This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus "failed yo connect to a widows service" [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, thanks in advance for your help.

 My son has an Inspiron 15r with a pretty decent infection i'm sure. Touch pad doesn't work.  No networking at all, ethernet, wifi, usb(wifi)dongle. Gives the Failed to connect to a windows service error on start up. Cannot view system event log. Cannot get admin privileges. In network just states dependency service or group failed to start. When i try to use aswMBR to scan i get the error avast Antirootkit has stopped working. I have included the log from frst. 

Things i have tried so far

Every thing i have read on the internet to fix failed to connect to a windows service and dependency or service group failed to start

I tried using combo fix(before i read your instructions) wouldn't let me anyway no admin priveledges

i have used chkdisk and clicked the fix errors box

i have used JRT

I have deleted utorrent and any program that looked susupicious

I ran FRST64 and aswMBR 

I have saved the logs from JRT and FRST64

Again thanks for the help. I am almost resigned that i am going to need to reinstall windows, but i dont want to as i dont have the recovery disks and it will be a mission.

Thank you,

 

Damien Parker

 

edit: i just read the part about post logs don't attach sorry will do now

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.3 (09.21.2015:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on Mon 28/09/2015 at 18:37:41.38
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
Successfully deleted: [Service] vToolbarUpdater17.0.12 [Reboot required]
 
 
 
~~~ Tasks
 
Failed to delete: [Task] C:\Windows\system32\tasks\ArcadeParlor
Successfully deleted: [Task] C:\Windows\Tasks\ArcadeParlor.job
 
 
 
~~~ Registry Values
 
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotect
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotectall
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\Default_Search_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Toolbar.CT3220468
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Toolbar.CT3306061
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3220468
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3306061
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update lucky leap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util lucky leap
 
 
 
~~~ Files
 
Successfully deleted: [File] C:\Users\Public\Desktop\ebay.lnk
Successfully disinfected: [Shortcut] C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Successfully disinfected: [Shortcut] C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Successfully disinfected: [Shortcut] C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
 
 
 
~~~ Folders
 
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{130A331A-146D-45CE-AA46-0418128A7D09}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{28459633-034C-4E3C-A122-96901C724EC4}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{4D1B3448-BFCC-40BD-8355-737986A16921}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{B33802BE-2E48-42C8-8D0C-04B1487639C8}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{B6C7B800-8C9E-44C8-9815-B827B893302C}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{C53AFFB1-6346-4B78-9A26-DBF44ECDD7F8}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{C885A46C-1057-4578-8EBE-C79A1D563EDF}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{D790316F-57E6-4F7D-B24E-49277B0B05DE}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{F44D68FF-9217-4535-BECE-67BB530161CA}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{F5ADF7CC-8DDB-4775-A595-1B1FA3C50FE7}
Successfully deleted: [Folder] C:\Program Files (x86)\avg safeguard toolbar
Successfully deleted: [Folder] C:\Program Files (x86)\Common Files\337
Successfully deleted: [Folder] C:\Program Files (x86)\lucky leap
Successfully deleted: [Folder] C:\Program Files (x86)\mypc backup
Successfully deleted: [Folder] C:\ProgramData\avg safeguard toolbar
Successfully deleted: [Folder] C:\Users\Tomton98\Appdata\Local\arcadeparlor
Successfully deleted: [Folder] C:\Users\Tomton98\Appdata\Local\avg safeguard toolbar
Successfully deleted: [Folder] C:\Users\Tomton98\Appdata\Local\nativemessaging
Successfully deleted: [Folder] C:\Users\Tomton98\Appdata\LocalLow\avg safeguard toolbar
Successfully deleted: [Folder] C:\Users\Tomton98\Appdata\LocalLow\pricegong
Successfully deleted: [Folder] C:\Users\Tomton98\Appdata\LocalLow\utorrentcontrol_v2
Successfully deleted: [Folder] C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\arcadeparlor
Successfully deleted: [Folder] C:\Users\Tomton98\AppData\Roaming\systweak
Successfully deleted: [Folder] C:\Users\Tomton98\Documents\add-in express
Successfully deleted: [Folder] C:\Users\Tomton98\Documents\optimizer pro
Successfully deleted: [Folder] C:\Windows\SysWOW64\ai_recyclebin
Successfully deleted: [Folder] C:\ProgramData\fcede5944c660eb4
 
