This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please Help get rid of totaladperformance & tradeadexchange in Chr

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi I have this issue that I have been trying to resolve.  I have issues only in Chrome.  At least I only know of.  I use Chrome 97% of the time.  I first was receiving a redirect script whenever I click on anything on any domain.  It would lead me to totalperformance dot com.  I ended up installing "Block Site app" and just redirect all traffic from that link to google.  This happened a few months ago and at that time I cleaned the computer with (Malwarebytes, AdwCleaner, Vipre, IObit Malware Fighter, and a few more.  I was getting annoyed with this redirect and dig some digging and tried to take on and fix this issue.  I tried to clean out Google sync settings and take out some of the default settings.  I have some Apps/Extensions I don't want to lose.  After doing that.  I staarted getting the tradeadexchange dot com redirect.  I also notice at the top of my bookmarks was 4 page links.

 

1)  goz.bz/fAFvMv - tab name: sexy picture
2)  goz.bz/EJR3An - tab name: hot games
3)  goz.bz/NJfeUn - tab name: big farm

 

I went into bookmarks and deleted them and once again ran several programs trying to resolve all of these issues.  I also ran things that may of damage my system (Combofix).  After doing some of the deleting and stuff.  I had to fix Adobe Acrobat and few other programs because of what I did.  That was an easy fix.  As of today I still have issues with the redirect.

 

I tried to run the program aswMBR

When I do run it.  It eventually crashes the computer and then it re-starts.

 

Here is the report file for Farbar Recovery Scan Tool

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:17-08-2015
Ran by [removed] (administrator) on MATTSWINDOWS7 (18-08-2015 14:48:58)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Storage Appliance Corp.) C:\ProgramData\OfficeGuardianV2\UACProxy.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Acer Incorporated) C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
() C:\Program Files (x86)\Livedrive\VSSService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe
(ThreatTrack Security, Inc.) C:\Program Files (x86)\VIPRE\SBPIMSvc.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
(Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Skillbrains) C:\Users\Matts Windows7\AppData\Local\Skillbrains\lightshot\5.1.4.41\Lightshot.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Dropbox, Inc.) C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(ThreatTrack Security, Inc.) C:\Program Files (x86)\VIPRE\SBAMTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
(ThreatTrack Security, Inc.) C:\Program Files (x86)\VIPRE\SBAMSvc.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\DataProxy.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Siber Systems Inc.) C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome-nm-host.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel(R) Corporation)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2280232 2010-07-29] (Synaptics Incorporated)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11785832 2011-03-10] (Realtek Semiconductor)
HKLM\…\Run: [Power Management] => C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe [1796200 2011-02-23] (Acer Incorporated)
HKLM\…\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
HKLM\…\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [281776 2014-09-16] (Samsung Electronics Co., Ltd.)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\…\Run: [SBAMTray] => C:\Program Files (x86)\VIPRE\SBAMTray.exe [3216272 2013-09-05] (ThreatTrack Security, Inc.)
HKLM-x32\…\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2620728 2015-07-22] (Malwarebytes Corporation)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation)
HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22344224 2015-07-29] (Google)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [LightShot] => C:\Users\Matts Windows7\AppData\Local\Skillbrains\lightshot\Lightshot.exe [226560 2014-07-01] ()
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [OneDrive] => C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\OneDrive.exe [402632 2015-07-27] (Microsoft Corporation)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [Dropbox Update] => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-15] (Dropbox, Inc.)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110160 2015-07-28] (Siber Systems)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3903056 2015-05-20] (Tonec Inc.)
AppInit_DLLs: C:\Windows\System32\acaptuser64.dll => C:\Windows\System32\acaptuser64.dll [119160 2008-06-12] (Adobe Systems, Inc.)
AppInit_DLLs-x32: C:\PROGRA~2\Citrix\ICACLI~1\RSHook.dll => C:\Program Files (x86)\Citrix\ICA Client\RSHook.dll [257208 2012-05-23] (Citrix Systems, Inc.)
AppInit_DLLs-x32:  acaptuser32.dll => "acaptuser32.dll" File not found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2014-08-09]
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-02-12]
ShortcutTarget: Dropbox.lnk -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [BackupOverlay] -> {B44A5D93-1351-41A1-BD91-5E92435D8ECD} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll [2012-11-10] (EldoS Corporation)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2014-04-21] (Tonec Inc.)
ShellIconOverlayIdentifiers: [LivedriveDownloadOverlay] -> {CBCDB610-6B68-4EE9-B7A2-1282FD0C9292} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveSharedOverlay] -> {84CEF1E4-1356-4063-845F-05047F4DD52C} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveSyncedOverlay] -> {42058329-2FBF-4B33-8E52-3BE5754DE0C1} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveUploadOverlay] -> {39A1715A-E4CD-4F1E-B5C4-36B5DB80124E} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll [2012-11-10] (EldoS Corporation)
BootExecute: autocheck autochk * SmartDefragBootTime.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000 -> DefaultScope {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2015-07-28] (Siber Systems Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08] (Adobe Systems Incorporated)
BHO-x32: CmjBrowserHelperObject Object -> {6FE6A929-59D1-4763-91AD-29B61CFFB35B} -> C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll [2011-09-14] (Mindjet)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2015-07-28] (Siber Systems Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-21] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: VIPRE Search Guard Helper -> {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} -> C:\Program Files (x86)\VIPRE\VSG.dll [2013-09-05] ()
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Lexmark Printable Web -> {D2C5E510-BE6D-42CC-9F61-E4F939078474} -> C:\Program Files\Lexmark Printable Web\bho.dll [2010-02-04] ()
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-21] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} -  No File
Toolbar: HKLM - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2015-07-28] (Siber Systems Inc.)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - C:\Program Files (x86)\VIPRE\VSG.dll [2013-09-05] ()
Toolbar: HKLM-x32 - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2015-07-28] (Siber Systems Inc.)
Toolbar: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} hxxps://fiserventerprise.webex.com/client/WBXclient-T27L10NSP32EP5-14362/support/ieatgpc1.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler-x32: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - C:\Program Files (x86)\VIPRE\VSG.dll [2013-09-05] ()
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{12A99469-5D32-4F0D-A147-834FA18A0312}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{74A46DCB-14BB-4752-B3FB-9562D1C5B0B1}: [NameServer] 192.168.1.254
Tcpip\..\Interfaces\{74A46DCB-14BB-4752-B3FB-9562D1C5B0B1}: [DhcpNameServer] 10.251.4.1
 
FireFox:
========
FF ProfilePath: C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default
FF NetworkProxy: "gopher", ""
FF NetworkProxy: "gopher_port", 0
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-11] ()
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2014-08-09] (LastPass)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2013-03-21] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-11] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2012-05-23] (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-21] (Oracle Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass.dll [2014-08-09] (LastPass)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2013-03-21] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Matts Windows7\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2013-05-29] (Citrix Online)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Matts Windows7\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @talk.google.com/O1DPlugin -> C:\Users\Matts Windows7\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Matts Windows7\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Matts Windows7\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Extension: FoxyProxy Standard - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2015-06-02]
FF Extension: LastPass - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2015-07-22]
FF Extension: SeoQuake - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74} [2015-06-05]
FF Extension: ColorZilla - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2015-05-28]
FF Extension: iMacros for Firefox - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2015-05-29]
FF Extension: Live HTTP headers - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2015-05-28]
FF Extension: Firebug - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2012-01-12]
FF Extension: VTzilla - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2012-01-12]
FF Extension: HMA! IP Checker - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2013-12-23]
FF Extension: SpyBar - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2015-08-06]
FF Extension: Multi Links - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2014-11-13]
FF Extension: Real Hide IP - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2012-04-28]
FF Extension: S3 Firefox Organizer(S3Fox) - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{7CEA821D-3DAB-4238-B424-BF7324531750}.xpi [2014-01-10]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2014-03-12]
FF Extension: Web Developer - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2014-02-03]
FF Extension: Adblock Plus - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-18]
FF Extension: SearchStatus - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{d57c9ff1-6389-48fc-b770-f78bd89b6e8a}.xpi [2014-11-13]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-09]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-09]
FF HKLM-x32\…\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox
FF Extension: RoboForm Toolbar for Firefox - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2015-07-28]
FF HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox
FF HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Matts Windows7\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Matts Windows7\AppData\Roaming\IDM\idmmzcc5 [2015-08-18]
FF HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\Matts Windows7\AppData\Roaming\IDM\idmmzcc5
 
Chrome: 
=======
CHR Profile: C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-22]
CHR Extension: (Google Docs) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-01]
CHR Extension: (Google Drive) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-01]
CHR Extension: (YouTube) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-01]
CHR Extension: (Precise Interest Profits) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cboffagmdlncaldokfebdghmcfnloffa [2014-06-06]
CHR Extension: (Adblock Plus) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-10-21]
CHR Extension: (Google Search) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-01]
CHR Extension: (SpyBar) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkcihmjnfimlnmdjoddhjfiihbfpcnfk [2014-06-03]
CHR Extension: (Block site) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimnmioipafcokbfikbljfdeojpcgbh [2015-05-28]
CHR Extension: (FB Pixel Helper) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdgfkebogiimcoedlicjlajpkdmockpc [2014-07-04]
CHR Extension: (Google Sheets) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-22]
CHR Extension: (Audience Intersect) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjeffkdcbmggkbkedhbjemcpmgfccpil [2014-10-10]
CHR Extension: (Video Downloader Super) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghciphhakbampjemlfbahnhhaemoeolf [2015-02-16]
CHR Extension: (Follow) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkakfimgbmogkpmjokgnbbanmmemcdij [2014-06-26]
CHR Extension: (Pin It Button) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2014-09-29]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2015-08-13]
CHR Extension: (Video Downloader) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnmpgleggfcndpeflbjhpjfckfmojnpo [2015-02-10]
CHR Extension: (SocialPinSniper) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\llfojbapbcelaoniflkhioicjmlpileg [2015-02-14]
CHR Extension: (Sunrise Calendar) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\mojepfklcankkmikonjlnidiooanmpbb [2015-08-18]
CHR Extension: (EXIF Viewer) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafpfdcmppffipmhcpkbplhkoiekndck [2015-07-27]
CHR Extension: (IDM Integration Module) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-07-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-01]
CHR Extension: (Docs PDF/PowerPoint Viewer (by Google)) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbmlagghjjcbdhgmkedmbmedengocbn [2014-02-01]
CHR Extension: (Pingler) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgiehjnopebofbjkgdjenflakfaahnm [2014-12-22]
CHR Extension: (Gmail) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-01]
CHR Extension: (Headlinr) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\plhlpcokjhajajgmpbapiohjhldkjdbi [2015-05-07]
CHR Extension: (RoboForm Password Manager) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2015-07-28]
CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
CHR HKLM\…\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2015-07-28]
CHR HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
CHR HKLM-x32\…\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2015-07-28]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdvancedSystemCareService8; C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [814880 2015-04-03] (IObit)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-03-13] (BlueStack Systems, Inc.)
S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-03-13] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [770832 2014-03-13] (BlueStack Systems, Inc.)
R2 CFUACProxy_officeguardianv2; C:\ProgramData\OfficeGuardianV2\UACProxy.exe [83792 2011-07-25] (Storage Appliance Corp.)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [878912 2015-04-02] (IObit)
R2 LivedriveVSSService; C:\Program Files (x86)\Livedrive\VSSService.exe [210584 2014-07-24] ()
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-30] (IObit)
S4 lxduCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\lxduserv.exe [29184 2009-10-16] (Lexmark International, Inc.)
S4 lxdu_device; C:\Windows\system32\lxducoms.exe [1039360 2009-10-16] ( )
S4 lxdu_device; C:\Windows\SysWOW64\lxducoms.exe [589824 2009-10-16] ( )
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [713016 2015-07-22] (Malwarebytes Corporation)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
R2 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2011-01-31] (Nalpeiron Ltd.) [File not signed]
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe [256536 2012-01-05] (NTI Corporation)
S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe [244904 2010-10-27] () [File not signed]
R2 SamsungRapidSvc; C:\Windows\System32\RAPID\SamsungRapidSvc.exe [28848 2014-09-16] (Samsung Electronics Co., Ltd.)
R2 SBAMSvc; C:\Program Files (x86)\VIPRE\SBAMSvc.exe [3937472 2013-09-05] (ThreatTrack Security, Inc.)
R2 SBPIMSvc; C:\Program Files (x86)\VIPRE\SBPIMSvc.exe [176016 2013-09-05] (ThreatTrack Security, Inc.)
S4 SpliCamService; C:\Program Files (x86)\SplitCam\SplitCamService.exe [311424 2014-09-15] (SplitCam Co.)
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [121616 2014-03-13] (BlueStack Systems)
S3 catchme; no ImagePath
R3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [352008 2012-11-10] (EldoS Corporation)
S3 cpudrv64; C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [17864 2011-06-02] ()
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [63064 2015-07-22] ()
S4 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2015-03-25] (IObit)
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
S3 gfiutil; C:\Windows\System32\drivers\gfiutil.sys [31264 2013-09-04] (ThreatTrack Security)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-03-01] (REALiX™)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
R3 NETwNs64; C:\Windows\System32\DRIVERS\NETwsw01.sys [11534096 2015-08-11] (Intel Corporation)
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2015-03-25] (IObit.com)
R0 SamsungRapidDiskFltr; C:\Windows\System32\DRIVERS\SamsungRapidDiskFltr.sys [268976 2014-09-16] (Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\Windows\System32\DRIVERS\SamsungRapidFSFltr.sys [111280 2014-09-16] (Samsung Electronics Co., Ltd.)
R2 sbapifs; C:\Windows\System32\DRIVERS\sbapifs.sys [88928 2013-06-18] (ThreatTrack Security, Inc.)
S1 SBRE; no ImagePath
R3 scvad_simple; C:\Windows\System32\drivers\SplitCamAudio.sys [23552 2014-06-30] (Windows (R) Win 7 DDK provider)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
R3 splitcam_hd_driver; C:\Windows\System32\DRIVERS\splitcam_hd_driver.sys [37496 2014-06-30] (Windows (R) Win 7 DDK provider)
R3 stdpms; C:\Windows\System32\DRIVERS\stdpms.sys [28904 2013-10-22] (Splashtop Inc.)
S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2015-03-25] (IObit.com)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-18 14:48 - 2015-08-18 14:49 - 00050035 _____ C:\Users\Matts Windows7\Desktop\FRST.txt
2015-08-18 14:34 - 2015-08-18 14:34 - 02173440 _____ (Farbar) C:\Users\Matts Windows7\Desktop\FRST64.exe
2015-08-18 12:47 - 2015-08-18 14:34 - 00000844 _____ C:\Users\Matts Windows7\Desktop\virus.txt
2015-08-18 12:21 - 2011-01-26 11:25 - 00000000 ____D C:\Users\Matts Windows7\Desktop\The Top 100 Best Fonts of All Time
2015-08-18 11:02 - 2015-08-18 11:02 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-18 09:47 - 2015-08-18 09:49 - 134128457 _____ C:\Users\Matts Windows7\Desktop\May 7th Webinar Replay.MP4
2015-08-18 08:05 - 2015-08-18 08:05 - 00000000 ___HD C:\OneDriveTemp
2015-08-17 13:34 - 2015-08-18 08:04 - 00000112 _____ C:\Windows\setupact.log
2015-08-17 13:34 - 2015-08-17 13:34 - 00000840 _____ C:\Windows\PFRO.log
2015-08-17 13:34 - 2015-08-17 13:34 - 00000000 _____ C:\Windows\setuperr.log
2015-08-17 13:33 - 2008-04-07 06:38 - 00051032 ____R (Adobe Systems Inc) C:\Windows\system32\AdobePDF.dll
2015-08-17 13:33 - 2008-04-07 06:38 - 00024416 ____R (Adobe Systems Inc.) C:\Windows\system32\AdobePDFUI.dll
2015-08-17 12:32 - 2015-08-17 12:32 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Social Multiplier
2015-08-17 02:29 - 2015-08-17 02:30 - 00000000 ____D C:\Users\Matts Windows7\Desktop\VC Color Vibrance Plugin
2015-08-17 01:56 - 2015-08-17 01:56 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Element 3D V2.2.0.2100 (Win)
2015-08-16 00:44 - 2015-08-17 18:17 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Social Video Formula
2015-08-16 00:05 - 2015-08-16 00:06 - 00000894 _____ C:\AdwCleaner[S20].txt
2015-08-15 23:56 - 2015-08-15 23:56 - 00067456 _____ C:\ComboFix.txt
2015-08-15 23:09 - 2011-06-26 02:45 - 00256000 _____ C:\Windows\PEV.exe
2015-08-15 23:09 - 2010-11-07 13:20 - 00208896 _____ C:\Windows\MBR.exe
2015-08-15 23:09 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00098816 _____ C:\Windows\sed.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00080412 _____ C:\Windows\grep.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00068096 _____ C:\Windows\zip.exe
2015-08-15 23:08 - 2015-08-15 23:57 - 00000000 ____D C:\Qoobox
2015-08-15 23:07 - 2015-08-15 23:45 - 00000000 ____D C:\Windows\erdnt
2015-08-15 23:01 - 2015-08-17 15:23 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Virus protection
2015-08-15 22:54 - 2015-08-15 22:54 - 00001083 _____ C:\AdwCleaner[C10].txt
2015-08-15 22:52 - 2015-08-15 22:53 - 00000900 _____ C:\AdwCleaner[S19].txt
2015-08-15 22:44 - 2015-08-15 22:44 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\LavasoftStatistics
2015-08-15 22:43 - 2015-08-15 22:43 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2015-08-15 22:37 - 2015-08-15 22:37 - 00000000 ____D C:\ProgramData\Lavasoft
2015-08-15 22:29 - 2015-08-15 22:33 - 00000000 ____D C:\AdwCleaner
2015-08-14 19:38 - 2015-08-14 19:38 - 00000027 _____ C:\Users\Matts Windows7\Desktop\BUY.txt
2015-08-14 19:01 - 2015-08-14 19:02 - 41019438 _____ C:\Users\Matts Windows7\Desktop\Element 3D V2.2   Crack.mp4
2015-08-14 18:19 - 2015-08-14 18:44 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Digital Profits Academy
2015-08-14 17:08 - 2015-08-14 17:12 - 00000000 ____D C:\Users\Matts Windows7\Desktop\videohive-8592149-code-source
2015-08-14 14:36 - 2015-08-14 14:36 - 15901641 _____ C:\Users\Matts Windows7\Desktop\attachments.zip
2015-08-13 13:55 - 2015-08-13 13:55 - 00000060 _____ C:\Users\Matts Windows7\Desktop\DOOOOOOOOOOOOOOOO.txt
2015-08-12 17:34 - 2015-07-30 09:13 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 17:34 - 2015-07-30 09:13 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 16:41 - 2015-08-12 16:41 - 00001057 _____ C:\Users\Matts Windows7\Desktop\[BBHF VIP Sachin's Cracked] Long Tail Pro Platinum 3.0.11 Updated.txt
2015-08-12 16:34 - 2015-08-12 16:35 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Immersion Session 3
2015-08-12 13:53 - 2015-07-28 16:09 - 00017344 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-08-12 13:53 - 2015-07-28 16:05 - 01116672 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00774656 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00743424 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00437760 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-08-12 13:53 - 2015-07-28 15:55 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-08-12 13:53 - 2015-07-15 14:15 - 05568960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-12 13:53 - 2015-07-15 14:15 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-08-12 13:53 - 2015-07-15 14:15 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-08-12 13:53 - 2015-07-15 14:15 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-12 13:53 - 2015-07-15 14:12 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-12 13:53 - 2015-07-15 14:11 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-08-12 13:53 - 2015-07-15 14:11 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-08-12 13:53 - 2015-07-15 14:11 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-08-12 13:53 - 2015-07-15 14:11 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-08-12 13:53 - 2015-07-15 14:11 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 01743360 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-08-12 13:53 - 2015-07-15 14:10 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-08-12 13:53 - 2015-07-15 14:10 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-08-12 13:53 - 2015-07-15 14:10 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-12 13:53 - 2015-07-15 14:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-08-12 13:53 - 2015-07-15 14:09 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-08-12 13:53 - 2015-07-15 14:05 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-08-12 13:53 - 2015-07-15 14:05 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 14:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:59 - 03989952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-08-12 13:53 - 2015-07-15 13:59 - 03934656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-08-12 13:53 - 2015-07-15 13:56 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-08-12 13:53 - 2015-07-15 13:55 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-08-12 13:53 - 2015-07-15 13:55 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-08-12 13:53 - 2015-07-15 13:55 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-08-12 13:53 - 2015-07-15 13:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-08-12 13:53 - 2015-07-15 13:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-08-12 13:53 - 2015-07-15 13:54 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-08-12 13:53 - 2015-07-15 13:54 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-08-12 13:53 - 2015-07-15 13:54 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-08-12 13:53 - 2015-07-15 13:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-08-12 13:53 - 2015-07-15 13:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-08-12 13:53 - 2015-07-15 13:54 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-08-12 13:53 - 2015-07-15 13:54 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-08-12 13:53 - 2015-07-15 13:53 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-08-12 13:53 - 2015-07-15 13:53 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-08-12 13:53 - 2015-07-15 13:53 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-08-12 13:53 - 2015-07-15 13:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-08-12 13:53 - 2015-07-15 13:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-08-12 13:53 - 2015-07-15 13:53 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-08-12 13:53 - 2015-07-15 13:49 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-08-12 13:53 - 2015-07-15 13:48 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 13:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 12:46 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-08-12 13:53 - 2015-07-15 12:46 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-08-12 13:53 - 2015-07-15 12:46 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-08-12 13:53 - 2015-07-15 12:37 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-08-12 13:53 - 2015-07-15 12:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-08-12 13:53 - 2015-07-15 12:34 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 12:34 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 12:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-12 13:53 - 2015-07-15 12:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-12 13:52 - 2015-07-20 20:39 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-12 13:52 - 2015-07-20 20:12 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-08-12 13:52 - 2015-07-16 17:14 - 25192448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-12 13:52 - 2015-07-16 16:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-12 13:52 - 2015-07-16 16:54 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-08-12 13:52 - 2015-07-16 16:37 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-08-12 13:52 - 2015-07-16 16:36 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-12 13:52 - 2015-07-16 16:36 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-12 13:52 - 2015-07-16 16:36 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-08-12 13:52 - 2015-07-16 16:35 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-12 13:52 - 2015-07-16 16:35 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-08-12 13:52 - 2015-07-16 16:27 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-12 13:52 - 2015-07-16 16:26 - 05923328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-12 13:52 - 2015-07-16 16:26 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-08-12 13:52 - 2015-07-16 16:23 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-12 13:52 - 2015-07-16 16:21 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-12 13:52 - 2015-07-16 16:21 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-08-12 13:52 - 2015-07-16 16:21 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-12 13:52 - 2015-07-16 16:21 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-08-12 13:52 - 2015-07-16 16:20 - 19870208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-08-12 13:52 - 2015-07-16 16:12 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-12 13:52 - 2015-07-16 16:08 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-12 13:52 - 2015-07-16 16:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-08-12 13:52 - 2015-07-16 16:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-12 13:52 - 2015-07-16 15:55 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-08-12 13:52 - 2015-07-16 15:54 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-12 13:52 - 2015-07-16 15:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-08-12 13:52 - 2015-07-16 15:51 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-12 13:52 - 2015-07-16 15:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-08-12 13:52 - 2015-07-16 15:50 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-08-12 13:52 - 2015-07-16 15:50 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-08-12 13:52 - 2015-07-16 15:49 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-08-12 13:52 - 2015-07-16 15:45 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-08-12 13:52 - 2015-07-16 15:43 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-08-12 13:52 - 2015-07-16 15:43 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-08-12 13:52 - 2015-07-16 15:41 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-08-12 13:52 - 2015-07-16 15:39 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-08-12 13:52 - 2015-07-16 15:39 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-08-12 13:52 - 2015-07-16 15:38 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-08-12 13:52 - 2015-07-16 15:36 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-12 13:52 - 2015-07-16 15:35 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-08-12 13:52 - 2015-07-16 15:34 - 14451200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-12 13:52 - 2015-07-16 15:33 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-08-12 13:52 - 2015-07-16 15:32 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-12 13:52 - 2015-07-16 15:29 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-08-12 13:52 - 2015-07-16 15:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-12 13:52 - 2015-07-16 15:20 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-08-12 13:52 - 2015-07-16 15:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-08-12 13:52 - 2015-07-16 15:17 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-08-12 13:52 - 2015-07-16 15:12 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-08-12 13:52 - 2015-07-16 15:12 - 02427904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-12 13:52 - 2015-07-16 15:10 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-08-12 13:52 - 2015-07-16 15:06 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-08-12 13:52 - 2015-07-16 15:06 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-08-12 13:52 - 2015-07-16 15:05 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-08-12 13:52 - 2015-07-16 15:01 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-12 13:52 - 2015-07-16 14:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-08-12 13:52 - 2015-07-16 14:42 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-08-12 13:52 - 2015-07-16 14:38 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-08-12 13:52 - 2015-07-16 14:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-08-12 13:52 - 2015-07-14 23:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-08-12 13:51 - 2015-07-30 13:55 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-08-12 13:51 - 2015-07-30 12:56 - 03208192 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-12 13:51 - 2015-07-30 12:52 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-12 13:51 - 2015-07-30 12:49 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-08-12 13:51 - 2015-07-14 23:19 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-12 13:51 - 2015-07-14 23:19 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-12 13:51 - 2015-07-14 23:14 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-08-12 13:51 - 2015-07-14 23:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-08-12 13:51 - 2015-07-14 22:55 - 01390592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-08-12 13:51 - 2015-07-14 22:55 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-08-12 13:51 - 2015-07-14 22:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-08-12 13:51 - 2015-07-14 22:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-08-12 13:51 - 2015-07-09 13:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-12 13:51 - 2015-07-09 13:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-12 13:51 - 2015-07-09 13:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
2015-08-12 13:51 - 2015-07-01 16:49 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-12 13:51 - 2015-07-01 16:48 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-08-12 13:51 - 2015-07-01 16:30 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2015-08-12 13:51 - 2015-07-01 16:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2015-08-12 13:50 - 2015-07-16 15:12 - 04922368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-08-12 13:50 - 2015-07-16 15:12 - 00269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2015-08-12 13:50 - 2015-07-16 15:12 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-08-12 13:50 - 2015-07-16 15:11 - 05779456 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-12 13:50 - 2015-07-16 15:11 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-08-12 13:50 - 2015-07-16 15:11 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-08-12 13:50 - 2015-07-10 13:51 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-12 13:50 - 2015-07-10 13:34 - 12875776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-08-12 02:25 - 2015-08-12 02:25 - 00000042 _____ C:\Users\Matts Windows7\Desktop\get get xxxxxx.txt
2015-08-11 20:30 - 2015-08-11 20:30 - 01743626 _____ C:\Users\Matts Windows7\Desktop\WP Animator.zip
2015-08-11 14:52 - 2015-08-11 14:52 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-11 09:52 - 2015-08-11 09:52 - 11534096 _____ (Intel Corporation) C:\Windows\system32\Drivers\NETwsw01.sys
2015-08-10 14:35 - 2015-08-10 14:56 - 00000000 ____D C:\Users\Matts Windows7\Desktop\BacklinkBeast_Cracked_by_Malice
2015-08-10 13:33 - 2015-08-17 15:39 - 00000000 ____D C:\Users\Matts Windows7\Desktop\ltp
2015-08-09 22:24 - 2015-08-09 22:54 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Local Client Takeover
2015-08-09 22:19 - 2015-08-09 22:51 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\GRAPHIX
2015-08-09 22:03 - 2015-08-11 17:32 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\UpViral and Audience Connect
2015-08-09 01:18 - 2015-08-09 23:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-07 22:16 - 2015-08-09 22:29 - 00000338 _____ C:\Users\Matts Windows7\Desktop\open.txt
2015-08-07 10:13 - 2015-08-07 10:14 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Immersion Session 2
2015-08-06 14:14 - 2015-08-06 14:14 - 47438474 _____ C:\Users\Matts Windows7\Desktop\The 5 Secret Steps to Creating Powerful Viral Marketing Loops.mp4
2015-08-05 16:02 - 2015-08-05 16:02 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 02606080 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-08-05 16:02 - 2015-08-05 16:02 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-08-05 16:02 - 2015-08-05 16:02 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-08-05 16:02 - 2015-08-05 16:02 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-08-04 20:43 - 2015-08-04 20:43 - 00000000 ____D C:\Program Files (x86)\LongTailPro
2015-08-04 16:49 - 2015-08-04 16:49 - 00000000 ____D C:\Program Files (x86)\GIGProspector
2015-08-04 15:50 - 2015-08-04 15:50 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\article.buddy.ArticleBuddy
2015-08-04 14:36 - 2015-08-04 14:36 - 00000000 ____D C:\Users\Matts Windows7\GPS
2015-08-04 14:36 - 2015-08-04 14:36 - 00000000 ____D C:\Users\Matts Windows7\Articles
2015-08-04 10:22 - 2015-08-17 15:48 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\IDM
2015-08-04 10:22 - 2015-08-04 10:22 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2015-08-04 10:22 - 2015-08-04 10:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2015-08-04 10:22 - 2015-08-04 10:22 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager
2015-08-03 15:01 - 2015-08-03 15:29 - 00000000 ____D C:\Users\Matts Windows7\Documents\Arclab Website Link Analyzer
2015-08-03 15:01 - 2015-08-03 15:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Website Link Analyzer
2015-08-03 15:01 - 2015-08-03 15:01 - 00000000 ____D C:\Program Files (x86)\Arclab
2015-08-03 15:00 - 2015-08-03 15:00 - 39724535 _____ C:\Users\Matts Windows7\Downloads\AutoresponderSetup-HD.zip
2015-08-01 15:36 - 2015-08-01 15:36 - 00000000 ____D C:\Users\Public\Documents\Red Giant
2015-08-01 15:36 - 2015-08-01 15:36 - 00000000 ____D C:\Users\Public\Documents\Knoll Software
2015-08-01 15:36 - 2015-07-02 15:25 - 00310272 _____ C:\Windows\system32\KLF_OGL_x64.dll
2015-08-01 15:30 - 2015-08-01 15:30 - 00000000 ____D C:\ProgramData\goodasnew
2015-08-01 15:28 - 2015-08-01 15:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant
2015-08-01 15:28 - 2015-08-01 15:30 - 00000000 ____D C:\Program Files (x86)\Red Giant Link
2015-08-01 15:28 - 2015-08-01 15:28 - 00003688 _____ C:\Windows\System32\Tasks\Red Giant Link
2015-08-01 15:28 - 2015-08-01 15:28 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Red Giant
2015-08-01 15:28 - 2015-08-01 15:28 - 00000000 ____D C:\ProgramData\Red Giant
2015-08-01 15:27 - 2015-08-01 15:27 - 00000000 ____D C:\Program Files (x86)\Red Giant
2015-08-01 15:23 - 2015-08-01 15:36 - 00000000 ____D C:\ProgramData\RedGiant
2015-07-31 16:27 - 2015-07-31 16:27 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\TeeSpy
2015-07-31 13:29 - 2015-07-31 13:37 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Community Chest
2015-07-30 21:28 - 2015-08-14 18:01 - 00002966 _____ C:\Windows\System32\Tasks\VIPRE Upgrade Task
2015-07-30 10:47 - 2015-08-14 16:40 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Abstract Magma Logo folder
2015-07-29 13:52 - 2015-07-29 14:00 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\PDFs Must Read
2015-07-28 23:22 - 2015-07-28 23:22 - 00000870 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AD RESPARK.lnk
2015-07-28 23:22 - 2015-07-28 23:22 - 00000000 ____D C:\Program Files (x86)\AD RESPARK
2015-07-28 23:21 - 2015-07-28 23:21 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\com.gorialogics.adrespark
2015-07-28 23:13 - 2015-07-28 23:13 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Ad-Respark
2015-07-28 16:48 - 2015-07-28 16:48 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\RoboForm
2015-07-28 16:42 - 2015-07-28 16:42 - 00000000 ____D C:\ProgramData\RoboForm
2015-07-28 16:42 - 2015-07-28 16:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
2015-07-28 16:41 - 2015-07-28 16:41 - 00000000 ____D C:\Users\Matts Windows7\Documents\My RoboForm Data
2015-07-28 16:41 - 2015-07-28 16:41 - 00000000 ____D C:\Program Files (x86)\Siber Systems
2015-07-28 15:54 - 2015-07-29 09:19 - 00000120 _____ C:\Users\Matts Windows7\Desktop\get get.txt
2015-07-28 15:49 - 2015-07-28 15:49 - 00000910 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstaBannerAIR.lnk
2015-07-28 15:49 - 2015-07-28 15:49 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\InstaBannerAIR
2015-07-28 15:49 - 2015-07-28 15:49 - 00000000 ____D C:\Program Files (x86)\InstaBannerAIR
2015-07-28 12:45 - 2015-07-28 12:45 - 00000000 ____D C:\$Windows.~BT
2015-07-27 23:29 - 2015-07-27 23:29 - 00000969 _____ C:\Users\Matts Windows7\Desktop\IrfanView.lnk
2015-07-27 23:29 - 2015-07-27 23:29 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2015-07-27 23:29 - 2015-07-27 23:29 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\IrfanView
2015-07-27 23:29 - 2015-07-27 23:29 - 00000000 ____D C:\Program Files (x86)\IrfanView
2015-07-24 19:58 - 2015-08-11 20:29 - 00000000 ____D C:\zxz
2015-07-22 11:59 - 2015-08-10 12:38 - 00000108 _____ C:\Users\Matts Windows7\dkKWOOj1AFxjAn8NHqWZgdFIjvrdBhZkbQ
2015-07-22 11:58 - 2015-08-04 20:43 - 00000880 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LongTailPro.lnk
2015-07-20 16:33 - 2015-08-10 12:38 - 00000268 _____ C:\Users\Matts Windows7\AppData\Roaming\RO39-2M3Q
2015-07-20 16:33 - 2015-07-20 16:33 - 00000088 _____ C:\Users\Matts Windows7\AppData\Roaming\.95d691779473f3e03bc4b4e56319d74c.key
2015-07-20 16:33 - 2015-07-20 16:33 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\com.longtailpro.LongTailPro
2015-07-20 15:47 - 2015-07-20 15:47 - 00155648 _____ C:\Users\Matts Windows7\Desktop\850+-WSOs-for-wsopack.com_.xls
2015-07-20 12:01 - 2015-07-20 15:42 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\High Conversion Webinar Signup Template
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-18 14:49 - 2015-06-08 15:10 - 00000000 ____D C:\FRST
2015-08-18 14:39 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-18 14:39 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-18 14:37 - 2014-03-25 20:08 - 00000556 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job
2015-08-18 14:24 - 2015-06-15 21:13 - 00000954 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job
2015-08-18 14:00 - 2015-05-18 11:25 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-18 13:58 - 2014-11-09 16:28 - 00000944 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job
2015-08-18 13:56 - 2012-09-05 13:57 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-18 13:39 - 2015-06-04 14:38 - 00000652 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job
2015-08-18 12:51 - 2015-07-15 12:03 - 00000000 ___RD C:\Users\Matts Windows7\Downloads\Compressed
2015-08-18 12:31 - 2011-05-24 15:02 - 01434343 _____ C:\Windows\WindowsUpdate.log
2015-08-18 11:32 - 2012-03-14 17:51 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\TOOLs
2015-08-18 09:49 - 2015-07-14 17:10 - 00000000 ___RD C:\Users\Matts Windows7\Downloads\Video
2015-08-18 08:05 - 2014-08-28 17:56 - 00000000 ___RD C:\Users\Matts Windows7\OneDrive
2015-08-18 08:05 - 2012-09-05 13:58 - 00000000 ___RD C:\Users\Matts Windows7\Google Drive
2015-08-18 08:05 - 2012-09-05 13:57 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-18 08:05 - 2012-02-22 13:17 - 00000000 ___RD C:\Users\Matts Windows7\Dropbox
2015-08-18 08:05 - 2012-02-22 13:15 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Dropbox
2015-08-18 08:05 - 2011-07-28 08:46 - 00442592 _____ C:\Users\Matts Windows7\AppData\Local\GDIPFONTCACHEV1.DAT
2015-08-18 08:04 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-18 08:04 - 2009-07-14 00:45 - 13680664 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-17 18:35 - 2015-07-14 17:00 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\DMCache
2015-08-17 18:16 - 2012-01-12 15:10 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\vlc
2015-08-17 18:13 - 2015-06-26 16:48 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Body by Matt Site
2015-08-17 13:37 - 2015-07-08 12:16 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2015-08-17 13:33 - 2014-01-16 15:05 - 00002471 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 9 Pro Extended.lnk
2015-08-17 13:33 - 2014-01-16 15:05 - 00002465 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Distiller 9.lnk
2015-08-17 13:33 - 2014-01-16 15:05 - 00002235 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe 3D Reviewer.lnk
2015-08-17 13:33 - 2014-01-16 15:05 - 00002138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle Designer ES 8.2.lnk
2015-08-17 02:24 - 2015-06-15 21:13 - 00000902 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job
2015-08-17 02:23 - 2009-07-14 01:13 - 00786622 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-17 01:36 - 2015-05-26 18:20 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-17 00:09 - 2014-11-09 16:28 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job
2015-08-16 00:11 - 2011-07-28 11:49 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\Apps\2.0
2015-08-15 23:56 - 2009-07-13 23:20 - 00000000 __RHD C:\Users\Default
2015-08-15 23:31 - 2009-07-13 22:34 - 00000215 _____ C:\Windows\system.ini
2015-08-15 23:20 - 2011-07-28 08:45 - 00000000 ____D C:\Users\Matts Windows7
2015-08-15 22:44 - 2015-03-01 03:13 - 00002932 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Matts_Windows7
2015-08-15 22:44 - 2015-03-01 01:59 - 00000000 ____D C:\ProgramData\ProductData
2015-08-15 21:41 - 2012-11-27 14:03 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Media Player Classic
2015-08-15 12:05 - 2009-07-14 01:08 - 00032544 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-15 08:54 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\Resources
2015-08-14 18:58 - 2012-09-05 13:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-08-14 15:04 - 2015-07-07 14:42 - 00000427 _____ C:\Users\Matts Windows7\Desktop\Penguin & WI-FI.txt
2015-08-13 21:45 - 2015-06-04 14:38 - 00003710 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000
2015-08-13 21:45 - 2014-03-25 20:08 - 00003614 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000
2015-08-13 18:39 - 2015-03-25 00:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2
2015-08-13 18:39 - 2015-03-01 02:32 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\ProductData
2015-08-13 18:39 - 2015-03-01 01:59 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\IObit
2015-08-13 18:39 - 2015-03-01 01:59 - 00000000 ____D C:\ProgramData\IObit
2015-08-13 18:39 - 2015-03-01 01:59 - 00000000 ____D C:\Program Files (x86)\IObit
2015-08-13 18:39 - 2014-06-17 19:09 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\uTorrent
2015-08-13 18:39 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\registration
2015-08-13 18:19 - 2015-06-02 17:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-08-13 17:54 - 2015-05-26 18:19 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-13 15:55 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2015-08-13 13:32 - 2015-03-25 00:05 - 00002902 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (Matts Windows7)
2015-08-13 13:28 - 2014-12-11 10:53 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-13 13:28 - 2014-05-07 09:41 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-12 17:34 - 2013-03-13 20:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-12 17:33 - 2013-03-13 20:05 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-12 17:33 - 2013-03-13 20:05 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-12 17:31 - 2014-06-16 19:59 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-12 17:27 - 2009-07-13 22:34 - 00000478 _____ C:\Windows\win.ini
2015-08-12 17:18 - 2013-08-15 10:46 - 00000000 ____D C:\Windows\system32\MRT
2015-08-12 17:18 - 2011-12-28 21:04 - 132483416 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-11 20:00 - 2015-05-18 11:25 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-08-11 20:00 - 2014-03-12 21:38 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-08-11 20:00 - 2014-03-12 21:38 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-10 11:51 - 2012-04-28 23:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-09 23:20 - 2015-02-06 17:16 - 00000000 ___RD C:\ICONS
2015-08-05 15:56 - 2015-06-23 00:38 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Dons RESULTS 6-23-15
2015-08-05 11:30 - 2012-01-17 15:00 - 00000000 ____D C:\Users\Matts Windows7\Documents\My Maps
2015-08-05 00:28 - 2014-10-29 13:29 - 00001456 _____ C:\Users\Matts Windows7\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-08-04 20:43 - 2013-04-08 12:39 - 00660720 ____H C:\Windows\SysWOW64\mlfcache.dat
2015-08-04 17:07 - 2015-01-29 15:45 - 00000222 _____ C:\Users\Matts Windows7\video2gifsett
2015-08-04 17:03 - 2015-01-29 15:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video2Gif
2015-08-04 17:03 - 2015-01-29 15:41 - 00000000 ____D C:\Program Files (x86)\ Video2Gif
2015-08-04 16:49 - 2013-05-08 12:05 - 00000900 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGProspector.lnk
2015-08-04 16:49 - 2013-05-08 12:05 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\GIGProspector
2015-08-04 16:30 - 2012-09-21 17:36 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Tin Nguyen
2015-08-04 15:35 - 2012-02-29 12:46 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\CrashDumps
2015-08-04 14:42 - 2014-07-25 16:21 - 00000000 ____D C:\Users\Matts Windows7\Documents\Outlook Files
2015-08-03 17:40 - 2011-10-05 23:16 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Skype
2015-08-03 14:51 - 2015-01-07 17:15 - 00000132 _____ C:\Users\Matts Windows7\AppData\Roaming\Adobe PNG Format CC Prefs
2015-07-28 14:46 - 2015-06-30 01:03 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\LABS
2015-07-28 12:45 - 2007-07-11 21:49 - 00000000 ____D C:\Windows\Panther
2015-07-28 00:36 - 2013-03-01 18:33 - 00000000 ____D C:\Users\Matts Windows7\Documents\Movie Studio Platinum 12.0 Projects
2015-07-28 00:34 - 2009-07-14 00:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-07-27 23:58 - 2013-03-17 09:42 - 00005632 _____ C:\Users\Matts Windows7\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-27 14:03 - 2015-07-08 12:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
2015-07-27 14:03 - 2015-07-08 12:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Exploit
2015-07-27 14:03 - 2014-02-20 11:18 - 00002200 _____ C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-07-26 23:55 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\NDF
2015-07-26 13:46 - 2015-03-30 22:50 - 00000000 ___SD C:\Windows\system32\GWX
2015-07-23 21:57 - 2015-07-17 16:21 - 00000075 _____ C:\Users\Matts Windows7\Desktop\GET.txt
2015-07-21 10:29 - 2013-11-07 11:05 - 00000000 ____D C:\ProgramData\Oracle
2015-07-21 10:26 - 2012-03-13 02:10 - 00000000 ____D C:\Program Files (x86)\Java
2015-07-21 10:21 - 2014-10-29 13:06 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-07-20 15:41 - 2015-02-21 00:35 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Recurring Revenue Machine
 
