PDA

View Full Version : Infected with Spyware - unable to clean



geraldgrogan
2014-10-05, 23:34
In an attempt to upgrade to the latest AOL desktop software I ran across some very tough spyware apps that I could not remove.
Any help would be appreciated.

==============
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-10-2014
Ran by Nancy (administrator) on NANCY-PC on 05-10-2014 14:39:11
Running from C:\Users\Nancy\Downloads\Repair_forum
Loaded Profile: Nancy (Available profiles: Nancy & Mcx1-NANCY-PC)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(iS3, Inc.) C:\Program Files (x86)\STOPzilla!\SZServer.exe
(AMD) C:\Windows\System32\atieclxx.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
() C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
(NDS Technologies) C:\Users\Nancy\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
() C:\Users\Nancy\AppData\Local\DIRECTV Player\NDSPCShowServer.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe
(AOL Inc.) C:\Users\Nancy\AppData\Local\AOL\AIM\aim.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
(Hewlett-Packard) C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
(Humana Inc.) C:\Users\Public\Humana\GearSync\Humana_GearSync.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\aol\1412533129\ee\aolsoftware.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\CNYHKEY.exe
(Belkin International, Inc.) C:\Program Files\Belkin\Belkin USB Print and Storage Center\Connect.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(iS3, Inc.) C:\Program Files (x86)\STOPzilla!\STOPzilla.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(AOL Inc.) C:\Program Files\AIM Toolbar\aimtbServer.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_15_0_0_167_ActiveX.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\aol\acs\AOLDial.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\aol\acs\AOLacsd.exe
(AOL Inc.) C:\Program Files\AOL Toolbar\aoltbServer.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SmartMenu] => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [610360 2009-07-08] ()
HKLM-x32\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM-x32\...\Run: [BATINDICATOR] => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe [2068992 2009-05-08] (Hewlett-Packard)
HKLM-x32\...\Run: [LaunchHPOSIAPP] => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe [385024 2009-04-03] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Remote Solution] => C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe [656896 2009-05-26] ()
HKLM-x32\...\Run: [HP Software Update] => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [InstaLAN] => C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe [1485208 2010-07-28] (Affinegy, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GearSyncAutoStart] => C:\Users\Public\Humana\GearSync\Humana_GearSync.exe [535112 2012-08-23] (Humana Inc.)
HKLM-x32\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [3414560 2014-05-19] (Fitbit, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [HostManager] => C:\Program Files (x86)\Common Files\AOL\1412533129\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [HPADVISOR] => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1668664 2009-07-15] (Hewlett-Packard)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-03-01] (Google Inc.)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1938112 2014-09-22] (Valve Corporation)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [PCShowServer] => C:\Users\Nancy\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe [351888 2012-04-02] (NDS Technologies)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-08-27] (TomTom)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [3414560 2014-05-19] (Fitbit, Inc.)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [AIM for Windows] => C:\Users\Nancy\AppData\Local\AOL\AIM\aim.exe [1075144 2014-02-04] (AOL Inc.)
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/?mtmhp=hyplogusaolp00000092
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt
URLSearchHook: HKLM-x32 - Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn0.dll No File
URLSearchHook: HKLM-x32 - (No Name) - {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - No File
URLSearchHook: HKCU - (No Name) - {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - No File
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {71588120-FC17-4463-B07D-2C71FE6E057B} URL = http://go.findrsearch.com/search/web?q={searchTerms}
SearchScopes: HKLM - {C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = http://slirsredirect.search.aol.com/redirector/sredir?sredir=843&query={SearchTerms}&invocationType=tb50TB50CL-chromesbox-en-us
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2438727
SearchScopes: HKLM-x32 - {C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
SearchScopes: HKCU - {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = http://slirsredirect.search.aol.com/redirector/sredir?sredir=843&query={SearchTerms}&invocationType=tb50TB50CL-chromesbox-en-us
SearchScopes: HKCU - {71588120-FC17-4463-B07D-2C71FE6E057B} URL =
SearchScopes: HKCU - {C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF} URL =
BHO: AOL Toolbar Loader -> {3ef64538-8b54-4573-b48f-4d34b0238ab2} -> C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: AOL Messaging Toolbar Loader -> {b0cda128-b425-4eef-a174-61a11ac5dbf8} -> C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: IEPlugin Class -> {11222041-111B-46E3-BD29-EFB2449479B1} -> C:\Program Files (x86)\ArcSoft\Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
BHO-x32: AOL Toolbar Loader -> {3ef64538-8b54-4573-b48f-4d34b0238ab2} -> C:\Program Files (x86)\AOL Toolbar\aoltb.dll (AOL Inc.)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Zynga Toolbar -> {7b13ec3e-999a-4b70-b9cb-2617b8323822} -> C:\Program Files (x86)\Zynga\prxtbZyn0.dll No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: ToolbarBHO Class -> {9519AF7E-638D-4933-BAD6-D33D23C79FE5} -> C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: AOL Messaging Toolbar Loader -> {b0cda128-b425-4eef-a174-61a11ac5dbf8} -> C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL Inc.)
BHO-x32: Microsoft Live Search Toolbar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM - AOL Messaging Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
Toolbar: HKLM - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
Toolbar: HKLM-x32 - Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
Toolbar: HKLM-x32 - Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn0.dll No File
Toolbar: HKLM-x32 - No Name - {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - No File
Toolbar: HKLM-x32 - RAW Thumbnail Viewer - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - AOL Messaging Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL Inc.)
Toolbar: HKLM-x32 - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll (AOL Inc.)
Toolbar: HKCU - No Name - {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - No File
Toolbar: HKCU - No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
Toolbar: HKCU - No Name - {90A1B331-C2B4-4933-9F63-BA7B84D60D58} - No File
Toolbar: HKCU - AOL Messaging Toolbar - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
Toolbar: HKCU - AOL Toolbar - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
DPF: HKLM-x32 {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://www.caminova.net/en/downloads/getmodule.aspx?lang=en
DPF: HKLM-x32 {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab
DPF: HKLM-x32 {C6A47FBB-2ECA-430E-8466-5523772CA4FA} http://www.uscconlinealbum.com/tlc/script/ext/bulkuploader/Uploader8.cab
DPF: HKLM-x32 {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v10.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: lbxfile - {56831180-F115-11d2-B6AA-00104B2B9943} - No File
Handler: lbxres - {24508F1B-9E94-40EE-9759-9AF5795ADF52} - No File
Handler-x32: lbxfile - {56831180-F115-11d2-B6AA-00104B2B9943} - C:\Program Files (x86)\Libronix DLS\System\FileProt.dll (Libronix Corporation)
Handler-x32: lbxres - {24508F1B-9E94-40EE-9759-9AF5795ADF52} - C:\Program Files (x86)\Libronix DLS\System\ResProt.dll (Libronix Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=1.132.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=1.140.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @viewpoint.com/VMP -> C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: npEpicPlayDisplayHost -> C:\Program Files (x86)\EpicPlay\npEpicHost.dll ( )
FF Plugin HKCU: @nds.com/PCShowPlugin -> C:\Users\Nancy\AppData\Local\DIRECTV Player\npPCShowPlugin.dll (NDS)
FF Plugin HKCU: @nds.com/PlayerPlugin -> C:\Users\Nancy\AppData\Local\DIRECTV Player\npPlayerPlugin.dll (NDS)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
FF Plugin HKCU: NDS.com/PlayerPlugin -> C:\Users\Nancy\AppData\Local\DIRECTV Player\npPlayerPlugin.dll (NDS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Extension: RivalGaming - C:\Users\Nancy\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\links@rivalgaming.com [2012-02-23]
FF Extension: EpicPlay Games - C:\Users\Nancy\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@epicplay.com [2011-09-27]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-01-18]
FF HKLM-x32\...\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn
FF HKLM-x32\...\Firefox\Extensions: [{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}] - C:\Program Files (x86)\ArcSoft\Video Downloader\Plugin_FireFox
FF Extension: ArcSoft Video Downloader Extension - C:\Program Files (x86)\ArcSoft\Video Downloader\Plugin_FireFox [2013-12-25]
FF HKLM-x32\...\Firefox\Extensions: [RAWThumbnailViewer@arcsoft.com.cn] - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension
FF Extension: RAW Thumbnail Viewer - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension [2013-12-25]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR Profile: C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-21]
CHR Extension: (Google Search) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-21]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2012-11-01]
CHR Extension: (Virtual Keyboard) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2012-11-01]
CHR Extension: (Google Wallet) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Gmail) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-21]
CHR Extension: (Anti-Banner) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2012-11-01]
CHR HKCU\...\Chrome\Extension: [bpfboklmeiefoedekjeigdcnfbpjeaii] - C:\Users\Nancy\AppData\Local\CRE\bpfboklmeiefoedekjeigdcnfbpjeaii.crx []
CHR HKLM-x32\...\Chrome\Extension: [bpfboklmeiefoedekjeigdcnfbpjeaii] - C:\Users\Nancy\AppData\Local\CRE\bpfboklmeiefoedekjeigdcnfbpjeaii.crx []
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AffinegyService; C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe [569752 2010-07-28] (Affinegy, Inc.)
R2 Belkin Local Backup Service; C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe [181760 2010-02-17] () [File not signed]
R2 Belkin Network USB Helper; C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe [55296 2010-02-09] () [File not signed]
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [1436192 2014-05-19] (Fitbit, Inc.)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries)
R2 HPBtnSrv; C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe [192512 2008-09-30] () [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 iprip; C:\Windows\System32\iprip.dll [35328 2009-07-13] (Microsoft Corporation)
R2 LightScribeService; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-05-18] (Hewlett-Packard Company) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 szserver; c:\Program Files (x86)\STOPzilla!\SZServer.exe [57136 2014-08-27] (iS3, Inc.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S0 is3srv; C:\Windows\SysWow64\drivers\is3srv64.sys [74768 2014-08-27] (iS3 Inc.)
S3 mr8980; C:\Windows\System32\DRIVERS\dwcamx64.sys [84992 2010-05-11] (Mars Semiconductor Corp.)
S3 mr8980; C:\Windows\SysWOW64\DRIVERS\dwcamx64.sys [84992 2010-05-11] (Mars Semiconductor Corp.)
S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [10368 2008-07-16] (Padus, Inc.) [File not signed]
R3 sxuptp; C:\Windows\System32\DRIVERS\sxuptp.sys [291352 2009-06-22] (silex technology, Inc.)
R0 szkg5; C:\Windows\SysWow64\DRIVERS\szkg64.sys [74768 2014-08-27] (iS3 Inc.)
S3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2010-01-21] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [27648 2010-01-21] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [33280 2010-01-21] (LG Electronics Inc.)
R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [146928 2009-07-23] (CyberLink Corp.)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-05 14:38 - 2014-10-05 14:39 - 00000000 ____D () C:\FRST
2014-10-05 14:33 - 2014-10-05 14:33 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-NANCY-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-10-05 14:31 - 2014-10-05 14:31 - 00002201 _____ () C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2014-10-05 14:31 - 2014-10-05 14:31 - 00000000 ____D () C:\RegBackup
2014-10-05 14:31 - 2014-10-05 14:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-10-05 14:31 - 2014-10-05 14:31 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-10-05 14:30 - 2014-10-05 14:39 - 00000000 ____D () C:\Users\Nancy\Downloads\Repair_forum
2014-10-05 14:18 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-10-05 14:17 - 2014-10-05 14:18 - 00000000 ____D () C:\AdwCleaner
2014-10-05 14:17 - 2014-10-05 14:17 - 01375089 _____ () C:\Users\Nancy\Downloads\adwcleaner_3.311.exe
2014-10-05 14:12 - 2014-10-05 14:12 - 00001016 _____ () C:\Windows\system32\Drivers\kgpcpy.cfg
2014-10-05 13:21 - 2014-10-05 13:21 - 00000995 _____ () C:\Users\Public\Desktop\AOL Desktop 9.7.lnk
2014-10-05 13:21 - 2014-10-05 13:21 - 00000929 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\AOL Desktop 9.7.lnk
2014-10-05 13:19 - 2014-10-05 14:13 - 00000000 ____D () C:\Users\Nancy\AppData\Local\AOL Toolbar
2014-10-05 13:19 - 2014-10-05 13:19 - 00000000 ____D () C:\ProgramData\AOL Toolbar
2014-10-05 13:19 - 2014-10-05 13:19 - 00000000 ____D () C:\Program Files\AOL Toolbar
2014-10-05 13:18 - 2014-10-05 14:01 - 00000000 ____D () C:\Program Files (x86)\AOL Desktop 9.7
2014-10-05 13:18 - 2014-10-05 13:18 - 00000000 ____D () C:\Program Files (x86)\AOL
2014-10-05 00:37 - 2014-10-05 00:37 - 00000000 _____ () C:\autoexec.bat
2014-10-05 00:36 - 2014-10-05 00:36 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-10-05 00:35 - 2014-10-05 09:31 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-10-05 00:22 - 2014-10-05 00:24 - 159405792 _____ () C:\Users\Nancy\Downloads\setup_11.0.3.7.x01_2014_10_05_08_26.exe
2014-10-04 21:32 - 2014-10-04 22:44 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-04 21:32 - 2014-10-04 21:32 - 00001075 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-04 21:32 - 2014-10-04 21:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-04 21:32 - 2014-10-04 21:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware2
2014-10-04 21:32 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-04 21:32 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-04 21:32 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-04 21:18 - 2014-10-04 21:19 - 00000000 ____D () C:\Users\Nancy\AppData\Local\AIM Toolbar
2014-10-04 21:18 - 2014-10-04 21:18 - 00001078 _____ () C:\Users\Nancy\Desktop\AIM.lnk
2014-10-04 21:18 - 2014-10-04 21:18 - 00000000 ____D () C:\Users\Nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AIM for Windows
2014-10-04 21:18 - 2014-10-04 21:18 - 00000000 ____D () C:\ProgramData\AIM Toolbar
2014-10-04 21:18 - 2014-10-04 21:18 - 00000000 ____D () C:\Program Files\AIM Toolbar
2014-10-04 21:18 - 2014-10-04 21:18 - 00000000 ____D () C:\Program Files (x86)\AIM Toolbar
2014-10-04 20:37 - 2014-10-04 20:37 - 00000000 ____D () C:\Windows\pss
2014-10-04 20:29 - 2014-10-04 20:29 - 00276448 _____ () C:\Windows\Minidump\100414-96798-01.dmp
2014-10-04 20:18 - 2014-10-05 13:19 - 00000000 ____D () C:\Program Files (x86)\AOL Toolbar
2014-10-04 20:18 - 2014-10-04 20:18 - 00000000 ____D () C:\ProgramData\Viewpoint
2014-10-04 20:18 - 2014-10-04 20:18 - 00000000 ____D () C:\Program Files (x86)\Viewpoint
2014-10-04 20:13 - 2014-10-04 20:12 - 00213168 _____ (AOL LLC.) C:\Users\Nancy\Downloads\AOL_Desktop_9.7 - Copy.exe
2014-10-04 20:00 - 2014-10-05 13:04 - 00000004 _____ () C:\Windows\msoffice.ini
2014-10-04 17:40 - 2014-10-05 13:30 - 00000000 ____D () C:\Users\Nancy\AppData\Roaming\AOL
2014-10-04 17:29 - 2014-10-05 13:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL
2014-10-04 17:27 - 2014-10-05 13:49 - 00000000 ____D () C:\ProgramData\AOL
2014-10-04 17:27 - 2014-10-05 13:06 - 00000000 ____D () C:\Users\Nancy\AppData\Local\AOL
2014-10-04 17:27 - 2014-10-04 17:27 - 00000000 ____D () C:\ProgramData\AOL OCP
2014-10-04 16:26 - 2014-10-04 16:26 - 00000000 ___SD () C:\Users\Nancy\Documents\Passwords Database
2014-10-04 15:47 - 2014-10-04 15:47 - 00040195 _____ () C:\Users\Nancy\Downloads\aolcleaner.exe
2014-10-04 14:55 - 2014-10-04 15:11 - 00000556 _____ () C:\Windows\wininit.ini
2014-10-04 14:16 - 2011-01-14 07:30 - 00000864 _____ () C:\Windows\system32\Drivers\etc\hosts.20141004-141646.backup
2014-10-04 14:15 - 2011-01-14 07:30 - 00000864 _____ () C:\Windows\system32\Drivers\etc\hosts.20141004-141549.backup
2014-10-04 14:11 - 2014-10-04 14:11 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Nancy\Downloads\mbam-setup-2.0.2.1012.exe
2014-10-04 14:06 - 2014-10-04 16:09 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-04 14:03 - 2014-10-04 14:55 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-10-04 14:03 - 2014-10-04 14:03 - 00001357 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-10-04 14:03 - 2014-10-04 14:03 - 00001345 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-10-04 14:03 - 2014-10-04 14:03 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-10-04 14:03 - 2014-10-04 14:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-10-04 14:03 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-10-04 14:02 - 2014-10-04 14:08 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-10-04 13:33 - 2014-09-24 21:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-04 13:33 - 2014-09-24 20:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-09-23 15:25 - 2014-09-09 17:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-23 15:25 - 2014-09-09 16:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-21 15:34 - 2014-09-21 15:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STOPzilla
2014-09-21 15:34 - 2014-08-27 13:30 - 00047496 ____R (GFI Software) C:\Windows\system32\SBBD.EXE
2014-09-20 13:31 - 2014-09-20 13:31 - 00002960 _____ () C:\Windows\System32\Tasks\{CF53108C-8CD9-43C0-9E68-E83BA10A8BCF}
2014-09-20 13:31 - 2014-09-20 13:31 - 00002960 _____ () C:\Windows\System32\Tasks\{0F12769E-3D7A-4A4C-AE76-99D4A60601DA}
2014-09-16 13:17 - 2014-09-16 13:17 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2014-09-16 13:17 - 2014-09-16 13:17 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2014-09-16 13:17 - 2014-09-16 13:17 - 00163840 _____ (America Online) C:\Windows\SysWOW64\jgdw400.dll
2014-09-16 13:17 - 2014-09-16 13:17 - 00027648 _____ (Johnson-Grace Company) C:\Windows\SysWOW64\jgpl400.dll
2014-09-15 16:17 - 2014-09-15 16:17 - 00002960 _____ () C:\Windows\System32\Tasks\{C4005CD9-C787-46F7-8F15-0C72A236B33F}
2014-09-15 13:28 - 2014-09-15 13:28 - 00003168 _____ () C:\Windows\System32\Tasks\{3AB45F11-DEB1-4623-A3D6-5E593F57AE41}
2014-09-14 15:27 - 2014-09-14 15:27 - 00000000 ____D () C:\ProgramData\Oracle
2014-09-14 15:26 - 2014-09-14 15:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-09-14 15:26 - 2014-07-25 12:55 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-09-14 15:26 - 2014-07-25 12:49 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-09-14 15:26 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-09-14 15:26 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-09-14 15:25 - 2014-09-14 15:26 - 00006747 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_67-b01.log
2014-09-13 14:25 - 2014-09-13 14:25 - 00284672 _____ () C:\Windows\Minidump\091314-23961-01.dmp
2014-09-11 12:54 - 2014-09-11 12:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fitbit Connect
2014-09-11 12:54 - 2014-09-11 12:54 - 00000000 ____D () C:\ProgramData\FitbitConnect
2014-09-11 12:54 - 2014-09-11 12:54 - 00000000 ____D () C:\Program Files (x86)\Fitbit Connect
2014-09-11 03:09 - 2014-08-19 13:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 03:09 - 2014-08-19 12:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 03:09 - 2014-08-18 18:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 03:09 - 2014-08-18 17:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 03:09 - 2014-08-18 17:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 03:09 - 2014-08-18 17:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 03:09 - 2014-08-18 17:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 03:09 - 2014-08-18 17:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 03:09 - 2014-08-18 17:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-11 03:09 - 2014-08-18 17:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 03:09 - 2014-08-18 17:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-11 03:09 - 2014-08-18 17:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-11 03:09 - 2014-08-18 17:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 03:09 - 2014-08-18 17:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 03:09 - 2014-08-18 17:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 03:09 - 2014-08-18 17:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-11 03:09 - 2014-08-18 17:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-11 03:09 - 2014-08-18 17:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-11 03:09 - 2014-08-18 17:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-11 03:09 - 2014-08-18 16:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 03:09 - 2014-08-18 16:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 03:09 - 2014-08-18 16:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 03:09 - 2014-08-18 16:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-11 03:09 - 2014-08-18 16:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 03:09 - 2014-08-18 16:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 03:09 - 2014-08-18 16:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 03:09 - 2014-08-18 16:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 03:09 - 2014-08-18 16:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 03:09 - 2014-08-18 16:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 03:09 - 2014-08-18 16:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 03:09 - 2014-08-18 16:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 03:09 - 2014-08-18 16:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 03:09 - 2014-08-18 16:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 03:09 - 2014-08-18 16:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-11 03:09 - 2014-08-18 16:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 03:09 - 2014-08-18 16:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 03:09 - 2014-08-18 16:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 03:09 - 2014-08-18 16:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 03:09 - 2014-08-18 16:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 03:09 - 2014-08-18 16:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 03:09 - 2014-08-18 16:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-11 03:09 - 2014-08-18 16:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 03:09 - 2014-08-18 16:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 03:09 - 2014-08-18 16:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 03:09 - 2014-08-18 16:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 03:09 - 2014-08-18 16:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 03:09 - 2014-08-18 16:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 03:09 - 2014-08-18 16:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 03:09 - 2014-08-18 16:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 03:09 - 2014-08-18 16:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 03:09 - 2014-08-18 16:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 03:09 - 2014-08-18 15:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 03:09 - 2014-08-18 15:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 03:09 - 2014-08-18 15:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 03:09 - 2014-08-18 15:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-11 03:09 - 2014-08-18 15:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 03:01 - 2014-06-26 21:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 03:01 - 2014-06-26 20:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-10 04:21 - 2014-09-04 21:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-10 04:21 - 2014-09-04 21:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-10 04:21 - 2014-08-01 06:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-10 04:21 - 2014-08-01 06:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-10 04:21 - 2014-07-06 21:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-10 04:21 - 2014-07-06 21:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-10 04:21 - 2014-07-06 20:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-10 04:21 - 2014-07-06 20:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-10 04:21 - 2014-07-06 20:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-09-10 04:21 - 2014-06-23 22:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-10 04:21 - 2014-06-23 21:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-05 13:37 - 2014-09-05 13:37 - 00284672 _____ () C:\Windows\Minidump\090514-20155-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-05 14:39 - 2011-01-14 07:26 - 00000000 ____D () C:\ProgramData\STOPzilla!
2014-10-05 14:31 - 2010-03-01 18:52 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-05 14:17 - 2009-07-13 23:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-05 14:17 - 2009-07-13 23:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-05 14:13 - 2012-06-18 19:36 - 02038498 _____ () C:\Windows\WindowsUpdate.log
2014-10-05 14:09 - 2011-07-01 22:52 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-10-05 14:06 - 2010-03-01 18:52 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-05 14:05 - 2012-06-18 19:27 - 00019810 _____ () C:\Windows\setupact.log
2014-10-05 14:05 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-05 14:03 - 2012-06-04 10:47 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-05 13:22 - 2009-12-18 23:23 - 00867304 _____ () C:\Windows\PFRO.log
2014-10-05 13:21 - 2011-12-22 15:50 - 00009351 ____H () C:\IPH.PH
2014-10-05 13:21 - 2011-03-07 03:47 - 00512498 _____ () C:\install.log
2014-10-05 13:16 - 2009-12-18 22:00 - 00058696 _____ (AOL Inc.) C:\Windows\SysWOW64\AOLParconLink.exe
2014-10-05 11:58 - 2013-07-06 16:57 - 00000464 _____ () C:\Windows\Tasks\Arcadesafari.job
2014-10-05 00:25 - 2010-03-01 22:14 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-10-04 23:27 - 2009-08-31 14:06 - 00000000 ____D () C:\ProgramData\Symantec
2014-10-04 23:10 - 2014-05-27 21:26 - 00000000 ____D () C:\Users\Nancy\AppData\Roaming\PerformerSoft
2014-10-04 23:10 - 2013-11-08 15:00 - 00000000 ____D () C:\ProgramData\Conduit
2014-10-04 23:10 - 2013-11-08 15:00 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2014-10-04 22:52 - 2014-03-15 14:33 - 00000000 ____D () C:\Program Files (x86)\Activeris AntiMalware
2014-10-04 22:52 - 2013-11-08 16:11 - 00009392 _____ () C:\Windows\SysWOW64\Drivers\kgpfr2.cfg
2014-10-04 20:37 - 2013-02-16 18:35 - 00000000 ____D () C:\Users\Nancy\AppData\Local\PMB Files
2014-10-04 20:29 - 2012-11-09 07:35 - 616735266 _____ () C:\Windows\MEMORY.DMP
2014-10-04 20:29 - 2010-03-16 07:34 - 00000000 ____D () C:\Windows\Minidump
2014-10-04 20:00 - 2009-07-13 21:34 - 00000438 _____ () C:\Windows\win.ini
2014-10-04 18:42 - 2013-12-02 20:27 - 00003186 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForNancy
2014-10-04 18:42 - 2013-12-02 20:27 - 00000332 _____ () C:\Windows\Tasks\HPCeeScheduleForNancy.job
2014-10-04 18:17 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
2014-10-04 17:21 - 2010-07-16 22:06 - 00000000 ____D () C:\Users\Nancy\Documents\26
2014-10-04 16:41 - 2009-08-31 13:44 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Help & Tools
2014-10-04 15:57 - 2013-02-24 18:04 - 00000000 ____D () C:\Firefox
2014-10-04 15:48 - 2013-01-07 19:17 - 00061424 _____ () C:\Windows\SysWOW64\Drivers\kgpcpy.cfg
2014-10-04 14:10 - 2010-03-01 18:52 - 00000000 ____D () C:\Users\Nancy\AppData\Local\Google
2014-10-04 14:06 - 2011-01-18 15:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-04 13:59 - 2009-12-19 22:20 - 00000000 ____D () C:\Users\Nancy\AppData\Roaming\HP Support Assistant
2014-10-04 13:59 - 2009-12-19 22:05 - 00000000 ____D () C:\Users\Nancy\AppData\Roaming\HpUpdate
2014-10-04 13:27 - 2013-01-04 15:16 - 00000000 ____D () C:\Program Files (x86)\STOPzilla!
2014-09-26 08:24 - 2011-01-14 09:21 - 00000016 _____ () C:\Windows\system32\config\software.szfi
2014-09-25 08:03 - 2012-06-04 10:47 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-25 08:03 - 2012-06-04 10:47 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-25 08:03 - 2011-06-03 08:15 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-23 12:59 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-19 18:14 - 2012-11-01 16:18 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-15 09:06 - 2010-02-17 22:11 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-14 15:26 - 2010-01-02 18:55 - 00000000 ____D () C:\Program Files (x86)\Java
2014-09-12 13:44 - 2009-12-18 22:13 - 00005678 _____ () C:\Users\Nancy\AppData\Roaming\wklnhst.dat
2014-09-12 13:44 - 2009-07-14 00:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-09-11 03:07 - 2010-12-06 00:36 - 00787980 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-11 03:07 - 2009-07-14 00:13 - 00787980 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-11 03:06 - 2013-08-07 03:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 03:02 - 2010-01-14 15:53 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-11 03:00 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel

Some content of TEMP:
====================
C:\Users\Nancy\AppData\Local\Temp\AcsInstall.dll
C:\Users\Nancy\AppData\Local\Temp\SHFOLDER.DLL
C:\Users\Nancy\AppData\Local\Temp\SHSetup.exe
C:\Users\Nancy\AppData\Local\Temp\uninst.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-26 00:37

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-10-2014
Ran by Nancy at 2014-10-05 14:39:49
Running from C:\Users\Nancy\Downloads\Repair_forum
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: STOPzilla (Disabled - Up to date) {17032AB1-6644-0721-EEB5-A39B8B646009}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: STOPzilla (Enabled - Up to date) {AC62CB55-407E-08AF-D405-98E9F0E32AB4}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3D Merry Christmas Screensaver 1.0 (HKLM-x32\...\3D Merry Christmas Screensaver_is1) (Version: - )
64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
Abrosoft FantaMorph 4.0 (HKLM-x32\...\Abrosoft FantaMorph 4_is1) (Version: 4.0 - Abrosoft)
Acrobat.com (HKLM-x32\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden
ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.3 - Hewlett-Packard) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.5.1.17730 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 2.5.1.17730 - Adobe Systems Inc.) Hidden
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
AIM for Windows (HKCU\...\AIM) (Version: - AOL Inc.)
Aimersoft DRM Media Converter(Build 1.5.3.0) (HKLM-x32\...\Aimersoft DRM Media Converter_is1) (Version: - Aimersoft Software)
Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.2.0.399 - Amazon Services LLC)
Amazon MP3 Downloader 1.0.15 (HKLM-x32\...\Amazon MP3 Downloader) (Version: 1.0.15 - Amazon Services LLC)
American Pickers (HKCU\...\American Pickers) (Version: - )
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
AOL Messaging Toolbar (HKLM-x32\...\AIM Toolbar) (Version: - AOL Inc.)
AOL Toolbar (HKLM-x32\...\AOL Toolbar) (Version: - AOL Inc.)
AOL Uninstaller (Choose which Products to Remove) (HKLM-x32\...\AOL Uninstaller) (Version: - AOL Inc.)
Apple Application Support (HKLM-x32\...\{853A4763-6643-4604-8D64-28BDD8925F4C}) (Version: 1.5.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{8F473675-D702-45F9-8EBC-342B40C17BF5}) (Version: 3.4.0.25 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}) (Version: 2.1.1.116 - Apple Inc.)
ArcSoft MediaImpression 2 (HKLM-x32\...\{210E8562-74DA-4D97-945B-88B2ED9C8028}) (Version: 2.0.15.1073 - ArcSoft)
ArcSoft Panorama Maker 4 (HKLM-x32\...\{37530151-56A6-4CE4-9F9F-CE1F5A1356C6}) (Version: 4.5.0.112 - ArcSoft)
ArcSoft Photo Book Screen Saver (HKLM-x32\...\{E2EE273D-E111-4FFD-ACD4-78E1D35E01D2}) (Version: 2.0.0.13 - ArcSoft)
ArcSoft PhotoStudio Darkroom 2 (HKLM-x32\...\{40DA94AF-34B7-4BA7-A37F-26F899C031FF}) (Version: 2.0.0.174 - ArcSoft)
ArcSoft Print Creations - Album Page (HKLM-x32\...\{E6B4117F-AC59-4B13-9274-EB136E8897EE}) (Version: - ArcSoft)
ArcSoft Print Creations - Brochures & Flyers (HKLM-x32\...\{01A1A019-E1D8-482A-BE17-5E118D17C0A0}) (Version: - ArcSoft)
ArcSoft Print Creations - Funhouse (HKLM-x32\...\{9591C049-5CAE-4E89-A8D9-191F1899628B}) (Version: - ArcSoft)
ArcSoft Print Creations - Funhouse II (HKLM-x32\...\{3CE47E6B-AE27-4E40-AC54-329EED96B933}) (Version: - ArcSoft)
ArcSoft Print Creations - Greeting Card (HKLM-x32\...\{F04F9557-81A9-4293-BC49-2C216FA325A7}) (Version: - ArcSoft)
ArcSoft Print Creations - Order Calendar (HKLM-x32\...\{BB3E6B07-2351-4424-B563-29D587C39956}) (Version: - ArcSoft)
ArcSoft Print Creations - Photo Book (HKLM-x32\...\{56589DFE-0C29-4DFE-8E42-887B771ECD23}) (Version: - ArcSoft)
ArcSoft Print Creations - Photo Calendar (HKLM-x32\...\{CA9ED5E4-1548-485B-A293-417840060158}) (Version: - ArcSoft)
ArcSoft Print Creations - Photo Prints (HKLM-x32\...\{95F875CC-1B85-43E6-B3E0-13EA04F3D995}) (Version: - ArcSoft)
ArcSoft Print Creations - Poster Creator (HKLM-x32\...\{5D1C82E7-7EC0-4404-A8AD-36C3B444BC34}) (Version: - ArcSoft)
ArcSoft Print Creations - Quick Photo Book (HKLM-x32\...\{5023B3E9-6B73-471E-8BD9-DA4442AE357C}) (Version: - ArcSoft)
ArcSoft Print Creations - Scrapbook (HKLM-x32\...\{B0D83FCD-9D42-43ED-8315-250326AADA02}) (Version: - ArcSoft)
ArcSoft Print Creations - Slimline Card (HKLM-x32\...\{007B37D9-0C45-4202-834B-DD5FAAE99D63}) (Version: - ArcSoft)
ArcSoft Print Creations (HKLM-x32\...\{9925A219-5F08-4C8C-809D-2599FEEF80A6}) (Version: 2.8.255.417 - ArcSoft)
ArcSoft RAW Thumbnail Viewer (HKLM-x32\...\{82FAC25D-D0E1-4D60-9268-F3DD958BF052}) (Version: 2.0.0.11 - ArcSoft)
ArcSoft Scan-n-Stitch Deluxe (HKLM-x32\...\{363188E4-1A27-4DE6-BA48-823D2E205385}) (Version: 1.1.0.17 - ArcSoft)
ArcSoft Video Downloader (HKLM-x32\...\{C8B44566-839A-459C-A73D-49764CE216CC}) (Version: 2.0.0.39 - ArcSoft)
Astro Gemini Screensaver Manager 2.0 (HKLM-x32\...\Astro Gemini Screensaver Manager_is1) (Version: - )
ATI Catalyst Install Manager (HKLM\...\{F4934901-B3C8-9918-F018-2D68F94B380E}) (Version: 3.0.728.0 - ATI Technologies, Inc.)
Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version: - )
Batch Update (x32 Version: 2.1 - Libronix Corporation) Hidden
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 1.140.0 - EA Digital Illusions CE AB)
Belkin Setup and Router Monitor (HKLM-x32\...\Belkin Setup and Router Monitor_is1) (Version: - )
Belkin USB Print and Storage Center (HKLM\...\Belkin USB Print and Storage Center) (Version: 1.0.0 - Belkin International, Inc.)
Bible Data Type System Files (x32 Version: 2.1 - Libronix Corporation) Hidden
Bonjour (HKLM\...\{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}) (Version: 2.0.4.0 - Apple Inc.)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
C309g-m (x32 Version: 130.0.396.000 - Hewlett-Packard) Hidden
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
Catalyst Control Center HydraVision Full (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2009.0520.1631.27815 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Czech (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Danish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Dutch (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help English (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Finnish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help French (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help German (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Greek (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Italian (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Japanese (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Korean (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Polish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Russian (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Spanish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Swedish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Thai (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Turkish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
ccc-core-static (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
ccc-utility64 (Version: 2009.0520.1631.27815 - ATI) Hidden
CCScore (x32 Version: 7.00.0000.0001 - EASTMAN KODAK Company) Hidden
Common System Files (x32 Version: 2.1 - Libronix Corporation) Hidden
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Coupon Printer for Windows (HKLM-x32\...\Coupon Printer for Windows5.0.0.0) (Version: 5.0.0.0 - Coupons.com Incorporated)
CyberLink DVD Suite Deluxe (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.3101 - CyberLink Corp.)
CyberLink DVD Suite Deluxe (x32 Version: 6.0.3101 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden
Digital Wireless Camera (HKLM-x32\...\{8EE8D436-CF54-4713-ABA1-B885FAB43D33}) (Version: 1.00.0000 - Digital Wireless Camera)
DIRECTV Player (HKLM-x32\...\{5F3783B7-F809-45A7-8A92-A44B441FDA7C}) (Version: 4.00 - DIRECTV)
DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
Document Express DjVu Plug-in (HKLM-x32\...\{65D29933-D1E5-4BDF-ACB1-DC41581EF342}) (Version: 6.1.31219 - Caminova, Inc.)
Download Updater (AOL Inc.) (HKLM-x32\...\SoftwareUpdUtility) (Version: - AOL Inc.) <==== ATTENTION
Elevated Installer (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
EpicPlay (HKLM-x32\...\EpicPlay) (Version: - EpicPlay LLC)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
ESSBrwr (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESSCDBK (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESScore (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESSgui (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESSini (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESSPCD (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
ESSPDock (x32 Version: 6.03.0001.0004 - EASTMAN KODAK Company) Hidden
ESSTOOLS (x32 Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
essvatgt (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
EuroTalk Talk Now! (HKLM-x32\...\{F26615EF-AF0A-486C-99C9-B65C8C401EBC}) (Version: 2.2.5.1 - EuroTalk Interactive)
fflink (x32 Version: 6.02.1001.0001 - EASTMAN KODAK Company) Hidden
Fitbit Connect (HKLM-x32\...\{D3CD091B-296B-48E9-9F0F-E9FE53E02E41}) (Version: 1.0.3.5511 - Fitbit Inc.)
Food Network Recipe Manager (HKLM-x32\...\{E321D364-2EA9-4906-BBAC-AD0246F9D3E7}) (Version: 1.0.4.0 - Nova Development)
GameSpy Arcade (HKLM-x32\...\GameSpy Arcade) (Version: - )
Garmin Express (HKLM-x32\...\{b43ffffb-1adc-4bcb-b277-7844ebff94da}) (Version: 3.2.17.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.124 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Graphical Query Editor (x32 Version: 2.1 - Libronix Corporation) Hidden
Hotel Giant 2 (HKLM-x32\...\{6E293CEF-E7D1-4397-A971-DE9C6AC2939E}) (Version: 110 - Nobilis)
HP Advisor (HKLM-x32\...\{B53E61D7-7C80-40DF-82D2-CF5390D6D20A}) (Version: 3.2.8946.3086 - Hewlett-Packard)
HP Customer Experience Enhancements (x32 Version: 6.0.1.3 - Hewlett-Packard) Hidden
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Easy Backup (HKLM-x32\...\{67431FA8-4B89-42DD-A68E-30D77F6C8D99}_is1) (Version: 1.0.8.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.0.71 - WildTangent)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP MAINSTREAM KEYBOARD (HKLM-x32\...\{B40D7926-AE5F-41EA-8AC6-56C0E2F00E9D}) (Version: 1.4.3.0 - Hewlett-Packard)
HP MediaSmart Demo (HKLM-x32\...\{9DEF9686-CCB2-47B7-BF83-B49EA21FA016}) (Version: 1.00.0000 - Hewlett-Packard)
HP MediaSmart DVD (HKLM-x32\...\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 3.0.3123 - Hewlett-Packard)
HP MediaSmart DVD (x32 Version: 3.0.3123 - Hewlett-Packard) Hidden
HP MediaSmart Movie Themes (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 3.0.3102 - Hewlett-Packard)
HP MediaSmart Movie Themes (x32 Version: 3.0.3102 - Hewlett-Packard) Hidden
HP MediaSmart Music/Photo/Video (HKLM-x32\...\InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}) (Version: 3.0.3205 - Hewlett-Packard)
HP MediaSmart Music/Photo/Video (x32 Version: 3.0.3205 - Hewlett-Packard) Hidden
HP MediaSmart SmartMenu (HKLM\...\{26280024-DFB7-4967-90DB-7F9C6660D01E}) (Version: 3.0.28.2 - Hewlett-Packard)
HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Photosmart Premium C309g-m All-In-One Driver Software 13.0 Rel .6 (HKLM\...\{181AC4C7-B83C-4B5F-B566-E19BF2472429}) (Version: 13.0 - HP)
HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP)
HP Remote Solution (HKLM-x32\...\HP Remote Solution) (Version: 1.1.9.0 - TopSeed)
HP Remote Solution (x32 Version: 1.1.9.0 - TopSeed) Hidden
HP Setup (HKLM-x32\...\{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}) (Version: 1.2.3220.3079 - Hewlett-Packard)
HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Support Assistant (HKLM-x32\...\{08DB3902-2CE0-474D-BCE3-0177766CE9F1}) (Version: 5.1.10.7 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}) (Version: 10.1.0002 - Hewlett-Packard)
HP Update (HKLM-x32\...\{D46D081B-F60E-467E-A7C4-117B70D76731}) (Version: 5.001.000.014 - Hewlett-Packard)
HPAsset component for HP Active Support Library (x32 Version: 3.0.0.3 - Hewlett-Packard) Hidden
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
hpPrintProjects (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
hpWLPGInstaller (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
Humana GearSync 1.5.117 (HKLM-x32\...\{4ADA60D4-895E-4B03-86BF-39582AD5E95C}_is1) (Version: 1.5.117 - Humana)
HydraVision (x32 Version: 4.2.98.0 - ATI Technologies Inc.) Hidden
Internet TV for Windows Media Center (HKLM-x32\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 3.2.1.0 - Microsoft Corporation)
iTunes (HKLM\...\{9545E9DB-6F4C-4404-BF25-E221BE8B44C5}) (Version: 10.2.1.1 - Apple Inc.)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217017FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden
Java(TM) 6 Update 30 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216027FF}) (Version: 6.0.300 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kodak EasyShare software (HKLM-x32\...\{D32470A1-B10C-4059-BA53-CF0486F68EBC}) (Version: - Eastman Kodak Company)
LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1901 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.1901 - CyberLink Corp.) Hidden
Libronix Digital Library System (HKLM-x32\...\Libronix DLS) (Version: - Libronix Corporation)
Libronix Digital Library System (x32 Version: 2.1 - Libronix Corporation) Hidden
Libronix DLS Application (x32 Version: 2.1 - Libronix Corporation) Hidden
Libronix DLS Shortcuts (x32 Version: 2.1 - Libronix Corporation) Hidden
LibronixUpdate (x32 Version: 2.1 - Libronix Corporation) Hidden
LightScribe System Software (HKLM-x32\...\{DD6C316A-FE75-4FBB-9D22-4C1920232B72}) (Version: 1.18.5.1 - LightScribe)
LLS Resource Driver (x32 Version: 2.1 - Libronix Corporation) Hidden
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
MemoriesOnTV (HKLM-x32\...\{982755B5-03A1-40B7-8F4A-13C17238D688}) (Version: 4.0.4 - Nova Development)
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Live Search Toolbar (HKLM-x32\...\{DF802C05-4660-418c-970C-B988ADB1D316}) (Version: 3.0.560.0 - Microsoft Live Search Toolbar)