 
 
~~~ Chrome
 
Successfully deleted: [Folder] C:\Users\Tomton98\Appdata\Local\Google\Chrome\User Data\Default\Extensions\eiimolhnbbbdagljikeckdkldgemmmlj
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\eiimolhnbbbdagljikeckdkldgemmmlj
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\ijblflkdjdopkpdgllkmlbgcffjbnfda
 
[C:\Users\Tomton98\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\Tomton98\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Users\Tomton98\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\Tomton98\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
  eiimolhnbbbdagljikeckdkldgemmmlj,
  ijblflkdjdopkpdgllkmlbgcffjbnfda
]
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-06-2016 02
Ran by [removed] (administrator) on TOMTON98-PC (28-06-2016 07:06:46)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\CxUtilSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\SmartAudio3.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
() C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe
(Facebook Inc.) C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\Grid64.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(GoPro) C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2878728 2014-04-17] (ELAN Microelectronics Corp.)
HKLM\…\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5729648 2012-02-08] (Dell Inc.)
HKLM\…\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SA3\SACpl.exe [1628288 2011-09-09] (Conexant Systems, Inc.)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\…\Run: [IntelliType Pro] => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation)
HKLM\…\Run: [IntelliPoint] => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-09-23] (Apple Inc.)
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-30] (Intel Corporation)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-17] (Intel Corporation)
HKLM-x32\…\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [503942 2011-04-14] (Creative Technology Ltd)
HKLM-x32\…\Run: [Dell DataSafe Online] => C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-26] (Dell, Inc.)
HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2015-06-27] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-20] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM-x32\…\Run: [NeroLauncher] => C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe [67496 2012-08-21] ()
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-09-23] (Apple Inc.)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-07-23] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6108752 2015-11-12] (AVAST Software)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
HKLM-x32\…\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2016-04-05] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-04-30] (Valve Corporation)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3619160 2015-01-28] (Electronic Arts)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [RGSC] => C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-07-23] (AMD)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Grid] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe [401408 2013-07-23] ()
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [News.net] => C:\Program Files\News.net\BreakingNews\DesktopContainer.exe
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Facebook Update] => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-01-12] (Facebook Inc.)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50670720 2016-03-01] (Skype Technologies S.A.)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [uTorrent] => "C:\Users\Tomton98\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\MountPoints2: {c1049b66-68da-11e2-8874-685d432459a0} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\MountPoints2: {c1049b6c-68da-11e2-8874-685d432459a0} - E:\setup_vmb_lite.exe /checkApplicationPresence
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-21] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CineForm Status.lnk [2014-01-10]
ShortcutTarget: CineForm Status.lnk -> C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe (GoPro)
Startup: C:\Users\GUEST DAWW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.0.lnk [2012-05-16]
ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 09  No File 
Winsock: -> Catalog5 - Broken internet access due to missing entry. <===== ATTENTION
Tcpip\..\Interfaces\{D8A27A5F-3916-43BC-B7D9-A5FAAE7F9BC8}: [NameServer] 10.143.147.147 10.143.147.148
 
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.news.net/index.php?referid=118
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
URLSearchHook: HKLM-x32 - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File
URLSearchHook: HKLM-x32 - (No Name) - {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - No File
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {7F8CCD3E-6F4E-4BA1-9F04-908D189BA03F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDR&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> {7F8CCD3E-6F4E-4BA1-9F04-908D189BA03F} URL = 
BHO: No Name -> {1346D119-159F-2B54-51CC-ABEF9A4BE183} -> No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-03-27] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-21] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-06] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-03-27] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-21] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-06] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-06] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-06] (Google Inc.)
DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-02-01] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll No File
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-13] ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-03-27] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-03-27] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-13] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.12\\npsitesafety.dll [No File]
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-04] (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.3 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll [No File]
FF Plugin-x32: @esn/esnlaunch,version=2.1.7 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll [2013-05-30] (ESN Social Software AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-12-10] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-09-07] (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-06-27] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Tomton98\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Tomton98\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [No File]
FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-09-07] (Pando Networks)
FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-04-12] (Ubisoft)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-14]
 
Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid;=GOB1&co;=AU&userid;=498b7376-d3a1-3183-ef1e-84d17cd84b02&searchtype;=hp&installDate;=04/11/2013","hxxp://www.google.com/ig/redirectdomain?brand=ASUT&bmod;=ASUT"
CHR Profile: C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Google Search) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Docs Offline) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-01]
CHR Extension: (Avast Online Security) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-04-09]
CHR Extension: (Skype) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-05-25]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-04]
CHR Extension: (Gmail) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-31]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-21]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-07-21] (AVAST Software)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4047768 2015-07-21] (Avast Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [802688 2015-01-22] ()
R2 CxUtilSvc; C:\Program Files\Conexant\SA3\CxUtilSvc.exe [109184 2011-10-12] (Conexant Systems, Inc.)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [174624 2015-01-17] (EasyAntiCheat Ltd)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2016-04-05] (LogMeIn, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-09] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2120712 2016-06-01] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-02-28] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-09] (Intel® Corporation)
S2 Hamachi2Svc; no ImagePath
S3 WinHttpAutoProxySvc; winhttp.dll [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [36096 2013-05-22] (Advanced Micro Devices, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-07-21] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-07-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-07-21] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-12] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150160 2015-07-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-07-21] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-11] (Broadcom Corporation)
R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [115152 2015-07-21] (AVAST Software)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-21] (Avast Software)
S3 ZTEusbwwan; C:\Windows\System32\DRIVERS\ZTEusbwwan.sys [235520 2010-06-10] (ZTE Incorporated)
U3 aswMBR; \??\C:\Users\Tomton98\AppData\Local\Temp\aswMBR.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-06-28 07:06 - 2016-06-28 07:07 - 00026953 _____ C:\Users\Tomton98\Desktop\FRST.txt
2016-06-28 07:06 - 2016-06-28 07:06 - 00000000 ____D C:\FRST
2016-06-28 07:04 - 2016-06-28 06:59 - 05198336 _____ (AVAST Software) C:\Users\Tomton98\Desktop\aswMBR.exe
2016-06-28 07:04 - 2016-06-28 06:58 - 02389504 _____ (Farbar) C:\Users\Tomton98\Desktop\FRST64.exe
2016-06-27 23:24 - 2016-06-27 23:24 - 00000000 ____D C:\Users\Tomton98\Documents\Add-in Express
2016-06-27 22:51 - 2016-06-27 22:49 - 01610816 _____ (Malwarebytes) C:\Users\Tomton98\Desktop\JRT (1).exe
2016-06-27 22:39 - 2016-06-27 22:39 - 00000000 ____D C:\Qoobox
2016-06-27 22:38 - 2016-06-27 22:38 - 00000000 ____D C:\Windows\erdnt
2016-06-27 22:38 - 2016-06-27 22:34 - 05659224 ____R (Swearware) C:\Users\Tomton98\Desktop\ComboFix.exe
2016-06-27 20:30 - 2016-06-27 21:40 - 00000000 ____D C:\Windows\pss
2016-06-27 17:30 - 2016-06-27 17:30 - 00283344 _____ C:\Windows\Minidump\062716-21481-01.dmp
2016-06-27 16:20 - 2016-06-27 17:26 - 00000271 _____ C:\WirelessDiagLog.csv
2016-06-24 15:29 - 2016-06-24 15:30 - 00000000 ____D C:\Users\Tomton98\Desktop\bomb 23.06.2016
2016-06-02 17:30 - 2016-06-02 17:30 - 00010312 ____N C:\bootsqm.dat
2016-05-31 15:54 - 2016-06-01 16:51 - 00003034 _____ C:\Windows\System32\Tasks\EVGAPrecision
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-06-28 05:45 - 2009-07-14 14:45 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-06-28 05:45 - 2009-07-14 14:45 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-06-28 05:41 - 2014-12-19 00:22 - 00000000 ____D C:\Users\Tomton98\AppData\Local\LogMeIn Hamachi
2016-06-28 05:36 - 2012-05-16 19:52 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2016-06-28 05:36 - 2012-05-16 19:52 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2016-06-28 05:36 - 2012-05-16 19:42 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2016-06-28 04:07 - 2013-04-15 10:42 - 00000000 ____D C:\Program Files\WinRAR
2016-06-27 23:26 - 2013-11-04 19:48 - 00000000 ____D C:\Program Files\HitmanPro
2016-06-27 23:21 - 2012-12-19 21:10 - 00000000 ____D C:\Users\Tomton98\AppData\Roaming\uTorrent
2016-06-27 22:37 - 2009-07-14 15:13 - 00782288 _____ C:\Windows\system32\PerfStringBackup.INI
2016-06-27 22:37 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\inf
2016-06-27 22:20 - 2012-12-17 20:35 - 00000000 ____D C:\Program Files (x86)\Origin
2016-06-27 19:46 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2016-06-27 19:46 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\system32\Dism
2016-06-27 17:30 - 2013-04-14 10:51 - 655389053 _____ C:\Windows\MEMORY.DMP
2016-06-27 17:30 - 2013-04-14 10:51 - 00000000 ____D C:\Windows\Minidump
2016-06-27 16:29 - 2013-10-06 14:34 - 00000000 ____D C:\Users\Tomton98\AppData\Local\ElevatedDiagnostics
2016-06-27 16:26 - 2013-02-22 14:30 - 00943320 _____ C:\Windows\ntbtlog.txt
2016-06-24 15:29 - 2015-04-15 21:34 - 00000000 ____D C:\Users\Tomton98\AppData\Local\Windows Live
2016-06-24 15:28 - 2015-08-26 20:37 - 00000000 ____D C:\Users\Tomton98\AppData\Roaming\vlc
2016-06-22 19:00 - 2012-05-16 19:46 - 00000000 ____D C:\ProgramData\Temp
2016-06-03 08:43 - 2012-12-10 14:29 - 00000000 ____D C:\Users\Tomton98\AppData\Local\Nero
2016-06-01 22:58 - 2012-05-16 19:13 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-06-01 22:31 - 2014-01-12 21:26 - 00000940 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001UA.job
2016-06-01 22:31 - 2014-01-12 21:26 - 00000918 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001Core.job
2016-06-01 22:27 - 2012-12-12 06:37 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-06-01 16:50 - 2012-12-11 14:29 - 00000000 ____D C:\Program Files (x86)\Steam
2016-06-01 16:48 - 2016-05-18 18:12 - 00000000 ____D C:\Users\Tomton98\AppData\LocalLow\uTorrent
2016-06-01 16:47 - 2012-12-12 06:37 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-06-01 16:46 - 2009-07-14 15:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-05-31 15:12 - 2014-03-10 19:46 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
 
==================== Files in the root of some directories =======
 
2013-03-10 13:59 - 2015-03-26 20:43 - 0009728 _____ () C:\Users\Tomton98\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-03-17 15:11 - 2013-03-17 15:11 - 0004096 ____H () C:\Users\Tomton98\AppData\Local\keyfile3.drm
2013-03-17 15:50 - 2015-01-22 23:22 - 0007601 _____ () C:\Users\Tomton98\AppData\Local\resmon.resmoncfg
2015-09-18 13:38 - 2015-09-18 13:38 - 0000000 _____ () C:\Users\Tomton98\AppData\Local\{265DA060-8805-4A19-A71F-E4B342EA3713}
2016-01-15 11:51 - 2016-01-15 11:53 - 0000000 _____ () C:\Users\Tomton98\AppData\Local\{AE64DE04-EC8A-4EF3-A4BA-4AED777EE961}
2015-01-28 21:09 - 2015-01-28 21:09 - 0000000 _____ () C:\Users\Tomton98\AppData\Local\{FB802408-E561-4C5E-B4A9-40E3C118C883}
 
Some files in TEMP:
====================
C:\Users\GUEST DAWW\AppData\Local\Temp\SearchWithGoogleUpdate.exe
C:\Users\Tomton98\AppData\Local\Temp\13-4_mobility_win7_win8_64_dd_ccc_whql.exe
C:\Users\Tomton98\AppData\Local\Temp\3zhnejvq.dll
C:\Users\Tomton98\AppData\Local\Temp\api1qhxy.dll
C:\Users\Tomton98\AppData\Local\Temp\BackupSetup.exe
C:\Users\Tomton98\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmprsuzwx.dll
C:\Users\Tomton98\AppData\Local\Temp\ev1fr3pf.dll
C:\Users\Tomton98\AppData\Local\Temp\gcapi_dll.dll
C:\Users\Tomton98\AppData\Local\Temp\HitmanPro.exe
C:\Users\Tomton98\AppData\Local\Temp\j75cknpg.dll
C:\Users\Tomton98\AppData\Local\Temp\nsaD8F6.exe
C:\Users\Tomton98\AppData\Local\Temp\nseCF43.exe
C:\Users\Tomton98\AppData\Local\Temp\nsgAB14.exe
C:\Users\Tomton98\AppData\Local\Temp\nsgD1C3.exe
C:\Users\Tomton98\AppData\Local\Temp\nsjCA44.exe
C:\Users\Tomton98\AppData\Local\Temp\nslA3E0.exe
C:\Users\Tomton98\AppData\Local\Temp\nso2532.exe
C:\Users\Tomton98\AppData\Local\Temp\nszD677.exe
C:\Users\Tomton98\AppData\Local\Temp\RegClean8.exe
C:\Users\Tomton98\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Tomton98\AppData\Local\Temp\sonarinst.exe
C:\Users\Tomton98\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Tomton98\AppData\Local\Temp\utt5AD6.tmp.exe
C:\Users\Tomton98\AppData\Local\Temp\uttE421.tmp.exe
C:\Users\Tomton98\AppData\Local\Temp\wtyqn_ke.dll
C:\Users\Tomton98\AppData\Local\Temp\_is7BEE.exe
C:\Users\Tomton98\AppData\Local\Temp\_n0nuc2j.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
ATTENTION: ==> Could not access BCD. 
 
 
LastRegBack: 2016-05-28 01:15
 
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-06-2016 02
Ran by [removed] (2016-06-28 07:07:24)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-12-10 04:13:49)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1821522787-3724074743-2321965764-500 - Administrator - Disabled)
Guest (S-1-5-21-1821522787-3724074743-2321965764-501 - Limited - Disabled)
GUEST DAWW (S-1-5-21-1821522787-3724074743-2321965764-1003 - Limited - Enabled) => C:\Users\GUEST DAWW
HomeGroupUser$ (S-1-5-21-1821522787-3724074743-2321965764-1002 - Limited - Enabled)
Tomton98 (S-1-5-21-1821522787-3724074743-2321965764-1001 - Administrator - Enabled) => C:\Users\Tomton98
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: avast! Antivirus (Enabled - Out of date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Out of date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Addon Sync 2009 (HKLM-x32\…\{4E3AA543-09D7-401E-9DF2-2591D24C7C49}) (Version: 1.0.67 - YomaTools)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
Adobe Flash Player 21 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 21.0.0.242 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated)
Adobe Reader X (10.1.15) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.15 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM-x32\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
AMD Catalyst Install Manager (HKLM\…\{3CB2E87A-33CC-8E5A-2D3F-E9ACDE622704}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\…\{A50679D9-6CBD-4FCD-BACB-62EF3894F6F3}) (Version: 4.0.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{1F72FDD5-A069-45B4-928F-D0F16492DC69}) (Version: 4.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Arma 2 (HKLM-x32\…\Steam App 33910) (Version:  - Bohemia Interactive)
