PDA

View Full Version : hello again guys malware adware and spyware removal help



Hunterkiller
2014-08-07, 09:06
Hey guys, my father and I had a falling out. Needless to say, he doesnt want to proceed with the work you guys had layed out for us. So, I figured I could atleast try and get my machine clean. Any help would be greatly appreciated. For some reason aswMBR isnt working correctly, it wont update the virus definitions and it wont allow me to scan at all. Any Ideas?



FRST LOG
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-08-2014
Ran by waynehunterq (administrator) on WAYNEHUNTERQ-PC on 06-08-2014 23:57:51
Running from C:\Users\waynehunterq\Desktop\Virus Recovery Folder
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
(Fuyu LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
(Anvisoft) C:\Program Files (x86)\Anvisoft\Cloud System Booster\extentions\Toolbox\Startup booster\StartupTimeSrv.exe
(AMD) C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
(AMD) C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
(Anvisoft) C:\Program Files (x86)\Anvisoft\Cloud System Booster\CSBSvc.exe
(Anvisoft) C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASD2Srv.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
() C:\Users\waynehunterq\AppData\Roaming\VOPackage\VOsrv.exe
() C:\Program Files (x86)\PassShowS\PassShowl.exe
() C:\Program Files (x86)\SupTab\HpUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(Anvisoft) C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASD2.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Wajam Internet Technologies Inc.) C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe
(RCP) C:\Program Files (x86)\RCP\RegCleanPro.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Anvisoft) C:\Program Files (x86)\Anvisoft\Cloud System Booster\CloudSystemBooster.exe
() C:\Program Files (x86)\SupTab\Loader32.exe
() C:\Program Files (x86)\SupTab\Loader64.exe
(Anvisoft Corporation) C:\Program Files (x86)\Anvisoft\Cloud System Booster\extentions\Toolbox\Anvi RAM Booster\Anvi_RAM_Booster.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe
() C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.PurBrowse64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BrowserAdapter.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AMD) C:\Windows\SysWOW64\WinMsgBalloonServer.exe
(AMD) C:\Windows\SysWOW64\WinMsgBalloonClient.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Deal Keeper\updateDealKeeper.exe
(Microsoft Corporation) C:\Windows\ehome\mcupdate.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-08-09] (VIA)
HKLM-x32\...\Run: [AnyProtect Scanner] => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [16987136 2014-07-27] (AnyProtect.com)
HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296520 2014-07-28] (RealNetworks, Inc.)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-05-21] (Microsoft Corporation)
HKU\.DEFAULT\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [GoogleChromeAutoLaunch_D1AED79CDC80A08C4FCDB94506043851] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488 2014-07-15] (Google Inc.)
HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [24477056 2014-06-27] (Google)
HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [CloudSystemBooster] => C:\Program Files (x86)\Anvisoft\Cloud System Booster\CloudSystemBooster.exe [527544 2014-05-29] (Anvisoft)
HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [mmonitor] => C:\Program Files (x86)\Anvisoft\Cloud System Booster\extentions\toolbox\Anvi RAM Booster\Anvi_RAM_Booster.exe [1681080 2013-12-23] (Anvisoft Corporation)
HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2014-04-12] (Google Inc.)
HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\MountPoints2: {e89b7deb-151d-11e4-bdfb-94de80ce65ca} - F:\setup.exe -a
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk
ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7EA35A4DC056CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istart123.com/?type=hp&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.calcitapp.info/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.v9.com/web/?type=ds&ts=1406390791&from=air&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&i=psd&t=346463446&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istart123.com/?type=hp&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istart123.com/?type=hp&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.v9.com/web/?type=ds&ts=1406390791&from=air&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&i=psd&t=346463446&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istart123.com/?type=hp&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://websearch.calcitapp.info/
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL =
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://rocket-find.com/results.php?f=4&q={searchTerms}&a=rckt_ir_14_30_ie&cd=2XzuyEtN2Y1L1QzuzyyE0D0EzztD0C0EyCyD0C0AyD0E0EtBtN0D0Tzu0SzytAtAtN1L2XzutBtFtBtCtFtCyEtFyEtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyE0CtDyBzz0D0FtDtG0BtC0B0BtGyCyCtDyBtGtD0B0AyCtGyD0B0AyEzzyD0A0EzzzytAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0A0DtA0F0CtD0BtGtDzz0FyEtG0AyD0A0AtGzz0CyBtCtGyD0AyE0EyEyDzyzytAzzyByD2Q&cr=1349864551&ir=
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://rocket-find.com/results.php?f=4&q={searchTerms}&a=rckt_ir_14_30_ie&cd=2XzuyEtN2Y1L1QzuzyyE0D0EzztD0C0EyCyD0C0AyD0E0EtBtN0D0Tzu0SzytAtAtN1L2XzutBtFtBtCtFtCyEtFyEtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyE0CtDyBzz0D0FtDtG0BtC0B0BtGyCyCtDyBtGtD0B0AyCtGyD0B0AyEzzyD0A0EzzzytAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0A0DtA0F0CtD0BtGtDzz0FyEtG0AyD0A0AtGzz0CyBtCtGyD0AyE0EyEyDzyzytAzzyByD2Q&cr=1349864551&ir=
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
BHO: No Name -> {181F2C09-56DD-4F98-86D7-59BA2BC59B5A} -> No File
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll (RealDownloader)
BHO: ShopSave ToolbarBHO -> {6CC4BF79-7708-4ECB-8F2B-A11264A67989} -> C:\Program Files (x86)\ShopSave Toolbar\2.1.2\KangoBHO64.dll (Kango)
BHO: No Name -> {7D1B27B2-3DE0-4F26-94A0-E14FDB06D292} -> No File
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: CostMin -> {AAC25859-AD45-D406-F3AB-2A1280536BE6} -> C:\Program Files (x86)\CostMin\QvFQg39u.x64.dll ()
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg64.dll (Google Inc.)
BHO-x32: No Name -> {181F2C09-56DD-4F98-86D7-59BA2BC59B5A} -> No File
BHO-x32: Deal Keeper -> {1ec8187a-6435-44e3-bbe4-6ce6d3c69254} -> C:\Program Files (x86)\Deal Keeper\DealKeeperbho.dll (Deal Keeper)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited)
BHO-x32: ShopSave ToolbarBHO -> {6CC4BF79-7708-4ECB-8F2B-A11264A67989} -> C:\Program Files (x86)\ShopSave Toolbar\2.1.2\KangoBHO.dll (Kango)
BHO-x32: No Name -> {7D1B27B2-3DE0-4F26-94A0-E14FDB06D292} -> No File
BHO-x32: PassShow -> {A1067C25-D623-DD31-A82F-A717FA2046EC} -> C:\Program Files (x86)\PassShowS\173.dll ()
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: CostMin -> {AAC25859-AD45-D406-F3AB-2A1280536BE6} -> C:\Program Files (x86)\CostMin\QvFQg39u.dll ()
BHO-x32: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO-x32: No Name -> {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} -> No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM - ShopSave Toolbar - {033BE5FC-ED4C-48A0-8F07-E0128384D828} - C:\Program Files (x86)\ShopSave Toolbar\2.1.2\KangoBHO64.dll (Kango)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=17.0.11.0 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=17.0.11 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.11 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=17.0.11 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.11.0 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer Cloud)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: anvisoft.com/AdblockPlugin - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll (Anvisoft)
FF HKLM-x32\...\Firefox\Extensions: [{1DD9AC48-0855-4AE7-9934-159B4377FFA2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-07-28]
FF HKCU\...\Firefox\Extensions: [{C516109B-6EA1-337C-2C31-0D60F65A73F0}] - C:\Program Files (x86)\PassShowS\173.xpi
FF Extension: PassShow - C:\Program Files (x86)\PassShowS\173.xpi [2014-06-30]