==================== Files in the root of some directories =======
 
2012-03-06 18:34 - 2012-03-06 18:34 - 0001005 _____ () C:\Program Files (x86)\Backlink Skyrocket.lnk
2012-03-06 18:37 - 2012-03-06 18:37 - 0000993 _____ () C:\Program Files (x86)\Traffic SkyRocket.lnk
2012-03-06 18:34 - 2012-03-06 18:34 - 0000960 _____ () C:\Program Files (x86)\Update Skyrocket.lnk
2014-08-09 01:42 - 2014-08-09 02:16 - 15000576 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2015-07-20 16:33 - 2015-07-20 16:33 - 0000088 _____ () C:\Users\Matts Windows7\AppData\Roaming\.95d691779473f3e03bc4b4e56319d74c.key
2015-03-12 18:12 - 2015-03-12 18:12 - 0000132 _____ () C:\Users\Matts Windows7\AppData\Roaming\Adobe GIF Format CC Prefs
2015-01-07 17:15 - 2015-08-03 14:51 - 0000132 _____ () C:\Users\Matts Windows7\AppData\Roaming\Adobe PNG Format CC Prefs
2012-08-01 15:02 - 2012-08-01 15:02 - 0000098 _____ () C:\Users\Matts Windows7\AppData\Roaming\netstat.bat
2015-07-20 16:33 - 2015-08-10 12:38 - 0000268 _____ () C:\Users\Matts Windows7\AppData\Roaming\RO39-2M3Q
2015-02-17 12:10 - 2015-02-17 12:19 - 0558080 _____ () C:\Users\Matts Windows7\AppData\Roaming\SharedSettings.ccs
2014-10-29 13:29 - 2015-08-05 00:28 - 0001456 _____ () C:\Users\Matts Windows7\AppData\Local\Adobe Save for Web 13.0 Prefs
2013-03-17 09:42 - 2015-07-27 23:58 - 0005632 _____ () C:\Users\Matts Windows7\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-25 15:25 - 2014-07-25 15:25 - 0004096 ____H () C:\Users\Matts Windows7\AppData\Local\keyfile3.drm
2014-09-17 17:26 - 2014-09-17 21:39 - 0000600 _____ () C:\Users\Matts Windows7\AppData\Local\PUTTY.RND
2013-05-29 13:03 - 2014-05-30 08:54 - 17977856 _____ () C:\Users\Matts Windows7\AppData\Local\ReputationCrusher.msi
2014-02-05 02:23 - 2014-11-05 10:53 - 0007597 _____ () C:\Users\Matts Windows7\AppData\Local\Resmon.ResmonCfg
2014-07-22 20:25 - 2014-07-22 20:25 - 0000003 _____ () C:\Users\Matts Windows7\AppData\Local\updater.log
2014-07-22 20:25 - 2014-11-22 18:18 - 0000455 _____ () C:\Users\Matts Windows7\AppData\Local\UserProducts.xml
2015-01-10 01:22 - 2015-01-10 01:22 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-05-15 10:57 - 2012-05-15 10:57 - 0000252 _____ () C:\ProgramData\FastPics.log
2013-07-15 17:43 - 2013-07-15 17:43 - 0000032 _____ () C:\ProgramData\Temp.log
2012-05-15 10:52 - 2012-05-15 10:52 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt
 
ZeroAccess:
C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}
C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}\@
 
Some files in TEMP:
====================
C:\Users\Matts Windows7\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgmx8xt.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-08-13 15:48
 
==================== End of log ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:17-08-2015
Ran by [removed] (2015-08-18 14:49:55)
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3123964009-4157677460-2703354282-500 - Administrator - Disabled)
Guest (S-1-5-21-3123964009-4157677460-2703354282-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3123964009-4157677460-2703354282-1004 - Limited - Enabled)
Matts Windows7 (S-1-5-21-3123964009-4157677460-2703354282-1000 - Administrator - Enabled) => C:\Users\Matts Windows7
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: ThreatTrack Security VIPRE (Enabled - Up to date) {FFE93D16-FD09-0282-C7D3-8B1731B6A051}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ThreatTrack Security VIPRE (Enabled - Up to date) {4488DCF2-DB33-0D0C-FD63-B0654A31EAEC}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\uTorrent) (Version: 3.4.2.31743 - BitTorrent Inc.)
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
AD RESPARK (HKLM-x32\…\com.gorialogics.adrespark) (Version: 1.2 - Your Marketing Tech Support, LLC)
AD RESPARK (x32 Version: 1.2 - Your Marketing Tech Support, LLC) Hidden
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch (HKLM-x32\…\{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}) (Version: 9.0.0 - Adobe Systems)
Adobe Acrobat 9 Pro Extended 64-bit Add-On (HKLM\…\{AC76BA86-1033-0000-0064-0003D0000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Adobe After Effects CS6 (HKLM-x32\…\{4817D846-700B-474E-A31B-80892B3E92E3}) (Version: 11 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated)
Adobe Anchor Service x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe CMaps x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe CSI CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe Drive CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 18 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Fonts All x64 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Illustrator CS5 (HKLM-x32\…\{9B97EC91-B3FD-4BFF-88FC-5345A26AC2E7}) (Version: 15.0 - Adobe Systems Incorporated)
Adobe Linguistics CS4 x64 (Version: 4.0.0 - Adobe Systems Incorporated) Hidden
Adobe Media Player (HKLM-x32\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
Adobe PDF Library Files x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CC (HKLM-x32\…\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated)
Adobe Photoshop CS4 (64 Bit) (Version: 11.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS4 (HKLM-x32\…\Adobe_faf656ef605427ee2f42989c3ad31b8) (Version: 11.0 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Adobe Type Support x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe WinSoft Linguistics Plugin x64 (Version: 1.1 - Adobe Systems Incorporated) Hidden
Advanced SystemCare 8 (HKLM-x32\…\Advanced SystemCare 8_is1) (Version: 8.2.0 - IObit)
AliG Social Lead Freak (HKLM-x32\…\com.aligmarketing.slf) (Version: 2.4.0 - Ali M. Gadit)
AliG Social Lead Freak (x32 Version: 2.4.0 - Ali M. Gadit) Hidden
Any Video Converter 5 5.0.3 (HKLM-x32\…\Any Video Converter 5_is1) (Version:  - Any-Video-Converter.com)
Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Arclab Website Link Analyzer 1.21 (HKLM-x32\…\Arclab Website Link Analyzer_is1) (Version: 1.21 - Arclab Software GbR)
Audacity 1.2.6 (HKLM-x32\…\Audacity_is1) (Version:  - )
AVCHD To MP4 Converter 1.0 (HKLM-x32\…\AVCHD To MP4 Converter) (Version: 1.0 - Mark Dulisse)
Backlink SkyRocket (HKLM-x32\…\{DA043E6D-2724-4894-8DD7-AC9020193663}) (Version: 1.4.8 - Backlink SkyRocket)
Backup Manager V3 (x32 Version: 3.0.0.100 - NTI Corporation) Hidden
BleuPage (HKLM-x32\…\{FE65FBDB-48D5-4145-8E24-3775F872F3E7}) (Version: 1.3.307 - BleuPage Software)
BlueStacks App Player (HKLM-x32\…\BlueStacks App Player) (Version: 0.8.7.3069 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\…\{FE5ABB0E-EDEA-4023-B0FB-9DEA39A98D76}) (Version: 0.8.7.3069 - BlueStack Systems, Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom Card Reader Driver Installer (HKLM\…\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 14.6.1.2 - Broadcom Corporation)
Broadcom Gigabit NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.6.1.2 - Broadcom Corporation)
Camtasia Studio 7 (HKLM-x32\…\{C0E8FE43-C35B-451D-B35F-D4BD056D70E7}) (Version: 7.1.1 - TechSmith Corporation)
CarMD (HKLM-x32\…\{7E213637-F640-4599-A8B3-5269BA7D66D3}) (Version: 4.0.120 - carmd.com)
Cisco WebEx Meetings (HKLM-x32\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Citrix Online Launcher (HKLM-x32\…\{DB014C85-A264-4BCA-A66F-6DD1FCF8EC36}) (Version: 1.0.335 - Citrix)
Citrix Receiver (HKLM-x32\…\CitrixOnlinePluginPackWeb) (Version: 13.1.201.3 - Citrix Systems, Inc.)
Commission Heist (HKLM-x32\…\commheist) (Version: 1.0.2 - Memberspeed Inc)
Commission Heist (x32 Version: 1.0.2 - Memberspeed Inc) Hidden
Conference Recording Service (HKLM-x32\…\{B293F0E6-10B7-45FD-BACF-18826515C246}_is1) (Version:  - GVO, Inc.)
Connect (x32 Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
CT4L (HKLM-x32\…\CT4L) (Version: 1.4.1 - UNKNOWN)
CT4L (x32 Version: 1.4.1 - UNKNOWN) Hidden
CyberLink MediaEspresso (HKLM-x32\…\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.0.1027_32100 - CyberLink Corp.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.2531.52 - CyberLink Corp.)
CyberSpy Intel Station  (HKLM-x32\…\{005DE34D-CE86-4C74-9B31-8C6D2E10ABBD}) (Version: 1.0.0 - Dean Sueck - CyberSpyIntelStation.com)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deals Flow (HKLM-x32\…\DealsFlow) (Version: 1.0.0 - UNKNOWN)
Deals Flow (x32 Version: 1.0.0 - UNKNOWN) Hidden
Digi Traffic Accelerator (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\27e1819d71203503) (Version: 1.1.9.119 - DigiResults)
Domain Security PRO 1.0 (HKLM-x32\…\Domain Security PRO) (Version: 1.0 - Mark Dulisse)
Driver Booster 2.3 (HKLM-x32\…\Driver Booster_is1) (Version: 2.3 - IObit)
Dropbox (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Dropbox) (Version: 3.8.6 - Dropbox, Inc.)
DVD Architect Studio 5.0 (HKLM-x32\…\{42C509F1-C451-11E1-AEC9-F04DA23A5C58}) (Version: 5.0.161 - Sony)
EasySketchPro version 2.0.0 (HKLM-x32\…\{90BB7D95-EBCA-4276-B15E-156F85E8B1DA}_is1) (Version: 2.0.0 - Inner Cirle Riches)
EasyVSL (HKLM-x32\…\com.searchcreatively.EasyVSL) (Version: 1.0.5 - Digital Kickstart)
EasyVSL (x32 Version: 1.0.5 - Digital Kickstart) Hidden
Effects Suite v11.1.6 (HKLM-x32\…\{4DD8EE5E-F571-4EC8-9526-E7C62FE39B19}_is1) (Version: 11.1.6 - Red Giant, LLC)
FB Ad Express (HKLM-x32\…\com.pageone.FBads) (Version: 1.2 - Jai Ganesh Venkateswaran)
FB Ad Express (x32 Version: 1.2 - Jai Ganesh Venkateswaran) Hidden
FileZilla Client 3.5.3 (HKLM-x32\…\FileZilla Client) (Version: 3.5.3 - FileZilla Project)
FreshKey (HKLM-x32\…\com.digitalmarketer.FreshKey) (Version: 1.5.4 - Idea Incubator LP)
FreshKey (x32 Version: 1.5.4 - Idea Incubator LP) Hidden
FunnelCreator (HKLM-x32\…\FunnelCreator) (Version: 1.0 - UNKNOWN)
FunnelCreator (x32 Version: 1.0 - UNKNOWN) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gateway MyBackup (HKLM-x32\…\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.100 - NTI Corporation)
Gateway Power Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Gateway Incorporated)
Gateway Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Gateway Incorporated)
Gateway Registration (HKLM-x32\…\Gateway Registration) (Version: 1.03.3004 - Gateway Incorporated)
Gateway ScreenSaver (HKLM-x32\…\Gateway Screensaver) (Version: 1.1.1022.2010 - Gateway Incorporated)
Gateway Social Networks (HKLM-x32\…\InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}) (Version: 2.0.3315 - CyberLink Corp.)
Gateway Social Networks (x32 Version: 2.0.3315 - CyberLink Corp.) Hidden
GIG Prospector (HKLM-x32\…\GIGProspector) (Version: 2.0.8 - UNKNOWN)
GIG Prospector (x32 Version: 2.0.8 - UNKNOWN) Hidden
Google AdWords Editor (HKLM-x32\…\{14069A87-872C-41E6-9D36-B1BE3870C35A}) (Version: 10.6.0 - Google)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 44.0.2403.155 - Google Inc.)
Google Drive (HKLM-x32\…\{12ADFB82-D5A3-43E4-B2F4-FCD9B690315B}) (Version: 1.24.9931.5480 - Google, Inc.)
Google Talk Plugin (HKLM-x32\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
GoToMeeting 7.2.4.3215 (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\GoToMeeting) (Version: 7.2.4.3215 - CitrixOnline)
HandBrake 0.9.9.1 (HKLM-x32\…\HandBrake) (Version: 0.9.9.1 - )
HD Video Converter Factory Pro 9.2 (HKLM-x32\…\HD Video Converter Factory Pro) (Version: 9.2 - WonderFox Soft, Inc.)
HomeMedia (HKLM-x32\…\{AA4BF92B-2AAF-11DA-9D78-000129760D75}) (Version: 2.0.8520 - CyberLink Corporation)
HP ENVY 4500 series Basic Device Software (HKLM\…\{6915424E-704F-4F5D-9057-9C7B406B36DB}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
iCloud (HKLM\…\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3006 - Gateway Incorporated)
iExplorer [removed] (HKLM-x32\…\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant LLC)
InstaBannerAIR (HKLM-x32\…\InstaBannerAIR) (Version: 1.1 - JHS Marketing LLC)
InstaBannerAIR (x32 Version: 1.1 - JHS Marketing LLC) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\…\{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}) (Version: 14.00.1000 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel(R) Wireless Display (HKLM-x32\…\{626663EE-B9E6-4982-995F-02C31E84F8FC}) (Version: 2.0.29.0 - Intel Corporation)
Internet Download Manager (HKLM-x32\…\Internet Download Manager) (Version:  - Tonec Inc.)
IObit Malware Fighter 3 (HKLM-x32\…\IObit Malware Fighter_is1) (Version: 3.1 - IObit)
IObit Uninstaller (HKLM-x32\…\IObitUninstall) (Version: 4.2.6.2 - IObit)
IrfanView (remove only) (HKLM-x32\…\IrfanView) (Version: 4.38 - Irfan Skiljan)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\…\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 51 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\…\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Jing (HKLM-x32\…\{22800204-9E53-45C7-B6F3-5BB0F1C1A147}) (Version: 2.8.13007.1 - TechSmith Corporation)
Juicer 3.90 (HKLM-x32\…\{640EAE56-81A2-49D4-9B8C-00DA3C0031AF}_is1) (Version:  - Digital Juice, Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Keyword Scout (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\6611abf67fa612f7) (Version: 1.0.1.55 - Josh MacDonald)
K-Lite Codec Pack 9.5.0 (Full) (HKLM-x32\…\KLiteCodecPack_is1) (Version: 9.5.0 - )
KompoZer 0.8b3 (HKLM-x32\…\{20aa4150-b5f4-11de-8a39-0800200c9a66}_is1) (Version:  - KompoZer)
kuler (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
LastPass (uninstall only) (HKLM-x32\…\LastPass) (Version:  - LastPass)
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.4 - Gateway)
Lexmark 5600-6600 Series (HKLM\…\Lexmark 5600-6600 Series) (Version:  - Lexmark International, Inc.)
Lexmark Printable Web (HKLM-x32\…\{D2C5E510-BE6D-42CC-9F61-E4F939078474}) (Version: 1.0.0.0 - )
Livedrive (HKLM\…\{7D2E0E90-3BBA-43B1-894D-EC39A4E18748}) (Version: 1.15.2.0 - Livedrive Internet Limited)
Local Lead Igniter (HKLM-x32\…\Service.Magic.Scrapper) (Version: 0.0.0 - UNKNOWN)
Local Lead Igniter (x32 Version: 0.0.0 - UNKNOWN) Hidden
Local Niche Spy (HKLM-x32\…\Niche) (Version: 2.1.4 - UNKNOWN)
Local Niche Spy (x32 Version: 2.1.4 - UNKNOWN) Hidden
Local Traffic Tool (HKLM-x32\…\{BAF1E625-29F3-4144-8686-4C89543C73D7}) (Version: 1.1.6 - Offline Inner Circle)
Localizer Leads Tool (HKLM-x32\…\LocalizerLeadsTool) (Version: 3.5.4 - Viper Consulting, LLC)
Localizer Leads Tool (x32 Version: 3.5.4 - Viper Consulting, LLC) Hidden
LongTailPro - Version 3.0.13 (HKLM-x32\…\com.longtailpro.LongTailPro) (Version: 3.0.13 - Long Tail Media, LLC)
LongTailPro - Version 3.0.13 (x32 Version: 3.0.13 - Long Tail Media, LLC) Hidden
Malwarebytes Anti-Exploit version 1.07.1.1015 (HKLM\…\Malwarebytes Anti-Exploit_is1) (Version: 1.07.1.1015 - Malwarebytes)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
MetaFrame Presentation Server Web Client for Win32 (HKLM\…\Citrix ICA Web Client) (Version:  - )
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\OneDriveSetup.exe) (Version: 17.3.5907.0716 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\…\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\…\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mindjet MindManager 2012 (HKLM-x32\…\{4E973CA9-5674-4FB4-8D83-3D8C5EB44AB3}) (Version: 10.0.445 - Mindjet)
Movie Studio Platinum 12.0 (64-bit) (HKLM\…\{FE052581-1CD8-11E2-B617-F04DA23A5C58}) (Version: 12.0.576 - Sony)
Mozilla Firefox 39.0.3 (x86 en-GB) (HKLM-x32\…\Mozilla Firefox 39.0.3 (x86 en-GB)) (Version: 39.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mp3tag v2.65a (HKLM-x32\…\Mp3tag) (Version: v2.65a - Florian Heidenreich)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MySpeed v5.4.5 (HKLM-x32\…\{C3F2AE48-FEEB-4697-BFCE-FB9B17289A7F}) (Version: 5.04.0413 - Enounce Incorporated)
Nero DiscSpeed 10 (HKLM-x32\…\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG)
Nero Express 10 (HKLM-x32\…\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12000.21.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.5.10300 - Nero AG)
Nero StartSmart 10 (HKLM-x32\…\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
Nero Update (HKLM-x32\…\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
NOOK for PC (HKLM-x32\…\BN_DesktopReader) (Version: 2.5.1.237 - Barnesandnoble.com)
Notepad++ (HKLM-x32\…\Notepad++) (Version: 6.4.2 - Notepad++ Team)
Online Plug-in (x32 Version: 13.1.201.3 - Citrix Systems, Inc.) Hidden
PandoraRecovery (Remove Only) (HKLM-x32\…\PandoraRecovery) (Version:  - )
PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden
PDF Settings CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
PDF-XChange 3 (HKLM\…\PDF-XChange 3_is1) (Version:  - Tracker Software)
Perfectly Clear Plugin 1.6.0 (HKLM-x32\…\Perfectly Clear Plugin) (Version: 1.6.0 - Athentech)
Photoshop Camera Raw (x32 Version: 5.0 - Adobe Systems Incorporated) Hidden
Photoshop Camera Raw_x64 (Version: 5.0 - Adobe Systems Incorporated) Hidden
Places Scout (HKLM-x32\…\{AA880B13-717B-46C6-B9F4-E38974D56881}) (Version: 2.2.0 - Automated Keyword Research, LLC)
PPTX Viewer 2.0 (HKLM-x32\…\PPTX Viewer 2.0) (Version:  - )
Proxy Goblin (HKLM-x32\…\{B77A5236-16DB-4DE5-B0CE-2E3F0B52C321}) (Version: 2.1.3 - Molura)
Publishers Review Accelerator (HKLM-x32\…\{95008B02-4CBD-4352-8180-56C414CBBCD1}) (Version: 1.1.65 - Scoritz)
Qilio (HKLM-x32\…\com.jayvenka.qilio) (Version: 1.0.7 - Jai Ganesh Venkateswaran)
Qilio (x32 Version: 1.0.7 - Jai Ganesh Venkateswaran) Hidden
QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RAPID Mode (Version: 1.0.1.81 - Samsung Electronics Co., Ltd.) Hidden
Real Hide IP (HKLM-x32\…\RealHideIP) (Version: 4.2.5.2 - )
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6329 - Realtek Semiconductor Corp.)
Red Giant Link (HKLM-x32\…\{10F82E5B-B611-4C65-8F29-666A9EC5680A}_is1) (Version: 1.9.6.0 - Red Giant, LLC)
Reflector (HKLM\…\{77342B24-A2A9-4420-8C9C-C109EE201CBC}) (Version: 1.3.3.1 - Squirrels)
Reputation Crusher (HKLM-x32\…\{FA0EFEF1-212F-45CC-9651-AACB66F75F8B}) (Version: 1.0.55 - MJISolutions)
Revo Uninstaller Pro 2.1.1 (HKLM\…\{FB562550-BBE6-4298-861A-5C0A6562C272}_is1) (Version:  - ;-))
RoboForm 7-9-14-4 (All Users) (HKLM-x32\…\AI RoboForm) (Version: 7-9-14-4 - Siber Systems)
S3 Ripper 2.0 (HKLM-x32\…\{AB3D78B7-8066-465A-82A8-5F3751564457}_is1) (Version:  - )
Samsung Data Migration (HKLM-x32\…\{D4DE3DB4-7734-47E5-8D92-B80146311406}) (Version: 2.7 - Samsung)
Samsung Magician (HKLM-x32\…\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.5.1 - Samsung Electronics)
Samsung Universal Print Driver 2 (HKLM-x32\…\Samsung Universal Print Driver 2) (Version: 2.50.02.00 - Samsung Electronics Co., Ltd.)
Scale Factor Social Leads Tool (HKLM-x32\…\FacebookLeads) (Version: 0.0.0 - UNKNOWN)
Scale Factor Social Leads Tool (x32 Version: 0.0.0 - UNKNOWN) Hidden
Self-service Plug-in (x32 Version: 3.2.0.24226 - Citrix Systems, Inc.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Click to Call (HKLM-x32\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.9.12585 - Skype Technologies S.A.)
Skype™ 7.5 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.102 - Skype Technologies S.A.)
Smart Defrag 4 (HKLM-x32\…\Smart Defrag 4_is1) (Version: 4.0 - IObit)
Snagit 12 (HKLM-x32\…\{588591F5-74D7-4646-87C5-6A07E526F303}) (Version: 12.3.2 - TechSmith Corporation)
Sound Forge Audio Studio 10.0 (HKLM-x32\…\{7A263871-BEEC-11E1-AC53-F04DA23A5C58}) (Version: 10.0.178 - Sony)
Sparkol VideoScribe (HKLM-x32\…\Sparkol VideoScribe 1.3.18) (Version: 1.3.18 - Sparkol)
Sparkol VideoScribe (x32 Version: 1.3.18 - Sparkol) Hidden
Splashtop Software Updater (HKLM-x32\…\Splashtop Software Updater) (Version: 1.5.6.15 - Splashtop Inc.)
Splashtop Streamer (HKLM-x32\…\{B7C5EA94-B96A-41F5-BE95-25D78B486678}) (Version: 2.6.2.4 - Splashtop Inc.)
SplitCam (HKLM-x32\…\SplitCam) (Version: 6.9.4.1 - SplitCam Co)
Suite Shared Configuration CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
Surfing Protection (HKLM-x32\…\IObit Surfing Protection_is1) (Version: 1.2 - IObit)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.1.6.0 - Synaptics Incorporated)
System Requirements Lab for Intel (HKLM-x32\…\{1EBDF6D2-CEA0-484C-A23E-2DDAD7FD0DD0}) (Version: 4.5.22.0 - Husdawg, LLC)
Target Generator (HKLM-x32\…\Target Generator1.0.0.3) (Version: 1.0.0.3 - AppBreed Software of InnAnTech Industries Inc.)
TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
Tee Inspector (HKLM-x32\…\Tee Inspector1.0.0.6) (Version: 1.0.0.6 - AppBreed Software of InnAnTech Industries Inc.)
The Logo Creator v6.6 (HKLM-x32\…\The Logo Creator) (Version: v6.6 - Laughingbird Software)
Times Reader (HKLM-x32\…\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1) (Version: 2.055 - The New York Times Company)
Times Reader (x32 Version: 2.055 - The New York Times Company) Hidden
Traffic SkyRocket (HKLM-x32\…\{1F0D32B8-B187-4295-A02C-CF5468F8E16F}) (Version: 1.0.0 - Traffic SkyRocket)
Traffic Travis 4.2.0 (HKLM-x32\…\Traffic Travis 4.2 Setup Wizard_is1) (Version:  - Affilorama Ltd.)
Trapcode Suite v12.1.9 (HKLM-x32\…\{DFD2DC6B-C634-4C1C-81CC-5EF852E71CEE}_is1) (Version: 12.1.9 - Red Giant, LLC)
Tube Maker PRO 1.0 (HKLM-x32\…\Tube Maker PRO) (Version: 1.0 - Mark Dulisse)
UberQast (HKLM-x32\…\com.web1-syndication-inc.uberqast) (Version: 3.0.0.8 - Web1 Syndication, Inc.)
UberQast (x32 Version: 3.0.0 - Web1 Syndication, Inc.) Hidden
URLShotgunPro (HKLM-x32\…\URLShotgunPro) (Version: 1.0.1 - UNKNOWN)
URLShotgunPro (x32 Version: 1.0.1 - UNKNOWN) Hidden
Viber (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Viber) (Version: 4.4.0.134678 - Viber Media Inc)
Video Marketer (HKLM-x32\…\com.immortal-marketing.video-marketer) (Version: 3.0.0.4 - UNKNOWN)
Video Marketer (x32 Version: 3.0.0 - UNKNOWN) Hidden
Video Web Camera (HKLM-x32\…\InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}) (Version: 1.5.3018.00 - CyberLink Corp.)
Video Web Camera (x32 Version: 1.5.3018.00 - CyberLink Corp.) Hidden
Video2Gif version 1.0 (HKLM-x32\…\{FA80C47D-C9F1-482E-8D3C-69490CADCA3A}_is1) (Version: 1.0 - Mark Dulisse)
VideoMakerFX (HKLM-x32\…\VideoMakerFX 1.01) (Version: 1.01 - Webvati)
VideoMakerFX (x32 Version: 1.01 - Webvati) Hidden
VideoMakerFX Josh Ratta Bonus Scenes (HKLM-x32\…\{E7CAFBCF-1A20-4AF8-AE0E-89A8282CCA46}) (Version: 1.0 - Webvati)
VideoMakerFX ProThemes May Addon 1.0 (HKLM-x32\…\{6073BA7B-671F-4F41-AA93-05164AAE6A72}) (Version: 1.0 - Webvati)
VideoMakerFX VideoProfitFX Add On 1.0 (HKLM-x32\…\{8F99303E-4E46-45DC-964D-649DBC72B717}) (Version: 1.0 - Webvati)
VidNeos (HKLM-x32\…\VidNeos) (Version: 1.1.0 - UNKNOWN)
VidNeos (x32 Version: 1.1.0 - UNKNOWN) Hidden
Viewlio (HKLM-x32\…\groinup.outsourcing.youtubetool) (Version: 1.2.4 - Web1 Syndication, Inc.)
Viewlio (x32 Version: 1.2.4 - Web1 Syndication, Inc.) Hidden
VIPRE Antivirus (HKLM-x32\…\{C1D1FC57-3EB9-4B21-BCA3-F1C927508200}) (Version: 7.0.6.2 - ThreatTrack Security, Inc.)
VIPRE Antivirus (x32 Version: 7.0.6.2 - ThreatTrack Security, Inc.) Hidden
Viral Image Curator Pro (HKLM-x32\…\com.webdimensions.viralimagecuratorpro) (Version: 1.3.6 - Web Dimensions, Inc.)
Viral Image Curator Pro (x32 Version: 1.3.6 - Web Dimensions, Inc.) Hidden
VLC media player 2.1.3 (HKLM-x32\…\VLC media player) (Version: 2.1.3 - VideoLAN)
Website Submitter 5.0.0.0 (HKLM-x32\…\{1CED286D-B45F-46BB-8EF4-73924C0FC970}_is1) (Version: 5.0.0.0 - Fastlink2)
Welcome Center (HKLM-x32\…\Gateway Welcome Center) (Version: 1.02.3102 - Gateway Incorporated)
Whistle (HKLM-x32\…\{28992A1F-DFD4-4CA2-9F8D-8D8294FF6D2A}) (Version: 1.30.0 - Vail Systems)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\…\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinHTTrack Website Copier 3.47-27 (x64) (HKLM\…\WinHTTrack Website Copier_is1) (Version: 3.47.27 - HTTrack)
WinZip 19.0 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E5}) (Version: 19.0.11293 - WinZip Computing, S.L. )
x264vfw - H.264/MPEG-4 AVC codec for x64 (remove only) (HKLM-x32\…\x264vfw64) (Version:  - )
XAMPP (HKLM-x32\…\xampp) (Version: 1.8.3-3 - Bitnami)
XMedia Recode version 3.1.7.7 (HKLM-x32\…\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.7.7 - XMedia Recode)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Program Files (x86)\Citrix\GoToMeeting\3019\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
 