ARMA 2 Operation Arrowhead Uninstall (HKLM-x32\…\ARMA 2 Operation Arrowhead) (Version:  - )
ArmA 2 Uninstall (HKLM-x32\…\ArmA 2) (Version:  - )
Arma 2: Operation Arrowhead (HKLM-x32\…\Steam App 33930) (Version:  - Bohemia Interactive)
Arma 3 Alpha (HKLM-x32\…\Steam App 107410) (Version:  - Bohemia Interactive)
Arma 3 Alpha Lite (HKLM-x32\…\Steam App 228800) (Version:  - Bohemia Interactive)
Arma: Cold War Assault (HKLM-x32\…\Steam App 65790) (Version:  - Bohemia Interactive)
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 10.3.2223 - AVAST Software)
Battlefield 3™ (HKLM-x32\…\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.5.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\…\Battlelog Web Plugins) (Version: 2.1.7 - EA Digital Illusions CE AB)
BattlEye for OA Uninstall (HKLM-x32\…\BattlEye for OA) (Version:  - )
BattlEye Uninstall (HKLM-x32\…\BattlEye for A2) (Version:  - )
BioShock (HKLM-x32\…\{E280923D-C5D9-4728-8C79-AC9A0DC75875}) (Version: 2.5.0000 - 2K Games)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon MP550 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP550_series) (Version:  - )
Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
Chivalry: Medieval Warfare (HKLM-x32\…\Steam App 219640) (Version:  - Torn Banner Studios)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Conexant SmartAudio HD (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.54.29.0 - Conexant)
Connect DLC 5 Toolbar for IE (HKLM-x32\…\IECT3306061) (Version: 6.17.1.25 - Connect DLC 5) <==== ATTENTION
Counter-Strike: Global Offensive (HKLM-x32\…\Steam App 730) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\…\Steam App 240) (Version:  - Valve)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DayZ (HKLM-x32\…\Steam App 221100) (Version:  - Bohemia Interactive)
DayZ Commander (HKLM-x32\…\{BAD8395E-CE31-44AA-B9FE-A14FCD0ABE4A}) (Version: 0.9.110 - Dotjosh Studios)
Dead Space™ 3 (HKLM-x32\…\{D4329609-4102-4F8C-B83F-7FE024EEA314}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Dell Data Vault (Version: 4.3.4.0 - Dell Inc.) Hidden
Dell DataSafe Local Backup - Support Software (HKLM-x32\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.67 - Dell Inc.)
Dell DataSafe Local Backup (HKLM-x32\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.67 - Dell Inc.)
Dell DataSafe Online (HKLM-x32\…\{7EC66A95-AC2D-4127-940B-0445A526AB2F}) (Version: 2.1.19634 - Dell)
Dell Edoc Viewer (HKLM\…\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell SupportAssistAgent (HKLM-x32\…\{287348C8-8B47-4C36-AF28-441A3B7D8722}) (Version: 1.1.0.47 - Dell)
Dell Touchpad (HKLM\…\Elantech) (Version: 11.3.16.1 - ELAN Microelectronic Corp.)
Dell Update (HKLM-x32\…\{90437913-9D4D-4D9D-B438-B8664DF851E9}) (Version: 1.7.1007.0 - Dell Inc.)
Dell Webcam Central (HKLM-x32\…\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd)
Dropbox (HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
eBay (HKLM-x32\…\{A8B88634-7F90-402F-B66A-86429755F6A5}) (Version: 1.4.0 - eBay Inc.)
ESN Sonar (HKLM-x32\…\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
EVGA Precision X 4.2.1 (HKLM-x32\…\PrecisionX) (Version: 4.2.1 - EVGA Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout 3 (HKLM-x32\…\Steam App 22300) (Version:  - Bethesda Game Studios)
Fallout: New Vegas (HKLM-x32\…\Steam App 22380) (Version:  - Obsidian Entertainment)
Far Cry 3 (HKLM-x32\…\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
Fraps (remove only) (HKLM-x32\…\Fraps) (Version:  - )
Game Dev Tycoon (HKLM-x32\…\Steam App 239820) (Version:  - Greenheart Games)
Garry's Mod (HKLM-x32\…\Steam App 4000) (Version:  - Garry)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 50.0.2661.102 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7619.1252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden
GoPro Studio 2.0.0 (HKLM-x32\…\GoPro Studio) (Version: 2.0.0 - WoodmanLabs Inc. d.b.a. GoPro)
Gotham City Impostors: Free To Play (HKLM-x32\…\Steam App 206210) (Version:  - )
Grand Theft Auto IV (HKLM-x32\…\GFWL_{5454083B-632A-4F1D-9CED-3D1000008600}) (Version: 1.0.0000.134 - Rockstar Games Inc)
Grand Theft Auto IV (x32 Version: 1.0.0000.134 - Rockstar Games Inc) Hidden
Grand Theft Auto IV (x32 Version: 1.0.0005.134 - Rockstar Games Inc.) Hidden
Grand Theft Auto: San Andreas (HKLM-x32\…\Steam App 12120) (Version:  - Rockstar Games)
GTA San Andreas (HKLM-x32\…\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
Guns of Icarus Online (HKLM-x32\…\Steam App 209080) (Version:  - Muse Games)
Heroes & Generals (HKLM-x32\…\Steam App 227940) (Version:  - Reto-Moto)
Hitman: Absolution (HKLM-x32\…\Steam App 203140) (Version:  - IO Interactive)
Hitman: Sniper Challenge (HKLM-x32\…\Steam App 205930) (Version:  - IO Interactive)
HydraVision (x32 Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden
iCloud (HKLM\…\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Display Audio Driver (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3090 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.1.1399 - Intel Corporation)
Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\…\{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}) (Version: 15.0.0.0059 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\…\{F0932859-AA60-459E-B843-0BDECA34E2C7}) (Version: 2.0.0.0086 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\…\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
Intel(R) WiDi (HKLM-x32\…\{7FCB8D5D-9396-4D17-8CFA-349D6D49CD32}) (Version: 3.0.13.0 - Intel Corporation)
Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® PROSet/Wireless WiFi Software (HKLM\…\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\…\{538B98C3-773F-4F20-9C66-802D104DCBE2}) (Version: 1.23.219.2 - Intel Corporation)
iTunes (HKLM\…\{96984DE8-1DB8-425C-AC8C-3098BC696F04}) (Version: 12.3.0.44 - Apple Inc.)
Java 7 Update 51 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
Java 7 Update 9 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
L.A. Noire (HKLM-x32\…\Steam App 110800) (Version:  - Team Bondi)
League of Legends (HKLM-x32\…\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Left 4 Dead 2 (HKLM-x32\…\Steam App 550) (Version:  - Valve)
LogMeIn Hamachi (HKLM-x32\…\LogMeIn Hamachi) (Version: 2.2.0.420 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.420 - LogMeIn, Inc.) Hidden
lucky leap 1.0.0 (HKLM\…\lucky leap) (Version: 1.0.0 - luckyleap)
Max Payne 3 (HKLM-x32\…\{1AA94747-3BF6-4237-9E1A-7B3067738FE1}) (Version: 1.0.0.0 - Rockstar Games)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\…\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\…\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.0.162.0 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\…\{91110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\…\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\…\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\…\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
NVIDIA PhysX (HKLM-x32\…\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Oblivion (HKLM-x32\…\{35CB6715-41F8-4F99-8881-6FC75BF054B0}) (Version: 1.00.0000 - Bethesda Softworks)
Origin (HKLM-x32\…\Origin) (Version: 9.1.3.2637 - Electronic Arts, Inc.)
Pando Media Booster (HKLM-x32\…\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
PAYDAY 2 (HKLM-x32\…\Steam App 218620) (Version:  - OVERKILL - a Starbreeze Studio.)
PAYDAY: The Heist (HKLM-x32\…\Steam App 24240) (Version:  - Overkill)
PlanetSide 2 (HKLM-x32\…\Steam App 218230) (Version:  - Sony Online Entertainment)
Product Support 1.74.b1377 (HKLM-x32\…\SP_963508d2) (Version:  - ) <==== ATTENTION
PunkBuster Services (HKLM-x32\…\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.14.010 - Dell Inc.)
QuickTime 7 (HKLM-x32\…\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7601.39019 - Realtek Semiconductor Corp.)
RivaTuner Statistics Server 5.2.0 (HKLM-x32\…\RTSS) (Version: 5.2.0 - Unwinder)
Rockstar Games Social Club (HKLM-x32\…\Rockstar Games Social Club) (Version: 1.1.0.6 - Rockstar Games)
RollerCoaster Tycoon 3: Platinum! (HKLM-x32\…\Steam App 2700) (Version:  - Frontier)
RuneScape Launcher 1.2.2 (HKLM-x32\…\{A85FCCBE-31AB-4312-A5A9-165FF3B0BF90}) (Version: 1.2.2 - Jagex Ltd)
Rust (HKLM-x32\…\Steam App 252490) (Version:  - Facepunch Studios)
Search Protect by conduit (HKLM-x32\…\SearchProtect) (Version: 1.7.0.72 - Conduit) <==== ATTENTION
Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Sid Meier's Civilization V (HKLM-x32\…\Steam App 8930) (Version:  - 2K Games, Inc.)
SimCity™ (HKLM-x32\…\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
Six Updater (HKLM-x32\…\{2D8CED57-CCDB-4D86-9087-3BBCAE8F8F22}) (Version: 2.09.7016 - Six Projects)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
Skype™ 7.21 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.21.100 - Skype Technologies S.A.)
Sleeping Dogs™ (HKLM-x32\…\Steam App 202170) (Version:  - United Front Games)
Spore (HKLM-x32\…\Steam App 17390) (Version:  - Maxis™)
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Surgeon Simulator 2013 (HKLM-x32\…\Steam App 233720) (Version:  - Bossa Studios)
SyncUP (HKLM-x32\…\{D92C9CCE-E5F0-4125-977A-0590F3225B74}) (Version: 10.2.16100 - Nero AG)
SyncUP (x32 Version: 1.12.12400.17.102 - Nero AG) Hidden
Team Fortress 2 (HKLM-x32\…\Steam App 440) (Version:  - Valve)
TeamSpeak 3 Client (HKLM-x32\…\TeamSpeak 3 Client) (Version: 3.0.12 - TeamSpeak Systems GmbH)
The Elder Scrolls III: Morrowind (HKLM-x32\…\Steam App 22320) (Version:  - Bethesda Game Studios®)
The Elder Scrolls V: Skyrim (HKLM-x32\…\Steam App 72850) (Version:  - Bethesda Game Studios)
The Sims 2: Ultimate Collection (HKLM-x32\…\{04450C18-F039-4B81-A621-70C3B0F523D5}) (Version: 1.0.0.0 - Electronic Arts)
The Sims™ 3 (HKLM-x32\…\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts)
The Sims™ 3 70s, 80s, & 90s Stuff (HKLM-x32\…\{E1868CAE-E3B9-4099-8C18-AA8944D336FD}) (Version: 17.0.77 - Electronic Arts)
The Sims™ 3 Ambitions (HKLM-x32\…\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts)
The Sims™ 3 Diesel Stuff (HKLM-x32\…\{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}) (Version: 14.0.48 - Electronic Arts)
The Sims™ 3 Fast Lane Stuff (HKLM-x32\…\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts)
The Sims™ 3 Generations (HKLM-x32\…\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts)
The Sims™ 3 High-End Loft Stuff (HKLM-x32\…\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts)
The Sims™ 3 Island Paradise (HKLM-x32\…\{DB21639E-FE55-432C-BCA2-0C5249E3F79E}) (Version: 19.0.101 - Electronic Arts)
The Sims™ 3 Late Night (HKLM-x32\…\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts)
The Sims™ 3 Master Suite Stuff (HKLM-x32\…\{08A25478-C5DD-4EA7-B168-3D687CA987FF}) (Version: 11.0.84 - Electronic Arts)
The Sims™ 3 Outdoor Living Stuff (HKLM-x32\…\{117B6BF6-82C3-420C-B284-9247C8568E53}) (Version: 7.0.55 - Electronic Arts)
The Sims™ 3 Pets (HKLM-x32\…\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts)
The Sims™ 3 Seasons (HKLM-x32\…\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts)
The Sims™ 3 Showtime (HKLM-x32\…\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts)
The Sims™ 3 Supernatural (HKLM-x32\…\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts)
The Sims™ 3 Town Life Stuff (HKLM-x32\…\{7B11296A-F894-449C-8DF6-6AAAA7D4D118}) (Version: 9.0.73 - Electronic Arts)
The Sims™ 3 University Life (HKLM-x32\…\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}) (Version: 18.0.126 - Electronic Arts)
The Sims™ 3 World Adventures (HKLM-x32\…\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts)
Thief (HKLM-x32\…\Steam App 239160) (Version:  - Eidos-Montréal)
Tropico 4 Gold (HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Tropico 4 Gold) (Version: 1.05 - Kalypso Media)
Tropico 5 (HKLM-x32\…\Steam App 245620) (Version:  - Haemimont Games)
Unity Web Player (HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\UnityWebPlayer) (Version: 5.0.1f1 - Unity Technologies ApS)
Uplay (HKLM-x32\…\Uplay) (Version: 2.0 - Ubisoft)
VIO Player version 1.0.1 (HKLM-x32\…\{C8A17598-7F89-41EA-9876-0F89DA0B24F1}_is1) (Version: 1.0.1 - VIO)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
Warframe (HKLM-x32\…\Steam App 230410) (Version:  - Digital Extremes)
Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices  (03/07/2012 ) (HKLM\…\0B624A43DD66DBF5CF3EDFA9741A364E688062A4) (Version: 03/07/2012  - GoPro)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Movie Maker 2.6 (HKLM-x32\…\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {04986720-95AF-4AE5-A028-FBAD214FF3E4} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2015-06-11] (Dell Inc.)
Task: {176B0FD7-2CC5-4890-BFAD-D3DE48A60639} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
Task: {1B2BF7FD-213C-47AB-B191-41FB869FC45A} - System32\Tasks\{486C2EC1-91DE-4997-B97C-6D8085EC3DEC} => C:\Program Files (x86)\Bohemia Interactive\ArmA 2\arma2OA.exe [2013-03-10] (Bohemia Interactive)
Task: {3364C208-BD3E-4121-93A6-E455C937C905} - System32\Tasks\{A42F91EF-79E2-4B10-BD5F-45C67B238C3F} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {355A5A19-CC60-4DCC-AD0B-412DE8A03E61} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-07-21] (AVAST Software)
Task: {3AF391DB-81EB-4999-A303-1A3D0C4350FF} - System32\Tasks\EVGAPrecision => C:\Program Files (x86)\EVGA Precision X\EVGAPrecision.exe [2013-07-18] ()
Task: {3B3090EA-B338-4F30-B800-1E6D4875B6F8} - System32\Tasks\{0F0A7E5D-A4FF-4DA9-96F8-245E48069309} => pcalua.exe -a C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69\GEARDIFx.exe -d C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
Task: {3C304234-609D-4CA2-9778-0287B37A9EEE} - System32\Tasks\RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe <==== ATTENTION
Task: {3D8A0521-5049-4199-A763-FBA0F99DCF5F} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-03-31] (AVAST Software)
Task: {3E4F8A16-6A43-46BE-BCB0-5D68F8145C79} - System32\Tasks\{C1397205-A924-40E8-BABC-90F8470FC152} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {4819DCCA-2472-49ED-B371-D6C0EBFB4556} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2012-11-02] (Microsoft Corporation)
Task: {59F44749-E201-4945-A2FA-4BDBA3150EAD} - System32\Tasks\{95A88E8F-1A35-418E-91C6-623E45497224} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {65D692E5-EFD1-4A06-8212-2D275B468BB0} - System32\Tasks\{87D6AF67-0AC9-4487-961E-48DD8279E085} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {70CC3F5D-16EC-4970-AFE7-DF50762F11D2} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2012-11-02] (Microsoft)
Task: {77B971D2-1360-49C4-802B-A0FE71AC47BD} - System32\Tasks\{510D9FCC-C247-42BB-8865-9BF9F9A12D43} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {7966649C-0BFE-446B-A3DF-2185D445791E} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001Core => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-12] (Facebook Inc.)
Task: {79BA81AC-140E-434B-AEFE-B4FB00C790CC} - System32\Tasks\{2ED90E63-1EFA-4874-9880-50F55D5B05A3} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {7D24805E-9738-4F0A-805E-C40689C47FE6} - System32\Tasks\{A0898C8A-B638-4FCC-9EA3-5627E35F4A76} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {81835C2A-9E23-47CA-9EF0-58DA1B70C124} - System32\Tasks\{B03A9A69-01BD-49E9-9487-2CB6E4AFD4F5} => pcalua.exe -a C:\Users\Tomton98\AppData\Local\Temp\Temp1_EVGAPrecisionX.zip\EVGA_PrecisionX_Setup_400.exe
Task: {850EA906-00FB-4C85-B05D-51F84637CE4A} - System32\Tasks\{E833EEB4-F078-4649-8451-4A9815559007} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {9AAF1711-2139-47CC-997A-2605A90B70CF} - System32\Tasks\{D7AB502A-0F67-44E6-BB12-C678A9802368} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {A0EC30EB-237E-4CA9-8F56-3397F9943713} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe
Task: {A423D2EB-59BE-4070-98D2-8D6B60762770} - System32\Tasks\{5FB514CF-A913-4AAF-B204-9F1876F7FB7E} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {A6D0945A-7130-4987-86B2-8E154C6CDA68} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {A7FBEA51-0EA2-42DF-B236-0683419DF8BC} - System32\Tasks\{14C66831-93DA-426D-A90D-0F1D42B01577} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent => aitagent.exe
Task: {B3EDB281-5791-48BB-8D3A-98C489FB6922} - System32\Tasks\{F2B51C84-7766-404C-B31D-F2032079966B} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {BD44F3E9-1E58-4579-94F5-0859F523DE23} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {BFEA4E8A-6FB0-42A9-9775-69866C7C286E} - System32\Tasks\{90C8B7AA-222D-41AC-87BE-B3FD06D3D7A7} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {D512AAA6-268E-49CF-83BA-384E6CBD21F7} - System32\Tasks\{FD2F5746-23D7-4628-9C45-C811788B4A10} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {DCE663B6-40DA-4C33-8583-B566259C92E9} - System32\Tasks\{F2A17ECB-C0C2-4ECD-AAD9-33C9BDE927C2} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {E15C7EFF-31C9-4511-B17F-A3C91F641491} - System32\Tasks\{0CFB6EBC-8F8E-44EC-8AF5-2DF3AF60683C} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {E2406D5B-9A8F-4CC4-A9AD-B1DDB8F4EC2A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-05-13] (Adobe Systems Incorporated)
Task: {E3163C33-301D-4730-A266-5518C5ED3967} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => BthUdTask.exe
Task: {E43463FC-5209-4F16-A5CC-FD713BA73DED} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2013-11-20] (Apple Inc.)
Task: {EE02410A-B1E4-4FCE-AFBE-893C390D110E} - System32\Tasks\{96351ECB-CB3A-434E-AA5C-299A56B11B45} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {F2FC758A-BCC4-4648-A89C-901389A134F4} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001UA => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-12] (Facebook Inc.)
Task: {F3E383DE-9DC2-4631-A292-A55A05B9AEC6} - System32\Tasks\{57529728-AB80-4AD7-B849-659206CEDFBA} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {F3FCFD1D-1C37-4ED3-9FF5-F28E03623037} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2012-11-02] (Microsoft Corporation)
Task: {F9FD37EA-00D5-4071-98DF-A64DD791F10F} - System32\Tasks\{548BC96D-8091-4868-9DF0-3D34E6D39169} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001Core.job => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001UA.job => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{F6A9A4FE-91CF-496D-8EC5-F11ACD174B28}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.rockstargames.com/sanandreas/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{E3EE9886-A04D-E37C-86CD-3E7EA3CF8A0B}\SupportTasks\2\Adobe Flash.lnk -> hxxp://www.adobe.com/products/flash/about (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{E3EE9886-A04D-E37C-86CD-3E7EA3CF8A0B}\SupportTasks\1\Social Club.lnk -> hxxp://socialclub.rockstargames.com/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{E3EE9886-A04D-E37C-86CD-3E7EA3CF8A0B}\SupportTasks\0\Rockstar Games.lnk -> hxxp://www.rockstargames.com/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{7D27B567-B3A3-48B0-B97E-80B69505D3A4}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.rockstargames.com/sanandreas/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{264058BF-9E81-495C-AB14-8DCF244449B6}\SupportTasks\1\Support.lnk -> hxxp://www.bethsoft.com/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{264058BF-9E81-495C-AB14-8DCF244449B6}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.elderscrolls.com/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.com (No File)
 
==================== Loaded Modules (Whitelisted) ==============
 
2012-12-27 12:54 - 2013-02-28 17:44 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2012-05-16 19:42 - 2012-01-27 12:49 - 02751808 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
2012-05-16 19:26 - 2012-01-11 06:36 - 00159360 _____ () C:\Program Files\Conexant\SA3\MaxxAudioWrapper.dll
2012-05-16 20:45 - 2012-01-19 08:48 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-09-23 15:47 - 2015-09-23 15:47 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-09-23 15:47 - 2015-09-23 15:47 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-07-23 19:36 - 2013-07-23 19:36 - 00401408 _____ () C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe
2015-07-21 21:11 - 2015-07-21 21:11 - 00102864 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-07-21 21:11 - 2015-07-21 21:11 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-06-01 20:51 - 2016-06-01 20:51 - 02984152 _____ () C:\Program Files\AVAST Software\Avast\defs\16060100\algo.dll
2016-05-12 19:40 - 2016-05-12 19:40 - 00172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\5a8eeeddc97028a9f94d0518c22f4c2c\IsdiInterop.ni.dll
2012-05-16 19:28 - 2011-11-30 11:00 - 00059392 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-09-14 00:51 - 2013-09-14 00:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
2013-09-14 00:50 - 2013-09-14 00:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
2015-07-21 21:11 - 2015-07-21 21:12 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\Temp:054203E4 [290]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\sony.com -> sony.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 12:34 - 2009-06-11 07:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
MpsSvc => Firewall Service is not running.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled
25-05-2016 19:29:34 Windows Update
27-05-2016 14:28:51 Windows Update
30-05-2016 17:14:30 Windows Backup
31-05-2016 15:47:06 Windows Update
Check "winmgmt" service or repair WMI.
 
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Could not start eventlog service, could not read events.
 
'net' is not recognized as an internal or external command,
operable program or batch file.
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i7-3612QM CPU @ 2.10GHz
Percentage of memory in use: 31%
Total physical RAM: 6046.36 MB
Available physical RAM: 4156.76 MB
Total Virtual: 12090.89 MB
Available Virtual: 9809.93 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:917.66 GB) (Free:62.49 GB) NTFS
Drive e: () (Removable) (Total:7.45 GB) (Free:6.33 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 69519867)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=13.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=917.7 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (Size: 7.5 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

:welcome:

 

You have a lot going on, most likely caused by using the torrents to download programs or files, also a ton of games, games are notorious for sometimes including unwanted programs with them.  When some people install programs, they just keep on clicking on next at the prompts without reading whats being installed.

 

 

Lets do this first

 

 Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.

Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [News.net] => C:\Program Files\News.net\BreakingNews\DesktopContainer.exe
C:\Program Files\News.net
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [uTorrent] => "C:\Users\Tomton98\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
Winsock: Catalog5 09  No File 
Winsock: -> Catalog5 - Broken internet access due to missing entry. <===== ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.news.net/index.php?referid=118
URLSearchHook: HKLM-x32 - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File
URLSearchHook: HKLM-x32 - (No Name) - {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - No File
BHO: No Name -> {1346D119-159F-2B54-51CC-ABEF9A4BE183} -> No File
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll No File
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=GOB1&co=AU&userid=498b7376-d3a1-3183-ef1e-84d17cd84b02&searchtype=hp&installDate=04/11/2013","hxxp://www.google.com/ig/redirectdomain?brand=ASUT&bmod=ASUT"
2016-06-01 16:48 - 2016-05-18 18:12 - 00000000 ____D C:\Users\Tomton98\AppData\LocalLow\uTorrent
Task: {3C304234-609D-4CA2-9778-0287B37A9EEE} - System32\Tasks\RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe <==== ATTENTION
C:\Program Files (x86)\Desk 365
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Fix result of Farbar Recovery Scan Tool (x64) Version: 26-06-2016 02
Ran by [removed] (2016-06-28 10:46:38) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [News.net] => C:\Program Files\News.net\BreakingNews\DesktopContainer.exe
C:\Program Files\News.net
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [uTorrent] => "C:\Users\Tomton98\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
Winsock: Catalog5 09  No File 
Winsock: -> Catalog5 - Broken internet access due to missing entry. <===== ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.news.net/index.php?referid=118
URLSearchHook: HKLM-x32 - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File
URLSearchHook: HKLM-x32 - (No Name) - {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - No File
BHO: No Name -> {1346D119-159F-2B54-51CC-ABEF9A4BE183} -> No File
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll No File
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=GOB1&co=AU&userid=498b7376-d3a1-3183-ef1e-84d17cd84b02&searchtype=hp&installDate=04/11/2013","hxxp://www.google.com/ig/redirectdomain?brand=ASUT&bmod=ASUT"
2016-06-01 16:48 - 2016-05-18 18:12 - 00000000 ____D C:\Users\Tomton98\AppData\LocalLow\uTorrent
Task: {3C304234-609D-4CA2-9778-0287B37A9EEE} - System32\Tasks\RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe <==== ATTENTION
C:\Program Files (x86)\Desk 365
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
*****************
 
Processes closed successfully.
Error: (0) Failed to create a restore point.
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Software\Microsoft\Windows\CurrentVersion\Run\\News.net => value removed successfully
"C:\Program Files\News.net" => not found.
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => value removed successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000009" => key removed successfully
Winsock: -> Catalog5 - Broken internet access due to missing entry. <===== ATTENTION => Winsock will be renumbered.
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => value removed successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} => value removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1346D119-159F-2B54-51CC-ABEF9A4BE183}" => key removed successfully
HKCR\CLSID\{1346D119-159F-2B54-51CC-ABEF9A4BE183} => key not found. 
"HKCR\PROTOCOLS\Handler\viprotocol" => key removed successfully
HKCR\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} => key not found. 
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
Chrome StartupUrls => removed successfully
C:\Users\Tomton98\AppData\LocalLow\uTorrent => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C304234-609D-4CA2-9778-0287B37A9EEE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C304234-609D-4CA2-9778-0287B37A9EEE}" => key removed successfully
C:\Windows\System32\Tasks\RunAsStdUser => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RunAsStdUser" => key removed successfully
"C:\Program Files (x86)\Desk 365" => not found.
 
=========  ipconfig /flushdns =========
 
'ipconfig' is not recognized as an internal or external command,
operable program or batch file.
 
========= End of CMD: =========
 
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 189661345 B
Java, Flash, Steam htmlcache => 31578862 B
Windows/system/drivers => 2059469466 B
Edge => 0 B
Chrome => 121528921 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 144808 B
systemprofile32 => 26363021 B
LocalService => 0 B
NetworkService => 4944809 B
Tomton98 => 7213875015 B
GUEST DAWW => 21580210 B
 
RecycleBin => 0 B
EmptyTemp: => 9 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 10:49:26 ====
 
Yes, there are many games…At least the games he bought from steam. I have no idea about what he may have been torrenting, but he is 17 so it could be anything. The network connection icon is at least appearing now, but network and sharing center is completely blank now.
I restarted the computer again, the network symbol on the bottom right has the blue circle constantly frozen on it. It seems to be stalled, but at least it doesn't have the red x through it now. 
I am still getting the failed to connect to a windows service error
tried to run aswMBR again seems to get to scanning: service hamachi c:\windows\system32\DRIVERS\hamachi.sys then the avast Antirootkit has stopped working error appears

Well, kids will be kids, you gotta love im , have 4 myself.

 

 

All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
 
 
 
Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
 
  •  
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
 
 
[external image: MBAM220_zpsox89gdej.jpg]
 
  •  
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
 
# AdwCleaner v5.200 - Logfile created 28/06/2016 at 12:05:22
# Updated 14/06/2016 by ToolsLib
# Database : 2016-06-14.1 [Local]
# Operating system : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Tomton98 - TOMTON98-PC
# Running from : C:\Users\Tomton98\Desktop\AdwCleaner.exe
# Option : Clean
# Support : https://toolslib.net/forum
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
[-] Folder Deleted : C:\ProgramData\ShoppingChip
[#] Folder Deleted : C:\ProgramData\Application Data\ShoppingChip
[-] Folder Deleted : C:\Program Files (x86)\ShoppingChip
[-] Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
[-] Folder Deleted : C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar
[-] Folder Deleted : C:\Users\Tomton98\AppData\Local\AVG Secure Search
[-] Folder Deleted : C:\Users\GUEST DAWW\AppData\Local\AVG SafeGuard toolbar
[-] Folder Deleted : C:\Users\GUEST DAWW\AppData\LocalLow\AVG SafeGuard toolbar
[-] Folder Deleted : C:\extensions
 
***** [ Files ] *****
 
[-] File Deleted : C:\END
[-] File Deleted : C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejpbbhjlbipncjklfjjaedaieimbmdda
[-] File Deleted : C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
[-] File Deleted : C:\Windows\SysNative\roboot64.exe
 
***** [ DLLs ] *****
 
 
***** [ WMI ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IECT3306061
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_963508d2
[-] Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
[-] Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
[-] Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\driverscanner
[-] Key Deleted : HKLM\SOFTWARE\Classes\OCComSDK.ComSDK
[-] Key Deleted : HKLM\SOFTWARE\Classes\OCComSDK.ComSDK.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.Protector
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.Protector.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd
[-] Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
[-] Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
[-] Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
[-] Key Deleted : HKCU\Software\lucky leap
[-] Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Key Deleted : HKCU\Software\AppDataLow\SProtector
[-] Key Deleted : HKCU\Software\AppDataLow\Toolbar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
[-] Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
[-] Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
[-] Key Deleted : HKLM\SOFTWARE\{F2E9660B-98AF-42c0-8258-9CDDF07BF95D}
[-] Key Deleted : HKLM\SOFTWARE\InstallIQ
[-] Key Deleted : HKLM\SOFTWARE\lucky leap
[-] Key Deleted : HKLM\SOFTWARE\SP Global
[-] Key Deleted : HKLM\SOFTWARE\SProtector
[-] Key Deleted : HKLM\SOFTWARE\Uniblue
[-] Key Deleted : HKLM\SOFTWARE\V9
[-] Key Deleted : HKLM\SOFTWARE\systweak
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\lucky leap
 
***** [ Web browsers ] *****
 
[-] [C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : search.conduit.com
[-] [C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : search.babylon.com
[-] [C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : isearch.avg.com
[-] [C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : mysearch.avg.com
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C1].txt - [8252 bytes] - [28/06/2016 12:05:22]
C:\AdwCleaner\AdwCleaner[S1].txt - [8443 bytes] - [28/06/2016 12:03:29]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [8398 bytes] ##########
cant get malware bytes to install yet, going to keep trying will edit when i have done it
should i try in safe mode?
i got it to install in safe mode…going to do a scan out of safe mode, i cant update it as i still have no working internet connection on the laptop. will not open out of safe mode, just stalls
malware antibytes results(safemode is all i can get it to work on)
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 28/06/2016
Scan Time: 1:00 PM
Logfile: 
Administrator: Yes
 
Version: 2.2.1.1043
Malware Database: v2016.02.16.06
Rootkit Database: v2016.02.08.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Tomton98
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 450444
Time Elapsed: 43 min, 2 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 16
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\TYPELIB\{E2343056-CC08-46AC-B898-BFC7ACF4E755}, , [1452e081cccdd6604abc208458aa3fc1], 
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\INTERFACE\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}, , [1452e081cccdd6604abc208458aa3fc1], 
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\INTERFACE\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}, , [1452e081cccdd6604abc208458aa3fc1], 
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\INTERFACE\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}, , [1452e081cccdd6604abc208458aa3fc1], 
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E2343056-CC08-46AC-B898-BFC7ACF4E755}, , [1452e081cccdd6604abc208458aa3fc1], 
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{E2343056-CC08-46AC-B898-BFC7ACF4E755}, , [1452e081cccdd6604abc208458aa3fc1], 
PUP.Optional.uTorrentControl, HKU\S-1-5-21-1821522787-3724074743-2321965764-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{7473B6BD-4691-4744-A82B-7854EB3D70B6}, , [471f3f220b8e4cea99cb28796d95837d], 
PUP.Optional.uTorrentControl, HKU\S-1-5-21-1821522787-3724074743-2321965764-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{7473B6BD-4691-4744-A82B-7854EB3D70B6}, , [471f3f220b8e4cea99cb28796d95837d], 
PUP.Optional.ShoppingChip, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1D2ABF6A-2B19-3E94-0991-5B5BDB7134DA}, , [72f46ff22f6a6ec89de04437f50dc838], 
PUP.Optional.ShoppingChip, HKLM\SOFTWARE\CLASSES\ShoppingChip.ShoppingChip, , [cf9775ec9efb43f3cfa915a4768d14ec], 
PUP.Optional.ShoppingChip, HKLM\SOFTWARE\CLASSES\ShoppingChip.ShoppingChip.1.1, , [91d5cb96cecb33032c4c229733d003fd], 
PUP.Optional.ShoppingChip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShoppingChip.ShoppingChip, , [97cfd38eaced171fff79bcfd6f94867a], 
PUP.Optional.ShoppingChip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShoppingChip.ShoppingChip.1.1, , [5f07c49d1d7c5fd77800a81111f26e92], 