Microsoft Live Search Toolbar (x32 Version: 3.0.560.0 - Microsoft Corporation) Hidden
Microsoft Rise Of Nations (HKLM-x32\...\RiseOfNations 1.0) (Version: - Microsoft)
Microsoft Search Enhancement Pack (x32 Version: 1.2.123.0 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft VC9 runtime libraries (x32 Version: 1.0.0 - AOL Inc.) Hidden
Microsoft VC9 runtime libraries (x32 Version: 1.0.0 - AOL LLC) Hidden
Microsoft VC9 runtime libraries (x32 Version: 2.0.0 - AOL Inc.) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Works (HKLM-x32\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
MobileMe Control Panel (HKLM\...\{56F26668-13DA-497A-883F-61434A10CBAB}) (Version: 3.1.5.0 - Apple Inc.)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML4 Parser (HKLM-x32\...\{01501EBA-EC35-4F9F-8889-3BE346E5DA13}) (Version: 1.0.0 - Microsoft Game Studios)
netbrdg (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
Netflix in Windows Media Center (HKLM-x32\...\{0CA72D12-F6C6-4D43-A2A0-41F5AA17E2B6}) (Version: 3.3.101.0 - Microsoft Corporation)
Network64 (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden
OEB Resource Driver (x32 Version: 2.1 - Libronix Corporation) Hidden
OfotoXMI (x32 Version: 7.02.0000.0001 - EASTMAN KODAK Company) Hidden
PDF Resource Driver (x32 Version: 2.1 - Libronix Corporation) Hidden
Photo Explosion (HKLM-x32\...\{822944D4-BC5D-44AE-9315-16C174D318B0}) (Version: 4.0.0.12 - Nova Development)
Picaboo X (HKLM-x32\...\com.picaboo.Picaboo.A382D4714709B456C4E0088DFC1F7243AF9EBF75.1) (Version: 10.136P - Picaboo Corporation)
Picaboo X (x32 Version: 10.136 - Picaboo Corporation) Hidden
PictureMover (HKLM-x32\...\{1896E712-2B3D-45eb-BCE9-542742A51032}) (Version: 3.3.1.19 - Hewlett-Packard Company)
Podmaxx (HKLM-x32\...\{E0DEA5B0-DF24-4CA2-B725-98C04FCB5DAF}) (Version: 3.00.82 - Bluecase Software)
Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.3101 - CyberLink Corp.)
Power2Go (x32 Version: 6.0.3101 - CyberLink Corp.) Hidden
PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.3101 - CyberLink Corp.)
PowerDirector (x32 Version: 7.0.3101 - CyberLink Corp.) Hidden
PowerRecover (x32 Version: 5.5.1923 - CyberLink Corp.) Hidden
PS_AIO_06_C309g-m_SW_Min (x32 Version: 130.0.396.000 - Hewlett-Packard) Hidden
QuickTime (HKLM-x32\...\{57752979-A1C9-4C02-856B-FBB27AC4E02C}) (Version: 7.69.80.9 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6196 - Realtek Semiconductor Corp.)
Rise of Nations Thrones and Patriots (HKLM-x32\...\RiseofNationsExpansion 1.0) (Version: - )
RivalGaming (HKLM-x32\...\RivalGaming) (Version: - RivalGaming)
Safari (HKLM-x32\...\{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}) (Version: 5.33.21.1 - Apple Inc.)
Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden
Screensavers.com Content (HKLM-x32\...\www_screensavers_com) (Version: - Screensavers.com)
Sentence Diagramming (x32 Version: 2.1 - Libronix Corporation) Hidden
Serif MontagePlus 1.0 (HKLM-x32\...\{A8A42A57-2320-464B-9F5D-3F85089C4714}) (Version: 1.0 - )
Serif PanoramaPlus 3 (HKLM-x32\...\{64893BC9-D912-4A2D-A47A-E38650112781}) (Version: 3.0.1.017 - Serif (Europe) Ltd)
SFR (x32 Version: 7.01.0000.0003 - Eastman Kodak Company) Hidden
SHASTA (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP)
Sid Meier's Civilization 4 - Beyond the Sword (HKLM-x32\...\{32E4F0D2-C135-475E-A841-1D59A0D22989}) (Version: 3.00 - Firaxis Games)
Sid Meier's Civilization 4 (HKLM-x32\...\{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}) (Version: 1.74 - Firaxis Games)
Sid Meier's Civilization 4 (x32 Version: 1.09 - Firaxis Games) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.)
Sins of a Solar Empire (HKLM-x32\...\Sins of a Solar Empire) (Version: - Stardock Entertainment)
Sins of a Solar Empire (x32 Version: 1.00.00 - Stardock Entertainment, Inc.) Hidden
skin0001 (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
SKINXSDK (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Star Trek Online (HKLM-x32\...\Star Trek Online) (Version: - Cryptic Studios)
staticcr (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
STOPzilla (HKLM-x32\...\{FEC0C541-FA7C-44EC-A62A-6B75793CE968}) (Version: 6.1.90.7 - iS3 Inc.)
Super Letter Linker (HKLM-x32\...\am-superletterlinker) (Version: - )
TomTom HOME (HKLM-x32\...\{99072AB4-D795-44D5-9D65-E3C9F8322C97}) (Version: 2.9.7 - TomTom)
TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TransferMy Music 3.0 (HKLM-x32\...\TransferMy Music_is1) (Version: 3.0 - Purple Ghost Software, Inc.)
TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 1.10.0 - Tweaking.com)
Uniden Surveillance System 5.0.0.302 (HKLM-x32\...\{E9ACF7F7-DB80-49B4-A1BC-63DB90913E67}_is1) (Version: - OEM)
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Video Mover (HKLM-x32\...\Video Mover_is1) (Version: - )
Video Resource Driver (x32 Version: 2.1 - Libronix Corporation) Hidden
Viewpoint Media Player (HKLM-x32\...\ViewpointMediaPlayer) (Version: - )
VPRINTOL (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
WildTangent Games App (HP Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.31 - WildTangent)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - OEM (mr8980) Image (05/10/2010 1.0.0.0) (HKLM\...\D9DD2BFD594FBF5476D0C2CAA2322CB7A65EB7CD) (Version: 05/10/2010 1.0.0.0 - OEM)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Media Center Add-in for Flash (HKLM-x32\...\{E2D09AC2-4153-4817-AAEB-24F92A8BCE88}) (Version: 3.1.1.0 - Microsoft Corporation)
WIRELESS (x32 Version: 7.02.0000.0001 - EASTMAN KODAK Company) Hidden
Zynga Toolbar (HKLM-x32\...\Zynga Toolbar) (Version: 6.8.2.0 - Zynga)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points =========================

04-10-2014 18:22:40 STOPzilla Restore Point.
04-10-2014 18:26:18 Windows Backup
04-10-2014 18:33:14 Windows Update
04-10-2014 20:11:10 Cleaner (Spybot - Search & Destroy 2.4, administrator privileges
05-10-2014 04:25:36 Removed Activate Norton Online Backup
05-10-2014 04:34:37 Removed Microsoft Office PowerPoint Viewer 2007 (English)
05-10-2014 05:35:54 Installed SpyHunter
05-10-2014 14:27:07 Removed SpyHunter
05-10-2014 18:45:48 Windows Modules Installer

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2010-03-01 18:30 - 2011-01-14 07:30 - 00000864 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {008FE78D-81C2-4AC3-858D-8F4BC001A9DB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2010-11-15] (Hewlett-Packard Company)
Task: {2E9422C2-9D2C-4C8E-BD97-13E79F8898F2} - System32\Tasks\Arcadesafari => C:\Users\Nancy\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe
Task: {442B6B02-3201-450C-8F15-52BEE25ADA60} - System32\Tasks\CLMLSvc => c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [2009-08-05] (CyberLink)
Task: {486E6041-FBFC-4866-83E4-D29A1A1E8BBF} - System32\Tasks\DVDAgent => c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe [2009-07-23] (CyberLink Corp.)
Task: {5EA75771-8291-4EE6-ACE2-FA9381101C41} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-01] (Google Inc.)
Task: {6B71FAA3-3A9C-4220-B1AF-62F07380C7A5} - System32\Tasks\{CF53108C-8CD9-43C0-9E68-E83BA10A8BCF} => C:\Program Files (x86)\AOL Desktop 9.7h\aol.exe
Task: {6D3E6CB0-4282-432F-915F-4808272BF790} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {724BB2AC-C044-4539-91BB-0213ABA1FCD5} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {72FBF166-F579-4EBE-9E10-9771BE2B82CB} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {7BC2E6D7-4047-4195-BC34-318B52D0D43B} - System32\Tasks\{0F12769E-3D7A-4A4C-AE76-99D4A60601DA} => C:\Program Files (x86)\AOL Desktop 9.7h\aol.exe
Task: {8D1A23E3-7B8F-4E15-AA03-8F520F0282B3} - \PC Performer No Task File <==== ATTENTION
Task: {8F025311-854B-4A5C-A186-13697604040E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP SoftPaq Installer => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Tasks.exe [2010-11-15] (Hewlett-Packard Company)
Task: {9CCF77B4-F7D7-4A5A-9CC3-D8260F7FE32C} - System32\Tasks\{C4005CD9-C787-46F7-8F15-0C72A236B33F} => C:\Program Files (x86)\AOL Desktop 9.7g\aol.exe
Task: {AA2B20E5-087A-4031-8436-A8A80DB28B91} - System32\Tasks\HPOSIAPP64 => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe [2009-02-27] ()
Task: {B5B51570-BCC1-4FC1-973B-561259BE597D} - System32\Tasks\Microsoft\Windows\Media Center\Extender\Update media permissions for Mcx1-NANCY-PC => C:\Windows\ehome\McxTask.exe [2009-07-13] (Microsoft Corporation)
Task: {B8A107AB-A9FD-4D62-B8DC-07645DE37E20} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe [2014-08-07] ()
Task: {BD118D22-1A5B-46A2-9767-E40021892710} - System32\Tasks\HPCeeScheduleForNancy => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07] (Hewlett-Packard)
Task: {BD5E9554-E80B-4825-87BE-F8CACDACC5B5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2010-11-15] (Hewlett-Packard Company)
Task: {CB88F86D-EABA-4082-B10D-6A55425F4577} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe <==== ATTENTION
Task: {E27E0D0D-6D7B-481B-A64D-52500B91A503} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-25] (Adobe Systems Incorporated)
Task: {E39F5C07-BC9C-435E-B797-77FC469A3789} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {E624CA9A-EBB1-4815-9ADF-1A0FC00A151A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-01] (Google Inc.)
Task: {FE69F5A8-BAE3-4C62-B48E-877C5F7FDA4D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2008-07-30] (Apple Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Arcadesafari.job => C:\Users\Nancy\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForNancy.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Loaded Modules (whitelisted) =============

2010-12-10 22:09 - 2010-02-17 19:25 - 00181760 ____N () C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
2010-12-10 22:09 - 2010-02-09 16:55 - 00055296 ____N () C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
2009-08-31 14:01 - 2008-09-30 20:59 - 00192512 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe
2009-08-31 13:46 - 2009-02-27 21:13 - 00053248 _____ () C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe
2009-07-08 16:35 - 2009-07-08 16:35 - 00610360 _____ () C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
2012-04-02 16:49 - 2012-04-02 16:49 - 00686208 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\NDSPCShowServer.exe
2009-05-26 03:36 - 2009-05-26 03:36 - 00656896 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
2010-12-11 00:53 - 2010-02-17 19:25 - 00149504 _____ () C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkLocalBackup.dll
2012-04-17 22:24 - 2014-06-20 06:08 - 00192376 _____ () c:\ProgramData\STOPzilla!\VIPRE\libBase64.dll
2012-04-17 22:24 - 2014-06-20 06:08 - 00180088 _____ () c:\ProgramData\STOPzilla!\VIPRE\libMachoUniv.dll
2010-12-10 22:05 - 2010-07-28 18:34 - 00022424 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinServicePS.dll
2014-10-04 14:03 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-10-04 14:03 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-10-04 14:03 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2009-08-05 15:45 - 2009-08-05 15:45 - 00931112 ____N () c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 00273528 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\ndsLogStore.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 02721920 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\PCShowServerDll.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 02049152 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\XferManagerDll.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 01945704 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\TSB.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 00051864 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\boost_thread-vc90-mt-1_39.dll
2012-04-02 16:49 - 2012-04-02 16:49 - 01988216 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\DrmSingleton.dll
2012-04-02 16:49 - 2012-04-02 16:49 - 01226872 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\CatalogDll.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 06809720 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\gsttspplugin.dll
2012-04-02 16:51 - 2012-04-02 16:51 - 00688264 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\libgstreamer-0.10.dll
2012-04-02 16:51 - 2012-04-02 16:51 - 01402488 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\libxml2-2.dll
2012-04-02 16:52 - 2012-04-02 16:52 - 00091240 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\z.dll
2014-02-04 16:47 - 2014-02-04 16:47 - 23782856 _____ () C:\Users\Nancy\AppData\Local\AOL\AIM\libcef.dll
2014-02-04 14:33 - 2014-02-04 14:33 - 16233864 _____ () C:\Users\Nancy\AppData\Local\AOL\AIM\npswf32.dll
2010-12-10 22:05 - 2010-06-23 19:11 - 00325632 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtXml4.dll
2010-12-10 22:05 - 2010-06-23 19:11 - 01954304 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll
2010-12-10 22:05 - 2010-06-23 19:12 - 07187456 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtGui4.dll
2010-12-10 22:05 - 2010-06-23 19:11 - 00847360 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtNetwork4.dll
2010-12-11 01:47 - 2010-06-23 18:38 - 00119808 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll
2014-09-16 13:17 - 2014-09-16 13:17 - 00059392 _____ () c:\program files (x86)\common files\aol\1412533129\ee\services\waolTrayMenuService\ver_0_9_1\waolTrayMenuService.dll
2009-08-31 13:46 - 2009-02-19 19:22 - 00028672 _____ () C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\WMINPUT.DLL
2010-12-11 01:47 - 2010-07-28 18:02 - 00658432 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:A8ADE5D8
AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2
AlternateDataStreams: C:\Users\Nancy\Documents\Fw_BEDTIMESTORY.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

HKU\.DEFAULT\Software\Classes\.exe: exefile => <===== ATTENTION!
HKU\.DEFAULT\Software\Classes\exefile: <===== ATTENTION!
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\Software\Classes\.exe: exefile => <===== ATTENTION!
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\Software\Classes\exefile: <===== ATTENTION!

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk => C:\Windows\pss\Kodak EasyShare software.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PictureMover.lnk => C:\Windows\pss\PictureMover.lnk.CommonStartup
MSCONFIG\startupreg: AddressBookReminderApp => C:\Program Files (x86)\Nova Development\Photo Explosion\4.0\ReminderApp.exe
MSCONFIG\startupreg: Aimersoft Helper Compact.exe => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
MSCONFIG\startupreg: Amazon Cloud Player => "C:\Users\Nancy\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe"
MSCONFIG\startupreg: AppleSyncNotifier => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
MSCONFIG\startupreg: ArcSoft Connection Service => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: NortonOnlineBackupReminder => "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
MSCONFIG\startupreg: Pando Media Booster => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SBRegRebootCleaner => "c:\Program Files (x86)\Common Files\iS3\Anti-Spyware\sbrc.exe"
MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
MSCONFIG\startupreg: Spybot-S&D Cleaning => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

========================= Accounts: ==========================

Administrator (S-1-5-21-4198835622-2076300525-3891148937-500 - Administrator - Disabled)
ASPNET (S-1-5-21-4198835622-2076300525-3891148937-1004 - Limited - Enabled)
Guest (S-1-5-21-4198835622-2076300525-3891148937-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4198835622-2076300525-3891148937-1002 - Limited - Enabled)
Mcx1-NANCY-PC (S-1-5-21-4198835622-2076300525-3891148937-1005 - Limited - Enabled) => C:\Users\Mcx1-NANCY-PC
Nancy (S-1-5-21-4198835622-2076300525-3891148937-1001 - Administrator - Enabled) => C:\Users\Nancy

==================== Faulty Device Manager Devices =============

Name: SBRE
Description: SBRE
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SBRE
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/05/2014 02:10:46 PM) (Source: HP Advisor) (EventID: 400) (User: )
Description: Timestamp: 10/05/2014 14:10:45.943;
Category: FATAL;
Priority:(4);
Win32 Thread Id: [3108];
Message: Application::OnStartService() failed!, shutdown application... ;
EventId: 400;
Severity: Critical;
Machine: NANCY-PC;
Application Domain: HPAdvisor.exe;
Process Id: 3104;
Process Name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe;
Extended Properties:

Error: (10/05/2014 02:03:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: waol.exe, version: 9.7.3.1, time stamp: 0x54187b7f
Faulting module name: acfBase.DLL, version: 1.0.0.1, time stamp: 0x541879f5
Exception code: 0xc0000005
Fault offset: 0x00006a65
Faulting process id: 0xb60
Faulting application start time: 0xwaol.exe0
Faulting application path: waol.exe1
Faulting module path: waol.exe2
Report Id: waol.exe3

Error: (10/05/2014 02:02:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: waol.exe, version: 9.7.3.1, time stamp: 0x54187b7f
Faulting module name: acfBase.DLL, version: 1.0.0.1, time stamp: 0x541879f5
Exception code: 0xc0000005
Fault offset: 0x00006a65
Faulting process id: 0x1030
Faulting application start time: 0xwaol.exe0
Faulting application path: waol.exe1
Faulting module path: waol.exe2
Report Id: waol.exe3

Error: (10/05/2014 01:57:47 PM) (Source: HP Advisor) (EventID: 400) (User: )
Description: Timestamp: 10/05/2014 13:57:47.146;
Category: FATAL;
Priority:(4);
Win32 Thread Id: [2360];
Message: Application::OnStartService() failed!, shutdown application... ;
EventId: 400;
Severity: Critical;
Machine: NANCY-PC;
Application Domain: HPAdvisor.exe;
Process Id: 2356;
Process Name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe;
Extended Properties:

Error: (10/05/2014 01:28:31 PM) (Source: HP Advisor) (EventID: 400) (User: )
Description: Timestamp: 10/05/2014 13:28:31.603;
Category: FATAL;
Priority:(4);
Win32 Thread Id: [2472];
Message: Application::OnStartService() failed!, shutdown application... ;
EventId: 400;
Severity: Critical;
Machine: NANCY-PC;
Application Domain: HPAdvisor.exe;
Process Id: 2468;
Process Name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe;
Extended Properties:

Error: (10/05/2014 01:19:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: dnupdatersetup.exe, version: 1.2.26.1, time stamp: 0x4b1ae3c1
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7
Exception code: 0xc0000005
Fault offset: 0x00037225
Faulting process id: 0xd08
Faulting application start time: 0xdnupdatersetup.exe0
Faulting application path: dnupdatersetup.exe1
Faulting module path: dnupdatersetup.exe2
Report Id: dnupdatersetup.exe3

Error: (10/05/2014 01:14:03 PM) (Source: HP Advisor) (EventID: 400) (User: )
Description: Timestamp: 10/05/2014 13:14:03.296;
Category: FATAL;
Priority:(4);
Win32 Thread Id: [3828];
Message: Application::OnStartService() failed!, shutdown application... ;
EventId: 400;
Severity: Critical;
Machine: NANCY-PC;
Application Domain: HPAdvisor.exe;
Process Id: 3824;
Process Name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe;
Extended Properties:

Error: (10/05/2014 09:39:10 AM) (Source: HP Advisor) (EventID: 400) (User: )
Description: Timestamp: 10/05/2014 09:39:10.119;
Category: FATAL;
Priority:(4);
Win32 Thread Id: [2344];
Message: Application::OnStartService() failed!, shutdown application... ;
EventId: 400;
Severity: Critical;
Machine: NANCY-PC;
Application Domain: HPAdvisor.exe;
Process Id: 2284;
Process Name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe;
Extended Properties:

Error: (10/05/2014 09:27:14 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.


Details:
AddLegacyDriverFiles: Unable to back up image of binary 1864718drv.

System Error:
The system cannot find the file specified.
.

Error: (10/05/2014 02:52:44 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005


System errors:
=============
Error: (10/05/2014 02:07:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error:
%%1053

Error: (10/05/2014 02:07:22 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Scanner Service service to connect.

Error: (10/05/2014 02:06:52 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
is3srv
SBRE

Error: (10/05/2014 02:06:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error:
%%1053

Error: (10/05/2014 02:06:33 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Scanner Service service to connect.

Error: (10/05/2014 02:05:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Garmin Core Update Service service failed to start due to the following error:
%%1053

Error: (10/05/2014 02:05:59 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Garmin Core Update Service service to connect.

Error: (10/05/2014 02:04:38 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (10/05/2014 02:04:38 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (10/05/2014 01:55:25 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error:
%%1053


Microsoft Office Sessions:
=========================
Error: (10/05/2014 02:10:46 PM) (Source: HP Advisor) (EventID: 400) (User: )
Description: Timestamp: 10/05/2014 14:10:45.943;
Category: FATAL;
Priority:(4);
Win32 Thread Id: [3108];
Message: Application::OnStartService() failed!, shutdown application... ;
EventId: 400;
Severity: Critical;
Machine: NANCY-PC;
Application Domain: HPAdvisor.exe;
Process Id: 3104;
Process Name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe;
Extended Properties:

Error: (10/05/2014 02:03:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: waol.exe9.7.3.154187b7facfBase.DLL1.0.0.1541879f5c000000500006a65b6001cfe0cf0de5e378C:\Program Files (x86)\AOL Desktop 9.7\waol.exeC:\Program Files (x86)\AOL Desktop 9.7\acfBase.DLL4ba0b699-4cc2-11e4-8977-00038a000015

Error: (10/05/2014 02:02:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: waol.exe9.7.3.154187b7facfBase.DLL1.0.0.1541879f5c000000500006a65103001cfe0ceda4148c6C:\Program Files (x86)\AOL Desktop 9.7\waol.exeC:\Program Files (x86)\AOL Desktop 9.7\acfBase.DLL1ab7f078-4cc2-11e4-8977-00038a000015

Error: (10/05/2014 01:57:47 PM) (Source: HP Advisor) (EventID: 400) (User: )
Description: Timestamp: 10/05/2014 13:57:47.146;
Category: FATAL;
Priority:(4);
Win32 Thread Id: [2360];
Message: Application::OnStartService() failed!, shutdown application... ;
EventId: 400;
Severity: Critical;
Machine: NANCY-PC;
Application Domain: HPAdvisor.exe;
Process Id: 2356;
Process Name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe;
Extended Properties:

Error: (10/05/2014 01:28:31 PM) (Source: HP Advisor) (EventID: 400) (User: )
Description: Timestamp: 10/05/2014 13:28:31.603;
Category: FATAL;
Priority:(4);
Win32 Thread Id: [2472];
Message: Application::OnStartService() failed!, shutdown application... ;
EventId: 400;
Severity: Critical;
Machine: NANCY-PC;
Application Domain: HPAdvisor.exe;
Process Id: 2468;
Process Name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe;
Extended Properties:

Error: (10/05/2014 01:19:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: dnupdatersetup.exe1.2.26.14b1ae3c1ntdll.dll6.1.7601.18247521ea8e7c000000500037225d0801cfe0c8eab086c8C:\Users\Nancy\AppData\Local\Temp\nsj5E36.tmp\dnupdatersetup.exeC:\Windows\SysWOW64\ntdll.dll29d2c9b4-4cbc-11e4-8519-90e6ba588c56

Error: (10/05/2014 01:14:03 PM) (Source: HP Advisor) (EventID: 400) (User: )
Description: Timestamp: 10/05/2014 13:14:03.296;
Category: FATAL;
Priority:(4);
Win32 Thread Id: [3828];
Message: Application::OnStartService() failed!, shutdown application... ;
EventId: 400;
Severity: Critical;
Machine: NANCY-PC;
Application Domain: HPAdvisor.exe;
Process Id: 3824;
Process Name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe;
Extended Properties:

Error: (10/05/2014 09:39:10 AM) (Source: HP Advisor) (EventID: 400) (User: )
Description: Timestamp: 10/05/2014 09:39:10.119;
Category: FATAL;
Priority:(4);
Win32 Thread Id: [2344];
Message: Application::OnStartService() failed!, shutdown application... ;
EventId: 400;
Severity: Critical;
Machine: NANCY-PC;
Application Domain: HPAdvisor.exe;
Process Id: 2284;
Process Name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe;
Extended Properties:

Error: (10/05/2014 09:27:14 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary 1864718drv.

System Error:
The system cannot find the file specified.

Error: (10/05/2014 02:52:44 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005


CodeIntegrity Errors:
===================================
Date: 2010-03-01 23:31:27.298
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 23:22:11.389
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 22:46:48.026
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 22:34:28.641
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 21:56:02.679
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 21:44:06.527
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 21:09:47.319
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 20:41:05.685
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 20:16:34.870
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 19:43:31.152
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Quad CPU Q9300 @ 2.50GHz
Percentage of memory in use: 42%
Total physical RAM: 8191.18 MB
Available physical RAM: 4731.15 MB
Total Pagefile: 16380.54 MB
Available Pagefile: 12614.33 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: (HP) (Fixed) (Total:919.33 GB) (Free:778.99 GB) NTFS
Drive d: (FACTORY_IMAGE) (Fixed) (Total:12.08 GB) (Free:2.21 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=919.3 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=12.1 GB) - (Type=07 NTFS)

==================== End Of Log ============================

aswMBR version 1.0.1.2041 Copyright(c) 2014 AVAST Software
Run date: 2014-10-05 14:42:34
-----------------------------
14:42:34.144 OS Version: Windows x64 6.1.7601 Service Pack 1
14:42:34.144 Number of processors: 4 586 0x1707
14:42:34.145 ComputerName: NANCY-PC UserName: Nancy
14:42:36.761 Initialize success
14:42:36.785 VM: initialized successfully
14:42:36.805 VM: Intel CPU BiosDisabled
14:42:43.651 VM: supported disk I/O ataport.SYS
14:46:24.411 AVAST engine defs: 14100500
14:47:13.118 The log file has been saved successfully to "C:\Users\Nancy\Downloads\Repair_forum\aswMBR.txt"

ken545
2014-10-06, 01:00
:welcome:

I am wondering why in this day and age anyone would want any AOL software on there system, when you did the install it looks like it came bundled with other software that is adware . A few years back PCWorld Magazine did an article on the 10 Best and 10 Worst software packages and AOL came in 1st place for the worst.

You can go to Programs and Features in the Control Panel and use there uninstaller to remove the components you don't use or want, personally I would get rid of it all
AOL Uninstaller (Choose which Products to Remove) (HKLM-x32\...\AOL Uninstaller) (Version: - AOL Inc.)

You have a bunch of bogus toolbars and such and also an infected backup copy of your hosts file, lets do this

Run these in order please and also download and run these tools from your desktop, not your downloads folder

-AdwCleaner-by Xplode

Click on this link to download : ADWCleaner (http://www.bleepingcomputer.com/download/adwcleaner/)
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.

Do not click on any links in the top Advertisment.


Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Scan.
After the scan is complete click on "Clean"
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next reply.
You can find the logfile at C:\AdwCleaner[S1].txt as well.



===============================================================================


http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.




===============================================================================

Download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam-download.php) to your desktop.


Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"


http://i1269.photobucket.com/albums/jj590/OCD-WTT/MBAMDashboard_zpsddef9b5f.gif (http://s1269.photobucket.com/user/OCD-WTT/media/MBAMDashboard_zpsddef9b5f.gif.html)


On the Dashboard click on Update Now
Go to the Setting Tab
Under Setting go to Detection and Protection
Under PUP and PUM make sure both are set to show Treat Detections as Malware
Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
Then on the Dashboard click on Scan
Make sure to select THREAT SCAN
Then click on Scan
When the scan is finished and the log pops up...select Copy to Clipboard
Please paste the log back into this thread for review
Exit Malwarebytes

geraldgrogan
2014-10-06, 01:09
I totally agreed with your assessment, and sentiments. This PC is from a family members which insists that they still need AOL based software. I will follow you steps now and repost when done. Thanks for picking up this issue and for your assistance.

geraldgrogan
2014-10-06, 02:28
# AdwCleaner v3.311 - Report created 05/10/2014 at 18:18:11
# Updated 30/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Nancy - NANCY-PC
# Running from : C:\Users\Nancy\Downloads\Repair_forum\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Activeris
Folder Deleted : C:\ProgramData\AOL Toolbar
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\ProgramData\Viewpoint
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activeris AntiMalware
Folder Deleted : C:\Program Files (x86)\Activeris AntiMalware
Folder Deleted : C:\Program Files (x86)\AOL Toolbar
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\HiDefMedia
Folder Deleted : C:\Program Files (x86)\SearchProtect
Folder Deleted : C:\Program Files (x86)\Viewpoint
Folder Deleted : C:\Program Files (x86)\Zynga
Folder Deleted : C:\Program Files (x86)\Common Files\Software Update Utility
Folder Deleted : C:\Program Files\AOL Toolbar
Folder Deleted : C:\Users\Nancy\AppData\Local\AOL Toolbar
Folder Deleted : C:\Users\Nancy\AppData\Local\NativeMessaging
Folder Deleted : C:\Users\Nancy\AppData\Local\Temp\AirInstaller
Folder Deleted : C:\Users\Nancy\AppData\Local\Temp\NativeMessaging
Folder Deleted : C:\Users\Nancy\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Nancy\AppData\LocalLow\HPAppData
Folder Deleted : C:\Users\Nancy\AppData\LocalLow\Toolbar4
Folder Deleted : C:\Users\Nancy\AppData\LocalLow\Zynga
Folder Deleted : C:\Users\Nancy\AppData\Roaming\PerformerSoft
Folder Deleted : C:\Users\Nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dogpile Bundle Toolbar
Folder Deleted : C:\Users\Nancy\Documents\PC Health Kit
File Deleted : C:\Users\Public\Desktop\Activeris AntiMalware.lnk
File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
File Deleted : C:\Windows\Downloaded Program Files\popcaploader.inf
File Deleted : C:\Windows\System32\acrisnative64.exe