==================== Restore Points =========================
 
16-08-2015 18:40:38 Windows Update
18-08-2015 14:28:49 tring to fix virus issues
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2015-08-15 23:30 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {161F3F57-9F98-43C2-B884-2A81E14F61AC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-05] (Google Inc.)
Task: {1C5D247F-A932-4C21-8AC9-B5C165567C8D} - System32\Tasks\ASC8_SkipUac_Matts Windows7 => C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe [2015-05-08] (IObit)
Task: {1F29DAE0-568A-437D-9554-8275E9E9FEA3} - System32\Tasks\UALU notificatin => C:\Program Files\Gateway\Gateway Updater\UALU.exe [2012-04-05] (Acer Incorporated)
Task: {3A35A426-4454-41DA-86B5-29AF66C0CD00} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2015-05-14] (IObit)
Task: {46BA7249-9A2D-4755-B3BF-D8FFECA438D3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-05] (Google Inc.)
Task: {50D58B99-3B73-4BBF-ADA2-FB33DB17CAAA} - System32\Tasks\ASC8_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe [2015-04-09] (IObit)
Task: {69F236FF-8599-44E1-A0AB-34E5286215C5} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {7934C737-3A92-4B0E-BB0B-7E304159238D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.)
Task: {7DDAFE9A-CC40-44B2-B562-DDB58FA2567C} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2014-09-28] (Samsung Electronics.)
Task: {869692B0-2CDB-4756-9DDC-F74346E9D169} - System32\Tasks\VIPRE Upgrade Task => C:\PROGRAM FILES\COMMON FILES\AV\ThreatTrack Security VIPRE\Upgrade.exe [2015-08-14] (ThreatTrack Security Inc.)
Task: {A3CB1314-4DD3-4302-B458-92521C31A2D7} - System32\Tasks\Red Giant Link => C:\Program Files\Red Giant Link\Red Giant Link.exe
Task: {A928F8E9-245A-4C2A-BFD6-F0AFFE2B9917} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [2014-07-31] (TechSmith Corporation)
Task: {B45970EE-97A8-42D1-AFDD-C3BD69ED555A} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {BAC008BE-218A-4A3B-B62F-F98C5400417A} - System32\Tasks\{E39722CC-5D81-4343-B049-24D4F71AE85D} => pcalua.exe -a "C:\Users\Matts Windows7\Desktop\setup-vipre-antivirus-en-us.exe" -d "C:\Users\Matts Windows7\Desktop"
Task: {C357B3D3-AF14-4CB0-AB4F-2EE436C91C29} - System32\Tasks\{1B26D4F7-75D2-485B-9BF1-94FB95852338} => pcalua.exe -a "C:\Users\Matts Windows7\Downloads\AdobeAIRInstaller.exe" -d "C:\Users\Matts Windows7\Downloads"
Task: {C4F4B161-73B2-41D8-A682-14066D75837D} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {C5F03AB6-FD0E-4A0F-9769-A019C85CB428} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-11] (Adobe Systems Incorporated)
Task: {C625DEDC-C9CE-4B79-A715-3A4139B80A29} - System32\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000 => C:\Program Files (x86)\Citrix\GoToMeeting\3215\g2mupdate.exe [2015-08-13] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {CAD45FFC-33CD-4837-8900-F21AE2963F4B} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2010-10-28] (CyberLink)
Task: {CC2A8EF4-1C90-42B9-AE0F-ED1EF3C3AD45} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 5600-6600 Series\ezprint.exe [2010-02-04] (Lexmark International Inc.)
Task: {DEBA24AE-6648-4BFA-8872-10A8EE096F6D} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2015-04-07] (IObit)
Task: {E6AE28F1-2E62-43E9-B7B7-9473561365EA} - System32\Tasks\Driver Booster SkipUAC (Matts Windows7) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-05-14] (IObit)
Task: {E748E5A1-5EDD-449E-A967-BC710282DFE0} - System32\Tasks\SmartDefrag4_Update => C:\Program Files (x86)\IObit\Smart Defrag 4\AutoUpdate.exe [2015-03-03] (IObit)
Task: {EA964A01-2773-4B39-908B-A619AD259B1C} - System32\Tasks\Uninstaller_SkipUac_Matts_Windows7 => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-01-20] (IObit)
Task: {EECFEE42-EBAC-4406-AC22-7489A88F608A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.)
Task: {FECDB8C5-87F5-48EC-AF70-57B2B76198D2} - System32\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000 => C:\Program Files (x86)\Citrix\GoToMeeting\3215\g2mupload.exe [2015-08-13] (Citrix Online, a division of Citrix Systems, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job => C:\Program Files (x86)\Citrix\GoToMeeting\3215\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job => C:\Program Files (x86)\Citrix\GoToMeeting\3215\g2mupload.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2010-12-17 16:53 - 2010-12-17 16:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2013-04-06 14:27 - 2011-04-11 01:26 - 00034304 _____ () C:\Windows\System32\spe__l.dll
2011-06-22 10:44 - 2011-06-22 10:44 - 00034304 _____ () C:\Windows\System32\sst2cl6.dll
2012-05-15 10:58 - 2009-10-16 12:07 - 00186880 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdudrpp.dll
2015-02-13 05:20 - 2015-02-13 05:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-02-13 05:20 - 2015-02-13 05:20 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-07-24 16:05 - 2014-07-24 16:05 - 00210584 _____ () C:\Program Files (x86)\Livedrive\VSSService.exe
2013-04-06 14:27 - 2013-03-18 10:16 - 01353728 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\spe__du.dll
2011-06-22 10:43 - 2011-06-22 10:43 - 00826880 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\sst2cdu.dll
2012-05-15 10:57 - 2009-10-16 12:03 - 01401856 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxduptpc.dll
2012-05-15 10:57 - 2009-10-16 12:07 - 00196608 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxdudrui.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2010-01-02 10:42 - 2010-01-02 10:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2012-06-18 11:24 - 2012-06-18 11:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll
2010-12-17 16:53 - 2010-12-17 16:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-04-15 10:16 - 2011-03-25 20:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-03-01 03:12 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\sqlite3.dll
2015-03-01 02:31 - 2015-01-09 18:46 - 00517408 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\sqlite3.dll
2012-01-05 15:22 - 2012-01-05 15:22 - 00465344 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\sqlite3.dll
2012-01-05 15:22 - 2012-01-05 15:22 - 01081368 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\ACE.dll
2012-01-05 15:22 - 2012-01-05 15:22 - 00125464 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\MailConverter32.dll
2012-02-20 23:26 - 2012-02-20 23:26 - 00160768 _____ () C:\Program Files (x86)\VIPRE\unrar.dll
2015-03-01 03:12 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madExcept_.bpl
2015-03-01 03:12 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madBasic_.bpl
2015-03-01 03:12 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madDisAsm_.bpl
2015-02-13 05:20 - 2015-02-13 05:20 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2015-08-18 08:05 - 2015-08-18 08:05 - 00071168 _____ () c:\Users\Matts Windows7\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgmx8xt.dll
2015-03-04 17:45 - 2015-08-05 16:49 - 00012800 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll
2015-03-04 17:45 - 2015-08-05 16:49 - 00779776 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-07-30 21:28 - 2015-08-05 16:49 - 00056320 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-03-04 17:45 - 2015-08-05 16:49 - 00012288 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll
2015-08-18 08:05 - 2015-08-18 08:05 - 00098816 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32api.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00110080 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\pywintypes27.dll
2015-08-18 08:05 - 2015-08-18 08:05 - 00364544 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\pythoncom27.dll
2015-08-18 08:05 - 2015-08-18 08:05 - 00045568 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\_socket.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 01161216 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\_ssl.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00320512 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32com.shell.shell.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00713216 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\_hashlib.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 01176576 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\wx._core_.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00806400 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\wx._gdi_.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00816128 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\wx._windows_.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 01067008 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\wx._controls_.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00733184 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\wx._misc_.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00682496 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\pysqlite2._sqlite.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00087552 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\_ctypes.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00119808 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32file.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00108544 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32security.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00007168 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\hashobjs_ext.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00068096 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\usb_ext.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00167936 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32gui.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00018432 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32event.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00128512 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\_elementtree.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00127488 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\pyexpat.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00013824 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\common.time34.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00036864 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\_psutil_windows.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00038912 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32inet.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00011264 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32crypt.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00077312 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\wx._html2.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00027136 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\_multiprocessing.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00020480 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\_yappi.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00035840 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32process.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00686080 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\unicodedata.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00123392 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\wx._wizard.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00024064 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32pipe.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00010240 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\select.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00025600 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32pdh.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00525640 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\windows._lib_cacheinvalidation.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00017408 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32profile.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00022528 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\win32ts.pyd
2015-08-18 08:05 - 2015-08-18 08:05 - 00078848 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI46322\wx._animate.pyd
2014-02-06 14:09 - 2015-06-26 03:13 - 00184184 _____ () C:\Program Files (x86)\VIPRE\Definitions\libBase64.dll
2014-02-06 14:09 - 2015-06-26 03:13 - 00175992 _____ () C:\Program Files (x86)\VIPRE\Definitions\libMachoUniv.dll
2015-03-11 23:12 - 2014-09-28 17:59 - 00019872 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAMSUNG_SSD.dll
2015-03-01 03:12 - 2013-01-15 19:48 - 00348992 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl
2015-03-01 03:12 - 2013-01-15 19:48 - 00183616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
2015-03-01 03:12 - 2013-01-15 19:48 - 00051008 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
2014-10-17 12:26 - 2014-10-17 12:26 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\ba8588c3319d63350220ec2ac3eb2c36\IsdiInterop.ni.dll
2011-04-15 09:31 - 2010-09-13 21:28 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2012-01-08 09:41 - 2012-01-08 09:41 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2014-09-15 01:17 - 2014-09-15 01:17 - 00114304 _____ () C:\Program Files (x86)\SplitCam\splitcam_hd_driver_ProxyPlugin.ax
2014-06-30 01:23 - 2014-06-30 01:23 - 02088960 _____ () C:\Program Files (x86)\SplitCam\opencv_core246.dll
2014-06-30 01:23 - 2014-06-30 01:23 - 01905664 _____ () C:\Program Files (x86)\SplitCam\opencv_imgproc246.dll
2014-06-30 01:23 - 2014-06-30 01:23 - 02092544 _____ () C:\Program Files (x86)\SplitCam\opencv_highgui246.dll
2015-08-11 14:58 - 2015-08-07 20:13 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.155\libglesv2.dll
2015-08-11 14:58 - 2015-08-07 20:13 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.155\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Windows:nlsPreferences
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBPIMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AmmyyAdmin => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\atashost => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBAMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBPIMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SplashtopRemoteService => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\aphelionasp.net -> aphelionasp.net
IE trusted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\webex.com -> hxxps://fiserventerprise.webex.com
 
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\100sexlinks.com -> 100sexlinks.com
 
There are 4789 more restricted sites.
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: AmmyyAdmin => 2
MSCONFIG\Services: atashost => 2
MSCONFIG\Services: BstHdAndroidSvc => 2
MSCONFIG\Services: BstHdLogRotatorSvc => 2
MSCONFIG\Services: BstHdUpdaterSvc => 2
MSCONFIG\Services: GamesAppService => 3
MSCONFIG\Services: lxduCATSCustConnectService => 2
MSCONFIG\Services: lxdu_device => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: RichVideo => 2
MSCONFIG\Services: SpliCamService => 2
MSCONFIG\Services: TeamViewer9 => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^LTT.lnk => C:\Windows\pss\LTT.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Matts Windows7^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: 3xAV => C:\Program Files (x86)\Enounce\MySpeed\MySpeed.exe
MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeBridge => 
MSCONFIG\startupreg: AdobeCS4ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: Advanced SystemCare 8 => "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BackupManagerTray => "C:\Program Files (x86)\NTI\Gateway MyBackup\BackupManagerTray.exe" -h -k
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: ConferenceRS => C:\Windows\ConferenceRS.exe 
MSCONFIG\startupreg: ConnectionCenter => "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
MSCONFIG\startupreg: EzPrint => "C:\Program Files (x86)\Lexmark 5600-6600 Series\ezprint.exe"
MSCONFIG\startupreg: GoogleChromeAutoLaunch_9F0FD1DA2B53BECFEBEA5616E08F9C6D => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" –no-startup-window
MSCONFIG\startupreg: HP ENVY 4500 series (NET) => "C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN4AS156NS05X4:NW" -scfn "HP ENVY 4500 series (NET)" -AutoStart 1
MSCONFIG\startupreg: IObit Malware Fighter => "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Jing => C:\Program Files (x86)\TechSmith\Jing\Jing.exe
MSCONFIG\startupreg: Livedrive => "C:\Program Files (x86)\Livedrive\Livedrive.exe" /setup
MSCONFIG\startupreg: lxdumon.exe => "C:\Program Files (x86)\Lexmark 5600-6600 Series\lxdumon.exe"
MSCONFIG\startupreg: MMReminderService => C:\Program Files (x86)\Mindjet\MindManager 10\MMReminderService.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
MSCONFIG\startupreg: SacReminderHDDV2 => C:\ProgramData\OfficeGuardianV2\reminder\SacReminder.exe
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{4994B15A-7B16-4892-B57D-22995C3B0A93}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{285D0772-3372-4239-8864-02FC3FF646D2}] => (Allow) LPort=2869
FirewallRules: [{888A4C9D-E2E2-456D-A957-594A71A226A4}] => (Allow) LPort=1900
FirewallRules: [{98937CF9-E1F7-449E-91D2-2214198F7469}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{5A5D406D-E383-4645-946F-E9472BDE5A0D}] => (Allow) C:\Program Files (x86)\CyberLink\HomeMedia\HomeMedia.exe
FirewallRules: [{406B9D8B-A434-48FA-8ACD-8BBD1F23B4F2}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel Wireless Display\WiDiApp.exe
FirewallRules: [{A5656061-2667-4672-8183-2A545E2BDD2A}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{C8D4D6C2-9006-4A4A-8403-71D855B8CCE6}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{C3AE7CA5-4AE0-4C03-80A9-4CCBE5709DF6}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{59CFCDAC-AE52-4F57-9733-B4C65A2C2FF7}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{3F752444-4AF6-47E5-BD06-02F41D392FDE}] => (Allow) LPort=5353
FirewallRules: [{692A01AB-0EAA-4DD2-BEFE-411D37519363}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
FirewallRules: [{887C0967-B7C1-46C5-89A3-E64C301AC2EC}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
FirewallRules: [TCP Query User{A8C8CE57-899C-42F8-9883-00200389CD47}C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{B880609C-BE39-4C11-95F9-9196F7A30655}C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{216CDBBE-F30A-40CC-BFB3-7312C6C22F8D}] => (Allow) C:\Windows\SysWOW64\lxducoms.exe
FirewallRules: [{0623DF9B-AA1D-42BE-9EC6-CF670C3FE0B9}] => (Allow) C:\Windows\SysWOW64\lxducoms.exe
FirewallRules: [{1E38857E-3C51-47E4-B76B-0622709C55A6}] => (Allow) C:\Windows\System32\lxducoms.exe
FirewallRules: [{F7A5EBD0-606D-4412-A016-90654E816D10}] => (Allow) C:\Windows\System32\lxducoms.exe
FirewallRules: [{FB3CAC58-CD4C-4F6E-9CC9-0E800B445FFD}] => (Allow) C:\Windows\system32\lxducoms.exe
FirewallRules: [{4004F364-20E4-4AD4-9510-3D6C441B6EA8}] => (Allow) C:\Windows\system32\spool\DRIVERS\x64\3\lxdupswx.exe
FirewallRules: [{E6FB8A6B-BB07-4A45-BBCE-9D782ED8FEBA}] => (Allow) C:\Windows\system32\spool\DRIVERS\x64\3\lxdutime.exe
FirewallRules: [{68EF4A10-F9B7-44B8-9E6A-988D6E0EEAD9}] => (Allow) C:\Windows\SysWOW64\lxducoms.exe
FirewallRules: [{2D773B35-093F-4CBF-BFAC-85A70C53B71D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0B0DAB0C-8F45-44F6-88B1-ACA89B9FF9C2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{33C28F0F-151D-4FF1-BE67-A79BBE5F3DCF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{83B81423-B95F-4ACC-AA23-0D96895D2DF5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4164D113-7D6D-41F3-A645-C498E764F821}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Print Driver 2\PrinterSelector\SUPDApp.exe
FirewallRules: [TCP Query User{1B420190-0675-4A38-84EA-C1F18E88DC3E}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{B33C280E-732E-4884-9720-F251B9CD8B3C}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{59838EEF-E840-46C8-B078-8936831DC67C}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{9337AD9B-6BB2-4622-8A5B-D7092C8AF684}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [TCP Query User{3DB83B16-7DDB-4304-AA83-DAB6154A6B24}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{75991F7B-1AE4-493C-9C8E-F74D2B7E8BD2}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{F7140CF0-4721-4019-96DE-EA9AA1699405}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{31D3216E-D052-40C1-892B-5B660E81CEEA}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [{3587FB72-4931-45E0-88B7-2C07F57A5B8B}] => (Block) %ProgramFiles% (x86)\Sparkol\Sparkol VideoScribe\VideoScribeDesktop.exe
FirewallRules: [TCP Query User{C27D82DC-90E6-4759-9F6F-0EDF90F5B402}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{28553A58-082D-4C80-822A-21CA4319A502}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [{3B51A5B6-D8D1-470E-B6EA-A4F3ABBA64EC}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6D30E3DF-9CD4-41CA-A38D-388B8771BB8E}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{E946012A-54A6-4D39-9CBE-57DFD071D68B}C:\program files\winhttrack\winhttrack.exe] => (Allow) C:\program files\winhttrack\winhttrack.exe
FirewallRules: [UDP Query User{ECA7A336-5DB8-46A7-A781-37B52DFF2EA0}C:\program files\winhttrack\winhttrack.exe] => (Allow) C:\program files\winhttrack\winhttrack.exe
FirewallRules: [TCP Query User{BC231830-FC16-4CE3-B3E3-7FFDE39EA008}C:\program files\reflector\reflector.exe] => (Allow) C:\program files\reflector\reflector.exe
FirewallRules: [UDP Query User{F80CEC39-54AD-4E8A-AD5F-A726221A7699}C:\program files\reflector\reflector.exe] => (Allow) C:\program files\reflector\reflector.exe
FirewallRules: [{D494E31C-B123-41F2-9787-9A71F62624CD}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{3B7A911E-EC62-4E24-90B1-123706B92DEA}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B226DE14-AB84-42FD-9B82-9DA07BFA12AA}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{05192244-B159-416C-9768-0D96679044C3}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{A525CCB4-2C86-4595-8CF4-3073D9FC8A7D}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{703017D9-876E-43E7-9C38-626880ED8030}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [TCP Query User{3DB8486D-D86B-4ED1-84D4-6A958F828F63}C:\programdata\microsoft\windows\start menu\programs\whistle.exe] => (Allow) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [UDP Query User{7BA04638-F71E-4B49-A0C6-8961CAEDF83C}C:\programdata\microsoft\windows\start menu\programs\whistle.exe] => (Allow) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [{56FE4147-C0BD-45AD-A487-914998E9F139}] => (Block) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [{438A4B5C-9673-4DB2-9A38-BB874DB793D6}] => (Block) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [{9F5B86D5-CA8B-4773-8DC1-ACC173DDE3F7}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{926F81CA-F346-4D6C-A473-51F7B0383DFF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{46B5B8C4-60E9-4D30-80B5-C71DC2B6643B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{6544F860-06B6-4FCA-9A63-AD3BC7DC7820}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{B9C8E0E7-2CFC-4447-A338-8D4F8E60ECFC}] => (Allow) LPort=8298
FirewallRules: [{864EF2AD-43AA-4664-9ACD-2EE60F69AAC8}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\DeviceSetup.exe
FirewallRules: [{68409358-C465-4D0A-AC68-388087D47BC7}] => (Allow) LPort=5357
FirewallRules: [{818B2472-4269-4FFB-AE3D-3A325B7EACFB}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{4210C355-B346-4F1F-8D74-8EA28D76F06A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C3EC7734-FE0E-4217-B64A-E28B51F787ED}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{22655FD0-A089-4539-B38B-E36F8DC29BFD}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [UDP Query User{04952FD7-B0D2-4ADE-A11C-52E9291D556E}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [TCP Query User{9E888F1E-F8D7-4F9E-95D1-D1D23B527956}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [UDP Query User{AFEC9CFD-5D68-4F03-9C56-CEFFF37F0855}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [TCP Query User{18850C7D-8832-4C09-A98A-EE84F6A9A83F}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{97ED0F4F-5A4A-4B0C-89E5-327F80F7506F}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [{64F35FE2-2045-4D89-97D0-0190D4D1EE53}] => (Allow) LPort=15600
FirewallRules: [{E6007C73-4446-4CBE-A702-096C73B9E1F0}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{499B0422-5E3F-433A-A603-A922BB1B357E}C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [UDP Query User{82A5671A-AAAB-43C1-8699-B67EC583658F}C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [{A3B58086-25FC-4A87-85C3-FFECF089CA41}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{4B489E80-2B94-4EEC-BC6D-890ADACB57A9}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
FirewallRules: [{DBB9A72E-139D-441B-B93C-9E91AE4FB8F5}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
FirewallRules: [{CB0D7568-18BD-48FD-8CDC-F2E03E2A089A}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\DataProxy.exe
 
==================== Faulty Device Manager Devices =============
 
Name: SBRE
Description: SBRE
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: SBRE
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/18/2015 08:04:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/18/2015 08:04:55 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/17/2015 01:34:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/17/2015 01:34:05 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/17/2015 12:21:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/17/2015 12:21:36 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/16/2015 12:00:19 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/16/2015 12:00:19 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/15/2015 11:29:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/15/2015 11:29:49 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
 
System errors:
=============
Error: (08/18/2015 11:31:38 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240020: Upgrade to Windows 10 Home.
 