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6A90F216-A04C-40E5-8129-F9611EFCBF93}, , [8bdb94cdd9c0be78d7204099b74c7e82], 
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DAC77720-0949-4349-A6B1-E9DB370B8592}, , [1452421f95046dc9ea0d5b7e7e856b95], 
PUP.Optional.BreakingNews, HKU\S-1-5-18\SOFTWARE\News.net, , [471fc9982e6b0a2c2b0221b339ca837d], 
 
Registry Values: 4
PUP.Optional.uTorrentControl, HKU\S-1-5-21-1821522787-3724074743-2321965764-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{7473B6BD-4691-4744-A82B-7854EB3D70B6}, ½¶st‘FDG¨+xTë=p¶, , [471f3f220b8e4cea99cb28796d95837d]
PUP.Optional.uTorrentControl, HKU\S-1-5-21-1821522787-3724074743-2321965764-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{7473B6BD-4691-4744-A82B-7854EB3D70B6}, , [4a1ccf928a0f00364d17564b9d65d729], 
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6A90F216-A04C-40E5-8129-F9611EFCBF93}|AppPath, C:\Users\Tomton98\AppData\Local\Conduit\CT3220468, , [8bdb94cdd9c0be78d7204099b74c7e82]
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DAC77720-0949-4349-A6B1-E9DB370B8592}|AppPath, C:\Users\Tomton98\AppData\Local\Conduit\CT3306061, , [1452421f95046dc9ea0d5b7e7e856b95]
 
Registry Data: 1
PUP.Optional.Conduit, HKU\S-1-5-21-1821522787-3724074743-2321965764-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://search.conduit.com?SearchSource=10&ctid=CT3220468, Good: (www.google.com), Bad: (http://search.conduit.com?SearchSource=10&ctid=CT3220468),,[c2a45f02f6a3a393652e588d4bb9d32d]
 
Folders: 39
PUP.Optional.Conduit, C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejpbbhjlbipncjklfjjaedaieimbmdda, , [194d4120b0e957df2e22f3d5ca3821df], 
PUP.Optional.ConnectDLC, C:\Program Files (x86)\Connect_DLC_5, , [1155253c5049d95dc5b646824db5fa06], 
PUP.Optional.ConnectDLC, C:\Users\Tomton98\AppData\LocalLow\Connect_DLC_5, , [3135bea3257469cddf9e92367191926e], 
PUP.Optional.ConnectDLC, C:\Users\Tomton98\AppData\LocalLow\Connect_DLC_5\Logs, , [3135bea3257469cddf9e92367191926e], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\AddedAppDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\DefualtImages, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\DetectedAppDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\EngineFirstTimeDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\images, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\Images, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarUntrustedAppsApprovalDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\UninstallDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAddedAppDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppApprovalDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppPendingDialog, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\EmailNotifier, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\ExternalComponent, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Logs, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\MyStuffApps, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\AppsMetaData, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\DynamicDialogs, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarLogin, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarSettings, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\ToolbarTranslation, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\SearchInNewTab, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
 
Files: 119
PUP.Optional.InstallCore, C:\Users\Tomton98\Downloads\CR_Downloader_for_desmume (1).exe, , [0b5bca97128765d17d96022bf80836ca], 
PUP.Optional.InstallCore, C:\Users\Tomton98\Downloads\CR_Downloader_for_desmume.exe, , [5016c29fdabf82b49e75db522bd511ef], 
PUP.Optional.InstallCore, C:\Users\Tomton98\Downloads\CR_Downloader_for_no$gba.exe, , [5a0cf0710198e353848fa984ca36bd43], 
PUP.Optional.InstallIQ, C:\Users\Tomton98\Downloads\vioplayer2_d3993239.exe, , [7beba5bcf7a290a6e00c980ed828629e], 
PUP.Optional.ConnectDLC, C:\Users\Tomton98\AppData\LocalLow\Connect_DLC_5\hk64tbConn.dll, , [3135bea3257469cddf9e92367191926e], 
PUP.Optional.ConnectDLC, C:\Users\Tomton98\AppData\LocalLow\Connect_DLC_5\hktbConn.dll, , [3135bea3257469cddf9e92367191926e], 
PUP.Optional.ConnectDLC, C:\Users\Tomton98\AppData\LocalLow\Connect_DLC_5\ldrtbConn.dll, , [3135bea3257469cddf9e92367191926e], 
PUP.Optional.ConnectDLC, C:\Users\Tomton98\AppData\LocalLow\Connect_DLC_5\tbConn.dll, , [3135bea3257469cddf9e92367191926e], 
PUP.Optional.ConnectDLC, C:\Users\Tomton98\AppData\LocalLow\Connect_DLC_5\toolbar.cfg, , [3135bea3257469cddf9e92367191926e], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\ldrtbuTor.dll, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\tbuTor.dll, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\ThirdPartyComponents.xml, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\toolbar.cfg, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_SearchEngines_images_search_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_SearchEngines_news_icon_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_searchengines_search_icon_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_searchengines_softonic_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_SearchEngines_tfd_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_SearchEngines_video_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_clear_history_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_contact_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_help_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_home_page_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_options_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_privacy_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_refresh_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_shrink_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_tell_a_friend_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_53_307_CT3072253_Images_634520779497696087_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_About_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Browse_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Contact_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Hide_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_LikeIcon_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_MoreFromPublisher_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_More_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Options_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Privacy_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Refresh_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Upgrade_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_eula_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_53_307_CT3072253_images_634514692184142958_20PX_png.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_about_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\CacheIcons\http___storage_conduit_com_images_main_menu_upgrade_gif.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\RoundedCornersIE9.css, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\DialogsAPI.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\excanvas.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\generalDialogStyle.css, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\PIE.htc, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\RoundedCorners.css, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\settings.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\version.txt, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\AddedAppDialog\app-added.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\AddedAppDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\DefualtImages\icon.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\DetectedAppDialog\app-2go.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\DetectedAppDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\EngineFirstTimeDialog\EngineFirstTimeDialog.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\EngineFirstTimeDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\EngineFirstTimeDialog\right-click.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\SearchProtector.css, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\SearchProtector.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\images\ok-button.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\images\separation-line.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\NewSearchProtectorDialog\images\warning.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\bubble.css, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\bubble.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images\information.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images\x-default-LTR.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images\x-default-RTL.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-LTR.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-RTL.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\SearchProtector.css, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\SearchProtector.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\Images\info.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\Images\ok-on.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorDialog\Images\ok.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\SearchProtectorRetakeover.css, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\SearchProtectorRetakeover.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\Icon.jpg, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\Icon.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\info.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\ok-on.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\SearchProtectorRetakeoverDialog\Images\ok.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.css, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\app-store-icon.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\arrow.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\divider.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\emailNotifier.gif, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\facebook.png, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\radio.GIF, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\Thumbs.db, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\truste_welcome.GIF, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarFirstTimeDialog\images\weather.GIF, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarUntrustedAppsApprovalDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\ToolbarUntrustedAppsApprovalDialog\ToolbarUntrustedAppsApprovalDialog.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAddedAppDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAddedAppDialog\UT-app-dialog-added.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppApprovalDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppApprovalDialog\UT-app-dialog-needs-your-approval.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppPendingDialog\main.html, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Dialogs\UntrustedAppPendingDialog\UT-app-dialog-is-waiting.js, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=GottenApps&locale=en.xml, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=OtherApps&locale=en.xml, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=SharedApps&locale=en.xml, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=Toolbar&locale=en.xml, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\AppsMetaData\data.bck.txt, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\AppsMetaData\data.txt, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\DynamicDialogs\data.txt, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarLogin\data.txt, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_CT3220468\ToolbarSettings\data.txt, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\Repository\conduit_CT3220468_en\ToolbarTranslation\data.txt, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
PUP.Optional.uTorrentControl, C:\Users\GUEST DAWW\AppData\LocalLow\uTorrentControl_v2\SearchInNewTab\SearchInNewTabContent.xml, , [b0b6cb960b8ed85e6bda34b31ee4e11f], 
 
Physical Sectors: 0
(No malicious items detected)
 
What would you like me to do now?   Thanks again for all your help

Good Morning

 

Did you have Malwarebytes remove all those entries, there bad and need to go . The log should show them all as Quarantined and it does not.  

 

Run the program again
 
  • You can highlight one of the detections by left clicking on it.
  • Then, right click on the highlighted detection, and select 'Check All Items'.
  • Next, click 'Remove Selected'. That should remove them all
  • thank you i will try that again, i did tick the boxes and hit remove selected.

    I just ran malware again it is showing no detections and is working in normal mode also

    still problem with the windows services error though.

     

    What would you like me to do next?

    By the way its night time here 830pm AEST. Im in Australia… and it was my birthday today! hahaha…thanks for your help

    Well then, Happy Birthday , enjoy your day :)

     

    Open up FRST by right clicking on it and selecting RUN AS ADMINISTRATOR. Make sure there is a checkmark in ADDITIONS, leave everything else as is. Click on Scan and post both new logs please

    seems to have frozen on scanning restore points…will wait, but green bar not moving.

    I think its frozen, won't minimise. Im trying again, It hung on trying to start eventlog…now says not responding.

    3rd time got stuck on scanning restore points

    i better leave this until the morning. I will try again then. I will just let this go to see if it unfreezes eventually…doubt it though

    Thanks for your help again today Ken, will definately use the paypal donate option once this is done

    just checked before i went to bed and it has unfrozen so here you goScan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-06-2016 02

    Ran by [removed] (administrator) on TOMTON98-PC (28-06-2016 20:58:56)
    Running from C:\Users\[removed]\Desktop
    [removed]
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
     
    ==================== Processes (Whitelisted) =================
     
    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
     
    (AMD) C:\Windows\System32\atiesrxx.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
    (Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\CxUtilSvc.exe
    (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
    (Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
    () C:\Windows\SysWOW64\PnkBstrA.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
    (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
    (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
    (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
    () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
    (Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\SmartAudio3.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
    (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
    () C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe
    (Facebook Inc.) C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
    (Facebook Inc.) C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe
    (GoPro) C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
    (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\Grid64.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
    (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
    (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
    (Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\SmartAudio3.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
    (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    (Nero AG) C:\Program Files (x86)\Nero\SyncUP\SyncUP.exe
    (Nero AG) C:\Program Files (x86)\Nero\SyncUP\Nero.AndroidServer.exe
     
     
    ==================== Registry (Whitelisted) ===========================
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
     
    HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2878728 2014-04-17] (ELAN Microelectronics Corp.)
    HKLM\…\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5729648 2012-02-08] (Dell Inc.)
    HKLM\…\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
    HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SA3\SACpl.exe [1628288 2011-09-09] (Conexant Systems, Inc.)
    HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
    HKLM\…\Run: [IntelliType Pro] => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation)
    HKLM\…\Run: [IntelliPoint] => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation)
    HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-09-23] (Apple Inc.)
    HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-30] (Intel Corporation)
    HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-17] (Intel Corporation)
    HKLM-x32\…\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [503942 2011-04-14] (Creative Technology Ltd)
    HKLM-x32\…\Run: [Dell DataSafe Online] => C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-26] (Dell, Inc.)
    HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2015-06-27] (Adobe Systems Incorporated)
    HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-20] (Adobe Systems Incorporated)