***** [ Scheduled Tasks ] *****

Task Deleted : LaunchApp
Task Deleted : PC Performer

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\Software\Classes\popcaploader.popcaploaderctrl2
Key Deleted : HKLM\Software\Classes\popcaploader.popcaploaderctrl2.1
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
Key Deleted : HKLM\SOFTWARE\Classes\TBSB07987.IEToolbar
Key Deleted : HKLM\SOFTWARE\Classes\TBSB07987.IEToolbar.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2438727
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3298580
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B13EC3E-999A-4B70-B9CB-2617B8323822}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{636E19A4-E9F1-4F72-8D81-85E5A2D3DB18}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E4E3E0F8-CD30-4380-8CE9-B96904BDEFCA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE8A736F-4124-4D9C-B4B1-3B12381EFABE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C9C5DEAF-0A1F-4660-8279-9EDFAD6FEFE1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7B13EC3E-999A-4B70-B9CB-2617B8323822}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B13EC3E-999A-4B70-B9CB-2617B8323822}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7B13EC3E-999A-4B70-B9CB-2617B8323822}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{636E19A4-E9F1-4F72-8D81-85E5A2D3DB18}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03E57067-7751-4D1B-852E-9ADB1CF7C8FD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5AFBA99-C418-475C-A380-EF506B921AE6}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4B5C-9287-DA72D38F4FE6}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{71588120-FC17-4463-B07D-2C71FE6E057B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4B5C-9287-DA72D38F4FE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{7B13EC3E-999A-4B70-B9CB-2617B8323822}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7B13EC3E-999A-4B70-B9CB-2617B8323822}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{7B13EC3E-999A-4B70-B9CB-2617B8323822}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E4E3E0F8-CD30-4380-8CE9-B96904BDEFCA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FE8A736F-4124-4D9C-B4B1-3B12381EFABE}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{71588120-FC17-4463-B07D-2C71FE6E057B}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DefaultTab
Key Deleted : HKCU\Software\performersoft llc
Key Deleted : HKCU\Software\PerformerSoft
Key Deleted : HKCU\Software\usyndication.com
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Zynga
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DefaultTab
Key Deleted : HKLM\SOFTWARE\firstsearch
Key Deleted : HKLM\SOFTWARE\MetaStream
Key Deleted : HKLM\SOFTWARE\PerformerSoft
Key Deleted : HKLM\SOFTWARE\PIP
Key Deleted : HKLM\SOFTWARE\Trymedia Systems
Key Deleted : HKLM\SOFTWARE\Viewpoint
Key Deleted : HKLM\SOFTWARE\Zynga
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Printer for Windows5.0.0.0
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280


-\\ Google Chrome v37.0.2062.124

[ File : C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2438727
Deleted [Search Provider] : hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=843&query={SearchTerms}&invocationType=tb50TB50CL-chromesbox-en-us
Deleted [Search Provider] : hxxp://ws.infospace.com/playsushi_tbar/ws/redir?_iceUrl=true& user_id=%userid&tool_id=60231&qkw={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
Deleted [Search Provider] : hxxp://go.findrsearch.com/search/web?q={searchTerms}
Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?ctid=CT3300019&SearchSource=45&UM=2&q={searchTerms}
Deleted [Extension] : kdidombaedgpfiiedeimiebkmbilgmlc

*************************

AdwCleaner[R0].txt - [17514 octets] - [05/10/2014 14:17:57]
AdwCleaner[R1].txt - [17498 octets] - [05/10/2014 18:16:33]
AdwCleaner[S0].txt - [16240 octets] - [05/10/2014 18:18:11]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16301 octets] ##########


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.0 (10.05.2014:1)
OS: Windows 7 Home Premium x64
Ran by Nancy on Sun 10/05/2014 at 18:26:30.27
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\msntask_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\msntask_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\msntask_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\msntask_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EF64538-8B54-4573-B48F-4D34B0238AB2}



~~~ Files

Successfully deleted: [File] "C:\Windows\couponprinter.ocx"
Successfully deleted: [File] "C:\Windows\wininit.ini"



~~~ Folders

Successfully deleted: [Folder] C:\Users\Nancy\AppData\LocalLow\FCTB000060231
Successfully deleted: [Folder] "C:\Users\Nancy\AppData\Roaming\getrighttogo"
Successfully deleted: [Folder] "C:\Users\Nancy\appdata\local\cre"
Successfully deleted: [Folder] "C:\Program Files (x86)\coupons"
Successfully deleted: [Folder] "C:\Program Files (x86)\epicplay"
Successfully deleted: [Folder] "C:\Program Files (x86)\rivalgaming"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\rivalgaming"
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{147E7BC1-7991-48F8-B70D-70B22C62531A}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{15DA02B4-E95A-4E96-88D3-9F535E664BBE}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{275CDE5D-358B-4FBE-A576-E611BC8CEFFB}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{2D7191BF-3A08-4C25-AD83-24E0211FCBC0}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{3552DF55-F3DD-4E45-B77D-4C2DA3EE3C51}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{3D15EEDE-D034-4A8F-B0D3-0B7955244D61}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{54826810-9636-45B0-B4C1-8D597E502382}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{56EE46F5-EB17-44A3-AA5A-8E96871DB273}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{6BD2F4D1-7E62-4188-A5A5-909100A7BF55}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{77469F04-650F-4F75-9940-CCBA4D18638E}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{77D9D140-3698-48AA-9089-1F55B3D4FEFC}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{7F2CB9BA-4519-4C87-A518-DD6B640B033E}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{850241EC-9E26-4299-A483-FB280635387A}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{8E1D1DDD-982E-4C32-8950-ED5D393C970F}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{91F8655B-F3BD-4D64-900B-0DEDABB973FF}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{A5330C74-B930-43C5-AA1E-A58195EE8A2D}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{BCD2562E-6EC0-4BD6-BDBC-7F398EF86BD3}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{D737FECC-120F-4590-934E-6A6232F08854}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{E067D2C8-644E-4F98-AABA-B635D064B99C}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{E49CF52E-0608-4DB7-8C55-1A60131B6708}
Successfully deleted: [Empty Folder] C:\Users\Nancy\appdata\local\{E84E0C2C-052E-417A-89E2-84B7CCCD26EA}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 10/05/2014 at 18:32:59.39
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

MalwareBytes Scan log
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 10/5/2014
Scan Time: 6:40:57 PM
Logfile:
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.10.05.08
Rootkit Database: v2014.09.19.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Nancy

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 468282
Time Elapsed: 25 min, 11 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

ken545
2014-10-06, 02:34
Good. I think you will find that a large portion of older people are still hooked on AOL. I remember back when Windows 95 came out, outside of some local iSPs they where about the only game in town

I need to see a new FRST log, besure to checkmark Additions and post both logs, before I pick entries to remove please tell what you removed and what you kept with AOL so I dont cause you problems

geraldgrogan
2014-10-06, 03:12
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-10-2014
Ran by Nancy (administrator) on NANCY-PC on 05-10-2014 20:10:03
Running from C:\Users\Nancy\Downloads\Repair_forum
Loaded Profile: Nancy (Available profiles: Nancy & Mcx1-NANCY-PC)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(iS3, Inc.) C:\Program Files (x86)\STOPzilla!\SZServer.exe
(AMD) C:\Windows\System32\atieclxx.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
() C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe
() C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
(NDS Technologies) C:\Users\Nancy\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
() C:\Users\Nancy\AppData\Local\DIRECTV Player\NDSPCShowServer.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
(AOL Inc.) C:\Users\Nancy\AppData\Local\AOL\AIM\aim.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
(Hewlett-Packard) C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
(Humana Inc.) C:\Users\Public\Humana\GearSync\Humana_GearSync.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\aol\1412533129\ee\aolsoftware.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\CNYHKEY.exe
(Belkin International, Inc.) C:\Program Files\Belkin\Belkin USB Print and Storage Center\Connect.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(iS3, Inc.) C:\Program Files (x86)\STOPzilla!\STOPzilla.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(AOL Inc.) C:\Program Files (x86)\AIM Toolbar\aimtbServer.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SmartMenu] => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [610360 2009-07-08] ()
HKLM-x32\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM-x32\...\Run: [BATINDICATOR] => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe [2068992 2009-05-08] (Hewlett-Packard)
HKLM-x32\...\Run: [LaunchHPOSIAPP] => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe [385024 2009-04-03] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Remote Solution] => C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe [656896 2009-05-26] ()
HKLM-x32\...\Run: [HP Software Update] => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [InstaLAN] => C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe [1485208 2010-07-28] (Affinegy, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GearSyncAutoStart] => C:\Users\Public\Humana\GearSync\Humana_GearSync.exe [535112 2012-08-23] (Humana Inc.)
HKLM-x32\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [3414560 2014-05-19] (Fitbit, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [HostManager] => C:\Program Files (x86)\Common Files\AOL\1412533129\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [HPADVISOR] => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1668664 2009-07-15] (Hewlett-Packard)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-03-01] (Google Inc.)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1938112 2014-09-22] (Valve Corporation)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [PCShowServer] => C:\Users\Nancy\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe [351888 2012-04-02] (NDS Technologies)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-08-27] (TomTom)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [3414560 2014-05-19] (Fitbit, Inc.)
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\...\Run: [AIM for Windows] => C:\Users\Nancy\AppData\Local\AOL\AIM\aim.exe [1075144 2014-02-04] (AOL Inc.)
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/?mtmhp=hyplogusaolp00000092
URLSearchHook: HKLM-x32 - (No Name) - {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - No File
URLSearchHook: HKCU - (No Name) - {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - No File
SearchScopes: HKLM - {C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
SearchScopes: HKCU - {C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF} URL =
BHO: AOL Toolbar Loader -> {3ef64538-8b54-4573-b48f-4d34b0238ab2} -> C:\Program Files\AOL Toolbar\aoltb.dll No File
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: AOL Messaging Toolbar Loader -> {b0cda128-b425-4eef-a174-61a11ac5dbf8} -> C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: IEPlugin Class -> {11222041-111B-46E3-BD29-EFB2449479B1} -> C:\Program Files (x86)\ArcSoft\Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: ToolbarBHO Class -> {9519AF7E-638D-4933-BAD6-D33D23C79FE5} -> C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: AOL Messaging Toolbar Loader -> {b0cda128-b425-4eef-a174-61a11ac5dbf8} -> C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL Inc.)
BHO-x32: Microsoft Live Search Toolbar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM - AOL Messaging Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
Toolbar: HKLM - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll No File
Toolbar: HKLM-x32 - Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
Toolbar: HKLM-x32 - No Name - {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - No File
Toolbar: HKLM-x32 - RAW Thumbnail Viewer - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - AOL Messaging Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL Inc.)
Toolbar: HKLM-x32 - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll No File
Toolbar: HKCU - No Name - {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
Toolbar: HKCU - No Name - {90A1B331-C2B4-4933-9F63-BA7B84D60D58} - No File
Toolbar: HKCU - AOL Messaging Toolbar - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
Toolbar: HKCU - AOL Toolbar - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll No File
DPF: HKLM-x32 {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://www.caminova.net/en/downloads/getmodule.aspx?lang=en
DPF: HKLM-x32 {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab
DPF: HKLM-x32 {C6A47FBB-2ECA-430E-8466-5523772CA4FA} http://www.uscconlinealbum.com/tlc/script/ext/bulkuploader/Uploader8.cab
DPF: HKLM-x32 {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v10.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: lbxfile - {56831180-F115-11d2-B6AA-00104B2B9943} - No File
Handler: lbxres - {24508F1B-9E94-40EE-9759-9AF5795ADF52} - No File
Handler-x32: lbxfile - {56831180-F115-11d2-B6AA-00104B2B9943} - C:\Program Files (x86)\Libronix DLS\System\FileProt.dll (Libronix Corporation)
Handler-x32: lbxres - {24508F1B-9E94-40EE-9759-9AF5795ADF52} - C:\Program Files (x86)\Libronix DLS\System\ResProt.dll (Libronix Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=1.132.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=1.140.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: npEpicPlayDisplayHost -> C:\Program Files (x86)\EpicPlay\npEpicHost.dll No File
FF Plugin HKCU: @nds.com/PCShowPlugin -> C:\Users\Nancy\AppData\Local\DIRECTV Player\npPCShowPlugin.dll (NDS)
FF Plugin HKCU: @nds.com/PlayerPlugin -> C:\Users\Nancy\AppData\Local\DIRECTV Player\npPlayerPlugin.dll (NDS)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
FF Plugin HKCU: NDS.com/PlayerPlugin -> C:\Users\Nancy\AppData\Local\DIRECTV Player\npPlayerPlugin.dll (NDS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Extension: RivalGaming - C:\Users\Nancy\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\links@rivalgaming.com [2012-02-23]
FF Extension: EpicPlay Games - C:\Users\Nancy\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@epicplay.com [2011-09-27]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-01-18]
FF HKLM-x32\...\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn
FF HKLM-x32\...\Firefox\Extensions: [{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}] - C:\Program Files (x86)\ArcSoft\Video Downloader\Plugin_FireFox
FF Extension: ArcSoft Video Downloader Extension - C:\Program Files (x86)\ArcSoft\Video Downloader\Plugin_FireFox [2013-12-25]
FF HKLM-x32\...\Firefox\Extensions: [RAWThumbnailViewer@arcsoft.com.cn] - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension
FF Extension: RAW Thumbnail Viewer - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension [2013-12-25]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: Default ->
CHR Profile: C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-21]
CHR Extension: (Google Search) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-21]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2012-11-01]
CHR Extension: (Virtual Keyboard) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2012-11-01]
CHR Extension: (Google Wallet) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Gmail) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-21]
CHR Extension: (Anti-Banner) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2012-11-01]
CHR HKCU\...\Chrome\Extension: [bpfboklmeiefoedekjeigdcnfbpjeaii] - C:\Users\Nancy\AppData\Local\CRE\bpfboklmeiefoedekjeigdcnfbpjeaii.crx []
CHR HKLM-x32\...\Chrome\Extension: [bpfboklmeiefoedekjeigdcnfbpjeaii] - C:\Users\Nancy\AppData\Local\CRE\bpfboklmeiefoedekjeigdcnfbpjeaii.crx []
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AffinegyService; C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe [569752 2010-07-28] (Affinegy, Inc.)
R2 Belkin Local Backup Service; C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe [181760 2010-02-17] () [File not signed]
R2 Belkin Network USB Helper; C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe [55296 2010-02-09] () [File not signed]
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [1436192 2014-05-19] (Fitbit, Inc.)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries)
R2 HPBtnSrv; C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe [192512 2008-09-30] () [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 iprip; C:\Windows\System32\iprip.dll [35328 2009-07-13] (Microsoft Corporation)
R2 LightScribeService; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-05-18] (Hewlett-Packard Company) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 szserver; c:\Program Files (x86)\STOPzilla!\SZServer.exe [57136 2014-08-27] (iS3, Inc.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S0 is3srv; C:\Windows\SysWow64\drivers\is3srv64.sys [74768 2014-08-27] (iS3 Inc.)
S3 mr8980; C:\Windows\System32\DRIVERS\dwcamx64.sys [84992 2010-05-11] (Mars Semiconductor Corp.)
S3 mr8980; C:\Windows\SysWOW64\DRIVERS\dwcamx64.sys [84992 2010-05-11] (Mars Semiconductor Corp.)
S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [10368 2008-07-16] (Padus, Inc.) [File not signed]
R3 sxuptp; C:\Windows\System32\DRIVERS\sxuptp.sys [291352 2009-06-22] (silex technology, Inc.)
R0 szkg5; C:\Windows\SysWow64\DRIVERS\szkg64.sys [74768 2014-08-27] (iS3 Inc.)
S3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2010-01-21] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [27648 2010-01-21] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [33280 2010-01-21] (LG Electronics Inc.)
R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [146928 2009-07-23] (CyberLink Corp.)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-05 18:32 - 2014-10-05 18:32 - 00004368 _____ () C:\Users\Nancy\Desktop\JRT.txt
2014-10-05 18:28 - 2014-10-05 18:28 - 00000728 _____ () C:\Windows\system32\Drivers\kgpcpy.cfg
2014-10-05 18:26 - 2014-10-05 18:26 - 00000000 ____D () C:\Windows\ERUNT
2014-10-05 14:38 - 2014-10-05 20:10 - 00000000 ____D () C:\FRST
2014-10-05 14:33 - 2014-10-05 14:33 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-NANCY-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-10-05 14:31 - 2014-10-05 14:31 - 00002201 _____ () C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2014-10-05 14:31 - 2014-10-05 14:31 - 00000000 ____D () C:\RegBackup
2014-10-05 14:31 - 2014-10-05 14:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-10-05 14:31 - 2014-10-05 14:31 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-10-05 14:30 - 2014-10-05 20:10 - 00000000 ____D () C:\Users\Nancy\Downloads\Repair_forum
2014-10-05 14:18 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-10-05 14:17 - 2014-10-05 18:18 - 00000000 ____D () C:\AdwCleaner
2014-10-05 14:17 - 2014-10-05 14:17 - 01375089 _____ () C:\Users\Nancy\Downloads\adwcleaner_3.311.exe
2014-10-05 13:21 - 2014-10-05 13:21 - 00000995 _____ () C:\Users\Public\Desktop\AOL Desktop 9.7.lnk
2014-10-05 13:21 - 2014-10-05 13:21 - 00000929 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\AOL Desktop 9.7.lnk
2014-10-05 13:18 - 2014-10-05 14:01 - 00000000 ____D () C:\Program Files (x86)\AOL Desktop 9.7
2014-10-05 13:18 - 2014-10-05 13:18 - 00000000 ____D () C:\Program Files (x86)\AOL
2014-10-05 00:37 - 2014-10-05 00:37 - 00000000 _____ () C:\autoexec.bat
2014-10-05 00:36 - 2014-10-05 00:36 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-10-05 00:35 - 2014-10-05 09:31 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-10-05 00:22 - 2014-10-05 00:24 - 159405792 _____ () C:\Users\Nancy\Downloads\setup_11.0.3.7.x01_2014_10_05_08_26.exe
2014-10-04 21:32 - 2014-10-05 18:37 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-04 21:32 - 2014-10-04 21:32 - 00001075 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-04 21:32 - 2014-10-04 21:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-04 21:32 - 2014-10-04 21:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware2
2014-10-04 21:32 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-04 21:32 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-04 21:32 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-04 21:18 - 2014-10-04 21:19 - 00000000 ____D () C:\Users\Nancy\AppData\Local\AIM Toolbar
2014-10-04 21:18 - 2014-10-04 21:18 - 00001078 _____ () C:\Users\Nancy\Desktop\AIM.lnk
2014-10-04 21:18 - 2014-10-04 21:18 - 00000000 ____D () C:\Users\Nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AIM for Windows
2014-10-04 21:18 - 2014-10-04 21:18 - 00000000 ____D () C:\ProgramData\AIM Toolbar
2014-10-04 21:18 - 2014-10-04 21:18 - 00000000 ____D () C:\Program Files\AIM Toolbar
2014-10-04 21:18 - 2014-10-04 21:18 - 00000000 ____D () C:\Program Files (x86)\AIM Toolbar
2014-10-04 20:37 - 2014-10-04 20:37 - 00000000 ____D () C:\Windows\pss
2014-10-04 20:29 - 2014-10-04 20:29 - 00276448 _____ () C:\Windows\Minidump\100414-96798-01.dmp
2014-10-04 20:13 - 2014-10-04 20:12 - 00213168 _____ (AOL LLC.) C:\Users\Nancy\Downloads\AOL_Desktop_9.7 - Copy.exe
2014-10-04 20:00 - 2014-10-05 13:04 - 00000004 _____ () C:\Windows\msoffice.ini
2014-10-04 17:40 - 2014-10-05 13:30 - 00000000 ____D () C:\Users\Nancy\AppData\Roaming\AOL
2014-10-04 17:29 - 2014-10-05 13:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL
2014-10-04 17:27 - 2014-10-05 13:49 - 00000000 ____D () C:\ProgramData\AOL
2014-10-04 17:27 - 2014-10-05 13:06 - 00000000 ____D () C:\Users\Nancy\AppData\Local\AOL
2014-10-04 17:27 - 2014-10-04 17:27 - 00000000 ____D () C:\ProgramData\AOL OCP
2014-10-04 16:26 - 2014-10-04 16:26 - 00000000 ___SD () C:\Users\Nancy\Documents\Passwords Database
2014-10-04 15:47 - 2014-10-04 15:47 - 00040195 _____ () C:\Users\Nancy\Downloads\aolcleaner.exe
2014-10-04 14:16 - 2011-01-14 07:30 - 00000864 _____ () C:\Windows\system32\Drivers\etc\hosts.20141004-141646.backup
2014-10-04 14:15 - 2011-01-14 07:30 - 00000864 _____ () C:\Windows\system32\Drivers\etc\hosts.20141004-141549.backup
2014-10-04 14:11 - 2014-10-04 14:11 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Nancy\Downloads\mbam-setup-2.0.2.1012.exe
2014-10-04 14:03 - 2014-10-04 14:55 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-10-04 14:03 - 2014-10-04 14:03 - 00001357 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-10-04 14:03 - 2014-10-04 14:03 - 00001345 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-10-04 14:03 - 2014-10-04 14:03 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-10-04 14:03 - 2014-10-04 14:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-10-04 14:03 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-10-04 14:02 - 2014-10-04 14:08 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-10-04 13:33 - 2014-09-24 21:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-04 13:33 - 2014-09-24 20:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-09-23 15:25 - 2014-09-09 17:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-23 15:25 - 2014-09-09 16:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-21 15:34 - 2014-09-21 15:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STOPzilla
2014-09-21 15:34 - 2014-08-27 13:30 - 00047496 ____R (GFI Software) C:\Windows\system32\SBBD.EXE
2014-09-20 13:31 - 2014-09-20 13:31 - 00002960 _____ () C:\Windows\System32\Tasks\{CF53108C-8CD9-43C0-9E68-E83BA10A8BCF}
2014-09-20 13:31 - 2014-09-20 13:31 - 00002960 _____ () C:\Windows\System32\Tasks\{0F12769E-3D7A-4A4C-AE76-99D4A60601DA}
2014-09-16 13:17 - 2014-09-16 13:17 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2014-09-16 13:17 - 2014-09-16 13:17 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2014-09-16 13:17 - 2014-09-16 13:17 - 00163840 _____ (America Online) C:\Windows\SysWOW64\jgdw400.dll
2014-09-16 13:17 - 2014-09-16 13:17 - 00027648 _____ (Johnson-Grace Company) C:\Windows\SysWOW64\jgpl400.dll
2014-09-15 16:17 - 2014-09-15 16:17 - 00002960 _____ () C:\Windows\System32\Tasks\{C4005CD9-C787-46F7-8F15-0C72A236B33F}
2014-09-15 13:28 - 2014-09-15 13:28 - 00003168 _____ () C:\Windows\System32\Tasks\{3AB45F11-DEB1-4623-A3D6-5E593F57AE41}
2014-09-14 15:27 - 2014-09-14 15:27 - 00000000 ____D () C:\ProgramData\Oracle
2014-09-14 15:26 - 2014-09-14 15:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-09-14 15:26 - 2014-07-25 12:55 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-09-14 15:26 - 2014-07-25 12:49 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-09-14 15:26 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-09-14 15:26 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-09-14 15:25 - 2014-09-14 15:26 - 00006747 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_67-b01.log
2014-09-13 14:25 - 2014-09-13 14:25 - 00284672 _____ () C:\Windows\Minidump\091314-23961-01.dmp
2014-09-11 12:54 - 2014-09-11 12:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fitbit Connect
2014-09-11 12:54 - 2014-09-11 12:54 - 00000000 ____D () C:\ProgramData\FitbitConnect
2014-09-11 12:54 - 2014-09-11 12:54 - 00000000 ____D () C:\Program Files (x86)\Fitbit Connect
2014-09-11 03:09 - 2014-08-19 13:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 03:09 - 2014-08-19 12:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 03:09 - 2014-08-18 18:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 03:09 - 2014-08-18 17:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 03:09 - 2014-08-18 17:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 03:09 - 2014-08-18 17:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 03:09 - 2014-08-18 17:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 03:09 - 2014-08-18 17:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 03:09 - 2014-08-18 17:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-11 03:09 - 2014-08-18 17:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 03:09 - 2014-08-18 17:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-11 03:09 - 2014-08-18 17:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-11 03:09 - 2014-08-18 17:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 03:09 - 2014-08-18 17:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 03:09 - 2014-08-18 17:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 03:09 - 2014-08-18 17:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-11 03:09 - 2014-08-18 17:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-11 03:09 - 2014-08-18 17:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-11 03:09 - 2014-08-18 17:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-11 03:09 - 2014-08-18 16:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 03:09 - 2014-08-18 16:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 03:09 - 2014-08-18 16:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 03:09 - 2014-08-18 16:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-11 03:09 - 2014-08-18 16:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 03:09 - 2014-08-18 16:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 03:09 - 2014-08-18 16:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 03:09 - 2014-08-18 16:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 03:09 - 2014-08-18 16:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 03:09 - 2014-08-18 16:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 03:09 - 2014-08-18 16:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 03:09 - 2014-08-18 16:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 03:09 - 2014-08-18 16:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 03:09 - 2014-08-18 16:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 03:09 - 2014-08-18 16:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-11 03:09 - 2014-08-18 16:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 03:09 - 2014-08-18 16:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 03:09 - 2014-08-18 16:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 03:09 - 2014-08-18 16:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 03:09 - 2014-08-18 16:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 03:09 - 2014-08-18 16:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 03:09 - 2014-08-18 16:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-11 03:09 - 2014-08-18 16:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 03:09 - 2014-08-18 16:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 03:09 - 2014-08-18 16:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 03:09 - 2014-08-18 16:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 03:09 - 2014-08-18 16:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 03:09 - 2014-08-18 16:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 03:09 - 2014-08-18 16:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 03:09 - 2014-08-18 16:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 03:09 - 2014-08-18 16:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 03:09 - 2014-08-18 16:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 03:09 - 2014-08-18 15:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 03:09 - 2014-08-18 15:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 03:09 - 2014-08-18 15:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 03:09 - 2014-08-18 15:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-11 03:09 - 2014-08-18 15:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 03:01 - 2014-06-26 21:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 03:01 - 2014-06-26 20:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-10 04:21 - 2014-09-04 21:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-10 04:21 - 2014-09-04 21:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-10 04:21 - 2014-08-01 06:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-10 04:21 - 2014-08-01 06:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-10 04:21 - 2014-07-06 21:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-10 04:21 - 2014-07-06 21:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-10 04:21 - 2014-07-06 20:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-10 04:21 - 2014-07-06 20:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-10 04:21 - 2014-07-06 20:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-09-10 04:21 - 2014-06-23 22:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-10 04:21 - 2014-06-23 21:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-05 13:37 - 2014-09-05 13:37 - 00284672 _____ () C:\Windows\Minidump\090514-20155-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-05 20:10 - 2011-01-14 07:26 - 00000000 ____D () C:\ProgramData\STOPzilla!
2014-10-05 20:03 - 2012-06-04 10:47 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-05 19:31 - 2010-03-01 18:52 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-05 18:33 - 2009-07-13 23:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-05 18:33 - 2009-07-13 23:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-05 18:31 - 2012-06-18 19:36 - 02053362 _____ () C:\Windows\WindowsUpdate.log
2014-10-05 18:23 - 2011-07-01 22:52 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-10-05 18:21 - 2010-03-01 18:52 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-05 18:20 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-05 18:19 - 2012-06-18 19:27 - 00019922 _____ () C:\Windows\setupact.log
2014-10-05 18:19 - 2009-12-18 23:23 - 00867618 _____ () C:\Windows\PFRO.log
2014-10-05 17:58 - 2013-07-06 16:57 - 00000464 _____ () C:\Windows\Tasks\Arcadesafari.job
2014-10-05 17:24 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
2014-10-05 16:12 - 2010-06-19 02:39 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-10-05 16:09 - 2009-07-13 22:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-10-05 13:21 - 2011-12-22 15:50 - 00009351 ____H () C:\IPH.PH
2014-10-05 13:21 - 2011-03-07 03:47 - 00512498 _____ () C:\install.log
2014-10-05 13:16 - 2009-12-18 22:00 - 00058696 _____ (AOL Inc.) C:\Windows\SysWOW64\AOLParconLink.exe
2014-10-05 00:25 - 2010-03-01 22:14 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-10-04 23:27 - 2009-08-31 14:06 - 00000000 ____D () C:\ProgramData\Symantec
2014-10-04 22:52 - 2013-11-08 16:11 - 00009392 _____ () C:\Windows\SysWOW64\Drivers\kgpfr2.cfg
2014-10-04 20:37 - 2013-02-16 18:35 - 00000000 ____D () C:\Users\Nancy\AppData\Local\PMB Files
2014-10-04 20:29 - 2012-11-09 07:35 - 616735266 _____ () C:\Windows\MEMORY.DMP
2014-10-04 20:29 - 2010-03-16 07:34 - 00000000 ____D () C:\Windows\Minidump
2014-10-04 20:00 - 2009-07-13 21:34 - 00000438 _____ () C:\Windows\win.ini
2014-10-04 18:42 - 2013-12-02 20:27 - 00003186 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForNancy
2014-10-04 18:42 - 2013-12-02 20:27 - 00000332 _____ () C:\Windows\Tasks\HPCeeScheduleForNancy.job
2014-10-04 17:21 - 2010-07-16 22:06 - 00000000 ____D () C:\Users\Nancy\Documents\26
2014-10-04 16:41 - 2009-08-31 13:44 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Help & Tools
2014-10-04 15:57 - 2013-02-24 18:04 - 00000000 ____D () C:\Firefox
2014-10-04 15:48 - 2013-01-07 19:17 - 00061424 _____ () C:\Windows\SysWOW64\Drivers\kgpcpy.cfg
2014-10-04 14:10 - 2010-03-01 18:52 - 00000000 ____D () C:\Users\Nancy\AppData\Local\Google
2014-10-04 14:06 - 2011-01-18 15:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-04 13:59 - 2009-12-19 22:20 - 00000000 ____D () C:\Users\Nancy\AppData\Roaming\HP Support Assistant
2014-10-04 13:59 - 2009-12-19 22:05 - 00000000 ____D () C:\Users\Nancy\AppData\Roaming\HpUpdate
2014-10-04 13:27 - 2013-01-04 15:16 - 00000000 ____D () C:\Program Files (x86)\STOPzilla!
2014-09-26 08:24 - 2011-01-14 09:21 - 00000016 _____ () C:\Windows\system32\config\software.szfi
2014-09-25 08:03 - 2012-06-04 10:47 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-25 08:03 - 2012-06-04 10:47 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-25 08:03 - 2011-06-03 08:15 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-23 12:59 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-19 18:14 - 2012-11-01 16:18 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-15 09:06 - 2010-02-17 22:11 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-14 15:26 - 2010-01-02 18:55 - 00000000 ____D () C:\Program Files (x86)\Java
2014-09-12 13:44 - 2009-12-18 22:13 - 00005678 _____ () C:\Users\Nancy\AppData\Roaming\wklnhst.dat
2014-09-12 13:44 - 2009-07-14 00:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-09-11 03:07 - 2010-12-06 00:36 - 00787980 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-11 03:07 - 2009-07-14 00:13 - 00787980 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-11 03:06 - 2013-08-07 03:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 03:02 - 2010-01-14 15:53 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-11 03:00 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel

Some content of TEMP:
====================
C:\Users\Nancy\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-26 00:37

==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-10-2014
Ran by Nancy at 2014-10-05 20:10:41
Running from C:\Users\Nancy\Downloads\Repair_forum
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: STOPzilla (Disabled - Up to date) {17032AB1-6644-0721-EEB5-A39B8B646009}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: STOPzilla (Enabled - Up to date) {AC62CB55-407E-08AF-D405-98E9F0E32AB4}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3D Merry Christmas Screensaver 1.0 (HKLM-x32\...\3D Merry Christmas Screensaver_is1) (Version: - )
64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
Abrosoft FantaMorph 4.0 (HKLM-x32\...\Abrosoft FantaMorph 4_is1) (Version: 4.0 - Abrosoft)
Acrobat.com (HKLM-x32\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden
ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.3 - Hewlett-Packard) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.5.1.17730 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 2.5.1.17730 - Adobe Systems Inc.) Hidden
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
AIM for Windows (HKCU\...\AIM) (Version: - AOL Inc.)
Aimersoft DRM Media Converter(Build 1.5.3.0) (HKLM-x32\...\Aimersoft DRM Media Converter_is1) (Version: - Aimersoft Software)
Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.2.0.399 - Amazon Services LLC)
Amazon MP3 Downloader 1.0.15 (HKLM-x32\...\Amazon MP3 Downloader) (Version: 1.0.15 - Amazon Services LLC)
American Pickers (HKCU\...\American Pickers) (Version: - )
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
AOL Messaging Toolbar (HKLM-x32\...\AIM Toolbar) (Version: - AOL Inc.)
AOL Toolbar (HKLM-x32\...\AOL Toolbar) (Version: - AOL Inc.)
AOL Uninstaller (Choose which Products to Remove) (HKLM-x32\...\AOL Uninstaller) (Version: - AOL Inc.)
Apple Application Support (HKLM-x32\...\{853A4763-6643-4604-8D64-28BDD8925F4C}) (Version: 1.5.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{8F473675-D702-45F9-8EBC-342B40C17BF5}) (Version: 3.4.0.25 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}) (Version: 2.1.1.116 - Apple Inc.)
ArcSoft MediaImpression 2 (HKLM-x32\...\{210E8562-74DA-4D97-945B-88B2ED9C8028}) (Version: 2.0.15.1073 - ArcSoft)
ArcSoft Panorama Maker 4 (HKLM-x32\...\{37530151-56A6-4CE4-9F9F-CE1F5A1356C6}) (Version: 4.5.0.112 - ArcSoft)
ArcSoft Photo Book Screen Saver (HKLM-x32\...\{E2EE273D-E111-4FFD-ACD4-78E1D35E01D2}) (Version: 2.0.0.13 - ArcSoft)
ArcSoft PhotoStudio Darkroom 2 (HKLM-x32\...\{40DA94AF-34B7-4BA7-A37F-26F899C031FF}) (Version: 2.0.0.174 - ArcSoft)
ArcSoft Print Creations - Album Page (HKLM-x32\...\{E6B4117F-AC59-4B13-9274-EB136E8897EE}) (Version: - ArcSoft)
ArcSoft Print Creations - Brochures & Flyers (HKLM-x32\...\{01A1A019-E1D8-482A-BE17-5E118D17C0A0}) (Version: - ArcSoft)
ArcSoft Print Creations - Funhouse (HKLM-x32\...\{9591C049-5CAE-4E89-A8D9-191F1899628B}) (Version: - ArcSoft)
ArcSoft Print Creations - Funhouse II (HKLM-x32\...\{3CE47E6B-AE27-4E40-AC54-329EED96B933}) (Version: - ArcSoft)
ArcSoft Print Creations - Greeting Card (HKLM-x32\...\{F04F9557-81A9-4293-BC49-2C216FA325A7}) (Version: - ArcSoft)
ArcSoft Print Creations - Order Calendar (HKLM-x32\...\{BB3E6B07-2351-4424-B563-29D587C39956}) (Version: - ArcSoft)
ArcSoft Print Creations - Photo Book (HKLM-x32\...\{56589DFE-0C29-4DFE-8E42-887B771ECD23}) (Version: - ArcSoft)
ArcSoft Print Creations - Photo Calendar (HKLM-x32\...\{CA9ED5E4-1548-485B-A293-417840060158}) (Version: - ArcSoft)
ArcSoft Print Creations - Photo Prints (HKLM-x32\...\{95F875CC-1B85-43E6-B3E0-13EA04F3D995}) (Version: - ArcSoft)
ArcSoft Print Creations - Poster Creator (HKLM-x32\...\{5D1C82E7-7EC0-4404-A8AD-36C3B444BC34}) (Version: - ArcSoft)
ArcSoft Print Creations - Quick Photo Book (HKLM-x32\...\{5023B3E9-6B73-471E-8BD9-DA4442AE357C}) (Version: - ArcSoft)
ArcSoft Print Creations - Scrapbook (HKLM-x32\...\{B0D83FCD-9D42-43ED-8315-250326AADA02}) (Version: - ArcSoft)
ArcSoft Print Creations - Slimline Card (HKLM-x32\...\{007B37D9-0C45-4202-834B-DD5FAAE99D63}) (Version: - ArcSoft)
ArcSoft Print Creations (HKLM-x32\...\{9925A219-5F08-4C8C-809D-2599FEEF80A6}) (Version: 2.8.255.417 - ArcSoft)
ArcSoft RAW Thumbnail Viewer (HKLM-x32\...\{82FAC25D-D0E1-4D60-9268-F3DD958BF052}) (Version: 2.0.0.11 - ArcSoft)
ArcSoft Scan-n-Stitch Deluxe (HKLM-x32\...\{363188E4-1A27-4DE6-BA48-823D2E205385}) (Version: 1.1.0.17 - ArcSoft)
ArcSoft Video Downloader (HKLM-x32\...\{C8B44566-839A-459C-A73D-49764CE216CC}) (Version: 2.0.0.39 - ArcSoft)
Astro Gemini Screensaver Manager 2.0 (HKLM-x32\...\Astro Gemini Screensaver Manager_is1) (Version: - )
ATI Catalyst Install Manager (HKLM\...\{F4934901-B3C8-9918-F018-2D68F94B380E}) (Version: 3.0.728.0 - ATI Technologies, Inc.)
Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version: - )
Batch Update (x32 Version: 2.1 - Libronix Corporation) Hidden
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 1.140.0 - EA Digital Illusions CE AB)
Belkin Setup and Router Monitor (HKLM-x32\...\Belkin Setup and Router Monitor_is1) (Version: - )
Belkin USB Print and Storage Center (HKLM\...\Belkin USB Print and Storage Center) (Version: 1.0.0 - Belkin International, Inc.)
Bible Data Type System Files (x32 Version: 2.1 - Libronix Corporation) Hidden
Bonjour (HKLM\...\{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}) (Version: 2.0.4.0 - Apple Inc.)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
C309g-m (x32 Version: 130.0.396.000 - Hewlett-Packard) Hidden
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
Catalyst Control Center HydraVision Full (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2009.0520.1631.27815 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Czech (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Danish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Dutch (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help English (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Finnish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help French (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help German (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Greek (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Italian (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Japanese (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Korean (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Polish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Russian (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Spanish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Swedish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Thai (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
CCC Help Turkish (x32 Version: 2009.0520.1630.27815 - ATI) Hidden
ccc-core-static (x32 Version: 2009.0520.1631.27815 - ATI) Hidden
ccc-utility64 (Version: 2009.0520.1631.27815 - ATI) Hidden
CCScore (x32 Version: 7.00.0000.0001 - EASTMAN KODAK Company) Hidden
Common System Files (x32 Version: 2.1 - Libronix Corporation) Hidden
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CyberLink DVD Suite Deluxe (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.3101 - CyberLink Corp.)
CyberLink DVD Suite Deluxe (x32 Version: 6.0.3101 - CyberLink Corp.) Hidden
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden
Digital Wireless Camera (HKLM-x32\...\{8EE8D436-CF54-4713-ABA1-B885FAB43D33}) (Version: 1.00.0000 - Digital Wireless Camera)
DIRECTV Player (HKLM-x32\...\{5F3783B7-F809-45A7-8A92-A44B441FDA7C}) (Version: 4.00 - DIRECTV)
DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
Document Express DjVu Plug-in (HKLM-x32\...\{65D29933-D1E5-4BDF-ACB1-DC41581EF342}) (Version: 6.1.31219 - Caminova, Inc.)
Elevated Installer (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
EpicPlay (HKLM-x32\...\EpicPlay) (Version: - EpicPlay LLC)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
ESSBrwr (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESSCDBK (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESScore (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESSgui (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESSini (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESSPCD (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
ESSPDock (x32 Version: 6.03.0001.0004 - EASTMAN KODAK Company) Hidden
ESSTOOLS (x32 Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
essvatgt (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
EuroTalk Talk Now! (HKLM-x32\...\{F26615EF-AF0A-486C-99C9-B65C8C401EBC}) (Version: 2.2.5.1 - EuroTalk Interactive)
fflink (x32 Version: 6.02.1001.0001 - EASTMAN KODAK Company) Hidden
Fitbit Connect (HKLM-x32\...\{D3CD091B-296B-48E9-9F0F-E9FE53E02E41}) (Version: 1.0.3.5511 - Fitbit Inc.)
Food Network Recipe Manager (HKLM-x32\...\{E321D364-2EA9-4906-BBAC-AD0246F9D3E7}) (Version: 1.0.4.0 - Nova Development)
GameSpy Arcade (HKLM-x32\...\GameSpy Arcade) (Version: - )
Garmin Express (HKLM-x32\...\{b43ffffb-1adc-4bcb-b277-7844ebff94da}) (Version: 3.2.17.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.124 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Graphical Query Editor (x32 Version: 2.1 - Libronix Corporation) Hidden
Hotel Giant 2 (HKLM-x32\...\{6E293CEF-E7D1-4397-A971-DE9C6AC2939E}) (Version: 110 - Nobilis)
HP Advisor (HKLM-x32\...\{B53E61D7-7C80-40DF-82D2-CF5390D6D20A}) (Version: 3.2.8946.3086 - Hewlett-Packard)
HP Customer Experience Enhancements (x32 Version: 6.0.1.3 - Hewlett-Packard) Hidden
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Easy Backup (HKLM-x32\...\{67431FA8-4B89-42DD-A68E-30D77F6C8D99}_is1) (Version: 1.0.8.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.0.71 - WildTangent)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP MAINSTREAM KEYBOARD (HKLM-x32\...\{B40D7926-AE5F-41EA-8AC6-56C0E2F00E9D}) (Version: 1.4.3.0 - Hewlett-Packard)
HP MediaSmart Demo (HKLM-x32\...\{9DEF9686-CCB2-47B7-BF83-B49EA21FA016}) (Version: 1.00.0000 - Hewlett-Packard)
HP MediaSmart DVD (HKLM-x32\...\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 3.0.3123 - Hewlett-Packard)
HP MediaSmart DVD (x32 Version: 3.0.3123 - Hewlett-Packard) Hidden
HP MediaSmart Movie Themes (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 3.0.3102 - Hewlett-Packard)
HP MediaSmart Movie Themes (x32 Version: 3.0.3102 - Hewlett-Packard) Hidden
HP MediaSmart Music/Photo/Video (HKLM-x32\...\InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}) (Version: 3.0.3205 - Hewlett-Packard)
HP MediaSmart Music/Photo/Video (x32 Version: 3.0.3205 - Hewlett-Packard) Hidden
HP MediaSmart SmartMenu (HKLM\...\{26280024-DFB7-4967-90DB-7F9C6660D01E}) (Version: 3.0.28.2 - Hewlett-Packard)
HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Photosmart Premium C309g-m All-In-One Driver Software 13.0 Rel .6 (HKLM\...\{181AC4C7-B83C-4B5F-B566-E19BF2472429}) (Version: 13.0 - HP)
HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP)
HP Remote Solution (HKLM-x32\...\HP Remote Solution) (Version: 1.1.9.0 - TopSeed)
HP Remote Solution (x32 Version: 1.1.9.0 - TopSeed) Hidden
HP Setup (HKLM-x32\...\{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}) (Version: 1.2.3220.3079 - Hewlett-Packard)
HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Support Assistant (HKLM-x32\...\{08DB3902-2CE0-474D-BCE3-0177766CE9F1}) (Version: 5.1.10.7 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}) (Version: 10.1.0002 - Hewlett-Packard)
HP Update (HKLM-x32\...\{D46D081B-F60E-467E-A7C4-117B70D76731}) (Version: 5.001.000.014 - Hewlett-Packard)
HPAsset component for HP Active Support Library (x32 Version: 3.0.0.3 - Hewlett-Packard) Hidden
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
hpPrintProjects (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
hpWLPGInstaller (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
Humana GearSync 1.5.117 (HKLM-x32\...\{4ADA60D4-895E-4B03-86BF-39582AD5E95C}_is1) (Version: 1.5.117 - Humana)
HydraVision (x32 Version: 4.2.98.0 - ATI Technologies Inc.) Hidden
Internet TV for Windows Media Center (HKLM-x32\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 3.2.1.0 - Microsoft Corporation)
iTunes (HKLM\...\{9545E9DB-6F4C-4404-BF25-E221BE8B44C5}) (Version: 10.2.1.1 - Apple Inc.)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217017FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden
Java(TM) 6 Update 30 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216027FF}) (Version: 6.0.300 - Oracle)
Kodak EasyShare software (HKLM-x32\...\{D32470A1-B10C-4059-BA53-CF0486F68EBC}) (Version: - Eastman Kodak Company)
LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1901 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.1901 - CyberLink Corp.) Hidden
Libronix Digital Library System (HKLM-x32\...\Libronix DLS) (Version: - Libronix Corporation)
Libronix Digital Library System (x32 Version: 2.1 - Libronix Corporation) Hidden
Libronix DLS Application (x32 Version: 2.1 - Libronix Corporation) Hidden
Libronix DLS Shortcuts (x32 Version: 2.1 - Libronix Corporation) Hidden
LibronixUpdate (x32 Version: 2.1 - Libronix Corporation) Hidden
LightScribe System Software (HKLM-x32\...\{DD6C316A-FE75-4FBB-9D22-4C1920232B72}) (Version: 1.18.5.1 - LightScribe)
LLS Resource Driver (x32 Version: 2.1 - Libronix Corporation) Hidden
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
MemoriesOnTV (HKLM-x32\...\{982755B5-03A1-40B7-8F4A-13C17238D688}) (Version: 4.0.4 - Nova Development)
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Live Search Toolbar (HKLM-x32\...\{DF802C05-4660-418c-970C-B988ADB1D316}) (Version: 3.0.560.0 - Microsoft Live Search Toolbar)
Microsoft Live Search Toolbar (x32 Version: 3.0.560.0 - Microsoft Corporation) Hidden
Microsoft Rise Of Nations (HKLM-x32\...\RiseOfNations 1.0) (Version: - Microsoft)
Microsoft Search Enhancement Pack (x32 Version: 1.2.123.0 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft VC9 runtime libraries (x32 Version: 1.0.0 - AOL Inc.) Hidden
Microsoft VC9 runtime libraries (x32 Version: 1.0.0 - AOL LLC) Hidden
Microsoft VC9 runtime libraries (x32 Version: 2.0.0 - AOL Inc.) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Works (HKLM-x32\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
MobileMe Control Panel (HKLM\...\{56F26668-13DA-497A-883F-61434A10CBAB}) (Version: 3.1.5.0 - Apple Inc.)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML4 Parser (HKLM-x32\...\{01501EBA-EC35-4F9F-8889-3BE346E5DA13}) (Version: 1.0.0 - Microsoft Game Studios)
netbrdg (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
Netflix in Windows Media Center (HKLM-x32\...\{0CA72D12-F6C6-4D43-A2A0-41F5AA17E2B6}) (Version: 3.3.101.0 - Microsoft Corporation)
Network64 (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden
OEB Resource Driver (x32 Version: 2.1 - Libronix Corporation) Hidden
OfotoXMI (x32 Version: 7.02.0000.0001 - EASTMAN KODAK Company) Hidden
PDF Resource Driver (x32 Version: 2.1 - Libronix Corporation) Hidden
Photo Explosion (HKLM-x32\...\{822944D4-BC5D-44AE-9315-16C174D318B0}) (Version: 4.0.0.12 - Nova Development)
Picaboo X (HKLM-x32\...\com.picaboo.Picaboo.A382D4714709B456C4E0088DFC1F7243AF9EBF75.1) (Version: 10.136P - Picaboo Corporation)
Picaboo X (x32 Version: 10.136 - Picaboo Corporation) Hidden
PictureMover (HKLM-x32\...\{1896E712-2B3D-45eb-BCE9-542742A51032}) (Version: 3.3.1.19 - Hewlett-Packard Company)
Podmaxx (HKLM-x32\...\{E0DEA5B0-DF24-4CA2-B725-98C04FCB5DAF}) (Version: 3.00.82 - Bluecase Software)
Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.3101 - CyberLink Corp.)
Power2Go (x32 Version: 6.0.3101 - CyberLink Corp.) Hidden
PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.3101 - CyberLink Corp.)
PowerDirector (x32 Version: 7.0.3101 - CyberLink Corp.) Hidden
PowerRecover (x32 Version: 5.5.1923 - CyberLink Corp.) Hidden
PS_AIO_06_C309g-m_SW_Min (x32 Version: 130.0.396.000 - Hewlett-Packard) Hidden
QuickTime (HKLM-x32\...\{57752979-A1C9-4C02-856B-FBB27AC4E02C}) (Version: 7.69.80.9 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6196 - Realtek Semiconductor Corp.)
Rise of Nations Thrones and Patriots (HKLM-x32\...\RiseofNationsExpansion 1.0) (Version: - )
RivalGaming (HKLM-x32\...\RivalGaming) (Version: - RivalGaming)
Safari (HKLM-x32\...\{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}) (Version: 5.33.21.1 - Apple Inc.)
Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden
Screensavers.com Content (HKLM-x32\...\www_screensavers_com) (Version: - Screensavers.com)
Sentence Diagramming (x32 Version: 2.1 - Libronix Corporation) Hidden
Serif MontagePlus 1.0 (HKLM-x32\...\{A8A42A57-2320-464B-9F5D-3F85089C4714}) (Version: 1.0 - )
Serif PanoramaPlus 3 (HKLM-x32\...\{64893BC9-D912-4A2D-A47A-E38650112781}) (Version: 3.0.1.017 - Serif (Europe) Ltd)
SFR (x32 Version: 7.01.0000.0003 - Eastman Kodak Company) Hidden
SHASTA (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP)
Sid Meier's Civilization 4 - Beyond the Sword (HKLM-x32\...\{32E4F0D2-C135-475E-A841-1D59A0D22989}) (Version: 3.00 - Firaxis Games)
Sid Meier's Civilization 4 (HKLM-x32\...\{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}) (Version: 1.74 - Firaxis Games)
Sid Meier's Civilization 4 (x32 Version: 1.09 - Firaxis Games) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.)
Sins of a Solar Empire (HKLM-x32\...\Sins of a Solar Empire) (Version: - Stardock Entertainment)
Sins of a Solar Empire (x32 Version: 1.00.00 - Stardock Entertainment, Inc.) Hidden
skin0001 (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
SKINXSDK (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Star Trek Online (HKLM-x32\...\Star Trek Online) (Version: - Cryptic Studios)
staticcr (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
STOPzilla (HKLM-x32\...\{FEC0C541-FA7C-44EC-A62A-6B75793CE968}) (Version: 6.1.90.7 - iS3 Inc.)
Super Letter Linker (HKLM-x32\...\am-superletterlinker) (Version: - )
TomTom HOME (HKLM-x32\...\{99072AB4-D795-44D5-9D65-E3C9F8322C97}) (Version: 2.9.7 - TomTom)
TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TransferMy Music 3.0 (HKLM-x32\...\TransferMy Music_is1) (Version: 3.0 - Purple Ghost Software, Inc.)
TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 1.10.0 - Tweaking.com)
Uniden Surveillance System 5.0.0.302 (HKLM-x32\...\{E9ACF7F7-DB80-49B4-A1BC-63DB90913E67}_is1) (Version: - OEM)
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Video Mover (HKLM-x32\...\Video Mover_is1) (Version: - )
Video Resource Driver (x32 Version: 2.1 - Libronix Corporation) Hidden
VPRINTOL (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
WildTangent Games App (HP Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.31 - WildTangent)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - OEM (mr8980) Image (05/10/2010 1.0.0.0) (HKLM\...\D9DD2BFD594FBF5476D0C2CAA2322CB7A65EB7CD) (Version: 05/10/2010 1.0.0.0 - OEM)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows Live Sync (HKLM-x32\...\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Media Center Add-in for Flash (HKLM-x32\...\{E2D09AC2-4153-4817-AAEB-24F92A8BCE88}) (Version: 3.1.1.0 - Microsoft Corporation)
WIRELESS (x32 Version: 7.02.0000.0001 - EASTMAN KODAK Company) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points =========================

04-10-2014 18:22:40 STOPzilla Restore Point.
04-10-2014 18:26:18 Windows Backup
04-10-2014 18:33:14 Windows Update
04-10-2014 20:11:10 Cleaner (Spybot - Search & Destroy 2.4, administrator privileges
05-10-2014 04:25:36 Removed Activate Norton Online Backup
05-10-2014 04:34:37 Removed Microsoft Office PowerPoint Viewer 2007 (English)
05-10-2014 05:35:54 Installed SpyHunter
05-10-2014 14:27:07 Removed SpyHunter
05-10-2014 18:45:48 Windows Modules Installer
05-10-2014 21:04:14 Removed Windows Live Sync
05-10-2014 21:09:16 Windows Live Essentials
05-10-2014 21:10:01 WLSetup
06-10-2014 00:00:37 Windows Backup

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2010-03-01 18:30 - 2011-01-14 07:30 - 00000864 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {008FE78D-81C2-4AC3-858D-8F4BC001A9DB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2010-11-15] (Hewlett-Packard Company)
Task: {2E9422C2-9D2C-4C8E-BD97-13E79F8898F2} - System32\Tasks\Arcadesafari => C:\Users\Nancy\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe
Task: {442B6B02-3201-450C-8F15-52BEE25ADA60} - System32\Tasks\CLMLSvc => c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [2009-08-05] (CyberLink)
Task: {486E6041-FBFC-4866-83E4-D29A1A1E8BBF} - System32\Tasks\DVDAgent => c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe [2009-07-23] (CyberLink Corp.)
Task: {5EA75771-8291-4EE6-ACE2-FA9381101C41} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-01] (Google Inc.)
Task: {6B71FAA3-3A9C-4220-B1AF-62F07380C7A5} - System32\Tasks\{CF53108C-8CD9-43C0-9E68-E83BA10A8BCF} => C:\Program Files (x86)\AOL Desktop 9.7h\aol.exe
Task: {6D3E6CB0-4282-432F-915F-4808272BF790} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {724BB2AC-C044-4539-91BB-0213ABA1FCD5} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {72FBF166-F579-4EBE-9E10-9771BE2B82CB} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {7BC2E6D7-4047-4195-BC34-318B52D0D43B} - System32\Tasks\{0F12769E-3D7A-4A4C-AE76-99D4A60601DA} => C:\Program Files (x86)\AOL Desktop 9.7h\aol.exe
Task: {8F025311-854B-4A5C-A186-13697604040E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP SoftPaq Installer => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Tasks.exe [2010-11-15] (Hewlett-Packard Company)
Task: {9CCF77B4-F7D7-4A5A-9CC3-D8260F7FE32C} - System32\Tasks\{C4005CD9-C787-46F7-8F15-0C72A236B33F} => C:\Program Files (x86)\AOL Desktop 9.7g\aol.exe
Task: {AA2B20E5-087A-4031-8436-A8A80DB28B91} - System32\Tasks\HPOSIAPP64 => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe [2009-02-27] ()
Task: {B5B51570-BCC1-4FC1-973B-561259BE597D} - System32\Tasks\Microsoft\Windows\Media Center\Extender\Update media permissions for Mcx1-NANCY-PC => C:\Windows\ehome\McxTask.exe [2009-07-13] (Microsoft Corporation)
Task: {B8A107AB-A9FD-4D62-B8DC-07645DE37E20} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe [2014-08-07] ()
Task: {BD118D22-1A5B-46A2-9767-E40021892710} - System32\Tasks\HPCeeScheduleForNancy => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07] (Hewlett-Packard)
Task: {BD5E9554-E80B-4825-87BE-F8CACDACC5B5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2010-11-15] (Hewlett-Packard Company)
Task: {E27E0D0D-6D7B-481B-A64D-52500B91A503} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-25] (Adobe Systems Incorporated)
Task: {E39F5C07-BC9C-435E-B797-77FC469A3789} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {E624CA9A-EBB1-4815-9ADF-1A0FC00A151A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-01] (Google Inc.)
Task: {FE69F5A8-BAE3-4C62-B48E-877C5F7FDA4D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2008-07-30] (Apple Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Arcadesafari.job => C:\Users\Nancy\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForNancy.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Loaded Modules (whitelisted) =============

2010-12-10 22:09 - 2010-02-17 19:25 - 00181760 ____N () C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
2010-12-10 22:09 - 2010-02-09 16:55 - 00055296 ____N () C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
2009-08-31 14:01 - 2008-09-30 20:59 - 00192512 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe
2009-08-31 13:46 - 2009-02-27 21:13 - 00053248 _____ () C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe
2009-07-08 16:35 - 2009-07-08 16:35 - 00610360 _____ () C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
2012-04-02 16:49 - 2012-04-02 16:49 - 00686208 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\NDSPCShowServer.exe
2009-05-26 03:36 - 2009-05-26 03:36 - 00656896 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
2010-12-11 00:53 - 2010-02-17 19:25 - 00149504 _____ () C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkLocalBackup.dll
2012-04-17 22:24 - 2014-06-20 06:08 - 00192376 _____ () c:\ProgramData\STOPzilla!\VIPRE\libBase64.dll
2012-04-17 22:24 - 2014-06-20 06:08 - 00180088 _____ () c:\ProgramData\STOPzilla!\VIPRE\libMachoUniv.dll
2010-12-10 22:05 - 2010-07-28 18:34 - 00022424 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinServicePS.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 00273528 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\ndsLogStore.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 02721920 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\PCShowServerDll.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 02049152 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\XferManagerDll.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 01945704 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\TSB.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 00051864 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\boost_thread-vc90-mt-1_39.dll
2012-04-02 16:49 - 2012-04-02 16:49 - 01988216 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\DrmSingleton.dll
2012-04-02 16:49 - 2012-04-02 16:49 - 01226872 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\CatalogDll.dll
2012-04-02 16:50 - 2012-04-02 16:50 - 06809720 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\gsttspplugin.dll
2012-04-02 16:51 - 2012-04-02 16:51 - 00688264 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\libgstreamer-0.10.dll
2012-04-02 16:51 - 2012-04-02 16:51 - 01402488 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\libxml2-2.dll
2012-04-02 16:52 - 2012-04-02 16:52 - 00091240 _____ () C:\Users\Nancy\AppData\Local\DIRECTV Player\z.dll
2014-10-04 14:03 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-10-04 14:03 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-10-04 14:03 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2009-08-05 15:45 - 2009-08-05 15:45 - 00931112 ____N () c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
2014-02-04 16:47 - 2014-02-04 16:47 - 23782856 _____ () C:\Users\Nancy\AppData\Local\AOL\AIM\libcef.dll
2014-02-04 14:33 - 2014-02-04 14:33 - 16233864 _____ () C:\Users\Nancy\AppData\Local\AOL\AIM\npswf32.dll
2010-12-10 22:05 - 2010-06-23 19:11 - 00325632 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtXml4.dll
2010-12-10 22:05 - 2010-06-23 19:11 - 01954304 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll
2010-12-10 22:05 - 2010-06-23 19:12 - 07187456 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtGui4.dll
2010-12-10 22:05 - 2010-06-23 19:11 - 00847360 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtNetwork4.dll
2010-12-11 01:47 - 2010-06-23 18:38 - 00119808 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll
2009-08-31 13:46 - 2009-02-19 19:22 - 00028672 _____ () C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\WMINPUT.DLL
2010-12-11 01:47 - 2010-07-28 18:02 - 00658432 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll
2014-09-16 13:17 - 2014-09-16 13:17 - 00048640 _____ () C:\Program Files (x86)\AOL Desktop 9.7\zlib.dll
2014-09-16 13:17 - 2014-09-16 13:17 - 21151232 _____ () C:\Program Files (x86)\AOL Desktop 9.7\libcef.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:A8ADE5D8
AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2
AlternateDataStreams: C:\Users\Nancy\Documents\Fw_BEDTIMESTORY.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

HKU\.DEFAULT\Software\Classes\.exe: exefile => <===== ATTENTION!
HKU\.DEFAULT\Software\Classes\exefile: <===== ATTENTION!
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\Software\Classes\.exe: exefile => <===== ATTENTION!
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\Software\Classes\exefile: <===== ATTENTION!

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk => C:\Windows\pss\Kodak EasyShare software.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PictureMover.lnk => C:\Windows\pss\PictureMover.lnk.CommonStartup
MSCONFIG\startupreg: AddressBookReminderApp => C:\Program Files (x86)\Nova Development\Photo Explosion\4.0\ReminderApp.exe
MSCONFIG\startupreg: Aimersoft Helper Compact.exe => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
MSCONFIG\startupreg: Amazon Cloud Player => "C:\Users\Nancy\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe"
MSCONFIG\startupreg: AppleSyncNotifier => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
MSCONFIG\startupreg: ArcSoft Connection Service => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: NortonOnlineBackupReminder => "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
MSCONFIG\startupreg: Pando Media Booster => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SBRegRebootCleaner => "c:\Program Files (x86)\Common Files\iS3\Anti-Spyware\sbrc.exe"
MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
MSCONFIG\startupreg: Spybot-S&D Cleaning => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

========================= Accounts: ==========================

Administrator (S-1-5-21-4198835622-2076300525-3891148937-500 - Administrator - Disabled)
ASPNET (S-1-5-21-4198835622-2076300525-3891148937-1004 - Limited - Enabled)
Guest (S-1-5-21-4198835622-2076300525-3891148937-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4198835622-2076300525-3891148937-1002 - Limited - Enabled)
Mcx1-NANCY-PC (S-1-5-21-4198835622-2076300525-3891148937-1005 - Limited - Enabled) => C:\Users\Mcx1-NANCY-PC
Nancy (S-1-5-21-4198835622-2076300525-3891148937-1001 - Administrator - Enabled) => C:\Users\Nancy

==================== Faulty Device Manager Devices =============

Name: SBRE
Description: SBRE
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SBRE
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/05/2014 07:11:31 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17280 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 19b8

Start Time: 01cfe0f515b98759

Termination Time: 22

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id:


System errors:
=============
Error: (10/05/2014 07:10:08 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793}


Microsoft Office Sessions:
=========================
Error: (10/05/2014 07:11:31 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.1728019b801cfe0f515b9875922C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE


CodeIntegrity Errors:
===================================
Date: 2010-03-01 23:31:27.298
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 23:22:11.389
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 22:46:48.026
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 22:34:28.641
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 21:56:02.679
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 21:44:06.527
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 21:09:47.319
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 20:41:05.685
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 20:16:34.870
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.

Date: 2010-03-01 19:43:31.152
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Quad CPU Q9300 @ 2.50GHz
Percentage of memory in use: 35%
Total physical RAM: 8191.18 MB
Available physical RAM: 5294.85 MB
Total Pagefile: 16380.54 MB
Available Pagefile: 12926.59 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (HP) (Fixed) (Total:919.33 GB) (Free:778.55 GB) NTFS
Drive d: (FACTORY_IMAGE) (Fixed) (Total:12.08 GB) (Free:2.21 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=919.3 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=12.1 GB) - (Type=07 NTFS)

==================== End Of Log ============================

geraldgrogan
2014-10-06, 03:17
On the AOL module keep/nokeep question:
My tsk was to get AOL up and running which till just before this post was not working at all. Now just for posting this - I noticed it started functioning again.

Now that I see progress with AOL, I asked and I was told that they use AOL mainly for mail pickup, and some web surfing. It does seem to be some kind of gaming PC, however I am not sure that is related to AOL or not. I guess I am saying, I would rather have the bare minimum on here, but AOL seems to be very picky if some modules are not installed. This pass I left the full site of AOL modules installed. Please let me know you suggest I proceed.

ken545
2014-10-06, 03:58
If you want to keep any AOL software thats fine, its not harmful, just some of the garbage bundled with it was not so nice and its about gone

I am looking for where you have FRST64, dont see it on your desktop, it may be hidden in your downloads folder, anyway find it and right click on it and select CUT, then come back to your desktop and right click a blank spot and select PASTE, then you will have FRST64 on your desktop and I need you to place this fixlist to your desktop also or the fix wont work


Open notepad (Start --> All Programs --> Accessories --> Notepad).
Please copy the entire contents of the code box below.
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Save it to the same directory as FRST or FRST64 as fixlist.txt. (it has to be right next to FRST or FRST64) either in a directory you saved FRST or FRST64 or on your desktop if thats where you saved it.
You can use your mouse to drag Fixlist right next to FRST or FRST64, either above or below it but not on top of it.



Start
CloseProcesses:
URLSearchHook: HKLM-x32 - (No Name) - {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - No File
URLSearchHook: HKCU - (No Name) - {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - No File
SearchScopes: HKLM - {C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
SearchScopes: HKCU - {C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF} URL =
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
Toolbar: HKCU - No Name - {90A1B331-C2B4-4933-9F63-BA7B84D60D58} - No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
2014-10-04 14:16 - 2011-01-14 07:30 - 00000864 _____ () C:\Windows\system32\Drivers\etc\hosts.20141004-141646.backup
2014-10-04 14:15 - 2011-01-14 07:30 - 00000864 _____ () C:\Windows\system32\Drivers\etc\hosts.20141004-141549.backup
Task: {2E9422C2-9D2C-4C8E-BD97-13E79F8898F2} - System32\Tasks\Arcadesafari => C:\Users\Nancy\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe
C:\Users\Nancy\AppData\Local\Arcadesafari
Task: C:\Windows\Tasks\Arcadesafari.job => C:\Users\Nancy\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe
HKU\.DEFAULT\Software\Classes\.exe: exefile => <===== ATTENTION!
HKU\.DEFAULT\Software\Classes\exefile: <===== ATTENTION!
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\Software\Classes\.exe: exefile => <===== ATTENTION!
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\Software\Classes\exefile: <===== ATTENTION!
Hosts:
EmptyTemp:
End


NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Then open FRST or FRST64 and click on fix
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

geraldgrogan
2014-10-06, 05:11
You were correct - sorry the requested exe files were in the download subdirectory. This time I copied the to the desktop before running them as requested.
PC did a BSOD just before I was to execute this scan/fix. No big deal, but it was interesting.

Also, this PC only has Safari & EI 11 installed yet there seems to be traces of Chrome & Firefox.
================

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-10-2014
Ran by Nancy at 2014-10-05 21:55:12 Run:1
Running from C:\Users\Nancy\Desktop
Loaded Profile: Nancy (Available profiles: Nancy & Mcx1-NANCY-PC)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CloseProcesses:
URLSearchHook: HKLM-x32 - (No Name) - {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - No File
URLSearchHook: HKCU - (No Name) - {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - No File
SearchScopes: HKLM - {C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
SearchScopes: HKCU - {C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF} URL =
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
Toolbar: HKCU - No Name - {90A1B331-C2B4-4933-9F63-BA7B84D60D58} - No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
2014-10-04 14:16 - 2011-01-14 07:30 - 00000864 _____ () C:\Windows\system32\Drivers\etc\hosts.20141004-141646.backup
2014-10-04 14:15 - 2011-01-14 07:30 - 00000864 _____ () C:\Windows\system32\Drivers\etc\hosts.20141004-141549.backup
Task: {2E9422C2-9D2C-4C8E-BD97-13E79F8898F2} - System32\Tasks\Arcadesafari => C:\Users\Nancy\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe
C:\Users\Nancy\AppData\Local\Arcadesafari
Task: C:\Windows\Tasks\Arcadesafari.job => C:\Users\Nancy\AppData\Local\Arcadesafari\ArcadesafariUpdater.exe
HKU\.DEFAULT\Software\Classes\.exe: exefile => <===== ATTENTION!
HKU\.DEFAULT\Software\Classes\exefile: <===== ATTENTION!
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\Software\Classes\.exe: exefile => <===== ATTENTION!
HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\Software\Classes\exefile: <===== ATTENTION!
Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{90a1b331-c2b4-4933-9f63-ba7b84d60d58} => value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{90a1b331-c2b4-4933-9f63-ba7b84d60d58} => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF}" => Key deleted successfully.
"HKCR\CLSID\{C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF}" => Key deleted successfully.
"HKCR\CLSID\{C7BA9893-AA7B-40EF-A2FF-D0AEE7CB88EF}" => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => value deleted successfully.
"HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}" => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} => value deleted successfully.
"HKCR\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{90A1B331-C2B4-4933-9F63-BA7B84D60D58} => value deleted successfully.
"HKCR\CLSID\{90A1B331-C2B4-4933-9F63-BA7B84D60D58}" => Key not found.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
esgiguard => Service deleted successfully.
C:\Windows\system32\Drivers\etc\hosts.20141004-141646.backup => Moved successfully.
C:\Windows\system32\Drivers\etc\hosts.20141004-141549.backup => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2E9422C2-9D2C-4C8E-BD97-13E79F8898F2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2E9422C2-9D2C-4C8E-BD97-13E79F8898F2}" => Key deleted successfully.
C:\Windows\System32\Tasks\Arcadesafari => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Arcadesafari" => Key deleted successfully.
"C:\Users\Nancy\AppData\Local\Arcadesafari" => File/Directory not found.
C:\Windows\Tasks\Arcadesafari.job => Moved successfully.
"HKU\.DEFAULT\Software\Classes\exefile" => Key deleted successfully.
"HKU\.DEFAULT\Software\Classes\.exe" => Key deleted successfully.
"HKU\.DEFAULT\Software\Classes\exefile" => Key not found.
"HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\Software\Classes\exefile" => Key deleted successfully.
"HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\Software\Classes\.exe" => Key deleted successfully.
"HKU\S-1-5-21-4198835622-2076300525-3891148937-1001\Software\Classes\exefile" => Key not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 544.8 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====

ken545
2014-10-06, 12:13
Good Morning,

How is everything running now ?

FYI ...When you download any programs from the internet and install it, most people don't even look they just keep on clicking on NEXT during the install, but before you click NEXT you have to take the time to read what your doing, a good example is when someone updates there Java, if you keep clicking NEXT you wind up with the ASK Toolbar and search engine, there not really bad but ASK is an inferior toolbar and search engine and its really not something you want to use.


Lets check for leftovers, your doing and excellent job by the way following instructions, Some other people that I have worked with I have to stop and just shake my head . So read the instructions for ESET carefully and uncheck to remove found threats as there are sometimes false positives picked up and we don't want it removing anything that you may need and causing other problems

Depending on your system this may take awhile, I have seen it finish in less than and sometimes more than and hour


ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan (http://eset.com/onlinescan)
Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png button.
For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
Click on http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstallDesktopIcon.png icon on your desktop.

Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png
Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png button.
Accept any security warnings from your browser.
Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png
Make sure that the option "Remove found threats" is Unchecked
Push the Start button.
ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time.
When the scan completes, push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png
Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png, and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply.
Push the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetBack.png button.
Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetFinish.png
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.

geraldgrogan
2014-10-07, 08:08
Yes this PC is working much better now.
scan is completed:
contents of ESETScan.txt

C:\Users\Nancy\Documents\26\PlayFizzSetup.exe Win32/OpenCandy potentially unsafe application deleted - quarantined

geraldgrogan
2014-10-07, 08:10
Oops - just realized I forgot to uncheck to 'remove found threats' - I saw this request and did the exact opposite. At least there was no harm done.

ken545
2014-10-07, 13:13
That was just a set up file and its gone.

Glad things are back to normal for you and things are running ok :)


Double click on AdwCleaner.exe to run the tool again.

Click on the Uninstall button.
Click Yes when asked are you sure you want to uninstall.
Both AdwCleaner.exe, its folder and all logs will be removed.



==========================================================


Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix) and save the file to your Desktop.


Windows XP Double Click DelFix.exe to run the program.
Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR
Place a checkmark next to the following items


Activate UAC
Remove Disinfection Tools
Create registry backup
Reset System Settings


Click the Run button

This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually



==========================================================




How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/index.php?showtopic=57817)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)



Safe Surfn
Ken

geraldgrogan
2014-10-08, 06:28
The steps requested in your last post have been successfully executed.
Thanks again for you very helpful assistance.

geraldgrogan
2014-10-08, 06:32
One last question: This PC is currently setup to use the virus protection software called STOPzilla. It seems to be a full features protection software package.
How does this software title rank as compared to the other competitors?
Is there another, or a list others I should consider replacing it with?

ken545
2014-10-08, 10:35
Stopzilla <---Never been a fan, you can read the reviews here, there is better protection software available
https://www.google.com/search?q=STOPzilla&rlz=1C1CHFX_enUS561US561&oq=STOPzilla&aqs=chrome..69i57j69i59j69i60&sourceid=chrome&es_sm=122&ie=UTF-8



Myself I have Microsoft Security Essentials , its free from Microsoft along with Spybot Search and Destroy and the Pro Version of Malwarebytes
http://www.microsoft.com/en-us/download/details.aspx?id=5201

Remember to uninstall Stopzilla in you install MSE

Hope this helps

Ken :)