Error: (08/18/2015 08:05:59 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (08/18/2015 08:05:55 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)
 
Error: (08/18/2015 08:04:59 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
SBRE
 
Error: (08/18/2015 08:04:55 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The BlueStacks Android Service service terminated with the following error: 
%%1064
 
Error: (08/17/2015 03:42:31 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240020: Upgrade to Windows 10 Home.
 
Error: (08/17/2015 01:35:10 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (08/17/2015 01:35:05 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)
 
Error: (08/17/2015 01:34:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
SBRE
 
Error: (08/17/2015 01:34:05 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The BlueStacks Android Service service terminated with the following error: 
%%1064
 
 
Microsoft Office:
=========================
Error: (08/18/2015 08:04:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/18/2015 08:04:55 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/17/2015 01:34:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/17/2015 01:34:05 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/17/2015 12:21:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/17/2015 12:21:36 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/16/2015 12:00:19 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/16/2015 12:00:19 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/15/2015 11:29:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/15/2015 11:29:49 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
 
CodeIntegrity:
===================================
  Date: 2015-08-15 23:17:13.727
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-08-15 23:17:13.696
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
Percentage of memory in use: 48%
Total physical RAM: 8043.86 MB
Available physical RAM: 4158.61 MB
Total Virtual: 16085.92 MB
Available Virtual: 11504.35 MB
 
==================== Drives ================================
 
Drive c: (Gateway) (Fixed) (Total:419.08 GB) (Free:130.12 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 380202E7)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=419.1 GB) - (Type=07 NTFS)
 
==================== End of log ============================

 

This was the report from ComboFix from a few days ago.  When I tried to fix it :(

 

ComboFix 15-08-14.01 - Matts Windows7 08/15/2015  23:10:36.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.8044.4732 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: ThreatTrack Security VIPRE *Disabled/Updated* {FFE93D16-FD09-0282-C7D3-8B1731B6A051}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: ThreatTrack Security VIPRE *Disabled/Updated* {4488DCF2-DB33-0D0C-FD63-B0654A31EAEC}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
ADS - Windows: deleted 192 bytes in 1 streams.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\programdata\Roaming
c:\users\Matts Windows7\AppData\Local\assembly\tmp
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\_ctypes.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\_elementtree.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\_hashlib.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\_multiprocessing.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\_psutil_windows.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\_socket.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\_ssl.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\_yappi.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\common.time34.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\hashobjs_ext.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\pyexpat.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\pysqlite2._sqlite.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\python27.dll
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\pythoncom27.dll
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\PyWinTypes27.dll
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\select.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\unicodedata.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\usb_ext.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32api.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32com.shell.shell.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32crypt.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32event.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32file.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32gui.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32inet.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32pdh.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32pipe.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32process.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32profile.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32security.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\win32ts.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\windows._lib_cacheinvalidation.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wx._animate.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wx._controls_.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wx._core_.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wx._gdi_.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wx._html2.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wx._misc_.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wx._windows_.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wx._wizard.pyd
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wxbase30u_net_vc90.dll
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wxbase30u_vc90.dll
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wxmsw30u_adv_vc90.dll
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wxmsw30u_core_vc90.dll
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wxmsw30u_html_vc90.dll
c:\users\Matts Windows7\AppData\Local\Temp\_MEI54842\wxmsw30u_webview_vc90.dll
c:\users\Matts Windows7\g2mdlhlpx.exe
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\_ctypes.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\_elementtree.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\_hashlib.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\_multiprocessing.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\_psutil_windows.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\_socket.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\_ssl.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\_yappi.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\common.time34.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\hashobjs_ext.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\pyexpat.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\pysqlite2._sqlite.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\python27.dll
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\pythoncom27.dll
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\PyWinTypes27.dll
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\select.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\unicodedata.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\usb_ext.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32api.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32com.shell.shell.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32crypt.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32event.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32file.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32gui.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32inet.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32pdh.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32pipe.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32process.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32profile.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32security.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\win32ts.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\windows._lib_cacheinvalidation.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wx._animate.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wx._controls_.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wx._core_.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wx._gdi_.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wx._html2.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wx._misc_.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wx._windows_.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wx._wizard.pyd
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wxbase30u_net_vc90.dll
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wxbase30u_vc90.dll
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wxmsw30u_adv_vc90.dll
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wxmsw30u_core_vc90.dll
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wxmsw30u_html_vc90.dll
c:\users\MATTSW~1\AppData\Local\Temp\_MEI54842\wxmsw30u_webview_vc90.dll
c:\windows\Hook.dll
c:\windows\SysWow64\DEBUG.log
c:\windows\wininit.ini
.
.
(((((((((((((((((((((((((   Files Created from 2015-07-16 to 2015-08-16  )))))))))))))))))))))))))))))))
.
.
2015-08-16 03:28 . 2015-08-16 03:28 ——– d—–w- c:\users\Default\AppData\Local\temp
2015-08-16 02:44 . 2015-08-16 02:44 ——– d—–w- c:\users\Matts Windows7\AppData\Roaming\LavasoftStatistics
2015-08-16 02:43 . 2015-08-16 02:43 ——– d—–w- c:\program files\Common Files\Lavasoft
2015-08-16 02:38 . 2015-08-16 02:38 ——– d—–w- C:\OneDriveTemp
2015-08-16 02:37 . 2015-08-16 02:37 ——– d—–w- c:\programdata\Lavasoft
2015-08-16 02:29 . 2015-08-16 02:33 ——– d—–w- C:\AdwCleaner
2015-08-12 21:34 . 2015-07-30 13:13 103120 —-a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 21:34 . 2015-07-30 13:13 124624 —-a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 17:52 . 2015-07-15 03:19 52736 —-a-w- c:\windows\system32\basesrv.dll
2015-08-12 17:51 . 2015-07-01 20:49 260096 —-a-w- c:\windows\system32\WebClnt.dll
2015-08-12 17:50 . 2015-07-16 19:12 37376 —-a-w- c:\windows\SysWow64\tsgqec.dll
2015-08-12 17:50 . 2015-07-16 19:12 4922368 —-a-w- c:\windows\SysWow64\mstscax.dll
2015-08-12 17:50 . 2015-07-16 19:12 269824 —-a-w- c:\windows\SysWow64\aaclient.dll
2015-08-12 17:50 . 2015-07-16 19:11 44032 —-a-w- c:\windows\system32\tsgqec.dll
2015-08-12 17:50 . 2015-07-16 19:11 5779456 —-a-w- c:\windows\system32\mstscax.dll
2015-08-12 17:50 . 2015-07-16 19:11 322560 —-a-w- c:\windows\system32\aaclient.dll
2015-08-12 17:50 . 2015-07-10 17:51 14177280 —-a-w- c:\windows\system32\shell32.dll
2015-08-11 13:52 . 2015-08-11 13:52 11534096 —-a-w- c:\windows\system32\drivers\NETwsw01.sys
2015-08-05 00:43 . 2015-08-05 00:43 ——– d—–w- c:\program files (x86)\LongTailPro
2015-08-04 20:49 . 2015-08-04 20:49 ——– d—–w- c:\program files (x86)\GIGProspector
2015-08-04 19:50 . 2015-08-04 19:50 ——– d—–w- c:\users\Matts Windows7\AppData\Roaming\article.buddy.ArticleBuddy
2015-08-04 18:36 . 2015-08-04 18:36 ——– d—–w- c:\users\Matts Windows7\Articles
2015-08-04 18:36 . 2015-08-04 18:36 ——– d—–w- c:\users\Matts Windows7\AppData\Roaming\User
2015-08-04 18:36 . 2015-08-04 18:36 ——– d—–w- c:\users\Matts Windows7\GPS
2015-08-04 14:22 . 2015-08-16 02:48 ——– d—–w- c:\users\Matts Windows7\AppData\Roaming\IDM
2015-08-04 14:22 . 2015-08-04 14:22 ——– d—–w- c:\program files (x86)\Internet Download Manager
2015-08-03 19:01 . 2015-08-03 19:01 ——– d—–w- c:\program files (x86)\Arclab
2015-08-01 19:36 . 2015-07-02 19:25 310272 —-a-w- c:\windows\system32\KLF_OGL_x64.dll
2015-08-01 19:30 . 2015-08-01 19:30 ——– d—–w- c:\programdata\goodasnew
2015-08-01 19:28 . 2015-08-01 19:28 ——– d—–w- c:\users\Matts Windows7\AppData\Roaming\Red Giant
2015-08-01 19:28 . 2015-08-01 19:30 ——– d—–w- c:\program files (x86)\Red Giant Link
2015-08-01 19:28 . 2015-08-01 19:28 ——– d—–w- c:\programdata\Red Giant
2015-08-01 19:27 . 2015-08-01 19:27 ——– d—–w- c:\program files (x86)\Red Giant
2015-08-01 19:23 . 2015-08-01 19:36 ——– d—–w- c:\programdata\RedGiant
2015-07-31 20:27 . 2015-07-31 20:27 ——– d—–w- c:\users\Matts Windows7\AppData\Roaming\TeeSpy
2015-07-29 03:22 . 2015-07-29 03:22 ——– d—–w- c:\program files (x86)\AD RESPARK
2015-07-29 03:21 . 2015-07-29 03:21 ——– d—–w- c:\users\Matts Windows7\AppData\Roaming\com.gorialogics.adrespark
2015-07-28 20:48 . 2015-07-28 20:48 ——– d—–w- c:\users\Matts Windows7\AppData\Roaming\RoboForm
2015-07-28 20:42 . 2015-07-28 20:42 ——– d—–w- c:\programdata\RoboForm
2015-07-28 20:41 . 2015-07-28 20:41 ——– d—–w- c:\program files (x86)\Siber Systems
2015-07-28 19:49 . 2015-07-28 19:49 ——– d—–w- c:\users\Matts Windows7\AppData\Roaming\InstaBannerAIR
2015-07-28 19:49 . 2015-07-28 19:49 ——– d—–w- c:\program files (x86)\InstaBannerAIR
2015-07-28 16:45 . 2015-07-28 16:45 ——– d—–w- C:\$Windows.~BT
2015-07-28 03:29 . 2015-07-28 03:29 ——– d—–w- c:\users\Matts Windows7\AppData\Roaming\IrfanView
2015-07-28 03:29 . 2015-07-28 03:29 ——– d—–w- c:\program files (x86)\IrfanView
2015-07-24 23:58 . 2015-08-12 00:29 ——– d—–w- C:\zxz
2015-07-22 22:37 . 2015-07-22 22:37 2689680 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\VBA\VBA7\VBE7.DLL
2015-07-21 14:34 . 2015-07-21 14:34 ——– d—–w- c:\program files (x86)\Common Files\Java
2015-07-20 20:33 . 2015-07-20 20:33 ——– d—–w- c:\users\Matts Windows7\AppData\Roaming\com.longtailpro.LongTailPro
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-08-16 02:03 . 2015-05-26 22:20 136408 —-a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-08-13 21:54 . 2015-05-26 22:19 107736 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-08-12 21:18 . 2011-12-29 01:04 132483416 —-a-w- c:\windows\system32\MRT.exe
2015-08-12 00:00 . 2014-03-13 01:38 778440 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-08-12 00:00 . 2014-03-13 01:38 142536 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-07-21 14:21 . 2014-10-29 17:06 97888 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-07-15 17:54 . 2015-08-12 17:53 44032 —-a-w- c:\windows\apppatch\acwow64.dll
2015-07-15 15:09 . 2015-07-15 15:09 458960 —-a-w- c:\windows\system32\drivers\k57nd60a.sys
2015-07-04 18:07 . 2015-07-14 18:33 2087424 —-a-w- c:\windows\system32\ole32.dll
2015-07-04 17:48 . 2015-07-14 18:33 1414656 —-a-w- c:\windows\SysWow64\ole32.dll
2015-06-29 16:44 . 2015-06-29 16:44 280680 —-a-w- c:\windows\SysWow64\IntelCpHeciSvc.exe
2015-06-29 16:44 . 2015-06-29 16:44 116224 —-a-w- c:\windows\system32\igfxCoIn_v4229.dll
2015-06-29 16:44 . 2015-06-29 16:44 410112 —-a-w- c:\windows\system32\igfxTMM.dll
2015-06-29 16:44 . 2015-06-29 16:44 173672 —-a-w- c:\windows\system32\igfxtray.exe
2015-06-29 16:44 . 2015-06-29 16:44 513640 —-a-w- c:\windows\system32\igfxsrvc.exe
2015-06-29 16:44 . 2015-06-29 16:44 440320 —-a-w- c:\windows\system32\igfxrell.lrc
2015-06-29 16:44 . 2015-06-29 16:44 439808 —-a-w- c:\windows\system32\igfxrfra.lrc
2015-06-29 16:44 . 2015-06-29 16:44 439808 —-a-w- c:\windows\system32\igfxresn.lrc
2015-06-29 16:44 . 2015-06-29 16:44 439296 —-a-w- c:\windows\system32\igfxrrus.lrc
2015-06-29 16:44 . 2015-06-29 16:44 439296 —-a-w- c:\windows\system32\igfxrrom.lrc
2015-06-29 16:44 . 2015-06-29 16:44 438784 —-a-w- c:\windows\system32\igfxrsky.lrc
2015-06-29 16:44 . 2015-06-29 16:44 438784 —-a-w- c:\windows\system32\igfxrptg.lrc
2015-06-29 16:44 . 2015-06-29 16:44 438784 —-a-w- c:\windows\system32\igfxrplk.lrc
2015-06-29 16:44 . 2015-06-29 16:44 438784 —-a-w- c:\windows\system32\igfxrnld.lrc
2015-06-29 16:44 . 2015-06-29 16:44 438784 —-a-w- c:\windows\system32\igfxrita.lrc
2015-06-29 16:44 . 2015-06-29 16:44 438784 —-a-w- c:\windows\system32\igfxrhrv.lrc
2015-06-29 16:44 . 2015-06-29 16:44 438784 —-a-w- c:\windows\system32\igfxrdeu.lrc
2015-06-29 16:44 . 2015-06-29 16:44 438272 —-a-w- c:\windows\system32\igfxrhun.lrc
2015-06-29 16:44 . 2015-06-29 16:44 438272 —-a-w- c:\windows\system32\igfxrfin.lrc
2015-06-29 16:44 . 2015-06-29 16:44 438272 —-a-w- c:\windows\system32\igfxrcsy.lrc
2015-06-29 16:44 . 2015-06-29 16:44 437760 —-a-w- c:\windows\system32\igfxrtrk.lrc
2015-06-29 16:44 . 2015-06-29 16:44 437760 —-a-w- c:\windows\system32\igfxrsve.lrc
2015-06-29 16:44 . 2015-06-29 16:44 437760 —-a-w- c:\windows\system32\igfxrslv.lrc
2015-06-29 16:44 . 2015-06-29 16:44 437760 —-a-w- c:\windows\system32\igfxrptb.lrc
2015-06-29 16:44 . 2015-06-29 16:44 437760 —-a-w- c:\windows\system32\igfxrnor.lrc
2015-06-29 16:44 . 2015-06-29 16:44 437248 —-a-w- c:\windows\system32\igfxrtha.lrc
2015-06-29 16:44 . 2015-06-29 16:44 437248 —-a-w- c:\windows\system32\igfxrdan.lrc
2015-06-29 16:44 . 2015-06-29 16:44 435712 —-a-w- c:\windows\system32\igfxrheb.lrc
2015-06-29 16:44 . 2015-06-29 16:44 435712 —-a-w- c:\windows\system32\igfxrara.lrc
2015-06-29 16:44 . 2015-06-29 16:44 432128 —-a-w- c:\windows\system32\igfxrjpn.lrc
2015-06-29 16:44 . 2015-06-29 16:44 431104 —-a-w- c:\windows\system32\igfxrkor.lrc
2015-06-29 16:44 . 2015-06-29 16:44 429056 —-a-w- c:\windows\system32\igfxrcht.lrc
2015-06-29 16:44 . 2015-06-29 16:44 428544 —-a-w- c:\windows\system32\igfxrchs.lrc
2015-06-29 16:44 . 2015-06-29 16:44 286208 —-a-w- c:\windows\system32\igfxrenu.lrc
2015-06-29 16:44 . 2011-04-15 14:16 9007616 —-a-w- c:\windows\system32\igfxress.dll
2015-06-29 16:44 . 2011-04-15 14:16 64000 —-a-w- c:\windows\system32\igfxsrvc.dll
2015-06-29 16:44 . 2015-06-29 16:44 444008 —-a-w- c:\windows\system32\igfxpers.exe
2015-06-29 16:44 . 2015-06-29 16:44 384512 —-a-w- c:\windows\system32\igfxpph.dll
2015-06-29 16:44 . 2015-06-29 16:44 256616 —-a-w- c:\windows\system32\igfxext.exe
2015-06-29 16:44 . 2015-06-29 16:44 25088 —-a-w- c:\windows\SysWow64\igfxexps32.dll
2015-06-29 16:44 . 2011-04-15 14:16 31984 —-a-w- c:\windows\system32\igfxexps.dll
2015-06-29 16:44 . 2015-06-29 16:44 9728 —-a-w- c:\windows\system32\IGFXDEVLib.dll
2015-06-29 16:44 . 2015-06-29 16:44 330752 —-a-w- c:\windows\SysWow64\igfxdv32.dll
2015-06-29 16:44 . 2015-06-29 16:44 142336 —-a-w- c:\windows\system32\igfxdo.dll
2015-06-29 16:44 . 2015-06-29 16:44 126976 —-a-w- c:\windows\system32\igfxcpl.cpl
2015-06-29 16:44 . 2011-04-15 14:16 442880 —-a-w- c:\windows\system32\igfxdev.dll
2015-06-29 16:44 . 2015-06-29 16:44 12694808 —-a-w- c:\windows\system32\igdumd64.dll
2015-06-29 16:44 . 2015-06-29 16:44 11117808 —-a-w- c:\windows\SysWow64\igdumd32.dll
2015-06-29 16:43 . 2015-06-29 16:43 5375448 —-a-w- c:\windows\system32\drivers\igdkmd64.sys
2015-06-29 16:43 . 2015-06-29 16:43 81408 —-a-w- c:\windows\SysWow64\igdde32.dll
2015-06-29 16:43 . 2015-06-29 16:43 101376 —-a-w- c:\windows\system32\igdde64.dll
2015-06-29 16:43 . 2011-04-15 14:16 12937864 —-a-w- c:\windows\system32\igd10umd64.dll
2015-06-29 16:43 . 2015-05-06 01:27 11245520 —-a-w- c:\windows\SysWow64\igd10umd32.dll
2015-06-29 16:43 . 2015-06-29 16:43 13028864 —-a-w- c:\windows\system32\ig4icd64.dll
2015-06-29 16:43 . 2015-06-29 16:43 10811392 —-a-w- c:\windows\SysWow64\ig4icd32.dll
2015-06-29 16:43 . 2015-06-29 16:43 401512 —-a-w- c:\windows\system32\hkcmd.exe
2015-06-29 16:43 . 2011-04-15 14:16 110592 —-a-w- c:\windows\system32\hccutils.dll
2015-06-29 16:43 . 2015-06-29 16:43 5906536 —-a-w- c:\windows\system32\GfxUI.exe
2015-06-29 16:43 . 2015-06-29 16:43 175104 —-a-w- c:\windows\system32\gfxSrvc.dll
2015-06-29 16:43 . 2015-06-29 16:43 187496 —-a-w- c:\windows\system32\difx64.exe
2015-06-26 02:11 . 2015-06-26 02:11 493504 —-a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2015-06-26 02:11 . 2015-06-26 02:11 229376 —-a-w- c:\windows\system32\wintrust.dll
2015-06-26 02:11 . 2015-06-26 02:11 188416 —-a-w- c:\windows\system32\cryptsvc.dll
2015-06-26 02:11 . 2015-06-26 02:11 179200 —-a-w- c:\windows\SysWow64\wintrust.dll
2015-06-26 02:11 . 2015-06-26 02:11 1480192 —-a-w- c:\windows\system32\crypt32.dll
2015-06-26 02:11 . 2015-06-26 02:11 143872 —-a-w- c:\windows\SysWow64\cryptsvc.dll
2015-06-26 02:11 . 2015-06-26 02:11 140288 —-a-w- c:\windows\system32\cryptnet.dll
2015-06-26 02:11 . 2015-06-26 02:11 1174528 —-a-w- c:\windows\SysWow64\crypt32.dll
2015-06-26 02:11 . 2015-06-26 02:11 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll
2015-06-24 05:29 . 2015-06-24 05:29 1217192 —-a-w- c:\windows\SysWow64\FM20.DLL
2015-06-17 17:47 . 2015-07-14 18:36 404992 —-a-w- c:\windows\system32\gdi32.dll
2015-06-17 17:37 . 2015-07-14 18:36 312320 —-a-w- c:\windows\SysWow64\gdi32.dll
2015-06-15 21:50 . 2015-07-14 18:32 112064 —-a-w- c:\windows\system32\consent.exe
2015-06-15 21:45 . 2015-07-14 18:32 3242496 —-a-w- c:\windows\system32\msi.dll
2015-06-15 21:45 . 2015-07-14 18:32 504320 —-a-w- c:\windows\system32\msihnd.dll
2015-06-15 21:45 . 2015-07-14 18:32 1941504 —-a-w- c:\windows\system32\authui.dll
2015-06-15 21:45 . 2015-07-14 18:32 70656 —-a-w- c:\windows\system32\appinfo.dll
2015-06-15 21:44 . 2015-07-14 18:32 128000 —-a-w- c:\windows\system32\msiexec.exe
2015-06-15 21:43 . 2015-07-14 18:32 2364416 —-a-w- c:\windows\SysWow64\msi.dll
2015-06-15 21:43 . 2015-07-14 18:32 337408 —-a-w- c:\windows\SysWow64\msihnd.dll
2015-06-15 21:43 . 2015-07-14 18:32 1805824 —-a-w- c:\windows\SysWow64\authui.dll
2015-06-15 21:42 . 2015-07-14 18:32 73216 —-a-w- c:\windows\SysWow64\msiexec.exe
2015-06-15 21:42 . 2015-07-14 18:32 25088 —-a-w- c:\windows\system32\msimsg.dll
2015-06-15 21:37 . 2015-07-14 18:32 25088 —-a-w- c:\windows\SysWow64\msimsg.dll
2015-06-09 18:03 . 2015-07-14 18:37 3180544 —-a-w- c:\windows\system32\rdpcorets.dll
2015-06-09 18:03 . 2015-07-14 18:37 16384 —-a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2015-06-08 20:23 . 2015-06-08 20:23 36864 —-a-w- c:\windows\system32\UtcResources.dll
2015-06-08 20:23 . 2015-06-08 20:23 1255424 —-a-w- c:\windows\system32\diagtrack.dll
2015-06-08 20:23 . 2015-06-08 20:23 879104 —-a-w- c:\windows\system32\tdh.dll
2015-06-08 20:23 . 2015-06-08 20:23 879104 —-a-w- c:\windows\system32\advapi32.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt3]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt4]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt5]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt6]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt7]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt8]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2015-07-27 18:03 1584328 —-a-w- c:\users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2015-07-27 18:03 1584328 —-a-w- c:\users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2015-07-27 18:03 1584328 —-a-w- c:\users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2015-07-27 18:03 1584328 —-a-w- c:\users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2015-07-27 18:03 1584328 —-a-w- c:\users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt3]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt4]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt5]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt6]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt7]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt8]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 189464 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay]
@="{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}"
[HKEY_CLASSES_ROOT\CLSID\{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}]
2012-11-10 14:55 158056 —-a-w- c:\windows\SysWOW64\CbFsMntNtf3.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2015-07-29 22344224]
"LightShot"="c:\users\Matts Windows7\AppData\Local\Skillbrains\lightshot\Lightshot.exe" [2014-07-01 226560]
"OneDrive"="c:\users\Matts Windows7\AppData\Local\Microsoft\OneDrive\OneDrive.exe" [2015-07-27 402632]
"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2015-04-26 43816]
"Dropbox Update"="c:\users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe" [2015-06-16 134512]
"RoboForm"="c:\program files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2015-07-28 110160]
"IDMan"="c:\program files (x86)\Internet Download Manager\IDMan.exe" [2015-05-20 3903056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2011-03-14 1081424]
"SBAMTray"="c:\program files (x86)\VIPRE\SBAMTray.exe" [2013-09-06 3216272]
"Malwarebytes Anti-Exploit"="c:\program files (x86)\Malwarebytes Anti-Exploit\mbae.exe" [2015-07-22 2620728]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2015-06-08 334896]
.
c:\users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2015-6-15 39179912]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Install LastPass FF RunOnce.lnk - c:\program files (x86)\Common Files\lpuninstall.exe -q -name=LastPass -ffuuid [removed] [2014-8-9 15000576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\Citrix\ICACLI~1\RSHook.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ   autocheck autochk *\0SmartDefragBootTime.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBPIMSvc]
@="Service"
.
R1 SBRE;SBRE; [x]
R2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 cpudrv64;cpudrv64;c:\program files (x86)\SystemRequirementsLab\cpudrv64.sys;c:\program files (x86)\SystemRequirementsLab\cpudrv64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 gfiark;gfiark;c:\windows\system32\drivers\gfiark.sys;c:\windows\SYSNATIVE\drivers\gfiark.sys [x]
R3 gfiutil;gfiutil;c:\windows\system32\drivers\gfiutil.sys;c:\windows\SYSNATIVE\drivers\gfiutil.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys;c:\windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
R4 atashost;WebEx Service Host for Support Center;c:\windows\SysWOW64\atashost.exe;c:\windows\SysWOW64\atashost.exe [x]
R4 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
R4 lxdu_device;lxdu_device;c:\windows\system32\lxducoms.exe;c:\windows\SYSNATIVE\lxducoms.exe [x]
R4 lxduCATSCustConnectService;lxduCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\lxduserv.exe;c:\windows\SYSNATIVE\spool\DRIVERS\x64\3\\lxduserv.exe [x]
R4 SpliCamService;SplitCamService;c:\program files (x86)\SplitCam\SplitCamService.exe;c:\program files (x86)\SplitCam\SplitCamService.exe [x]
R4 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 SamsungRapidDiskFltr;SAMSUNG RAPID Mode Disk Filter Driver;c:\windows\system32\DRIVERS\SamsungRapidDiskFltr.sys;c:\windows\SYSNATIVE\DRIVERS\SamsungRapidDiskFltr.sys [x]
S0 SamsungRapidFSFltr;SamsungRapidFSFltr;c:\windows\system32\DRIVERS\SamsungRapidFSFltr.sys;c:\windows\SYSNATIVE\DRIVERS\SamsungRapidFSFltr.sys [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys;c:\windows\SYSNATIVE\DRIVERS\ctxusbm.sys [x]
S1 ESProtectionDriver;Malwarebytes Anti-Exploit;c:\program files (x86)\Malwarebytes Anti-Exploit\mbae64.sys;c:\program files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AdvancedSystemCareService8;Advanced SystemCare Service 8;c:\program files (x86)\IObit\Advanced SystemCare 8\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [x]
S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
S2 CFUACProxy_officeguardianv2;CFUACProxy_officeguardianv2;c:\programdata\OfficeGuardianV2\UACProxy.exe;c:\programdata\OfficeGuardianV2\UACProxy.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 ePowerSvc;Acer ePower Service;c:\program files\Gateway\Gateway Power Management\ePowerSvc.exe;c:\program files\Gateway\Gateway Power Management\ePowerSvc.exe [x]
S2 GREGService;GREGService;c:\program files (x86)\Gateway\Registration\GREGsvc.exe;c:\program files (x86)\Gateway\Registration\GREGsvc.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys;c:\windows\SYSNATIVE\DRIVERS\idmwfp.sys [x]
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S2 Live Updater Service;Live Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [x]
S2 LivedriveVSSService;Livedrive VSS Service;c:\program files (x86)\Livedrive\VSSService.exe;c:\program files (x86)\Livedrive\VSSService.exe [x]
S2 MbaeSvc;Malwarebytes Anti-Exploit Service;c:\program files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe;c:\program files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\nlssrv32.exe;c:\windows\SysWOW64\nlssrv32.exe [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe;c:\program files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe [x]
S2 SamsungRapidSvc;Samsung RAPID Mode Service;c:\windows\system32\RAPID\SamsungRapidSvc.exe;c:\windows\SYSNATIVE\RAPID\SamsungRapidSvc.exe [x]
S2 SBAMSvc;VIPRE Antivirus;c:\program files (x86)\VIPRE\SBAMSvc.exe;c:\program files (x86)\VIPRE\SBAMSvc.exe [x]
S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys;c:\windows\SYSNATIVE\DRIVERS\sbapifs.sys [x]
S2 SBPIMSvc;SB Recovery Service;c:\program files (x86)\VIPRE\SBPIMSvc.exe;c:\program files (x86)\VIPRE\SBPIMSvc.exe [x]
S2 SplashtopRemoteService;Splashtop® Remote Service;c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe;c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe [x]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x]
S2 SSUService;Splashtop Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe;c:\program files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe [x]
S2 TechSmith Uploader Service;TechSmith Uploader Service;c:\program files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe;c:\program files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 b57xdbd;Broadcom xD Picture Bus Driver Service;c:\windows\system32\DRIVERS\b57xdbd.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdbd.sys [x]
S3 b57xdmp;Broadcom xD Picture vstorp client drv;c:\windows\system32\DRIVERS\b57xdmp.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdmp.sys [x]
S3 bScsiMSa;bScsiMSa;c:\windows\system32\DRIVERS\bScsiMSa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiMSa.sys [x]
S3 bScsiSDa;bScsiSDa;c:\windows\system32\DRIVERS\bScsiSDa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiSDa.sys [x]
S3 cbfs3;EldoS Callback File System driver v3;c:\windows\system32\DRIVERS\cbfs3.sys;c:\windows\SYSNATIVE\DRIVERS\cbfs3.sys [x]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 sbwtis;sbwtis;c:\windows\system32\DRIVERS\sbwtis.sys;c:\windows\SYSNATIVE\DRIVERS\sbwtis.sys [x]
S3 scvad_simple;SplitCam Virtual Microphone (WDM);c:\windows\system32\drivers\SplitCamAudio.sys;c:\windows\SYSNATIVE\drivers\SplitCamAudio.sys [x]
S3 splitcam_hd_driver;SplitCam Virtual Video Driver;c:\windows\system32\DRIVERS\splitcam_hd_driver.sys;c:\windows\SYSNATIVE\DRIVERS\splitcam_hd_driver.sys [x]
S3 stdpms;Splashtop DPMS Driver;c:\windows\system32\DRIVERS\stdpms.sys;c:\windows\SYSNATIVE\DRIVERS\stdpms.sys [x]
S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys;c:\windows\SYSNATIVE\DRIVERS\WDKMD.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-08-11 18:58 995144 —-a-w- c:\program files (x86)\Google\Chrome\Application\44.0.2403.155\Installer\chrmstp.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{90EF4A5E-85DB-4825-96F5-1AB93C2A8EEB}]
2011-09-14 17:52 1409 —-a-r- c:\program files (x86)\Mindjet\MindManager 10\sys\MmInternetExplorerActiveSetup.vbs
.
Contents of the 'Scheduled Tasks' folder
.
2015-08-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-13 00:00]
.
2015-08-15 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job
- c:\users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-16 01:13]
.
2015-08-16 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job
- c:\users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-16 01:13]
.
2015-08-16 c:\windows\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job
- c:\program files (x86)\Citrix\GoToMeeting\3215\g2mupdate.exe [2015-08-14 01:45]
.
2015-08-16 c:\windows\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job
- c:\program files (x86)\Citrix\GoToMeeting\3215\g2mupload.exe [2015-08-14 01:45]
.
2015-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-05 17:57]
.
2015-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-05 17:57]
.
2015-08-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job
- c:\users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe [2014-11-09 03:20]
.
2015-08-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job
- c:\users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe [2014-11-09 03:20]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\  GoogleDriveBlacklisted]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-07-29 13:23 775496 —-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\  GoogleDriveSynced]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-07-29 13:23 775496 —-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\  GoogleDriveSyncing]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-07-29 13:23 775496 —-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 226328 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 226328 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt3]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 226328 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt4]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 226328 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt5]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 226328 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt6]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 226328 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt7]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 226328 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt8]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2015-08-05 22:53 226328 —-a-w- c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2015-07-27 18:03 1636040 —-a-w- c:\users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2015-07-27 18:03 1636040 —-a-w- c:\users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2015-07-27 18:03 1636040 —-a-w- c:\users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2015-07-27 18:03 1636040 —-a-w- c:\users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2015-07-27 18:03 1636040 —-a-w- c:\users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupOverlay]
@="{B44A5D93-1351-41A1-BD91-5E92435D8ECD}"
[HKEY_CLASSES_ROOT\CLSID\{B44A5D93-1351-41A1-BD91-5E92435D8ECD}]
2014-07-24 20:05 1245848 —-a-w- c:\program files (x86)\Livedrive\Extensions.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay]
@="{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}"
[HKEY_CLASSES_ROOT\CLSID\{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}]
2012-11-10 14:55 190312 —-a-w- c:\windows\System32\CbFsMntNtf3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2014-04-21 08:02 25112 —-a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\LivedriveDownloadOverlay]
@="{CBCDB610-6B68-4EE9-B7A2-1282FD0C9292}"
[HKEY_CLASSES_ROOT\CLSID\{CBCDB610-6B68-4EE9-B7A2-1282FD0C9292}]
2014-07-24 20:05 1245848 —-a-w- c:\program files (x86)\Livedrive\Extensions.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\LivedriveSharedOverlay]
@="{84CEF1E4-1356-4063-845F-05047F4DD52C}"
[HKEY_CLASSES_ROOT\CLSID\{84CEF1E4-1356-4063-845F-05047F4DD52C}]
2014-07-24 20:05 1245848 —-a-w- c:\program files (x86)\Livedrive\Extensions.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\LivedriveSyncedOverlay]
@="{42058329-2FBF-4B33-8E52-3BE5754DE0C1}"
[HKEY_CLASSES_ROOT\CLSID\{42058329-2FBF-4B33-8E52-3BE5754DE0C1}]
2014-07-24 20:05 1245848 —-a-w- c:\program files (x86)\Livedrive\Extensions.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\LivedriveUploadOverlay]
@="{39A1715A-E4CD-4F1E-B5C4-36B5DB80124E}"
[HKEY_CLASSES_ROOT\CLSID\{39A1715A-E4CD-4F1E-B5C4-36B5DB80124E}]
2014-07-24 20:05 1245848 —-a-w- c:\program files (x86)\Livedrive\Extensions.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-17 1933584]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-03-10 11785832]
"Power Management"="c:\program files\Gateway\Gateway Power Management\ePowerTray.exe" [2011-02-23 1796200]
"FAHConsole"="c:\program files\File Association Helper\FAHConsole.exe" [2014-01-28 729272]
"SamsungRapidApp"="c:\program files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe" [2014-09-16 281776]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2015-04-07 169768]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2015-06-29 173672]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2015-06-29 401512]
"Persistence"="c:\windows\system32\igfxpers.exe" [2015-06-29 444008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\acaptuser64.dll
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE:
IE: Append to existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert link target to existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Customize Menu - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComCustomizeIEMenu.html
IE: Download all links with IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: E&xport; to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Fill Forms - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComFillForms.html
IE: Save Forms - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComSavePass.html
IE: Se&nd; to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: Send Image To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/201
IE: Send Link To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/203
IE: Send Page To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/204
IE: Send Text To MindManager - c:\program files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll/202
IE: Show RoboForm Toolbar - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComShowToolbar.html
Trusted Zone: aphelionasp.net
Trusted Zone: webex.com\fiserventerprise
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{74A46DCB-14BB-4752-B3FB-9562D1C5B0B1}: NameServer = 192.168.1.254
TCP: Interfaces\{74A46DCB-14BB-4752-B3FB-9562D1C5B0B1}\144545A496E607577716: NameServer = 192.168.1.254
TCP: Interfaces\{74A46DCB-14BB-4752-B3FB-9562D1C5B0B1}\2375942554031303: NameServer = 192.168.1.254
FF - ProfilePath - c:\users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/
FF - prefs.js: network.proxy.gopher - 
FF - prefs.js: network.proxy.gopher_port - 0
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
SafeBoot-MBAMSwissArmy
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\Wow6432Node\CLSID\{4e88c395-62c4-427c-b3a3-6a42c6ffb16a}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:000000d7
"Therad"=dword:00000016
.
[HKEY_USERS\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):3c,63,03,99,cc,15,b4,eb,d8,dc,9a,8b,e4,78,a4,75,08,7f,e8,d6,9b,
   a8,22,d7,b4,41,05,88,ac,cc,86,63,37,f9,dc,a6,de,d3,88,4a,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_232_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_232_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_232_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_232_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.18"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Launch Manager\LMutilps32.exe
c:\program files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
c:\users\Matts Windows7\AppData\Local\Skillbrains\lightshot\5.1.4.41\Lightshot.exe
c:\users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe
c:\program files (x86)\Launch Manager\LMworker.exe
c:\program files (x86)\Samsung\Samsung Magician\Samsung Magician.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Completion time: 2015-08-15  23:55:55 - machine was rebooted
ComboFix-quarantined-files.txt  2015-08-16 03:55
.
Pre-Run: 144,431,505,408 bytes free
Post-Run: 144,321,581,056 bytes free
.
- - End Of File - - C5BB86CDAD4E7C446E2C9403C992F3BA

This was the report from Rkill from a few days ago.  When I tried to fix it :(

 

Rkill 2.7.0 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html
 
Program started at: 08/15/2015 11:02:02 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * C:\Windows\SysWOW64\nlssrv32.exe (PID: 2344) [WD-HEUR]
 * C:\Users\Matts Windows7\AppData\Local\Skillbrains\lightshot\5.1.4.41\Lightshot.exe (PID: 5500) [UP-HEUR]
 
2 proccesses terminated!
 
Checking Registry for malware related settings:
 
 * No issues found in the Registry.
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
 
Performing miscellaneous checks:
 
 * Windows Defender Disabled
 
   [HKLM\SOFTWARE\Microsoft\Windows Defender]
   "DisableAntiSpyware" = dword:00000001
 
 * ALERT: ZEROACCESS rootkit symptoms found!
 
     * C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}\ [ZA Dir]
     * C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}\@ [ZA File]
     * C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}\L\ [ZA Dir]
     * C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}\U\ [ZA Dir]
 
Checking Windows Service Integrity: 
 
 * Windows Defender (WinDefend) is not Running.
   Startup Type set to: Manual
 
 * wuauserv [Missing Service]
 
Searching for Missing Digital Signatures: 
 
 * No issues found.
 
Checking HOSTS File: 
 
 * HOSTS file entries found: 
 
  127.0.0.1 localhost wordpress wordpress1 wordpress2 wordpress3 wordpress4 wordpress5 wordpress6 wordpress7 wordpress8 wordpress9 wordpress10 wordpress351 wpsim
  127.0.0.1 127.0.0.1
  ::1 localhost 
  127.0.0.1 activate.adobe.com
  127.0.0.1 practivate.adobe.com
  127.0.0.1 ereg.adobe.com
  127.0.0.1 activate.wip3.adobe.com
  127.0.0.1 wip3.adobe.com
  127.0.0.1 3dns-3.adobe.com
  127.0.0.1 3dns-2.adobe.com
  127.0.0.1 adobe-dns.adobe.com
  127.0.0.1 adobe-dns-2.adobe.com
  127.0.0.1 adobe-dns-3.adobe.com
  127.0.0.1 ereg.wip3.adobe.com
  127.0.0.1 activate-sea.adobe.com
  127.0.0.1 wwis-dubc1-vip60.adobe.com
  127.0.0.1 activate-sjc0.adobe.com
  127.0.0.1 wwis-dubc1-vip60.adobe.com
  127.0.0.1 192.150.18.108
  127.0.0.1 localhost
 
  20 out of 23 HOSTS entries shown.
  Please review HOSTS file for further entries.
 
Program finished at: 08/15/2015 11:02:23 PM
Execution time: 0 hours(s), 0 minute(s), and 20 seconds(s)

Hello Matt11,

Welcome to WTT.

Firstly a question:

Do you connect Chrome with a Google account?

Tell me when you return.

For now

Please download Junkware Removal Tool to your desktop.
 

  • Shut down your protection software to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right click JRT.exe and "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Next

Download and run the Chrome Cleanup Tool.

   Open the Chrome Cleanup Tool. It will immediately start searching your computer for programs known to cause problems with Chrome.


  •     A message will tell you if any programs were found.
  •     Click Remove programs. Wait until you see the message "Removal complete." Some open applications may be closed in the process.
  •     Click Continue to quit the tool. (If your computer needs to reboot, the button will say Restart.)
  •     Chrome will automatically reopen asking if you want to reset your browser settings.
  •     Click Reset.

Finally

If you do connect through Google do the following:

Please open Chrome, connect to Google, then check the preferences and the advanced preferences. Delete every Addon and Extension you do not know. Reset Chrome while the account is still connected.

Come back and tell me how the machine is now.

So when you return please post

  • JRT.txt
  • Tell me if you use the Google account with Chrome
  • Tell me if the above actions have made a difference

 

Hi,
 
Yes I connect Chrome with my gmail account.  I only sync my (Apps, Extensions, Bookmarks).
 
I did do the Chrome Clean Up Tool and all apps/extensions are there the ones I recognized.
 
I am not sure yet if these changes made a difference.  I will have to click around on some sites to see if it has.

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.6 (08.10.2015:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on Tue 08/18/2015 at 23:23:07.70
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
Successfully deleted: [Task] C:\Windows\system32\tasks\Driver Booster Scan
Successfully deleted: [Task] C:\Windows\system32\tasks\Driver Booster SkipUAC (Matts Windows7)
Successfully deleted: [Task] C:\Windows\system32\tasks\Driver Booster Update
Successfully deleted: [Task] C:\Windows\system32\tasks\Uninstaller_SkipUac_Matts_Windows7
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Empty Folder] C:\Users\Matts Windows7\Appdata\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}
Successfully deleted: [Folder] C:\Program Files (x86)\iobit\driver booster
Successfully deleted: [Folder] C:\ProgramData\iobit\driver booster
Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\driver booster 2
Successfully deleted: [Folder] C:\ProgramData\productdata
Successfully deleted: [Folder] C:\Users\Matts Windows7\AppData\Roaming\iobit\driver booster
Successfully deleted: [Folder] C:\Users\Matts Windows7\AppData\Roaming\productdata
 
 
 
~~~ FireFox
 
Successfully deleted the following from C:\Users\Matts Windows7\AppData\Roaming\mozilla\firefox\profiles\hbgszlrn.default\prefs.js
 
user_pref(extensions.seoquake.params.10.disable-yandex, true);
user_pref(extensions.seoquake.params.150.disable-yandex, true);
user_pref(extensions.seoquake.params.160.disable-yandex, true);
user_pref(extensions.seoquake.params.370.disable-yandex, true);
user_pref(extensions.seoquake.params.380.disable-yandex, true);
user_pref(extensions.seoquake.params.410.disable-yandex, true);
user_pref(extensions.seoquake.params.430.disable-yandex, true);
user_pref(extensions.seoquake.params.500.disable-yandex, true);
user_pref(extensions.seoquake.params.510.disable-yandex, true);
user_pref(extensions.seoquake.params.530.disable-yandex, true);
Emptied folder: C:\Users\Matts Windows7\AppData\Roaming\mozilla\firefox\profiles\hbgszlrn.default\minidumps [79 files]
 
 
 
~~~ Chrome
 
Successfully deleted: [Folder] C:\Users\Matts Windows7\Appdata\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic
 
[C:\Users\Matts Windows7\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\Matts Windows7\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
gpdjojdkbbmdfjfahjcgigfpmkopogic
 
[C:\Users\Matts Windows7\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\Matts Windows7\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
  gpdjojdkbbmdfjfahjcgigfpmkopogic
]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 08/18/2015 at 23:27:19.98
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Just a follow up.  I am still testing this out.  So far it hasn't reoccurred.  I will slowly begin to add back a few of my extensions to see if they are corrupt.

Encouraging so far then. :thumbup:

Once you are happy, we should run an on line anti-virus scan to make sure we haven't missed any bits and pieces. I will give you some instructions for that.

 

Finally, all going well, we will remove the tools we have been using. :)

Ok this is what I can figure out for the most part.  I started to get the same error again.  But what I did was install the 3 extensions.  Out of the 3 extensions, I'm not sure which one is the culprit.

 

Adblock Plus 1.9.1

Video Downloader 1.0.4.8

Video Downloader Super 6.2.0

 

When I unstalled them and reset Chrome.  The redirect errors stop.  It has been 36 hours with no redirects.

I would replace Adblock Plus with this:

 

Download Adblock edge to prevent unwanted pop up adds. This one doesn't have sponsored adds whitelisted.

 

Adblock Plus has sponsored adds nowadays.

 

As far as the other two are concerned there are a number of Video Downloader ones that are bad. AdwCleaner usually picks them up but not always. Really a matter of testing them.

 

Also, when you get a moment it might be worth running another scan with FRST. Check the Addition.txt box and post back the two logs generated. FRST.txt and Addition.txt.

 

I will have a look and see if anything else jumps out at me. :)

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:25-08-2015 02
Ran by [removed] (administrator) on MATTSWINDOWS7 (25-08-2015 21:19:30)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Storage Appliance Corp.) C:\ProgramData\OfficeGuardianV2\UACProxy.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Acer Incorporated) C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
() C:\Program Files (x86)\Livedrive\VSSService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe
(ThreatTrack Security, Inc.) C:\Program Files (x86)\VIPRE\SBPIMSvc.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
(Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Skillbrains) C:\Users\Matts Windows7\AppData\Local\Skillbrains\lightshot\5.1.4.41\Lightshot.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Dropbox, Inc.) C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(ThreatTrack Security, Inc.) C:\Program Files (x86)\VIPRE\SBAMSvc.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\DataProxy.exe
(ThreatTrack Security, Inc.) C:\Program Files (x86)\VIPRE\SBAMTray.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel(R) Corporation)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2280232 2010-07-29] (Synaptics Incorporated)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11785832 2011-03-10] (Realtek Semiconductor)
HKLM\…\Run: [Power Management] => C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe [1796200 2011-02-23] (Acer Incorporated)
HKLM\…\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
HKLM\…\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [281776 2014-09-16] (Samsung Electronics Co., Ltd.)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\…\Run: [SBAMTray] => C:\Program Files (x86)\VIPRE\SBAMTray.exe [3216272 2013-09-05] (ThreatTrack Security, Inc.)
HKLM-x32\…\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2620728 2015-07-22] (Malwarebytes Corporation)
HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22344224 2015-07-29] (Google)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [LightShot] => C:\Users\Matts Windows7\AppData\Local\Skillbrains\lightshot\Lightshot.exe [226560 2014-07-01] ()
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [OneDrive] => C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\OneDrive.exe [404064 2015-08-20] (Microsoft Corporation)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [Dropbox Update] => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-15] (Dropbox, Inc.)
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3903056 2015-05-20] (Tonec Inc.)
AppInit_DLLs: C:\Windows\System32\acaptuser64.dll => C:\Windows\System32\acaptuser64.dll [119160 2008-06-12] (Adobe Systems, Inc.)
AppInit_DLLs-x32: C:\PROGRA~2\Citrix\ICACLI~1\RSHook.dll => C:\Program Files (x86)\Citrix\ICA Client\RSHook.dll [257208 2012-05-23] (Citrix Systems, Inc.)
AppInit_DLLs-x32:  acaptuser32.dll => "acaptuser32.dll" File not found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2014-08-09]
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-02-12]
ShortcutTarget: Dropbox.lnk -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [BackupOverlay] -> {B44A5D93-1351-41A1-BD91-5E92435D8ECD} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll [2012-11-10] (EldoS Corporation)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2014-04-21] (Tonec Inc.)
ShellIconOverlayIdentifiers: [LivedriveDownloadOverlay] -> {CBCDB610-6B68-4EE9-B7A2-1282FD0C9292} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveSharedOverlay] -> {84CEF1E4-1356-4063-845F-05047F4DD52C} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveSyncedOverlay] -> {42058329-2FBF-4B33-8E52-3BE5754DE0C1} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveUploadOverlay] -> {39A1715A-E4CD-4F1E-B5C4-36B5DB80124E} => C:\Program Files (x86)\Livedrive\Extensions.dll [2014-07-24] (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll [2012-11-10] (EldoS Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000 -> DefaultScope {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08] (Adobe Systems Incorporated)
BHO-x32: CmjBrowserHelperObject Object -> {6FE6A929-59D1-4763-91AD-29B61CFFB35B} -> C:\Program Files (x86)\Mindjet\MindManager 10\Mm8InternetExplorer.dll [2011-09-14] (Mindjet)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-08-18] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: VIPRE Search Guard Helper -> {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} -> C:\Program Files (x86)\VIPRE\VSG.dll [2013-09-05] ()
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Lexmark Printable Web -> {D2C5E510-BE6D-42CC-9F61-E4F939078474} -> C:\Program Files\Lexmark Printable Web\bho.dll [2010-02-04] ()
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-18] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} -  No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - C:\Program Files (x86)\VIPRE\VSG.dll [2013-09-05] ()
Toolbar: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} hxxps://fiserventerprise.webex.com/client/WBXclient-T27L10NSP32EP5-14362/support/ieatgpc1.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler-x32: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - C:\Program Files (x86)\VIPRE\VSG.dll [2013-09-05] ()
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-05-23] (Citrix Systems, Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{12A99469-5D32-4F0D-A147-834FA18A0312}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{74A46DCB-14BB-4752-B3FB-9562D1C5B0B1}: [NameServer] 192.168.1.254
Tcpip\..\Interfaces\{74A46DCB-14BB-4752-B3FB-9562D1C5B0B1}: [DhcpNameServer] 10.251.4.1
 
FireFox:
========
FF ProfilePath: C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default
FF Homepage: hxxps://www.google.com/
FF NetworkProxy: "gopher", ""
FF NetworkProxy: "gopher_port", 0
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-11] ()
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2014-08-09] (LastPass)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2013-03-21] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-11] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2012-05-23] (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-18] (Oracle Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass.dll [2014-08-09] (LastPass)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2013-03-21] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Matts Windows7\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2013-05-29] (Citrix Online)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Matts Windows7\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @talk.google.com/O1DPlugin -> C:\Users\Matts Windows7\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-3123964009-4157677460-2703354282-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-10-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Matts Windows7\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Matts Windows7\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Extension: FoxyProxy Standard - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2015-06-02]
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2015-08-19]
FF Extension: LastPass - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2015-07-22]
FF Extension: SeoQuake - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74} [2015-06-05]
FF Extension: ColorZilla - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2015-05-28]
FF Extension: iMacros for Firefox - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2015-05-29]
FF Extension: Live HTTP headers - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2015-05-28]
FF Extension: Firebug - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2012-01-12]
FF Extension: VTzilla - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2012-01-12]
FF Extension: HMA! IP Checker - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2013-12-23]
FF Extension: SpyBar - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2015-08-06]
FF Extension: Multi Links - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2014-11-13]
FF Extension: Real Hide IP - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\[removed] [2012-04-28]
FF Extension: S3 Firefox Organizer(S3Fox) - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{7CEA821D-3DAB-4238-B424-BF7324531750}.xpi [2014-01-10]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2014-03-12]
FF Extension: Video DownloadHelper - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-08-23]
FF Extension: Web Developer - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2014-02-03]
FF Extension: Adblock Plus - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-18]
FF Extension: SearchStatus - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{d57c9ff1-6389-48fc-b770-f78bd89b6e8a}.xpi [2014-11-13]
FF Extension: Adblock Edge - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2015-08-25]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-20]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-20]
FF HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Matts Windows7\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Matts Windows7\AppData\Roaming\IDM\idmmzcc5 [2015-08-25]
FF HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\Matts Windows7\AppData\Roaming\IDM\idmmzcc5
 
Chrome: 
=======
CHR Profile: C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-22]
CHR Extension: (Google Docs) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-01]
CHR Extension: (Google Drive) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-01]
CHR Extension: (YouTube) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-01]
CHR Extension: (Precise Interest Profits) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cboffagmdlncaldokfebdghmcfnloffa [2014-06-06]
CHR Extension: (Adblock Plus) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-10-21]
CHR Extension: (Google Search) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-01]
CHR Extension: (SpyBar) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkcihmjnfimlnmdjoddhjfiihbfpcnfk [2014-06-03]
CHR Extension: (Block site) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimnmioipafcokbfikbljfdeojpcgbh [2015-05-28]
CHR Extension: (FB Pixel Helper) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdgfkebogiimcoedlicjlajpkdmockpc [2014-07-04]
CHR Extension: (Google Sheets) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-22]
CHR Extension: (Audience Intersect) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjeffkdcbmggkbkedhbjemcpmgfccpil [2014-10-10]
CHR Extension: (Video Downloader Super) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghciphhakbampjemlfbahnhhaemoeolf [2015-02-16]
CHR Extension: (Follow) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkakfimgbmogkpmjokgnbbanmmemcdij [2014-06-26]
CHR Extension: (Pin It Button) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-08-18]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2015-08-13]
CHR Extension: (Video Downloader) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnmpgleggfcndpeflbjhpjfckfmojnpo [2015-02-10]
CHR Extension: (SocialPinSniper) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\llfojbapbcelaoniflkhioicjmlpileg [2015-02-14]
CHR Extension: (Sunrise Calendar) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\mojepfklcankkmikonjlnidiooanmpbb [2015-08-18]
CHR Extension: (EXIF Viewer) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafpfdcmppffipmhcpkbplhkoiekndck [2015-07-27]
CHR Extension: (IDM Integration Module) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-07-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-01]
CHR Extension: (Docs PDF/PowerPoint Viewer (by Google)) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbmlagghjjcbdhgmkedmbmedengocbn [2014-02-01]
CHR Extension: (Pingler) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgiehjnopebofbjkgdjenflakfaahnm [2014-12-22]
CHR Extension: (Gmail) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-01]
CHR Extension: (Headlinr) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\plhlpcokjhajajgmpbapiohjhldkjdbi [2015-05-07]
CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
CHR HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdvancedSystemCareService8; C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [814880 2015-04-03] (IObit)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-03-13] (BlueStack Systems, Inc.)
S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-03-13] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [770832 2014-03-13] (BlueStack Systems, Inc.)
R2 CFUACProxy_officeguardianv2; C:\ProgramData\OfficeGuardianV2\UACProxy.exe [83792 2011-07-25] (Storage Appliance Corp.)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [878912 2015-04-02] (IObit)
R2 LivedriveVSSService; C:\Program Files (x86)\Livedrive\VSSService.exe [210584 2014-07-24] ()
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-30] (IObit)
S4 lxduCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\lxduserv.exe [29184 2009-10-16] (Lexmark International, Inc.)
S4 lxdu_device; C:\Windows\system32\lxducoms.exe [1039360 2009-10-16] ( )
S4 lxdu_device; C:\Windows\SysWOW64\lxducoms.exe [589824 2009-10-16] ( )
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [713016 2015-07-22] (Malwarebytes Corporation)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
R2 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2011-01-31] (Nalpeiron Ltd.) [File not signed]
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe [256536 2012-01-05] (NTI Corporation)
S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe [244904 2010-10-27] () [File not signed]
R2 SamsungRapidSvc; C:\Windows\System32\RAPID\SamsungRapidSvc.exe [28848 2014-09-16] (Samsung Electronics Co., Ltd.)
R2 SBAMSvc; C:\Program Files (x86)\VIPRE\SBAMSvc.exe [3937472 2013-09-05] (ThreatTrack Security, Inc.)
R2 SBPIMSvc; C:\Program Files (x86)\VIPRE\SBPIMSvc.exe [176016 2013-09-05] (ThreatTrack Security, Inc.)
S4 SpliCamService; C:\Program Files (x86)\SplitCam\SplitCamService.exe [311424 2014-09-15] (SplitCam Co.)
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [121616 2014-03-13] (BlueStack Systems)
S3 catchme; no ImagePath
R3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [352008 2012-11-10] (EldoS Corporation)
S3 cpudrv64; C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [17864 2011-06-02] ()
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [63064 2015-07-22] ()
S4 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2015-03-25] (IObit)
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
S3 gfiutil; C:\Windows\System32\drivers\gfiutil.sys [31264 2013-09-04] (ThreatTrack Security)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-03-01] (REALiX™)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-08-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
R3 NETwNs64; C:\Windows\System32\DRIVERS\NETwsw01.sys [11534096 2015-08-11] (Intel Corporation)
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2015-03-25] (IObit.com)
R0 SamsungRapidDiskFltr; C:\Windows\System32\DRIVERS\SamsungRapidDiskFltr.sys [268976 2014-09-16] (Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\Windows\System32\DRIVERS\SamsungRapidFSFltr.sys [111280 2014-09-16] (Samsung Electronics Co., Ltd.)
R2 sbapifs; C:\Windows\System32\DRIVERS\sbapifs.sys [88928 2013-06-18] (ThreatTrack Security, Inc.)
S1 SBRE; no ImagePath
R3 scvad_simple; C:\Windows\System32\drivers\SplitCamAudio.sys [23552 2014-06-30] (Windows (R) Win 7 DDK provider)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
R3 splitcam_hd_driver; C:\Windows\System32\DRIVERS\splitcam_hd_driver.sys [37496 2014-06-30] (Windows (R) Win 7 DDK provider)
R3 stdpms; C:\Windows\System32\DRIVERS\stdpms.sys [28904 2013-10-22] (Splashtop Inc.)
S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2015-03-25] (IObit.com)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-25 21:19 - 2015-08-25 21:20 - 00047942 _____ C:\Users\Matts Windows7\Desktop\FRST.txt
2015-08-25 21:16 - 2015-08-25 21:16 - 02186752 _____ (Farbar) C:\Users\Matts Windows7\Desktop\FRST64.exe
2015-08-25 21:01 - 2015-08-25 21:01 - 00001885 _____ C:\AdwCleaner[C11].txt
2015-08-25 20:56 - 2015-08-25 20:57 - 00001688 _____ C:\AdwCleaner[S21].txt
2015-08-25 20:35 - 2015-08-25 20:35 - 00000000 ___HD C:\OneDriveTemp
2015-08-25 16:05 - 2015-08-25 16:05 - 00000209 _____ C:\Users\Matts Windows7\Desktop\ASAP go.txt
2015-08-25 15:18 - 2015-08-25 16:06 - 00000000 ____D C:\Users\Matts Windows7\Desktop\The Clarity Program
2015-08-25 14:48 - 2015-08-25 21:10 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Virus protection
2015-08-25 11:59 - 2015-08-25 12:41 - 00000000 __RHD C:\ESD
2015-08-25 11:58 - 2012-04-15 09:50 - 330471842 _____ C:\Users\Matts Windows7\Desktop\GRAND PALMS.avi
2015-08-24 14:02 - 2015-08-24 16:38 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Fit Pros Swipes
2015-08-24 11:05 - 2015-08-25 21:01 - 00000448 _____ C:\Windows\setupact.log
2015-08-24 11:05 - 2015-08-24 11:05 - 00000548 _____ C:\Windows\PFRO.log
2015-08-24 11:05 - 2015-08-24 11:05 - 00000000 _____ C:\Windows\setuperr.log
2015-08-23 18:20 - 2015-08-24 18:27 - 00000249 _____ C:\Users\Matts Windows7\Desktop\Do and Read.txt
2015-08-21 18:03 - 2015-08-21 18:03 - 00001497 _____ C:\Users\Matts Windows7\Desktop\Schema-Swipe-File.txt
2015-08-21 17:29 - 2015-08-21 17:34 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Superfood PLR + OTO
2015-08-21 14:58 - 2015-08-21 14:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-21 10:39 - 2015-08-21 10:39 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 01632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 00115136 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-08-21 10:39 - 2015-08-21 10:39 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-08-21 10:39 - 2015-08-21 10:39 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 05568960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 03989952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 03934656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01390592 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-08-21 10:38 - 2015-08-21 10:38 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-08-21 10:38 - 2015-08-21 10:38 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-08-21 10:38 - 2015-08-21 10:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-08-21 10:38 - 2015-08-21 10:38 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-08-21 10:38 - 2015-08-21 10:38 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-08-21 10:38 - 2015-08-21 10:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-21 10:38 - 2015-08-21 10:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-08-21 10:36 - 2015-08-21 10:36 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-08-21 10:36 - 2015-08-21 10:36 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-08-20 23:57 - 2015-08-20 23:57 - 00000000 ____H C:\Users\Matts Windows7\Documents\Default.rdp
2015-08-20 21:50 - 2015-08-20 21:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-20 21:34 - 2015-08-20 21:34 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\Social_Multiplier
2015-08-20 21:32 - 2015-08-20 21:32 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SocialMultiplier
2015-08-20 21:32 - 2015-08-20 21:32 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\SkinSoft
2015-08-20 21:32 - 2015-08-20 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SocialMultiplier
2015-08-20 21:31 - 2015-08-20 21:32 - 00000000 ____D C:\Program Files (x86)\SocialMultiplier
2015-08-19 12:11 - 2015-08-19 12:20 - 00000000 ____D C:\ProgramData\flipBook
2015-08-19 12:11 - 2015-08-19 12:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flip PDF
2015-08-19 12:11 - 2015-08-19 12:11 - 00000000 ____D C:\ProgramData\A-PDF
2015-08-19 12:11 - 2015-08-19 12:11 - 00000000 ____D C:\Program Files (x86)\Flip PDF
2015-08-19 10:39 - 2015-08-20 20:16 - 00002932 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Matts_Windows7
2015-08-19 10:38 - 2015-08-25 21:02 - 00002902 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (Matts Windows7)
2015-08-19 10:38 - 2015-08-19 10:38 - 00003260 _____ C:\Windows\System32\Tasks\Driver Booster Scan
2015-08-19 10:38 - 2015-08-19 10:38 - 00003204 _____ C:\Windows\System32\Tasks\Driver Booster Update
2015-08-19 10:38 - 2015-08-19 10:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2
2015-08-19 09:53 - 2015-08-10 21:20 - 25191936 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-19 09:53 - 2015-08-10 21:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-19 09:53 - 2015-08-10 20:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-08-19 09:53 - 2015-08-10 20:20 - 19871232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-08-18 23:58 - 2015-08-21 10:25 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\ProductData
2015-08-18 23:58 - 2015-08-20 20:16 - 00000000 ____D C:\ProgramData\ProductData
2015-08-18 21:13 - 2015-08-18 21:13 - 00000000 ___SD C:\ComboFix
2015-08-18 18:47 - 2015-08-18 18:47 - 00281232 _____ C:\Windows\Minidump\081815-6957-01.dmp
2015-08-18 18:08 - 2015-08-18 18:08 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Sun
2015-08-18 18:08 - 2015-08-18 18:08 - 00000000 ____D C:\Users\Matts Windows7\.oracle_jre_usage
2015-08-18 17:28 - 2015-08-18 18:47 - 2085089726 _____ C:\Windows\MEMORY.DMP
2015-08-18 17:28 - 2015-08-18 17:28 - 00284984 _____ C:\Windows\Minidump\081815-8080-01.dmp
2015-08-18 11:02 - 2015-08-18 11:02 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-18 09:47 - 2015-08-18 09:49 - 134128457 _____ C:\Users\Matts Windows7\Desktop\May 7th Webinar Replay.MP4
2015-08-17 13:33 - 2008-04-07 06:38 - 00051032 ____R (Adobe Systems Inc) C:\Windows\system32\AdobePDF.dll
2015-08-17 13:33 - 2008-04-07 06:38 - 00024416 ____R (Adobe Systems Inc.) C:\Windows\system32\AdobePDFUI.dll
2015-08-17 12:32 - 2015-08-20 23:50 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Social Multiplier
2015-08-17 01:56 - 2015-08-17 01:56 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Element 3D V2.2.0.2100 (Win)
2015-08-16 00:44 - 2015-08-17 18:17 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Social Video Formula
2015-08-16 00:05 - 2015-08-16 00:06 - 00000894 _____ C:\AdwCleaner[S20].txt
2015-08-15 23:56 - 2015-08-15 23:56 - 00067456 _____ C:\ComboFix.txt
2015-08-15 23:09 - 2011-06-26 02:45 - 00256000 _____ C:\Windows\PEV.exe
2015-08-15 23:09 - 2010-11-07 13:20 - 00208896 _____ C:\Windows\MBR.exe
2015-08-15 23:09 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00098816 _____ C:\Windows\sed.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00080412 _____ C:\Windows\grep.exe
2015-08-15 23:09 - 2000-08-30 20:00 - 00068096 _____ C:\Windows\zip.exe
2015-08-15 23:08 - 2015-08-18 21:13 - 00000000 ____D C:\Qoobox
2015-08-15 23:07 - 2015-08-15 23:45 - 00000000 ____D C:\Windows\erdnt
2015-08-15 22:54 - 2015-08-15 22:54 - 00001083 _____ C:\AdwCleaner[C10].txt
2015-08-15 22:52 - 2015-08-15 22:53 - 00000900 _____ C:\AdwCleaner[S19].txt
2015-08-15 22:44 - 2015-08-15 22:44 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\LavasoftStatistics
2015-08-15 22:43 - 2015-08-15 22:43 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2015-08-15 22:37 - 2015-08-15 22:37 - 00000000 ____D C:\ProgramData\Lavasoft
2015-08-15 22:29 - 2015-08-15 22:33 - 00000000 ____D C:\AdwCleaner
2015-08-14 19:38 - 2015-08-14 19:38 - 00000027 _____ C:\Users\Matts Windows7\Desktop\BUY.txt
2015-08-14 19:01 - 2015-08-14 19:02 - 41019438 _____ C:\Users\Matts Windows7\Desktop\Element 3D V2.2   Crack.mp4
2015-08-14 18:19 - 2015-08-14 18:44 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Digital Profits Academy
2015-08-13 13:55 - 2015-08-13 13:55 - 00000060 _____ C:\Users\Matts Windows7\Desktop\DOOOOOOOOOOOOOOOO.txt
2015-08-12 17:34 - 2015-07-30 09:13 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 17:34 - 2015-07-30 09:13 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 16:41 - 2015-08-12 16:41 - 00001057 _____ C:\Users\Matts Windows7\Desktop\[BBHF VIP Sachin's Cracked] Long Tail Pro Platinum 3.0.11 Updated.txt
2015-08-12 16:34 - 2015-08-23 22:23 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Immersion Session 3
2015-08-12 13:53 - 2015-07-28 16:09 - 00017344 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-08-12 13:53 - 2015-07-28 16:05 - 01116672 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00774656 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00743424 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00437760 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-08-12 13:53 - 2015-07-28 16:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-08-12 13:53 - 2015-07-28 15:55 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-08-12 13:53 - 2015-07-15 14:15 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-12 13:53 - 2015-07-15 14:10 - 01743360 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-12 13:53 - 2015-07-15 14:10 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-12 13:52 - 2015-07-20 20:39 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-12 13:52 - 2015-07-20 20:12 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-08-12 13:52 - 2015-07-16 16:54 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-08-12 13:52 - 2015-07-16 16:37 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-08-12 13:52 - 2015-07-16 16:36 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-12 13:52 - 2015-07-16 16:36 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-12 13:52 - 2015-07-16 16:36 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-08-12 13:52 - 2015-07-16 16:35 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-12 13:52 - 2015-07-16 16:35 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-08-12 13:52 - 2015-07-16 16:27 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-12 13:52 - 2015-07-16 16:26 - 05923328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-12 13:52 - 2015-07-16 16:26 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-08-12 13:52 - 2015-07-16 16:23 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-12 13:52 - 2015-07-16 16:21 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-12 13:52 - 2015-07-16 16:21 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-08-12 13:52 - 2015-07-16 16:21 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-12 13:52 - 2015-07-16 16:21 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-08-12 13:52 - 2015-07-16 16:12 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-12 13:52 - 2015-07-16 16:08 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-12 13:52 - 2015-07-16 16:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-12 13:52 - 2015-07-16 15:55 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-08-12 13:52 - 2015-07-16 15:54 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-12 13:52 - 2015-07-16 15:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-08-12 13:52 - 2015-07-16 15:51 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-12 13:52 - 2015-07-16 15:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-08-12 13:52 - 2015-07-16 15:50 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-08-12 13:52 - 2015-07-16 15:50 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-08-12 13:52 - 2015-07-16 15:49 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-08-12 13:52 - 2015-07-16 15:45 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-08-12 13:52 - 2015-07-16 15:43 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-08-12 13:52 - 2015-07-16 15:43 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-08-12 13:52 - 2015-07-16 15:41 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-08-12 13:52 - 2015-07-16 15:39 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-08-12 13:52 - 2015-07-16 15:39 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-08-12 13:52 - 2015-07-16 15:38 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-08-12 13:52 - 2015-07-16 15:36 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-12 13:52 - 2015-07-16 15:35 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-08-12 13:52 - 2015-07-16 15:34 - 14451200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-12 13:52 - 2015-07-16 15:33 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-08-12 13:52 - 2015-07-16 15:32 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-12 13:52 - 2015-07-16 15:29 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-08-12 13:52 - 2015-07-16 15:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-12 13:52 - 2015-07-16 15:20 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-08-12 13:52 - 2015-07-16 15:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-08-12 13:52 - 2015-07-16 15:17 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-08-12 13:52 - 2015-07-16 15:12 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-08-12 13:52 - 2015-07-16 15:12 - 02427904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-12 13:52 - 2015-07-16 15:10 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-08-12 13:52 - 2015-07-16 15:06 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-08-12 13:52 - 2015-07-16 15:06 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-08-12 13:52 - 2015-07-16 15:05 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-08-12 13:52 - 2015-07-16 15:01 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-12 13:52 - 2015-07-16 14:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-08-12 13:52 - 2015-07-16 14:42 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-08-12 13:52 - 2015-07-16 14:38 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-08-12 13:52 - 2015-07-16 14:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-08-12 13:52 - 2015-07-14 23:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-08-12 13:51 - 2015-07-30 14:06 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-08-12 13:51 - 2015-07-30 13:57 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-08-12 13:51 - 2015-07-30 13:55 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-08-12 13:51 - 2015-07-30 12:56 - 03208192 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-12 13:51 - 2015-07-30 12:52 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-12 13:51 - 2015-07-30 12:49 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-08-12 13:51 - 2015-07-14 23:19 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-12 13:51 - 2015-07-14 23:19 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-12 13:51 - 2015-07-14 23:14 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-08-12 13:51 - 2015-07-14 23:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-08-12 13:51 - 2015-07-14 22:55 - 01390592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-08-12 13:51 - 2015-07-14 22:55 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-08-12 13:51 - 2015-07-14 22:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-08-12 13:51 - 2015-07-14 22:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-08-12 13:51 - 2015-07-09 13:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-12 13:51 - 2015-07-09 13:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-12 13:51 - 2015-07-09 13:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
2015-08-12 13:51 - 2015-07-01 16:49 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-12 13:51 - 2015-07-01 16:48 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-08-12 13:51 - 2015-07-01 16:30 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2015-08-12 13:51 - 2015-07-01 16:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2015-08-12 13:50 - 2015-07-16 15:12 - 04922368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-08-12 13:50 - 2015-07-16 15:12 - 00269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2015-08-12 13:50 - 2015-07-16 15:12 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-08-12 13:50 - 2015-07-16 15:11 - 05779456 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-12 13:50 - 2015-07-16 15:11 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-08-12 13:50 - 2015-07-16 15:11 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-08-12 13:50 - 2015-07-10 13:51 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-12 13:50 - 2015-07-10 13:34 - 12875776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-08-12 02:25 - 2015-08-12 02:25 - 00000042 _____ C:\Users\Matts Windows7\Desktop\get get xxxxxx.txt
2015-08-11 20:30 - 2015-08-11 20:30 - 01743626 _____ C:\Users\Matts Windows7\Desktop\WP Animator.zip
2015-08-11 14:52 - 2015-08-11 14:52 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-11 09:52 - 2015-08-11 09:52 - 11534096 _____ (Intel Corporation) C:\Windows\system32\Drivers\NETwsw01.sys
2015-08-10 14:35 - 2015-08-10 14:56 - 00000000 ____D C:\Users\Matts Windows7\Desktop\BacklinkBeast_Cracked_by_Malice
2015-08-10 13:33 - 2015-08-17 15:39 - 00000000 ____D C:\Users\Matts Windows7\Desktop\ltp
2015-08-09 22:24 - 2015-08-09 22:54 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Local Client Takeover
2015-08-09 22:03 - 2015-08-11 17:32 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\UpViral and Audience Connect
2015-08-07 22:16 - 2015-08-09 22:29 - 00000338 _____ C:\Users\Matts Windows7\Desktop\open.txt
2015-08-07 10:13 - 2015-08-07 10:14 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Immersion Session 2
2015-08-06 14:14 - 2015-08-06 14:14 - 47438474 _____ C:\Users\Matts Windows7\Desktop\The 5 Secret Steps to Creating Powerful Viral Marketing Loops.mp4
2015-08-05 16:02 - 2015-08-05 16:02 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 02606080 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-08-05 16:02 - 2015-08-05 16:02 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-08-05 16:02 - 2015-08-05 16:02 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-08-05 16:02 - 2015-08-05 16:02 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-08-05 16:02 - 2015-08-05 16:02 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-08-04 20:43 - 2015-08-04 20:43 - 00000000 ____D C:\Program Files (x86)\LongTailPro
2015-08-04 16:49 - 2015-08-04 16:49 - 00000000 ____D C:\Program Files (x86)\GIGProspector
2015-08-04 15:50 - 2015-08-04 15:50 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\article.buddy.ArticleBuddy
2015-08-04 14:36 - 2015-08-04 14:36 - 00000000 ____D C:\Users\Matts Windows7\GPS
2015-08-04 14:36 - 2015-08-04 14:36 - 00000000 ____D C:\Users\Matts Windows7\Articles
2015-08-04 10:22 - 2015-08-24 12:33 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\IDM
2015-08-04 10:22 - 2015-08-04 10:22 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2015-08-04 10:22 - 2015-08-04 10:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2015-08-04 10:22 - 2015-08-04 10:22 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager
2015-08-03 15:01 - 2015-08-03 15:29 - 00000000 ____D C:\Users\Matts Windows7\Documents\Arclab Website Link Analyzer
2015-08-03 15:01 - 2015-08-03 15:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Website Link Analyzer
2015-08-03 15:01 - 2015-08-03 15:01 - 00000000 ____D C:\Program Files (x86)\Arclab
2015-08-03 15:00 - 2015-08-03 15:00 - 39724535 _____ C:\Users\Matts Windows7\Downloads\AutoresponderSetup-HD.zip
2015-08-01 15:36 - 2015-08-01 15:36 - 00000000 ____D C:\Users\Public\Documents\Red Giant
2015-08-01 15:36 - 2015-08-01 15:36 - 00000000 ____D C:\Users\Public\Documents\Knoll Software
2015-08-01 15:36 - 2015-07-02 15:25 - 00310272 _____ C:\Windows\system32\KLF_OGL_x64.dll
2015-08-01 15:30 - 2015-08-01 15:30 - 00000000 ____D C:\ProgramData\goodasnew
2015-08-01 15:28 - 2015-08-01 15:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant
2015-08-01 15:28 - 2015-08-01 15:30 - 00000000 ____D C:\Program Files (x86)\Red Giant Link
2015-08-01 15:28 - 2015-08-01 15:28 - 00003688 _____ C:\Windows\System32\Tasks\Red Giant Link
2015-08-01 15:28 - 2015-08-01 15:28 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Red Giant
2015-08-01 15:28 - 2015-08-01 15:28 - 00000000 ____D C:\ProgramData\Red Giant
2015-08-01 15:27 - 2015-08-01 15:27 - 00000000 ____D C:\Program Files (x86)\Red Giant
2015-08-01 15:23 - 2015-08-01 15:36 - 00000000 ____D C:\ProgramData\RedGiant
2015-07-31 16:27 - 2015-07-31 16:27 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\TeeSpy
2015-07-31 13:29 - 2015-07-31 13:37 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Community Chest
2015-07-30 21:28 - 2015-08-14 18:01 - 00002966 _____ C:\Windows\System32\Tasks\VIPRE Upgrade Task
2015-07-29 13:52 - 2015-07-29 14:00 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\PDFs Must Read
2015-07-28 23:22 - 2015-07-28 23:22 - 00000870 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AD RESPARK.lnk
2015-07-28 23:22 - 2015-07-28 23:22 - 00000000 ____D C:\Program Files (x86)\AD RESPARK
2015-07-28 23:21 - 2015-07-28 23:21 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\com.gorialogics.adrespark
2015-07-28 23:13 - 2015-07-28 23:13 - 00000000 ____D C:\Users\Matts Windows7\Desktop\Ad-Respark
2015-07-28 16:48 - 2015-07-28 16:48 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\RoboForm
2015-07-28 16:42 - 2015-07-28 16:42 - 00000000 ____D C:\ProgramData\RoboForm
2015-07-28 16:41 - 2015-08-20 20:16 - 00000000 ____D C:\Users\Matts Windows7\Documents\My RoboForm Data
2015-07-28 15:54 - 2015-07-29 09:19 - 00000120 _____ C:\Users\Matts Windows7\Desktop\get get.txt
2015-07-28 15:49 - 2015-07-28 15:49 - 00000910 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstaBannerAIR.lnk
2015-07-28 15:49 - 2015-07-28 15:49 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\InstaBannerAIR
2015-07-28 15:49 - 2015-07-28 15:49 - 00000000 ____D C:\Program Files (x86)\InstaBannerAIR
2015-07-28 12:45 - 2015-07-28 12:45 - 00000000 ____D C:\$Windows.~BT
2015-07-27 23:29 - 2015-07-27 23:29 - 00000969 _____ C:\Users\Matts Windows7\Desktop\IrfanView.lnk
2015-07-27 23:29 - 2015-07-27 23:29 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2015-07-27 23:29 - 2015-07-27 23:29 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\IrfanView
2015-07-27 23:29 - 2015-07-27 23:29 - 00000000 ____D C:\Program Files (x86)\IrfanView
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-25 21:19 - 2015-06-08 15:10 - 00000000 ____D C:\FRST
2015-08-25 21:09 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-25 21:09 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-25 21:05 - 2011-05-24 15:02 - 01777990 _____ C:\Windows\WindowsUpdate.log
2015-08-25 21:02 - 2012-02-22 13:17 - 00000000 ___RD C:\Users\Matts Windows7\Dropbox
2015-08-25 21:02 - 2012-02-22 13:15 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Dropbox
2015-08-25 21:01 - 2014-08-28 17:56 - 00000000 ____D C:\Users\Matts Windows7\OneDrive
2015-08-25 21:01 - 2012-09-05 13:58 - 00000000 ___RD C:\Users\Matts Windows7\Google Drive
2015-08-25 21:01 - 2012-09-05 13:57 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-25 21:01 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-25 21:00 - 2015-05-18 11:25 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-25 20:58 - 2014-11-09 16:28 - 00000944 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job
2015-08-25 20:56 - 2012-09-05 13:57 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-25 20:51 - 2015-06-04 14:38 - 00000652 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job
2015-08-25 20:44 - 2012-02-29 12:46 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\CrashDumps
2015-08-25 20:43 - 2014-03-25 20:08 - 00000556 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job
2015-08-25 16:56 - 2015-07-14 17:00 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\DMCache
2015-08-25 16:24 - 2015-06-15 21:13 - 00000954 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job
2015-08-25 16:08 - 2009-07-14 01:13 - 00786622 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-25 15:51 - 2015-07-24 19:58 - 00000000 ____D C:\zxz
2015-08-25 15:51 - 2015-07-14 17:10 - 00000000 ___RD C:\Users\Matts Windows7\Downloads\Video
2015-08-25 15:51 - 2012-01-12 15:10 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\vlc
2015-08-25 15:11 - 2015-07-08 12:16 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2015-08-25 13:26 - 2012-11-27 14:03 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Media Player Classic
2015-08-24 16:46 - 2015-02-21 00:35 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Recurring Revenue Machine
2015-08-23 21:58 - 2014-11-09 16:28 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job
2015-08-23 20:38 - 2015-06-04 14:38 - 00003710 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000
2015-08-23 20:38 - 2014-03-25 20:08 - 00003614 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000
2015-08-23 18:20 - 2015-06-15 21:13 - 00000902 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job
2015-08-22 14:18 - 2015-07-15 12:03 - 00000000 ___RD C:\Users\Matts Windows7\Downloads\Compressed
2015-08-21 17:41 - 2015-06-23 00:38 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Dons RESULTS 6-23-15
2015-08-21 15:01 - 2011-10-05 23:16 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Skype
2015-08-21 14:58 - 2011-10-05 23:16 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-08-21 14:58 - 2011-04-15 09:44 - 00000000 ____D C:\ProgramData\Skype
2015-08-21 12:33 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2015-08-21 10:22 - 2012-04-28 23:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-21 00:38 - 2015-05-26 18:20 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-20 21:21 - 2014-10-29 13:29 - 00001456 _____ C:\Users\Matts Windows7\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-08-20 12:43 - 2014-02-20 11:18 - 00002200 _____ C:\Users\Matts Windows7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-08-19 12:22 - 2012-03-14 17:51 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\TOOLs
2015-08-19 10:39 - 2015-05-12 10:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 4
2015-08-19 10:39 - 2015-03-01 03:13 - 00003212 _____ C:\Windows\System32\Tasks\ASC8_PerformanceMonitor
2015-08-19 10:39 - 2015-03-01 03:12 - 00002900 _____ C:\Windows\System32\Tasks\ASC8_SkipUac_Matts Windows7
2015-08-19 10:39 - 2015-03-01 03:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8
2015-08-19 10:38 - 2015-03-01 01:59 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\IObit
2015-08-19 10:38 - 2015-03-01 01:59 - 00000000 ____D C:\ProgramData\IObit
2015-08-19 10:38 - 2015-03-01 01:59 - 00000000 ____D C:\Program Files (x86)\IObit
2015-08-18 23:32 - 2011-07-28 11:49 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\Google
2015-08-18 18:47 - 2014-05-22 12:30 - 00000000 ____D C:\Windows\Minidump
2015-08-18 18:08 - 2014-10-29 13:06 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-08-18 18:08 - 2014-10-29 13:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-08-18 18:08 - 2012-03-13 02:10 - 00000000 ____D C:\Program Files (x86)\Java
2015-08-18 18:08 - 2011-07-28 08:45 - 00000000 ____D C:\Users\Matts Windows7
2015-08-18 08:05 - 2011-07-28 08:46 - 00442592 _____ C:\Users\Matts Windows7\AppData\Local\GDIPFONTCACHEV1.DAT
2015-08-18 08:04 - 2009-07-14 00:45 - 13680664 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-17 18:13 - 2015-06-26 16:48 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\Body by Matt Site
2015-08-17 13:33 - 2014-01-16 15:05 - 00002471 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 9 Pro Extended.lnk
2015-08-17 13:33 - 2014-01-16 15:05 - 00002465 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Distiller 9.lnk
2015-08-17 13:33 - 2014-01-16 15:05 - 00002235 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe 3D Reviewer.lnk
2015-08-17 13:33 - 2014-01-16 15:05 - 00002138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle Designer ES 8.2.lnk
2015-08-16 00:11 - 2011-07-28 11:49 - 00000000 ____D C:\Users\Matts Windows7\AppData\Local\Apps\2.0
2015-08-15 23:56 - 2009-07-13 23:20 - 00000000 __RHD C:\Users\Default
2015-08-15 23:31 - 2009-07-13 22:34 - 00000215 _____ C:\Windows\system.ini
2015-08-15 12:05 - 2009-07-14 01:08 - 00032544 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-08-15 08:54 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\Resources
2015-08-14 18:58 - 2012-09-05 13:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-08-14 15:04 - 2015-07-07 14:42 - 00000427 _____ C:\Users\Matts Windows7\Desktop\Penguin & WI-FI.txt
2015-08-13 18:39 - 2014-06-17 19:09 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\uTorrent
2015-08-13 18:39 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\registration
2015-08-13 18:19 - 2015-06-02 17:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-08-13 17:54 - 2015-05-26 18:19 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-13 13:28 - 2014-12-11 10:53 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-13 13:28 - 2014-05-07 09:41 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-12 17:34 - 2013-03-13 20:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-12 17:33 - 2013-03-13 20:05 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-12 17:33 - 2013-03-13 20:05 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-12 17:31 - 2014-06-16 19:59 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-12 17:27 - 2009-07-13 22:34 - 00000478 _____ C:\Windows\win.ini
2015-08-12 17:18 - 2013-08-15 10:46 - 00000000 ____D C:\Windows\system32\MRT
2015-08-12 17:18 - 2011-12-28 21:04 - 132483416 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-11 20:00 - 2015-05-18 11:25 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-08-11 20:00 - 2014-03-12 21:38 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-08-11 20:00 - 2014-03-12 21:38 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-10 12:38 - 2015-07-22 11:59 - 00000108 _____ C:\Users\Matts Windows7\dkKWOOj1AFxjAn8NHqWZgdFIjvrdBhZkbQ
2015-08-10 12:38 - 2015-07-20 16:33 - 00000268 _____ C:\Users\Matts Windows7\AppData\Roaming\RO39-2M3Q
2015-08-09 23:20 - 2015-02-06 17:16 - 00000000 ___RD C:\ICONS
2015-08-05 11:30 - 2012-01-17 15:00 - 00000000 ____D C:\Users\Matts Windows7\Documents\My Maps
2015-08-04 20:43 - 2015-07-22 11:58 - 00000880 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LongTailPro.lnk
2015-08-04 20:43 - 2013-04-08 12:39 - 00660720 ____H C:\Windows\SysWOW64\mlfcache.dat
2015-08-04 17:07 - 2015-01-29 15:45 - 00000222 _____ C:\Users\Matts Windows7\video2gifsett
2015-08-04 17:03 - 2015-01-29 15:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video2Gif
2015-08-04 17:03 - 2015-01-29 15:41 - 00000000 ____D C:\Program Files (x86)\ Video2Gif
2015-08-04 16:49 - 2013-05-08 12:05 - 00000900 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGProspector.lnk
2015-08-04 16:49 - 2013-05-08 12:05 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\GIGProspector
2015-08-04 16:30 - 2012-09-21 17:36 - 00000000 ____D C:\Users\Matts Windows7\AppData\Roaming\Tin Nguyen
2015-08-04 14:42 - 2014-07-25 16:21 - 00000000 ____D C:\Users\Matts Windows7\Documents\Outlook Files
2015-08-03 14:51 - 2015-01-07 17:15 - 00000132 _____ C:\Users\Matts Windows7\AppData\Roaming\Adobe PNG Format CC Prefs
2015-07-28 14:46 - 2015-06-30 01:03 - 00000000 ___RD C:\Users\Matts Windows7\Desktop\LABS
2015-07-28 12:45 - 2007-07-11 21:49 - 00000000 ____D C:\Windows\Panther
2015-07-28 00:36 - 2013-03-01 18:33 - 00000000 ____D C:\Users\Matts Windows7\Documents\Movie Studio Platinum 12.0 Projects
2015-07-28 00:34 - 2009-07-14 00:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-07-27 23:58 - 2013-03-17 09:42 - 00005632 _____ C:\Users\Matts Windows7\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-27 14:03 - 2015-07-08 12:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
2015-07-27 14:03 - 2015-07-08 12:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Exploit
2015-07-26 23:55 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\NDF
2015-07-26 13:46 - 2015-03-30 22:50 - 00000000 ___SD C:\Windows\system32\GWX
 