    HKLM-x32\…\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    HKLM-x32\…\Run: [NeroLauncher] => C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe [67496 2012-08-21] ()
    HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-09-23] (Apple Inc.)
    HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-07-23] (Advanced Micro Devices, Inc.)
    HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
    HKLM-x32\…\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2016-04-05] (LogMeIn Inc.)
    Winlogon\Notify\igfxcui: igfxdev.dll [X]
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-04-30] (Valve Corporation)
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3619160 2015-01-28] (Electronic Arts)
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [RGSC] => C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-07-23] (AMD)
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Grid] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe [401408 2013-07-23] ()
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Facebook Update] => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-01-12] (Facebook Inc.)
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50670720 2016-03-01] (Skype Technologies S.A.)
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\MountPoints2: {c1049b66-68da-11e2-8874-685d432459a0} - E:\setup_vmb_lite.exe /checkApplicationPresence
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\MountPoints2: {c1049b6c-68da-11e2-8874-685d432459a0} - E:\setup_vmb_lite.exe /checkApplicationPresence
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
    ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
    Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.0.lnk [2012-05-16]
    ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CineForm Status.lnk [2014-01-10]
    ShortcutTarget: CineForm Status.lnk -> C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe (GoPro)
    Startup: C:\Users\GUEST DAWW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.0.lnk [2012-05-16]
    ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
     
    ==================== Internet (Whitelisted) ====================
     
    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
     
    Tcpip\..\Interfaces\{D8A27A5F-3916-43BC-B7D9-A5FAAE7F9BC8}: [NameServer] 10.143.147.147 10.143.147.148
     
    Internet Explorer:
    ==================
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKLM -> {7F8CCD3E-6F4E-4BA1-9F04-908D189BA03F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDR&src;=IE-SearchBox
    SearchScopes: HKLM-x32 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
    SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
    SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
    SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
    SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> {7F8CCD3E-6F4E-4BA1-9F04-908D189BA03F} URL = 
    BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-03-27] (Oracle Corporation)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22] (Microsoft Corp.)
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-06] (Google Inc.)
    BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
    BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-03-27] (Oracle Corporation)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22] (Microsoft Corp.)
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-06] (Google Inc.)
    BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
    Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-06] (Google Inc.)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-06] (Google Inc.)
    DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-02-01] (Skype Technologies)
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
    Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
    Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
    Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
    Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
     
    FireFox:
    ========
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-13] ()
    FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-03-27] (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-03-27] (Oracle Corporation)
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-13] ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
    FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-04] (ESN Social Software AB)
    FF Plugin-x32: @esn/esnlaunch,version=2.1.3 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll [No File]
    FF Plugin-x32: @esn/esnlaunch,version=2.1.7 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll [2013-05-30] (ESN Social Software AB)
    FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-12-10] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
    FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-09-07] (Pando Networks)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
    FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-06-27] (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Tomton98\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
    FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Tomton98\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [No File]
    FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-09-07] (Pando Networks)
    FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-04-12] (Ubisoft)
     
    Chrome: 
    =======
    CHR Profile: C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Drive) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
    CHR Extension: (YouTube) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
    CHR Extension: (Google Search) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
    CHR Extension: (Google Docs Offline) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-01]
    CHR Extension: (Avast Online Security) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-04-09]
    CHR Extension: (Skype) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-05-25]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-04]
    CHR Extension: (Gmail) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-31]
    CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
     
    ==================== Services (Whitelisted) ========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [802688 2015-01-22] ()
    R2 CxUtilSvc; C:\Program Files\Conexant\SA3\CxUtilSvc.exe [109184 2011-10-12] (Conexant Systems, Inc.)
    S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [174624 2015-01-17] (EasyAntiCheat Ltd)
    R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2016-04-05] (LogMeIn, Inc.)
    S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-09] ()
    S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2120712 2016-06-01] (Electronic Arts)
    R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-02-28] ()
    R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
    S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-09] (Intel® Corporation)
    S2 Hamachi2Svc; no ImagePath
    S3 WinHttpAutoProxySvc; winhttp.dll [X]
     
    ===================== Drivers (Whitelisted) ==========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [36096 2013-05-22] (Advanced Micro Devices, Inc.)
    S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-11] (Broadcom Corporation)
    S3 ZTEusbwwan; C:\Windows\System32\DRIVERS\ZTEusbwwan.sys [235520 2010-06-10] (ZTE Incorporated)
     
    ==================== NetSvcs (Whitelisted) ===================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
     
    ==================== One Month Created files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2016-06-28 20:55 - 2016-06-28 20:55 - 00038289 _____ C:\Users\Tomton98\Desktop\Addition.txt
    2016-06-28 20:25 - 2016-06-28 20:25 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\ATI
    2016-06-28 20:25 - 2016-06-28 20:25 - 00000000 ____D C:\Users\Administrator\AppData\Local\ATI
    2016-06-28 20:20 - 2016-06-28 20:23 - 00000000 ____D C:\Users\Administrator\AppData\Local\LogMeIn Hamachi
    2016-06-28 20:20 - 2016-06-28 20:20 - 00088248 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
    2016-06-28 20:20 - 2016-06-28 20:20 - 00001375 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2016-06-28 20:20 - 2016-06-28 20:20 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Intel Corporation
    2016-06-28 20:20 - 2016-06-28 20:20 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Creative
    2016-06-28 20:20 - 2016-06-28 20:20 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Apple Computer
    2016-06-28 20:20 - 2016-06-28 20:20 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
    2016-06-28 20:20 - 2016-06-28 20:20 - 00000000 ____D C:\Users\Administrator\AppData\Local\LogMeIn
    2016-06-28 20:20 - 2016-06-28 20:20 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
    2016-06-28 20:20 - 2016-06-28 20:20 - 00000000 ____D C:\Users\Administrator\AppData\Local\Conexant
    2016-06-28 20:04 - 2016-06-28 20:20 - 00000000 ____D C:\Users\Administrator
    2016-06-28 20:04 - 2016-06-28 20:04 - 00000020 ___SH C:\Users\Administrator\ntuser.ini
    2016-06-28 20:04 - 2016-06-28 20:04 - 00000000 _SHDL C:\Users\Administrator\My Documents
    2016-06-28 20:04 - 2016-06-28 20:04 - 00000000 _SHDL C:\Users\Administrator\Documents\My Videos
    2016-06-28 20:04 - 2016-06-28 20:04 - 00000000 _SHDL C:\Users\Administrator\Documents\My Pictures
    2016-06-28 20:04 - 2016-06-28 20:04 - 00000000 _SHDL C:\Users\Administrator\Documents\My Music
    2016-06-28 20:04 - 2016-06-28 20:04 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Intel
    2016-06-28 20:04 - 2016-06-28 20:04 - 00000000 ____D C:\Users\Administrator\AppData\Local\SoftThinks
    2016-06-28 20:04 - 2012-05-16 20:04 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia
    2016-06-28 20:04 - 2010-11-21 17:16 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Media Center Programs
    2016-06-28 14:05 - 2016-06-28 14:05 - 00001538 _____ C:\Users\Tomton98\Desktop\aswMBR.txt
    2016-06-28 14:05 - 2016-06-28 14:05 - 00000512 _____ C:\Users\Tomton98\Desktop\MBR.dat
    2016-06-28 13:51 - 2016-06-28 13:51 - 00032147 _____ C:\Users\Tomton98\Desktop\malware antibytes results.txt
    2016-06-28 12:43 - 2016-06-28 20:22 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2016-06-28 12:42 - 2016-06-28 12:42 - 00001108 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2016-06-28 12:42 - 2016-06-28 12:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2016-06-28 12:42 - 2016-06-28 12:42 - 00000000 ____D C:\ProgramData\Malwarebytes
    2016-06-28 12:42 - 2016-06-28 12:42 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2016-06-28 12:42 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2016-06-28 12:42 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
    2016-06-28 12:42 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
    2016-06-28 12:16 - 2016-06-28 12:03 - 22851472 _____ (Malwarebytes ) C:\Users\Tomton98\Desktop\mbam-setup-2.2.1.1043.exe
    2016-06-28 12:03 - 2016-06-28 12:05 - 00000000 ____D C:\AdwCleaner
    2016-06-28 12:03 - 2016-06-28 11:59 - 03703360 _____ C:\Users\Tomton98\Desktop\AdwCleaner.exe
    2016-06-28 10:46 - 2016-06-28 10:49 - 00005395 _____ C:\Users\Tomton98\Desktop\Fixlog.txt
    2016-06-28 07:07 - 2016-06-28 20:54 - 00038033 _____ C:\Users\Tomton98\Desktop\FRST1 (2).txt
    2016-06-28 07:06 - 2016-06-28 20:58 - 00025066 _____ C:\Users\Tomton98\Desktop\FRST.txt
    2016-06-28 07:06 - 2016-06-28 20:54 - 00036310 _____ C:\Users\Tomton98\Desktop\FRST1 (1).txt
    2016-06-28 07:06 - 2016-06-28 20:48 - 00000000 ____D C:\FRST
    2016-06-28 07:04 - 2016-06-28 06:59 - 05198336 _____ (AVAST Software) C:\Users\Tomton98\Desktop\aswMBR.exe
    2016-06-28 07:04 - 2016-06-28 06:58 - 02389504 _____ (Farbar) C:\Users\Tomton98\Desktop\FRST64.exe
    2016-06-27 23:24 - 2016-06-27 23:24 - 00000000 ____D C:\Users\Tomton98\Documents\Add-in Express
    2016-06-27 22:51 - 2016-06-27 22:49 - 01610816 _____ (Malwarebytes) C:\Users\Tomton98\Desktop\JRT (1).exe
    2016-06-27 22:39 - 2016-06-27 22:39 - 00000000 ____D C:\Qoobox
    2016-06-27 22:38 - 2016-06-27 22:38 - 00000000 ____D C:\Windows\erdnt
    2016-06-27 22:38 - 2016-06-27 22:34 - 05659224 ____R (Swearware) C:\Users\Tomton98\Desktop\,hgj.exe
    2016-06-27 20:30 - 2016-06-27 21:40 - 00000000 ____D C:\Windows\pss
    2016-06-27 17:30 - 2016-06-27 17:30 - 00283344 _____ C:\Windows\Minidump\062716-21481-01.dmp
    2016-06-27 16:20 - 2016-06-27 17:26 - 00000271 _____ C:\WirelessDiagLog.csv
    2016-06-24 15:29 - 2016-06-24 15:30 - 00000000 ____D C:\Users\Tomton98\Desktop\bomb 23.06.2016
    2016-06-02 17:30 - 2016-06-02 17:30 - 00010312 ____N C:\bootsqm.dat
    2016-05-31 15:54 - 2016-06-01 16:51 - 00003034 _____ C:\Windows\System32\Tasks\EVGAPrecision
     
    ==================== One Month Modified files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2016-06-28 20:35 - 2012-12-10 14:29 - 00000000 ____D C:\Users\Tomton98\AppData\Local\Nero
    2016-06-28 20:23 - 2014-12-19 00:22 - 00000000 ____D C:\Users\Tomton98\AppData\Local\LogMeIn Hamachi
    2016-06-28 20:20 - 2012-12-11 14:29 - 00000000 ____D C:\Program Files (x86)\Steam
    2016-06-28 20:20 - 2009-07-14 14:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2016-06-28 20:19 - 2012-05-16 19:42 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
    2016-06-28 20:04 - 2012-05-16 19:52 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
    2016-06-28 20:04 - 2012-05-16 19:52 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
    2016-06-28 19:40 - 2009-07-14 14:45 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2016-06-28 19:40 - 2009-07-14 14:45 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2016-06-28 19:00 - 2014-03-10 19:44 - 00000000 ____D C:\ProgramData\AVAST Software
    2016-06-28 18:37 - 2013-02-22 14:30 - 01339902 _____ C:\Windows\ntbtlog.txt
    2016-06-28 13:54 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\PLA
    2016-06-28 10:47 - 2012-12-19 21:11 - 00000000 ____D C:\Users\Tomton98\AppData\LocalLow\Temp
    2016-06-28 10:46 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\system32\GroupPolicy
    2016-06-28 04:07 - 2013-04-15 10:42 - 00000000 ____D C:\Program Files\WinRAR
    2016-06-27 23:26 - 2013-11-04 19:48 - 00000000 ____D C:\Program Files\HitmanPro
    2016-06-27 23:21 - 2012-12-19 21:10 - 00000000 ____D C:\Users\Tomton98\AppData\Roaming\uTorrent
    2016-06-27 22:37 - 2009-07-14 15:13 - 00782288 _____ C:\Windows\system32\PerfStringBackup.INI
    2016-06-27 22:37 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\inf
    2016-06-27 22:20 - 2012-12-17 20:35 - 00000000 ____D C:\Program Files (x86)\Origin
    2016-06-27 19:46 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
    2016-06-27 19:46 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\system32\Dism
    2016-06-27 17:30 - 2013-04-14 10:51 - 655389053 _____ C:\Windows\MEMORY.DMP
    2016-06-27 17:30 - 2013-04-14 10:51 - 00000000 ____D C:\Windows\Minidump
    2016-06-27 16:29 - 2013-10-06 14:34 - 00000000 ____D C:\Users\Tomton98\AppData\Local\ElevatedDiagnostics
    2016-06-24 15:29 - 2015-04-15 21:34 - 00000000 ____D C:\Users\Tomton98\AppData\Local\Windows Live
    2016-06-24 15:28 - 2015-08-26 20:37 - 00000000 ____D C:\Users\Tomton98\AppData\Roaming\vlc
    2016-06-22 19:00 - 2012-05-16 19:46 - 00000000 ____D C:\ProgramData\Temp
    2016-06-01 22:58 - 2012-05-16 19:13 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2016-06-01 22:31 - 2014-01-12 21:26 - 00000940 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001UA.job
    2016-06-01 22:31 - 2014-01-12 21:26 - 00000918 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001Core.job
    2016-06-01 22:27 - 2012-12-12 06:37 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2016-06-01 16:47 - 2012-12-12 06:37 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2016-06-01 16:46 - 2009-07-14 15:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2016-05-31 15:12 - 2014-03-10 19:46 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
     
    ==================== Files in the root of some directories =======
     
    2013-03-10 13:59 - 2015-03-26 20:43 - 0009728 _____ () C:\Users\Tomton98\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2013-03-17 15:11 - 2013-03-17 15:11 - 0004096 ____H () C:\Users\Tomton98\AppData\Local\keyfile3.drm
    2013-03-17 15:50 - 2015-01-22 23:22 - 0007601 _____ () C:\Users\Tomton98\AppData\Local\resmon.resmoncfg
    2015-09-18 13:38 - 2015-09-18 13:38 - 0000000 _____ () C:\Users\Tomton98\AppData\Local\{265DA060-8805-4A19-A71F-E4B342EA3713}
    2016-01-15 11:51 - 2016-01-15 11:53 - 0000000 _____ () C:\Users\Tomton98\AppData\Local\{AE64DE04-EC8A-4EF3-A4BA-4AED777EE961}
    2015-01-28 21:09 - 2015-01-28 21:09 - 0000000 _____ () C:\Users\Tomton98\AppData\Local\{FB802408-E561-4C5E-B4A9-40E3C118C883}
     
    Some files in TEMP:
    ====================
    C:\Users\Tomton98\AppData\Local\Temp\libeay32.dll
    C:\Users\Tomton98\AppData\Local\Temp\msvcr120.dll
    C:\Users\Tomton98\AppData\Local\Temp\sqlite3.dll
     
     
    ==================== Bamital & volsnap =================
     
    (There is no automatic fix for files that do not pass verification.)
     
    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll => File is digitally signed
    C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
     
     
    ATTENTION: ==> Could not access BCD. 
     
     
    LastRegBack: 2016-05-28 01:15
     
    ==================== End of FRST.txt ============================
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-06-2016 02
    Ran by [removed] (2016-06-28 20:59:13)
    Running from C:\Users\[removed]\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) (2012-12-10 04:13:49)
    Boot Mode: Normal
    ==========================================================
     
     
    ==================== Accounts: =============================
     
    Administrator (S-1-5-21-1821522787-3724074743-2321965764-500 - Administrator - Enabled) => C:\Users\Administrator
    Guest (S-1-5-21-1821522787-3724074743-2321965764-501 - Limited - Disabled)
    GUEST DAWW (S-1-5-21-1821522787-3724074743-2321965764-1003 - Limited - Enabled) => C:\Users\GUEST DAWW
    HomeGroupUser$ (S-1-5-21-1821522787-3724074743-2321965764-1002 - Limited - Enabled)
    Tomton98 (S-1-5-21-1821522787-3724074743-2321965764-1001 - Administrator - Enabled) => C:\Users\Tomton98
     
    ==================== Security Center ========================
     
    (If an entry is included in the fixlist, it will be removed.)
     
    AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
     
    ==================== Installed Programs ======================
     
    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
     
    Addon Sync 2009 (HKLM-x32\…\{4E3AA543-09D7-401E-9DF2-2591D24C7C49}) (Version: 1.0.67 - YomaTools)
    Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
    Adobe Flash Player 21 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 21.0.0.242 - Adobe Systems Incorporated)
    Adobe Flash Player 21 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated)
    Adobe Reader X (10.1.15) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.15 - Adobe Systems Incorporated)
    Advanced Audio FX Engine (HKLM-x32\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
    AMD Catalyst Install Manager (HKLM\…\{3CB2E87A-33CC-8E5A-2D3F-E9ACDE622704}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
    Apple Application Support (32-bit) (HKLM-x32\…\{A50679D9-6CBD-4FCD-BACB-62EF3894F6F3}) (Version: 4.0.3 - Apple Inc.)
    Apple Application Support (64-bit) (HKLM\…\{1F72FDD5-A069-45B4-928F-D0F16492DC69}) (Version: 4.0.3 - Apple Inc.)
    Apple Mobile Device Support (HKLM\…\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)
    Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
    Arma 2 (HKLM-x32\…\Steam App 33910) (Version:  - Bohemia Interactive)
    ARMA 2 Operation Arrowhead Uninstall (HKLM-x32\…\ARMA 2 Operation Arrowhead) (Version:  - )
    ArmA 2 Uninstall (HKLM-x32\…\ArmA 2) (Version:  - )
    Arma 2: Operation Arrowhead (HKLM-x32\…\Steam App 33930) (Version:  - Bohemia Interactive)
    Arma 3 Alpha (HKLM-x32\…\Steam App 107410) (Version:  - Bohemia Interactive)
    Arma 3 Alpha Lite (HKLM-x32\…\Steam App 228800) (Version:  - Bohemia Interactive)
    Arma: Cold War Assault (HKLM-x32\…\Steam App 65790) (Version:  - Bohemia Interactive)
    Battlefield 3™ (HKLM-x32\…\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.5.0.0 - Electronic Arts)
    Battlelog Web Plugins (HKLM-x32\…\Battlelog Web Plugins) (Version: 2.1.7 - EA Digital Illusions CE AB)
    BattlEye for OA Uninstall (HKLM-x32\…\BattlEye for OA) (Version:  - )
    BattlEye Uninstall (HKLM-x32\…\BattlEye for A2) (Version:  - )
    BioShock (HKLM-x32\…\{E280923D-C5D9-4728-8C79-AC9A0DC75875}) (Version: 2.5.0000 - 2K Games)
    Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
    Canon MP550 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP550_series) (Version:  - )
    Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
    Chivalry: Medieval Warfare (HKLM-x32\…\Steam App 219640) (Version:  - Torn Banner Studios)
    Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Conexant SmartAudio HD (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.54.29.0 - Conexant)
    Counter-Strike: Global Offensive (HKLM-x32\…\Steam App 730) (Version:  - Valve)
    Counter-Strike: Source (HKLM-x32\…\Steam App 240) (Version:  - Valve)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    DayZ (HKLM-x32\…\Steam App 221100) (Version:  - Bohemia Interactive)
    DayZ Commander (HKLM-x32\…\{BAD8395E-CE31-44AA-B9FE-A14FCD0ABE4A}) (Version: 0.9.110 - Dotjosh Studios)
    Dead Space™ 3 (HKLM-x32\…\{D4329609-4102-4F8C-B83F-7FE024EEA314}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
    Dell Data Vault (Version: 4.3.4.0 - Dell Inc.) Hidden
    Dell DataSafe Local Backup - Support Software (HKLM-x32\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.67 - Dell Inc.)
    Dell DataSafe Local Backup (HKLM-x32\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.67 - Dell Inc.)
    Dell DataSafe Online (HKLM-x32\…\{7EC66A95-AC2D-4127-940B-0445A526AB2F}) (Version: 2.1.19634 - Dell)
    Dell Edoc Viewer (HKLM\…\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
    Dell Getting Started Guide (HKLM-x32\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
    Dell SupportAssistAgent (HKLM-x32\…\{287348C8-8B47-4C36-AF28-441A3B7D8722}) (Version: 1.1.0.47 - Dell)
    Dell Touchpad (HKLM\…\Elantech) (Version: 11.3.16.1 - ELAN Microelectronic Corp.)
    Dell Update (HKLM-x32\…\{90437913-9D4D-4D9D-B438-B8664DF851E9}) (Version: 1.7.1007.0 - Dell Inc.)
    Dell Webcam Central (HKLM-x32\…\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd)
    Dropbox (HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
    eBay (HKLM-x32\…\{A8B88634-7F90-402F-B66A-86429755F6A5}) (Version: 1.4.0 - eBay Inc.)
    ESN Sonar (HKLM-x32\…\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
    EVGA Precision X 4.2.1 (HKLM-x32\…\PrecisionX) (Version: 4.2.1 - EVGA Corporation)
    Facebook Video Calling 3.1.0.521 (HKLM-x32\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
    Fallout 3 (HKLM-x32\…\Steam App 22300) (Version:  - Bethesda Game Studios)
    Fallout: New Vegas (HKLM-x32\…\Steam App 22380) (Version:  - Obsidian Entertainment)
    Far Cry 3 (HKLM-x32\…\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
    Fraps (remove only) (HKLM-x32\…\Fraps) (Version:  - )
    Game Dev Tycoon (HKLM-x32\…\Steam App 239820) (Version:  - Greenheart Games)
    Garry's Mod (HKLM-x32\…\Steam App 4000) (Version:  - Garry)
    Google Chrome (HKLM-x32\…\Google Chrome) (Version: 50.0.2661.102 - Google Inc.)
    Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7619.1252 - Google Inc.)
    Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden
    GoPro Studio 2.0.0 (HKLM-x32\…\GoPro Studio) (Version: 2.0.0 - WoodmanLabs Inc. d.b.a. GoPro)
    Gotham City Impostors: Free To Play (HKLM-x32\…\Steam App 206210) (Version:  - )
    Grand Theft Auto IV (HKLM-x32\…\GFWL_{5454083B-632A-4F1D-9CED-3D1000008600}) (Version: 1.0.0000.134 - Rockstar Games Inc)
    Grand Theft Auto IV (x32 Version: 1.0.0000.134 - Rockstar Games Inc) Hidden
    Grand Theft Auto IV (x32 Version: 1.0.0005.134 - Rockstar Games Inc.) Hidden
    Grand Theft Auto: San Andreas (HKLM-x32\…\Steam App 12120) (Version:  - Rockstar Games)
    GTA San Andreas (HKLM-x32\…\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
    Guns of Icarus Online (HKLM-x32\…\Steam App 209080) (Version:  - Muse Games)
    Heroes & Generals (HKLM-x32\…\Steam App 227940) (Version:  - Reto-Moto)
    Hitman: Absolution (HKLM-x32\…\Steam App 203140) (Version:  - IO Interactive)
    Hitman: Sniper Challenge (HKLM-x32\…\Steam App 205930) (Version:  - IO Interactive)
    HydraVision (x32 Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden
    iCloud (HKLM\…\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
    Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
    Intel(R) Display Audio Driver (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3090 - Intel Corporation)
    Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.1.1399 - Intel Corporation)
    Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\…\{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}) (Version: 15.0.0.0059 - Intel Corporation)
    Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\…\{F0932859-AA60-459E-B843-0BDECA34E2C7}) (Version: 2.0.0.0086 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
    Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\…\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel)
    Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
    Intel(R) WiDi (HKLM-x32\…\{7FCB8D5D-9396-4D17-8CFA-349D6D49CD32}) (Version: 3.0.13.0 - Intel Corporation)
    Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
    Intel® PROSet/Wireless WiFi Software (HKLM\…\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation)
    Intel® Trusted Connect Service Client (HKLM\…\{538B98C3-773F-4F20-9C66-802D104DCBE2}) (Version: 1.23.219.2 - Intel Corporation)
    iTunes (HKLM\…\{96984DE8-1DB8-425C-AC8C-3098BC696F04}) (Version: 12.3.0.44 - Apple Inc.)
    Java 7 Update 51 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
    Java 7 Update 9 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    L.A. Noire (HKLM-x32\…\Steam App 110800) (Version:  - Team Bondi)
    League of Legends (HKLM-x32\…\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
    League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
    Left 4 Dead 2 (HKLM-x32\…\Steam App 550) (Version:  - Valve)
    LogMeIn Hamachi (HKLM-x32\…\LogMeIn Hamachi) (Version: 2.2.0.420 - LogMeIn, Inc.)
    LogMeIn Hamachi (x32 Version: 2.2.0.420 - LogMeIn, Inc.) Hidden
    Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
    Max Payne 3 (HKLM-x32\…\{1AA94747-3BF6-4237-9E1A-7B3067738FE1}) (Version: 1.0.0.0 - Rockstar Games)
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
    Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\…\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
    Microsoft Games for Windows Marketplace (HKLM-x32\…\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
    Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.0.162.0 - Microsoft Corporation)
    Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
    Microsoft Office Professional Edition 2003 (HKLM-x32\…\{91110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\…\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\…\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
    Microsoft WSE 3.0 Runtime (HKLM-x32\…\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
    NVIDIA PhysX (HKLM-x32\…\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
    Oblivion (HKLM-x32\…\{35CB6715-41F8-4F99-8881-6FC75BF054B0}) (Version: 1.00.0000 - Bethesda Softworks)
    Origin (HKLM-x32\…\Origin) (Version: 9.1.3.2637 - Electronic Arts, Inc.)
    Pando Media Booster (HKLM-x32\…\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
    PAYDAY 2 (HKLM-x32\…\Steam App 218620) (Version:  - OVERKILL - a Starbreeze Studio.)
    PAYDAY: The Heist (HKLM-x32\…\Steam App 24240) (Version:  - Overkill)
    PlanetSide 2 (HKLM-x32\…\Steam App 218230) (Version:  - Sony Online Entertainment)
    PunkBuster Services (HKLM-x32\…\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
    PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
    Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.14.010 - Dell Inc.)
    QuickTime 7 (HKLM-x32\…\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
    Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7601.39019 - Realtek Semiconductor Corp.)
    RivaTuner Statistics Server 5.2.0 (HKLM-x32\…\RTSS) (Version: 5.2.0 - Unwinder)
    Rockstar Games Social Club (HKLM-x32\…\Rockstar Games Social Club) (Version: 1.1.0.6 - Rockstar Games)
    RollerCoaster Tycoon 3: Platinum! (HKLM-x32\…\Steam App 2700) (Version:  - Frontier)
    RuneScape Launcher 1.2.2 (HKLM-x32\…\{A85FCCBE-31AB-4312-A5A9-165FF3B0BF90}) (Version: 1.2.2 - Jagex Ltd)
    Rust (HKLM-x32\…\Steam App 252490) (Version:  - Facepunch Studios)
    Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
    Sid Meier's Civilization V (HKLM-x32\…\Steam App 8930) (Version:  - 2K Games, Inc.)
    SimCity™ (HKLM-x32\…\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
    Six Updater (HKLM-x32\…\{2D8CED57-CCDB-4D86-9087-3BBCAE8F8F22}) (Version: 2.09.7016 - Six Projects)
    Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
    Skype™ 7.21 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.21.100 - Skype Technologies S.A.)
    Sleeping Dogs™ (HKLM-x32\…\Steam App 202170) (Version:  - United Front Games)
    Spore (HKLM-x32\…\Steam App 17390) (Version:  - Maxis™)
    Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
    Surgeon Simulator 2013 (HKLM-x32\…\Steam App 233720) (Version:  - Bossa Studios)
    SyncUP (HKLM-x32\…\{D92C9CCE-E5F0-4125-977A-0590F3225B74}) (Version: 10.2.16100 - Nero AG)
    SyncUP (x32 Version: 1.12.12400.17.102 - Nero AG) Hidden
    Team Fortress 2 (HKLM-x32\…\Steam App 440) (Version:  - Valve)
    TeamSpeak 3 Client (HKLM-x32\…\TeamSpeak 3 Client) (Version: 3.0.12 - TeamSpeak Systems GmbH)
    The Elder Scrolls III: Morrowind (HKLM-x32\…\Steam App 22320) (Version:  - Bethesda Game Studios®)
    The Elder Scrolls V: Skyrim (HKLM-x32\…\Steam App 72850) (Version:  - Bethesda Game Studios)
    The Sims 2: Ultimate Collection (HKLM-x32\…\{04450C18-F039-4B81-A621-70C3B0F523D5}) (Version: 1.0.0.0 - Electronic Arts)
    The Sims™ 3 (HKLM-x32\…\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts)
    The Sims™ 3 70s, 80s, & 90s Stuff (HKLM-x32\…\{E1868CAE-E3B9-4099-8C18-AA8944D336FD}) (Version: 17.0.77 - Electronic Arts)
    The Sims™ 3 Ambitions (HKLM-x32\…\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts)
    The Sims™ 3 Diesel Stuff (HKLM-x32\…\{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}) (Version: 14.0.48 - Electronic Arts)
    The Sims™ 3 Fast Lane Stuff (HKLM-x32\…\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts)
    The Sims™ 3 Generations (HKLM-x32\…\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts)
    The Sims™ 3 High-End Loft Stuff (HKLM-x32\…\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts)
    The Sims™ 3 Island Paradise (HKLM-x32\…\{DB21639E-FE55-432C-BCA2-0C5249E3F79E}) (Version: 19.0.101 - Electronic Arts)
    The Sims™ 3 Late Night (HKLM-x32\…\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts)
    The Sims™ 3 Master Suite Stuff (HKLM-x32\…\{08A25478-C5DD-4EA7-B168-3D687CA987FF}) (Version: 11.0.84 - Electronic Arts)
    The Sims™ 3 Outdoor Living Stuff (HKLM-x32\…\{117B6BF6-82C3-420C-B284-9247C8568E53}) (Version: 7.0.55 - Electronic Arts)
    The Sims™ 3 Pets (HKLM-x32\…\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts)
    The Sims™ 3 Seasons (HKLM-x32\…\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts)
    The Sims™ 3 Showtime (HKLM-x32\…\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts)
    The Sims™ 3 Supernatural (HKLM-x32\…\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts)
    The Sims™ 3 Town Life Stuff (HKLM-x32\…\{7B11296A-F894-449C-8DF6-6AAAA7D4D118}) (Version: 9.0.73 - Electronic Arts)
    The Sims™ 3 University Life (HKLM-x32\…\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}) (Version: 18.0.126 - Electronic Arts)
    The Sims™ 3 World Adventures (HKLM-x32\…\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts)
    Thief (HKLM-x32\…\Steam App 239160) (Version:  - Eidos-Montréal)
    Tropico 4 Gold (HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Tropico 4 Gold) (Version: 1.05 - Kalypso Media)
    Tropico 5 (HKLM-x32\…\Steam App 245620) (Version:  - Haemimont Games)
    Unity Web Player (HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\UnityWebPlayer) (Version: 5.0.1f1 - Unity Technologies ApS)
    Uplay (HKLM-x32\…\Uplay) (Version: 2.0 - Ubisoft)
    VIO Player version 1.0.1 (HKLM-x32\…\{C8A17598-7F89-41EA-9876-0F89DA0B24F1}_is1) (Version: 1.0.1 - VIO)
    VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
    Warframe (HKLM-x32\…\Steam App 230410) (Version:  - Digital Extremes)
    Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices  (03/07/2012 ) (HKLM\…\0B624A43DD66DBF5CF3EDFA9741A364E688062A4) (Version: 03/07/2012  - GoPro)
    Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Movie Maker 2.6 (HKLM-x32\…\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
     
    ==================== Custom CLSID (Whitelisted): ==========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
     
    ==================== Scheduled Tasks (Whitelisted) =============
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    Task: {04986720-95AF-4AE5-A028-FBAD214FF3E4} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2015-06-11] (Dell Inc.)
    Task: {176B0FD7-2CC5-4890-BFAD-D3DE48A60639} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
    Task: {1B2BF7FD-213C-47AB-B191-41FB869FC45A} - System32\Tasks\{486C2EC1-91DE-4997-B97C-6D8085EC3DEC} => C:\Program Files (x86)\Bohemia Interactive\ArmA 2\arma2OA.exe [2013-03-10] (Bohemia Interactive)
    Task: {3364C208-BD3E-4121-93A6-E455C937C905} - System32\Tasks\{A42F91EF-79E2-4B10-BD5F-45C67B238C3F} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
    Task: {355A5A19-CC60-4DCC-AD0B-412DE8A03E61} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
    Task: {3AF391DB-81EB-4999-A303-1A3D0C4350FF} - System32\Tasks\EVGAPrecision => C:\Program Files (x86)\EVGA Precision X\EVGAPrecision.exe [2013-07-18] ()