Chrome:
=======
CHR HomePage: hxxp://websearch.calcitapp.info/
CHR StartupUrls: "hxxp://websearch.calcitapp.info/"
CHR NewTab: "chrome-extension://pelmeidfhdlhlbjimpabfcbnnojbboma/index.html"
CHR DefaultSearchKeyword: v9
CHR DefaultNewTabURL:
CHR Extension: (Google Drive) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-28]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-28]
CHR Extension: (RealPlayer Downloader) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-07-17]
CHR Extension: (AnviAdblock) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhmiofmipcpmhgihiecmpiekcacigpgb [2014-07-26]
CHR Extension: (Google Wallet) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-14]
CHR Extension: (PassShow) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\peebhdfiangfgjfgcllikhdckkhibbcb [2014-06-30]
CHR Extension: (Quick start) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [2014-07-27]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\WAYNEH~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-05-21]
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2014-06-10]
CHR HKLM-x32\...\Chrome\Extension: [lhmiofmipcpmhgihiecmpiekcacigpgb] - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\chrome.crx [2014-04-29]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AnviStartupTime; C:\Program Files (x86)\Anvisoft\Cloud System Booster\extentions\Toolbox\Startup booster\StartupTimeSrv.exe [193256 2013-05-07] (Anvisoft)
R2 AnviCsbSvc; C:\Program Files (x86)\Anvisoft\Cloud System Booster\CSBSvc.exe [42680 2014-05-29] (Anvisoft)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 ASD2Svc; C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASD2Srv.exe [1206504 2014-05-28] (Anvisoft)
R2 be0fb33b; c:\Program Files (x86)\Supporter\SupporterSvc.dll [174416 2014-07-27] () [File not signed]
R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173792 2014-06-03] (Microsoft Corp.)
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [702344 2014-07-27] (Cherished Technololgy LIMITED)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-06-10] ()
R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-07-28] (RealNetworks, Inc.)
R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [23552 2014-06-10] () [File not signed]
R2 servervo; C:\Users\waynehunterq\AppData\Roaming\VOPackage\VOsrv.exe [71680 2014-07-27] () [File not signed]
R2 Update Deal Keeper; C:\Program Files (x86)\Deal Keeper\updateDealKeeper.exe [323320 2014-08-06] ()
R2 Util Deal Keeper; C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe [323320 2014-08-06] ()
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-03] (VIA Technologies, Inc.)
R2 Wajam Internet Enhancer Service; C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe [303616 2014-07-31] (Wajam Internet Technologies Inc.) [File not signed]
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [535936 2014-07-27] (Fuyu LIMITED)
S2 pcregservice; C:\Program Files\pcreg\pcreg.exe [X]
S2 pennybee; "C:\PROGRA~3\pennybee\pennybee.exe" /task=4 /InstallOn=0 /closebr=0 /active=24 /update=24 /interval=2880 /pubId=1004 /affId=10040007 /appId=116 /uId=3EBDC1B9-8EFC-4D16-94F5-8E71B540A678 /version=1.1.0.13 /Override=0 /regAppName=pennybee /curSID= /logf=\10040007_loger_25_07_19_58_38_-1170997570.txt /mac=94DE80CE65CA /tst=none /ts2=1 [X]
S2 sssvc; "C:\Program Files (x86)\SearchSnacks\Service\sssvc.exe" [X]
S2 Update sizlsearch; "C:\Program Files (x86)\sizlsearch\updatesizlsearch.exe" [X]
S2 Util sizlsearch; "C:\Program Files (x86)\sizlsearch\bin\utilsizlsearch.exe" [X]
S2 wpennybeed; "C:\PROGRA~3\pennybee\wpennybeed.exe" -scm [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
R1 asd2fsm; C:\Windows\System32\DRIVERS\asd2fsm.sys [48656 2014-05-28] (Anvisoft)
R1 Asdids; C:\Windows\System32\DRIVERS\asdids.sys [47632 2014-05-28] (Anvisoft)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-06-12] (NetFilterSDK.com)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [231112 2013-01-02] (VIA Technologies, Inc.)
R2 webinstr; C:\Windows\system32\Drivers\webinstr.sys [57528 2014-06-10] (Corsica)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [301256 2013-01-02] (VIA Technologies, Inc.)
R1 {55dce8ba-9dec-4013-937e-adbf9317d990}Gw64; C:\Windows\System32\drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}Gw64.sys [61072 2014-07-25] (StdLib)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S1 {9d5747ee-0448-4681-8337-1555de75a3b6}Gw64; system32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}Gw64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-06 23:59 - 2014-08-06 23:59 - 05185536 _____ (AVAST Software) C:\Users\waynehunterq\Desktop\aswMBR.exe
2014-08-06 23:58 - 2014-08-06 23:59 - 05185536 _____ (AVAST Software) C:\Users\waynehunterq\Downloads\aswMBR.exe
2014-08-06 23:56 - 2014-08-06 23:56 - 02094080 _____ (Farbar) C:\Users\waynehunterq\Downloads\FRST64.exe
2014-08-06 23:52 - 2014-08-06 23:52 - 00001332 _____ () C:\Users\waynehunterq\Desktop\Clean Registry for Free!.lnk
2014-08-06 23:51 - 2014-08-06 23:51 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-08-06 23:51 - 2014-08-06 23:51 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-08-06 23:50 - 2014-08-06 23:50 - 00003368 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
2014-08-06 23:50 - 2014-08-06 23:50 - 00003248 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000
2014-08-01 19:58 - 2014-08-06 23:48 - 00000168 _____ () C:\Windows\setupact.log
2014-08-01 19:58 - 2014-08-01 19:58 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-31 23:03 - 2014-07-31 23:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam
2014-07-31 23:03 - 2014-07-31 23:03 - 00000000 ____D () C:\Program Files (x86)\Wajam
2014-07-31 23:02 - 2014-07-31 23:02 - 00002222 _____ () C:\Users\Public\Desktop\Google Earth.lnk
2014-07-31 23:02 - 2014-07-31 23:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2014-07-31 23:01 - 2014-07-31 23:01 - 00000000 ____D () C:\Program Files (x86)\ShopSave Toolbar
2014-07-31 23:00 - 2014-07-31 23:00 - 00000000 ____D () C:\ProgramData\smdmf
2014-07-31 23:00 - 2014-07-31 23:00 - 00000000 ____D () C:\Program Files (x86)\Settings Manager
2014-07-31 03:32 - 2014-07-31 03:32 - 00000045 _____ () C:\Users\waynehunterq\AppData\Roaming\WB.CFG
2014-07-29 17:07 - 2014-07-29 17:07 - 00000000 ____D () C:\Program Files (x86)\PennyBee
2014-07-29 16:28 - 2014-08-06 23:51 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-07-28 17:13 - 2014-07-28 17:13 - 00000000 ____D () C:\Program Files (x86)\RealNetworks
2014-07-28 17:10 - 2014-07-28 17:10 - 00201800 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2014-07-28 17:09 - 2014-07-28 17:09 - 00278600 _____ (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2014-07-28 17:07 - 2014-07-28 17:07 - 00505416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2014-07-28 06:22 - 2014-07-28 17:21 - 00003390 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
2014-07-28 06:22 - 2014-07-28 17:21 - 00003270 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000
2014-07-28 06:22 - 2014-07-28 06:22 - 00003410 _____ () C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
2014-07-27 12:10 - 2014-07-27 16:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FREESOFTTODAY
2014-07-27 12:10 - 2014-07-27 12:10 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\fst_us_181
2014-07-27 12:10 - 2014-07-27 12:10 - 00000000 ____D () C:\Program Files (x86)\fst_us_181
2014-07-27 11:15 - 2014-07-25 16:19 - 00061072 _____ (StdLib) C:\Windows\system32\Drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}Gw64.sys
2014-07-27 10:12 - 2014-07-27 10:12 - 00002928 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.scan.results
2014-07-27 10:12 - 2014-07-27 10:12 - 00001176 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.scan.quick.results
2014-07-27 10:12 - 2014-07-27 10:12 - 00000318 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.uninstall.scan.results
2014-07-27 10:10 - 2014-07-31 23:17 - 00000000 ____D () C:\Program Files (x86)\Deal Keeper
2014-07-27 10:10 - 2014-07-27 10:10 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-27 10:10 - 2014-07-27 10:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Windows\system32\Macromed
2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
2014-07-27 10:09 - 2014-07-27 10:11 - 00000000 ____D () C:\Program Files (x86)\AnyProtectEx
2014-07-27 10:09 - 2014-07-25 10:13 - 00575544 _____ (ClickMeIn Limited) C:\Users\waynehunterq\AppData\Local\AnyProtectScannerSetup.exe
2014-07-27 09:57 - 2014-07-27 12:09 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\VOPackage
2014-07-27 09:57 - 2014-07-27 09:57 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\istart123
2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\Program Files (x86)\Supporter
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Torch
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Packages
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Comodo
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Chromatic Browser
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Chromatic Browser
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\ProgramData\CostMin
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\ProgramData\1b82de639df9d971
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Program Files (x86)\CostMin
2014-07-27 09:23 - 2014-07-27 09:24 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\vlc
2014-07-27 00:03 - 2014-08-06 23:58 - 00000000 ____D () C:\FRST
2014-07-26 23:57 - 2014-07-29 18:50 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro
2014-07-26 23:57 - 2014-07-29 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2014-07-26 23:56 - 2014-07-26 23:56 - 00003632 _____ () C:\Windows\System32\Tasks\Sparta WW1
2014-07-26 23:56 - 2014-07-26 23:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\sparta111
2014-07-26 23:56 - 2014-07-26 23:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sparta
2014-07-26 23:55 - 2014-07-26 23:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Sparta
2014-07-26 18:54 - 2014-05-08 04:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-07-26 18:54 - 2014-05-08 04:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-07-26 18:54 - 2014-01-08 21:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-07-26 18:54 - 2014-01-03 17:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-07-26 11:28 - 2014-07-26 11:29 - 10304417 _____ () C:\Users\waynehunterq\Downloads\240P_400K_1027280 (1).mp4
2014-07-26 11:26 - 2014-07-26 11:27 - 03735208 _____ () C:\Users\waynehunterq\Downloads\144P_150K_1027280.3gp
2014-07-26 11:17 - 2014-07-26 11:17 - 00000458 _____ () C:\Windows\Tasks\SpeedyPC Registration3.job
2014-07-26 11:17 - 2014-07-26 11:17 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\SpeedyPC Software
2014-07-26 11:17 - 2014-07-26 11:17 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\DriverCure
2014-07-26 11:12 - 2014-07-31 11:11 - 00003740 _____ () C:\Windows\System32\Tasks\DriverRestore_ScheduledScan
2014-07-26 11:12 - 2014-07-31 11:11 - 00003592 _____ () C:\Windows\System32\Tasks\DriverRestore_DailyScan
2014-07-26 11:12 - 2014-07-26 11:12 - 00000585 _____ () C:\Windows\Tasks\SpeedyPC Pro_sch_94F6518D-14DF-11E4-A166-94DE80CE65CA.job
2014-07-26 11:12 - 2014-07-26 11:12 - 00000478 _____ () C:\Windows\Tasks\SpeedyPC Update Version3_triggeronce.job
2014-07-26 11:12 - 2014-07-26 11:12 - 00000478 _____ () C:\Windows\Tasks\SpeedyPC Update Version3.job
2014-07-26 11:12 - 2014-07-26 11:12 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedyPC Software
2014-07-26 11:11 - 2014-07-26 11:12 - 00000000 ____D () C:\ProgramData\SpeedyPC Software
2014-07-26 11:11 - 2014-07-26 11:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
2014-07-26 11:11 - 2014-07-26 11:11 - 00000000 ____D () C:\Program Files (x86)\SpeedyPC Software
2014-07-26 11:11 - 2014-07-01 12:37 - 00020872 _____ (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS
2014-07-26 11:10 - 2014-07-31 13:11 - 00000000 ____D () C:\Program Files (x86)\DriverRestore
2014-07-26 11:09 - 2014-07-26 11:09 - 00000000 ____D () C:\Program Files\SearchSnacks
2014-07-26 11:09 - 2014-07-26 11:09 - 00000000 ____D () C:\Program Files (x86)\SearchSnacks
2014-07-26 11:08 - 2014-07-27 09:57 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-07-26 11:08 - 2014-07-26 22:17 - 00000000 ____D () C:\Program Files (x86)\PCTechHotline
2014-07-26 11:08 - 2014-07-26 14:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Fix Speed with PC Tech Hotline
2014-07-26 11:08 - 2014-07-26 13:27 - 00000000 ____D () C:\Program Files (x86)\PCFixSpeed
2014-07-26 11:08 - 2014-07-26 11:09 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\PCFixSpeed
2014-07-26 11:08 - 2014-07-26 11:08 - 00000000 ____D () C:\ProgramData\PCFixSpeed
2014-07-26 11:07 - 2014-07-27 09:57 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-07-26 11:07 - 2014-07-26 11:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiDefMedia
2014-07-26 11:06 - 2014-07-26 11:06 - 00000000 ____D () C:\Program Files (x86)\HiDefMedia
2014-07-26 10:28 - 2014-07-26 10:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-26 10:24 - 2014-07-26 10:24 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-26 10:24 - 2014-07-26 10:24 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-26 10:06 - 2014-07-26 10:13 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-26 10:06 - 2014-06-26 17:40 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-26 09:57 - 2013-10-01 20:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-07-26 09:56 - 2013-10-01 21:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-07-26 09:56 - 2013-10-01 21:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-07-26 09:56 - 2013-10-01 21:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-07-26 09:56 - 2013-10-01 20:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-07-26 09:56 - 2013-10-01 20:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-07-26 09:56 - 2013-10-01 20:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-07-26 09:56 - 2013-10-01 19:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-07-26 09:56 - 2013-10-01 19:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-07-26 09:56 - 2013-10-01 19:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-07-26 09:56 - 2013-10-01 19:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-07-26 09:56 - 2013-10-01 19:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-07-26 09:56 - 2013-10-01 18:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-07-26 09:56 - 2013-10-01 18:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-07-26 09:56 - 2013-10-01 18:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-07-26 09:56 - 2013-10-01 17:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-07-26 09:54 - 2012-08-23 09:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-07-26 09:54 - 2012-08-23 09:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-07-26 09:54 - 2012-08-23 06:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2014-07-26 09:54 - 2012-08-23 05:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-07-26 09:36 - 2013-09-24 21:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-07-26 09:36 - 2013-09-24 20:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-07-26 09:31 - 2012-05-04 06:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-07-26 09:31 - 2012-05-04 04:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-07-26 09:29 - 2014-07-26 09:29 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Anvisoft
2014-07-26 09:28 - 2014-07-26 09:28 - 00003548 _____ () C:\Windows\System32\Tasks\Csb_AutoScan_Task
2014-07-26 09:14 - 2014-07-26 09:14 - 00003748 _____ () C:\Windows\System32\Tasks\ASD_Schedule
2014-07-26 09:07 - 2014-08-06 23:48 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-07-26 09:07 - 2014-07-26 09:14 - 00003304 _____ () C:\Windows\System32\Tasks\ASD_Main
2014-07-26 09:06 - 2014-07-26 14:20 - 00000000 ____D () C:\ProgramData\Anvisoft
2014-07-26 09:06 - 2014-07-26 09:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft
2014-07-26 09:06 - 2014-07-26 09:06 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
2014-07-26 09:06 - 2014-05-28 21:03 - 00048656 _____ (Anvisoft) C:\Windows\system32\Drivers\asd2fsm.sys
2014-07-26 08:42 - 2014-07-26 08:42 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-WAYNEHUNTERQ-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-07-26 08:41 - 2014-07-26 08:41 - 00000000 ____D () C:\RegBackup
2014-07-26 08:40 - 2014-08-06 23:57 - 00000000 ____D () C:\Users\waynehunterq\Desktop\Virus Recovery Folder
2014-07-26 08:40 - 2014-07-26 08:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-26 08:40 - 2014-07-26 08:40 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-07-25 23:33 - 2014-07-25 23:33 - 00010666 _____ () C:\Users\waynehunterq\Downloads\pixel.htm
2014-07-25 21:49 - 2014-07-25 21:49 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp23588
2014-07-25 19:33 - 2014-07-25 19:34 - 02578135 _____ () C:\Users\waynehunterq\Downloads\shortshortts.wmv
2014-07-24 19:00 - 2014-07-24 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp3241
2014-07-23 19:00 - 2014-07-23 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp16151
2014-07-22 19:00 - 2014-07-22 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp28793
2014-07-22 13:49 - 2014-07-22 13:49 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp717
2014-07-22 06:20 - 2014-07-26 09:44 - 00000000 ____D () C:\Windows\Minidump
2014-07-22 03:34 - 2014-07-26 14:22 - 00003078 _____ () C:\Windows\System32\Tasks\Advanced System Protector_startup
2014-07-22 03:34 - 2014-07-22 03:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector
2014-07-22 03:33 - 2014-07-26 14:29 - 00000176 _____ () C:\Windows\Tasks\Tempo Runner.job
2014-07-22 03:33 - 2014-07-22 03:34 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Media Player Classic
2014-07-22 03:33 - 2014-07-22 03:34 - 00000000 ____D () C:\ProgramData\Systweak
2014-07-22 03:33 - 2014-07-22 03:34 - 00000000 ____D () C:\Program Files (x86)\ASP
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\unpacked11047
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\StormFall
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rocket
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp11037
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\StormFall
2014-07-22 03:33 - 2012-07-25 12:03 - 00016896 _____ () C:\Windows\system32\sasnative64.exe
2014-07-22 03:32 - 2014-08-06 23:56 - 00003090 _____ () C:\Windows\System32\Tasks\RegClean Pro
2014-07-22 03:32 - 2014-07-31 23:05 - 00000272 _____ () C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2014-07-22 03:32 - 2014-07-31 23:04 - 00000280 _____ () C:\Windows\Tasks\RegClean Pro_UPDATES.job
2014-07-22 03:32 - 2014-07-26 14:16 - 00000000 ____D () C:\ProgramData\pennybee
2014-07-22 03:32 - 2014-07-25 19:59 - 00000760 _____ () C:\Windows\Tasks\pennybee Runner.job
2014-07-22 03:32 - 2014-07-22 03:34 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Systweak
2014-07-22 03:32 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Rocket
2014-07-22 03:32 - 2014-07-22 03:32 - 00003556 _____ () C:\Windows\System32\Tasks\Rocket Updater
2014-07-22 03:32 - 2014-07-22 03:32 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\RocketUpdater
2014-07-22 03:31 - 2014-07-31 23:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
2014-07-22 03:31 - 2014-07-31 23:04 - 00000000 ____D () C:\Program Files (x86)\RCP
2014-07-22 03:31 - 2014-07-22 03:32 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Essentials Codec Pack
2014-07-22 03:31 - 2014-07-22 03:32 - 00000000 ____D () C:\Program Files (x86)\WSE Rocket
2014-07-22 03:31 - 2014-07-22 03:32 - 00000000 ____D () C:\Program Files (x86)\Essentials Codec Pack
2014-07-22 03:31 - 2014-07-17 11:42 - 00020328 _____ () C:\Windows\system32\roboot64.exe
2014-07-22 03:30 - 2014-07-22 03:30 - 00683360 _____ () C:\Users\waynehunterq\Downloads\MediaCodec.exe
2014-07-22 03:30 - 2014-07-22 03:30 - 00683360 _____ () C:\Users\waynehunterq\Downloads\MediaCodec (1).exe
2014-07-17 12:30 - 2014-07-17 12:30 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\RealNetworks
2014-07-17 12:29 - 2014-07-17 12:29 - 00000000 ____D () C:\ProgramData\RealNetworks
2014-07-17 12:28 - 2014-07-28 17:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
2014-07-17 12:28 - 2014-07-28 17:13 - 00000000 ____D () C:\Program Files (x86)\Real
2014-07-17 12:28 - 2014-07-17 12:28 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2014-07-17 12:27 - 2014-07-28 17:21 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Real
2014-07-17 12:27 - 2014-07-28 17:11 - 00000000 ____D () C:\ProgramData\Real
2014-07-09 14:45 - 2014-06-29 21:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 14:45 - 2014-06-29 21:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 14:45 - 2014-06-20 15:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 14:45 - 2014-06-18 20:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 14:45 - 2014-06-18 19:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 14:45 - 2014-06-18 19:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 14:45 - 2014-06-18 19:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 14:45 - 2014-06-18 18:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 14:45 - 2014-06-18 18:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 14:45 - 2014-06-18 18:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-09 14:45 - 2014-06-18 18:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-09 14:45 - 2014-06-18 18:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 14:45 - 2014-06-18 18:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-09 14:45 - 2014-06-18 18:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-09 14:45 - 2014-06-18 18:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 14:45 - 2014-06-18 18:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-09 14:45 - 2014-06-18 17:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 14:45 - 2014-06-18 17:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 14:45 - 2014-06-18 17:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 14:45 - 2014-06-18 17:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 14:45 - 2014-06-18 17:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 14:45 - 2014-06-17 21:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 14:45 - 2014-06-17 20:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-09 14:45 - 2014-06-17 20:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 14:45 - 2014-06-06 05:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 14:45 - 2014-06-06 04:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 14:45 - 2014-05-30 03:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 14:45 - 2014-05-30 03:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 14:45 - 2014-05-30 03:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 14:45 - 2014-05-30 03:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 14:45 - 2014-05-30 03:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 14:45 - 2014-05-30 03:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 14:45 - 2014-05-30 03:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 14:45 - 2014-05-30 02:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-09 14:45 - 2014-05-30 02:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-09 14:45 - 2014-05-30 02:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-09 14:45 - 2014-05-30 02:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-09 14:45 - 2014-05-30 02:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-09 14:45 - 2014-05-30 02:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-09 14:45 - 2014-05-30 02:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-09 14:45 - 2014-05-30 01:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 14:44 - 2014-06-20 14:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 14:44 - 2014-06-18 20:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 14:44 - 2014-06-18 20:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 14:44 - 2014-06-18 19:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 14:44 - 2014-06-18 19:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 14:44 - 2014-06-18 19:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 14:44 - 2014-06-18 19:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 14:44 - 2014-06-18 19:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 14:44 - 2014-06-18 19:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 14:44 - 2014-06-18 19:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 14:44 - 2014-06-18 19:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 14:44 - 2014-06-18 19:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 14:44 - 2014-06-18 19:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 14:44 - 2014-06-18 19:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 14:44 - 2014-06-18 18:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 14:44 - 2014-06-18 18:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 14:44 - 2014-06-18 18:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 14:44 - 2014-06-18 18:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 14:44 - 2014-06-18 18:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 14:44 - 2014-06-18 18:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 14:44 - 2014-06-18 18:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-09 14:44 - 2014-06-18 18:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 14:44 - 2014-06-18 18:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 14:44 - 2014-06-18 18:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 14:44 - 2014-06-18 18:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 14:44 - 2014-06-18 18:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 14:44 - 2014-06-18 18:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 14:44 - 2014-06-18 18:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-09 14:44 - 2014-06-18 17:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 14:44 - 2014-06-18 17:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 14:44 - 2014-06-18 17:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 14:44 - 2014-06-18 17:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 14:44 - 2014-06-18 17:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-09 14:44 - 2014-06-18 17:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 14:44 - 2014-06-18 17:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 14:44 - 2014-06-18 17:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 14:44 - 2014-06-18 17:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-09 14:44 - 2014-06-05 09:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 14:44 - 2014-06-05 09:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-09 14:44 - 2014-06-05 09:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-06 23:59 - 2014-08-06 23:59 - 05185536 _____ (AVAST Software) C:\Users\waynehunterq\Desktop\aswMBR.exe
2014-08-06 23:59 - 2014-08-06 23:58 - 05185536 _____ (AVAST Software) C:\Users\waynehunterq\Downloads\aswMBR.exe
2014-08-06 23:58 - 2014-07-27 00:03 - 00000000 ____D () C:\FRST
2014-08-06 23:57 - 2014-07-26 08:40 - 00000000 ____D () C:\Users\waynehunterq\Desktop\Virus Recovery Folder
2014-08-06 23:57 - 2014-04-12 21:32 - 01213241 _____ () C:\Windows\WindowsUpdate.log
2014-08-06 23:56 - 2014-08-06 23:56 - 02094080 _____ (Farbar) C:\Users\waynehunterq\Downloads\FRST64.exe
2014-08-06 23:56 - 2014-07-22 03:32 - 00003090 _____ () C:\Windows\System32\Tasks\RegClean Pro
2014-08-06 23:52 - 2014-08-06 23:52 - 00001332 _____ () C:\Users\waynehunterq\Desktop\Clean Registry for Free!.lnk
2014-08-06 23:51 - 2014-08-06 23:51 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-08-06 23:51 - 2014-08-06 23:51 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-08-06 23:51 - 2014-07-29 16:28 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-08-06 23:50 - 2014-08-06 23:50 - 00003368 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
2014-08-06 23:50 - 2014-08-06 23:50 - 00003248 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000
2014-08-06 23:50 - 2014-05-21 05:28 - 00000000 ___RD () C:\Users\waynehunterq\Google Drive
2014-08-06 23:50 - 2009-07-13 21:34 - 00000505 _____ () C:\Windows\win.ini
2014-08-06 23:48 - 2014-08-01 19:58 - 00000168 _____ () C:\Windows\setupact.log
2014-08-06 23:48 - 2014-07-26 09:07 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-08-06 23:48 - 2014-06-30 21:17 - 00000398 _____ () C:\Windows\Tasks\PassShow Update.job
2014-08-06 23:48 - 2014-06-30 21:17 - 00000378 _____ () C:\Windows\Tasks\PassShow_wd.job
2014-08-06 23:48 - 2014-04-12 22:35 - 00000906 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-06 23:48 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-04 21:05 - 2009-07-13 23:45 - 00014464 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-04 21:05 - 2009-07-13 23:45 - 00014464 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-01 20:25 - 2014-04-12 22:35 - 00000910 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-01 19:58 - 2014-08-01 19:58 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-31 23:17 - 2014-07-27 10:10 - 00000000 ____D () C:\Program Files (x86)\Deal Keeper
2014-07-31 23:05 - 2014-07-22 03:32 - 00000272 _____ () C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2014-07-31 23:04 - 2014-07-22 03:32 - 00000280 _____ () C:\Windows\Tasks\RegClean Pro_UPDATES.job
2014-07-31 23:04 - 2014-07-22 03:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
2014-07-31 23:04 - 2014-07-22 03:31 - 00000000 ____D () C:\Program Files (x86)\RCP
2014-07-31 23:03 - 2014-07-31 23:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam
2014-07-31 23:03 - 2014-07-31 23:03 - 00000000 ____D () C:\Program Files (x86)\Wajam
2014-07-31 23:03 - 2014-04-12 23:09 - 00002273 _____ () C:\Install.log
2014-07-31 23:02 - 2014-07-31 23:02 - 00002222 _____ () C:\Users\Public\Desktop\Google Earth.lnk
2014-07-31 23:02 - 2014-07-31 23:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2014-07-31 23:02 - 2014-04-12 22:35 - 00000000 ____D () C:\Program Files (x86)\Google
2014-07-31 23:01 - 2014-07-31 23:01 - 00000000 ____D () C:\Program Files (x86)\ShopSave Toolbar
2014-07-31 23:00 - 2014-07-31 23:00 - 00000000 ____D () C:\ProgramData\smdmf
2014-07-31 23:00 - 2014-07-31 23:00 - 00000000 ____D () C:\Program Files (x86)\Settings Manager
2014-07-31 23:00 - 2014-04-13 18:26 - 00000358 _____ () C:\Windows\Tasks\bench-sys.job
2014-07-31 23:00 - 2014-04-12 21:40 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\CrashDumps
2014-07-31 22:26 - 2014-04-13 18:26 - 00000358 _____ () C:\Windows\Tasks\bench-S-1-5-21-2235072853-4185849235-691160065-1000.job
2014-07-31 19:57 - 2014-07-04 14:42 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\serv
2014-07-31 13:11 - 2014-07-26 11:10 - 00000000 ____D () C:\Program Files (x86)\DriverRestore
2014-07-31 11:11 - 2014-07-26 11:12 - 00003740 _____ () C:\Windows\System32\Tasks\DriverRestore_ScheduledScan
2014-07-31 11:11 - 2014-07-26 11:12 - 00003592 _____ () C:\Windows\System32\Tasks\DriverRestore_DailyScan
2014-07-31 03:32 - 2014-07-31 03:32 - 00000045 _____ () C:\Users\waynehunterq\AppData\Roaming\WB.CFG
2014-07-31 00:21 - 2014-04-13 00:18 - 00000000 ____D () C:\Program Files (x86)\File Type Assistant
2014-07-29 19:19 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
2014-07-29 18:50 - 2014-07-26 23:57 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro
2014-07-29 18:43 - 2014-07-26 23:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2014-07-29 17:07 - 2014-07-29 17:07 - 00000000 ____D () C:\Program Files (x86)\PennyBee
2014-07-28 17:21 - 2014-07-28 06:22 - 00003390 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
2014-07-28 17:21 - 2014-07-28 06:22 - 00003270 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000
2014-07-28 17:21 - 2014-07-17 12:27 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Real
2014-07-28 17:13 - 2014-07-28 17:13 - 00000000 ____D () C:\Program Files (x86)\RealNetworks
2014-07-28 17:13 - 2014-07-17 12:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
2014-07-28 17:13 - 2014-07-17 12:28 - 00000000 ____D () C:\Program Files (x86)\Real
2014-07-28 17:11 - 2014-07-17 12:27 - 00000000 ____D () C:\ProgramData\Real
2014-07-28 17:10 - 2014-07-28 17:10 - 00201800 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2014-07-28 17:09 - 2014-07-28 17:09 - 00278600 _____ (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2014-07-28 17:07 - 2014-07-28 17:07 - 00505416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2014-07-28 06:22 - 2014-07-28 06:22 - 00003410 _____ () C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
2014-07-27 16:45 - 2014-07-27 12:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FREESOFTTODAY
2014-07-27 12:10 - 2014-07-27 12:10 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\fst_us_181
2014-07-27 12:10 - 2014-07-27 12:10 - 00000000 ____D () C:\Program Files (x86)\fst_us_181
2014-07-27 12:09 - 2014-07-27 09:57 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\VOPackage
2014-07-27 10:12 - 2014-07-27 10:12 - 00002928 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.scan.results
2014-07-27 10:12 - 2014-07-27 10:12 - 00001176 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.scan.quick.results
2014-07-27 10:12 - 2014-07-27 10:12 - 00000318 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.uninstall.scan.results
2014-07-27 10:11 - 2014-07-27 10:09 - 00000000 ____D () C:\Program Files (x86)\AnyProtectEx
2014-07-27 10:10 - 2014-07-27 10:10 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-27 10:10 - 2014-07-27 10:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Windows\system32\Macromed
2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
2014-07-27 09:57 - 2014-07-27 09:57 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-07-27 09:57 - 2014-07-26 11:08 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-07-27 09:57 - 2014-07-26 11:07 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\istart123
2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\Program Files (x86)\Supporter
2014-07-27 09:55 - 2014-04-12 22:33 - 00001623 _____ () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Torch
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Packages
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Comodo
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Chromatic Browser
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Chromatic Browser
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\ProgramData\CostMin
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\ProgramData\1b82de639df9d971
2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Program Files (x86)\CostMin
2014-07-27 09:54 - 2014-04-12 22:35 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Google
2014-07-27 09:24 - 2014-07-27 09:23 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\vlc
2014-07-27 04:49 - 2014-04-13 18:26 - 00000258 __RSH () C:\ProgramData\ntuser.pol
2014-07-27 00:50 - 2014-05-20 02:09 - 00000000 ____D () C:\Program Files (x86)\sizlsearch
2014-07-26 23:56 - 2014-07-26 23:56 - 00003632 _____ () C:\Windows\System32\Tasks\Sparta WW1
2014-07-26 23:56 - 2014-07-26 23:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\sparta111
2014-07-26 23:56 - 2014-07-26 23:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sparta
2014-07-26 23:56 - 2014-07-26 23:55 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Sparta
2014-07-26 23:53 - 2009-07-14 00:13 - 00782470 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-26 22:17 - 2014-07-26 11:08 - 00000000 ____D () C:\Program Files (x86)\PCTechHotline
2014-07-26 19:37 - 2014-07-04 15:52 - 00000000 ____D () C:\ProgramData\WeCareReminder
2014-07-26 18:40 - 2009-07-13 22:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-26 18:39 - 2009-07-13 23:45 - 00273872 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-26 14:29 - 2014-07-22 03:33 - 00000176 _____ () C:\Windows\Tasks\Tempo Runner.job
2014-07-26 14:27 - 2014-06-30 21:42 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-26 14:27 - 2009-07-14 02:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-26 14:27 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-26 14:27 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-26 14:27 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-07-26 14:22 - 2014-07-22 03:34 - 00003078 _____ () C:\Windows\System32\Tasks\Advanced System Protector_startup
2014-07-26 14:22 - 2014-04-13 18:23 - 00003720 _____ () C:\Windows\System32\Tasks\pcreg
2014-07-26 14:22 - 2014-04-13 18:23 - 00000000 ____D () C:\Program Files\pcreg
2014-07-26 14:22 - 2014-04-13 00:19 - 00003946 _____ () C:\Windows\System32\Tasks\ProgramUpdateCheck
2014-07-26 14:21 - 2014-04-12 21:38 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\SevereWeatherAlerts
2014-07-26 14:20 - 2014-07-26 09:06 - 00000000 ____D () C:\ProgramData\Anvisoft
2014-07-26 14:19 - 2014-07-26 11:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Fix Speed with PC Tech Hotline
2014-07-26 14:16 - 2014-07-22 03:32 - 00000000 ____D () C:\ProgramData\pennybee
2014-07-26 13:27 - 2014-07-26 11:08 - 00000000 ____D () C:\Program Files (x86)\PCFixSpeed
2014-07-26 12:53 - 2014-05-20 02:16 - 00000000 ____D () C:\Program Files\suprasavings
2014-07-26 11:29 - 2014-07-26 11:28 - 10304417 _____ () C:\Users\waynehunterq\Downloads\240P_400K_1027280 (1).mp4
2014-07-26 11:27 - 2014-07-26 11:26 - 03735208 _____ () C:\Users\waynehunterq\Downloads\144P_150K_1027280.3gp
2014-07-26 11:24 - 2014-04-13 18:23 - 00000000 ____D () C:\Temp
2014-07-26 11:17 - 2014-07-26 11:17 - 00000458 _____ () C:\Windows\Tasks\SpeedyPC Registration3.job
2014-07-26 11:17 - 2014-07-26 11:17 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\SpeedyPC Software
2014-07-26 11:17 - 2014-07-26 11:17 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\DriverCure
2014-07-26 11:12 - 2014-07-26 11:12 - 00000585 _____ () C:\Windows\Tasks\SpeedyPC Pro_sch_94F6518D-14DF-11E4-A166-94DE80CE65CA.job
2014-07-26 11:12 - 2014-07-26 11:12 - 00000478 _____ () C:\Windows\Tasks\SpeedyPC Update Version3_triggeronce.job
2014-07-26 11:12 - 2014-07-26 11:12 - 00000478 _____ () C:\Windows\Tasks\SpeedyPC Update Version3.job
2014-07-26 11:12 - 2014-07-26 11:12 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedyPC Software
2014-07-26 11:12 - 2014-07-26 11:11 - 00000000 ____D () C:\ProgramData\SpeedyPC Software
2014-07-26 11:11 - 2014-07-26 11:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
2014-07-26 11:11 - 2014-07-26 11:11 - 00000000 ____D () C:\Program Files (x86)\SpeedyPC Software
2014-07-26 11:09 - 2014-07-26 11:09 - 00000000 ____D () C:\Program Files\SearchSnacks
2014-07-26 11:09 - 2014-07-26 11:09 - 00000000 ____D () C:\Program Files (x86)\SearchSnacks
2014-07-26 11:09 - 2014-07-26 11:08 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\PCFixSpeed
2014-07-26 11:08 - 2014-07-26 11:08 - 00000000 ____D () C:\ProgramData\PCFixSpeed
2014-07-26 11:07 - 2014-07-26 11:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiDefMedia
2014-07-26 11:06 - 2014-07-26 11:06 - 00000000 ____D () C:\Program Files (x86)\HiDefMedia
2014-07-26 10:28 - 2014-07-26 10:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-26 10:24 - 2014-07-26 10:24 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-26 10:24 - 2014-07-26 10:24 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-26 10:13 - 2014-07-26 10:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-26 09:44 - 2014-07-22 06:20 - 00000000 ____D () C:\Windows\Minidump
2014-07-26 09:29 - 2014-07-26 09:29 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Anvisoft
2014-07-26 09:28 - 2014-07-26 09:28 - 00003548 _____ () C:\Windows\System32\Tasks\Csb_AutoScan_Task
2014-07-26 09:18 - 2014-06-01 11:50 - 00000000 ___RD () C:\Users\waynehunterq\Desktop\Icons
2014-07-26 09:17 - 2014-04-12 21:38 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Severe Weather Alerts
2014-07-26 09:14 - 2014-07-26 09:14 - 00003748 _____ () C:\Windows\System32\Tasks\ASD_Schedule
2014-07-26 09:14 - 2014-07-26 09:07 - 00003304 _____ () C:\Windows\System32\Tasks\ASD_Main
2014-07-26 09:09 - 2014-04-12 22:29 - 00000000 ____D () C:\Windows\Panther
2014-07-26 09:07 - 2014-07-26 09:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft
2014-07-26 09:06 - 2014-07-26 09:06 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
2014-07-26 08:42 - 2014-07-26 08:42 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-WAYNEHUNTERQ-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-07-26 08:41 - 2014-07-26 08:41 - 00000000 ____D () C:\RegBackup
2014-07-26 08:40 - 2014-07-26 08:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-26 08:40 - 2014-07-26 08:40 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-07-25 23:33 - 2014-07-25 23:33 - 00010666 _____ () C:\Users\waynehunterq\Downloads\pixel.htm
2014-07-25 21:49 - 2014-07-25 21:49 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp23588
2014-07-25 19:59 - 2014-07-22 03:32 - 00000760 _____ () C:\Windows\Tasks\pennybee Runner.job
2014-07-25 19:58 - 2009-07-14 00:08 - 00032546 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-25 19:34 - 2014-07-25 19:33 - 02578135 _____ () C:\Users\waynehunterq\Downloads\shortshortts.wmv
2014-07-25 16:19 - 2014-07-27 11:15 - 00061072 _____ (StdLib) C:\Windows\system32\Drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}Gw64.sys
2014-07-25 10:13 - 2014-07-27 10:09 - 00575544 _____ (ClickMeIn Limited) C:\Users\waynehunterq\AppData\Local\AnyProtectScannerSetup.exe
2014-07-24 19:00 - 2014-07-24 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp3241
2014-07-23 19:00 - 2014-07-23 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp16151
2014-07-22 19:00 - 2014-07-22 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp28793
2014-07-22 13:49 - 2014-07-22 13:49 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp717
2014-07-22 03:34 - 2014-07-22 03:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector
2014-07-22 03:34 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Media Player Classic
2014-07-22 03:34 - 2014-07-22 03:33 - 00000000 ____D () C:\ProgramData\Systweak
2014-07-22 03:34 - 2014-07-22 03:33 - 00000000 ____D () C:\Program Files (x86)\ASP
2014-07-22 03:34 - 2014-07-22 03:32 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Systweak
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\unpacked11047
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\StormFall
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rocket
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp11037
2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\StormFall
2014-07-22 03:33 - 2014-07-22 03:32 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Rocket
2014-07-22 03:32 - 2014-07-22 03:32 - 00003556 _____ () C:\Windows\System32\Tasks\Rocket Updater
2014-07-22 03:32 - 2014-07-22 03:32 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\RocketUpdater
2014-07-22 03:32 - 2014-07-22 03:31 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Essentials Codec Pack
2014-07-22 03:32 - 2014-07-22 03:31 - 00000000 ____D () C:\Program Files (x86)\WSE Rocket
2014-07-22 03:32 - 2014-07-22 03:31 - 00000000 ____D () C:\Program Files (x86)\Essentials Codec Pack
2014-07-22 03:30 - 2014-07-22 03:30 - 00683360 _____ () C:\Users\waynehunterq\Downloads\MediaCodec.exe
2014-07-22 03:30 - 2014-07-22 03:30 - 00683360 _____ () C:\Users\waynehunterq\Downloads\MediaCodec (1).exe
2014-07-17 12:30 - 2014-07-17 12:30 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\RealNetworks
2014-07-17 12:29 - 2014-07-17 12:29 - 00000000 ____D () C:\ProgramData\RealNetworks
2014-07-17 12:28 - 2014-07-17 12:28 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2014-07-17 11:42 - 2014-07-22 03:31 - 00020328 _____ () C:\Windows\system32\roboot64.exe
2014-07-16 05:47 - 2009-07-14 00:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-29 19:12

==================== End Of Log ============================





Addition LOG
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-08-2014
Ran by waynehunterq at 2014-08-07 00:00:41
Running from C:\Users\waynehunterq\Desktop\Virus Recovery Folder
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 13.0.0.83 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 13.0.0.83 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 11 ActiveX (HKLM-x32\...\{41042E28-CCA1-4147-869F-9E928B38F04C}) (Version: 11.9.900.170 - Adobe Systems Incorporated)
Advanced-System Protector (HKLM-x32\...\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1) (Version: 2.1.1000.13665 - Systweak Software)
AMD Catalyst Install Manager (HKLM\...\{60BBC176-C393-6033-837E-B6BF4CDCBFB9}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Anvi Smart Defender 2.2 (HKLM-x32\...\Anvi Smart Defender) (Version: 2.2 - Anvisoft)
AnyProtect (HKLM-x32\...\AnyProtect) (Version: 1.0.0.1 - CMI Limited) <==== ATTENTION
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Bing Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.470.0 - Microsoft Corporation)
Buzzdock (HKLM\...\{ac225167-00fc-452d-94c5-bb93600e7d9a}) (Version: - Alactro LLC) <==== ATTENTION
Cloud System Booster (HKLM-x32\...\Cloud System Booster) (Version: 3.3 - Anvisoft)
CostMin (HKLM-x32\...\{2F5F003B-C71B-72E3-42B4-DE51AB079EB2}) (Version: 3.3.0.1900 - CostMin)
COTM App by We-Care.com v4.1.29.2 (HKLM-x32\...\{18753869-2CAE-44DD-B98A-0A8AC24B0D57}) (Version: 4.1.29.2 - We-Care.com)
Deal Keeper (HKLM\...\Deal Keeper) (Version: 2014.07.27.142853 - Deal Keeper) <==== ATTENTION
DriverRestore (HKLM\...\DriverRestore) (Version: 1.0 - 383 Media, Inc.)
File Type Assistant (HKLM-x32\...\Trusted Software Assistant_is1) (Version: 2014.5.6.0 - ) <==== ATTENTION
Free All-In-One Media Player (HKLM-x32\...\Free Media Player_is1) (Version: - Free Software Group)
FreeSoftToday 025.181 (HKLM-x32\...\fst_us_181_is1) (Version: - FREESOFTTODAY) <==== ATTENTION
FrostWire 5.7.4 (HKLM-x32\...\FrostWire 5) (Version: 5.7.4.1 - FrostWire LLC)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google Drive (HKLM-x32\...\{75939021-3B68-419D-8DC1-E9823BFF9658}) (Version: 1.16.7009.9618 - Google, Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
HiDef Media Player 1.1.12 (HKLM-x32\...\HiDef Media Player) (Version: 1.1.12 - HiDefMedia)
istart123 uninstall (HKLM-x32\...\istart123 uninstall) (Version: - istart123)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
ModifyRegistry version 0.1 (HKLM-x32\...\{1D5BE6B5-7FD4-4A78-90F2-AF6B53BC8C1C}_is1) (Version: 0.1 - VIA Technologies, Inc.)
ON_OFF Charge B12.1025.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE)
Optimizer Pro v3.2 (HKLM-x32\...\Optimizer Pro_is1) (Version: - ) <==== ATTENTION
PassShow (HKLM-x32\...\D653625D-A4F4-672A-F0EA-5B7F3331AB76) (Version: - PassShow-software) <==== ATTENTION
PC Fix Speed with PC Tech Hotline 1.2.0.42 (HKLM-x32\...\{F7B34B38-02A6-44D5-B8CC-06EB3B8ACFC9}_is1) (Version: 1.2.0.42 - Crawler, LLC)
Penny Bee (HKCU\...\pennybee) (Version: 3.0.0.0 - pennybee)
PennyBee (HKLM-x32\...\PennyBee) (Version: 1.0.1.0 - PennyBee)
Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
RAIDXpert (HKLM-x32\...\InstallShield_{8A4A80C2-87B1-44FB-BC24-9168930EB150}) (Version: 3.3.1540.19 - AMD)
RAIDXpert (x32 Version: 3.3.1540.19 - AMD) Hidden
RealDownloader (x32 Version: 17.0.11 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.10 - RealNetworks)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
RegClean-Pro (HKLM-x32\...\RegClean-Pro_is1) (Version: 6.21 - Systweak Inc) <==== ATTENTION
Remote Desktop Access (VuuPC) (HKLM-x32\...\VOPackage) (Version: 1.0.0.0 - CMI Limited) <==== ATTENTION
Rocket (HKCU\...\Rocket) (Version: 31.0.1650.23 - Rocket) <==== ATTENTION
Search Snacks (HKLM-x32\...\SearchSnacks) (Version: 1.9.0.5 - Search Snacks)
Severe Weather Alerts (HKCU\...\Severe Weather Alerts) (Version: 1.26.0.0 - Weather Notifications, LLC) <==== ATTENTION
ShopSave Toolbar (HKLM-x32\...\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}) (Version: 2.1.2 - KangoExtensions) <==== ATTENTION
sizlsearch (HKLM\...\sizlsearch) (Version: 2014.05.19.235641 - sizlsearch)
Sparta (HKCU\...\Sparta) (Version: - Sparta)
SpeedyPC Pro (HKLM-x32\...\{604CD5A1-4520-4844-B064-A3D884B77E91}) (Version: 3.2.5.0 - SpeedyPC Software) <==== ATTENTION
Start Savin (HKLM-x32\...\35450_Start Savin) (Version: 1.0 - App Squad)
StormFall (HKCU\...\StormFall) (Version: - StormFall)
Supporter 1.80 (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{be0fb33b}) (Version: - Costmin) <==== ATTENTION
suprasavings (HKLM\...\suprasavings) (Version: 2.0.1 - suprasavings) <==== ATTENTION
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 1.9.0 - Tweaking.com)
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
Wajam (HKLM-x32\...\Wajam) (Version: 2.12 (i2.4) - Wajam) <==== ATTENTION
WebInternetSecurity (HKCU\...\webinternetsecurity) (Version: - WebInternetSecurity) <==== ATTENTION
Windows Essentials Media Codec Pack 4.7 [64-Bit] (HKLM-x32\...\Windows Essentials Media Codec Pack) (Version: 4.7 - Media Codec)
WindowsMangerProtect20.0.0.502 (HKLM-x32\...\WindowsMangerProtect) (Version: 20.0.0.502 - WindowsProtect LIMITED) <==== ATTENTION
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
WSE Rocket (HKLM-x32\...\WSE Rocket) (Version: - WSE Rocket) <==== ATTENTION

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points =========================

27-07-2014 08:03:38 Windows Update
28-07-2014 00:00:14 Windows Backup
30-07-2014 23:07:39 Windows Update
07-08-2014 04:58:36 Windows Backup

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2014-07-22 03:32 - 00004512 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 capitalimonline.com
127.0.0.1 www.verifi-infonet.com
127.0.0.1 www.forsil-srl.com
127.0.0.1 trustedppiclaims.co.uk
127.0.0.1 ftp.signara.org
127.0.0.1 buy-fifa-ultimateteam-coins.com
127.0.0.1 pay.pal-schutz.com
127.0.0.1 swqk3xftx38.h149.pp39dk.com
127.0.0.1 robertoleal.es
127.0.0.1 verifi-infonet.com
127.0.0.1 ssl.paypal.secure.your.billing.information.mytrickworld.com
127.0.0.1 lastminute-ibiza.net
127.0.0.1 myaccount.aol.com.onlineaccounts.upgrade.online.billing.account.update.alcaldiadearaure.gob.ve
127.0.0.1 www.rhnp.org
127.0.0.1 173.214.178.24
127.0.0.1 bit.ly
127.0.0.1 www.axisengneering.com
127.0.0.1 www.positive-eft.com
127.0.0.1 hw0vrcfmu0fpd.com
127.0.0.1 www.art3c.com.tw
127.0.0.1 www.kielkoppfest.harzwinter.net
127.0.0.1 www.battle.net-account.asxp.cn.com
127.0.0.1 mgstrategiesstudio.com
127.0.0.1 www.paypal.com.p2jdb5zb17llxg1i.0243cn71m8gjun1.com
127.0.0.1 paypal.com.update.account.toughbook.cl
127.0.0.1 www.lappen-123.no
127.0.0.1 www.paypal-update.visitasgratis.info
127.0.0.1 stromarket.ru
127.0.0.1 www.ocevap.com

There are 65 more lines.


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {014E5A52-9DE4-4ACF-A6BB-C70CDEFC2233} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-12] (Google Inc.)
Task: {03513526-5A1A-46A6-973E-49D06396908D} - System32\Tasks\pcreg => C:\Program Files\pcreg\service.exe
Task: {154B95FB-CB85-4537-A9D1-5D51313CA3EB} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-06-10] (RealNetworks, Inc.)
Task: {2ABD568F-CAFC-4C30-A578-BF344B9A7C8F} - System32\Tasks\bench-S-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\Bench\Updater\updater.exe [2014-03-27] () <==== ATTENTION
Task: {42135C2B-4484-4958-8633-DF0CD0FAAE73} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe [2014-07-16] (Systweak)
Task: {4EF8989B-696F-45C3-9576-EA114C00DFE5} - System32\Tasks\ASD_Main => C:/Program Files (x86)/Anvisoft/Anvi Smart Defender/ASD2.exe [2014-05-28] (Anvisoft)
Task: {4FEBC66C-E3B6-4CF7-9F9A-09132DED1D42} - System32\Tasks\PassShow_wd => C:\Program Files (x86)\PassShowS\PassShowl.exe [2014-06-30] () <==== ATTENTION
Task: {5056BD37-B44A-4B74-84E9-162750B19586} - System32\Tasks\DriverRestore_DailyScan => C:\Program Files (x86)\DriverRestore\DriverRestore.exe [2014-07-06] ()
Task: {528569A1-44B4-4543-9A3B-6575C36451CF} - System32\Tasks\PassShow Update => C:\Program Files (x86)\PassShowS\PassShowG38.exe [2014-06-30] () <==== ATTENTION
Task: {5BD6371A-AC56-4D13-9D16-8577DAA01885} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-06-10] (RealNetworks, Inc.)
Task: {626A5E02-6F76-4FE5-AD90-FB708E5C64E6} - System32\Tasks\Sparta WW1 => Chrome.exe --kiosk http://plarium.com/play/en/sparta/top/?adCampaign=30639&amp;ClickID=zyyE0D0EzztD0C0EyCyD0C0AyD0E0EtB&amp;publisherID=9
Task: {6E696841-DD78-44EA-95FB-650AD1A6E7DF} - System32\Tasks\DriverRestore_ScheduledScan => C:\Program Files (x86)\DriverRestore\DriverRestore.exe [2014-07-06] ()
Task: {7739AE33-2144-4189-8051-1AA3E5CCB4B1} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-06-10] (RealNetworks, Inc.)
Task: {791E9AAD-2E64-4E0E-8DAC-D8BBCBCE3F98} - System32\Tasks\ProgramRefresh-ATFST => C:\Program Files (x86)\File Type Assistant\tsasetup.exe [2014-05-07] ( ) <==== ATTENTION
Task: {7E41D011-4B35-4B82-80C9-B00233622256} - System32\Tasks\bench-sys => C:\Program Files (x86)\Bench\Updater\updater.exe [2014-03-27] () <==== ATTENTION
Task: {8F740334-D45A-49CC-8081-2E74D56EEE2C} - System32\Tasks\ASD_Schedule => C:/Program Files (x86)/Anvisoft/Anvi Smart Defender/ASD2.exe [2014-05-28] (Anvisoft)
Task: {91502108-7823-4669-8E9D-26C9F66C03EA} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {9C6518F7-7332-427A-9544-55DF6B612927} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-12] (Google Inc.)
Task: {E0255F48-B4A5-46BE-B453-521B6BAD410F} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-07-17] (RCP)
Task: {E3C034E6-3579-4543-AEBA-D45356710DCB} - System32\Tasks\Rocket Updater => C:\Users\waynehunterq\AppData\Roaming\RocketUpdater\UpdateProc\UpdateTask.exe [2013-04-12] ()
Task: {E7B9136D-66B6-4312-BDE9-02CDE55954BB} - System32\Tasks\ProgramUpdateCheck => C:\Program Files (x86)\File Type Assistant\TSAssist.exe [2014-05-06] (FTA ApS) <==== ATTENTION
Task: {ED3A10DA-8279-45E6-AEA7-FCAE53BC715E} - System32\Tasks\Csb_AutoScan_Task => C:/Program Files (x86)/Anvisoft/Cloud System Booster/CloudSystemBooster.exe [2014-05-29] (Anvisoft)
Task: {F45FEB23-C672-4B49-B13E-3795EFFD302E} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-06-10] (RealNetworks, Inc.)
Task: {F829A5BC-D52D-4E54-84C4-19E633AF23B0} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-06-10] (RealNetworks, Inc.)
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-S-1-5-21-2235072853-4185849235-691160065-1000.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-sys.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\PassShow Update.job => C:\Program Files (x86)\PassShowS\PassShowG38.exe <==== ATTENTION
Task: C:\Windows\Tasks\PassShow_wd.job => C:\Program Files (x86)\PassShowS\PassShowl.exe <==== ATTENTION
Task: C:\Windows\Tasks\pennybee Runner.job => C:\PROGRA~3\pennybee\pennybee.exe
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RCP\RegCleanPro.exe
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RCP\RegCleanPro.exe
Task: C:\Windows\Tasks\SpeedyPC Pro_sch_94F6518D-14DF-11E4-A166-94DE80CE65CA.job => C:\Program Files (x86)\SpeedyPC Software\SpeedyPC\SpeedyPC.exe <==== ATTENTION
Task: C:\Windows\Tasks\SpeedyPC Registration3.job => C:\Program Files (x86)\Common Files\SpeedyPC Software\UUS3\UUS3.dll <==== ATTENTION
Task: C:\Windows\Tasks\SpeedyPC Update Version3.job => c:\program files (x86)\common files\speedypc software\uus3\SpeedyPC_Update3.exe <==== ATTENTION
Task: C:\Windows\Tasks\SpeedyPC Update Version3_triggeronce.job => c:\program files (x86)\common files\speedypc software\uus3\SpeedyPC_Update3.exe <==== ATTENTION
Task: C:\Windows\Tasks\Tempo Runner.job => C:\PROGRA~3\pennybee\pennybee.exe

==================== Loaded Modules (whitelisted) =============

2014-06-10 17:50 - 2014-06-10 17:50 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-06-10 22:03 - 2014-06-10 22:03 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
2014-07-27 09:58 - 2014-07-27 09:58 - 00071680 _____ () C:\Users\waynehunterq\AppData\Roaming\VOPackage\VOsrv.exe
2014-07-23 16:32 - 2014-07-26 11:07 - 00106376 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll64.dll
2014-06-30 21:17 - 2014-06-30 21:17 - 00100864 _____ () C:\Program Files (x86)\PassShowS\PassShowl.exe
2014-07-23 16:32 - 2014-07-26 11:07 - 00732040 _____ () C:\Program Files (x86)\SupTab\HpUI.exe
2014-07-16 11:16 - 2014-07-16 11:16 - 00064000 _____ () C:\Program Files (x86)\SupTab\Loader32.exe
2014-07-16 10:55 - 2014-07-16 10:55 - 00073216 _____ () C:\Program Files (x86)\SupTab\Loader64.exe
2014-07-27 11:14 - 2014-08-06 23:48 - 00323320 _____ () C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe
2014-04-12 23:08 - 2012-08-09 05:55 - 00078480 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2014-04-12 23:08 - 2012-08-09 05:55 - 00386192 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2014-07-27 11:15 - 2014-08-06 11:25 - 00286968 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.PurBrowse64.exe
2014-07-27 11:15 - 2014-08-06 23:31 - 00095528 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BrowserAdapter.exe
2014-07-27 09:28 - 2014-08-06 23:53 - 00323320 _____ () C:\Program Files (x86)\Deal Keeper\updateDealKeeper.exe
2011-07-22 14:48 - 2011-07-22 14:48 - 00516096 _____ () C:\Program Files (x86)\AMD\RAIDXpert\bin\libxml2.dll
2014-05-27 02:02 - 2014-05-27 02:02 - 00500968 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\http_hook.dll
2014-04-29 21:04 - 2014-04-29 21:04 - 00088080 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\libglog.dll
2014-05-27 02:02 - 2014-05-27 02:02 - 01039080 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASD2Engine.dll
2014-04-29 21:04 - 2014-04-29 21:04 - 00038928 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\fuzzy.dll
2014-04-29 21:04 - 2014-04-29 21:04 - 00093712 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\zlibwapi.dll
2014-05-27 02:02 - 2014-05-27 02:02 - 00135400 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ExtractImpl.dll
2014-05-27 02:02 - 2014-05-27 02:02 - 00437480 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\InnoExtractDll.dll
2014-05-27 02:02 - 2014-05-27 02:02 - 00030440 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\UnpackImpl.dll
2014-05-27 02:02 - 2014-05-27 02:02 - 00259816 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\pyunpacker.dll
2014-05-27 02:02 - 2014-05-27 02:02 - 00041704 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\fsmlib.dll
2014-04-29 20:27 - 2014-04-29 20:27 - 00649744 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\sqlite3.dll
2014-07-27 09:56 - 2014-07-27 09:56 - 00174416 _____ () c:\Program Files (x86)\Supporter\SupporterSvc.dll
2014-07-27 09:56 - 2014-07-27 09:56 - 04312064 _____ () c:\Program Files (x86)\Supporter\Supporter.dll
2014-07-28 17:09 - 2014-07-28 17:09 - 00861784 _____ () c:\program files (x86)\real\realplayer\RPDS\Plugins\cldplin.dll
2014-05-27 02:02 - 2014-05-27 02:02 - 00305896 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\UserProfile.dll
2014-05-28 04:25 - 2014-05-28 04:25 - 00776936 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\CoreScan.dll
2014-05-27 02:02 - 2014-05-27 02:02 - 00125672 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\FileSearcher.dll
2014-07-23 16:32 - 2014-07-26 11:07 - 00093576 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll
2014-05-29 01:47 - 2014-05-29 01:47 - 00018616 _____ () C:\Program Files (x86)\Anvisoft\Cloud System Booster\Public.dll
2013-11-27 04:33 - 2013-11-27 04:33 - 00156344 _____ () C:\Program Files (x86)\Anvisoft\Cloud System Booster\ui.dll
2013-11-27 04:33 - 2013-11-27 04:33 - 00090808 _____ () C:\Program Files (x86)\Anvisoft\Cloud System Booster\libglognc.dll
2014-05-29 01:47 - 2014-05-29 01:47 - 00028856 _____ () C:\Program Files (x86)\Anvisoft\Cloud System Booster\extentions\TestExtention.dll
2014-08-06 23:48 - 2014-08-06 23:48 - 00098816 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32api.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00110080 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\pywintypes27.dll
2014-08-06 23:48 - 2014-08-06 23:48 - 00364544 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\pythoncom27.dll
2014-08-06 23:48 - 2014-08-06 23:48 - 00045568 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_socket.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 01160704 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_ssl.pyd
2014-08-06 23:48 - 2014-08-06 23:48 - 00320512 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32com.shell.shell.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00713216 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_hashlib.pyd
2014-08-06 23:48 - 2014-08-06 23:48 - 01175040 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._core_.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00805888 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._gdi_.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00811008 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._windows_.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 01062400 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._controls_.pyd
2014-08-06 23:48 - 2014-08-06 23:48 - 00735232 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._misc_.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00128512 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_elementtree.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00127488 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\pyexpat.pyd
2014-08-06 23:48 - 2014-08-06 23:48 - 00557056 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\pysqlite2._sqlite.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00007168 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\hashobjs_ext.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00087552 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_ctypes.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00119808 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32file.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00108544 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32security.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00018432 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32event.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00038912 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32inet.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00070656 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._html2.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00167936 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32gui.pyd
2014-08-06 23:48 - 2014-08-06 23:48 - 00011264 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32crypt.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00027136 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_multiprocessing.pyd
2014-08-06 23:48 - 2014-08-06 23:48 - 00122368 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._wizard.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00010240 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\select.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00024064 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32pipe.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00686080 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\unicodedata.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00025600 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32pdh.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00525640 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\windows._lib_cacheinvalidation.pyd
2014-08-06 23:48 - 2014-08-06 23:48 - 00035840 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32process.pyd
2014-08-06 23:49 - 2014-08-06 23:49 - 00017408 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32profile.pyd
2014-08-06 23:48 - 2014-08-06 23:48 - 00022528 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32ts.pyd
2014-08-06 23:48 - 2014-08-06 23:48 - 00078336 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._animate.pyd
2014-07-27 11:15 - 2014-08-06 23:31 - 00195320 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeperBAApp.dll
2014-07-18 15:28 - 2014-07-15 04:24 - 00718664 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libglesv2.dll
2014-07-18 15:28 - 2014-07-15 04:24 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libegl.dll
2014-07-18 15:28 - 2014-07-15 04:24 - 08537928 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll
2014-07-18 15:28 - 2014-07-15 04:24 - 00353096 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll
2014-07-18 15:28 - 2014-07-15 04:24 - 01732936 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll
2014-07-18 15:28 - 2014-07-15 04:24 - 14664008 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: {9d5747ee-0448-4681-8337-1555de75a3b6}Gw64
Description: {9d5747ee-0448-4681-8337-1555de75a3b6}Gw64
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: {9d5747ee-0448-4681-8337-1555de75a3b6}Gw64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/31/2014 11:00:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SettingsManagerSetup.exe, version: 5.0.0.0, time stamp: 0x51a70926
Faulting module name: Helper.DLL, version: 0.0.0.0, time stamp: 0x53da3fb9
Exception code: 0xc0000005
Fault offset: 0x00159005
Faulting process id: 0xb6c
Faulting application start time: 0xSettingsManagerSetup.exe0
Faulting application path: SettingsManagerSetup.exe1
Faulting module path: SettingsManagerSetup.exe2
Report Id: SettingsManagerSetup.exe3

Error: (07/31/2014 01:12:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17207, time stamp: 0x53a20c50
Faulting module name: urlmon.dll, version: 11.0.9600.17207, time stamp: 0x53a20e1a
Exception code: 0xc0000005
Fault offset: 0x00042d30
Faulting process id: 0x159c
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3

Error: (07/31/2014 09:04:04 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17207 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 2554

Start Time: 01cfacc68de2c711

Termination Time: 18

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id:

Error: (07/31/2014 08:52:58 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17207 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1c6c

Start Time: 01cfacc049f9e666

Termination Time: 23

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id:

Error: (07/31/2014 05:28:59 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17207 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 2be4

Start Time: 01cfaca33a7e9f5a

Termination Time: 45

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id:

Error: (07/31/2014 00:06:16 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (07/30/2014 00:01:51 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (07/29/2014 07:17:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17207, time stamp: 0x53a20c50
Faulting module name: urlmon.dll, version: 11.0.9600.17207, time stamp: 0x53a20e1a
Exception code: 0xc0000005
Fault offset: 0x00042d30
Faulting process id: 0x2bd8
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3

Error: (07/29/2014 07:15:41 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (07/29/2014 06:46:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17207, time stamp: 0x53a20c50
Faulting module name: urlmon.dll, version: 11.0.9600.17207, time stamp: 0x53a20e1a
Exception code: 0xc0000005
Fault offset: 0x00042d30
Faulting process id: 0x33c
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3


System errors:
=============
Error: (08/06/2014 11:49:47 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
%%-2147467259

Error: (08/06/2014 11:49:47 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147467259

Error: (08/06/2014 11:48:38 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
{9d5747ee-0448-4681-8337-1555de75a3b6}Gw64

Error: (08/06/2014 11:48:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The wpennybeed service failed to start due to the following error:
%%2

Error: (08/06/2014 11:48:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Util sizlsearch service failed to start due to the following error:
%%2

Error: (08/06/2014 11:48:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Update sizlsearch service failed to start due to the following error:
%%2

Error: (08/06/2014 11:48:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Search Snacks Client Service service failed to start due to the following error:
%%2

Error: (08/06/2014 11:48:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The pennybee service failed to start due to the following error:
%%2

Error: (08/06/2014 11:48:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The pcregservice Service service failed to start due to the following error:
%%2

Error: (08/04/2014 09:04:52 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}


Microsoft Office Sessions:
=========================
Error: (07/31/2014 11:00:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: SettingsManagerSetup.exe5.0.0.051a70926Helper.DLL0.0.0.053da3fb9c000000500159005b6c01cfad3d171288c2C:\Users\WAYNEH~1\AppData\Local\Temp\nshD4D8.tmp\SettingsManagerSetup.exeC:\Users\WAYNEH~1\AppData\Local\Temp\nshD788.tmp\Helper.DLL5dede387-1930-11e4-ac80-94de80ce65ca

Error: (07/31/2014 01:12:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: IEXPLORE.EXE11.0.9600.1720753a20c50urlmon.dll11.0.9600.1720753a20e1ac000000500042d30159c01cfaceaeb71987eC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dll49646401-18de-11e4-ac80-94de80ce65ca

Error: (07/31/2014 09:04:04 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17207255401cfacc68de2c71118C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (07/31/2014 08:52:58 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.172071c6c01cfacc049f9e66623C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (07/31/2014 05:28:59 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.172072be401cfaca33a7e9f5a45C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (07/31/2014 00:06:16 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"C:\Windows\Installer\{20C2051A-1ACA-48B4-9BA5-24625DCBD880}\recordingmanager.exe

Error: (07/30/2014 00:01:51 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"C:\Windows\Installer\{20C2051A-1ACA-48B4-9BA5-24625DCBD880}\recordingmanager.exe

Error: (07/29/2014 07:17:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: IEXPLORE.EXE11.0.9600.1720753a20c50urlmon.dll11.0.9600.1720753a20e1ac000000500042d302bd801cfab8350eefef0C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dllf5db6c40-177e-11e4-ac80-94de80ce65ca

Error: (07/29/2014 07:15:41 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"C:\Windows\Installer\{20C2051A-1ACA-48B4-9BA5-24625DCBD880}\recordingmanager.exe

Error: (07/29/2014 06:46:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: IEXPLORE.EXE11.0.9600.1720753a20c50urlmon.dll11.0.9600.1720753a20e1ac000000500042d3033c01cfab80cd63fc2aC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dll8c365dc6-177a-11e4-ac80-94de80ce65ca


==================== Memory info ===========================

Percentage of memory in use: 45%
Total physical RAM: 5629.55 MB
Available physical RAM: 3086.29 MB
Total Pagefile: 11257.29 MB
Available Pagefile: 8448.05 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: (New Volume) (Fixed) (Total:149.05 GB) (Free:74.17 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (LIBRARY) (Removable) (Total:14.9 GB) (Free:12.32 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 8D688C24)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 15 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

==================== End Of Log ============================

tashi
2014-08-07, 17:34
Hello Hunterkiller,

Last topic closed due to lack of feedback: http://forums.spybot.info/showthread.php?70881-need-assistance-with-malware-and-adware-lol

Also see: http://forums.spybot.info/showthread.php?70878-In-need-of-assistance-in-removal-of-Malware-and-Adware&p=455766#post455766


Hey guys, my father and I had a falling out. Needless to say, he doesnt want to proceed with the work you guys had layed out for us. So, I figured I could atleast try and get my machine clean. Any help would be greatly appreciated. For some reason aswMBR isnt working correctly, it wont update the virus definitions and it wont allow me to scan at all. Any Ideas?


Under the circumstances it might be best if you take the machine to a technician. :)

Best regards.