==================== Files in the root of some directories =======
 
2012-03-06 18:34 - 2012-03-06 18:34 - 0001005 _____ () C:\Program Files (x86)\Backlink Skyrocket.lnk
2012-03-06 18:37 - 2012-03-06 18:37 - 0000993 _____ () C:\Program Files (x86)\Traffic SkyRocket.lnk
2012-03-06 18:34 - 2012-03-06 18:34 - 0000960 _____ () C:\Program Files (x86)\Update Skyrocket.lnk
2014-08-09 01:42 - 2014-08-09 02:16 - 15000576 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2015-07-20 16:33 - 2015-07-20 16:33 - 0000088 _____ () C:\Users\Matts Windows7\AppData\Roaming\.95d691779473f3e03bc4b4e56319d74c.key
2015-03-12 18:12 - 2015-03-12 18:12 - 0000132 _____ () C:\Users\Matts Windows7\AppData\Roaming\Adobe GIF Format CC Prefs
2015-01-07 17:15 - 2015-08-03 14:51 - 0000132 _____ () C:\Users\Matts Windows7\AppData\Roaming\Adobe PNG Format CC Prefs
2012-08-01 15:02 - 2012-08-01 15:02 - 0000098 _____ () C:\Users\Matts Windows7\AppData\Roaming\netstat.bat
2015-07-20 16:33 - 2015-08-10 12:38 - 0000268 _____ () C:\Users\Matts Windows7\AppData\Roaming\RO39-2M3Q
2015-02-17 12:10 - 2015-02-17 12:19 - 0558080 _____ () C:\Users\Matts Windows7\AppData\Roaming\SharedSettings.ccs
2014-10-29 13:29 - 2015-08-20 21:21 - 0001456 _____ () C:\Users\Matts Windows7\AppData\Local\Adobe Save for Web 13.0 Prefs
2013-03-17 09:42 - 2015-07-27 23:58 - 0005632 _____ () C:\Users\Matts Windows7\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-25 15:25 - 2014-07-25 15:25 - 0004096 ____H () C:\Users\Matts Windows7\AppData\Local\keyfile3.drm
2014-09-17 17:26 - 2014-09-17 21:39 - 0000600 _____ () C:\Users\Matts Windows7\AppData\Local\PUTTY.RND
2013-05-29 13:03 - 2014-05-30 08:54 - 17977856 _____ () C:\Users\Matts Windows7\AppData\Local\ReputationCrusher.msi
2014-02-05 02:23 - 2014-11-05 10:53 - 0007597 _____ () C:\Users\Matts Windows7\AppData\Local\Resmon.ResmonCfg
2014-07-22 20:25 - 2014-07-22 20:25 - 0000003 _____ () C:\Users\Matts Windows7\AppData\Local\updater.log
2014-07-22 20:25 - 2014-11-22 18:18 - 0000455 _____ () C:\Users\Matts Windows7\AppData\Local\UserProducts.xml
2015-01-10 01:22 - 2015-01-10 01:22 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-05-15 10:57 - 2012-05-15 10:57 - 0000252 _____ () C:\ProgramData\FastPics.log
2013-07-15 17:43 - 2013-07-15 17:43 - 0000032 _____ () C:\ProgramData\Temp.log
2012-05-15 10:52 - 2012-05-15 10:52 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt
 
ZeroAccess:
C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}
C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}\@
 
Some files in TEMP:
====================
C:\Users\Matts Windows7\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpc86hzw.dll
C:\Users\Matts Windows7\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Matts Windows7\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-08-24 11:23
 
==================== End of FRST.txt ============================
 
ADDITION
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:25-08-2015 02
Ran by [removed] (2015-08-25 21:20:26)
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3123964009-4157677460-2703354282-500 - Administrator - Disabled)
Guest (S-1-5-21-3123964009-4157677460-2703354282-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3123964009-4157677460-2703354282-1004 - Limited - Enabled)
Matts Windows7 (S-1-5-21-3123964009-4157677460-2703354282-1000 - Administrator - Enabled) => C:\Users\Matts Windows7
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: ThreatTrack Security VIPRE (Enabled - Up to date) {FFE93D16-FD09-0282-C7D3-8B1731B6A051}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ThreatTrack Security VIPRE (Enabled - Up to date) {4488DCF2-DB33-0D0C-FD63-B0654A31EAEC}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\uTorrent) (Version: 3.4.2.31743 - BitTorrent Inc.)
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
AD RESPARK (HKLM-x32\…\com.gorialogics.adrespark) (Version: 1.2 - Your Marketing Tech Support, LLC)
AD RESPARK (x32 Version: 1.2 - Your Marketing Tech Support, LLC) Hidden
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch (HKLM-x32\…\{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}) (Version: 9.0.0 - Adobe Systems)
Adobe Acrobat 9 Pro Extended 64-bit Add-On (HKLM\…\{AC76BA86-1033-0000-0064-0003D0000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Adobe After Effects CS6 (HKLM-x32\…\{4817D846-700B-474E-A31B-80892B3E92E3}) (Version: 11 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated)
Adobe Anchor Service x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe CMaps x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe CSI CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe Drive CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 18 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Fonts All x64 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Illustrator CS5 (HKLM-x32\…\{9B97EC91-B3FD-4BFF-88FC-5345A26AC2E7}) (Version: 15.0 - Adobe Systems Incorporated)
Adobe Linguistics CS4 x64 (Version: 4.0.0 - Adobe Systems Incorporated) Hidden
Adobe Media Player (HKLM-x32\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
Adobe PDF Library Files x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CC (HKLM-x32\…\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated)
Adobe Photoshop CS4 (64 Bit) (Version: 11.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS4 (HKLM-x32\…\Adobe_faf656ef605427ee2f42989c3ad31b8) (Version: 11.0 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Adobe Type Support x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe WinSoft Linguistics Plugin x64 (Version: 1.1 - Adobe Systems Incorporated) Hidden
Advanced SystemCare 8 (HKLM-x32\…\Advanced SystemCare 8_is1) (Version: 8.3.0 - IObit)
AliG Social Lead Freak (HKLM-x32\…\com.aligmarketing.slf) (Version: 2.4.0 - Ali M. Gadit)
AliG Social Lead Freak (x32 Version: 2.4.0 - Ali M. Gadit) Hidden
Any Video Converter 5 5.0.3 (HKLM-x32\…\Any Video Converter 5_is1) (Version:  - Any-Video-Converter.com)
Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Arclab Website Link Analyzer 1.21 (HKLM-x32\…\Arclab Website Link Analyzer_is1) (Version: 1.21 - Arclab Software GbR)
Audacity 1.2.6 (HKLM-x32\…\Audacity_is1) (Version:  - )
AVCHD To MP4 Converter 1.0 (HKLM-x32\…\AVCHD To MP4 Converter) (Version: 1.0 - Mark Dulisse)
Backlink SkyRocket (HKLM-x32\…\{DA043E6D-2724-4894-8DD7-AC9020193663}) (Version: 1.4.8 - Backlink SkyRocket)
Backup Manager V3 (x32 Version: 3.0.0.100 - NTI Corporation) Hidden
BleuPage (HKLM-x32\…\{FE65FBDB-48D5-4145-8E24-3775F872F3E7}) (Version: 1.3.307 - BleuPage Software)
BlueStacks App Player (HKLM-x32\…\BlueStacks App Player) (Version: 0.8.7.3069 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\…\{FE5ABB0E-EDEA-4023-B0FB-9DEA39A98D76}) (Version: 0.8.7.3069 - BlueStack Systems, Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom Card Reader Driver Installer (HKLM\…\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 14.6.1.2 - Broadcom Corporation)
Broadcom Gigabit NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.6.1.2 - Broadcom Corporation)
Camtasia Studio 7 (HKLM-x32\…\{C0E8FE43-C35B-451D-B35F-D4BD056D70E7}) (Version: 7.1.1 - TechSmith Corporation)
CarMD (HKLM-x32\…\{7E213637-F640-4599-A8B3-5269BA7D66D3}) (Version: 4.0.120 - carmd.com)
Cisco WebEx Meetings (HKLM-x32\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Citrix Online Launcher (HKLM-x32\…\{DB014C85-A264-4BCA-A66F-6DD1FCF8EC36}) (Version: 1.0.335 - Citrix)
Citrix Receiver (HKLM-x32\…\CitrixOnlinePluginPackWeb) (Version: 13.1.201.3 - Citrix Systems, Inc.)
Commission Heist (HKLM-x32\…\commheist) (Version: 1.0.2 - Memberspeed Inc)
Commission Heist (x32 Version: 1.0.2 - Memberspeed Inc) Hidden
Conference Recording Service (HKLM-x32\…\{B293F0E6-10B7-45FD-BACF-18826515C246}_is1) (Version:  - GVO, Inc.)
Connect (x32 Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
CT4L (HKLM-x32\…\CT4L) (Version: 1.4.1 - UNKNOWN)
CT4L (x32 Version: 1.4.1 - UNKNOWN) Hidden
CyberLink MediaEspresso (HKLM-x32\…\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.0.1027_32100 - CyberLink Corp.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.2531.52 - CyberLink Corp.)
CyberSpy Intel Station  (HKLM-x32\…\{005DE34D-CE86-4C74-9B31-8C6D2E10ABBD}) (Version: 1.0.0 - Dean Sueck - CyberSpyIntelStation.com)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deals Flow (HKLM-x32\…\DealsFlow) (Version: 1.0.0 - UNKNOWN)
Deals Flow (x32 Version: 1.0.0 - UNKNOWN) Hidden
Digi Traffic Accelerator (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\27e1819d71203503) (Version: 1.1.9.119 - DigiResults)
Domain Security PRO 1.0 (HKLM-x32\…\Domain Security PRO) (Version: 1.0 - Mark Dulisse)
Driver Booster 2.4 (HKLM-x32\…\Driver Booster_is1) (Version: 2.4 - IObit)
Dropbox (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Dropbox) (Version: 3.8.6 - Dropbox, Inc.)
DVD Architect Studio 5.0 (HKLM-x32\…\{42C509F1-C451-11E1-AEC9-F04DA23A5C58}) (Version: 5.0.161 - Sony)
EasySketchPro version 2.0.0 (HKLM-x32\…\{90BB7D95-EBCA-4276-B15E-156F85E8B1DA}_is1) (Version: 2.0.0 - Inner Cirle Riches)
EasyVSL (HKLM-x32\…\com.searchcreatively.EasyVSL) (Version: 1.0.5 - Digital Kickstart)
EasyVSL (x32 Version: 1.0.5 - Digital Kickstart) Hidden
Effects Suite v11.1.6 (HKLM-x32\…\{4DD8EE5E-F571-4EC8-9526-E7C62FE39B19}_is1) (Version: 11.1.6 - Red Giant, LLC)
FB Ad Express (HKLM-x32\…\com.pageone.FBads) (Version: 1.2 - Jai Ganesh Venkateswaran)
FB Ad Express (x32 Version: 1.2 - Jai Ganesh Venkateswaran) Hidden
FileZilla Client 3.5.3 (HKLM-x32\…\FileZilla Client) (Version: 3.5.3 - FileZilla Project)
Flip PDF (HKLM-x32\…\Flip PDF_is1) (Version:  - FlipBuilder Solution)
FreshKey (HKLM-x32\…\com.digitalmarketer.FreshKey) (Version: 1.5.4 - Idea Incubator LP)
FreshKey (x32 Version: 1.5.4 - Idea Incubator LP) Hidden
FunnelCreator (HKLM-x32\…\FunnelCreator) (Version: 1.0 - UNKNOWN)
FunnelCreator (x32 Version: 1.0 - UNKNOWN) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gateway MyBackup (HKLM-x32\…\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.100 - NTI Corporation)
Gateway Power Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Gateway Incorporated)
Gateway Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Gateway Incorporated)
Gateway Registration (HKLM-x32\…\Gateway Registration) (Version: 1.03.3004 - Gateway Incorporated)
Gateway ScreenSaver (HKLM-x32\…\Gateway Screensaver) (Version: 1.1.1022.2010 - Gateway Incorporated)
Gateway Social Networks (HKLM-x32\…\InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}) (Version: 2.0.3315 - CyberLink Corp.)
Gateway Social Networks (x32 Version: 2.0.3315 - CyberLink Corp.) Hidden
GIG Prospector (HKLM-x32\…\GIGProspector) (Version: 2.0.8 - UNKNOWN)
GIG Prospector (x32 Version: 2.0.8 - UNKNOWN) Hidden
Google AdWords Editor (HKLM-x32\…\{14069A87-872C-41E6-9D36-B1BE3870C35A}) (Version: 10.6.0 - Google)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 44.0.2403.157 - Google Inc.)
Google Drive (HKLM-x32\…\{12ADFB82-D5A3-43E4-B2F4-FCD9B690315B}) (Version: 1.24.9931.5480 - Google, Inc.)
Google Talk Plugin (HKLM-x32\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
GoToMeeting 7.2.4.3277 (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\GoToMeeting) (Version: 7.2.4.3277 - CitrixOnline)
HandBrake 0.9.9.1 (HKLM-x32\…\HandBrake) (Version: 0.9.9.1 - )
HD Video Converter Factory Pro 9.2 (HKLM-x32\…\HD Video Converter Factory Pro) (Version: 9.2 - WonderFox Soft, Inc.)
HomeMedia (HKLM-x32\…\{AA4BF92B-2AAF-11DA-9D78-000129760D75}) (Version: 2.0.8520 - CyberLink Corporation)
HP ENVY 4500 series Basic Device Software (HKLM\…\{6915424E-704F-4F5D-9057-9C7B406B36DB}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
iCloud (HKLM\…\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3006 - Gateway Incorporated)
iExplorer [removed] (HKLM-x32\…\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant LLC)
InstaBannerAIR (HKLM-x32\…\InstaBannerAIR) (Version: 1.1 - JHS Marketing LLC)
InstaBannerAIR (x32 Version: 1.1 - JHS Marketing LLC) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\…\{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}) (Version: 14.00.1000 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel(R) Wireless Display (HKLM-x32\…\{626663EE-B9E6-4982-995F-02C31E84F8FC}) (Version: 2.0.29.0 - Intel Corporation)
Internet Download Manager (HKLM-x32\…\Internet Download Manager) (Version:  - Tonec Inc.)
IObit Malware Fighter 3 (HKLM-x32\…\IObit Malware Fighter_is1) (Version: 3.1 - IObit)
IObit Uninstaller (HKLM-x32\…\IObitUninstall) (Version: 4.3.0.5 - IObit)
IrfanView (remove only) (HKLM-x32\…\IrfanView) (Version: 4.38 - Irfan Skiljan)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\…\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 51 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
Java 8 Update 60 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\…\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Jing (HKLM-x32\…\{22800204-9E53-45C7-B6F3-5BB0F1C1A147}) (Version: 2.8.13007.1 - TechSmith Corporation)
Juicer 3.90 (HKLM-x32\…\{640EAE56-81A2-49D4-9B8C-00DA3C0031AF}_is1) (Version:  - Digital Juice, Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Keyword Scout (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\6611abf67fa612f7) (Version: 1.0.1.55 - Josh MacDonald)
K-Lite Codec Pack 9.5.0 (Full) (HKLM-x32\…\KLiteCodecPack_is1) (Version: 9.5.0 - )
KompoZer 0.8b3 (HKLM-x32\…\{20aa4150-b5f4-11de-8a39-0800200c9a66}_is1) (Version:  - KompoZer)
kuler (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
LastPass (uninstall only) (HKLM-x32\…\LastPass) (Version:  - LastPass)
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.4 - Gateway)
Lexmark 5600-6600 Series (HKLM\…\Lexmark 5600-6600 Series) (Version:  - Lexmark International, Inc.)
Lexmark Printable Web (HKLM-x32\…\{D2C5E510-BE6D-42CC-9F61-E4F939078474}) (Version: 1.0.0.0 - )
Livedrive (HKLM\…\{7D2E0E90-3BBA-43B1-894D-EC39A4E18748}) (Version: 1.15.2.0 - Livedrive Internet Limited)
Local Lead Igniter (HKLM-x32\…\Service.Magic.Scrapper) (Version: 0.0.0 - UNKNOWN)
Local Lead Igniter (x32 Version: 0.0.0 - UNKNOWN) Hidden
Local Niche Spy (HKLM-x32\…\Niche) (Version: 2.1.4 - UNKNOWN)
Local Niche Spy (x32 Version: 2.1.4 - UNKNOWN) Hidden
Local Traffic Tool (HKLM-x32\…\{BAF1E625-29F3-4144-8686-4C89543C73D7}) (Version: 1.1.6 - Offline Inner Circle)
Localizer Leads Tool (HKLM-x32\…\LocalizerLeadsTool) (Version: 3.5.4 - Viper Consulting, LLC)
Localizer Leads Tool (x32 Version: 3.5.4 - Viper Consulting, LLC) Hidden
LongTailPro - Version 3.0.13 (HKLM-x32\…\com.longtailpro.LongTailPro) (Version: 3.0.13 - Long Tail Media, LLC)
LongTailPro - Version 3.0.13 (x32 Version: 3.0.13 - Long Tail Media, LLC) Hidden
Malwarebytes Anti-Exploit version 1.07.1.1015 (HKLM\…\Malwarebytes Anti-Exploit_is1) (Version: 1.07.1.1015 - Malwarebytes)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
MetaFrame Presentation Server Web Client for Win32 (HKLM\…\Citrix ICA Web Client) (Version:  - )
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\OneDriveSetup.exe) (Version: 17.3.5930.0814 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\…\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\…\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mindjet MindManager 2012 (HKLM-x32\…\{4E973CA9-5674-4FB4-8D83-3D8C5EB44AB3}) (Version: 10.0.445 - Mindjet)
Movie Studio Platinum 12.0 (64-bit) (HKLM\…\{FE052581-1CD8-11E2-B617-F04DA23A5C58}) (Version: 12.0.576 - Sony)
Mozilla Firefox 40.0.2 (x86 en-GB) (HKLM-x32\…\Mozilla Firefox 40.0.2 (x86 en-GB)) (Version: 40.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 40.0.2.5702 - Mozilla)
Mp3tag v2.65a (HKLM-x32\…\Mp3tag) (Version: v2.65a - Florian Heidenreich)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MySpeed v5.4.5 (HKLM-x32\…\{C3F2AE48-FEEB-4697-BFCE-FB9B17289A7F}) (Version: 5.04.0413 - Enounce Incorporated)
Nero DiscSpeed 10 (HKLM-x32\…\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG)
Nero Express 10 (HKLM-x32\…\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12000.21.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.5.10300 - Nero AG)
Nero StartSmart 10 (HKLM-x32\…\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
Nero Update (HKLM-x32\…\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
NOOK for PC (HKLM-x32\…\BN_DesktopReader) (Version: 2.5.1.237 - Barnesandnoble.com)
Notepad++ (HKLM-x32\…\Notepad++) (Version: 6.4.2 - Notepad++ Team)
Online Plug-in (x32 Version: 13.1.201.3 - Citrix Systems, Inc.) Hidden
PandoraRecovery (Remove Only) (HKLM-x32\…\PandoraRecovery) (Version:  - )
PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden
PDF Settings CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
PDF-XChange 3 (HKLM\…\PDF-XChange 3_is1) (Version:  - Tracker Software)
Perfectly Clear Plugin 1.6.0 (HKLM-x32\…\Perfectly Clear Plugin) (Version: 1.6.0 - Athentech)
Photoshop Camera Raw (x32 Version: 5.0 - Adobe Systems Incorporated) Hidden
Photoshop Camera Raw_x64 (Version: 5.0 - Adobe Systems Incorporated) Hidden
Places Scout (HKLM-x32\…\{AA880B13-717B-46C6-B9F4-E38974D56881}) (Version: 2.2.0 - Automated Keyword Research, LLC)
PPTX Viewer 2.0 (HKLM-x32\…\PPTX Viewer 2.0) (Version:  - )
Proxy Goblin (HKLM-x32\…\{B77A5236-16DB-4DE5-B0CE-2E3F0B52C321}) (Version: 2.1.3 - Molura)
Publishers Review Accelerator (HKLM-x32\…\{95008B02-4CBD-4352-8180-56C414CBBCD1}) (Version: 1.1.65 - Scoritz)
Qilio (HKLM-x32\…\com.jayvenka.qilio) (Version: 1.0.7 - Jai Ganesh Venkateswaran)
Qilio (x32 Version: 1.0.7 - Jai Ganesh Venkateswaran) Hidden
QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RAPID Mode (Version: 1.0.1.81 - Samsung Electronics Co., Ltd.) Hidden
Real Hide IP (HKLM-x32\…\RealHideIP) (Version: 4.2.5.2 - )
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6329 - Realtek Semiconductor Corp.)
Red Giant Link (HKLM-x32\…\{10F82E5B-B611-4C65-8F29-666A9EC5680A}_is1) (Version: 1.9.6.0 - Red Giant, LLC)
Reflector (HKLM\…\{77342B24-A2A9-4420-8C9C-C109EE201CBC}) (Version: 1.3.3.1 - Squirrels)
Reputation Crusher (HKLM-x32\…\{FA0EFEF1-212F-45CC-9651-AACB66F75F8B}) (Version: 1.0.55 - MJISolutions)
Revo Uninstaller Pro 2.1.1 (HKLM\…\{FB562550-BBE6-4298-861A-5C0A6562C272}_is1) (Version:  - ;-))
S3 Ripper 2.0 (HKLM-x32\…\{AB3D78B7-8066-465A-82A8-5F3751564457}_is1) (Version:  - )
Samsung Data Migration (HKLM-x32\…\{D4DE3DB4-7734-47E5-8D92-B80146311406}) (Version: 2.7 - Samsung)
Samsung Magician (HKLM-x32\…\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.5.1 - Samsung Electronics)
Samsung Universal Print Driver 2 (HKLM-x32\…\Samsung Universal Print Driver 2) (Version: 2.50.02.00 - Samsung Electronics Co., Ltd.)
Scale Factor Social Leads Tool (HKLM-x32\…\FacebookLeads) (Version: 0.0.0 - UNKNOWN)
Scale Factor Social Leads Tool (x32 Version: 0.0.0 - UNKNOWN) Hidden
Self-service Plug-in (x32 Version: 3.2.0.24226 - Citrix Systems, Inc.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Click to Call (HKLM-x32\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.9.12585 - Skype Technologies S.A.)
Skype™ 7.8 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
Smart Defrag 4 (HKLM-x32\…\Smart Defrag 4_is1) (Version: 4.1 - IObit)
Snagit 12 (HKLM-x32\…\{588591F5-74D7-4646-87C5-6A07E526F303}) (Version: 12.3.2 - TechSmith Corporation)
SocialMultiplier (HKLM-x32\…\SocialMultiplier) (Version:  - )
Sound Forge Audio Studio 10.0 (HKLM-x32\…\{7A263871-BEEC-11E1-AC53-F04DA23A5C58}) (Version: 10.0.178 - Sony)
Sparkol VideoScribe (HKLM-x32\…\Sparkol VideoScribe 1.3.18) (Version: 1.3.18 - Sparkol)
Sparkol VideoScribe (x32 Version: 1.3.18 - Sparkol) Hidden
Splashtop Software Updater (HKLM-x32\…\Splashtop Software Updater) (Version: 1.5.6.15 - Splashtop Inc.)
Splashtop Streamer (HKLM-x32\…\{B7C5EA94-B96A-41F5-BE95-25D78B486678}) (Version: 2.6.2.4 - Splashtop Inc.)
SplitCam (HKLM-x32\…\SplitCam) (Version: 6.9.4.1 - SplitCam Co)
Suite Shared Configuration CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
Surfing Protection (HKLM-x32\…\IObit Surfing Protection_is1) (Version: 1.2 - IObit)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.1.6.0 - Synaptics Incorporated)
System Requirements Lab for Intel (HKLM-x32\…\{1EBDF6D2-CEA0-484C-A23E-2DDAD7FD0DD0}) (Version: 4.5.22.0 - Husdawg, LLC)
Target Generator (HKLM-x32\…\Target Generator1.0.0.3) (Version: 1.0.0.3 - AppBreed Software of InnAnTech Industries Inc.)
TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
Tee Inspector (HKLM-x32\…\Tee Inspector1.0.0.6) (Version: 1.0.0.6 - AppBreed Software of InnAnTech Industries Inc.)
The Logo Creator v6.6 (HKLM-x32\…\The Logo Creator) (Version: v6.6 - Laughingbird Software)
Times Reader (HKLM-x32\…\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1) (Version: 2.055 - The New York Times Company)
Times Reader (x32 Version: 2.055 - The New York Times Company) Hidden
Traffic SkyRocket (HKLM-x32\…\{1F0D32B8-B187-4295-A02C-CF5468F8E16F}) (Version: 1.0.0 - Traffic SkyRocket)
Traffic Travis 4.2.0 (HKLM-x32\…\Traffic Travis 4.2 Setup Wizard_is1) (Version:  - Affilorama Ltd.)
Trapcode Suite v12.1.9 (HKLM-x32\…\{DFD2DC6B-C634-4C1C-81CC-5EF852E71CEE}_is1) (Version: 12.1.9 - Red Giant, LLC)
Tube Maker PRO 1.0 (HKLM-x32\…\Tube Maker PRO) (Version: 1.0 - Mark Dulisse)
UberQast (HKLM-x32\…\com.web1-syndication-inc.uberqast) (Version: 3.0.0.8 - Web1 Syndication, Inc.)
UberQast (x32 Version: 3.0.0 - Web1 Syndication, Inc.) Hidden
URLShotgunPro (HKLM-x32\…\URLShotgunPro) (Version: 1.0.1 - UNKNOWN)
URLShotgunPro (x32 Version: 1.0.1 - UNKNOWN) Hidden
Viber (HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\Viber) (Version: 4.4.0.134678 - Viber Media Inc)
Video Marketer (HKLM-x32\…\com.immortal-marketing.video-marketer) (Version: 3.0.0.4 - UNKNOWN)
Video Marketer (x32 Version: 3.0.0 - UNKNOWN) Hidden
Video Web Camera (HKLM-x32\…\InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}) (Version: 1.5.3018.00 - CyberLink Corp.)
Video Web Camera (x32 Version: 1.5.3018.00 - CyberLink Corp.) Hidden
Video2Gif version 1.0 (HKLM-x32\…\{FA80C47D-C9F1-482E-8D3C-69490CADCA3A}_is1) (Version: 1.0 - Mark Dulisse)
VideoMakerFX (HKLM-x32\…\VideoMakerFX 1.01) (Version: 1.01 - Webvati)
VideoMakerFX (x32 Version: 1.01 - Webvati) Hidden
VideoMakerFX Josh Ratta Bonus Scenes (HKLM-x32\…\{E7CAFBCF-1A20-4AF8-AE0E-89A8282CCA46}) (Version: 1.0 - Webvati)
VideoMakerFX ProThemes May Addon 1.0 (HKLM-x32\…\{6073BA7B-671F-4F41-AA93-05164AAE6A72}) (Version: 1.0 - Webvati)
VideoMakerFX VideoProfitFX Add On 1.0 (HKLM-x32\…\{8F99303E-4E46-45DC-964D-649DBC72B717}) (Version: 1.0 - Webvati)
VidNeos (HKLM-x32\…\VidNeos) (Version: 1.1.0 - UNKNOWN)
VidNeos (x32 Version: 1.1.0 - UNKNOWN) Hidden
Viewlio (HKLM-x32\…\groinup.outsourcing.youtubetool) (Version: 1.2.4 - Web1 Syndication, Inc.)
Viewlio (x32 Version: 1.2.4 - Web1 Syndication, Inc.) Hidden
VIPRE Antivirus (HKLM-x32\…\{C1D1FC57-3EB9-4B21-BCA3-F1C927508200}) (Version: 7.0.6.2 - ThreatTrack Security, Inc.)
VIPRE Antivirus (x32 Version: 7.0.6.2 - ThreatTrack Security, Inc.) Hidden
Viral Image Curator Pro (HKLM-x32\…\com.webdimensions.viralimagecuratorpro) (Version: 1.3.6 - Web Dimensions, Inc.)
Viral Image Curator Pro (x32 Version: 1.3.6 - Web Dimensions, Inc.) Hidden
VLC media player 2.1.3 (HKLM-x32\…\VLC media player) (Version: 2.1.3 - VideoLAN)
Website Submitter 5.0.0.0 (HKLM-x32\…\{1CED286D-B45F-46BB-8EF4-73924C0FC970}_is1) (Version: 5.0.0.0 - Fastlink2)
Welcome Center (HKLM-x32\…\Gateway Welcome Center) (Version: 1.02.3102 - Gateway Incorporated)
Whistle (HKLM-x32\…\{28992A1F-DFD4-4CA2-9F8D-8D8294FF6D2A}) (Version: 1.30.0 - Vail Systems)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\…\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinHTTrack Website Copier 3.47-27 (x64) (HKLM\…\WinHTTrack Website Copier_is1) (Version: 3.47.27 - HTTrack)
WinZip 19.0 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E5}) (Version: 19.0.11293 - WinZip Computing, S.L. )
x264vfw - H.264/MPEG-4 AVC codec for x64 (remove only) (HKLM-x32\…\x264vfw64) (Version:  - )
XAMPP (HKLM-x32\…\xampp) (Version: 1.8.3-3 - Bitnami)
XMedia Recode version 3.1.7.7 (HKLM-x32\…\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.7.7 - XMedia Recode)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Program Files (x86)\Citrix\GoToMeeting\3215\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
 