    Task: {3B3090EA-B338-4F30-B800-1E6D4875B6F8} - System32\Tasks\{0F0A7E5D-A4FF-4DA9-96F8-245E48069309} => pcalua.exe -a C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69\GEARDIFx.exe -d C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    Task: {3D8A0521-5049-4199-A763-FBA0F99DCF5F} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-03-31] (AVAST Software)
    Task: {3E4F8A16-6A43-46BE-BCB0-5D68F8145C79} - System32\Tasks\{C1397205-A924-40E8-BABC-90F8470FC152} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
    Task: {4819DCCA-2472-49ED-B371-D6C0EBFB4556} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2012-11-02] (Microsoft Corporation)
    Task: {59F44749-E201-4945-A2FA-4BDBA3150EAD} - System32\Tasks\{95A88E8F-1A35-418E-91C6-623E45497224} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
    Task: {65D692E5-EFD1-4A06-8212-2D275B468BB0} - System32\Tasks\{87D6AF67-0AC9-4487-961E-48DD8279E085} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
    Task: {70CC3F5D-16EC-4970-AFE7-DF50762F11D2} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2012-11-02] (Microsoft)
    Task: {77B971D2-1360-49C4-802B-A0FE71AC47BD} - System32\Tasks\{510D9FCC-C247-42BB-8865-9BF9F9A12D43} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
    Task: {7966649C-0BFE-446B-A3DF-2185D445791E} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001Core => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-12] (Facebook Inc.)
    Task: {79BA81AC-140E-434B-AEFE-B4FB00C790CC} - System32\Tasks\{2ED90E63-1EFA-4874-9880-50F55D5B05A3} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
    Task: {7D24805E-9738-4F0A-805E-C40689C47FE6} - System32\Tasks\{A0898C8A-B638-4FCC-9EA3-5627E35F4A76} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
    Task: {81835C2A-9E23-47CA-9EF0-58DA1B70C124} - System32\Tasks\{B03A9A69-01BD-49E9-9487-2CB6E4AFD4F5} => pcalua.exe -a C:\Users\Tomton98\AppData\Local\Temp\Temp1_EVGAPrecisionX.zip\EVGA_PrecisionX_Setup_400.exe
    Task: {850EA906-00FB-4C85-B05D-51F84637CE4A} - System32\Tasks\{E833EEB4-F078-4649-8451-4A9815559007} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
    Task: {9AAF1711-2139-47CC-997A-2605A90B70CF} - System32\Tasks\{D7AB502A-0F67-44E6-BB12-C678A9802368} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
    Task: {A0EC30EB-237E-4CA9-8F56-3397F9943713} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe
    Task: {A423D2EB-59BE-4070-98D2-8D6B60762770} - System32\Tasks\{5FB514CF-A913-4AAF-B204-9F1876F7FB7E} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
    Task: {A6D0945A-7130-4987-86B2-8E154C6CDA68} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
    Task: {A7FBEA51-0EA2-42DF-B236-0683419DF8BC} - System32\Tasks\{14C66831-93DA-426D-A90D-0F1D42B01577} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
    Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent => aitagent.exe
    Task: {B3EDB281-5791-48BB-8D3A-98C489FB6922} - System32\Tasks\{F2B51C84-7766-404C-B31D-F2032079966B} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
    Task: {BD44F3E9-1E58-4579-94F5-0859F523DE23} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
    Task: {BFEA4E8A-6FB0-42A9-9775-69866C7C286E} - System32\Tasks\{90C8B7AA-222D-41AC-87BE-B3FD06D3D7A7} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
    Task: {D512AAA6-268E-49CF-83BA-384E6CBD21F7} - System32\Tasks\{FD2F5746-23D7-4628-9C45-C811788B4A10} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
    Task: {DCE663B6-40DA-4C33-8583-B566259C92E9} - System32\Tasks\{F2A17ECB-C0C2-4ECD-AAD9-33C9BDE927C2} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
    Task: {E15C7EFF-31C9-4511-B17F-A3C91F641491} - System32\Tasks\{0CFB6EBC-8F8E-44EC-8AF5-2DF3AF60683C} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
    Task: {E2406D5B-9A8F-4CC4-A9AD-B1DDB8F4EC2A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-05-13] (Adobe Systems Incorporated)
    Task: {E3163C33-301D-4730-A266-5518C5ED3967} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => BthUdTask.exe
    Task: {E43463FC-5209-4F16-A5CC-FD713BA73DED} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2013-11-20] (Apple Inc.)
    Task: {EE02410A-B1E4-4FCE-AFBE-893C390D110E} - System32\Tasks\{96351ECB-CB3A-434E-AA5C-299A56B11B45} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
    Task: {F2FC758A-BCC4-4648-A89C-901389A134F4} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001UA => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-12] (Facebook Inc.)
    Task: {F3E383DE-9DC2-4631-A292-A55A05B9AEC6} - System32\Tasks\{57529728-AB80-4AD7-B849-659206CEDFBA} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
    Task: {F3FCFD1D-1C37-4ED3-9FF5-F28E03623037} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2012-11-02] (Microsoft Corporation)
    Task: {F9FD37EA-00D5-4071-98DF-A64DD791F10F} - System32\Tasks\{548BC96D-8091-4868-9DF0-3D34E6D39169} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
     
    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
     
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001Core.job => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001UA.job => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
     
    ==================== Shortcuts =============================
     
    (The entries could be listed to be restored or removed.)
     
    Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{F6A9A4FE-91CF-496D-8EC5-F11ACD174B28}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.rockstargames.com/sanandreas/ (No File)
    Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{E3EE9886-A04D-E37C-86CD-3E7EA3CF8A0B}\SupportTasks\2\Adobe Flash.lnk -> hxxp://www.adobe.com/products/flash/about (No File)
    Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{E3EE9886-A04D-E37C-86CD-3E7EA3CF8A0B}\SupportTasks\1\Social Club.lnk -> hxxp://socialclub.rockstargames.com/ (No File)
    Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{E3EE9886-A04D-E37C-86CD-3E7EA3CF8A0B}\SupportTasks\0\Rockstar Games.lnk -> hxxp://www.rockstargames.com/ (No File)
    Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{7D27B567-B3A3-48B0-B97E-80B69505D3A4}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.rockstargames.com/sanandreas/ (No File)
    Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{264058BF-9E81-495C-AB14-8DCF244449B6}\SupportTasks\1\Support.lnk -> hxxp://www.bethsoft.com/ (No File)
    Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{264058BF-9E81-495C-AB14-8DCF244449B6}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.elderscrolls.com/ (No File)
    Shortcut: C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.com (No File)
     
    ==================== Loaded Modules (Whitelisted) ==============
     
    2012-12-27 12:54 - 2013-02-28 17:44 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
    2012-05-16 19:42 - 2012-01-27 12:49 - 02751808 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
    2012-05-16 19:26 - 2012-01-11 06:36 - 00159360 _____ () C:\Program Files\Conexant\SA3\MaxxAudioWrapper.dll
    2012-05-16 20:45 - 2012-01-19 08:48 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
    2015-09-23 15:47 - 2015-09-23 15:47 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2015-09-23 15:47 - 2015-09-23 15:47 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2013-07-23 19:36 - 2013-07-23 19:36 - 00401408 _____ () C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe
    2016-05-12 19:40 - 2016-05-12 19:40 - 00172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\5a8eeeddc97028a9f94d0518c22f4c2c\IsdiInterop.ni.dll
    2012-05-16 19:28 - 2011-11-30 11:00 - 00059392 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
    2012-05-16 19:27 - 2012-01-21 21:23 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
    2013-09-14 00:51 - 2013-09-14 00:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
    2013-09-14 00:50 - 2013-09-14 00:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
    2012-01-01 08:04 - 2012-01-01 08:04 - 00251688 _____ () C:\Program Files (x86)\Nero\SyncUP\System.ComponentModel.Composition.dll
    2012-01-01 08:04 - 2012-01-01 08:04 - 00891688 _____ () C:\Program Files (x86)\Nero\SyncUP\System.Data.SQLite.dll
     
    ==================== Alternate Data Streams (Whitelisted) =========
     
    (If an entry is included in the fixlist, only the ADS will be removed.)
     
    AlternateDataStreams: C:\ProgramData\Temp:054203E4 [290]
     
    ==================== Safe Mode (Whitelisted) ===================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
     
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
     
    ==================== Association (Whitelisted) ===============
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
     
     
    ==================== Internet Explorer trusted/restricted ===============
     
    (If an entry is included in the fixlist, it will be removed from the registry.)
     
    IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\clonewarsadventures.com -> clonewarsadventures.com
    IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\freerealms.com -> freerealms.com
    IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\soe.com -> soe.com
    IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\sony.com -> sony.com
     
    ==================== Hosts content: ===============================
     
    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
     
    2009-07-14 12:34 - 2016-06-28 10:46 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
     
     
    ==================== Other Areas ============================
     
    (Currently there is no automatic fix for this section.)
     
    HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    HKU\S-1-5-21-1821522787-3724074743-2321965764-500\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: Media is not connected to internet.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    MpsSvc => Firewall Service is not running.
     
    ==================== MSCONFIG/TASK MANAGER disabled items ==
     
    (Currently there is no automatic fix for this section.)
     
     
    ==================== FirewallRules (Whitelisted) ===============
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
     
    ==================== Restore Points =========================
     
    ATTENTION: System Restore is disabled
    25-05-2016 19:29:34 Windows Update
    27-05-2016 14:28:51 Windows Update
    30-05-2016 17:14:30 Windows Backup
    31-05-2016 15:47:06 Windows Update
    Check "winmgmt" service or repair WMI.
     
     
    ==================== Faulty Device Manager Devices =============
     
     
    ==================== Event log errors: =========================
     
    Could not start eventlog service, could not read events.
     
    'net' is not recognized as an internal or external command,
    operable program or batch file.
     
    ==================== Memory info =========================== 
     
    Processor: Intel(R) Core(TM) i7-3612QM CPU @ 2.10GHz
    Percentage of memory in use: 41%
    Total physical RAM: 6046.36 MB
    Available physical RAM: 3513.18 MB
    Total Virtual: 12090.89 MB
    Available Virtual: 9165.41 MB
     
    ==================== Drives ================================
     
    Drive c: (OS) (Fixed) (Total:917.66 GB) (Free:72.69 GB) NTFS
     
    ==================== MBR & Partition Table ==================
     
    ========================================================
    Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 69519867)
    Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
    Partition 2: (Active) - (Size=13.8 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=917.7 GB) - (Type=07 NTFS)
     
    ==================== End of Addition.txt ============================

    When we ran the first fix, I had it fix your winsock setting hoping that it would have given you back your internet connection.  Is ii still not working ?

     

    Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
    Please copy the entire contents Inside of the code box below beginning with START and ending with END
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
    Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
     
    Start
    CloseProcesses:
    CreateRestorePoint:
    HKLM-x32\…\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    EmptyTemp:
    End
    
     
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
    Good morning, still no internet after the fix. When i click on network and sharing center a window pops up but just hangs and freezes. Won't close, wont minimise. The window is empty too
     
     
     
    Fix result of Farbar Recovery Scan Tool (x64) Version: 26-06-2016 02
    Ran by [removed] (2016-06-29 07:30:02) Run:2
    Running from C:\Users\[removed]\Desktop
    [removed]
    Boot Mode: Normal
    ==============================================
     
    fixlist content:
    *****************
    Start
    CloseProcesses:
    CreateRestorePoint:
    HKLM-x32\…\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    EmptyTemp:
    End
    *****************
     
    Processes closed successfully.
    Error: (0) Failed to create a restore point.
    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mcui_exe => value removed successfully
     
    =========== EmptyTemp: ==========
     
    BITS transfer queue => 0 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 4448546 B
    Java, Flash, Steam htmlcache => 24203713 B
    Windows/system/drivers => 40 B
    Edge => 0 B
    Chrome => 0 B
    Firefox => 0 B
    Opera => 0 B
     
    Temp, IE cache, history, cookies, recent:
    Default => 0 B
    Public => 0 B
    ProgramData => 0 B
    systemprofile => 128 B
    systemprofile32 => 128 B
    LocalService => 0 B
    NetworkService => 0 B
    Tomton98 => 5404097 B
    GUEST DAWW => 0 B
    Administrator => 264716 B
     
    RecycleBin => 78636 B
    EmptyTemp: => 32.8 MB temporary data Removed.
     
    ================================
     
     
    The system needed a reboot.
     
    ==== End of Fixlog 07:30:08 ====
    there appear to be a lot of services set to automatic that are not starting such as windows event log(gives error 1053 did not respond in a timely fashion"when i try to start it manually.
    The network sharing center window finally opened it says for information Unknown and then under, "The dependency service or group failed to start"
    services set to Automatic that did not start include
    DNS Client - gives error 11003 when try to start manually
    FDHOST
    IKE and Auth IP
    IP helper
    Soft ware protection
    Task scheduler
    Windows event log
    windows firewall
    windows update
    WLAN Auto Config
    WWAN Auto Config
    there are a few others but the didn't seem too important

    Looks like your using CCleaner, its a good program, I use it myself ….BUT…for general use like removing temp files , cookies and browsing history its just fine, but if you use it to fix registry entries and are not sure what your removing it can and will get you into trouble, lets hope that didnt happen

     

    Your logs look ok at this point but let me tell you we removed more than the average junk, its a wonder this computer would even start up at all. Somewhere along the line prior to you posting some damage has been done, if you look at your FRST fix, your winsock setting where corrupt,  and also it will not let you create a restore point.  I am wondering if we may just have to do a system reinstall or repair. 

     

    Let me ask you your set up, do you use a cable modem and router ??  Do you have other computers that access this set up and if so are they able to access the internet ??

     

     

    Lets do this first.
     
    1. Turn off your computer
    2. Turn off your router by unplugging the power cord on the back of the unit
    3. Turn off your Cable / DSL modem by unplugging the power cord on the back of the unit
     
    Leave everything off for about 5 minutes, this lets it all reset 
     
    Then
     
    1. Plug in your Cable / DSL modem and wait until all the lights come back on
    2. Now do the same thing with your router
    3. Turn your computer back on and see if it made a difference

    all done no change, the files are probably corrupt. What are the steps to doing a windows repair?

    I guess it was my son who used CCleaner I have never used that, he also had Hitman on there, but i deleted it as i thought it may conflict with what we are doing

    when i plug the ethernet cable to the router no light comes on on either the router or the connection to the laptop

     

    Im trying to restore the windows files using upgrading windows method. If this does not work, i will try to take all the important files and do a fresh install.

    seems to be hanging(after reboot) on expanding windows files 18% gathering additional information…going to let it run..if it takes all night…

    working again..99% now, hope this works

    so far it finished everything and is stuck in some kind of reboot… black screen hdd light flashing like it is processing info but pure black screen. I can hear the hdd its sounds like its busy…i guess i should just leave it. Do you know how long this last bit should take?, its been at least an hour now. Just wondering if you think i should leave it all night or turn it off and on again if it hasn't restarted before i go to bed

    Ask AI

    AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

    Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI