{C0E8FE43-C35B-451D-B35F-D4BD056D70E7}) (Version: 7.1.1 - TechSmith Corporation)
CarMD (HKLM-x32\…\{7E213637-F640-4599-A8B3-5269BA7D66D3}) (Version: 4.0.120 - carmd.com)
Cisco WebEx Meetings (HKLM-x32\…\ActiveTouchMeetingClient) (Version: - Cisco WebEx LLC)
Citrix Online Launcher (HKLM-x32\…\{DB014C85-A264-4BCA-A66F-6DD1FCF8EC36}) (Version: 1.0.335 - Citrix)
Citrix Receiver (HKLM-x32\…\CitrixOnlinePluginPackWeb) (Version: 13.1.201.3 - Citrix Systems, Inc.)
Commission Heist (HKLM-x32\…\commheist) (Version: 1.0.2 - Memberspeed Inc)
Commission Heist (x32 Version: 1.0.2 - Memberspeed Inc) Hidden
Conference Recording Service (HKLM-x32\…\{B293F0E6-10B7-45FD-BACF-18826515C246}_is1) (Version: - GVO, Inc.)
Connect (x32 Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
CT4L (HKLM-x32\…\CT4L) (Version: 1.4.1 - UNKNOWN)
CT4L (x32 Version: 1.4.1 - UNKNOWN) Hidden
CyberLink MediaEspresso (HKLM-x32\…\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.0.1027_32100 - CyberLink Corp.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.2531.52 - CyberLink Corp.)
CyberSpy Intel Station (HKLM-x32\…\{005DE34D-CE86-4C74-9B31-8C6D2E10ABBD}) (Version: 1.0.0 - Dean Sueck - CyberSpyIntelStation.com)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deals Flow (HKLM-x32\…\DealsFlow) (Version: 1.0.0 - UNKNOWN)
Deals Flow (x32 Version: 1.0.0 - UNKNOWN) Hidden
Digi Traffic Accelerator (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\27e1819d71203503) (Version: 1.1.9.119 - DigiResults)
Domain Security PRO 1.0 (HKLM-x32\…\Domain Security PRO) (Version: 1.0 - Mark Dulisse)
Driver Booster 2.4 (HKLM-x32\…\Driver Booster_is1) (Version: 2.4 - IObit)
Dropbox (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Dropbox) (Version: 3.8.6 - Dropbox, Inc.)
DVD Architect Studio 5.0 (HKLM-x32\…\{42C509F1-C451-11E1-AEC9-F04DA23A5C58}) (Version: 5.0.161 - Sony)
EasySketchPro version 2.0.0 (HKLM-x32\…\{90BB7D95-EBCA-4276-B15E-156F85E8B1DA}_is1) (Version: 2.0.0 - Inner Cirle Riches)
EasyVSL (HKLM-x32\…\com.searchcreatively.EasyVSL) (Version: 1.0.5 - Digital Kickstart)
EasyVSL (x32 Version: 1.0.5 - Digital Kickstart) Hidden
Effects Suite v11.1.6 (HKLM-x32\…\{4DD8EE5E-F571-4EC8-9526-E7C62FE39B19}_is1) (Version: 11.1.6 - Red Giant, LLC)
FB Ad Express (HKLM-x32\…\com.pageone.FBads) (Version: 1.2 - Jai Ganesh Venkateswaran)
FB Ad Express (x32 Version: 1.2 - Jai Ganesh Venkateswaran) Hidden
FileZilla Client 3.5.3 (HKLM-x32\…\FileZilla Client) (Version: 3.5.3 - FileZilla Project)
Flip PDF (HKLM-x32\…\Flip PDF_is1) (Version: - FlipBuilder Solution)
FreshKey (HKLM-x32\…\com.digitalmarketer.FreshKey) (Version: 1.5.4 - Idea Incubator LP)
FreshKey (x32 Version: 1.5.4 - Idea Incubator LP) Hidden
FunnelCreator (HKLM-x32\…\FunnelCreator) (Version: 1.0 - UNKNOWN)
FunnelCreator (x32 Version: 1.0 - UNKNOWN) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gateway MyBackup (HKLM-x32\…\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.100 - NTI Corporation)
Gateway Power Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Gateway Incorporated)
Gateway Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Gateway Incorporated)
Gateway Registration (HKLM-x32\…\Gateway Registration) (Version: 1.03.3004 - Gateway Incorporated)
Gateway ScreenSaver (HKLM-x32\…\Gateway Screensaver) (Version: 1.1.1022.2010 - Gateway Incorporated)
Gateway Social Networks (HKLM-x32\…\InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}) (Version: 2.0.3315 - CyberLink Corp.)
Gateway Social Networks (x32 Version: 2.0.3315 - CyberLink Corp.) Hidden
GIG Prospector (HKLM-x32\…\GIGProspector) (Version: 2.0.8 - UNKNOWN)
GIG Prospector (x32 Version: 2.0.8 - UNKNOWN) Hidden
Google AdWords Editor (HKLM-x32\…\{14069A87-872C-41E6-9D36-B1BE3870C35A}) (Version: 10.6.0 - Google)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 44.0.2403.157 - Google Inc.)
Google Drive (HKLM-x32\…\{12ADFB82-D5A3-43E4-B2F4-FCD9B690315B}) (Version: 1.24.9931.5480 - Google, Inc.)
Google Talk Plugin (HKLM-x32\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
GoToMeeting 7.2.4.3277 (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\GoToMeeting) (Version: 7.2.4.3277 - CitrixOnline)
HandBrake 0.9.9.1 (HKLM-x32\…\HandBrake) (Version: 0.9.9.1 - )
HD Video Converter Factory Pro 9.2 (HKLM-x32\…\HD Video Converter Factory Pro) (Version: 9.2 - WonderFox Soft, Inc.)
HomeMedia (HKLM-x32\…\{AA4BF92B-2AAF-11DA-9D78-000129760D75}) (Version: 2.0.8520 - CyberLink Corporation)
HP ENVY 4500 series Basic Device Software (HKLM\…\{6915424E-704F-4F5D-9057-9C7B406B36DB}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
iCloud (HKLM\…\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3006 - Gateway Incorporated)
iExplorer [removed] (HKLM-x32\…\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version: - Macroplant LLC)
InstaBannerAIR (HKLM-x32\…\InstaBannerAIR) (Version: 1.1 - JHS Marketing LLC)
InstaBannerAIR (x32 Version: 1.1 - JHS Marketing LLC) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\…\{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}) (Version: 14.00.1000 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - )
Intel(R) Wireless Display (HKLM-x32\…\{626663EE-B9E6-4982-995F-02C31E84F8FC}) (Version: 2.0.29.0 - Intel Corporation)
Internet Download Manager (HKLM-x32\…\Internet Download Manager) (Version: - Tonec Inc.)
IObit Malware Fighter 3 (HKLM-x32\…\IObit Malware Fighter_is1) (Version: 3.1 - IObit)
IObit Uninstaller (HKLM-x32\…\IObitUninstall) (Version: 4.3.0.5 - IObit)
IrfanView (remove only) (HKLM-x32\…\IrfanView) (Version: 4.38 - Irfan Skiljan)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\…\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 51 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
Java 8 Update 60 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\…\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Jing (HKLM-x32\…\{22800204-9E53-45C7-B6F3-5BB0F1C1A147}) (Version: 2.8.13007.1 - TechSmith Corporation)
Juicer 3.90 (HKLM-x32\…\{640EAE56-81A2-49D4-9B8C-00DA3C0031AF}_is1) (Version: - Digital Juice, Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Keyword Scout (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\6611abf67fa612f7) (Version: 1.0.1.55 - Josh MacDonald)
K-Lite Codec Pack 9.5.0 (Full) (HKLM-x32\…\KLiteCodecPack_is1) (Version: 9.5.0 - )
KompoZer 0.8b3 (HKLM-x32\…\{20aa4150-b5f4-11de-8a39-0800200c9a66}_is1) (Version: - KompoZer)
kuler (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
LastPass (uninstall only) (HKLM-x32\…\LastPass) (Version: - LastPass)
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.4 - Gateway)
Lexmark 5600-6600 Series (HKLM\…\Lexmark 5600-6600 Series) (Version: - Lexmark International, Inc.)
Lexmark Printable Web (HKLM-x32\…\{D2C5E510-BE6D-42CC-9F61-E4F939078474}) (Version: 1.0.0.0 - )
Livedrive (HKLM\…\{7D2E0E90-3BBA-43B1-894D-EC39A4E18748}) (Version: 1.15.2.0 - Livedrive Internet Limited)
Local Lead Igniter (HKLM-x32\…\Service.Magic.Scrapper) (Version: 0.0.0 - UNKNOWN)
Local Lead Igniter (x32 Version: 0.0.0 - UNKNOWN) Hidden
Local Niche Spy (HKLM-x32\…\Niche) (Version: 2.1.4 - UNKNOWN)
Local Niche Spy (x32 Version: 2.1.4 - UNKNOWN) Hidden
Local Traffic Tool (HKLM-x32\…\{BAF1E625-29F3-4144-8686-4C89543C73D7}) (Version: 1.1.6 - Offline Inner Circle)
Localizer Leads Tool (HKLM-x32\…\LocalizerLeadsTool) (Version: 3.5.4 - Viper Consulting, LLC)
Localizer Leads Tool (x32 Version: 3.5.4 - Viper Consulting, LLC) Hidden
LongTailPro - Version 3.0.13 (HKLM-x32\…\com.longtailpro.LongTailPro) (Version: 3.0.13 - Long Tail Media, LLC)
LongTailPro - Version 3.0.13 (x32 Version: 3.0.13 - Long Tail Media, LLC) Hidden
Malwarebytes Anti-Exploit version 1.07.1.1015 (HKLM\…\Malwarebytes Anti-Exploit_is1) (Version: 1.07.1.1015 - Malwarebytes)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
MetaFrame Presentation Server Web Client for Win32 (HKLM\…\Citrix ICA Web Client) (Version: - )
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\OneDriveSetup.exe) (Version: 17.3.5930.0814 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\…\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\…\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mindjet MindManager 2012 (HKLM-x32\…\{4E973CA9-5674-4FB4-8D83-3D8C5EB44AB3}) (Version: 10.0.445 - Mindjet)
Movie Studio Platinum 12.0 (64-bit) (HKLM\…\{FE052581-1CD8-11E2-B617-F04DA23A5C58}) (Version: 12.0.576 - Sony)
Mozilla Firefox 40.0.2 (x86 en-GB) (HKLM-x32\…\Mozilla Firefox 40.0.2 (x86 en-GB)) (Version: 40.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 40.0.2.5702 - Mozilla)
Mp3tag v2.65a (HKLM-x32\…\Mp3tag) (Version: v2.65a - Florian Heidenreich)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MySpeed v5.4.5 (HKLM-x32\…\{C3F2AE48-FEEB-4697-BFCE-FB9B17289A7F}) (Version: 5.04.0413 - Enounce Incorporated)
Nero DiscSpeed 10 (HKLM-x32\…\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG)
Nero Express 10 (HKLM-x32\…\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12000.21.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.5.10300 - Nero AG)
Nero StartSmart 10 (HKLM-x32\…\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
Nero Update (HKLM-x32\…\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
NOOK for PC (HKLM-x32\…\BN_DesktopReader) (Version: 2.5.1.237 - Barnesandnoble.com)
Notepad++ (HKLM-x32\…\Notepad++) (Version: 6.4.2 - Notepad++ Team)
Online Plug-in (x32 Version: 13.1.201.3 - Citrix Systems, Inc.) Hidden
PandoraRecovery (Remove Only) (HKLM-x32\…\PandoraRecovery) (Version: - )
PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden
PDF Settings CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
PDF-XChange 3 (HKLM\…\PDF-XChange 3_is1) (Version: - Tracker Software)
Perfectly Clear Plugin 1.6.0 (HKLM-x32\…\Perfectly Clear Plugin) (Version: 1.6.0 - Athentech)
Photoshop Camera Raw (x32 Version: 5.0 - Adobe Systems Incorporated) Hidden
Photoshop Camera Raw_x64 (Version: 5.0 - Adobe Systems Incorporated) Hidden
Places Scout (HKLM-x32\…\{AA880B13-717B-46C6-B9F4-E38974D56881}) (Version: 2.2.0 - Automated Keyword Research, LLC)
PPTX Viewer 2.0 (HKLM-x32\…\PPTX Viewer 2.0) (Version: - )
Proxy Goblin (HKLM-x32\…\{B77A5236-16DB-4DE5-B0CE-2E3F0B52C321}) (Version: 2.1.3 - Molura)
Publishers Review Accelerator (HKLM-x32\…\{95008B02-4CBD-4352-8180-56C414CBBCD1}) (Version: 1.1.65 - Scoritz)
Qilio (HKLM-x32\…\com.jayvenka.qilio) (Version: 1.0.7 - Jai Ganesh Venkateswaran)
Qilio (x32 Version: 1.0.7 - Jai Ganesh Venkateswaran) Hidden
QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RAPID Mode (Version: 1.0.1.81 - Samsung Electronics Co., Ltd.) Hidden
Real Hide IP (HKLM-x32\…\RealHideIP) (Version: 4.2.5.2 - )
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6329 - Realtek Semiconductor Corp.)
Red Giant Link (HKLM-x32\…\{10F82E5B-B611-4C65-8F29-666A9EC5680A}_is1) (Version: 1.9.6.0 - Red Giant, LLC)
Reflector (HKLM\…\{77342B24-A2A9-4420-8C9C-C109EE201CBC}) (Version: 1.3.3.1 - Squirrels)
Reputation Crusher (HKLM-x32\…\{FA0EFEF1-212F-45CC-9651-AACB66F75F8B}) (Version: 1.0.55 - MJISolutions)
Revo Uninstaller Pro 2.1.1 (HKLM\…\{FB562550-BBE6-4298-861A-5C0A6562C272}_is1) (Version: - ;-))
S3 Ripper 2.0 (HKLM-x32\…\{AB3D78B7-8066-465A-82A8-5F3751564457}_is1) (Version: - )
Samsung Data Migration (HKLM-x32\…\{D4DE3DB4-7734-47E5-8D92-B80146311406}) (Version: 2.7 - Samsung)
Samsung Magician (HKLM-x32\…\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.5.1 - Samsung Electronics)
Samsung Universal Print Driver 2 (HKLM-x32\…\Samsung Universal Print Driver 2) (Version: 2.50.02.00 - Samsung Electronics Co., Ltd.)
Scale Factor Social Leads Tool (HKLM-x32\…\FacebookLeads) (Version: 0.0.0 - UNKNOWN)
Scale Factor Social Leads Tool (x32 Version: 0.0.0 - UNKNOWN) Hidden
Self-service Plug-in (x32 Version: 3.2.0.24226 - Citrix Systems, Inc.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Skype Click to Call (HKLM-x32\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.9.12585 - Skype Technologies S.A.)
Skype™ 7.8 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
Smart Defrag 4 (HKLM-x32\…\Smart Defrag 4_is1) (Version: 4.1 - IObit)
Snagit 12 (HKLM-x32\…\{588591F5-74D7-4646-87C5-6A07E526F303}) (Version: 12.3.2 - TechSmith Corporation)
SocialMultiplier (HKLM-x32\…\SocialMultiplier) (Version: - )
Sound Forge Audio Studio 10.0 (HKLM-x32\…\{7A263871-BEEC-11E1-AC53-F04DA23A5C58}) (Version: 10.0.178 - Sony)
Sparkol VideoScribe (HKLM-x32\…\Sparkol VideoScribe 1.3.18) (Version: 1.3.18 - Sparkol)
Sparkol VideoScribe (x32 Version: 1.3.18 - Sparkol) Hidden
Splashtop Software Updater (HKLM-x32\…\Splashtop Software Updater) (Version: 1.5.6.15 - Splashtop Inc.)
Splashtop Streamer (HKLM-x32\…\{B7C5EA94-B96A-41F5-BE95-25D78B486678}) (Version: 2.6.2.4 - Splashtop Inc.)
SplitCam (HKLM-x32\…\SplitCam) (Version: 6.9.4.1 - SplitCam Co)
Suite Shared Configuration CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
Surfing Protection (HKLM-x32\…\IObit Surfing Protection_is1) (Version: 1.2 - IObit)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.1.6.0 - Synaptics Incorporated)
System Requirements Lab for Intel (HKLM-x32\…\{1EBDF6D2-CEA0-484C-A23E-2DDAD7FD0DD0}) (Version: 4.5.22.0 - Husdawg, LLC)
Target Generator (HKLM-x32\…\Target Generator1.0.0.3) (Version: 1.0.0.3 - AppBreed Software of InnAnTech Industries Inc.)
TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
Tee Inspector (HKLM-x32\…\Tee Inspector1.0.0.6) (Version: 1.0.0.6 - AppBreed Software of InnAnTech Industries Inc.)
The Logo Creator v6.6 (HKLM-x32\…\The Logo Creator) (Version: v6.6 - Laughingbird Software)
Times Reader (HKLM-x32\…\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1) (Version: 2.055 - The New York Times Company)
Times Reader (x32 Version: 2.055 - The New York Times Company) Hidden
Traffic SkyRocket (HKLM-x32\…\{1F0D32B8-B187-4295-A02C-CF5468F8E16F}) (Version: 1.0.0 - Traffic SkyRocket)
Traffic Travis 4.2.0 (HKLM-x32\…\Traffic Travis 4.2 Setup Wizard_is1) (Version: - Affilorama Ltd.)
Trapcode Suite v12.1.9 (HKLM-x32\…\{DFD2DC6B-C634-4C1C-81CC-5EF852E71CEE}_is1) (Version: 12.1.9 - Red Giant, LLC)
Tube Maker PRO 1.0 (HKLM-x32\…\Tube Maker PRO) (Version: 1.0 - Mark Dulisse)
UberQast (HKLM-x32\…\com.web1-syndication-inc.uberqast) (Version: 3.0.0.8 - Web1 Syndication, Inc.)
UberQast (x32 Version: 3.0.0 - Web1 Syndication, Inc.) Hidden
URLShotgunPro (HKLM-x32\…\URLShotgunPro) (Version: 1.0.1 - UNKNOWN)
URLShotgunPro (x32 Version: 1.0.1 - UNKNOWN) Hidden
Viber (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Viber) (Version: 4.4.0.134678 - Viber Media Inc)
Video Marketer (HKLM-x32\…\com.immortal-marketing.video-marketer) (Version: 3.0.0.4 - UNKNOWN)
Video Marketer (x32 Version: 3.0.0 - UNKNOWN) Hidden
Video Web Camera (HKLM-x32\…\InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}) (Version: 1.5.3018.00 - CyberLink Corp.)
Video Web Camera (x32 Version: 1.5.3018.00 - CyberLink Corp.) Hidden
Video2Gif version 1.0 (HKLM-x32\…\{FA80C47D-C9F1-482E-8D3C-69490CADCA3A}_is1) (Version: 1.0 - Mark Dulisse)
VideoMakerFX (HKLM-x32\…\VideoMakerFX 1.01) (Version: 1.01 - Webvati)
VideoMakerFX (x32 Version: 1.01 - Webvati) Hidden
VideoMakerFX Josh Ratta Bonus Scenes (HKLM-x32\…\{E7CAFBCF-1A20-4AF8-AE0E-89A8282CCA46}) (Version: 1.0 - Webvati)
VideoMakerFX ProThemes May Addon 1.0 (HKLM-x32\…\{6073BA7B-671F-4F41-AA93-05164AAE6A72}) (Version: 1.0 - Webvati)
VideoMakerFX VideoProfitFX Add On 1.0 (HKLM-x32\…\{8F99303E-4E46-45DC-964D-649DBC72B717}) (Version: 1.0 - Webvati)
VidNeos (HKLM-x32\…\VidNeos) (Version: 1.1.0 - UNKNOWN)
VidNeos (x32 Version: 1.1.0 - UNKNOWN) Hidden
Viewlio (HKLM-x32\…\groinup.outsourcing.youtubetool) (Version: 1.2.4 - Web1 Syndication, Inc.)
Viewlio (x32 Version: 1.2.4 - Web1 Syndication, Inc.) Hidden
VIPRE Antivirus (HKLM-x32\…\{C1D1FC57-3EB9-4B21-BCA3-F1C927508200}) (Version: 7.0.6.2 - ThreatTrack Security, Inc.)
VIPRE Antivirus (x32 Version: 7.0.6.2 - ThreatTrack Security, Inc.) Hidden
Viral Image Curator Pro (HKLM-x32\…\com.webdimensions.viralimagecuratorpro) (Version: 1.3.6 - Web Dimensions, Inc.)
Viral Image Curator Pro (x32 Version: 1.3.6 - Web Dimensions, Inc.) Hidden
VLC media player 2.1.3 (HKLM-x32\…\VLC media player) (Version: 2.1.3 - VideoLAN)
Website Submitter 5.0.0.0 (HKLM-x32\…\{1CED286D-B45F-46BB-8EF4-73924C0FC970}_is1) (Version: 5.0.0.0 - Fastlink2)
Welcome Center (HKLM-x32\…\Gateway Welcome Center) (Version: 1.02.3102 - Gateway Incorporated)
Whistle (HKLM-x32\…\{28992A1F-DFD4-4CA2-9F8D-8D8294FF6D2A}) (Version: 1.30.0 - Vail Systems)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\…\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinHTTrack Website Copier 3.47-27 (x64) (HKLM\…\WinHTTrack Website Copier_is1) (Version: 3.47.27 - HTTrack)
WinZip 19.0 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E5}) (Version: 19.0.11293 - WinZip Computing, S.L. )
x264vfw - H.264/MPEG-4 AVC codec for x64 (remove only) (HKLM-x32\…\x264vfw64) (Version: - )
XAMPP (HKLM-x32\…\xampp) (Version: 1.8.3-3 - Bitnami)
XMedia Recode version 3.1.7.7 (HKLM-x32\…\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.7.7 - XMedia Recode)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Program Files (x86)\Citrix\GoToMeeting\3215\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
==================== Restore Points =========================
16-08-2015 18:40:38 Windows Update
18-08-2015 14:28:49 tring to fix virus issues
18-08-2015 23:23:08 JRT Pre-Junkware Removal
19-08-2015 09:52:48 Windows Update
19-08-2015 12:10:04 getting ready install flipbook
20-08-2015 20:15:31 Revo Uninstaller Pro's restore point - RoboForm 7-9-14-4 (All Users)
21-08-2015 10:36:32 Windows Modules Installer
21-08-2015 10:37:01 Windows Modules Installer
22-08-2015 14:24:57 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 22:34 - 2015-08-19 00:53 - 00001721 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost wordpress wordpress1 wordpress2 wordpress3 wordpress4 wordpress5 wordpress6 wordpress7 wordpress8 wordpress9 wordpress10 wordpress351 wpsim
127.0.0.1 127.0.0.1
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 192.150.18.108
127.0.0.1 localhost
127.0.0.1 127.0.0.1
127.0.0.1 www.iobit.com
127.0.0.1 www.asc55.iobit.com
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {161F3F57-9F98-43C2-B884-2A81E14F61AC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-05] (Google Inc.)
Task: {1F29DAE0-568A-437D-9554-8275E9E9FEA3} - System32\Tasks\UALU notificatin => C:\Program Files\Gateway\Gateway Updater\UALU.exe [2012-04-05] (Acer Incorporated)
Task: {2CF826FF-E640-4DFE-9D78-F1FE65BF3FB4} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2015-07-06] (IObit)
Task: {3CC188A7-21DD-45C8-964E-5A9D8FEEB151} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2015-07-06] (IObit)
Task: {46BA7249-9A2D-4755-B3BF-D8FFECA438D3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-05] (Google Inc.)
Task: {49900C2D-E815-4512-9241-8698E003D042} - System32\Tasks\Driver Booster SkipUAC (Matts Windows7) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-07-06] (IObit)
Task: {69F236FF-8599-44E1-A0AB-34E5286215C5} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {7934C737-3A92-4B0E-BB0B-7E304159238D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.)
Task: {7DDAFE9A-CC40-44B2-B562-DDB58FA2567C} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2014-09-28] (Samsung Electronics.)
Task: {80C87536-2BAB-4555-9C59-3FA49D1BD921} - System32\Tasks\ASC8_SkipUac_Matts Windows7 => C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe [2015-06-16] (IObit)
Task: {869692B0-2CDB-4756-9DDC-F74346E9D169} - System32\Tasks\VIPRE Upgrade Task => C:\PROGRAM FILES\COMMON FILES\AV\ThreatTrack Security VIPRE\Upgrade.exe [2015-08-14] (ThreatTrack Security Inc.)
Task: {A3CB1314-4DD3-4302-B458-92521C31A2D7} - System32\Tasks\Red Giant Link => C:\Program Files\Red Giant Link\Red Giant Link.exe
Task: {A928F8E9-245A-4C2A-BFD6-F0AFFE2B9917} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [2014-07-31] (TechSmith Corporation)
Task: {B45970EE-97A8-42D1-AFDD-C3BD69ED555A} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {BAC008BE-218A-4A3B-B62F-F98C5400417A} - System32\Tasks\{E39722CC-5D81-4343-B049-24D4F71AE85D} => pcalua.exe -a "C:\Users\Matts Windows7\Desktop\setup-vipre-antivirus-en-us.exe" -d "C:\Users\Matts Windows7\Desktop"
Task: {C357B3D3-AF14-4CB0-AB4F-2EE436C91C29} - System32\Tasks\{1B26D4F7-75D2-485B-9BF1-94FB95852338} => pcalua.exe -a "C:\Users\Matts Windows7\Downloads\AdobeAIRInstaller.exe" -d "C:\Users\Matts Windows7\Downloads"
Task: {C4F4B161-73B2-41D8-A682-14066D75837D} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {C5F03AB6-FD0E-4A0F-9769-A019C85CB428} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-11] (Adobe Systems Incorporated)
Task: {C625DEDC-C9CE-4B79-A715-3A4139B80A29} - System32\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000 => C:\Program Files (x86)\Citrix\GoToMeeting\3277\g2mupdate.exe [2015-08-23] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {CAD45FFC-33CD-4837-8900-F21AE2963F4B} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2010-10-28] (CyberLink)
Task: {CC2A8EF4-1C90-42B9-AE0F-ED1EF3C3AD45} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 5600-6600 Series\ezprint.exe [2010-02-04] (Lexmark International Inc.)
Task: {E748E5A1-5EDD-449E-A967-BC710282DFE0} - System32\Tasks\SmartDefrag4_Update => C:\Program Files (x86)\IObit\Smart Defrag 4\AutoUpdate.exe [2015-03-03] (IObit)
Task: {EBD3BDDE-BEC3-4AD2-96D8-A670EBA0BBA0} - System32\Tasks\ASC8_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe [2015-06-10] (IObit)
Task: {EECFEE42-EBAC-4406-AC22-7489A88F608A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.)
Task: {F0776AAB-951D-40B0-A8C9-79E862C96B19} - System32\Tasks\Uninstaller_SkipUac_Matts_Windows7 => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-05-20] (IObit)
Task: {FECDB8C5-87F5-48EC-AF70-57B2B76198D2} - System32\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000 => C:\Program Files (x86)\Citrix\GoToMeeting\3277\g2mupload.exe [2015-08-23] (Citrix Online, a division of Citrix Systems, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job => C:\Program Files (x86)\Citrix\GoToMeeting\3277\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job => C:\Program Files (x86)\Citrix\GoToMeeting\3277\g2mupload.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2010-12-17 16:53 - 2010-12-17 16:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2013-04-06 14:27 - 2011-04-11 01:26 - 00034304 _____ () C:\Windows\System32\spe__l.dll
2011-06-22 10:44 - 2011-06-22 10:44 - 00034304 _____ () C:\Windows\System32\sst2cl6.dll
2012-05-15 10:58 - 2009-10-16 12:07 - 00186880 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdudrpp.dll
2015-02-13 05:20 - 2015-02-13 05:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-02-13 05:20 - 2015-02-13 05:20 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-07-24 16:05 - 2014-07-24 16:05 - 00210584 _____ () C:\Program Files (x86)\Livedrive\VSSService.exe
2013-04-06 14:27 - 2013-03-18 10:16 - 01353728 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\spe__du.dll
2011-06-22 10:43 - 2011-06-22 10:43 - 00826880 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\sst2cdu.dll
2012-05-15 10:57 - 2009-10-16 12:03 - 01401856 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxduptpc.dll
2012-05-15 10:57 - 2009-10-16 12:07 - 00196608 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxdudrui.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2010-01-02 10:42 - 2010-01-02 10:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2012-06-18 11:24 - 2012-06-18 11:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll
2010-12-17 16:53 - 2010-12-17 16:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-04-15 10:16 - 2011-03-25 20:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-03-01 03:12 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\sqlite3.dll
2015-03-01 02:31 - 2015-01-09 18:46 - 00517408 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\sqlite3.dll
2012-01-05 15:22 - 2012-01-05 15:22 - 00465344 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\sqlite3.dll
2012-01-05 15:22 - 2012-01-05 15:22 - 01081368 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\ACE.dll
2012-01-05 15:22 - 2012-01-05 15:22 - 00125464 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\MailConverter32.dll
2012-02-20 23:26 - 2012-02-20 23:26 - 00160768 _____ () C:\Program Files (x86)\VIPRE\unrar.dll
2015-03-01 03:12 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madExcept_.bpl
2015-03-01 03:12 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madBasic_.bpl
2015-03-01 03:12 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madDisAsm_.bpl
2015-02-13 05:20 - 2015-02-13 05:20 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2015-08-25 21:01 - 2015-08-25 21:01 - 00071168 _____ () c:\Users\Matts Windows7\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpc86hzw.dll
2015-03-04 17:45 - 2015-08-05 16:49 - 00012800 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll
2015-03-04 17:45 - 2015-08-05 16:49 - 00779776 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-07-30 21:28 - 2015-08-05 16:49 - 00056320 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-03-04 17:45 - 2015-08-05 16:49 - 00012288 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll
2015-08-25 21:01 - 2015-08-25 21:01 - 00098816 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32api.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00110080 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\pywintypes27.dll
2015-08-25 21:01 - 2015-08-25 21:01 - 00364544 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\pythoncom27.dll
2015-08-25 21:01 - 2015-08-25 21:01 - 00045568 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_socket.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 01161216 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_ssl.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00320512 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32com.shell.shell.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00713216 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_hashlib.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 01176576 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._core_.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00806400 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._gdi_.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00816128 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._windows_.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 01067008 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._controls_.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00733184 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._misc_.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00682496 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\pysqlite2._sqlite.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00087552 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_ctypes.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00119808 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32file.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00108544 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32security.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00007168 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\hashobjs_ext.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00068096 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\usb_ext.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00167936 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32gui.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00018432 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32event.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00128512 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_elementtree.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00127488 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\pyexpat.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00013824 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\common.time34.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00036864 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_psutil_windows.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00038912 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32inet.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00011264 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32crypt.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00077312 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._html2.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00027136 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_multiprocessing.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00020480 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_yappi.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00035840 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32process.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00686080 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\unicodedata.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00123392 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._wizard.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00024064 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32pipe.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00010240 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\select.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00025600 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32pdh.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00525640 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\windows._lib_cacheinvalidation.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00017408 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32profile.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00022528 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32ts.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00078848 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._animate.pyd
2014-02-06 14:09 - 2015-06-26 03:13 - 00184184 _____ () C:\Program Files (x86)\VIPRE\Definitions\libBase64.dll
2014-02-06 14:09 - 2015-06-26 03:13 - 00175992 _____ () C:\Program Files (x86)\VIPRE\Definitions\libMachoUniv.dll
2015-03-11 23:12 - 2014-09-28 17:59 - 00019872 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAMSUNG_SSD.dll
2015-03-01 03:12 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl
2015-03-01 03:12 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
2015-03-01 03:12 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
2014-10-17 12:26 - 2014-10-17 12:26 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\ba8588c3319d63350220ec2ac3eb2c36\IsdiInterop.ni.dll
2011-04-15 09:31 - 2010-09-13 21:28 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2012-01-08 09:41 - 2012-01-08 09:41 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2015-08-20 14:17 - 2015-08-18 01:23 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libglesv2.dll
2015-08-20 14:17 - 2015-08-18 01:23 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Windows:nlsPreferences
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBPIMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AmmyyAdmin => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\atashost => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBAMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBPIMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SplashtopRemoteService => ""="Service"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\aphelionasp.net -> aphelionasp.net
IE trusted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\webex.com -> hxxps://fiserventerprise.webex.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\100sexlinks.com -> 100sexlinks.com
There are 4789 more restricted sites.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: AmmyyAdmin => 2
MSCONFIG\Services: atashost => 2
MSCONFIG\Services: BstHdAndroidSvc => 2
MSCONFIG\Services: BstHdLogRotatorSvc => 2
MSCONFIG\Services: BstHdUpdaterSvc => 2
MSCONFIG\Services: GamesAppService => 3
MSCONFIG\Services: lxduCATSCustConnectService => 2
MSCONFIG\Services: lxdu_device => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: RichVideo => 2
MSCONFIG\Services: SpliCamService => 2
MSCONFIG\Services: TeamViewer9 => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^LTT.lnk => C:\Windows\pss\LTT.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Matts Windows7^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: 3xAV => C:\Program Files (x86)\Enounce\MySpeed\MySpeed.exe
MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeBridge =>
MSCONFIG\startupreg: AdobeCS4ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: Advanced SystemCare 8 => "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BackupManagerTray => "C:\Program Files (x86)\NTI\Gateway MyBackup\BackupManagerTray.exe" -h -k
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: ConferenceRS => C:\Windows\ConferenceRS.exe
MSCONFIG\startupreg: ConnectionCenter => "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
MSCONFIG\startupreg: EzPrint => "C:\Program Files (x86)\Lexmark 5600-6600 Series\ezprint.exe"
MSCONFIG\startupreg: GoogleChromeAutoLaunch_9F0FD1DA2B53BECFEBEA5616E08F9C6D => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" –no-startup-window
MSCONFIG\startupreg: HP ENVY 4500 series (NET) => "C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN4AS156NS05X4:NW" -scfn "HP ENVY 4500 series (NET)" -AutoStart 1
MSCONFIG\startupreg: IObit Malware Fighter => "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Jing => C:\Program Files (x86)\TechSmith\Jing\Jing.exe
MSCONFIG\startupreg: Livedrive => "C:\Program Files (x86)\Livedrive\Livedrive.exe" /setup
MSCONFIG\startupreg: lxdumon.exe => "C:\Program Files (x86)\Lexmark 5600-6600 Series\lxdumon.exe"
MSCONFIG\startupreg: MMReminderService => C:\Program Files (x86)\Mindjet\MindManager 10\MMReminderService.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
MSCONFIG\startupreg: SacReminderHDDV2 => C:\ProgramData\OfficeGuardianV2\reminder\SacReminder.exe
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{4994B15A-7B16-4892-B57D-22995C3B0A93}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{285D0772-3372-4239-8864-02FC3FF646D2}] => (Allow) LPort=2869
FirewallRules: [{888A4C9D-E2E2-456D-A957-594A71A226A4}] => (Allow) LPort=1900
FirewallRules: [{98937CF9-E1F7-449E-91D2-2214198F7469}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{5A5D406D-E383-4645-946F-E9472BDE5A0D}] => (Allow) C:\Program Files (x86)\CyberLink\HomeMedia\HomeMedia.exe
FirewallRules: [{406B9D8B-A434-48FA-8ACD-8BBD1F23B4F2}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel Wireless Display\WiDiApp.exe
FirewallRules: [{A5656061-2667-4672-8183-2A545E2BDD2A}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{C8D4D6C2-9006-4A4A-8403-71D855B8CCE6}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{C3AE7CA5-4AE0-4C03-80A9-4CCBE5709DF6}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{59CFCDAC-AE52-4F57-9733-B4C65A2C2FF7}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{3F752444-4AF6-47E5-BD06-02F41D392FDE}] => (Allow) LPort=5353
FirewallRules: [{692A01AB-0EAA-4DD2-BEFE-411D37519363}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
FirewallRules: [{887C0967-B7C1-46C5-89A3-E64C301AC2EC}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
FirewallRules: [TCP Query User{A8C8CE57-899C-42F8-9883-00200389CD47}C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{B880609C-BE39-4C11-95F9-9196F7A30655}C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{216CDBBE-F30A-40CC-BFB3-7312C6C22F8D}] => (Allow) C:\Windows\SysWOW64\lxducoms.exe
FirewallRules: [{0623DF9B-AA1D-42BE-9EC6-CF670C3FE0B9}] => (Allow) C:\Windows\SysWOW64\lxducoms.exe
FirewallRules: [{1E38857E-3C51-47E4-B76B-0622709C55A6}] => (Allow) C:\Windows\System32\lxducoms.exe
FirewallRules: [{F7A5EBD0-606D-4412-A016-90654E816D10}] => (Allow) C:\Windows\System32\lxducoms.exe
FirewallRules: [{FB3CAC58-CD4C-4F6E-9CC9-0E800B445FFD}] => (Allow) C:\Windows\system32\lxducoms.exe
FirewallRules: [{4004F364-20E4-4AD4-9510-3D6C441B6EA8}] => (Allow) C:\Windows\system32\spool\DRIVERS\x64\3\lxdupswx.exe
FirewallRules: [{E6FB8A6B-BB07-4A45-BBCE-9D782ED8FEBA}] => (Allow) C:\Windows\system32\spool\DRIVERS\x64\3\lxdutime.exe
FirewallRules: [{68EF4A10-F9B7-44B8-9E6A-988D6E0EEAD9}] => (Allow) C:\Windows\SysWOW64\lxducoms.exe
FirewallRules: [{2D773B35-093F-4CBF-BFAC-85A70C53B71D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0B0DAB0C-8F45-44F6-88B1-ACA89B9FF9C2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{33C28F0F-151D-4FF1-BE67-A79BBE5F3DCF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{83B81423-B95F-4ACC-AA23-0D96895D2DF5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4164D113-7D6D-41F3-A645-C498E764F821}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Print Driver 2\PrinterSelector\SUPDApp.exe
FirewallRules: [TCP Query User{1B420190-0675-4A38-84EA-C1F18E88DC3E}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{B33C280E-732E-4884-9720-F251B9CD8B3C}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{59838EEF-E840-46C8-B078-8936831DC67C}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{9337AD9B-6BB2-4622-8A5B-D7092C8AF684}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [TCP Query User{3DB83B16-7DDB-4304-AA83-DAB6154A6B24}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{75991F7B-1AE4-493C-9C8E-F74D2B7E8BD2}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{F7140CF0-4721-4019-96DE-EA9AA1699405}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{31D3216E-D052-40C1-892B-5B660E81CEEA}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [{3587FB72-4931-45E0-88B7-2C07F57A5B8B}] => (Block) %ProgramFiles% (x86)\Sparkol\Sparkol VideoScribe\VideoScribeDesktop.exe
FirewallRules: [TCP Query User{C27D82DC-90E6-4759-9F6F-0EDF90F5B402}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{28553A58-082D-4C80-822A-21CA4319A502}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [{3B51A5B6-D8D1-470E-B6EA-A4F3ABBA64EC}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6D30E3DF-9CD4-41CA-A38D-388B8771BB8E}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{E946012A-54A6-4D39-9CBE-57DFD071D68B}C:\program files\winhttrack\winhttrack.exe] => (Allow) C:\program files\winhttrack\winhttrack.exe
FirewallRules: [UDP Query User{ECA7A336-5DB8-46A7-A781-37B52DFF2EA0}C:\program files\winhttrack\winhttrack.exe] => (Allow) C:\program files\winhttrack\winhttrack.exe
FirewallRules: [TCP Query User{BC231830-FC16-4CE3-B3E3-7FFDE39EA008}C:\program files\reflector\reflector.exe] => (Allow) C:\program files\reflector\reflector.exe
FirewallRules: [UDP Query User{F80CEC39-54AD-4E8A-AD5F-A726221A7699}C:\program files\reflector\reflector.exe] => (Allow) C:\program files\reflector\reflector.exe
FirewallRules: [{D494E31C-B123-41F2-9787-9A71F62624CD}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{3B7A911E-EC62-4E24-90B1-123706B92DEA}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B226DE14-AB84-42FD-9B82-9DA07BFA12AA}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{05192244-B159-416C-9768-0D96679044C3}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{A525CCB4-2C86-4595-8CF4-3073D9FC8A7D}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{703017D9-876E-43E7-9C38-626880ED8030}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [TCP Query User{3DB8486D-D86B-4ED1-84D4-6A958F828F63}C:\programdata\microsoft\windows\start menu\programs\whistle.exe] => (Allow) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [UDP Query User{7BA04638-F71E-4B49-A0C6-8961CAEDF83C}C:\programdata\microsoft\windows\start menu\programs\whistle.exe] => (Allow) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [{56FE4147-C0BD-45AD-A487-914998E9F139}] => (Block) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [{438A4B5C-9673-4DB2-9A38-BB874DB793D6}] => (Block) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [{9F5B86D5-CA8B-4773-8DC1-ACC173DDE3F7}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{926F81CA-F346-4D6C-A473-51F7B0383DFF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{46B5B8C4-60E9-4D30-80B5-C71DC2B6643B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{6544F860-06B6-4FCA-9A63-AD3BC7DC7820}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{B9C8E0E7-2CFC-4447-A338-8D4F8E60ECFC}] => (Allow) LPort=8298
FirewallRules: [{864EF2AD-43AA-4664-9ACD-2EE60F69AAC8}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\DeviceSetup.exe
FirewallRules: [{68409358-C465-4D0A-AC68-388087D47BC7}] => (Allow) LPort=5357
FirewallRules: [{818B2472-4269-4FFB-AE3D-3A325B7EACFB}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{4210C355-B346-4F1F-8D74-8EA28D76F06A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C3EC7734-FE0E-4217-B64A-E28B51F787ED}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{22655FD0-A089-4539-B38B-E36F8DC29BFD}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [UDP Query User{04952FD7-B0D2-4ADE-A11C-52E9291D556E}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [TCP Query User{9E888F1E-F8D7-4F9E-95D1-D1D23B527956}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [UDP Query User{AFEC9CFD-5D68-4F03-9C56-CEFFF37F0855}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [TCP Query User{18850C7D-8832-4C09-A98A-EE84F6A9A83F}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{97ED0F4F-5A4A-4B0C-89E5-327F80F7506F}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [{64F35FE2-2045-4D89-97D0-0190D4D1EE53}] => (Allow) LPort=15600
FirewallRules: [{E6007C73-4446-4CBE-A702-096C73B9E1F0}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{499B0422-5E3F-433A-A603-A922BB1B357E}C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [UDP Query User{82A5671A-AAAB-43C1-8699-B67EC583658F}C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [{090184A1-4EDD-4ED9-8BF1-AE5C1A3B14F5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{8FC63A2B-FC58-48BD-B27F-0F4725678CA5}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
FirewallRules: [{BA6C668D-C4FD-4858-AFCB-B7173FADE7F2}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
FirewallRules: [{0C3C6DC1-6339-43E6-9DF7-B084B9F64EFF}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\DataProxy.exe
==================== Faulty Device Manager Devices =============
Name: SBRE
Description: SBRE
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SBRE
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (08/25/2015 09:01:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/25/2015 09:01:40 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/25/2015 08:44:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GWXUX.exe, version: 6.3.9600.17923, time stamp: 0x55945dbd
Faulting module name: ntdll.dll, version: 6.1.7601.18939, time stamp: 0x55b02e88
Exception code: 0xc0000005
Fault offset: 0x000000000004ac04
Faulting process id: 0xfc0
Faulting application start time: 0xGWXUX.exe0
Faulting application path: GWXUX.exe1
Faulting module path: GWXUX.exe2
Report Id: GWXUX.exe3
Error: (08/25/2015 08:34:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/25/2015 08:34:41 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/25/2015 10:08:03 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/25/2015 10:08:02 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/24/2015 04:29:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 40.0.2.5702, time stamp: 0x55cc03bd
Faulting module name: mozglue.dll, version: 40.0.2.5702, time stamp: 0x55cbf190
Exception code: 0x80000003
Fault offset: 0x0000e631
Faulting process id: 0xe68
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Error: (08/24/2015 11:06:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SRFeature.exe, version: 2.62.6.5913, time stamp: 0x546d7ba8
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00e94fa8
Faulting process id: 0xac8
Faulting application start time: 0xSRFeature.exe0
Faulting application path: SRFeature.exe1
Faulting module path: SRFeature.exe2
Report Id: SRFeature.exe3
Error: (08/24/2015 11:05:56 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (08/25/2015 09:02:44 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
Error: (08/25/2015 09:02:40 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)
Error: (08/25/2015 09:01:44 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
SBRE
Error: (08/25/2015 09:01:40 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The BlueStacks Android Service service terminated with the following error:
%%1064
Error: (08/25/2015 09:01:21 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\Windows\System32\IWMSSvc.dll
Error: (08/25/2015 09:01:21 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\Windows\System32\IWMSSvc.dll
Error: (08/25/2015 09:01:21 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\Windows\System32\IWMSSvc.dll
Error: (08/25/2015 09:01:20 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\Windows\System32\IWMSSvc.dll
Error: (08/25/2015 09:01:11 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Modules Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
Error: (08/25/2015 09:01:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) Management and Security Application User Notification Service service terminated unexpectedly. It has done this 1 time(s).
Microsoft Office:
=========================
Error: (08/25/2015 09:01:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/25/2015 09:01:40 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/25/2015 08:44:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: GWXUX.exe6.3.9600.1792355945dbdntdll.dll6.1.7601.1893955b02e88c0000005000000000004ac04fc001d0df9865fea0cfC:\Windows\System32\GWX\GWXUX.exeC:\Windows\SYSTEM32\ntdll.dlla42cdf30-4b8b-11e5-9031-b870f48410d0
Error: (08/25/2015 08:34:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/25/2015 08:34:41 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/25/2015 10:08:03 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/25/2015 10:08:02 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (08/24/2015 04:29:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.2.570255cc03bdmozglue.dll40.0.2.570255cbf190800000030000e631e6801d0dea3ce8b0562C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dllc18367d4-4a9e-11e5-90ee-b870f48410d0
Error: (08/24/2015 11:06:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: SRFeature.exe2.62.6.5913546d7ba8unknown0.0.0.000000000c000000500e94fa8ac801d0de7e60408f4bC:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exeunknowna26e7d17-4a71-11e5-90ee-b870f48410d0
Error: (08/24/2015 11:05:56 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
CodeIntegrity:
===================================
Date: 2015-08-15 23:17:13.727
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2015-08-15 23:17:13.696
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
Percentage of memory in use: 47%
Total physical RAM: 8043.86 MB
Available physical RAM: 4193.6 MB
Total Virtual: 16085.92 MB
Available Virtual: 12064 MB
==================== Drives ================================
Drive c: (Gateway) (Fixed) (Total:419.08 GB) (Free:113.16 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 380202E7)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=419.1 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================