==================== Restore Points =========================
 
16-08-2015 18:40:38 Windows Update
18-08-2015 14:28:49 tring to fix virus issues
18-08-2015 23:23:08 JRT Pre-Junkware Removal
19-08-2015 09:52:48 Windows Update
19-08-2015 12:10:04 getting ready install flipbook
20-08-2015 20:15:31 Revo Uninstaller Pro's restore point - RoboForm 7-9-14-4 (All Users)
21-08-2015 10:36:32 Windows Modules Installer
21-08-2015 10:37:01 Windows Modules Installer
22-08-2015 14:24:57 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2015-08-19 00:53 - 00001721 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost wordpress wordpress1 wordpress2 wordpress3 wordpress4 wordpress5 wordpress6 wordpress7 wordpress8 wordpress9 wordpress10 wordpress351 wpsim
127.0.0.1 127.0.0.1
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 192.150.18.108
127.0.0.1 localhost
127.0.0.1 127.0.0.1
127.0.0.1 www.iobit.com
127.0.0.1 www.asc55.iobit.com
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {161F3F57-9F98-43C2-B884-2A81E14F61AC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-05] (Google Inc.)
Task: {1F29DAE0-568A-437D-9554-8275E9E9FEA3} - System32\Tasks\UALU notificatin => C:\Program Files\Gateway\Gateway Updater\UALU.exe [2012-04-05] (Acer Incorporated)
Task: {2CF826FF-E640-4DFE-9D78-F1FE65BF3FB4} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2015-07-06] (IObit)
Task: {3CC188A7-21DD-45C8-964E-5A9D8FEEB151} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2015-07-06] (IObit)
Task: {46BA7249-9A2D-4755-B3BF-D8FFECA438D3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-05] (Google Inc.)
Task: {49900C2D-E815-4512-9241-8698E003D042} - System32\Tasks\Driver Booster SkipUAC (Matts Windows7) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-07-06] (IObit)
Task: {69F236FF-8599-44E1-A0AB-34E5286215C5} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {7934C737-3A92-4B0E-BB0B-7E304159238D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.)
Task: {7DDAFE9A-CC40-44B2-B562-DDB58FA2567C} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2014-09-28] (Samsung Electronics.)
Task: {80C87536-2BAB-4555-9C59-3FA49D1BD921} - System32\Tasks\ASC8_SkipUac_Matts Windows7 => C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe [2015-06-16] (IObit)
Task: {869692B0-2CDB-4756-9DDC-F74346E9D169} - System32\Tasks\VIPRE Upgrade Task => C:\PROGRAM FILES\COMMON FILES\AV\ThreatTrack Security VIPRE\Upgrade.exe [2015-08-14] (ThreatTrack Security Inc.)
Task: {A3CB1314-4DD3-4302-B458-92521C31A2D7} - System32\Tasks\Red Giant Link => C:\Program Files\Red Giant Link\Red Giant Link.exe
Task: {A928F8E9-245A-4C2A-BFD6-F0AFFE2B9917} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [2014-07-31] (TechSmith Corporation)
Task: {B45970EE-97A8-42D1-AFDD-C3BD69ED555A} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-15] (Dropbox, Inc.)
Task: {BAC008BE-218A-4A3B-B62F-F98C5400417A} - System32\Tasks\{E39722CC-5D81-4343-B049-24D4F71AE85D} => pcalua.exe -a "C:\Users\Matts Windows7\Desktop\setup-vipre-antivirus-en-us.exe" -d "C:\Users\Matts Windows7\Desktop"
Task: {C357B3D3-AF14-4CB0-AB4F-2EE436C91C29} - System32\Tasks\{1B26D4F7-75D2-485B-9BF1-94FB95852338} => pcalua.exe -a "C:\Users\Matts Windows7\Downloads\AdobeAIRInstaller.exe" -d "C:\Users\Matts Windows7\Downloads"
Task: {C4F4B161-73B2-41D8-A682-14066D75837D} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {C5F03AB6-FD0E-4A0F-9769-A019C85CB428} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-11] (Adobe Systems Incorporated)
Task: {C625DEDC-C9CE-4B79-A715-3A4139B80A29} - System32\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000 => C:\Program Files (x86)\Citrix\GoToMeeting\3277\g2mupdate.exe [2015-08-23] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {CAD45FFC-33CD-4837-8900-F21AE2963F4B} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2010-10-28] (CyberLink)
Task: {CC2A8EF4-1C90-42B9-AE0F-ED1EF3C3AD45} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 5600-6600 Series\ezprint.exe [2010-02-04] (Lexmark International Inc.)
Task: {E748E5A1-5EDD-449E-A967-BC710282DFE0} - System32\Tasks\SmartDefrag4_Update => C:\Program Files (x86)\IObit\Smart Defrag 4\AutoUpdate.exe [2015-03-03] (IObit)
Task: {EBD3BDDE-BEC3-4AD2-96D8-A670EBA0BBA0} - System32\Tasks\ASC8_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe [2015-06-10] (IObit)
Task: {EECFEE42-EBAC-4406-AC22-7489A88F608A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-19] (Google Inc.)
Task: {F0776AAB-951D-40B0-A8C9-79E862C96B19} - System32\Tasks\Uninstaller_SkipUac_Matts_Windows7 => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-05-20] (IObit)
Task: {FECDB8C5-87F5-48EC-AF70-57B2B76198D2} - System32\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000 => C:\Program Files (x86)\Citrix\GoToMeeting\3277\g2mupload.exe [2015-08-23] (Citrix Online, a division of Citrix Systems, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job => C:\Users\Matts Windows7\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job => C:\Program Files (x86)\Citrix\GoToMeeting\3277\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-3123964009-4157677460-2703354282-1000.job => C:\Program Files (x86)\Citrix\GoToMeeting\3277\g2mupload.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000Core.job => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3123964009-4157677460-2703354282-1000UA.job => C:\Users\Matts Windows7\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2010-12-17 16:53 - 2010-12-17 16:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2013-04-06 14:27 - 2011-04-11 01:26 - 00034304 _____ () C:\Windows\System32\spe__l.dll
2011-06-22 10:44 - 2011-06-22 10:44 - 00034304 _____ () C:\Windows\System32\sst2cl6.dll
2012-05-15 10:58 - 2009-10-16 12:07 - 00186880 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdudrpp.dll
2015-02-13 05:20 - 2015-02-13 05:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-02-13 05:20 - 2015-02-13 05:20 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-07-24 16:05 - 2014-07-24 16:05 - 00210584 _____ () C:\Program Files (x86)\Livedrive\VSSService.exe
2013-04-06 14:27 - 2013-03-18 10:16 - 01353728 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\spe__du.dll
2011-06-22 10:43 - 2011-06-22 10:43 - 00826880 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\sst2cdu.dll
2012-05-15 10:57 - 2009-10-16 12:03 - 01401856 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxduptpc.dll
2012-05-15 10:57 - 2009-10-16 12:07 - 00196608 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxdudrui.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2010-01-02 10:42 - 2010-01-02 10:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2012-06-18 11:24 - 2012-06-18 11:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll
2010-12-17 16:53 - 2010-12-17 16:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-04-15 10:16 - 2011-03-25 20:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-03-01 03:12 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\sqlite3.dll
2015-03-01 02:31 - 2015-01-09 18:46 - 00517408 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\sqlite3.dll
2012-01-05 15:22 - 2012-01-05 15:22 - 00465344 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\sqlite3.dll
2012-01-05 15:22 - 2012-01-05 15:22 - 01081368 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\ACE.dll
2012-01-05 15:22 - 2012-01-05 15:22 - 00125464 _____ () C:\Program Files (x86)\NTI\Gateway MyBackup\MailConverter32.dll
2012-02-20 23:26 - 2012-02-20 23:26 - 00160768 _____ () C:\Program Files (x86)\VIPRE\unrar.dll
2015-03-01 03:12 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madExcept_.bpl
2015-03-01 03:12 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madBasic_.bpl
2015-03-01 03:12 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madDisAsm_.bpl
2015-02-13 05:20 - 2015-02-13 05:20 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2015-08-25 21:01 - 2015-08-25 21:01 - 00071168 _____ () c:\Users\Matts Windows7\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpc86hzw.dll
2015-03-04 17:45 - 2015-08-05 16:49 - 00012800 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll
2015-03-04 17:45 - 2015-08-05 16:49 - 00779776 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-07-30 21:28 - 2015-08-05 16:49 - 00056320 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-03-04 17:45 - 2015-08-05 16:49 - 00012288 _____ () C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll
2015-08-25 21:01 - 2015-08-25 21:01 - 00098816 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32api.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00110080 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\pywintypes27.dll
2015-08-25 21:01 - 2015-08-25 21:01 - 00364544 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\pythoncom27.dll
2015-08-25 21:01 - 2015-08-25 21:01 - 00045568 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_socket.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 01161216 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_ssl.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00320512 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32com.shell.shell.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00713216 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_hashlib.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 01176576 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._core_.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00806400 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._gdi_.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00816128 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._windows_.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 01067008 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._controls_.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00733184 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._misc_.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00682496 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\pysqlite2._sqlite.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00087552 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_ctypes.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00119808 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32file.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00108544 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32security.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00007168 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\hashobjs_ext.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00068096 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\usb_ext.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00167936 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32gui.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00018432 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32event.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00128512 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_elementtree.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00127488 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\pyexpat.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00013824 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\common.time34.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00036864 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_psutil_windows.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00038912 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32inet.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00011264 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32crypt.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00077312 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._html2.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00027136 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_multiprocessing.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00020480 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\_yappi.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00035840 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32process.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00686080 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\unicodedata.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00123392 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._wizard.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00024064 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32pipe.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00010240 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\select.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00025600 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32pdh.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00525640 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\windows._lib_cacheinvalidation.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00017408 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32profile.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00022528 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\win32ts.pyd
2015-08-25 21:01 - 2015-08-25 21:01 - 00078848 _____ () C:\Users\Matts Windows7\AppData\Local\Temp\_MEI42762\wx._animate.pyd
2014-02-06 14:09 - 2015-06-26 03:13 - 00184184 _____ () C:\Program Files (x86)\VIPRE\Definitions\libBase64.dll
2014-02-06 14:09 - 2015-06-26 03:13 - 00175992 _____ () C:\Program Files (x86)\VIPRE\Definitions\libMachoUniv.dll
2015-03-11 23:12 - 2014-09-28 17:59 - 00019872 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAMSUNG_SSD.dll
2015-03-01 03:12 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl
2015-03-01 03:12 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
2015-03-01 03:12 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
2014-10-17 12:26 - 2014-10-17 12:26 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\ba8588c3319d63350220ec2ac3eb2c36\IsdiInterop.ni.dll
2011-04-15 09:31 - 2010-09-13 21:28 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2012-01-08 09:41 - 2012-01-08 09:41 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2015-08-20 14:17 - 2015-08-18 01:23 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libglesv2.dll
2015-08-20 14:17 - 2015-08-18 01:23 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Windows:nlsPreferences
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBPIMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AmmyyAdmin => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\atashost => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBAMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBPIMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SplashtopRemoteService => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\aphelionasp.net -> aphelionasp.net
IE trusted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\webex.com -> hxxps://fiserventerprise.webex.com
 
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\…\100sexlinks.com -> 100sexlinks.com
 
There are 4789 more restricted sites.
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3123964009-4157677460-2703354282-1000\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: AmmyyAdmin => 2
MSCONFIG\Services: atashost => 2
MSCONFIG\Services: BstHdAndroidSvc => 2
MSCONFIG\Services: BstHdLogRotatorSvc => 2
MSCONFIG\Services: BstHdUpdaterSvc => 2
MSCONFIG\Services: GamesAppService => 3
MSCONFIG\Services: lxduCATSCustConnectService => 2
MSCONFIG\Services: lxdu_device => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: RichVideo => 2
MSCONFIG\Services: SpliCamService => 2
MSCONFIG\Services: TeamViewer9 => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^LTT.lnk => C:\Windows\pss\LTT.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Matts Windows7^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: 3xAV => C:\Program Files (x86)\Enounce\MySpeed\MySpeed.exe
MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeBridge => 
MSCONFIG\startupreg: AdobeCS4ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: Advanced SystemCare 8 => "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BackupManagerTray => "C:\Program Files (x86)\NTI\Gateway MyBackup\BackupManagerTray.exe" -h -k
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: ConferenceRS => C:\Windows\ConferenceRS.exe 
MSCONFIG\startupreg: ConnectionCenter => "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
MSCONFIG\startupreg: EzPrint => "C:\Program Files (x86)\Lexmark 5600-6600 Series\ezprint.exe"
MSCONFIG\startupreg: GoogleChromeAutoLaunch_9F0FD1DA2B53BECFEBEA5616E08F9C6D => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" –no-startup-window
MSCONFIG\startupreg: HP ENVY 4500 series (NET) => "C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN4AS156NS05X4:NW" -scfn "HP ENVY 4500 series (NET)" -AutoStart 1
MSCONFIG\startupreg: IObit Malware Fighter => "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Jing => C:\Program Files (x86)\TechSmith\Jing\Jing.exe
MSCONFIG\startupreg: Livedrive => "C:\Program Files (x86)\Livedrive\Livedrive.exe" /setup
MSCONFIG\startupreg: lxdumon.exe => "C:\Program Files (x86)\Lexmark 5600-6600 Series\lxdumon.exe"
MSCONFIG\startupreg: MMReminderService => C:\Program Files (x86)\Mindjet\MindManager 10\MMReminderService.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
MSCONFIG\startupreg: SacReminderHDDV2 => C:\ProgramData\OfficeGuardianV2\reminder\SacReminder.exe
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{4994B15A-7B16-4892-B57D-22995C3B0A93}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{285D0772-3372-4239-8864-02FC3FF646D2}] => (Allow) LPort=2869
FirewallRules: [{888A4C9D-E2E2-456D-A957-594A71A226A4}] => (Allow) LPort=1900
FirewallRules: [{98937CF9-E1F7-449E-91D2-2214198F7469}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{5A5D406D-E383-4645-946F-E9472BDE5A0D}] => (Allow) C:\Program Files (x86)\CyberLink\HomeMedia\HomeMedia.exe
FirewallRules: [{406B9D8B-A434-48FA-8ACD-8BBD1F23B4F2}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel Wireless Display\WiDiApp.exe
FirewallRules: [{A5656061-2667-4672-8183-2A545E2BDD2A}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{C8D4D6C2-9006-4A4A-8403-71D855B8CCE6}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{C3AE7CA5-4AE0-4C03-80A9-4CCBE5709DF6}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{59CFCDAC-AE52-4F57-9733-B4C65A2C2FF7}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{3F752444-4AF6-47E5-BD06-02F41D392FDE}] => (Allow) LPort=5353
FirewallRules: [{692A01AB-0EAA-4DD2-BEFE-411D37519363}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
FirewallRules: [{887C0967-B7C1-46C5-89A3-E64C301AC2EC}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
FirewallRules: [TCP Query User{A8C8CE57-899C-42F8-9883-00200389CD47}C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{B880609C-BE39-4C11-95F9-9196F7A30655}C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\matts windows7\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{216CDBBE-F30A-40CC-BFB3-7312C6C22F8D}] => (Allow) C:\Windows\SysWOW64\lxducoms.exe
FirewallRules: [{0623DF9B-AA1D-42BE-9EC6-CF670C3FE0B9}] => (Allow) C:\Windows\SysWOW64\lxducoms.exe
FirewallRules: [{1E38857E-3C51-47E4-B76B-0622709C55A6}] => (Allow) C:\Windows\System32\lxducoms.exe
FirewallRules: [{F7A5EBD0-606D-4412-A016-90654E816D10}] => (Allow) C:\Windows\System32\lxducoms.exe
FirewallRules: [{FB3CAC58-CD4C-4F6E-9CC9-0E800B445FFD}] => (Allow) C:\Windows\system32\lxducoms.exe
FirewallRules: [{4004F364-20E4-4AD4-9510-3D6C441B6EA8}] => (Allow) C:\Windows\system32\spool\DRIVERS\x64\3\lxdupswx.exe
FirewallRules: [{E6FB8A6B-BB07-4A45-BBCE-9D782ED8FEBA}] => (Allow) C:\Windows\system32\spool\DRIVERS\x64\3\lxdutime.exe
FirewallRules: [{68EF4A10-F9B7-44B8-9E6A-988D6E0EEAD9}] => (Allow) C:\Windows\SysWOW64\lxducoms.exe
FirewallRules: [{2D773B35-093F-4CBF-BFAC-85A70C53B71D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0B0DAB0C-8F45-44F6-88B1-ACA89B9FF9C2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{33C28F0F-151D-4FF1-BE67-A79BBE5F3DCF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{83B81423-B95F-4ACC-AA23-0D96895D2DF5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4164D113-7D6D-41F3-A645-C498E764F821}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Print Driver 2\PrinterSelector\SUPDApp.exe
FirewallRules: [TCP Query User{1B420190-0675-4A38-84EA-C1F18E88DC3E}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{B33C280E-732E-4884-9720-F251B9CD8B3C}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{59838EEF-E840-46C8-B078-8936831DC67C}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{9337AD9B-6BB2-4622-8A5B-D7092C8AF684}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [TCP Query User{3DB83B16-7DDB-4304-AA83-DAB6154A6B24}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{75991F7B-1AE4-493C-9C8E-F74D2B7E8BD2}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{F7140CF0-4721-4019-96DE-EA9AA1699405}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{31D3216E-D052-40C1-892B-5B660E81CEEA}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [{3587FB72-4931-45E0-88B7-2C07F57A5B8B}] => (Block) %ProgramFiles% (x86)\Sparkol\Sparkol VideoScribe\VideoScribeDesktop.exe
FirewallRules: [TCP Query User{C27D82DC-90E6-4759-9F6F-0EDF90F5B402}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{28553A58-082D-4C80-822A-21CA4319A502}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [{3B51A5B6-D8D1-470E-B6EA-A4F3ABBA64EC}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6D30E3DF-9CD4-41CA-A38D-388B8771BB8E}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{E946012A-54A6-4D39-9CBE-57DFD071D68B}C:\program files\winhttrack\winhttrack.exe] => (Allow) C:\program files\winhttrack\winhttrack.exe
FirewallRules: [UDP Query User{ECA7A336-5DB8-46A7-A781-37B52DFF2EA0}C:\program files\winhttrack\winhttrack.exe] => (Allow) C:\program files\winhttrack\winhttrack.exe
FirewallRules: [TCP Query User{BC231830-FC16-4CE3-B3E3-7FFDE39EA008}C:\program files\reflector\reflector.exe] => (Allow) C:\program files\reflector\reflector.exe
FirewallRules: [UDP Query User{F80CEC39-54AD-4E8A-AD5F-A726221A7699}C:\program files\reflector\reflector.exe] => (Allow) C:\program files\reflector\reflector.exe
FirewallRules: [{D494E31C-B123-41F2-9787-9A71F62624CD}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{3B7A911E-EC62-4E24-90B1-123706B92DEA}] => (Allow) C:\Users\Matts Windows7\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B226DE14-AB84-42FD-9B82-9DA07BFA12AA}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{05192244-B159-416C-9768-0D96679044C3}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{A525CCB4-2C86-4595-8CF4-3073D9FC8A7D}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{703017D9-876E-43E7-9C38-626880ED8030}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [TCP Query User{3DB8486D-D86B-4ED1-84D4-6A958F828F63}C:\programdata\microsoft\windows\start menu\programs\whistle.exe] => (Allow) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [UDP Query User{7BA04638-F71E-4B49-A0C6-8961CAEDF83C}C:\programdata\microsoft\windows\start menu\programs\whistle.exe] => (Allow) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [{56FE4147-C0BD-45AD-A487-914998E9F139}] => (Block) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [{438A4B5C-9673-4DB2-9A38-BB874DB793D6}] => (Block) C:\programdata\microsoft\windows\start menu\programs\whistle.exe
FirewallRules: [{9F5B86D5-CA8B-4773-8DC1-ACC173DDE3F7}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{926F81CA-F346-4D6C-A473-51F7B0383DFF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{46B5B8C4-60E9-4D30-80B5-C71DC2B6643B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{6544F860-06B6-4FCA-9A63-AD3BC7DC7820}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{B9C8E0E7-2CFC-4447-A338-8D4F8E60ECFC}] => (Allow) LPort=8298
FirewallRules: [{864EF2AD-43AA-4664-9ACD-2EE60F69AAC8}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\DeviceSetup.exe
FirewallRules: [{68409358-C465-4D0A-AC68-388087D47BC7}] => (Allow) LPort=5357
FirewallRules: [{818B2472-4269-4FFB-AE3D-3A325B7EACFB}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{4210C355-B346-4F1F-8D74-8EA28D76F06A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C3EC7734-FE0E-4217-B64A-E28B51F787ED}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{22655FD0-A089-4539-B38B-E36F8DC29BFD}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [UDP Query User{04952FD7-B0D2-4ADE-A11C-52E9291D556E}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [TCP Query User{9E888F1E-F8D7-4F9E-95D1-D1D23B527956}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [UDP Query User{AFEC9CFD-5D68-4F03-9C56-CEFFF37F0855}C:\users\matts windows7\desktop\tools\whistle.exe] => (Allow) C:\users\matts windows7\desktop\tools\whistle.exe
FirewallRules: [TCP Query User{18850C7D-8832-4C09-A98A-EE84F6A9A83F}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{97ED0F4F-5A4A-4B0C-89E5-327F80F7506F}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [{64F35FE2-2045-4D89-97D0-0190D4D1EE53}] => (Allow) LPort=15600
FirewallRules: [{E6007C73-4446-4CBE-A702-096C73B9E1F0}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{499B0422-5E3F-433A-A603-A922BB1B357E}C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [UDP Query User{82A5671A-AAAB-43C1-8699-B67EC583658F}C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [{090184A1-4EDD-4ED9-8BF1-AE5C1A3B14F5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{8FC63A2B-FC58-48BD-B27F-0F4725678CA5}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
FirewallRules: [{BA6C668D-C4FD-4858-AFCB-B7173FADE7F2}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
FirewallRules: [{0C3C6DC1-6339-43E6-9DF7-B084B9F64EFF}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\DataProxy.exe
 
==================== Faulty Device Manager Devices =============
 
Name: SBRE
Description: SBRE
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: SBRE
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/25/2015 09:01:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/25/2015 09:01:40 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/25/2015 08:44:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GWXUX.exe, version: 6.3.9600.17923, time stamp: 0x55945dbd
Faulting module name: ntdll.dll, version: 6.1.7601.18939, time stamp: 0x55b02e88
Exception code: 0xc0000005
Fault offset: 0x000000000004ac04
Faulting process id: 0xfc0
Faulting application start time: 0xGWXUX.exe0
Faulting application path: GWXUX.exe1
Faulting module path: GWXUX.exe2
Report Id: GWXUX.exe3
 
Error: (08/25/2015 08:34:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/25/2015 08:34:41 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/25/2015 10:08:03 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/25/2015 10:08:02 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/24/2015 04:29:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 40.0.2.5702, time stamp: 0x55cc03bd
Faulting module name: mozglue.dll, version: 40.0.2.5702, time stamp: 0x55cbf190
Exception code: 0x80000003
Fault offset: 0x0000e631
Faulting process id: 0xe68
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
 
Error: (08/24/2015 11:06:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SRFeature.exe, version: 2.62.6.5913, time stamp: 0x546d7ba8
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00e94fa8
Faulting process id: 0xac8
Faulting application start time: 0xSRFeature.exe0
Faulting application path: SRFeature.exe1
Faulting module path: SRFeature.exe2
Report Id: SRFeature.exe3
 
Error: (08/24/2015 11:05:56 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (08/25/2015 09:02:44 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (08/25/2015 09:02:40 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)
 
Error: (08/25/2015 09:01:44 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
SBRE
 
Error: (08/25/2015 09:01:40 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The BlueStacks Android Service service terminated with the following error: 
%%1064
 
Error: (08/25/2015 09:01:21 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\System32\IWMSSvc.dll
 
Error: (08/25/2015 09:01:21 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\System32\IWMSSvc.dll
 
Error: (08/25/2015 09:01:21 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\System32\IWMSSvc.dll
 
Error: (08/25/2015 09:01:20 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\System32\IWMSSvc.dll
 
Error: (08/25/2015 09:01:11 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Modules Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
 
Error: (08/25/2015 09:01:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) Management and Security Application User Notification Service service terminated unexpectedly.  It has done this 1 time(s).
 
 
Microsoft Office:
=========================
Error: (08/25/2015 09:01:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/25/2015 09:01:40 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/25/2015 08:44:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: GWXUX.exe6.3.9600.1792355945dbdntdll.dll6.1.7601.1893955b02e88c0000005000000000004ac04fc001d0df9865fea0cfC:\Windows\System32\GWX\GWXUX.exeC:\Windows\SYSTEM32\ntdll.dlla42cdf30-4b8b-11e5-9031-b870f48410d0
 
Error: (08/25/2015 08:34:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/25/2015 08:34:41 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/25/2015 10:08:03 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/25/2015 10:08:02 AM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
   at BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (08/24/2015 04:29:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.2.570255cc03bdmozglue.dll40.0.2.570255cbf190800000030000e631e6801d0dea3ce8b0562C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dllc18367d4-4a9e-11e5-90ee-b870f48410d0
 
Error: (08/24/2015 11:06:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: SRFeature.exe2.62.6.5913546d7ba8unknown0.0.0.000000000c000000500e94fa8ac801d0de7e60408f4bC:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exeunknowna26e7d17-4a71-11e5-90ee-b870f48410d0
 
Error: (08/24/2015 11:05:56 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
CodeIntegrity:
===================================
  Date: 2015-08-15 23:17:13.727
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-08-15 23:17:13.696
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
Percentage of memory in use: 47%
Total physical RAM: 8043.86 MB
Available physical RAM: 4193.6 MB
Total Virtual: 16085.92 MB
Available Virtual: 12064 MB
 
==================== Drives ================================
 
Drive c: (Gateway) (Fixed) (Total:419.08 GB) (Free:113.16 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 380202E7)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=419.1 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

Hello again Matt M11,

Looks like you have had a ZeroAccess infection at some point. There are remnants there but I don't see the active files.

 

Perhaps ComboFix removed it.

Moving on

Please uninstall the following adware/tracking/malware programs:

Splashtop Streamer
Splashtop Software Updater
Advanced SystemCare 8


And
Consider uninstalling the following if they are the free version as they come bundled with adware:

IObit Malware Fighter 3
IObit Uninstaller


After that

Open notepad.

Please copy the contents of the code box below.

To do this highlight (click in the box and press Ctrl + A) the contents of the box and right click on it. Paste this into the open notepad. Save it to the Desktop as fixlist.txt.

Alternatively type the contents of the box into notepad and save it to your desktop as fixlist.txt.

NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
 

C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}
C:\Users\Matts Windows7\AppData\Local\{98a3383a-d721-6367-f3cf-6c5bf885b02d}\@
HKLM-x32\…\Run: [] => [X]
AppInit_DLLs-x32:  acaptuser32.dll => "acaptuser32.dll" File not found
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKLM - No Name - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} -  No File
Toolbar: HKU\S-1-5-21-3123964009-4157677460-2703354282-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
FF Extension: Video DownloadHelper - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-08-23]
FF Extension: Adblock Plus - C:\Users\Matts Windows7\AppData\Roaming\Mozilla\Firefox\Profiles\hbgszlrn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-18]
CHR Extension: (Video Downloader) - C:\Users\Matts Windows7\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnmpgleggfcndpeflbjhpjfckfmojnpo [2015-02-10]
S1 SBRE; no ImagePath
Hosts:
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
EmptyTemp:

This script is specifically written for the infection on this person's computer. It should NOT to be used on another machine. It may cause serious damage even to the point of rendering the computer unusable.

Run FRST/FRST64 and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

Finally in this post

Please run another FRST scan with the Addition.txt box ticked and post back the two logs generated - FRST.txt and Addition.txt.

So when you return please post

  • Fixlog.txt
  • FRST.txt
  • Addition.txt

 

I haven't remove the files selected below as of yet.  Splashtop is a program where I can access my computer remotely from my phone and it is a paid program.  Also the other 3 programs came direct from vendors website and are Pro license and all work smoothly together.
 
Splashtop Streamer
Splashtop Software Updater
Advanced SystemCare 8
 
IObit Malware Fighter 3
IObit Uninstaller
 
I have not run the script yet because I wanted to tell you about these 5 above.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI