2015-01-29, 04:05
hello again and 3rd time lately and afraid it's worse. i d'loaded a music editor and got it. i'm getting a new tab or two each time i click on anything...i thank you all so much.

Previous topic: http://forums.spybot.info/showthread.php?71849-Farbar-Recovery-Scan-Tool-and-aswMBR-results/page2

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by Dad (administrator) on BRIDGES1 on 28-01-2015 19:56:23
Running from C:\Users\Dad\Desktop
Loaded Profiles: Dad (Available profiles: Dad)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files (x86)\Lydynamidae\Lydynamidae.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
() C:\Program Files (x86)\Lydynamidae\LydynamidaeHelper.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\\SeaPort.EXE
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Weather Protector LLC) C:\Program Files (x86)\StormWatch\SWUpdaterSvc.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Catalytix Web Services) C:\Users\Dad\AppData\Local\ArcadeParlor\CatWs\CatWSPrx.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MountPoints2: {474142ab-da60-11e1-b2fb-e840f20c0b8d} - J:\EasySuite.exe
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MountPoints2: {474142ae-da60-11e1-b2fb-e840f20c0b8d} - E:\EasySuite.exe
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MountPoints2: {474142b1-da60-11e1-b2fb-e840f20c0b8d} - E:\EasySuite.exe
Startup: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatch.lnk
ShortcutTarget: StormWatch.lnk -> C:\Program Files (x86)\StormWatch\StormWatch.exe (Weather Protector LLC)
Startup: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatchApp.lnk
ShortcutTarget: StormWatchApp.lnk -> C:\Program Files (x86)\StormWatch\StormWatchApp.exe ()
BootExecute: autocheck autochk * sdnclean64.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [S-1-5-21-2107755742-302254199-1763176924-1001] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-2107755742-302254199-1763176924-1001] => http=;https=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://search.yahoo.com/yhs/web?hspart=w3i&hsimp=yhs-syctransfer&type=W3i_SP,204,0_0,StartPage,20150105,20029,0,103,6479
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {4C4C7AAB-5854-4241-A414-E2F1EF119C4A} URL = http://www.dnsbasic.com/?prt=DNSBASIC111&sp=&keywords={searchTerms}
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2107755742-302254199-1763176924-1001 -> DefaultScope {321D8FDA-F347-4A55-96EF-6AA04630B8A7} URL = https://search.yahoo.com/search?p={searchTerms}&ei=UTF-8&fr=w3i&type=W3i_DS,136,0_0,Search,20150105,20028,0,103,0
SearchScopes: HKU\S-1-5-21-2107755742-302254199-1763176924-1001 -> {321D8FDA-F347-4A55-96EF-6AA04630B8A7} URL = https://search.yahoo.com/search?p={searchTerms}&ei=UTF-8&fr=w3i&type=W3i_DS,136,0_0,Search,20150105,20028,0,103,0
SearchScopes: HKU\S-1-5-21-2107755742-302254199-1763176924-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear
BHO: CinPlus-2.7dV27.01 -> {11111111-1111-1111-1111-110611901165} -> C:\Program Files (x86)\CinPlus-2.7dV27.01\CinPlus-2.7dV27.01-bho64.dll No File
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO: PriceLess -> {d3db9a68-a6a0-4bb3-bb04-d14d1a92fa85} -> C:\Program Files (x86)\PriceLess\ClSBKIrNV3OZih.x64.dll No File
BHO-x32: &Yahoo! Toolbar Helper -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
Winsock: Catalog9 01 C:\Windows\SysWOW64\CatWSPrx.dll [331016] (Catalytix Web Services)
Winsock: Catalog9 02 C:\Windows\SysWOW64\CatWSPrx.dll [331016] (Catalytix Web Services)
Winsock: Catalog9 03 C:\Windows\SysWOW64\CatWSPrx.dll [331016] (Catalytix Web Services)
Winsock: Catalog9 04 C:\Windows\SysWOW64\CatWSPrx.dll [331016] (Catalytix Web Services)
Winsock: Catalog9 15 C:\Windows\SysWOW64\CatWSPrx.dll [331016] (Catalytix Web Services)
Winsock: Catalog9-x64 01 C:\Windows\system32\CatWSPrx64.dll [387408] (Catalytix Web Services)
Winsock: Catalog9-x64 02 C:\Windows\system32\CatWSPrx64.dll [387408] (Catalytix Web Services)
Winsock: Catalog9-x64 03 C:\Windows\system32\CatWSPrx64.dll [387408] (Catalytix Web Services)
Winsock: Catalog9-x64 04 C:\Windows\system32\CatWSPrx64.dll [387408] (Catalytix Web Services)
Winsock: Catalog9-x64 15 C:\Windows\system32\CatWSPrx64.dll [387408] (Catalytix Web Services)
Tcpip\Parameters: [DhcpNameServer]
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FF ProfilePath: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396
FF NewTab: https://us.search.yahoo.com/yhs/web?&hspart=w3i&hsimp=yhs-syctransfer&type=W3i_NT,205,0_0,NewTab,20150105,20031,0,FF35,6479
FF SearchEngineOrder.1: Yahoo
FF SearchEngineOrder.2:
FF SelectedSearchEngine: Yahoo
FF Homepage: https://search.yahoo.com/yhs/web?hspart=w3i&hsimp=yhs-syctransfer&type=W3i_SP,205,0_0,StartPage,20150105,20031,0,103,0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\user.js
FF Extension: Booster Web - C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\Extensions\jid1-U7omKQ6kQfxMaQ@jetpack [2015-01-28]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-26]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-08-01]

CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Dad\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [eefhnbpnnaaokmclnihgajdnlgljajjg] - No Path
CHR HKLM-x32\...\Chrome\Extension: [ggebenakhmhfdkmkemdmllecchcldgec] - No Path

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 AffinegyService; C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe [563104 2011-11-14] (Affinegy, Inc.)
R2 CatWSPrx; C:\Users\Dad\AppData\Local\ArcadeParlor\CatWs\CatWSPrx.exe [1356672 2015-01-28] (Catalytix Web Services)
R2 Lydynamidae; C:\Program Files (x86)\Lydynamidae\Lydynamidae.exe [3959296 2015-01-27] () [File not signed] <==== ATTENTION
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-12] (DEVGURU Co., LTD.)
R2 SWUpdater; C:\Program Files (x86)\StormWatch\SWUpdaterSvc.exe [17584 2014-11-21] (Weather Protector LLC)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /svc [X]
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /medsvc [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [22528 2011-08-02] (Apple Inc.) [File not signed]
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-11] (Microsoft Corporation)
S3 RTL8192su; system32\DRIVERS\RTL8192su.sys [X]
S3 sxuptp; system32\DRIVERS\sxuptp.sys [X]
U3 aswMBR; \??\C:\Users\Dad\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Dad\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-28 19:56 - 2015-01-28 19:56 - 02130432 _____ (Farbar) C:\Users\Dad\Desktop\FRST64.exe
2015-01-28 19:56 - 2015-01-28 19:56 - 00013744 _____ () C:\Users\Dad\Desktop\FRST.txt
2015-01-28 19:54 - 2015-01-28 19:54 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-BRIDGES1-Windows-7-Home-Premium-(64-bit).dat
2015-01-28 19:53 - 2015-01-28 19:53 - 00002242 _____ () C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2015-01-28 19:52 - 2015-01-28 19:52 - 04712336 _____ () C:\Users\Dad\Desktop\tweaking.com_registry_backup_setup.exe
2015-01-28 19:51 - 2015-01-28 19:51 - 00000000 ____D () C:\ProgramData\Winferno
2015-01-28 19:47 - 2015-01-26 02:52 - 00272296 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2015-01-28 19:47 - 2015-01-26 02:52 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2015-01-28 19:47 - 2015-01-26 02:52 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2015-01-28 19:46 - 2015-01-28 19:53 - 00000326 _____ () C:\Windows\Tasks\ApCatSupport.job
2015-01-28 19:46 - 2015-01-28 19:51 - 00003140 _____ () C:\Windows\System32\Tasks\RPCReminder
2015-01-28 19:46 - 2015-01-28 19:51 - 00000458 _____ () C:\Windows\Tasks\RegPowerClean.job
2015-01-28 19:46 - 2015-01-28 19:51 - 00000444 _____ () C:\Windows\Tasks\RPCReminder.job
2015-01-28 19:46 - 2015-01-28 19:46 - 00387408 _____ (Catalytix Web Services) C:\Windows\system32\CatWSPrx64.dll
2015-01-28 19:46 - 2015-01-28 19:46 - 00331016 _____ (Catalytix Web Services) C:\Windows\SysWOW64\CatWSPrx.dll
2015-01-28 19:46 - 2015-01-28 19:46 - 00005176 _____ () C:\Windows\SysWOW64\CatWSPrx.ini
2015-01-28 19:46 - 2015-01-28 19:46 - 00003258 _____ () C:\Windows\System32\Tasks\ApCatSupport
2015-01-28 19:46 - 2015-01-28 19:46 - 00003202 _____ () C:\Windows\System32\Tasks\RegPowerClean
2015-01-28 19:46 - 2015-01-28 19:46 - 00003140 _____ () C:\Windows\System32\Tasks\ArcadeParlor
2015-01-28 19:46 - 2015-01-28 19:46 - 00002880 _____ () C:\Windows\SysWOW64\CatWSPrxOff.ini
2015-01-28 19:46 - 2015-01-28 19:46 - 00002880 _____ () C:\Windows\system32\CatWSPrxOff.ini
2015-01-28 19:46 - 2015-01-28 19:46 - 00001460 _____ () C:\Users\Public\Desktop\Norton Security Scan.LNK
2015-01-28 19:46 - 2015-01-28 19:46 - 00001378 _____ () C:\Users\Public\Desktop\Check PC for Errors.lnk
2015-01-28 19:46 - 2015-01-28 19:46 - 00000264 _____ () C:\Windows\Tasks\ArcadeParlor.job
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\Windows\system32\Drivers\NSSx64
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ArcadeParlor
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\Users\Dad\AppData\Local\Weather_Protector_LLC
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\Users\Dad\AppData\Local\StormWatch
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\Users\Dad\AppData\Local\ArcadeParlor
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\ProgramData\Yahoo! Companion
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winferno
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\Program Files (x86)\Winferno
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\Program Files (x86)\StormWatch
2015-01-28 19:46 - 2015-01-28 19:46 - 00000000 ____D () C:\Program Files (x86)\Norton Security Scan
2015-01-28 19:46 - 2010-10-26 11:07 - 00499785 _____ (Capital Intellect Inc) C:\Windows\SysWOW64\WINUTIL8.DLL
2015-01-28 19:46 - 2010-09-01 15:59 - 00835656 _____ (Capital Intellect Inc) C:\Windows\SysWOW64\WINCTL5.OCX
2015-01-28 19:46 - 2010-01-14 10:31 - 00425984 _____ () C:\Windows\SysWOW64\WinCMR.dll
2015-01-28 19:46 - 2009-06-05 11:04 - 00393216 _____ (Capital Intellect Inc) C:\Windows\SysWOW64\WINLCTL6.DLL
2015-01-28 19:43 - 2015-01-28 19:43 - 00962848 _____ (SaferInstall, LLC) C:\Users\Dad\Desktop\java_setup.exe
2015-01-28 19:19 - 2015-01-28 19:19 - 02930092 _____ (Gisburne Media) C:\Users\Dad\Desktop\kbplayer.exe
2015-01-28 19:19 - 2015-01-28 19:19 - 00000000 ____D () C:\Program Files (x86)\Karaoke Builder Player
2015-01-28 18:44 - 2015-01-28 18:44 - 00000000 ____D () C:\ProgramData\af0e05b2000074da
2015-01-28 18:24 - 2015-01-28 18:24 - 00003074 _____ () C:\Windows\System32\Tasks\RPC
2015-01-28 18:16 - 2015-01-28 19:12 - 00001322 _____ () C:\Windows\Tasks\HQ.job
2015-01-28 18:16 - 2015-01-28 18:16 - 00004344 _____ () C:\Windows\System32\Tasks\HQ
2015-01-28 18:16 - 2015-01-28 18:16 - 00000000 ____D () C:\ProgramData\16969743963293318193
2015-01-28 18:15 - 2015-01-28 19:12 - 00001326 _____ () C:\Windows\Tasks\NEDL.job
2015-01-28 18:15 - 2015-01-28 18:16 - 00000000 __SHD () C:\Program Files (x86)\Lydynamidae
2015-01-28 18:15 - 2015-01-28 18:15 - 00004348 _____ () C:\Windows\System32\Tasks\NEDL
2015-01-28 18:15 - 2015-01-28 18:15 - 00000000 ____D () C:\ProgramData\fpebkpiipncfojhgaddgnofadahpmcjm
2015-01-28 18:15 - 2015-01-28 18:15 - 00000000 ____D () C:\Program Files (x86)\52df7d05-df7b-4abf-8cb0-684d1a20a3e7
2015-01-28 17:54 - 2015-01-28 17:54 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Publish Providers
2015-01-28 17:35 - 2015-01-28 17:54 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Sony
2015-01-28 17:35 - 2015-01-28 17:50 - 00000000 ____D () C:\Users\Dad\AppData\Local\Sony
2015-01-28 17:35 - 2015-01-28 17:35 - 00001129 _____ () C:\Users\Public\Desktop\Sound Forge Pro 10.0.lnk
2015-01-28 17:35 - 2015-01-28 17:35 - 00000000 ____D () C:\ProgramData\Sony
2015-01-28 17:35 - 2015-01-28 17:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-01-28 17:35 - 2015-01-28 17:35 - 00000000 ____D () C:\Program Files (x86)\Sony
2015-01-28 17:34 - 2015-01-28 17:34 - 160079840 _____ (Sony Creative Software Inc.) C:\Users\Dad\Desktop\soundforgepro10-0-507.exe
2015-01-28 10:15 - 2015-01-28 10:15 - 00000000 ____D () C:\ProgramData\NCH Software
2015-01-28 09:34 - 2015-01-28 09:34 - 00389912 _____ (AnalogX, LLC) C:\Users\Dad\Downloads\autotune [1].exe
2015-01-28 09:21 - 2015-01-28 09:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voxengo
2015-01-28 09:21 - 2015-01-28 09:26 - 00000000 ____D () C:\Program Files\Voxengo
2015-01-28 09:21 - 2015-01-28 09:26 - 00000000 ____D () C:\Program Files\Common Files\VST3
2015-01-28 09:21 - 2015-01-28 09:21 - 00000000 ____D () C:\Program Files\Common Files\Steinberg
2015-01-27 18:34 - 2015-01-27 18:34 - 00001976 _____ () C:\Users\Public\Desktop\Samsung Kies 3.lnk
2015-01-26 21:26 - 2015-01-26 21:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-25 14:50 - 2015-01-25 14:50 - 00003106 _____ () C:\Windows\System32\Tasks\{DF80F471-10C4-4247-BCB7-5B67BA005FD2}
2015-01-25 10:12 - 2015-01-25 10:12 - 00002086 _____ () C:\Users\Dad\AppData\Roaming\HQ
2015-01-25 10:12 - 2015-01-25 10:12 - 00001248 _____ () C:\Users\Dad\AppData\Roaming\NEDL
2015-01-24 23:58 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2015-01-15 18:43 - 2014-12-18 21:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-15 18:43 - 2014-12-18 19:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-15 18:43 - 2014-12-11 11:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-15 18:43 - 2014-12-05 22:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-15 18:43 - 2014-12-05 21:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-15 18:43 - 2014-12-05 21:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-15 18:42 - 2014-12-11 23:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-15 18:42 - 2014-12-11 23:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-15 18:42 - 2014-12-11 23:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-15 18:42 - 2014-12-11 23:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-15 18:42 - 2014-12-11 23:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-15 18:42 - 2014-12-11 23:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-15 18:42 - 2014-12-11 23:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-15 18:40 - 2015-01-15 18:40 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\ESET
2015-01-15 18:40 - 2015-01-15 18:40 - 00000000 ____D () C:\Users\Dad\AppData\Local\ESET
2015-01-15 18:32 - 2015-01-15 18:32 - 01661128 _____ (ESET) C:\Users\Dad\Desktop\eset_smart_security_live_installer.exe
2015-01-07 18:00 - 2015-01-07 18:00 - 02347384 _____ (ESET) C:\Users\Dad\Desktop\esetsmartinstaller_enu.exe
2015-01-07 16:10 - 2015-01-07 16:22 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-01-07 12:03 - 2015-01-07 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2015-01-05 12:21 - 2014-12-12 23:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-01-05 12:21 - 2014-12-12 21:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-01-04 15:25 - 2014-10-17 20:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-01-04 15:25 - 2014-10-17 19:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2015-01-04 15:24 - 2014-11-26 19:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-01-04 15:24 - 2014-11-26 19:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-01-04 15:24 - 2014-11-21 21:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-01-04 15:24 - 2014-11-21 21:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-01-04 15:24 - 2014-11-21 21:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-01-04 15:24 - 2014-11-21 20:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-01-04 15:24 - 2014-11-21 20:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-01-04 15:24 - 2014-11-21 20:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-01-04 15:24 - 2014-11-21 20:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-01-04 15:24 - 2014-11-21 20:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-01-04 15:24 - 2014-11-21 20:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-01-04 15:24 - 2014-11-21 20:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-01-04 15:24 - 2014-11-21 20:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-01-04 15:24 - 2014-11-21 20:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-01-04 15:24 - 2014-11-21 20:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-01-04 15:24 - 2014-11-21 20:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-01-04 15:24 - 2014-11-21 20:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-01-04 15:24 - 2014-11-21 20:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-01-04 15:24 - 2014-11-21 20:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-01-04 15:24 - 2014-11-21 20:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-01-04 15:24 - 2014-11-21 20:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-01-04 15:24 - 2014-11-21 20:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-01-04 15:24 - 2014-11-21 20:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-01-04 15:24 - 2014-11-21 20:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-01-04 15:24 - 2014-11-21 20:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-01-04 15:24 - 2014-11-21 20:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-01-04 15:24 - 2014-11-21 20:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-01-04 15:24 - 2014-11-21 20:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-01-04 15:24 - 2014-11-21 20:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-01-04 15:24 - 2014-11-21 19:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-01-04 15:24 - 2014-11-21 19:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-01-04 15:24 - 2014-11-21 19:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-01-04 15:24 - 2014-11-21 19:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-01-04 15:24 - 2014-11-21 19:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-01-04 15:24 - 2014-11-21 19:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-01-04 15:24 - 2014-11-21 19:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-01-04 15:24 - 2014-11-21 19:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-01-04 15:24 - 2014-11-21 19:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-01-04 15:24 - 2014-11-21 19:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-01-04 15:24 - 2014-11-21 19:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-01-04 15:24 - 2014-11-21 19:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-01-04 15:24 - 2014-11-21 19:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-01-04 15:24 - 2014-11-21 19:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-01-04 15:24 - 2014-11-21 19:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-01-04 15:24 - 2014-11-21 19:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-01-04 15:24 - 2014-11-21 19:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-01-04 15:24 - 2014-11-21 19:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-01-04 15:24 - 2014-11-21 19:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-01-04 15:24 - 2014-11-21 19:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-01-04 15:24 - 2014-11-21 19:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-01-04 15:24 - 2014-11-21 19:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-01-04 15:24 - 2014-11-21 19:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-01-04 15:24 - 2014-11-21 18:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-01-04 15:24 - 2014-11-21 18:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-01-04 15:23 - 2014-11-10 21:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-01-04 15:23 - 2014-11-10 20:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-01-04 15:22 - 2014-10-29 20:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2015-01-04 15:22 - 2014-10-29 19:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2015-01-04 15:22 - 2014-10-02 20:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-01-04 15:22 - 2014-10-02 20:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-01-04 15:22 - 2014-10-02 20:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-01-04 15:22 - 2014-10-02 20:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-01-04 15:22 - 2014-10-02 20:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-01-04 15:22 - 2014-10-02 19:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2015-01-04 15:22 - 2014-10-02 19:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2015-01-04 15:22 - 2014-10-02 19:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2015-01-04 15:22 - 2014-10-02 19:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2015-01-04 15:22 - 2014-10-02 19:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2015-01-04 15:19 - 2014-11-07 21:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-01-04 15:19 - 2014-11-07 20:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-01-04 15:12 - 2015-01-04 15:13 - 00000340 _____ () C:\Windows\LkmdfCoInst.log
2015-01-04 11:02 - 2015-01-04 11:02 - 00000000 __SHD () C:\Users\Dad\AppData\Local\EmieBrowserModeList
2015-01-03 16:51 - 2015-01-03 16:51 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\AVG
2015-01-03 16:50 - 2015-01-03 16:53 - 00000000 ____D () C:\ProgramData\AVG
2015-01-03 16:50 - 2015-01-03 16:50 - 00000000 ____D () C:\Users\Dad\AppData\Local\Avg
2015-01-03 16:38 - 2015-01-04 15:07 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Avg_Update_1014av
2015-01-03 16:38 - 2015-01-04 15:07 - 00000000 ____D () C:\ProgramData\Avg_Update_1014av
2015-01-03 16:35 - 2015-01-03 16:35 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\TuneUp Software
2015-01-03 16:34 - 2015-01-04 14:51 - 00000000 ____D () C:\ProgramData\AVG2015
2015-01-03 16:33 - 2015-01-03 16:51 - 00000000 ____D () C:\Program Files (x86)\AVG
2015-01-03 16:31 - 2015-01-04 15:07 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-03 16:31 - 2015-01-03 22:01 - 00000000 ____D () C:\Users\Dad\AppData\Local\Avg2015
2015-01-03 16:31 - 2015-01-03 16:31 - 00000000 ____D () C:\Users\Dad\AppData\Local\MFAData
2014-12-31 17:30 - 2014-11-10 19:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-28 19:56 - 2014-10-14 12:26 - 00000000 ____D () C:\FRST
2015-01-28 19:46 - 2014-10-16 15:37 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-28 19:46 - 2012-07-11 11:56 - 00000000 ____D () C:\Program Files (x86)\Yahoo!
2015-01-28 19:46 - 2012-04-06 02:18 - 00000000 ____D () C:\Users\Dad\AppData\Local\CrashDumps
2015-01-28 19:46 - 2012-03-30 23:28 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Yahoo!
2015-01-28 19:46 - 2012-03-29 14:47 - 00000000 ____D () C:\ProgramData\Yahoo!
2015-01-28 19:46 - 2011-11-08 02:41 - 00000000 ____D () C:\ProgramData\Norton
2015-01-28 19:43 - 2014-08-22 20:33 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-28 19:43 - 2013-01-04 20:52 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-28 19:20 - 2009-07-13 22:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-28 19:20 - 2009-07-13 22:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-28 19:19 - 2014-12-09 16:32 - 00001112 _____ () C:\Users\Public\Desktop\Karaoke Builder Player.lnk
2015-01-28 19:18 - 2009-07-13 23:13 - 00783464 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-28 19:16 - 2014-01-07 20:18 - 01238239 _____ () C:\Windows\WindowsUpdate.log
2015-01-28 19:12 - 2014-10-16 10:25 - 00127002 _____ () C:\Windows\PFRO.log
2015-01-28 19:12 - 2014-09-04 19:35 - 00007730 _____ () C:\Windows\setupact.log
2015-01-28 19:12 - 2014-02-11 16:00 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-28 19:12 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-28 19:11 - 2011-11-08 02:40 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-28 19:02 - 2014-10-16 10:35 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-28 18:47 - 2014-05-23 02:40 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2015-01-28 18:47 - 2009-07-13 22:45 - 00271752 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-28 18:46 - 2014-02-03 18:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-28 18:43 - 2014-08-22 20:33 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-28 17:56 - 2014-12-02 19:16 - 00000000 ____D () C:\Users\Dad\Desktop\My Recordings
2015-01-28 17:40 - 2014-11-09 11:54 - 00000000 ____D () C:\Users\Dad\AppData\Local\Adobe
2015-01-28 17:40 - 2014-08-22 20:33 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-28 17:40 - 2014-08-22 20:33 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-28 14:51 - 2012-03-29 14:02 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2015-01-28 09:28 - 2013-12-22 18:31 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Samsung
2015-01-28 09:28 - 2013-12-04 21:28 - 00000000 ____D () C:\Program Files (x86)\Samsung
2015-01-27 14:28 - 2014-02-08 19:02 - 00000000 ____D () C:\Users\Dad\Desktop\Samsung pics
2015-01-27 08:06 - 2014-12-09 11:08 - 00000000 ____D () C:\Users\Dad\Desktop\CDG.zip files
2015-01-26 14:06 - 2014-12-04 13:31 - 00000000 ____D () C:\Users\Dad\Documents\Audio Recorder for Free
2015-01-26 07:13 - 2014-02-09 16:47 - 03402752 ___SH () C:\Users\Dad\Desktop\Thumbs.db
2015-01-26 05:26 - 2014-09-14 12:12 - 00000000 ____D () C:\Users\Dad\Desktop\CDG
2015-01-26 02:54 - 2013-10-17 16:34 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-26 02:52 - 2014-10-16 15:38 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-26 01:04 - 2014-08-04 23:52 - 02162696 _____ () C:\console.log
2015-01-25 14:57 - 2014-01-14 12:38 - 00059600 _____ () C:\Users\Dad\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-25 08:49 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-24 22:59 - 2014-11-03 14:51 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dwyco CDC-X
2015-01-17 09:26 - 2014-01-04 07:24 - 00000398 _____ () C:\Windows\Tasks\Wise Turbo Checker.job
2015-01-16 03:03 - 2013-08-16 02:00 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-16 03:00 - 2012-03-30 20:51 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-15 18:34 - 2012-07-18 19:56 - 00001945 _____ () C:\Windows\epplauncher.mif
2015-01-08 09:55 - 2010-11-20 21:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-07 17:35 - 2014-10-16 10:35 - 00096472 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-07 17:28 - 2014-10-15 08:47 - 00000000 ____D () C:\AdwCleaner
2015-01-05 18:25 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\rescache
2015-01-05 15:49 - 2013-08-07 09:19 - 00000000 ___RD () C:\Users\Dad\Dropbox
2015-01-05 15:49 - 2013-07-07 09:31 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Dropbox
2015-01-04 15:35 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-01-04 15:12 - 2012-03-29 12:09 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2015-01-04 15:11 - 2012-03-29 11:32 - 00000000 ____D () C:\Users\Dad
2015-01-04 15:08 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2015-01-04 15:07 - 2014-12-09 16:32 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Karaoke Builder
2015-01-04 15:07 - 2014-10-14 12:20 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2015-01-04 15:07 - 2014-10-14 12:20 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2015-01-04 15:07 - 2014-08-22 12:20 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-01-04 15:07 - 2014-07-04 13:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Peace Art App
2015-01-04 15:07 - 2014-05-23 02:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec
2015-01-04 15:07 - 2014-03-28 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-04 15:07 - 2014-01-10 23:00 - 00000000 ____D () C:\Program Files (x86)\Paltalk Messenger
2015-01-04 15:07 - 2013-04-29 03:49 - 00000000 ____D () C:\Program Files\Bonjour
2015-01-04 15:07 - 2013-04-29 03:49 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2015-01-04 15:07 - 2012-08-19 16:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
2015-01-04 15:07 - 2012-04-05 11:30 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2015-01-04 15:07 - 2012-02-06 05:15 - 00000000 ____D () C:\ProgramData\Temp
2015-01-04 15:07 - 2011-11-08 02:31 - 00000000 ___HD () C:\ProgramData\{37272A44-A110-4EB7-A5EF-88B2A05A08C4}
2015-01-04 15:07 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\servicing
2015-01-04 15:07 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-01-04 15:06 - 2014-08-22 12:21 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2015-01-04 15:06 - 2013-03-16 02:01 - 00000000 __SHD () C:\Windows\SysWOW64\%APPDATA%
2015-01-04 15:06 - 2012-04-06 02:18 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2015-01-04 15:06 - 2011-11-08 02:41 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\winrm
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\WCN
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\slmgr
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\winrm
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\WCN
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\slmgr
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2015-01-04 15:06 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\SysWOW64\WindowsPowerShell
2015-01-04 15:06 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\system32\WindowsPowerShell
2015-01-04 15:06 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Web
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Vss
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\spp
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Speech
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\NetworkList
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Msdtc
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\InstallShield
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\IME
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\com
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\sysprep
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\spp
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\spool
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Speech
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\SMI
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\oobe
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\NetworkList
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\registration
2015-01-04 15:05 - 2014-10-19 15:30 - 00000000 ____D () C:\Users\Dad\Documents\Dwyco
2015-01-04 15:05 - 2014-10-15 08:54 - 00000000 ____D () C:\Windows\ERUNT
2015-01-04 15:05 - 2014-05-02 02:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-01-04 15:05 - 2014-04-18 18:06 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information
2015-01-04 15:05 - 2013-03-16 02:01 - 00000000 __SHD () C:\Windows\system32\%APPDATA%
2015-01-04 15:05 - 2012-02-06 04:53 - 00000000 ____D () C:\Windows\NAPP_Dism_Log
2015-01-04 15:05 - 2011-11-08 02:41 - 00000000 ____D () C:\Windows\system32\Macromed
2015-01-04 15:05 - 2011-11-08 02:33 - 00000000 ____D () C:\Windows\es
2015-01-04 15:05 - 2011-11-08 02:31 - 00000000 ____D () C:\Windows\oem
2015-01-04 15:05 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\Performance
2015-01-04 15:05 - 2009-07-13 22:45 - 00000000 ____D () C:\Windows\Setup
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 __RSD () C:\Windows\Media
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\MUI
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Msdtc
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\migwiz
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\IME
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\com
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Speech
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\security
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\schemas
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Resources
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\PLA
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\IME
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Help
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Globalization
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Branding
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\AppCompat
2015-01-04 15:04 - 2014-12-02 18:54 - 00000000 ____D () C:\Program Files (x86)\PreSonus
2015-01-04 15:04 - 2014-10-16 10:35 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-04 15:04 - 2014-08-01 23:23 - 00000000 ____D () C:\Program Files\Logitech
2015-01-04 15:04 - 2014-04-18 20:20 - 00000000 ____D () C:\Program Files (x86)\Canon
2015-01-04 15:04 - 2014-04-18 18:05 - 00000000 ___HD () C:\Program Files\CanonBJ
2015-01-04 15:04 - 2013-09-18 01:41 - 00000000 ____D () C:\Program Files\behringer
2015-01-04 15:04 - 2013-08-07 23:30 - 00000000 ____D () C:\Program Files (x86)\AVS4YOU
2015-01-04 15:04 - 2013-05-13 16:12 - 00000000 ____D () C:\Program Files (x86)\EPUBSOFT
2015-01-04 15:04 - 2013-04-29 09:46 - 00000000 ____D () C:\Program Files\iTunes
2015-01-04 15:04 - 2013-04-29 09:46 - 00000000 ____D () C:\Program Files\iPod
2015-01-04 15:04 - 2013-04-29 09:46 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-01-04 15:04 - 2013-03-16 02:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-01-04 15:04 - 2013-03-16 02:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-01-04 15:04 - 2013-01-04 20:52 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-04 15:04 - 2012-10-20 15:41 - 00000000 ____D () C:\Program Files (x86)\Belkin
2015-01-04 15:04 - 2012-09-17 10:56 - 00000000 ____D () C:\Program Files (x86)\Outsim
2015-01-04 15:04 - 2012-09-17 10:50 - 00000000 ____D () C:\Program Files (x86)\Image-Line
2015-01-04 15:04 - 2012-04-15 16:50 - 00000000 ____D () C:\Program Files\Defraggler
2015-01-04 15:04 - 2012-04-15 16:49 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-04 15:04 - 2012-04-06 10:37 - 00000000 ____D () C:\Program Files (x86)\Freemake
2015-01-04 15:04 - 2012-04-06 02:06 - 00000000 ____D () C:\Program Files (x86)\Microsoft CAPICOM
2015-01-04 15:04 - 2012-04-05 11:35 - 00000000 __RHD () C:\MSOCache
2015-01-04 15:04 - 2012-04-05 11:30 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-01-04 15:04 - 2012-03-29 17:20 - 00000000 ____D () C:\Program Files (x86)\Logitech
2015-01-04 15:04 - 2012-03-29 15:08 - 00000000 ____D () C:\Program Files (x86)\The Anubis Group
2015-01-04 15:04 - 2012-03-29 12:09 - 00000000 ____D () C:\Program Files\Common Files\Logishrd
2015-01-04 15:04 - 2012-02-06 05:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2015-01-04 15:04 - 2012-02-06 05:15 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2015-01-04 15:04 - 2012-02-06 05:12 - 00000000 ____D () C:\Program Files\Realtek
2015-01-04 15:04 - 2012-02-06 05:10 - 00000000 ____D () C:\Program Files (x86)\Etron Technology
2015-01-04 15:04 - 2012-02-06 05:07 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-01-04 15:04 - 2012-02-06 04:58 - 00000000 ____D () C:\Program Files\Common Files\Intel
2015-01-04 15:04 - 2011-11-08 02:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-01-04 15:04 - 2011-11-08 02:32 - 00000000 ____D () C:\Program Files\Windows Live
2015-01-04 15:04 - 2011-11-08 02:32 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-01-04 15:04 - 2011-11-08 02:31 - 00000000 ____D () C:\Program Files\Gateway
2015-01-04 15:04 - 2011-11-08 02:31 - 00000000 ____D () C:\Program Files (x86)\Gateway
2015-01-04 15:04 - 2011-11-08 02:24 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-04 15:04 - 2011-11-08 02:24 - 00000000 ____D () C:\Program Files (x86)\Intel
2015-01-04 15:04 - 2011-11-08 02:15 - 00000000 ___HD () C:\OEM
2015-01-04 15:04 - 2011-08-17 21:01 - 00000000 ___HD () C:\dad
2015-01-04 15:04 - 2011-08-17 20:39 - 00000000 ____D () C:\C_
2015-01-04 15:04 - 2010-11-21 01:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Defender
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Reference Assemblies
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\MSBuild
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Microsoft Games
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\DVD Maker
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Windows NT
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Common Files\SpeechEngines
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files (x86)\Windows NT
2015-01-03 17:13 - 2012-05-05 10:55 - 00000000 ____D () C:\Users\Dad\.thumbnails
2015-01-01 01:10 - 2014-02-13 09:25 - 00001019 _____ () C:\Users\Dad\Desktop\Dropbox.lnk
2015-01-01 01:10 - 2013-07-07 09:32 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-12-31 16:51 - 2014-10-16 10:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware

==================== Files in the root of some directories =======

2015-01-25 10:12 - 2015-01-25 10:12 - 0002086 _____ () C:\Users\Dad\AppData\Roaming\HQ
2015-01-25 10:12 - 2015-01-25 10:12 - 0001248 _____ () C:\Users\Dad\AppData\Roaming\NEDL
2013-08-07 06:12 - 2014-11-16 00:53 - 0001181 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.1.txt
2013-08-07 06:12 - 2014-03-30 11:59 - 0000919 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.2.txt
2013-08-07 06:12 - 2014-03-29 18:54 - 0001181 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.3.txt
2013-08-07 06:12 - 2013-08-07 06:34 - 0000919 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.4.txt
2013-08-07 06:12 - 2013-08-07 06:12 - 0001181 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.5.txt
2013-08-07 06:12 - 2014-12-02 18:47 - 0000919 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.txt
2013-08-07 06:12 - 2014-12-02 18:47 - 0000000 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt
2012-05-12 15:58 - 2012-05-12 15:58 - 0024597 _____ () C:\Users\Dad\AppData\Roaming\UserTile.png
2014-09-01 02:18 - 2014-09-01 02:18 - 0001248 _____ () C:\Users\Dad\AppData\Roaming\UZNYUL
2014-02-13 10:52 - 2014-10-16 10:22 - 0000109 _____ () C:\Users\Dad\AppData\Roaming\WB.CFG
2014-09-01 02:18 - 2014-09-01 02:18 - 0002086 _____ () C:\Users\Dad\AppData\Roaming\WTPQZFD
2012-04-14 21:46 - 2014-01-03 22:33 - 0119296 _____ () C:\Users\Dad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-02 22:37 - 2014-12-02 22:37 - 0000010 _____ () C:\Users\Dad\AppData\Local\DSI.DAT
2012-08-18 05:51 - 2012-08-18 05:51 - 0004028 _____ () C:\Users\Dad\AppData\Local\HWVendorDetection.log
2013-01-10 08:07 - 2013-01-10 08:07 - 0000866 _____ () C:\Users\Dad\AppData\Local\recently-used.xbel
2012-07-16 06:22 - 2014-01-11 09:02 - 0007629 _____ () C:\Users\Dad\AppData\Local\Resmon.ResmonCfg
2012-03-29 12:09 - 2012-03-29 12:09 - 0017408 _____ () C:\Users\Dad\AppData\Local\WebpageIcons.db
2013-04-11 00:27 - 2013-04-11 00:27 - 0000000 _____ () C:\ProgramData\2a3b3a3028372a59_c
2012-11-19 02:10 - 2012-11-19 02:10 - 0000105 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

Some content of TEMP:

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-10-16 09:14

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-01-2015
Ran by Dad at 2015-01-28 19:56:43
Running from C:\Users\Dad\Desktop
Boot Mode: Normal

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Spybot - Search and Destroy (Disabled - Out of date) {20A26C15-1AF0-7CA3-9380-FAB824A7EE0D}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: - Adobe Systems Incorporated)
Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version: - )
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated)
Adobe PDF ePub DRM Removal 4.7.1 (HKLM-x32\...\{C9DD56CA-BAE9-452A-AFE9-834C7770D1A3}) (Version: 4.7.1 - EPUBSOFT)
Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\...\{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}) (Version: 2.3.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: - Apple Inc.)
ArcadeParlor (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\{B74443DB-5A88-4583-860A-F0D06EF399E3}) (Version: - ArcadeParlor)
Audio Recorder for Free v12.9.8 (HKLM-x32\...\Audio Recorder for Free_is1) (Version: - Copyright(C) 2006-2012 AudioToolMedia Software.)
BEHRINGER UFX 1394 Drivers v6.11.0.0 (HKLM-x32\...\BEHRINGER UFX 1394 Drivers v6.11.0.0) (Version: - BEHRINGER)
Belkin Setup and Router Monitor (HKLM-x32\...\Belkin Setup and Router Monitor_is1) (Version: - )
Best Buy pc app (Version: - Best Buy) Hidden
Best Buy pc app (x32 Version: - Best Buy) Hidden
Bing Bar (HKLM-x32\...\{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}) (Version: - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: - Apple Inc.)
CameraHelperMsi (x32 Version: 13.50.854.0 - Logitech) Hidden
Canon MP Navigator 3.0 (HKLM-x32\...\MP Navigator 3.0) (Version: - )
Canon MP160 (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 4.16 - Piriform)
CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.2531.52 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Defraggler (HKLM\...\Defraggler) (Version: 2.15 - Piriform)
Dropbox (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
Dwyco CDC-X version 2.10 (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Dwyco CDC-X_is1) (Version: 2.10 - Dwyco, Inc.)
Easy Thumbnails (Remove only) (HKLM-x32\...\Easy Thumbnails_is1) (Version: 3.0 - Fookes Software)
eReg (x32 Version: - Logitech, Inc.) Hidden
Etron USB3.0 Host Controller (x32 Version: 0.103 - Etron Technology) Hidden
Freemake Video Converter version 3.1.0 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 3.1.0 - Ellora Assets Corporation)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gateway Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Gateway Incorporated)
Gateway Registration (HKLM-x32\...\Gateway Registration) (Version: 1.04.3503 - Gateway Incorporated)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.93 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: - Google)
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: - Google)
Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3505 - Gateway Incorporated)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Gateway Incorporated)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: - Intel Corporation)
iTunes (HKLM\...\{0225AD21-F3E2-4916-BFF3-65D3F9052582}) (Version: - Apple Inc.)
Java 7 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217065FF}) (Version: 7.0.650 - Oracle)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Karaoke Builder Player 3.0 (HKLM-x32\...\Karaoke Builder Player 3.0) (Version: - )
Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.0 - Logitech Inc.)
LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden
Malwarebytes Anti-Malware version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5131.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 35.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyFreeCodec (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MyFreeCodec) (Version: - )
Noise Reduction Plug-In 2.0 (HKLM-x32\...\{B94515E1-2DD6-11E2-849E-F04DA23A5C58}) (Version: 2.0.515 - Sony)
Norton Security Scan (HKLM-x32\...\NSS) (Version: - Symantec Corporation)
Paltalk Ad Remover 4.0 (HKLM-x32\...\Paltalk Ad Remover_is1) (Version: - The Anubis Group (T.A.G.))
Paltalk Messenger 11.4 (HKLM-x32\...\Paltalk Messenger) (Version: 11.4.564.16191 - AVM Software Inc.)
Peace Art App 2 version 1.1 (HKLM-x32\...\{36756AF9-18F1-467A-AE37-62BC72A0029A}_is1) (Version: 1.1 - Kelly Anne)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: - SAMSUNG Electronics Co., Ltd.)
Sound Forge Pro 10.0 (HKLM-x32\...\{8EF5E2B0-2DD1-11E2-89A5-F04DA23A5C58}) (Version: 10.0.507 - Sony)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
StormWatch (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\StormWatch) (Version: - StormWatch) <==== ATTENTION!
Switch Sound File Converter (HKLM-x32\...\Switch) (Version: - NCH Software)
swMSM (x32 Version: - Adobe Systems, Inc) Hidden
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 2.0.0 - Tweaking.com)
VisioForge Video Capture SDK Delphi Redist (x32 Version: - VisioForge) Hidden
Welcome Center (HKLM-x32\...\Gateway Welcome Center) (Version: 1.02.3504 - Gateway Incorporated)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Winferno Registry Power Cleaner (HKLM-x32\...\RegPowerClean_is1) (Version: 2012 - Winferno.com)
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.)
Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - Yahoo! Inc.)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points =========================

16-01-2015 03:00:40 Windows Update
16-01-2015 03:10:37 Windows Backup
24-01-2015 20:34:51 Windows Backup
24-01-2015 23:58:39 Installed DirectX
25-01-2015 19:00:17 Windows Backup
27-01-2015 10:01:28 Windows Update
27-01-2015 18:34:21 Installed Samsung Kies3
28-01-2015 09:27:57 Removed Samsung Kies

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 20:34 - 2015-01-07 16:04 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {03A17A14-F01E-40FD-9432-A4CEADEDBBD6} - System32\Tasks\RPC => C:\Program Files (x86)\Regprocleaner\Regprocleaner.exe
Task: {0642325B-D49D-4797-BC3D-2F56533546BB} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {09EEC63B-21B8-4656-86A9-CCDD9C10A77F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-04] (Google Inc.)
Task: {2019B661-1B14-49C2-A758-D24F0F404B7E} - System32\Tasks\ArcadeParlor => C:\Users\Dad\AppData\Local\ArcadeParlor\versioncheck.exe [2015-01-28] ()
Task: {346B439C-CE11-4CE0-B14C-D2FD4E18F124} - System32\Tasks\{1DD8B5E2-C122-4D1F-9758-9B0F5D4479E4} => pcalua.exe -a "C:\Users\Dad\Desktop\My Documents\mp160win64111ea23.exe" -d "C:\Users\Dad\Desktop\My Documents"
Task: {3EB83F69-6812-41E2-A848-7F3A8D689E89} - System32\Tasks\Wise Turbo Checker => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe
Task: {490D819C-47D5-456C-A5EB-EEFBD6B58C82} - System32\Tasks\{62ACF029-05DB-43E9-B5E0-E093E965ED01} => C:\Program Files (x86)\Paltalk Messenger\paltalk.exe [2014-06-24] (AVM Software Inc.)
Task: {4D60D52A-0F7B-4776-9A5E-7366825088C9} - System32\Tasks\HQ => C:\Users\Dad\AppData\Roaming\HQ.exe <==== ATTENTION
Task: {57F10B8A-E6DC-41AF-836F-3D3323A974EC} - System32\Tasks\{8438242B-619B-42CD-9AD1-2D389FF75225} => C:\Program Files (x86)\Paltalk Messenger\paltalk.exe [2014-06-24] (AVM Software Inc.)
Task: {65FBC813-8ECD-4300-99D3-4822AFCDAFE9} - System32\Tasks\{F2D720B6-011A-46ED-9209-2320052E5916} => pcalua.exe -a C:\PROGRA~2\Yahoo!\MESSEN~1\UNWISE.EXE -c /U C:\PROGRA~2\Yahoo!\MESSEN~1\INSTALL.LOG
Task: {8C25C726-0EDD-419C-ABAE-AB81DD4A8954} - System32\Tasks\{DF80F471-10C4-4247-BCB7-5B67BA005FD2} => pcalua.exe -a C:\Users\Dad\Desktop\ts_webcam.exe -d C:\Users\Dad\Desktop
Task: {8D943107-6A50-440B-8E05-7B77AD0A1BEB} - System32\Tasks\{D9E1C870-B7E8-4995-8A98-D579504F6B41} => C:\Program Files (x86)\Paltalk Messenger\paltalk.exe [2014-06-24] (AVM Software Inc.)
Task: {A39A575A-244E-4472-9FE4-7C43C694ECDC} - System32\Tasks\RPCReminder => C:\Program Files (x86)\Winferno\RegistryPowerCleaner\RPCReminder.exe [2012-02-08] (Winferno Software)
Task: {AE3C4923-DF05-46BF-9F7D-71972FD7EF73} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-28] (Adobe Systems Incorporated)
Task: {B0C3D0A2-E90E-41D9-A2AA-D31480DA3178} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-04] (Google Inc.)
Task: {B8D04CC6-6343-45C9-B405-F55D65E7D99C} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {CB7581B8-8545-4786-B62C-1567DBFA5960} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
Task: {CE4612D6-865E-46E6-A8C8-E78BF08ACC3D} - System32\Tasks\NBAgent => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
Task: {D1BA1D14-BA0E-4E6C-B8BD-EE9D098887EF} - System32\Tasks\NEDL => C:\Users\Dad\AppData\Roaming\NEDL.exe <==== ATTENTION
Task: {D67B1D7D-E9C3-4AE6-BC10-908166FF1A41} - System32\Tasks\ApCatSupport => Rundll32.exe C:\Users\Dad\AppData\Local\ARCADE~1\CATHEL~1.DLL,Start
Task: {E6392F7E-8094-4810-A3A2-612265F0F48F} - System32\Tasks\{F126331D-C6F2-47BE-94F5-C17820994183} => pcalua.exe -a "C:\Program Files (x86)\NCH Software\Recordpad\uninst.exe"
Task: {ED36A8FB-B1CF-421E-8C67-F352A7A69286} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {F4FE48D0-691E-474D-9BF8-E1EE2DC18853} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {F5B9905B-C517-4DB0-978F-072B2DCCC0F5} - System32\Tasks\RegPowerClean => C:\Program Files (x86)\Winferno\RegistryPowerCleaner\RegPowerClean.exe [2012-02-08] (Capital Intellect Inc)
Task: {FF5AE516-004E-406B-8236-DF11EE525F5D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-07-23] (Piriform Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\ApCatSupport.job => [뀪‰ÊJĹÌBžèF<
s€ €!ß5!C:\Windows\system32\rundll32.exe7C:\Users\Dad\AppData\Local\ARCADE~1\CATHEL~1.DLL,StartDad0Ý¥
Task: C:\Windows\Tasks\ArcadeParlor.job => C:\Users\Dad\AppData\Local\ArcadeParlor\versioncheck.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HQ.job => C:\Users\Dad\AppData\Roaming\HQ.exe <==== ATTENTION
Task: C:\Windows\Tasks\NEDL.job => C:\Users\Dad\AppData\Roaming\NEDL.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegPowerClean.job => C:\Program Files (x86)\Winferno\RegistryPowerCleaner\RegPowerClean.exe
Task: C:\Windows\Tasks\RPCReminder.job => C:\Program Files (x86)\Winferno\RegistryPowerCleaner\RPCReminder.exe
Task: C:\Windows\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe

==================== Loaded Modules (whitelisted) =============

2015-01-28 18:16 - 2015-01-27 13:57 - 03959296 ___SH () C:\Program Files (x86)\Lydynamidae\Lydynamidae.exe
2015-01-28 18:16 - 2015-01-28 18:16 - 00043520 ____R () C:\Program Files (x86)\Lydynamidae\LydynamidaeHelper.exe
2015-01-28 19:46 - 2015-01-28 19:46 - 00211744 _____ () C:\Users\Dad\AppData\Local\ArcadeParlor\CatHelper.dll
2015-01-26 21:26 - 2015-01-26 21:26 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2015-01-25 20:43 - 2015-01-28 17:40 - 16844976 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CatWSPrx => ""="service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Behringer UFX 1394 Control Panel.lnk => C:\Windows\pss\Behringer UFX 1394 Control Panel.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Dad^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Dad^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk => C:\Windows\pss\Logitech . Product Registration.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Dad^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PalTalk.lnk => C:\Windows\pss\PalTalk.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: ConduitFloatingPlugin_lcnnhcneegeeojhgpfijnlnocjdmlaon => "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Dad\AppData\Roaming\ValueApps\CH\TBVerifier.dll",RunConduitFloatingPlugin lcnnhcneegeeojhgpfijnlnocjdmlaon
MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
MSCONFIG\startupreg: Hotkey Utility => C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: InstaLAN => "C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" startup
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: Messenger (Yahoo!) => "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
MSCONFIG\startupreg: Obrona Block Ads => "C:\Users\Dad\AppData\Local\Obrona Block Ads\ObronaBlockAds.exe" --hidden
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
MSCONFIG\startupreg: smoother => C:\Users\Dad\AppData\Roaming\Booster-Web\Booster-Web-Installer.exe
MSCONFIG\startupreg: SoftonicAssistant => "C:\Users\Dad\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe"
MSCONFIG\startupreg: SpybotSD TeaTimer => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-2107755742-302254199-1763176924-500 - Administrator - Disabled)
Dad (S-1-5-21-2107755742-302254199-1763176924-1001 - Administrator - Enabled) => C:\Users\Dad
Guest (S-1-5-21-2107755742-302254199-1763176924-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2107755742-302254199-1763176924-1003 - Limited - Enabled)

==================== Faulty Device Manager Devices =============

Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Microsoft Teredo Tunneling Adapter #2
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

==================== Event log errors: =========================

Application errors:
Error: (01/28/2015 07:45:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version:, time stamp: 0x54c1f9f3
Faulting module name: mozalloc.dll, version:, time stamp: 0x54c1f224
Exception code: 0x80000003
Fault offset: 0x00001425
Faulting process id: 0x324
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3

Error: (01/28/2015 07:35:39 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Information only.
Error: The operation timed out
ErrorCode: 14007(0x36b7).

System errors:

Microsoft Office Sessions:
Error: (01/28/2015 07:45:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe35.0.1.550054c1f9f3mozalloc.dll35.0.1.550054c1f224800000030000142532401d03b639f06d062C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll921f3ba2-a758-11e4-abca-02060d5d6465

Error: (01/28/2015 07:35:39 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Error: The operation timed out
ErrorCode: 14007(0x36b7).

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 34%
Total physical RAM: 6048.28 MB
Available physical RAM: 3959.12 MB
Total Pagefile: 12094.74 MB
Available Pagefile: 9956.81 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (Gateway) (Fixed) (Total:918.41 GB) (Free:808.23 GB) NTFS
Drive d: (MAN_OF_STEEL) (CDROM) (Total:7.57 GB) (Free:0 GB) UDF
Drive k: (FreeAgent GoFlex Drive) (Fixed) (Total:465.76 GB) (Free:0.02 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 5D81C09C)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=918.4 GB) - (Type=07 NTFS)

Disk: 1 (Size: 465.8 GB) (Disk ID: 4E80EAC4)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End Of Log ============================

aswMBR version Copyright(c) 2014 AVAST Software
Run date: 2015-01-28 19:57:15
19:57:15.853 OS Version: Windows x64 6.1.7601 Service Pack 1
19:57:15.853 Number of processors: 4 586 0x2A07
19:57:15.854 ComputerName: BRIDGES1 UserName: Dad
19:57:18.464 Initialize success
19:57:18.466 VM: initialized successfully
19:57:18.466 VM: Intel CPU supported
19:57:20.888 VM: supported disk I/O iaStor.sys
19:58:58.641 The log file has been saved successfully to "C:\Users\Dad\Desktop\aswMBR.txt"

2015-01-29, 23:12
Your infected!

Do you know what this is? C:\Program Files (x86)\Lydynamidae <--
A high possibility it's malicious.

We're going to have to uninstall/delete Google Chrome, then redownload.

Instructions on how to backup your Favourites/Bookmarks and other data can be found below.
http://i.imgur.com/U5NwUGc.png Backup Chrome Bookmarks (http://www.wikihow.com/Export-Bookmarks-from-Chrome)

Please download and install Revo Uninstaller Free (http://www.revouninstaller.com/)

Double click Revo Uninstaller to run it.
From the list of programs double click on Google Chrome
When prompted if you want to uninstall click Yes.
Be sure the Moderate option is selected then click Next.
The program will run, If prompted again click Yes
when the built-in uninstaller is finished click on Next.
Once the program has searched for leftovers click Next.
Check/tick the bolded items only on the list then click Delete
when prompted click on Yes and then on next.
put a check on any folders that are found and select delete
when prompted select yes then on next
Once done click Finish.


Redownload from here http://www.google.com/chrome/


Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
ProxyEnable: [S-1-5-21-2107755742-302254199-1763176924-1001] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-2107755742-302254199-1763176924-1001] => http=;https=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
BHO: CinPlus-2.7dV27.01 -> {11111111-1111-1111-1111-110611901165} -> C:\Program Files (x86)\CinPlus-2.7dV27.01\CinPlus-2.7dV27.01-bho64.dll No File
BHO: PriceLess -> {d3db9a68-a6a0-4bb3-bb04-d14d1a92fa85} -> C:\Program Files (x86)\PriceLess\ClSBKIrNV3OZih.x64.dll No File
FF user.js: detected! => C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\user.js
R2 CatWSPrx; C:\Users\Dad\AppData\Local\ArcadeParlor\CatWs\CatWSPrx.exe [1356672 2015-01-28] (Catalytix Web Services)
Task: {03A17A14-F01E-40FD-9432-A4CEADEDBBD6} - System32\Tasks\RPC => C:\Program Files (x86)\Regprocleaner\Regprocleaner.exe
Task: {4D60D52A-0F7B-4776-9A5E-7366825088C9} - System32\Tasks\HQ => C:\Users\Dad\AppData\Roaming\HQ.exe <==== ATTENTION
Task: {D1BA1D14-BA0E-4E6C-B8BD-EE9D098887EF} - System32\Tasks\NEDL => C:\Users\Dad\AppData\Roaming\NEDL.exe <==== ATTENTION
Task: C:\Windows\Tasks\HQ.job => C:\Users\Dad\AppData\Roaming\HQ.exe <==== ATTENTION
Task: C:\Windows\Tasks\NEDL.job => C:\Users\Dad\AppData\Roaming\NEDL.exe <==== ATTENTION
2015-01-28 19:46 - 2015-01-28 19:46 - 00211744 _____ () C:\Users\Dad\AppData\Local\ArcadeParlor\CatHelper.dll
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CatWSPrx => ""="service"
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Dad\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [eefhnbpnnaaokmclnihgajdnlgljajjg] - No Path
CHR HKLM-x32\...\Chrome\Extension: [ggebenakhmhfdkmkemdmllecchcldgec] - No Path

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

http://i.imgur.com/BY4dvz9.png AdwCleaner

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) and save the file to your Desktop.
Right-Click AdwCleaner.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Follow the prompts.
Click Scan.
Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
Follow the prompts and allow your computer to reboot.
After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.

-- File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.

Since you already have MBAM onboard we'll scan with that.

Please run a Threat Scan with Malwarebytes' Anti-Malware. If you're unable to run or complete the scan as shown below please see the following: MBAM Clean Removal Process 2x (https://forums.malwarebytes.org/index.php?showtopic=146017)
When reinstalling the program please try the latest version (http://www.malwarebytes.org/mwb-download/).

Right click and choose "Run as administrator" to open Malwarebytes Anti-Malware and from the Dashboard please Check for Updates by clicking the Update Now... link
Open up Malwarebytes > Settings > Detection and Protection > Enable Scan for rootkit and Under Non Malware Protection set both PUP and PUM to Treat detections as malware.
Click on the SCAN button and run a Threat Scan with Malwarebytes Anti-Malware by clicking the Scan Now>> button.
Once completed please click on the History > Application Logs and find your scan log and open it and then click on the "copy to clipboard" button and post back the results on your next reply.

please post
AdwCleaner log
MBAM log

2015-01-31, 05:15
well hello again! i have no idea what that is...getting hammered here with new tabs opening by the dozen. thanks for helping! the mbam showed malware which i deleted all.

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-01-2015
Ran by Dad at 2015-01-30 20:54:10 Run:4
Running from C:\Users\Dad\Desktop
Loaded Profiles: Dad (Available profiles: Dad)
Boot Mode: Normal

Content of fixlist:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
ProxyEnable: [S-1-5-21-2107755742-302254199-1763176924-1001] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-2107755742-302254199-1763176924-1001] => http=;https=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
BHO: CinPlus-2.7dV27.01 -> {11111111-1111-1111-1111-110611901165} -> C:\Program Files (x86)\CinPlus-2.7dV27.01\CinPlus-2.7dV27.01-bho64.dll No File
BHO: PriceLess -> {d3db9a68-a6a0-4bb3-bb04-d14d1a92fa85} -> C:\Program Files (x86)\PriceLess\ClSBKIrNV3OZih.x64.dll No File
FF user.js: detected! => C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\user.js
R2 CatWSPrx; C:\Users\Dad\AppData\Local\ArcadeParlor\CatWs\CatWSPrx.exe [1356672 2015-01-28] (Catalytix Web Services)
Task: {03A17A14-F01E-40FD-9432-A4CEADEDBBD6} - System32\Tasks\RPC => C:\Program Files (x86)\Regprocleaner\Regprocleaner.exe
Task: {4D60D52A-0F7B-4776-9A5E-7366825088C9} - System32\Tasks\HQ => C:\Users\Dad\AppData\Roaming\HQ.exe <==== ATTENTION
Task: {D1BA1D14-BA0E-4E6C-B8BD-EE9D098887EF} - System32\Tasks\NEDL => C:\Users\Dad\AppData\Roaming\NEDL.exe <==== ATTENTION
Task: C:\Windows\Tasks\HQ.job => C:\Users\Dad\AppData\Roaming\HQ.exe <==== ATTENTION
Task: C:\Windows\Tasks\NEDL.job => C:\Users\Dad\AppData\Roaming\NEDL.exe <==== ATTENTION
2015-01-28 19:46 - 2015-01-28 19:46 - 00211744 _____ () C:\Users\Dad\AppData\Local\ArcadeParlor\CatHelper.dll
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CatWSPrx => ""="service"
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Dad\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [eefhnbpnnaaokmclnihgajdnlgljajjg] - No Path
CHR HKLM-x32\...\Chrome\Extension: [ggebenakhmhfdkmkemdmllecchcldgec] - No Path

Processes closed successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611901165}" => Key deleted successfully.
"HKCR\CLSID\{11111111-1111-1111-1111-110611901165}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d3db9a68-a6a0-4bb3-bb04-d14d1a92fa85}" => Key deleted successfully.
"HKCR\CLSID\{d3db9a68-a6a0-4bb3-bb04-d14d1a92fa85}" => Key deleted successfully.
C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\user.js => Moved successfully.
CatWSPrx => Service not found.
C:\Users\Dad\AppData\Local\Temp\BootstrapperIminent.exe => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\ConsumerInputSetup.exe => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\Execute2App.exe => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\InstHelper.exe => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\jre-8u31-windows-au.exe => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\msvcp90.dll => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\msvcr90.dll => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\optprosetup.exe => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\SoftonicAssistant_v0-1-6.exe => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\SpOrder.dll => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\sprz.exe => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\sqlite3.dll => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\SymCCIS.dll => Moved successfully.
C:\Users\Dad\AppData\Local\Temp\SymInstallStub.exe => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{03A17A14-F01E-40FD-9432-A4CEADEDBBD6}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03A17A14-F01E-40FD-9432-A4CEADEDBBD6}" => Key deleted successfully.
C:\Windows\System32\Tasks\RPC => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RPC" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4D60D52A-0F7B-4776-9A5E-7366825088C9}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4D60D52A-0F7B-4776-9A5E-7366825088C9}" => Key deleted successfully.
C:\Windows\System32\Tasks\HQ => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HQ" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D1BA1D14-BA0E-4E6C-B8BD-EE9D098887EF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D1BA1D14-BA0E-4E6C-B8BD-EE9D098887EF}" => Key deleted successfully.
C:\Windows\System32\Tasks\NEDL => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NEDL" => Key deleted successfully.
C:\Windows\Tasks\HQ.job => Moved successfully.
C:\Windows\Tasks\NEDL.job => Moved successfully.
C:\Users\Dad\AppData\Local\ArcadeParlor\CatHelper.dll => Moved successfully.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\CatWSPrx" => Key deleted successfully.
CHR dev: Chrome dev build detected! <======= ATTENTION => Error: No automatic fix found for this entry.
CHR Profile: C:\Users\Dad\AppData\Local\Google\Chrome\User Data\Default => Error: No automatic fix found for this entry.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eefhnbpnnaaokmclnihgajdnlgljajjg => Key not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ggebenakhmhfdkmkemdmllecchcldgec => Key not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1.2 GB temporary data.

The system needed a reboot.

==== End of Fixlog 20:54:50 ====

# AdwCleaner v4.109 - Report created 30/01/2015 at 21:00:45
# Updated 24/01/2015 by Xplode
# Database : 2015-01-26.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Dad - BRIDGES1
# Running from : C:\Users\Dad\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\NCH Software
Folder Deleted : C:\ProgramData\16969743963293318193
Folder Deleted : C:\ProgramData\af0e05b2000074da

***** [ Scheduled Tasks ] *****

Task Deleted : ApCatSupport

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{230332DF-D235-47EE-BC42-60860EF144CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Red Sky
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\CompeteInc
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\{F2E9660B-98AF-42c0-8258-9CDDF07BF95D}
Key Deleted : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Deleted : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=;hxxps=
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyEnable] - 1

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17496

-\\ Mozilla Firefox v35.0.1 (x86 en-US)

[fen9gfz2.default-1409800020396\prefs.js] - Line Deleted : user_pref("extensions.YiqnjJ2RnCzChHdH.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]


AdwCleaner[R0].txt - [10622 octets] - [15/10/2014 08:47:45]
AdwCleaner[R1].txt - [8806 octets] - [16/10/2014 10:55:24]
AdwCleaner[R2].txt - [8866 octets] - [16/10/2014 11:13:07]
AdwCleaner[R3].txt - [8130 octets] - [07/01/2015 17:26:30]
AdwCleaner[R4].txt - [7986 octets] - [30/01/2015 20:58:50]
AdwCleaner[S0].txt - [8698 octets] - [16/10/2014 11:14:02]
AdwCleaner[S1].txt - [8127 octets] - [07/01/2015 17:28:47]
AdwCleaner[S2].txt - [7837 octets] - [30/01/2015 21:00:45]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [7897 octets] ##########

Malwarebytes Anti-Malware

Scan Date: 1/30/2015
Scan Time: 9:02:57 PM
Administrator: Yes

Malware Database: v2015.01.30.08
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Dad

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 346975
Time Elapsed: 8 min, 33 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 1
PUM.Bad.Proxy, HKU\S-1-5-21-2107755742-302254199-1763176924-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=;https=, , [464a78857a0f6cca7583bbdb3fc44cb4]

Registry Data: 0
(No malicious items detected)

Folders: 2
PUP.Optional.SmootherWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\jetpack\jid1-U7omKQ6kQfxMaQ@jetpack, , [c6ca34c987021125c586264f976c9070],
PUP.Optional.SmootherWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\jetpack\jid1-U7omKQ6kQfxMaQ@jetpack\simple-storage, , [c6ca34c987021125c586264f976c9070],

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


2015-01-31, 14:10
This is an undesirable program.

Please go to add/remove programs list, and if found and uninstall.

wise care365
It's a registry cleaner/system optimizer tool. We do not recommend the use of registry cleaners/optimizers/tweakers.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

C:\Program Files (x86)\Lydynamidae\Lydynamidae.exe
C:\Program Files (x86)\Lydynamidae\LydynamidaeHelper.exe
R2 Lydynamidae; C:\Program Files (x86)\Lydynamidae\Lydynamidae.exe [3959296 2015-01-27] () [File not signed] <==== ATTENTION
2015-01-28 18:15 - 2015-01-28 18:16 - 00000000 __SHD () C:\Program Files (x86)\Lydynamidae
2015-01-28 18:16 - 2015-01-27 13:57 - 03959296 ___SH () C:\Program Files (x86)\Lydynamidae\Lydynamidae.exe
2015-01-28 18:16 - 2015-01-28 18:16 - 00043520 ____R () C:\Program Files (x86)\Lydynamidae\LydynamidaeHelper.exe
Task: C:\Windows\Tasks\RegPowerClean.job => C:\Program Files (x86)\Winferno\RegistryPowerCleaner\RegPowerClean.exe
Task: C:\Windows\Tasks\RPCReminder.job => C:\Program Files (x86)\Winferno\RegistryPowerCleaner\RPCReminder.exe
2015-01-28 18:15 - 2015-01-28 18:15 - 00004348 _____ () C:\Windows\System32\Tasks\NEDL
2015-01-25 10:12 - 2015-01-25 10:12 - 00001248 _____ () C:\Users\Dad\AppData\Roaming\NEDL
2015-01-25 10:12 - 2015-01-25 10:12 - 0002086 _____ () C:\Users\Dad\AppData\Roaming\HQ
2015-01-25 10:12 - 2015-01-25 10:12 - 0001248 _____ () C:\Users\Dad\AppData\Roaming\NEDL
Task: {D1BA1D14-BA0E-4E6C-B8BD-EE9D098887EF} - System32\Tasks\NEDL => C:\Users\Dad\AppData\Roaming\NEDL.exe <==== ATTENTION

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


Download Emsisoft Emergency Kit (http://www.emsisoft.com/en/software/eek/download/) and save it to your desktop.
Double click on the EmsisoftEmergencyKit.exe icon, click Run then Extract
Double click the Start Emsisoft Emergency Kit icon that will appear after extraction
Click Yes to update the program
Once the update is completed click the Back button
Click on 2. Scan (not Quick Scan or Smart Scan)
Click Yes to detect Potentially Unwanted Programs (PUPs)
Patiently wait for the thorough scan to complete, this can be a lengthy process
Once completed click Quarantine selected objects (if computer is clean you will not have this option) then click OK
Click View Report
Attach the report to your reply
Close the program then click Close

please post
Emsisoft log

2015-02-02, 22:08
now it's giving me heck after a restart to connect to the net...
Emsisoft Emergency Kit - Version 9.0
Last update: 2/2/2015 12:00:31 PM
User account: Bridges1\Dad

Scan settings:

Scan type: Full Scan
Objects: Rootkits, Memory, Traces, C:\, K:\, Q:\

Detect PUPs: On
Scan archives: On
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off

Scan start: 2/2/2015 12:01:04 PM
C:\Users\Dad\AppData\Local\SlimWare Utilities Inc\DriverUpdate detected: Application.InstallDrive (A)
Key: HKEY_USERS\S-1-5-21-2107755742-302254199-1763176924-1001\SOFTWARE\SLIMWARE UTILITIES INC\DRIVERUPDATE detected: Application.InstallDrive (A)
Value: HKEY_USERS\S-1-5-21-2107755742-302254199-1763176924-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR detected: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-21-2107755742-302254199-1763176924-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS detected: Setting.DisableRegistryTools (A)
Key: HKEY_USERS\.DEFAULT\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F} detected: Application.Win32.InstallAd (A)
Key: HKEY_USERS\S-1-5-19\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F} detected: Application.Win32.InstallAd (A)
Key: HKEY_USERS\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F} detected: Application.Win32.InstallAd (A)
C:\FRST\Quarantine\C\Program Files (x86)\Lydynamidae\Lydynamidae.exe.xBAD detected: Adware.Generic.1155047 (B)
C:\FRST\Quarantine\C\Users\Dad\AppData\Roaming\HQ.xBAD -> content/overlay.js detected: Adware.JS.Mplug.A (B)
C:\FRST\Quarantine\C\Users\Dad\AppData\Roaming\NEDL.xBAD -> background.js detected: Trojan.Script.Agent.FA (B)
C:\Users\Dad\AppData\Roaming\UZNYUL -> background.js detected: Trojan.Script.Agent.FA (B)
C:\Users\Dad\AppData\Roaming\WTPQZFD -> content/overlay.js detected: Adware.JS.Mplug.A (B)

Scanned 303699
Found 13

Scan end: 2/2/2015 1:04:00 PM
Scan time: 1:02:56

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015
Ran by Dad at 2015-02-02 11:36:54 Run:5
Running from C:\Users\Dad\Desktop
Loaded Profiles: Dad (Available profiles: Dad)
Boot Mode: Normal

Content of fixlist:
C:\Program Files (x86)\Lydynamidae\Lydynamidae.exe
C:\Program Files (x86)\Lydynamidae\LydynamidaeHelper.exe
R2 Lydynamidae; C:\Program Files (x86)\Lydynamidae\Lydynamidae.exe [3959296 2015-01-27] () [File not signed] <==== ATTENTION
2015-01-28 18:15 - 2015-01-28 18:16 - 00000000 __SHD () C:\Program Files (x86)\Lydynamidae
2015-01-28 18:16 - 2015-01-27 13:57 - 03959296 ___SH () C:\Program Files (x86)\Lydynamidae\Lydynamidae.exe
2015-01-28 18:16 - 2015-01-28 18:16 - 00043520 ____R () C:\Program Files (x86)\Lydynamidae\LydynamidaeHelper.exe
Task: C:\Windows\Tasks\RegPowerClean.job => C:\Program Files (x86)\Winferno\RegistryPowerCleaner\RegPowerClean.exe
Task: C:\Windows\Tasks\RPCReminder.job => C:\Program Files (x86)\Winferno\RegistryPowerCleaner\RPCReminder.exe
2015-01-28 18:15 - 2015-01-28 18:15 - 00004348 _____ () C:\Windows\System32\Tasks\NEDL
2015-01-25 10:12 - 2015-01-25 10:12 - 00001248 _____ () C:\Users\Dad\AppData\Roaming\NEDL
2015-01-25 10:12 - 2015-01-25 10:12 - 0002086 _____ () C:\Users\Dad\AppData\Roaming\HQ
2015-01-25 10:12 - 2015-01-25 10:12 - 0001248 _____ () C:\Users\Dad\AppData\Roaming\NEDL
Task: {D1BA1D14-BA0E-4E6C-B8BD-EE9D098887EF} - System32\Tasks\NEDL => C:\Users\Dad\AppData\Roaming\NEDL.exe <==== ATTENTION

C:\Program Files (x86)\Lydynamidae\Lydynamidae.exe => Moved successfully.
C:\Program Files (x86)\Lydynamidae\LydynamidaeHelper.exe => Moved successfully.
Lydynamidae => Unable to stop service
Lydynamidae => Service deleted successfully.
C:\Program Files (x86)\Lydynamidae => Moved successfully.
"C:\Program Files (x86)\Lydynamidae\Lydynamidae.exe" => File/Directory not found.
"C:\Program Files (x86)\Lydynamidae\LydynamidaeHelper.exe" => File/Directory not found.
C:\Windows\Tasks\RegPowerClean.job not found.
C:\Windows\Tasks\RPCReminder.job not found.
"C:\Windows\Tasks\NEDL.job" => File/Directory not found.
"C:\Windows\System32\Tasks\NEDL" => File/Directory not found.
C:\Users\Dad\AppData\Roaming\NEDL => Moved successfully.
C:\Users\Dad\AppData\Roaming\HQ => Moved successfully.
"C:\Users\Dad\AppData\Roaming\NEDL" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D1BA1D14-BA0E-4E6C-B8BD-EE9D098887EF} => Key not found.
C:\Windows\System32\Tasks\NEDL not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NEDL => Key not found.
EmptyTemp: => Removed 59.7 MB temporary data.

The system needed a reboot.

==== End of Fixlog 11:37:02 ====

2015-02-02, 23:12
now it's giving me heck after a restart to connect to the net

See if these settings help?

Internet Explorer:
Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" and check to "Automatically detect settings". Also clear any proxy address and port. ok, apply (only if applicable), ok.
Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection. "No Proxy" should be selected, unless you have one set up yourself.
Select -> Tools menu -> then "Options", then go to "Change Proxy Settings", then "LAN Settings" , then take out the check mark for "Use a proxy server for your LAN" if set, unless you set this up yourself.

2015-02-03, 01:28
See if these settings help?

Internet Explorer:
Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" and check to "Automatically detect settings". Also clear any proxy address and port. ok, apply (only if applicable), ok.
Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection. "No Proxy" should be selected, unless you have one set up yourself.
Select -> Tools menu -> then "Options", then go to "Change Proxy Settings", then "LAN Settings" , then take out the check mark for "Use a proxy server for your LAN" if set, unless you set this up yourself.
i found that and did as you said. not restarted since, but i am seeing it get better as far as new tabs and windows popping up. still tho i can tell somethings wrong...but we're getting there

2015-02-03, 03:12
I want you to download this script I've created to your desktop

It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.

Go here (http://www.eset.com/us/online-scanner/) to run an online scannner from ESET. Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator

For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
Turn off the real time scanner of any existing antivirus program while performing the online scan. Here's how (http://www.techsupportforum.com/forums/f50/how-to-disable-your-security-applications-490111.html).
Click the blue Run ESET Online Scanner button
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
Click on Advanced Settings[/*]
Make sure that the option Remove found threats is unticked.
Ensure these options are ticked

Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology

Click Start
Wait for the scan to finish
When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
Close the ESET online scan.

2015-02-03, 03:21
I want you to download this script I've created to your desktop

It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.

Go here (http://www.eset.com/us/online-scanner/) to run an online scannner from ESET. Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator

For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
Turn off the real time scanner of any existing antivirus program while performing the online scan. Here's how (http://www.techsupportforum.com/forums/f50/how-to-disable-your-security-applications-490111.html).
Click the blue Run ESET Online Scanner button
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
Click on Advanced Settings[/*]
Make sure that the option Remove found threats is unticked.
Ensure these options are ticked

Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology

Click Start
Wait for the scan to finish
When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
Close the ESET online scan.

ok upon running FRST64 it said there was no fixlist...but it was right next to it. running est now as you said

2015-02-03, 03:29
the eset program won't run and says cannot get update is proxy figured?

2015-02-03, 03:47
I don't know what happened to FRST

Which browser are you using?
May need to set to No Proxy

Please download MiniToolBox http://www.bleepingcomputer.com/download/minitoolbox/
save it to your desktop and run it.

Checkmark the following check-boxes:

Flush DNS
Report IE Proxy Settings
Reset IE Proxy Settings
Report FF Proxy Settings
Reset FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Devices
List Users, Partitions and Memory size.
List Minidump Files

Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using Reset FF Proxy Settings option Firefox should be closed.

2015-02-03, 03:55
Try this fixlist.txt


2015-02-03, 04:07
ok here is that scan...i use firefox and had no proxy selected

MiniToolBox by Farbar Version: 30-11-2014
Ran by Dad (administrator) on 02-02-2015 at 20:04:33
Running from "C:\Users\Dad\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is enabled.
ProxyServer: http=;https=

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================

"network.proxy.type", 4

"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================

========================= IP Configuration: ================================

Remote NDIS based Internet Sharing Device = Local Area Connection 2 (Connected)
802.11n Wireless LAN Card = Wireless Network Connection (Media disconnected)
Realtek PCIe GBE Family Controller = Local Area Connection (Media disconnected)
Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected)

# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

set global defaultcurhoplimit=64 icmpredirects=enabled taskoffload=disabled

# End of IPv4 configuration

Windows IP Configuration

Host Name . . . . . . . . . . . . : Bridges1
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Remote NDIS based Internet Sharing Device
Physical Address. . . . . . . . . : 02-06-0D-5D-64-65
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::f5df:bd8d:4a88:2a24%18(Preferred)
IPv4 Address. . . . . . . . . . . :
Subnet Mask . . . . . . . . . . . :
Lease Obtained. . . . . . . . . . : Monday, February 02, 2015 2:05:09 PM
Lease Expires . . . . . . . . . . : Monday, February 02, 2015 9:00:11 PM
Default Gateway . . . . . . . . . :
DHCP Server . . . . . . . . . . . :
DHCPv6 IAID . . . . . . . . . . . : 285345293
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-16-C1-6B-BA-9C-B7-0D-63-72-44
DNS Servers . . . . . . . . . . . :
NetBIOS over Tcpip. . . . . . . . : Enabled

Wireless LAN adapter Wireless Network Connection 2:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter
Physical Address. . . . . . . . . : 9C-B7-0D-63-72-45
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
Physical Address. . . . . . . . . : E8-40-F2-0C-0B-8D
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wireless Network Connection:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : 802.11n Wireless LAN Card
Physical Address. . . . . . . . . : 9C-B7-0D-63-72-44
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Server: UnKnown

Name: google.com
Addresses: 2607:f8b0:4000:80a::200e

Pinging google.com [] with 32 bytes of data:
Reply from bytes=32 time=47ms TTL=54
Reply from bytes=32 time=48ms TTL=54

Ping statistics for
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 47ms, Maximum = 48ms, Average = 47ms
Server: UnKnown

Name: yahoo.com

Pinging yahoo.com [] with 32 bytes of data:
Reply from bytes=32 time=93ms TTL=49
Reply from bytes=32 time=143ms TTL=49

Ping statistics for
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 93ms, Maximum = 143ms, Average = 118ms

Pinging with 32 bytes of data:
Reply from bytes=32 time<1ms TTL=64
Reply from bytes=32 time<1ms TTL=64

Ping statistics for
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Interface List
18...02 06 0d 5d 64 65 ......Remote NDIS based Internet Sharing Device
13...9c b7 0d 63 72 45 ......Microsoft Virtual WiFi Miniport Adapter
12...e8 40 f2 0c 0b 8d ......Realtek PCIe GBE Family Controller
11...9c b7 0d 63 72 44 ......802.11n Wireless LAN Card
1...........................Software Loopback Interface 1

IPv4 Route Table
Active Routes:
Network Destination Netmask Gateway Interface Metric 10 On-link 306 On-link 306 On-link 306 On-link 266 On-link 266 On-link 266 On-link 306 On-link 266 On-link 306 On-link 266
Persistent Routes:

IPv6 Route Table
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
18 266 fe80::/64 On-link
18 266 fe80::f5df:bd8d:4a88:2a24/128
1 306 ff00::/8 On-link
18 266 ff00::/8 On-link
Persistent Routes:
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 09 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
Error: (02/02/2015 07:28:12 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/02/2015 07:28:06 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/02/2015 07:27:42 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/02/2015 07:22:35 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/02/2015 02:04:42 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/02/2015 02:04:38 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:44:34 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:38:05 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:36:55 AM) (Source: Application Error) (User: )
Description: Faulting application name: plugin-container.exe, version:, time stamp: 0x54c1f9f3
Faulting module name: mozalloc.dll, version:, time stamp: 0x54c1f224
Exception code: 0x80000003
Fault offset: 0x00001425
Faulting process id: 0xff8
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3

Error: (02/02/2015 11:33:03 AM) (Source: Windows Backup) (User: )
Description: The backup was not successful. The error is: There is not enough space on this drive to save the backup. Free up space by deleting older backups and unnecessary data or change your backup settings. (0x81000005).

System errors:
Error: (02/02/2015 02:04:40 PM) (Source: Service Control Manager) (User: )
Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error:

Error: (02/02/2015 02:04:40 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Scanner Service service to connect.

Error: (02/02/2015 02:04:34 PM) (Source: Service Control Manager) (User: )
Description: The Spybot-S&D 2 Updating Service service failed to start due to the following error:

Error: (02/02/2015 02:04:34 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Updating Service service to connect.

Error: (02/02/2015 02:04:34 PM) (Source: Service Control Manager) (User: )
Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error:

Error: (02/02/2015 02:04:34 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Scanner Service service to connect.

Error: (02/02/2015 02:04:31 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 2:03:20 PM on ‎2/‎2/‎2015 was unexpected.

Error: (02/02/2015 11:44:38 AM) (Source: Service Control Manager) (User: )
Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error:

Error: (02/02/2015 11:44:38 AM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Scanner Service service to connect.

Error: (02/02/2015 11:44:31 AM) (Source: Service Control Manager) (User: )
Description: The Spybot-S&D 2 Updating Service service failed to start due to the following error:

Microsoft Office Sessions:
Error: (02/02/2015 07:28:12 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Dad\Desktop\esetsmartinstaller_enu.exe

Error: (02/02/2015 07:28:06 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Dad\Desktop\esetsmartinstaller_enu.exe

Error: (02/02/2015 07:27:42 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Dad\Desktop\esetsmartinstaller_enu.exe

Error: (02/02/2015 07:22:35 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Dad\Desktop\esetsmartinstaller_enu.exe

Error: (02/02/2015 02:04:42 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Dad\Desktop\esetsmartinstaller_enu.exe

Error: (02/02/2015 02:04:38 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:44:34 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:38:05 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:36:55 AM) (Source: Application Error)(User: )
Description: plugin-container.exe35.0.1.550054c1f9f3mozalloc.dll35.0.1.550054c1f2248000000300001425ff801d03f0e03132d54C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll14602565-ab02-11e4-9f9e-02060d5d6465

Error: (02/02/2015 11:33:03 AM) (Source: Windows Backup)(User: )
Description: There is not enough space on this drive to save the backup. Free up space by deleting older backups and unnecessary data or change your backup settings. (0x81000005)

=========================== Installed Programs ============================
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: - Adobe Systems Incorporated)
Adobe AIR (x32 Version: - Adobe Systems Incorporated) Hidden
Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version: - )
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated)
Adobe PDF ePub DRM Removal 4.7.1 (HKLM-x32\...\{C9DD56CA-BAE9-452A-AFE9-834C7770D1A3}) (Version: 4.7.1 - EPUBSOFT)
Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\...\{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}) (Version: 2.3.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: - Apple Inc.)
Audio Recorder for Free v12.9.8 (HKLM-x32\...\Audio Recorder for Free_is1) (Version: - Copyright(C) 2006-2012 AudioToolMedia Software.)
BEHRINGER UFX 1394 Drivers v6.11.0.0 (HKLM-x32\...\BEHRINGER UFX 1394 Drivers v6.11.0.0) (Version: - BEHRINGER)
Belkin Setup and Router Monitor (HKLM-x32\...\Belkin Setup and Router Monitor_is1) (Version: - )
Best Buy pc app (Version: - Best Buy) Hidden
Best Buy pc app (x32 Version: - Best Buy) Hidden
Bing Bar (HKLM-x32\...\{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}) (Version: - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: - Apple Inc.)
CameraHelperMsi (x32 Version: 13.50.854.0 - Logitech) Hidden
Canon MP Navigator 3.0 (HKLM-x32\...\MP Navigator 3.0) (Version: - )
Canon MP160 (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 4.16 - Piriform)
CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.2531.52 - CyberLink Corp.)
CyberLink PowerDVD 10 (x32 Version: 10.0.2531.52 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Defraggler (HKLM\...\Defraggler) (Version: 2.15 - Piriform)
Dropbox (HKCU\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
Dwyco CDC-X version 2.10 (HKCU\...\Dwyco CDC-X_is1) (Version: 2.10 - Dwyco, Inc.)
Easy Thumbnails (Remove only) (HKLM-x32\...\Easy Thumbnails_is1) (Version: 3.0 - Fookes Software)
eReg (x32 Version: - Logitech, Inc.) Hidden
Etron USB3.0 Host Controller (x32 Version: 0.103 - Etron Technology) Hidden
Freemake Video Converter version 3.1.0 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 3.1.0 - Ellora Assets Corporation)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gateway Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Gateway Incorporated)
Gateway Registration (HKLM-x32\...\Gateway Registration) (Version: 1.04.3503 - Gateway Incorporated)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: - Google)
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: - Google)
Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3505 - Gateway Incorporated)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Gateway Incorporated)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: - Intel Corporation)
iTunes (HKLM\...\{0225AD21-F3E2-4916-BFF3-65D3F9052582}) (Version: - Apple Inc.)
Java 7 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217065FF}) (Version: 7.0.650 - Oracle)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Java Auto Updater (x32 Version: - Oracle Corporation) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Karaoke Builder Player 3.0 (HKLM-x32\...\Karaoke Builder Player 3.0) (Version: - )
Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.0 - Logitech Inc.)
LWS Facebook (x32 Version: 13.50.854.0 - Logitech) Hidden
LWS Gallery (x32 Version: 13.50.854.0 - Logitech) Hidden
LWS Help_main (x32 Version: 13.50.862.0 - Logitech) Hidden
LWS Launcher (x32 Version: 13.50.859.0 - Logitech) Hidden
LWS Motion Detection (x32 Version: 13.30.1395.0 - Logitech) Hidden
LWS Pictures And Video (x32 Version: 13.50.861.0 - Logitech) Hidden
LWS Twitter (x32 Version: 13.30.1346.0 - Logitech) Hidden
LWS Video Mask Maker (x32 Version: 13.30.1379.0 - Logitech) Hidden
LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden
LWS Webcam Software (x32 Version: 13.31.1038.0 - Logitech) Hidden
LWS WLM Plugin (x32 Version: 1.30.1201.0 - Logitech) Hidden
LWS YouTube Plugin (x32 Version: 13.31.1038.0 - Logitech) Hidden
Malwarebytes Anti-Malware version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5131.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 35.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT Redists (x32 Version: 1.0 - Sony Creative Software Inc.) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyFreeCodec (HKCU\...\MyFreeCodec) (Version: - )
Noise Reduction Plug-In 2.0 (HKLM-x32\...\{B94515E1-2DD6-11E2-849E-F04DA23A5C58}) (Version: 2.0.515 - Sony)
Paltalk Ad Remover 4.0 (HKLM-x32\...\Paltalk Ad Remover_is1) (Version: - The Anubis Group (T.A.G.))
Paltalk Messenger 11.4 (HKLM-x32\...\Paltalk Messenger) (Version: 11.4.564.16191 - AVM Software Inc.)
Peace Art App 2 version 1.1 (HKLM-x32\...\{36756AF9-18F1-467A-AE37-62BC72A0029A}_is1) (Version: 1.1 - Kelly Anne)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.2 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: - SAMSUNG Electronics Co., Ltd.)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Switch Sound File Converter (HKLM-x32\...\Switch) (Version: - NCH Software)
swMSM (x32 Version: - Adobe Systems, Inc) Hidden
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 2.0.0 - Tweaking.com)
VisioForge Video Capture SDK Delphi Redist (x32 Version: - VisioForge) Hidden
Welcome Center (HKLM-x32\...\Gateway Welcome Center) (Version: 1.02.3504 - Gateway Incorporated)
Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.)

========================= Devices: ================================

Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Microsoft Teredo Tunneling Adapter #2
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

========================= Memory info: ===================================

Percentage of memory in use: 23%
Total physical RAM: 6048.28 MB
Available physical RAM: 4633.07 MB
Total Pagefile: 12094.74 MB
Available Pagefile: 10702.8 MB
Total Virtual: 4095.88 MB
Available Virtual: 3976.11 MB

========================= Partitions: =====================================

1 Drive c: (Gateway) (Fixed) (Total:918.41 GB) (Free:806.73 GB) NTFS
2 Drive d: (MAN_OF_STEEL) (CDROM) (Total:7.57 GB) (Free:0 GB) UDF
8 Drive k: (FreeAgent GoFlex Drive) (Fixed) (Total:465.76 GB) (Free:0.04 GB) NTFS

========================= Users: ========================================

User accounts for \\BRIDGES1

Administrator Dad Guest

========================= Minidump Files ==================================

No minidump file found

**** End of log ****

2015-02-03, 04:10
See if Eset will run and update now.

2015-02-03, 04:11
ok i used the fix u posted and frst ran

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015
Ran by Dad at 2015-02-02 20:08:16 Run:6
Running from C:\Users\Dad\Desktop
Loaded Profiles: Dad (Available profiles: Dad)
Boot Mode: Normal

Content of fixlist:
Task: {D67B1D7D-E9C3-4AE6-BC10-908166FF1A41} - System32\Tasks\ApCatSupport => Rundll32.exe C:\Users\Dad\AppData\Local\ARCADE~1\CATHEL~1.DLL,Start
Task: C:\Windows\Tasks\ApCatSupport.job => [뀪‰ÊJĹÌBžèF<
s€ €!ß5!C:\Windows\system32\rundll32.exe7C:\Users\Dad\AppData\Local\ARCADE~1\CATHEL~1.DLL,StartDad0Ý¥
Task: C:\Windows\Tasks\ArcadeParlor.job => C:\Users\Dad\AppData\Local\ArcadeParlor\versioncheck.exe
2015-01-28 19:46 - 2015-01-28 19:46 - 00211744 _____ () C:\Users\Dad\AppData\Local\ArcadeParlor\CatHelper.dll

Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D67B1D7D-E9C3-4AE6-BC10-908166FF1A41} => Key not found.
C:\Windows\System32\Tasks\ApCatSupport not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ApCatSupport => Key not found.
C:\Windows\Tasks\ApCatSupport.job not found.
s€ €!ß5!C:\Windows\system32\rundll32.exe7C:\Users\Dad\AppData\Local\ARCADE~1\CATHEL~1.DLL,StartDad0Ý¥ => Error: No automatic fix found for this entry.
C:\Windows\Tasks\ArcadeParlor.job not found.
"C:\Users\Dad\AppData\Local\ArcadeParlor\CatHelper.dll" => File/Directory not found.
EmptyTemp: => Removed 290.6 MB temporary data.

The system needed a reboot.

==== End of Fixlog 20:08:21 ====

2015-02-03, 04:12
also juliet, my pc restarted a lot quicker just now and connected right away. but i keep getting yahoo as my default search which i've never had

2015-02-03, 04:20
Which browser uses Yahoo for default search?

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

2015-02-03, 04:31
firefox is using it now...i've deleted it but it comes back...have always used google and never yahoo

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015
Ran by Dad at 2015-02-02 20:29:07 Run:7
Running from C:\Users\Dad\Desktop
Loaded Profiles: Dad (Available profiles: Dad)
Boot Mode: Normal

Content of fixlist:

Processes closed successfully.
"C:\Users\Dad\AppData\Local\ARCADE~1\CATHEL~1.DLL" => File/Directory not found.

The system needed a reboot.

==== End of Fixlog 20:29:07 ====

2015-02-03, 04:32
See if this will run now.

Go here (http://www.eset.com/us/online-scanner/) to run an online scannner from ESET. Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator

For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
Turn off the real time scanner of any existing antivirus program while performing the online scan. Here's how (http://www.techsupportforum.com/forums/f50/how-to-disable-your-security-applications-490111.html).
Click the blue Run ESET Online Scanner button
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
Click on Advanced Settings[/*]
Make sure that the option Remove found threats is unticked.
Ensure these options are ticked

Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology

Click Start
Wait for the scan to finish
When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
Close the ESET online scan.

2015-02-03, 04:40
1. Open Firefox browser. Click on Tools, then Options, select Privacy.
2. Click “Remove individual cookies.”
3. In the Cookies panel, click on “Show Cookies.” Remove a single cookie click on the entry in the list and click on the “Remove Cookie button.”
4. To remove all cookies click on the “Remove All Cookies button.”
5. Click Tools and select Add-ons. On the Extensions and Plugin tabs search for any suspicious add-ons and remove them.
7. Come back Tools again, this time you need click on “Clear Recent History” and you need clear all recent history.
8. Click on the Start menu go to Control Panel, then click Network and Internet. You then click on the Programs tab, then select Set your default programs.If you want to set Mozilla Firefox or Google Chrome, you can select either of them

2015-02-03, 04:43
It's late here.

Will check back in the morning :)

2015-02-03, 12:08
this keeps opening in a new window and multiple windows...maybe 5 of them,


also when i select a new tab my homepage is msn.com yet this opens in a new tab, i've removed yahoo from the search engines but still...


also i tried to log in at at&t to pay my phone bill and i've always had the same username and password, yet in firefox it kept prompting me for the name and password. i opened IE and tried with it and it opened the first time. is it possible firefox has just been made stupid by all of this? should i uninstall it?

2015-02-03, 12:41
this keeps opening in a new window and multiple windows...maybe 5 of them,


also when i select a new tab my homepage is msn.com yet this opens in a new tab, i've removed yahoo from the search engines but still...


also i tried to log in at at&t to pay my phone bill and i've always had the same username and password, yet in firefox it kept prompting me for the name and password. i opened IE and tried with it and it opened the first time. is it possible firefox has just been made stupid by all of this? should i uninstall it?

For Firefox

Instructions on how to backup your Favourites/Bookmarks and other data can be found below.

http://2-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg Backup Firefox Bookmarks (https://support.mozilla.org/en-US/kb/export-firefox-bookmarks-to-backup-or-transfer)

Please download and install Revo Uninstaller Free (http://www.revouninstaller.com/)

Double click Revo Uninstaller to run it.
From the list of programs double click on Firefox
When prompted if you want to uninstall click Yes.
Be sure the Moderate option is selected then click Next.
The program will run, If prompted again click Yes
when the built-in uninstaller is finished click on Next.
Once the program has searched for leftovers click Next.
Check/tick the bolded items only on the list then click Delete
when prompted click on Yes and then on next.
put a check on any folders that are found and select delete
when prompted select yes then on next
Once done click Finish.

Download Firefox from here

Have you downloaded any new software, trading software?

Let me see a new FRST log.

Right-Click FRST.exe / FRST64.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Click Yes to the disclaimer.
Ensure the Addition.txt box is checked.
Click the Scan button and let the programme run.
Upon completion, click OK, then OK on the Addition.txt pop up screen.
Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

2015-02-03, 18:55
i haven't intentionally d'loaded anything except quicktime which i thought i needed but didn't. that's all tho and was just this morning. the yahoo search engine has now shown up in IE. grrrrrr!

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015
Ran by Dad at 2015-02-03 10:52:05
Running from C:\Users\Dad\Desktop\FRST-OlderVersion
Boot Mode: Safe Mode (with Networking)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Spybot - Search and Destroy (Disabled - Out of date) {20A26C15-1AF0-7CA3-9380-FAB824A7EE0D}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: - Adobe Systems Incorporated)
Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version: - )
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated)
Adobe PDF ePub DRM Removal 4.7.1 (HKLM-x32\...\{C9DD56CA-BAE9-452A-AFE9-834C7770D1A3}) (Version: 4.7.1 - EPUBSOFT)
Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: - Apple Inc.)
Audio Recorder for Free v12.9.8 (HKLM-x32\...\Audio Recorder for Free_is1) (Version: - Copyright(C) 2006-2012 AudioToolMedia Software.)
BEHRINGER UFX 1394 Drivers v6.11.0.0 (HKLM-x32\...\BEHRINGER UFX 1394 Drivers v6.11.0.0) (Version: - BEHRINGER)
Belkin Setup and Router Monitor (HKLM-x32\...\Belkin Setup and Router Monitor_is1) (Version: - )
Best Buy pc app (Version: - Best Buy) Hidden
Best Buy pc app (x32 Version: - Best Buy) Hidden
Bing Bar (HKLM-x32\...\{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}) (Version: - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: - Apple Inc.)
CameraHelperMsi (x32 Version: 13.50.854.0 - Logitech) Hidden
Canon MP Navigator 3.0 (HKLM-x32\...\MP Navigator 3.0) (Version: - )
Canon MP160 (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 4.16 - Piriform)
CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.2531.52 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Defraggler (HKLM\...\Defraggler) (Version: 2.15 - Piriform)
Dropbox (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
Dwyco CDC-X version 2.10 (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Dwyco CDC-X_is1) (Version: 2.10 - Dwyco, Inc.)
Easy Thumbnails (Remove only) (HKLM-x32\...\Easy Thumbnails_is1) (Version: 3.0 - Fookes Software)
eReg (x32 Version: - Logitech, Inc.) Hidden
Etron USB3.0 Host Controller (x32 Version: 0.103 - Etron Technology) Hidden
Freemake Video Converter version 3.1.0 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 3.1.0 - Ellora Assets Corporation)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gateway Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Gateway Incorporated)
Gateway Registration (HKLM-x32\...\Gateway Registration) (Version: 1.04.3503 - Gateway Incorporated)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: - Google)
Google Talk Plugin (HKLM-x32\...\{C77CC230-7417-3F01-B70D-52583DC9FEC9}) (Version: - Google)
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: - Google)
Google+ Auto Backup (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Google+ Auto Backup) (Version: - Google, Inc.)
Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3505 - Gateway Incorporated)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Gateway Incorporated)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: - Intel Corporation)
iTunes (HKLM\...\{0225AD21-F3E2-4916-BFF3-65D3F9052582}) (Version: - Apple Inc.)
Java 7 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217065FF}) (Version: 7.0.650 - Oracle)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Karaoke Builder Player 3.0 (HKLM-x32\...\Karaoke Builder Player 3.0) (Version: - )
Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.0 - Logitech Inc.)
LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden
Malwarebytes Anti-Malware version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5131.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyFreeCodec (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MyFreeCodec) (Version: - )
Noise Reduction Plug-In 2.0 (HKLM-x32\...\{B94515E1-2DD6-11E2-849E-F04DA23A5C58}) (Version: 2.0.515 - Sony)
Paltalk Ad Remover 4.0 (HKLM-x32\...\Paltalk Ad Remover_is1) (Version: - The Anubis Group (T.A.G.))
Paltalk Messenger 11.4 (HKLM-x32\...\Paltalk Messenger) (Version: 11.4.564.16191 - AVM Software Inc.)
Peace Art App 2 version 1.1 (HKLM-x32\...\{36756AF9-18F1-467A-AE37-62BC72A0029A}_is1) (Version: 1.1 - Kelly Anne)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: - Apple Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.2 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: - SAMSUNG Electronics Co., Ltd.)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Switch Sound File Converter (HKLM-x32\...\Switch) (Version: - NCH Software)
swMSM (x32 Version: - Adobe Systems, Inc) Hidden
Taplika (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Taplika) (Version: 31.0.1650.23 - Taplika) <==== ATTENTION!
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 2.0.0 - Tweaking.com)
VisioForge Video Capture SDK Delphi Redist (x32 Version: - VisioForge) Hidden
Welcome Center (HKLM-x32\...\Gateway Welcome Center) (Version: 1.02.3504 - Gateway Incorporated)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Dad\AppData\Local\Google\Update\\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Dad\AppData\Local\Google\Update\\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points =========================

25-01-2015 19:00:17 Windows Backup
27-01-2015 10:01:28 Windows Update
27-01-2015 18:34:21 Installed Samsung Kies3
28-01-2015 09:27:57 Removed Samsung Kies
28-01-2015 22:51:57 Removed Sound Forge Pro 10.0
30-01-2015 20:48:48 Revo Uninstaller Pro's restore point - Google Chrome
30-01-2015 20:54:54 Windows Update
02-02-2015 11:29:56 Windows Backup
03-02-2015 08:22:48 Installed QuickTime 7
03-02-2015 10:19:10 Revo Uninstaller Pro's restore point - Mozilla Firefox 35.0.1 (x86 en-US)
03-02-2015 10:19:44 Revo Uninstaller Pro's restore point - Mozilla Firefox 35.0.1 (x86 en-US)

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 20:34 - 2015-01-30 20:54 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0642325B-D49D-4797-BC3D-2F56533546BB} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {09EEC63B-21B8-4656-86A9-CCDD9C10A77F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-04] (Google Inc.)
Task: {3300F4CE-D879-4D35-8449-19AFCAB8A938} - System32\Tasks\WSE_Taplika => C:\Users\Dad\AppData\Roaming\WSE_TA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {346B439C-CE11-4CE0-B14C-D2FD4E18F124} - System32\Tasks\{1DD8B5E2-C122-4D1F-9758-9B0F5D4479E4} => pcalua.exe -a "C:\Users\Dad\Desktop\My Documents\mp160win64111ea23.exe" -d "C:\Users\Dad\Desktop\My Documents"
Task: {3EB83F69-6812-41E2-A848-7F3A8D689E89} - System32\Tasks\Wise Turbo Checker => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe
Task: {474B6DAF-131A-4A72-908B-2653EDE97FBF} - System32\Tasks\ArcadeGiant Updater => C:\Users\Dad\AppData\Local\ArcadeGiant\updater.exe [2015-02-03] (ArcadeGiant) <==== ATTENTION
Task: {490D819C-47D5-456C-A5EB-EEFBD6B58C82} - System32\Tasks\{62ACF029-05DB-43E9-B5E0-E093E965ED01} => C:\Program Files (x86)\Paltalk Messenger\paltalk.exe [2014-06-24] (AVM Software Inc.)
Task: {57F10B8A-E6DC-41AF-836F-3D3323A974EC} - System32\Tasks\{8438242B-619B-42CD-9AD1-2D389FF75225} => C:\Program Files (x86)\Paltalk Messenger\paltalk.exe [2014-06-24] (AVM Software Inc.)
Task: {65FBC813-8ECD-4300-99D3-4822AFCDAFE9} - System32\Tasks\{F2D720B6-011A-46ED-9209-2320052E5916} => pcalua.exe -a C:\PROGRA~2\Yahoo!\MESSEN~1\UNWISE.EXE -c /U C:\PROGRA~2\Yahoo!\MESSEN~1\INSTALL.LOG
Task: {89903DAE-62F9-4E24-BF41-F181F8031DD0} - System32\Tasks\AgSupport => Rundll32.exe C:\Users\Dad\AppData\Local\ARCADE~1\AgHelp.dll,Start
Task: {8C25C726-0EDD-419C-ABAE-AB81DD4A8954} - System32\Tasks\{DF80F471-10C4-4247-BCB7-5B67BA005FD2} => pcalua.exe -a C:\Users\Dad\Desktop\ts_webcam.exe -d C:\Users\Dad\Desktop
Task: {8D943107-6A50-440B-8E05-7B77AD0A1BEB} - System32\Tasks\{D9E1C870-B7E8-4995-8A98-D579504F6B41} => C:\Program Files (x86)\Paltalk Messenger\paltalk.exe [2014-06-24] (AVM Software Inc.)
Task: {91183DFD-7C1C-4471-B424-93FFA034740B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001UA => C:\Users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe [2015-02-03] (Google Inc.)
Task: {AE3C4923-DF05-46BF-9F7D-71972FD7EF73} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-03] (Adobe Systems Incorporated)
Task: {B0C3D0A2-E90E-41D9-A2AA-D31480DA3178} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-04] (Google Inc.)
Task: {B8D04CC6-6343-45C9-B405-F55D65E7D99C} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {CB7581B8-8545-4786-B62C-1567DBFA5960} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
Task: {CE4612D6-865E-46E6-A8C8-E78BF08ACC3D} - System32\Tasks\NBAgent => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
Task: {E6392F7E-8094-4810-A3A2-612265F0F48F} - System32\Tasks\{F126331D-C6F2-47BE-94F5-C17820994183} => pcalua.exe -a "C:\Program Files (x86)\NCH Software\Recordpad\uninst.exe"
Task: {E738236C-04D2-4CBD-818D-A308E1376E2E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001Core => C:\Users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe [2015-02-03] (Google Inc.)
Task: {ED36A8FB-B1CF-421E-8C67-F352A7A69286} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {F4FE48D0-691E-474D-9BF8-E1EE2DC18853} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {FF5AE516-004E-406B-8236-DF11EE525F5D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-07-23] (Piriform Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001Core.job => C:\Users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001UA.job => C:\Users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe
Task: C:\Windows\Tasks\WSE_Taplika.job => C:\Users\Dad\AppData\Roaming\WSE_TA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Behringer UFX 1394 Control Panel.lnk => C:\Windows\pss\Behringer UFX 1394 Control Panel.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Dad^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Dad^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk => C:\Windows\pss\Logitech . Product Registration.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Dad^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PalTalk.lnk => C:\Windows\pss\PalTalk.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: ConduitFloatingPlugin_lcnnhcneegeeojhgpfijnlnocjdmlaon => "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Dad\AppData\Roaming\ValueApps\CH\TBVerifier.dll",RunConduitFloatingPlugin lcnnhcneegeeojhgpfijnlnocjdmlaon
MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
MSCONFIG\startupreg: Hotkey Utility => C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: InstaLAN => "C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" startup
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: Messenger (Yahoo!) => "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
MSCONFIG\startupreg: Obrona Block Ads => "C:\Users\Dad\AppData\Local\Obrona Block Ads\ObronaBlockAds.exe" --hidden
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
MSCONFIG\startupreg: smoother => C:\Users\Dad\AppData\Roaming\Booster-Web\Booster-Web-Installer.exe
MSCONFIG\startupreg: SoftonicAssistant => "C:\Users\Dad\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe"
MSCONFIG\startupreg: SpybotSD TeaTimer => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-2107755742-302254199-1763176924-500 - Administrator - Disabled)
Dad (S-1-5-21-2107755742-302254199-1763176924-1001 - Administrator - Enabled) => C:\Users\Dad
Guest (S-1-5-21-2107755742-302254199-1763176924-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2107755742-302254199-1763176924-1003 - Limited - Enabled)

==================== Faulty Device Manager Devices =============

Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Microsoft Teredo Tunneling Adapter #2
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

==================== Event log errors: =========================

Application errors:
Error: (02/03/2015 10:27:06 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 10:26:27 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe" ; Description = Revo Uninstaller Pro's restore point - QuickTime 2015 Packages; Error = 0x8007043c).

Error: (02/03/2015 10:25:36 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/03/2015 10:21:31 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 10:19:44 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
This is often caused by incorrect security settings in either the writer or requestor process.

Gathering Writer Data

Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {baae700c-cc61-4732-9a8c-1e02bd7b1d13}

Error: (02/03/2015 10:19:10 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
This is often caused by incorrect security settings in either the writer or requestor process.

Gathering Writer Data

Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {baae700c-cc61-4732-9a8c-1e02bd7b1d13}

Error: (02/03/2015 09:24:22 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: dsisetup464480652.exe, version:, time stamp: 0x2a425e19
Faulting module name: dsisetup464480652.exe, version:, time stamp: 0x2a425e19
Exception code: 0xc0000005
Fault offset: 0x00002810
Faulting process id: 0x1d18
Faulting application start time: 0xdsisetup464480652.exe0
Faulting application path: dsisetup464480652.exe1
Faulting module path: dsisetup464480652.exe2
Report Id: dsisetup464480652.exe3

Error: (02/03/2015 04:33:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version:, time stamp: 0x54c1f9f3
Faulting module name: mozalloc.dll, version:, time stamp: 0x54c1f224
Exception code: 0x80000003
Fault offset: 0x00001425
Faulting process id: 0x59c
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3

Error: (02/02/2015 08:46:46 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Information only.
Error: The server returned an invalid or unrecognized response
ErrorCode: 14007(0x36b7).

Error: (02/02/2015 08:30:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

System errors:
Error: (02/03/2015 10:27:42 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:

Error: (02/03/2015 10:27:42 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:

Error: (02/03/2015 10:27:42 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:

Error: (02/03/2015 10:27:34 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:

Error: (02/03/2015 10:27:34 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:

Error: (02/03/2015 10:27:34 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:

Error: (02/03/2015 10:27:28 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:

Error: (02/03/2015 10:27:28 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:

Error: (02/03/2015 10:27:28 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:

Error: (02/03/2015 10:25:40 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:

Microsoft Office Sessions:
Error: (02/03/2015 10:27:06 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 10:26:27 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe" Revo Uninstaller Pro's restore point - QuickTime 2015 Packages0x8007043c

Error: (02/03/2015 10:25:36 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Dad\Desktop\esetsmartinstaller_enu.exe

Error: (02/03/2015 10:21:31 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 10:19:44 AM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.

Gathering Writer Data

Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {baae700c-cc61-4732-9a8c-1e02bd7b1d13}

Error: (02/03/2015 10:19:10 AM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.

Gathering Writer Data

Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {baae700c-cc61-4732-9a8c-1e02bd7b1d13}

Error: (02/03/2015 09:24:22 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: dsisetup464480652.exe0.0.0.02a425e19dsisetup464480652.exe0.0.0.02a425e19c0000005000028101d1801d03fc5737b318eC:\Users\Dad\AppData\Local\dsisetup464480652.exeC:\Users\Dad\AppData\Local\dsisetup464480652.exeba6f92f1-abb8-11e4-a7fe-02060d5d6465

Error: (02/03/2015 04:33:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe35.0.1.550054c1f9f3mozalloc.dll35.0.1.550054c1f224800000030000142559c01d03f9cba71a908C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll2556d749-ab90-11e4-a7fe-02060d5d6465

Error: (02/02/2015 08:46:46 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Error: The server returned an invalid or unrecognized response
ErrorCode: 14007(0x36b7).

Error: (02/02/2015 08:30:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 15%
Total physical RAM: 6048.28 MB
Available physical RAM: 5106.27 MB
Total Pagefile: 12094.74 MB
Available Pagefile: 11220.72 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (Gateway) (Fixed) (Total:918.41 GB) (Free:807.56 GB) NTFS
Drive d: (MAN_OF_STEEL) (CDROM) (Total:7.57 GB) (Free:0 GB) UDF
Drive k: (FreeAgent GoFlex Drive) (Fixed) (Total:465.76 GB) (Free:0.04 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 5D81C09C)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=918.4 GB) - (Type=07 NTFS)

Disk: 1 (Size: 465.8 GB) (Disk ID: 4E80EAC4)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by Dad (administrator) on BRIDGES1 on 03-02-2015 10:51:31
Running from C:\Users\Dad\Desktop\FRST-OlderVersion
Loaded Profiles: Dad (Available profiles: Dad)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Taplika)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\RunOnce: [WSE_Taplika] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Dad\AppData\Roaming\WSE_Taplika\UpdateProc\bkup.dat"
HKLM-x32\...\RunOnce: [DelTr96190] => cmd.exe /c rd /s /q "C:\Users\Dad\AppData\Roaming\WSE_Taplika"
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Run: [GoogleChromeAutoLaunch_C1DAAF30A00C843105EF5E39636EB999] => C:\Users\Dad\AppData\Local\Taplika\Application\taplika.exe [754176 2014-11-06] ()
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Run: [Google Update] => C:\Users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2015-02-03] (Google Inc.)
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Run: [Google+ Auto Backup] => C:\Users\Dad\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [3746120 2014-08-12] (Google Inc.)
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [WSE_Taplika] => [X]
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [DelTr96190] => cmd.exe /c rd /s /q "C:\Users\Dad\AppData\Roaming\WSE_Taplika"
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [ArcadeGiant508] => cmd.exe /c rmdir "C:\Users\Dad\AppData\Local\ArcadeGiant" /s /q
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [ArcadeGiant120] => cmd.exe /s /c reg delete "HKCU\Software\AppDataLow\ArcadeGiant" /f
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MountPoints2: {474142ab-da60-11e1-b2fb-e840f20c0b8d} - J:\EasySuite.exe
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MountPoints2: {474142ae-da60-11e1-b2fb-e840f20c0b8d} - E:\EasySuite.exe
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MountPoints2: {474142b1-da60-11e1-b2fb-e840f20c0b8d} - E:\EasySuite.exe
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1me10IE10ENUS/MSN_WCP
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {4C4C7AAB-5854-4241-A414-E2F1EF119C4A} URL = http://www.dnsbasic.com/?prt=DNSBASIC111&sp=&keywords={searchTerms}
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer]
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FF ProfilePath: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396
FF DefaultSearchEngine: Taplika
FF SearchEngineOrder.1: Yahoo
FF SearchEngineOrder.2:
FF SelectedSearchEngine: Taplika
FF Homepage: hxxp://taplika.com/?f=1&a=tlk_dwndlm_15_06_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtBtD0CtD0Bzz0D0FyE0DtAtN0D0Tzu0StCtCtBzytN1L2XzutAtFyBtFtBtFtDtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StByD0AtDtAyEyBzytGzyyD0F0FtG0Ezy0F0BtG0EyCtA0BtGyCzytB0ByC0AtByBtDtA0A0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyB0FyCzz0E0AtDtG0AzyyB0CtGyE0C0C0BtGzy0Ezy0FtGyEyByCyEtCtCyD0AtDtCyEtA2Q&cr=1534779659&ir=
FF NetworkProxy: "type", 4
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2107755742-302254199-1763176924-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Dad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKU\S-1-5-21-2107755742-302254199-1763176924-1001: @talk.google.com/O1DPlugin -> C:\Users\Dad\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKU\S-1-5-21-2107755742-302254199-1763176924-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Dad\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-2107755742-302254199-1763176924-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Dad\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Dad\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Dad\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\searchplugins\Taplika.xml
FF Extension: Booster Web - C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\Extensions\jid1-U7omKQ6kQfxMaQ@jetpack [2015-01-28]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-26]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-08-01]
FF Extension: No Name - C:\PROGRA~2\MOZILL~1\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
StartMenuInternet: FIREFOX.EXE - firefox.exe

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 AffinegyService; C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe [563104 2011-11-14] (Affinegy, Inc.)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-12] (DEVGURU Co., LTD.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 cleanhlp; C:\Users\Dad\Desktop\bin\cleanhlp64.sys [57024 2015-02-02] (Emsisoft GmbH)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-30] (Malwarebytes Corporation)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [22528 2011-08-02] (Apple Inc.) [File not signed]
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-11] (Microsoft Corporation)
S3 RTL8192su; system32\DRIVERS\RTL8192su.sys [X]
S3 sxuptp; system32\DRIVERS\sxuptp.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 09:24 - 2015-02-03 09:24 - 00022528 _____ () C:\Users\Dad\AppData\Local\dsisetup464480652.exe
2015-02-03 08:28 - 2015-02-03 09:33 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001UA.job
2015-02-03 08:28 - 2015-02-03 08:33 - 00000848 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001Core.job
2015-02-03 08:28 - 2015-02-03 08:28 - 00880784 _____ (Google Inc.) C:\Users\Dad\Desktop\GoogleVoiceAndVideoSetup.exe
2015-02-03 08:28 - 2015-02-03 08:28 - 00003870 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001UA
2015-02-03 08:23 - 2015-02-03 10:23 - 00000284 _____ () C:\Windows\Tasks\WSE_Taplika.job
2015-02-03 08:23 - 2015-02-03 09:24 - 00000000 ____D () C:\Users\Dad\AppData\Local\Taplika
2015-02-03 08:23 - 2015-02-03 08:23 - 00003220 _____ () C:\Windows\System32\Tasks\WSE_Taplika
2015-02-03 08:23 - 2015-02-03 08:23 - 00001852 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk
2015-02-03 08:23 - 2015-02-03 08:23 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Taplika
2015-02-03 08:23 - 2015-02-03 08:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-02-03 08:22 - 2015-02-03 08:23 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\WSE_Taplika
2015-02-03 08:22 - 2015-02-03 08:23 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2015-02-03 08:22 - 2015-02-03 08:22 - 00003128 _____ () C:\Windows\System32\Tasks\ArcadeGiant Updater
2015-02-03 08:21 - 2015-02-03 08:22 - 00000000 ____D () C:\Users\Dad\AppData\Local\ArcadeGiant
2015-02-03 08:21 - 2015-02-03 08:21 - 41945432 _____ (Apple Inc.) C:\Users\Dad\Downloads\QuickTime Setup [1].exe
2015-02-03 08:21 - 2015-02-03 08:21 - 00003254 _____ () C:\Windows\System32\Tasks\AgSupport
2015-02-02 20:04 - 2015-02-02 20:04 - 00037714 _____ () C:\Windows\SysWOW64\Result.txt
2015-02-02 20:03 - 2015-02-02 20:03 - 00401920 _____ (Farbar) C:\Users\Dad\Desktop\MiniToolBox.exe
2015-02-02 19:28 - 2015-02-02 19:28 - 00000000 ____D () C:\Program Files (x86)\ESET
2015-02-02 19:27 - 2015-02-02 19:27 - 02347384 _____ (ESET) C:\Users\Dad\Desktop\esetsmartinstaller_enu.exe
2015-02-02 19:18 - 2015-02-02 19:18 - 00001048 _____ () C:\Users\Dad\Desktop\fixlist-1.txt
2015-02-02 14:03 - 2015-02-02 14:03 - 00004176 _____ () C:\Users\Dad\Desktop\a2scan_150202-120104.txt
2015-02-02 11:58 - 2015-02-02 11:58 - 00000694 _____ () C:\Users\Dad\Desktop\Start Emsisoft Emergency Kit.lnk
2015-02-02 11:57 - 2015-02-02 14:03 - 00000000 ____D () C:\Users\Dad\Desktop\bin
2015-02-02 11:57 - 2015-02-02 00:13 - 00432328 ____N (Emsisoft GmbH) C:\Users\Dad\Desktop\Start Emergency Kit Scanner.exe
2015-02-02 11:57 - 2015-02-02 00:13 - 00432328 ____N (Emsisoft GmbH) C:\Users\Dad\Desktop\Start Commandline Scanner.exe
2015-02-02 11:57 - 2015-02-02 00:13 - 00423064 ____N (Emsisoft GmbH) C:\Users\Dad\Desktop\Start BlitzBlank.exe
2015-02-02 11:57 - 2015-02-02 00:13 - 00004079 ____N () C:\Users\Dad\Desktop\readme.txt
2015-02-02 11:56 - 2015-02-02 11:57 - 170235400 _____ () C:\Users\Dad\Desktop\EmsisoftEmergencyKit.exe
2015-02-02 11:36 - 2015-02-03 10:51 - 00000000 ____D () C:\Users\Dad\Desktop\FRST-OlderVersion
2015-01-30 20:58 - 2015-01-30 20:58 - 02194432 _____ () C:\Users\Dad\Desktop\AdwCleaner.exe
2015-01-30 20:48 - 2015-02-02 11:33 - 00001237 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2015-01-30 20:48 - 2015-01-30 20:48 - 00000000 ____D () C:\Users\Dad\AppData\Local\VS Revo Group
2015-01-30 20:48 - 2015-01-30 20:48 - 00000000 ____D () C:\ProgramData\VS Revo Group
2015-01-30 20:48 - 2015-01-30 20:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2015-01-30 20:48 - 2015-01-30 20:48 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-01-30 20:48 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2015-01-30 20:47 - 2015-01-30 20:47 - 10801480 _____ (VS Revo Group ) C:\Users\Dad\Desktop\RevoUninProSetup.exe
2015-01-28 19:58 - 2015-01-28 19:58 - 00000567 _____ () C:\Users\Dad\Desktop\aswMBR.txt
2015-01-28 19:56 - 2015-02-02 11:36 - 02131456 _____ (Farbar) C:\Users\Dad\Desktop\FRST64.exe
2015-01-28 19:56 - 2015-01-28 19:56 - 05198336 _____ (AVAST Software) C:\Users\Dad\Desktop\aswMBR.exe
2015-01-28 19:56 - 2015-01-28 19:56 - 00055206 _____ () C:\Users\Dad\Desktop\FRST.txt
2015-01-28 19:56 - 2015-01-28 19:56 - 00027818 _____ () C:\Users\Dad\Desktop\Addition.txt
2015-01-28 19:54 - 2015-01-28 19:54 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-BRIDGES1-Windows-7-Home-Premium-(64-bit).dat
2015-01-28 19:53 - 2015-01-28 19:53 - 00002242 _____ () C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2015-01-28 19:52 - 2015-01-28 19:52 - 04712336 _____ () C:\Users\Dad\Desktop\tweaking.com_registry_backup_setup.exe
2015-01-28 19:51 - 2015-01-28 19:51 - 00000000 ____D () C:\ProgramData\Winferno
2015-01-28 19:47 - 2015-01-26 02:52 - 00272296 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2015-01-28 19:47 - 2015-01-26 02:52 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2015-01-28 19:47 - 2015-01-26 02:52 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2015-01-28 19:46 - 2015-01-28 09:45 - 00387200 _____ (Catalytix Web Services) C:\Windows\system32\CatWSPrx64.dll
2015-01-28 19:46 - 2015-01-28 09:45 - 00330808 _____ (Catalytix Web Services) C:\Windows\SysWOW64\CatWSPrx.dll
2015-01-28 19:19 - 2015-01-28 19:19 - 02930092 _____ (Gisburne Media) C:\Users\Dad\Desktop\kbplayer.exe
2015-01-28 19:19 - 2015-01-28 19:19 - 00000000 ____D () C:\Program Files (x86)\Karaoke Builder Player
2015-01-28 18:15 - 2015-01-28 18:15 - 00000000 ____D () C:\ProgramData\fpebkpiipncfojhgaddgnofadahpmcjm
2015-01-28 18:15 - 2015-01-28 18:15 - 00000000 ____D () C:\Program Files (x86)\52df7d05-df7b-4abf-8cb0-684d1a20a3e7
2015-01-28 17:54 - 2015-01-28 17:54 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Publish Providers
2015-01-28 17:35 - 2015-01-28 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-01-28 17:35 - 2015-01-28 17:54 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Sony
2015-01-28 17:35 - 2015-01-28 17:50 - 00000000 ____D () C:\Users\Dad\AppData\Local\Sony
2015-01-28 17:35 - 2015-01-28 17:35 - 00000000 ____D () C:\ProgramData\Sony
2015-01-28 17:35 - 2015-01-28 17:35 - 00000000 ____D () C:\Program Files (x86)\Sony
2015-01-28 09:34 - 2015-01-28 09:34 - 00389912 _____ (AnalogX, LLC) C:\Users\Dad\Downloads\autotune [1].exe
2015-01-28 09:21 - 2015-01-28 09:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voxengo
2015-01-28 09:21 - 2015-01-28 09:26 - 00000000 ____D () C:\Program Files\Voxengo
2015-01-28 09:21 - 2015-01-28 09:26 - 00000000 ____D () C:\Program Files\Common Files\VST3
2015-01-28 09:21 - 2015-01-28 09:21 - 00000000 ____D () C:\Program Files\Common Files\Steinberg
2015-01-27 18:34 - 2015-01-27 18:34 - 00001976 _____ () C:\Users\Public\Desktop\Samsung Kies 3.lnk
2015-01-26 21:26 - 2015-02-03 10:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-25 14:50 - 2015-01-25 14:50 - 00003106 _____ () C:\Windows\System32\Tasks\{DF80F471-10C4-4247-BCB7-5B67BA005FD2}
2015-01-24 23:58 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2015-01-15 18:43 - 2014-12-18 21:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-15 18:43 - 2014-12-18 19:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-15 18:43 - 2014-12-11 11:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-15 18:43 - 2014-12-05 22:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-15 18:43 - 2014-12-05 21:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-15 18:43 - 2014-12-05 21:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-15 18:42 - 2014-12-11 23:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-15 18:42 - 2014-12-11 23:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-15 18:42 - 2014-12-11 23:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-15 18:42 - 2014-12-11 23:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-15 18:42 - 2014-12-11 23:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-15 18:42 - 2014-12-11 23:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-15 18:42 - 2014-12-11 23:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-15 18:40 - 2015-01-15 18:40 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\ESET
2015-01-15 18:40 - 2015-01-15 18:40 - 00000000 ____D () C:\Users\Dad\AppData\Local\ESET
2015-01-07 16:10 - 2015-01-07 16:22 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-01-07 12:03 - 2015-01-07 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2015-01-05 12:21 - 2014-12-12 23:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-01-05 12:21 - 2014-12-12 21:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-01-04 15:25 - 2014-10-17 20:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-01-04 15:25 - 2014-10-17 19:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2015-01-04 15:24 - 2014-11-26 19:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-01-04 15:24 - 2014-11-26 19:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-01-04 15:24 - 2014-11-21 21:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-01-04 15:24 - 2014-11-21 21:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-01-04 15:24 - 2014-11-21 21:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-01-04 15:24 - 2014-11-21 20:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-01-04 15:24 - 2014-11-21 20:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-01-04 15:24 - 2014-11-21 20:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-01-04 15:24 - 2014-11-21 20:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-01-04 15:24 - 2014-11-21 20:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-01-04 15:24 - 2014-11-21 20:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-01-04 15:24 - 2014-11-21 20:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-01-04 15:24 - 2014-11-21 20:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-01-04 15:24 - 2014-11-21 20:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-01-04 15:24 - 2014-11-21 20:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-01-04 15:24 - 2014-11-21 20:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-01-04 15:24 - 2014-11-21 20:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-01-04 15:24 - 2014-11-21 20:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-01-04 15:24 - 2014-11-21 20:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-01-04 15:24 - 2014-11-21 20:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-01-04 15:24 - 2014-11-21 20:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-01-04 15:24 - 2014-11-21 20:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-01-04 15:24 - 2014-11-21 20:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-01-04 15:24 - 2014-11-21 20:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-01-04 15:24 - 2014-11-21 20:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-01-04 15:24 - 2014-11-21 20:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-01-04 15:24 - 2014-11-21 20:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-01-04 15:24 - 2014-11-21 20:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-01-04 15:24 - 2014-11-21 20:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-01-04 15:24 - 2014-11-21 19:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-01-04 15:24 - 2014-11-21 19:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-01-04 15:24 - 2014-11-21 19:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-01-04 15:24 - 2014-11-21 19:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-01-04 15:24 - 2014-11-21 19:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-01-04 15:24 - 2014-11-21 19:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-01-04 15:24 - 2014-11-21 19:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-01-04 15:24 - 2014-11-21 19:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-01-04 15:24 - 2014-11-21 19:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-01-04 15:24 - 2014-11-21 19:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-01-04 15:24 - 2014-11-21 19:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-01-04 15:24 - 2014-11-21 19:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-01-04 15:24 - 2014-11-21 19:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-01-04 15:24 - 2014-11-21 19:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-01-04 15:24 - 2014-11-21 19:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-01-04 15:24 - 2014-11-21 19:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-01-04 15:24 - 2014-11-21 19:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-01-04 15:24 - 2014-11-21 19:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-01-04 15:24 - 2014-11-21 19:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-01-04 15:24 - 2014-11-21 19:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-01-04 15:24 - 2014-11-21 19:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-01-04 15:24 - 2014-11-21 19:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-01-04 15:24 - 2014-11-21 19:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-01-04 15:24 - 2014-11-21 18:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-01-04 15:24 - 2014-11-21 18:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-01-04 15:23 - 2014-11-10 21:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-01-04 15:23 - 2014-11-10 20:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-01-04 15:22 - 2014-10-29 20:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2015-01-04 15:22 - 2014-10-29 19:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2015-01-04 15:22 - 2014-10-02 20:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-01-04 15:22 - 2014-10-02 20:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-01-04 15:22 - 2014-10-02 20:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-01-04 15:22 - 2014-10-02 20:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-01-04 15:22 - 2014-10-02 20:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-01-04 15:22 - 2014-10-02 19:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2015-01-04 15:22 - 2014-10-02 19:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2015-01-04 15:22 - 2014-10-02 19:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2015-01-04 15:22 - 2014-10-02 19:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2015-01-04 15:22 - 2014-10-02 19:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2015-01-04 15:19 - 2014-11-07 21:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-01-04 15:19 - 2014-11-07 20:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-01-04 15:12 - 2015-01-04 15:13 - 00000340 _____ () C:\Windows\LkmdfCoInst.log
2015-01-04 11:02 - 2015-01-04 11:02 - 00000000 __SHD () C:\Users\Dad\AppData\Local\EmieBrowserModeList

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 10:51 - 2014-10-14 12:26 - 00000000 ____D () C:\FRST
2015-02-03 10:30 - 2009-07-13 23:13 - 00783464 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-03 10:21 - 2014-10-16 10:25 - 00155336 _____ () C:\Windows\PFRO.log
2015-02-03 10:21 - 2014-09-04 19:35 - 00008850 _____ () C:\Windows\setupact.log
2015-02-03 10:21 - 2014-02-11 16:00 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-03 10:21 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-03 10:20 - 2014-01-07 20:18 - 01421856 _____ () C:\Windows\WindowsUpdate.log
2015-02-03 10:16 - 2012-03-31 17:15 - 00000000 ____D () C:\Users\Dad\AppData\Local\Apple Computer
2015-02-03 09:43 - 2014-08-22 20:33 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-03 09:43 - 2013-01-04 20:52 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-03 09:24 - 2014-12-02 22:37 - 00000010 _____ () C:\Users\Dad\AppData\Local\DSI.DAT
2015-02-03 09:24 - 2012-04-06 02:18 - 00000000 ____D () C:\Users\Dad\AppData\Local\CrashDumps
2015-02-03 09:23 - 2014-02-13 10:52 - 00000136 _____ () C:\Users\Dad\AppData\Roaming\WB.CFG
2015-02-03 09:19 - 2014-02-09 16:47 - 03417600 ___SH () C:\Users\Dad\Desktop\Thumbs.db
2015-02-03 08:40 - 2014-02-13 10:57 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
2015-02-03 08:40 - 2012-10-03 00:44 - 00000000 ____D () C:\Users\Dad\AppData\Local\Google
2015-02-03 08:28 - 2012-10-03 00:44 - 00003474 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001Core
2015-02-03 08:28 - 2012-03-29 11:48 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Mozilla
2015-02-03 05:31 - 2014-11-09 11:54 - 00000000 ____D () C:\Users\Dad\AppData\Local\Adobe
2015-02-03 05:31 - 2014-08-22 20:33 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-03 05:31 - 2014-08-22 20:33 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-03 05:31 - 2014-08-22 20:33 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-02 20:37 - 2009-07-13 22:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-02 20:37 - 2009-07-13 22:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-02 14:00 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-02-02 11:29 - 2014-01-04 07:24 - 00000398 _____ () C:\Windows\Tasks\Wise Turbo Checker.job
2015-01-30 21:02 - 2014-10-16 10:35 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-30 21:00 - 2014-10-15 08:47 - 00000000 ____D () C:\AdwCleaner
2015-01-30 20:56 - 2012-07-11 11:56 - 00000000 ____D () C:\Program Files (x86)\Yahoo!
2015-01-30 20:55 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2015-01-30 20:49 - 2013-01-04 20:52 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-28 22:52 - 2012-03-29 14:47 - 00000000 ____D () C:\ProgramData\Yahoo!
2015-01-28 22:51 - 2011-11-08 02:41 - 00000000 ____D () C:\ProgramData\Norton
2015-01-28 21:31 - 2014-12-04 13:31 - 00000000 ____D () C:\Users\Dad\Documents\Audio Recorder for Free
2015-01-28 21:31 - 2014-12-02 19:16 - 00000000 ____D () C:\Users\Dad\Desktop\My Recordings
2015-01-28 19:46 - 2014-10-16 15:37 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-28 19:19 - 2014-12-09 16:32 - 00001112 _____ () C:\Users\Public\Desktop\Karaoke Builder Player.lnk
2015-01-28 19:11 - 2011-11-08 02:40 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-28 18:47 - 2014-05-23 02:40 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2015-01-28 18:47 - 2009-07-13 22:45 - 00271752 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-28 14:51 - 2012-03-29 14:02 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2015-01-28 09:28 - 2013-12-22 18:31 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Samsung
2015-01-28 09:28 - 2013-12-04 21:28 - 00000000 ____D () C:\Program Files (x86)\Samsung
2015-01-27 14:28 - 2014-02-08 19:02 - 00000000 ____D () C:\Users\Dad\Desktop\Samsung pics
2015-01-27 08:06 - 2014-12-09 11:08 - 00000000 ____D () C:\Users\Dad\Desktop\CDG.zip files
2015-01-26 05:26 - 2014-09-14 12:12 - 00000000 ____D () C:\Users\Dad\Desktop\CDG
2015-01-26 02:54 - 2013-10-17 16:34 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-26 02:52 - 2014-10-16 15:38 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-26 01:04 - 2014-08-04 23:52 - 02162696 _____ () C:\console.log
2015-01-25 14:57 - 2014-01-14 12:38 - 00059600 _____ () C:\Users\Dad\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-24 22:59 - 2014-11-03 14:51 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dwyco CDC-X
2015-01-16 03:03 - 2013-08-16 02:00 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-16 03:00 - 2012-03-30 20:51 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-15 18:34 - 2012-07-18 19:56 - 00001945 _____ () C:\Windows\epplauncher.mif
2015-01-08 09:55 - 2010-11-20 21:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-07 17:35 - 2014-10-16 10:35 - 00096472 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-05 18:25 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\rescache
2015-01-05 15:49 - 2013-08-07 09:19 - 00000000 ___RD () C:\Users\Dad\Dropbox
2015-01-05 15:49 - 2013-07-07 09:31 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Dropbox
2015-01-04 15:35 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-01-04 15:12 - 2012-03-29 12:09 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2015-01-04 15:11 - 2012-03-29 11:32 - 00000000 ____D () C:\Users\Dad
2015-01-04 15:08 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2015-01-04 15:07 - 2015-01-03 16:38 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Avg_Update_1014av
2015-01-04 15:07 - 2015-01-03 16:38 - 00000000 ____D () C:\ProgramData\Avg_Update_1014av
2015-01-04 15:07 - 2015-01-03 16:31 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-04 15:07 - 2014-12-09 16:32 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Karaoke Builder
2015-01-04 15:07 - 2014-10-14 12:20 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2015-01-04 15:07 - 2014-10-14 12:20 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2015-01-04 15:07 - 2014-08-22 12:20 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-01-04 15:07 - 2014-07-04 13:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Peace Art App
2015-01-04 15:07 - 2014-05-23 02:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec
2015-01-04 15:07 - 2014-01-10 23:00 - 00000000 ____D () C:\Program Files (x86)\Paltalk Messenger
2015-01-04 15:07 - 2013-04-29 03:49 - 00000000 ____D () C:\Program Files\Bonjour
2015-01-04 15:07 - 2013-04-29 03:49 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2015-01-04 15:07 - 2012-08-19 16:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
2015-01-04 15:07 - 2012-04-05 11:30 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2015-01-04 15:07 - 2012-02-06 05:15 - 00000000 ____D () C:\ProgramData\Temp
2015-01-04 15:07 - 2011-11-08 02:31 - 00000000 ___HD () C:\ProgramData\{37272A44-A110-4EB7-A5EF-88B2A05A08C4}
2015-01-04 15:07 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\servicing
2015-01-04 15:07 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-01-04 15:06 - 2014-08-22 12:21 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2015-01-04 15:06 - 2013-03-16 02:01 - 00000000 __SHD () C:\Windows\SysWOW64\%APPDATA%
2015-01-04 15:06 - 2012-04-06 02:18 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2015-01-04 15:06 - 2011-11-08 02:41 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\winrm
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\WCN
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\slmgr
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\winrm
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\WCN
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\slmgr
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2015-01-04 15:06 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\SysWOW64\WindowsPowerShell
2015-01-04 15:06 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\system32\WindowsPowerShell
2015-01-04 15:06 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Web
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Vss
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\spp
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Speech
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\NetworkList
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Msdtc
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\InstallShield
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\IME
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\com
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\sysprep
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\spp
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\spool
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Speech
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\SMI
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\oobe
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\NetworkList
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\registration
2015-01-04 15:05 - 2014-10-19 15:30 - 00000000 ____D () C:\Users\Dad\Documents\Dwyco
2015-01-04 15:05 - 2014-10-15 08:54 - 00000000 ____D () C:\Windows\ERUNT
2015-01-04 15:05 - 2014-05-02 02:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-01-04 15:05 - 2014-04-18 18:06 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information
2015-01-04 15:05 - 2013-03-16 02:01 - 00000000 __SHD () C:\Windows\system32\%APPDATA%
2015-01-04 15:05 - 2012-02-06 04:53 - 00000000 ____D () C:\Windows\NAPP_Dism_Log
2015-01-04 15:05 - 2011-11-08 02:41 - 00000000 ____D () C:\Windows\system32\Macromed
2015-01-04 15:05 - 2011-11-08 02:33 - 00000000 ____D () C:\Windows\es
2015-01-04 15:05 - 2011-11-08 02:31 - 00000000 ____D () C:\Windows\oem
2015-01-04 15:05 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\Performance
2015-01-04 15:05 - 2009-07-13 22:45 - 00000000 ____D () C:\Windows\Setup
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 __RSD () C:\Windows\Media
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\MUI
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Msdtc
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\migwiz
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\IME
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\com
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Speech
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\security
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\schemas
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Resources
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\PLA
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\IME
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Help
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Globalization
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Branding
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\AppCompat
2015-01-04 15:04 - 2014-12-02 18:54 - 00000000 ____D () C:\Program Files (x86)\PreSonus
2015-01-04 15:04 - 2014-10-16 10:35 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-04 15:04 - 2014-08-01 23:23 - 00000000 ____D () C:\Program Files\Logitech
2015-01-04 15:04 - 2014-04-18 20:20 - 00000000 ____D () C:\Program Files (x86)\Canon
2015-01-04 15:04 - 2014-04-18 18:05 - 00000000 ___HD () C:\Program Files\CanonBJ
2015-01-04 15:04 - 2013-09-18 01:41 - 00000000 ____D () C:\Program Files\behringer
2015-01-04 15:04 - 2013-08-07 23:30 - 00000000 ____D () C:\Program Files (x86)\AVS4YOU
2015-01-04 15:04 - 2013-05-13 16:12 - 00000000 ____D () C:\Program Files (x86)\EPUBSOFT
2015-01-04 15:04 - 2013-04-29 09:46 - 00000000 ____D () C:\Program Files\iTunes
2015-01-04 15:04 - 2013-04-29 09:46 - 00000000 ____D () C:\Program Files\iPod
2015-01-04 15:04 - 2013-04-29 09:46 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-01-04 15:04 - 2013-03-16 02:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-01-04 15:04 - 2013-03-16 02:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-01-04 15:04 - 2012-10-20 15:41 - 00000000 ____D () C:\Program Files (x86)\Belkin
2015-01-04 15:04 - 2012-09-17 10:56 - 00000000 ____D () C:\Program Files (x86)\Outsim
2015-01-04 15:04 - 2012-09-17 10:50 - 00000000 ____D () C:\Program Files (x86)\Image-Line
2015-01-04 15:04 - 2012-04-15 16:50 - 00000000 ____D () C:\Program Files\Defraggler
2015-01-04 15:04 - 2012-04-15 16:49 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-04 15:04 - 2012-04-06 10:37 - 00000000 ____D () C:\Program Files (x86)\Freemake
2015-01-04 15:04 - 2012-04-06 02:06 - 00000000 ____D () C:\Program Files (x86)\Microsoft CAPICOM
2015-01-04 15:04 - 2012-04-05 11:35 - 00000000 __RHD () C:\MSOCache
2015-01-04 15:04 - 2012-04-05 11:30 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-01-04 15:04 - 2012-03-29 17:20 - 00000000 ____D () C:\Program Files (x86)\Logitech
2015-01-04 15:04 - 2012-03-29 15:08 - 00000000 ____D () C:\Program Files (x86)\The Anubis Group
2015-01-04 15:04 - 2012-03-29 12:09 - 00000000 ____D () C:\Program Files\Common Files\Logishrd
2015-01-04 15:04 - 2012-02-06 05:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2015-01-04 15:04 - 2012-02-06 05:15 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2015-01-04 15:04 - 2012-02-06 05:12 - 00000000 ____D () C:\Program Files\Realtek
2015-01-04 15:04 - 2012-02-06 05:10 - 00000000 ____D () C:\Program Files (x86)\Etron Technology
2015-01-04 15:04 - 2012-02-06 05:07 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-01-04 15:04 - 2012-02-06 04:58 - 00000000 ____D () C:\Program Files\Common Files\Intel
2015-01-04 15:04 - 2011-11-08 02:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-01-04 15:04 - 2011-11-08 02:32 - 00000000 ____D () C:\Program Files\Windows Live
2015-01-04 15:04 - 2011-11-08 02:32 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-01-04 15:04 - 2011-11-08 02:31 - 00000000 ____D () C:\Program Files\Gateway
2015-01-04 15:04 - 2011-11-08 02:31 - 00000000 ____D () C:\Program Files (x86)\Gateway
2015-01-04 15:04 - 2011-11-08 02:24 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-04 15:04 - 2011-11-08 02:24 - 00000000 ____D () C:\Program Files (x86)\Intel
2015-01-04 15:04 - 2011-11-08 02:15 - 00000000 ___HD () C:\OEM
2015-01-04 15:04 - 2011-08-17 21:01 - 00000000 ___HD () C:\dad
2015-01-04 15:04 - 2011-08-17 20:39 - 00000000 ____D () C:\C_
2015-01-04 15:04 - 2010-11-21 01:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Defender
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Reference Assemblies
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\MSBuild
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Microsoft Games
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\DVD Maker
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Windows NT
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Common Files\SpeechEngines
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files (x86)\Windows NT
2015-01-04 14:51 - 2015-01-03 16:34 - 00000000 ____D () C:\ProgramData\AVG2015

==================== Files in the root of some directories =======

2013-08-07 06:12 - 2014-11-16 00:53 - 0001181 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.1.txt
2013-08-07 06:12 - 2014-03-30 11:59 - 0000919 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.2.txt
2013-08-07 06:12 - 2014-03-29 18:54 - 0001181 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.3.txt
2013-08-07 06:12 - 2013-08-07 06:34 - 0000919 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.4.txt
2013-08-07 06:12 - 2013-08-07 06:12 - 0001181 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.5.txt
2013-08-07 06:12 - 2014-12-02 18:47 - 0000919 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.txt
2013-08-07 06:12 - 2014-12-02 18:47 - 0000000 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt
2012-05-12 15:58 - 2012-05-12 15:58 - 0024597 _____ () C:\Users\Dad\AppData\Roaming\UserTile.png
2014-09-01 02:18 - 2014-09-01 02:18 - 0001248 _____ () C:\Users\Dad\AppData\Roaming\UZNYUL
2014-02-13 10:52 - 2015-02-03 09:23 - 0000136 _____ () C:\Users\Dad\AppData\Roaming\WB.CFG
2014-09-01 02:18 - 2014-09-01 02:18 - 0002086 _____ () C:\Users\Dad\AppData\Roaming\WTPQZFD
2012-04-14 21:46 - 2014-01-03 22:33 - 0119296 _____ () C:\Users\Dad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-02 22:37 - 2015-02-03 09:24 - 0000010 _____ () C:\Users\Dad\AppData\Local\DSI.DAT
2015-02-03 09:24 - 2015-02-03 09:24 - 0022528 _____ () C:\Users\Dad\AppData\Local\dsisetup464480652.exe
2012-08-18 05:51 - 2012-08-18 05:51 - 0004028 _____ () C:\Users\Dad\AppData\Local\HWVendorDetection.log
2013-01-10 08:07 - 2013-01-10 08:07 - 0000866 _____ () C:\Users\Dad\AppData\Local\recently-used.xbel
2012-07-16 06:22 - 2014-01-11 09:02 - 0007629 _____ () C:\Users\Dad\AppData\Local\Resmon.ResmonCfg
2012-03-29 12:09 - 2012-03-29 12:09 - 0017408 _____ () C:\Users\Dad\AppData\Local\WebpageIcons.db
2013-04-11 00:27 - 2013-04-11 00:27 - 0000000 _____ () C:\ProgramData\2a3b3a3028372a59_c
2012-11-19 02:10 - 2012-11-19 02:10 - 0000105 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

Some content of TEMP:

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-10-16 09:14

==================== End Of Log ============================

2015-02-03, 21:32
also juliet i'm getting this popped up quite frequent...i think it was part of the quicktime i d'loaded and uninstalled earlier

there was a problem starting


the specified module could not be found

2015-02-03, 23:30
Don't know what your using for an antivirus but let me post info on some you might want to consider

http://1-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/8fj6i2U.png.pagespeed.ce.RUYs43FaJ5.pngavast! Free Anti-Virus (http://www.avast.com/en-gb/download-thank-you.php?product=FA-ONLINE&locale=en-gb) (free)
http://1-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/8fj6i2U.png.pagespeed.ce.RUYs43FaJ5.pngAvira AntiVir Personal - Free Antivirus (http://www.free-av.com/en/products/1/avira_antivir_personal__free_antivirus.html)
http://1-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/xUbJpW95.png.pagespeed.ic.Eg8QK7Uzqf.jpg (http://windows.microsoft.com/en-us/windows/security-essentials-all-versions) Microsoft Security Essentials (http://windows.microsoft.com/en-us/windows/security-essentials-all-versions) (free)
http://2-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/GzlsbnV.png.pagespeed.ce.SLxxSJVib_.png (http://www.eset.co.uk/Download/Software/Home) ESET NOD32 Anti-Virus (http://www.eset.co.uk/Download/Software/Home) (paid)
http://2-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/YARWD1t.png.pagespeed.ce.nvhmVeYDe3.png (http://www.kaspersky.co.uk/home-products) Kaspersky Anti-Virus (http://www.kaspersky.co.uk/home-products) (paid)
http://2-ps.googleusercontent.com/x/www.geekstogo.com/i.imgur.com/x7D2ig3K.png.pagespeed.ic.x4TC1AK8OX.jpgEmsisoft Internet Security (http://www.emsisoft.de/en/software/internetsecurity/) (paid)


Next, launch Notepad, (Start > Run, type in: notepad) copy and paste next present in the quotebox below in it: (don't forget to copy and paste REGEDIT4)


[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ConduitFloatingPlugin_lcnnhcneegeeojhgpfijnlnocjdmlaon]
"ConduitFloatingPlugin lcnnhcneegeeojhgpfijnlnocjdmlaon"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Obrona Block Ads]

Save this as fix.reg and change the "Save as type" to "All Files" and place it on your desktop. It should look like this: http://i204.photobucket.com/albums/bb106/Juliet702/regMiekie.png
Double-click on it and when it asks you if you want to merge the contents to the registry, click "Yes" or "OK". You should receive a message that it was successful. You may delete the file afterwards


Taplika (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Taplika) (Version: 31.0.1650.23 - Taplika) <==== ATTENTION!
The above entry should had been taken out using MBAM, we can go to add/remove programs list to uninstall/delete or run MBAM again (Updated first)

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


Task: {3300F4CE-D879-4D35-8449-19AFCAB8A938} - System32\Tasks\WSE_Taplika => C:\Users\Dad\AppData\Roaming\WSE_TA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {474B6DAF-131A-4A72-908B-2653EDE97FBF} - System32\Tasks\ArcadeGiant Updater => C:\Users\Dad\AppData\Local\ArcadeGiant\updater.exe [2015-02-03] (ArcadeGiant) <==== ATTENTION
Task: {89903DAE-62F9-4E24-BF41-F181F8031DD0} - System32\Tasks\AgSupport => Rundll32.exe C:\Users\Dad\AppData\Local\ARCADE~1\AgHelp.dll,Start
Task: C:\Windows\Tasks\WSE_Taplika.job => C:\Users\Dad\AppData\Roaming\WSE_TA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
C:\Users\Dad\AppData\Local\Obrona Block Ads\ObronaBlockAds.exe
HKLM-x32\...\RunOnce: [WSE_Taplika] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Dad\AppData\Roaming\WSE_Taplika\UpdateProc\bkup.dat"
HKLM-x32\...\RunOnce: [DelTr96190] => cmd.exe /c rd /s /q "C:\Users\Dad\AppData\Roaming\WSE_Taplika"
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Run: [GoogleChromeAutoLaunch_C1DAAF30A00C843105EF5E39636EB999] => C:\Users\Dad\AppData\Local\Taplika\Application\taplika.exe [754176 2014-11-06] ()
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [WSE_Taplika] => [X]
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [DelTr96190] => cmd.exe /c rd /s /q "C:\Users\Dad\AppData\Roaming\WSE_Taplika"
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [ArcadeGiant508] => cmd.exe /c rmdir "C:\Users\Dad\AppData\Local\ArcadeGiant" /s /q
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [ArcadeGiant120] => cmd.exe /s /c reg delete "HKCU\Software\AppDataLow\ArcadeGiant" /f
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF DefaultSearchEngine: Taplika
FF SearchEngineOrder.1: Yahoo
FF SelectedSearchEngine: Taplika
FF Homepage: hxxp://taplika.com/?f=1&a=tlk_dwndlm_15_06_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtBtD0CtD0Bzz0D0FyE0DtAtN0D0Tzu0StCtCtBzytN1L2XzutAtFyBtFtBtFtDtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StByD0AtDtAyEyBzytGzyyD0F0FtG0Ezy0F0BtG0EyCtA0BtGyCzytB0ByC0AtByBtDtA0A0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyB0FyCzz0E0AtDtG0AzyyB0CtGyE0C0C0BtGzy0Ezy0FtGyEyByCyEtCtCyD0AtDtCyEtA2Q&cr=1534779659&ir=
FF SearchPlugin: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\searchplugins\Taplika.xml
FF Extension: No Name - C:\PROGRA~2\MOZILL~1\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
2015-02-03 08:23 - 2015-02-03 10:23 - 00000284 _____ () C:\Windows\Tasks\WSE_Taplika.job
2015-02-03 08:23 - 2015-02-03 09:24 - 00000000 ____D () C:\Users\Dad\AppData\Local\Taplika
2015-02-03 08:23 - 2015-02-03 08:23 - 00003220 _____ () C:\Windows\System32\Tasks\WSE_Taplika
2015-02-03 08:23 - 2015-02-03 08:23 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Taplika
2015-02-03 08:22 - 2015-02-03 08:23 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\WSE_Taplika
2015-02-03 08:22 - 2015-02-03 08:22 - 00003128 _____ () C:\Windows\System32\Tasks\ArcadeGiant Updater
2015-02-03 08:21 - 2015-02-03 08:22 - 00000000 ____D () C:\Users\Dad\AppData\Local\ArcadeGiant

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

Please run a Threat Scan with Malwarebytes' Anti-Malware.

Right click and choose "Run as administrator" to open Malwarebytes Anti-Malware and from the Dashboard please Check for Updates by clicking the Update Now... link
Open up Malwarebytes > Settings > Detection and Protection > Enable Scan for rootkit and Under Non Malware Protection set both PUP and PUM to Treat detections as malware.
Click on the SCAN button and run a Threat Scan with Malwarebytes Anti-Malware by clicking the Scan Now>> button.
Once completed please click on the History > Application Logs and find your scan log and open it and then click on the "copy to clipboard" button and post back the results on your next reply.

Please post
MBAM log

2015-02-04, 00:06
i was using microsoft essentials when all this happened, when i used the eset scanner i saw they had a trial ver. and had been using it.

Malwarebytes Anti-Malware

Scan Date: 2/3/2015
Scan Time: 3:45:00 PM
Administrator: Yes

Malware Database: v2015.02.03.07
Rootkit Database: v2015.02.03.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Dad

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 347691
Time Elapsed: 11 min, 41 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 3
PUP.Optional.Taplika.A, HKU\S-1-5-21-2107755742-302254199-1763176924-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Taplika Browser, Quarantined, [987aca50b4d62d091e30cbba4ab912ee],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2107755742-302254199-1763176924-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [40d217034248df573fd4aa20669db848],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2107755742-302254199-1763176924-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [21f101190b7f7cba4fd87b657490b24e],

Registry Values: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2107755742-302254199-1763176924-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0U1N2S1K1M, Quarantined, [21f101190b7f7cba4fd87b657490b24e]

Registry Data: 0
(No malicious items detected)

Folders: 17
PUP.Optional.SmootherWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\jetpack\jid1-U7omKQ6kQfxMaQ@jetpack, Quarantined, [d2407e9cb9d1e94d4393e394fc07a759],
PUP.Optional.SmootherWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\jetpack\jid1-U7omKQ6kQfxMaQ@jetpack\simple-storage, Quarantined, [d2407e9cb9d1e94d4393e394fc07a759],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\defaults, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\defaults\preferences, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\locale, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\addon-sdk, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\addon-sdk\lib, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\livecharity, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\livecharity\data, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\livecharity\data\fonts, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\livecharity\data\img, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\smootherweb, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\smootherweb\data, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\smootherweb\lib, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\smootherweb\tests, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],

Files: 16
PUP.Optional.Taplika.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\h46m51x5.default-1342635577168\searchplugins\Taplika.xml, Quarantined, [18fa5fbb9eecf244123bdfa6dd2617e9],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\.buildpath, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\.project, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\bootstrap.js, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\harness-options.json, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\icon.png, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\icon64.png, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\install.rdf, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\locales.json, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\defaults\preferences\prefs.js, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\smootherweb\data\content.js, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\smootherweb\data\easylist.txt, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\smootherweb\lib\ajax.js, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\smootherweb\lib\main.js, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\smootherweb\lib\main.js-backup, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],
PUP.Optional.BoosterWeb.A, C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\extensions\jid1-U7omKQ6kQfxMaQ@jetpack\resources\smootherweb\lib\main.js-backup last, Quarantined, [c44e17030b7f5ed8ef80701144bf02fe],

Physical Sectors: 0
(No malicious items detected)


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015
Ran by Dad at 2015-02-03 15:42:03 Run:8
Running from C:\Users\Dad\Desktop
Loaded Profiles: Dad (Available profiles: Dad)
Boot Mode: Normal

Content of fixlist:
Task: {3300F4CE-D879-4D35-8449-19AFCAB8A938} - System32\Tasks\WSE_Taplika => C:\Users\Dad\AppData\Roaming\WSE_TA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {474B6DAF-131A-4A72-908B-2653EDE97FBF} - System32\Tasks\ArcadeGiant Updater => C:\Users\Dad\AppData\Local\ArcadeGiant\updater.exe [2015-02-03] (ArcadeGiant) <==== ATTENTION
Task: {89903DAE-62F9-4E24-BF41-F181F8031DD0} - System32\Tasks\AgSupport => Rundll32.exe C:\Users\Dad\AppData\Local\ARCADE~1\AgHelp.dll,Start
Task: C:\Windows\Tasks\WSE_Taplika.job => C:\Users\Dad\AppData\Roaming\WSE_TA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
C:\Users\Dad\AppData\Local\Obrona Block Ads\ObronaBlockAds.exe
HKLM-x32\...\RunOnce: [WSE_Taplika] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Dad\AppData\Roaming\WSE_Taplika\UpdateProc\bkup.dat"
HKLM-x32\...\RunOnce: [DelTr96190] => cmd.exe /c rd /s /q "C:\Users\Dad\AppData\Roaming\WSE_Taplika"
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Run: [GoogleChromeAutoLaunch_C1DAAF30A00C843105EF5E39636EB999] => C:\Users\Dad\AppData\Local\Taplika\Application\taplika.exe [754176 2014-11-06] ()
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [WSE_Taplika] => [X]
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [DelTr96190] => cmd.exe /c rd /s /q "C:\Users\Dad\AppData\Roaming\WSE_Taplika"
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [ArcadeGiant508] => cmd.exe /c rmdir "C:\Users\Dad\AppData\Local\ArcadeGiant" /s /q
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [ArcadeGiant120] => cmd.exe /s /c reg delete "HKCU\Software\AppDataLow\ArcadeGiant" /f
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF DefaultSearchEngine: Taplika
FF SearchEngineOrder.1: Yahoo
FF SelectedSearchEngine: Taplika
FF Homepage: hxxp://taplika.com/?f=1&a=tlk_dwndlm_15_06_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtBtD0CtD0Bzz0D0FyE0DtAtN0D0Tzu0StCtCtBzytN1L2XzutAtFyBtFtBtFtDtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StByD0AtDtAyEyBzytGzyyD0F0FtG0Ezy0F0BtG0EyCtA0BtGyCzytB0ByC0AtByBtDtA0A0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyB0FyCzz0E0AtDtG0AzyyB0CtGyE0C0C0BtGzy0Ezy0FtGyEyByCyEtCtCyD0AtDtCyEtA2Q&cr=1534779659&ir=
FF SearchPlugin: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\searchplugins\Taplika.xml
FF Extension: No Name - C:\PROGRA~2\MOZILL~1\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
2015-02-03 08:23 - 2015-02-03 10:23 - 00000284 _____ () C:\Windows\Tasks\WSE_Taplika.job
2015-02-03 08:23 - 2015-02-03 09:24 - 00000000 ____D () C:\Users\Dad\AppData\Local\Taplika
2015-02-03 08:23 - 2015-02-03 08:23 - 00003220 _____ () C:\Windows\System32\Tasks\WSE_Taplika
2015-02-03 08:23 - 2015-02-03 08:23 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Taplika
2015-02-03 08:22 - 2015-02-03 08:23 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\WSE_Taplika
2015-02-03 08:22 - 2015-02-03 08:22 - 00003128 _____ () C:\Windows\System32\Tasks\ArcadeGiant Updater
2015-02-03 08:21 - 2015-02-03 08:22 - 00000000 ____D () C:\Users\Dad\AppData\Local\ArcadeGiant

Processes closed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3300F4CE-D879-4D35-8449-19AFCAB8A938}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3300F4CE-D879-4D35-8449-19AFCAB8A938}" => Key deleted successfully.
C:\Windows\System32\Tasks\WSE_Taplika => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WSE_Taplika" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{474B6DAF-131A-4A72-908B-2653EDE97FBF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{474B6DAF-131A-4A72-908B-2653EDE97FBF}" => Key deleted successfully.
C:\Windows\System32\Tasks\ArcadeGiant Updater => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ArcadeGiant Updater" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{89903DAE-62F9-4E24-BF41-F181F8031DD0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89903DAE-62F9-4E24-BF41-F181F8031DD0}" => Key deleted successfully.
C:\Windows\System32\Tasks\AgSupport => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AgSupport" => Key deleted successfully.
C:\Windows\Tasks\WSE_Taplika.job => Moved successfully.
"C:\Users\Dad\AppData\Local\Obrona Block Ads\ObronaBlockAds.exe" => File/Directory not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\WSE_Taplika => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\DelTr96190 => Value not found.
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_C1DAAF30A00C843105EF5E39636EB999 => Value not found.
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\WSE_Taplika => Value not found.
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\DelTr96190 => Value not found.
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ArcadeGiant508 => Value not found.
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ArcadeGiant120 => Value not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
Firefox DefaultSearchEngine deleted successfully.
Firefox SearchEngineOrder.1 deleted successfully.
Firefox SelectedSearchEngine deleted successfully.
Firefox homepage deleted successfully.
C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\searchplugins\Taplika.xml => Moved successfully.
C:\PROGRA~2\MOZILL~1\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} not found.
"C:\Windows\Tasks\WSE_Taplika.job" => File/Directory not found.
"C:\Users\Dad\AppData\Local\Taplika" => File/Directory not found.
"C:\Windows\System32\Tasks\WSE_Taplika" => File/Directory not found.
"C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Taplika" => File/Directory not found.
"C:\Users\Dad\AppData\Roaming\WSE_Taplika" => File/Directory not found.
"C:\Windows\System32\Tasks\ArcadeGiant Updater" => File/Directory not found.
"C:\Users\Dad\AppData\Local\ArcadeGiant" => File/Directory not found.
C:\Users\Dad\AppData\Local\Temp\SpOrder.dll => Moved successfully.
"C:\Users\Dad\AppData\Local|ARCADE~1\AgHelp.dll" => File/Directory not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 835.5 MB temporary data.

The system needed a reboot.

==== End of Fixlog 15:42:58 ====

2015-02-04, 00:09
Goodness we found a ton of junk

How's the computer?

2015-02-04, 00:15
i believe there was a load here huh? it seems to be doing ok...a lot better...and that is a big improvement. i just used the link you gave for firefox and just reinstalled it. i'll know more in a little bit about any pop ups or excessive tabs and all.

2015-02-04, 00:25
Let's run an online scan for assurance

http://i.imgur.com/GzlsbnV.png ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

Please download ESET Online Scan (http://download.eset.com/special/eos/esetsmartinstaller_enu.exe) and save the file to your Desktop.
Temporarily disable your anti-virus software. For instructions, please refer to the following link (http://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/).
Double-click esetsmartinstaller_enu.exe to run the programme.
Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
Agree to the Terms of Use once more and click Start. Allow components to download.
Place a checkmark next to Enable detection of potentially unwanted applications.
Click Advanced settings. Place a checkmark next to:

Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology

Ensure Remove found threats is unchecked.
Click Start.
Wait for the scan to finish. Please be patient as this can take some time.
Upon completion, click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png. If no threats were found, skip the next two bullet points.
Click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png and save the file to your Desktop, naming it something such as "MyEsetScan".
Push the Back button.
Place a checkmark next to http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png and click http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png.
Re-enable your anti-virus software.
Copy the contents of the log and paste in your next reply.


2015-02-04, 02:14
ok...is it the same to run the trial of eset? i started it about an hour or so ago and is almost through. so far it has found 18 threats and cleaned three. if i need to run the online scanner i will, it may be tomorrow before i post again. so far firefox has done fine and all the new tabs and windows popping up have stopped. none!

2015-02-04, 02:28
ok...is it the same to run the trial of eset? i started it about an hour or so ago and is almost through. so far it has found 18 threats and cleaned three. if i need to run the online scanner i will, it may be tomorrow before i post again. so far firefox has done fine and all the new tabs and windows popping up have stopped. none!

That should be the free online scanner?

Good deal for Firefox!

Sometimes these infections can be quite a bugger to get rid of.:)

2015-02-04, 03:38
haha...i'm proof of that! why people put that crap in stuff is beside me...money i guess. that scan is still running and is just past halfway so it'll be a while yet.

2015-02-04, 03:39
and after all you've helped with...eset shows now 71 threats found!

2015-02-04, 03:58
ok it just finished...

Scan Log
Version of virus signature database: 11118

Date: 2/3/2015 Time: 5:20:58 PM
Scanned disks, folders and files: Operating

memory;C:\Boot sector;K:\Boot sector;Q:\Boot

Boot sector of disk Q: - error opening [4]
C:\hiberfil.sys - error opening [4]
C:\pagefile.sys - error opening [4]
C:\AdwCleaner\Quarantine\C\Program Files


ABD0-CA2F5A326744}.xpi.vir » ZIP »

chrome/content/main.js -

Win32/Toolbar.Perion.K potentially unwanted

application - action selection postponed until

scan completion
C:\dad\Desktop\My Documents


xe » RAR » 1324898rar.exe » RAR - error -

password-protected file
C:\dad\Desktop\My Documents


xe » RAR » 9091789rar.exe » RAR - error -

password-protected file
C:\Documents\Downloads\kav8.0.0.523en.exe »

NSIS » kav.en.msi » MSI » KAV8.cab » CAB »

ushata.dll - is OK
C:\Documents\Downloads\kav9.0.0.736en.exe »

NSIS » kav.en.msi » MSI » KAV9.cab » CAB »

ushata.dll - is OK
C:\Documents\Downloads\setup (1).exe » 7ZSD

» data/Microsoft Windows Installer

2.0/mWinRun.dll/unicode/shfolder.dll - is OK
C:\Documents\Downloads\setup (1).exe » 7ZSD

» data/Microsoft Windows Installer

2.0/mWinRun.dll/ansi/shfolder.dll - is OK
C:\Downloads\GRMWDK_EN_7600_1.ISO »

ISO » instmsi.exe » CAB » shfolder.dll - is


» INNO » {app}\Tools\CodecTweakTool-0.bin -

error - password-protected file

» INNO » {app}\Tools\CodecTweakTool-1.bin -

error - password-protected file

» INNO » {app}\Tools\Win7DSFilterTweaker-

0.bin - error - password-protected file

» INNO » {app}\Tools\Win7DSFilterTweaker-

1.bin - error - password-protected file

» INNO » {app}\Info\faq.htm - error -

password-protected file

» INNO » {app}\Info\faq_64bit.htm - error -

password-protected file

» INNO » {app}\Info\faq_configuration.htm -

error - password-protected file

» INNO » {app}\Info\faq_display_issues.htm -

error - password-protected file

» INNO » {app}\Info\faq_dxva.htm - error -

password-protected file

» INNO » {app}\Info\faq_general.htm - error

- password-protected file

» INNO » {app}\Info\faq_installation.htm -

error - password-protected file

» INNO » {app}\Info\faq_miscellaneous.htm -

error - password-protected file

» INNO » {app}\Info\faq_mpc.htm - error -

password-protected file

» INNO » {app}\Info\faq_playback_issues.htm

- error - password-protected file

» INNO » {app}\Info\faq_subtitles.htm -

error - password-protected file

» INNO » {app}\Info\faq_thumbnails.htm -

error - password-protected file

» INNO » {app}\Info\faq_troubleshooting.htm

- error - password-protected file

» INNO » {app}\Info\faq_windows_issues.htm

- error - password-protected file

» INNO » {app}\Info\faq_wmp.htm - error -

password-protected file

» INNO » {app}\Info\faq.css - error -

password-protected file

» INNO » {app}\Icons\xvid.ico - error -

password-protected file

» INNO » {app}\Icons\delete.ico - error -

password-protected file

» INNO » {app}\Icons\config.ico - error -

password-protected file

» INNO » {app}\ffdshow\ffmpegmt.dll - error

- password-protected file

» INNO » {app}\ffdshow\libavcodec.dll - error

- password-protected file

» INNO » {app}\ffdshow\libmplayer.dll - error

- password-protected file

» INNO » {app}\ffdshow\ffdshow.ax - error -

password-protected file

» INNO » {app}\ffdshow\ff_liba52.dll - error

- password-protected file

» INNO » {app}\ffdshow\ff_libdts.dll - error

- password-protected file

» INNO » {app}\ffdshow\ff_libfaad2.dll -

error - password-protected file

» INNO » {app}\ffdshow\ff_libmad.dll - error

- password-protected file

» INNO » {app}\ffdshow\ff_unrar.dll - error

- password-protected file

» INNO » {app}\ffdshow\libmpeg2_ff.dll -

error - password-protected file

» INNO » {app}\ffdshow\ff_samplerate.dll -

error - password-protected file

» INNO » {app}\ffdshow\ff_wmv9.dll - error

- password-protected file

» INNO » {sys}\ff_vfw.dll - error -

password-protected file

» INNO » {app}\ffdshow\ff_kernelDeint.dll -

error - password-protected file

» INNO » {app}\ffdshow\TomsMoComp_ff.dll

- error - password-protected file

» INNO »

{code:GetDScalerDir|}\FLT_ffdshow.dll - error

- password-protected file

» INNO » {app}\ffdshow\openIE.js - error -

password-protected file

» INNO » {app}\ffdshow\ffdshow.ax.manifest

- error - password-protected file

» INNO » {sys}\ff_vfw.dll.manifest - error -

password-protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1026.bg - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1028.tc - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1029.cs - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1029.cz - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1031.de - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1033.en - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1034.es - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1035.fi - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1036.fr - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1038.hu - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1040.it - error - password-protected


» INNO » {app}\ffdshow\languages

\ffdshow.1041.ja - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1045.pl - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1046.br - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1049.ru - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1051.sk - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1053.se - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.1053.sv - error - password-

protected file

» INNO » {app}\ffdshow\languages

\ffdshow.2052.sc - error - password-

protected file

» INNO » {app}\ffdshow\custom matrices

\andreas_78er.matrix.xcm - error -

password-protected file

» INNO » {app}\ffdshow\custom matrices

\andreas_doppelte_99er.matrix.xcm - error -

password-protected file

» INNO » {app}\ffdshow\custom matrices

\andreas_einfache_99er.matrix.xcm - error -

password-protected file

» INNO » {app}\ffdshow\custom matrices

\Bulletproof's Heavy Compression Matrix.xcm -

error - password-protected file

» INNO » {app}\ffdshow\custom matrices

\Bulletproof's High Quality Matrix.xcm - error

- password-protected file

» INNO » {app}\ffdshow\custom matrices

\CG-Animation Matrix.xcm - error -

password-protected file

» INNO » {app}\ffdshow\custom matrices

\hvs-best-picture.xcm - error - password-

protected file

» INNO » {app}\ffdshow\custom matrices

\hvs-better-picture.xcm - error - password-

protected file

» INNO » {app}\ffdshow\custom matrices

\hvs-good-picture.xcm - error - password-

protected file

» INNO » {app}\ffdshow\custom matrices\Low

Bitrate Matrix.xcm - error - password-

protected file

» INNO » {app}\ffdshow\custom matrices

\MPEG.xcm - error - password-protected file

» INNO » {app}\ffdshow\custom matrices

\pvcd.xcm - error - password-protected file

» INNO » {app}\ffdshow\custom matrices

\Soulhunters V3.xcm - error - password-

protected file

» INNO » {app}\ffdshow\custom matrices

\Soulhunters V5.xcm - error - password-

protected file

» INNO » {app}\ffdshow\custom matrices

\Standard.xcm - error - password-protected


» INNO » {app}\ffdshow\custom matrices

\Ultimate Matrix.xcm - error - password-

protected file

» INNO » {app}\ffdshow\custom matrices

\Ultra Low Bitrate Matrix.xcm - error -

password-protected file

» INNO » {app}\ffdshow\custom matrices\Very

Low Bitrate Matrix.xcm - error - password-

protected file

» INNO » {app}\Media Player Classic\mpc-

hc.ini - error - password-protected file

» INNO » {app}\Media Player Classic\mpc-

hc.exe - error - password-protected file

» INNO » {app}\Media Player Classic\mpc-

hc.exe - error - password-protected file

» INNO » {app}\Media Player Classic

\mpciconlib.dll - error - password-protected


» INNO » {app}\Media Player Classic

\D3DX9_41.dll - error - password-protected


» INNO » {app}\Media Player Classic

\toolbar.bmp - error - password-protected file

» INNO » {app}\Filters\DivXDecH264.ax -

error - password-protected file

» INNO » {app}\Filters\xvid.ax - error -

password-protected file

» INNO » {sys}\xvidvfw.dll - error -

password-protected file

» INNO » {sys}\xvidcore.dll - error -

password-protected file

» INNO » {app}\Tools\XvidQuantMatrices

\andreas_78er.matrix.txt - error - password-

protected file

» INNO » {app}\Tools\XvidQuantMatrices

\andreas_doppelte_99er.matrix.txt - error -

password-protected file

» INNO » {app}\Tools\XvidQuantMatrices

\andreas_einfache_99er.matrix.txt - error -

password-protected file

» INNO » {app}\Tools\XvidQuantMatrices

\Bulletproof's Heavy Compression Matrix.TXT

- error - password-protected file

» INNO » {app}\Tools\XvidQuantMatrices

\Bulletproof's High Quality Matrix.TXT -

error - password-protected file

» INNO » {app}\Tools\XvidQuantMatrices

\CG-Animation Matrix.txt - error -

password-protected file

» INNO » {app}\Tools\XvidQuantMatrices

\hvs-best-picture.txt - error - password-

protected file

» INNO » {app}\Tools\XvidQuantMatrices

\hvs-better-picture.txt - error - password-

protected file

» INNO » {app}\Tools\XvidQuantMatrices

\hvs-good-picture.txt - error - password-

protected file

» INNO » {app}\Tools\XvidQuantMatrices\Low

Bitrate Matrix.txt - error - password-

protected file

» INNO » {app}\Tools\XvidQuantMatrices

\MPEG.txt - error - password-protected file

» INNO » {app}\Tools\XvidQuantMatrices

\Standard.txt - error - password-protected


» INNO » {app}\Tools\XvidQuantMatrices

\Ultimate Matrix.txt - error - password-

protected file

» INNO » {app}\Tools\XvidQuantMatrices

\Ultra Low Bitrate Matrix.txt - error -

password-protected file

» INNO » {app}\Tools\XvidQuantMatrices\Very

Low Bitrate Matrix.txt - error - password-

protected file

» INNO » {app}\Tools\StatsReader.exe -

error - password-protected file

» INNO » {app}\Filters\vp7dec.ax - error -

password-protected file

» INNO » {sys}\vp7vfw.dll - error -

password-protected file

» INNO » {sys}\yv12vfw.dll - error -

password-protected file

» INNO » {sys}\huffyuv.dll - error -

password-protected file

» INNO » {app}\Filters\ac3filter.ax - error -

password-protected file

» INNO » {app}\Filters\ac3config.exe - error

- password-protected file

» INNO » {sys}\ac3acm.acm - error -

password-protected file

» INNO » {app}\Filters\ac3file.ax - error -

password-protected file

» INNO » {app}\Filters\mmamr.ax - error -

password-protected file

» INNO » {app}\Filters\mmmpcdmx.ax - error

- password-protected file

» INNO » {app}\Filters\mmmpcdec.ax - error

- password-protected file

» INNO » {app}\Filters\mmaacd.ax - error -

password-protected file

» INNO » {app}\Filters\CoreVorbis.ax - error

- password-protected file

» INNO » {sys}\lameACM.acm - error -

password-protected file

» INNO » {sys}\lame_acm.xml - error -

password-protected file

» INNO » {app}\Filters\WavPackDSDecoder.ax

- error - password-protected file

» INNO » {app}\Filters\WavPackDSSplitter.ax

- error - password-protected file

» INNO » {app}\Filters\madFlac.ax - error -

password-protected file

» INNO » {app}\Filters\libFLAC.dll - error -

password-protected file

» INNO » {app}\Filters\DCBassSource.ax -

error - password-protected file

» INNO » {app}\Filters\bass.dll - error -

password-protected file

» INNO » {app}\Filters\bass_alac.dll - error -

password-protected file

» INNO » {app}\Filters\bass_tta.dll - error -

password-protected file

» INNO » {app}\Filters\bass_aac.dll - error -

password-protected file

» INNO » {app}\Filters\RLOFRDec.ax - error

- password-protected file

» INNO » {app}\Filters\OptimFROG.dll - error

- password-protected file

» INNO » {app}\Filters\MonkeySource.ax -

error - password-protected file

» INNO » {app}\Filters\MACDec.dll - error -

password-protected file

» INNO » {app}\Filters\CLVSD.ax - error -

password-protected file

» INNO » {app}\Filters\Mpeg2DecFilter.ax -

error - password-protected file

» INNO » {app}\Filters\MpegSplitter.ax -

error - password-protected file

» INNO » {app}\Filters\FLVSplitter.ax - error

- password-protected file

» INNO » {app}\Filters\cdxareader.ax - error

- password-protected file

» INNO » {app}\Filters\MP4Splitter.ax - error

- password-protected file

» INNO » {app}\Filters\MatroskaSplitter.ax -

error - password-protected file

» INNO » {app}\Filters\OggSplitter.ax - error

- password-protected file

» INNO » {app}\Filters\avisplitter.ax - error -

password-protected file

» INNO » {win}\avisplitter.ini - error -

password-protected file

» INNO » {app}\Filters\Haali\mkx.dll - error -

password-protected file

» INNO » {app}\Filters\Haali\ogm.dll - error -

password-protected file

» INNO » {app}\Filters\Haali\mp4.dll - error -

password-protected file

» INNO » {app}\Filters\Haali\ts.dll - error -

password-protected file

» INNO » {app}\Filters\Haali\avi.dll - error -

password-protected file

» INNO » {app}\Filters\Haali\mmfinfo.dll -

error - password-protected file

» INNO » {app}\Filters\Haali\splitter.ax -

error - password-protected file

» INNO » {app}\Filters\Haali\mkzlib.dll -

error - password-protected file

» INNO » {app}\Filters\Haali\mkunicode.dll -

error - password-protected file

» INNO » {app}\Filters\Haali\avs.dll - error -

password-protected file

» INNO » {app}\Filters\Haali\avss.dll - error

- password-protected file

» INNO » {app}\Filters\Haali\gdsmux.exe -

error - password-protected file

» INNO » {app}\Filters\Haali\cue2xml.js -

error - password-protected file

» INNO » {app}\Filters\Haali\dxr.dll - error -

password-protected file

» INNO » {app}\Filters\vsfilter.dll - error -

password-protected file

» INNO » {app}\Filters\vsfilter.dll - error -

password-protected file

» INNO » {sys}\unrar.dll - error - password-

protected file

» INNO » {app}\Tools\VobSubStrip.exe -

error - password-protected file

» INNO » {app}\Tools\mediainfo.exe - error -

password-protected file

» INNO » {app}\Media Player Classic

\mediainfo.dll - error - password-protected


» INNO » {app}\Tools\graphstudio.exe - error

- password-protected file

» INNO » {app}\Tools\xmllite.dll - error -

password-protected file

» INNO » {app}\Tools\minicalc.exe - error -

password-protected file

» INNO » {app}\Tools\SetACL_x86.exe -

error - password-protected file

» INNO » {app}\Tools\SetACL_x64.exe -

error - password-protected file

» INNO » {app}\Tools\dsconfig.exe - error -

password-protected file

» INNO » script_decompiled.pas - is OK
C:\Downloads\kis11.0.2.556EN-US.exe »

NSIS » kavkis.msi » MSI » KAVKIS11.cab »

CAB » ushata.dll - is OK
C:\Downloads\kis11.0.2.556EN-US.exe »

NSIS » kavkis.msi » MSI » mklifx86nt500.cab

» CAB - error reading archive


x264.ac3.HD-R-US\The A-Team Extended Cut

- Bluray & AVCHD [HD-R-US].iso » ISO -

error - unknown compression method
C:\FRST\Quarantine\C\Program Files

(x86)\Lydynamidae\Lydynamidae.exe.xBAD -

Win32/Adware.ObronaAds.D application -

cleaned by deleting - quarantined [1]
C:\FRST\Quarantine\C\Program Files


\LydynamidaeHelper.exe.xBAD -

Win32/Adware.ObronaAds.D application -

cleaned by deleting - quarantined [1]

\Local\Temp\BootstrapperIminent.exe.xBAD -

a variant of Win32/Toolbar.Iminent.C

potentially unwanted application - action

selection postponed until scan completion

\Local\Temp\ConsumerInputSetup.exe.xBAD -

Win32/Compete.A potentially unwanted

application - action selection postponed until

scan completion

\Local\Temp\optprosetup.exe.xBAD - a variant

of Win32/OptimizerEliteMax.C potentially

unwanted application - action selection

postponed until scan completion

\Local\Temp\sprz.exe.xBAD » INNO »

{app}\spdata.dat » RAR - error - password-

protected file

\Local\Temp\sprz.exe.xBAD » INNO »


50526718257D}.xpi » ZIP »

chrome/content/main.js -

Win32/Toolbar.Perion.K potentially unwanted

application - action selection postponed until

scan completion

\Local\Temp\sprz.exe.xBAD » INNO »

{app}\Firefox\chrome\content\main.js -

Win32/Toolbar.Perion.K potentially unwanted

application - action selection postponed until

scan completion

\Local\Temp\sprz.exe.xBAD » INNO »

{app}\source.crx » CHROMEEXTENSION »

content.zip » ZIP » main.js -

Win32/Toolbar.Perion.K potentially unwanted

application - action selection postponed until

scan completion

\Local\Temp\sprz.exe.xBAD » INNO »

{app}\DGChrome.exe - Win32/Toolbar.Perion.J

potentially unwanted application - action

selection postponed until scan completion

\Roaming\HQ.xBAD » ZIP » content/overlay.js

- JS/Toolbar.Crossrider.C potentially unwanted

application - action selection postponed until

scan completion

\Roaming\NEDL.xBAD » ZIP » background.js -

JS/Toolbar.Crossrider.C potentially unwanted

application - action selection postponed until

scan completion
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD » Best Buy pc app Setup.msi - Incorrect

file checksum (CRC); the file is probably

password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD » Best Buy pc app Setup.res - Incorrect

file checksum (CRC); the file is probably

password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD » mia.lib - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


deploy - Incorrect file checksum (CRC); the

file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


g.deploy - Incorrect file checksum (CRC); the

file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


.gif.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


al.png.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


w.gif.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


- Incorrect file checksum (CRC); the file is

probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD » OFFLINE/217807D8/1559E68B/card-

CID-A.png.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD » OFFLINE/217807D8/1559E68B/card-

CID-B.png.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD » OFFLINE/217807D8/1559E68B/Cart-

BtnSm.png.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


12.png.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


.deploy - Incorrect file checksum (CRC); the

file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


wav.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


JPG.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


pport_2.gif.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


-Bold.otf.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


-Roman.otf.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


.deploy - Incorrect file checksum (CRC); the

file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


deploy - Incorrect file checksum (CRC); the

file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


.png.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


nImage.png.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


oy - Incorrect file checksum (CRC); the file is

probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


deploy - Incorrect file checksum (CRC); the

file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


y - Incorrect file checksum (CRC); the file is

probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


BG.png.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


.png.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


Header.gif.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


deploy - Incorrect file checksum (CRC); the

file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


ploy - Incorrect file checksum (CRC); the file

is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


6x36.jpg.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


.png.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


g.deploy - Incorrect file checksum (CRC); the

file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD » OFFLINE/217807D8/15DD5D7A/Best

Buy pc app.application - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


y - Incorrect file checksum (CRC); the file is

probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


oy - Incorrect file checksum (CRC); the file is

probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


.rtf.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


- Incorrect file checksum (CRC); the file is

probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


y - Incorrect file checksum (CRC); the file is

probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


y - Incorrect file checksum (CRC); the file is

probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


y - Incorrect file checksum (CRC); the file is

probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


ultsOnly.gif.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


lyChildhood.gif.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


ryone.gif.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


ryone10plus.gif.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


ture.gif.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


ding.gif.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


en.gif.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


eploy - Incorrect file checksum (CRC); the file

is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


ml.deploy - Incorrect file checksum (CRC); the

file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


.xml.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


ema.xsd.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


BoldItalic.ttf.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


Book.ttf.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


BookItalic.ttf.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


Medium.ttf.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


MediumItalic.ttf.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


66FullFlyweight.ttf.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


67FullBantamwt.ttf.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


68FullFeatherwt.ttf.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


69FullLiteweight.ttf.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


70FullWelterwt.ttf.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


90UltmtWelterwt.ttf.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


91UltmtMiddlewt.ttf.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


92UltmtCruiserwt.ttf.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


93UltmtHeviwt.ttf.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


94UltmtSumo.ttf.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


ploy - Incorrect file checksum (CRC); the file

is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


nt_DotNET_Strong.dll.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD » OFFLINE/217807D8/F86FA20C/Best

Buy pc app.exe.config.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD » OFFLINE/217807D8/F86FA20C/Best

Buy pc app.exe.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD » OFFLINE/217807D8/F86FA20C/Best

Buy pc app.exe.manifest - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


reInstaller.dll.config.deploy - Incorrect file

checksum (CRC); the file is probably password

C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


reInstaller.dll.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


fig.deploy - Incorrect file checksum (CRC);

the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


loy - Incorrect file checksum (CRC); the file is

probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


Net.dll.deploy - Incorrect file checksum

(CRC); the file is probably password protected.
C:\OEM\BBYAP\Best Buy pc app Setup.exe »

7ZSD »


Number of threats found: 71
Number of cleaned objects: 13
Time of completion: 7:54:39 PM Total scanning

time: 9221 sec (02:33:41)

[1] Object has been deleted as it only

contained the virus body.
[4] Object cannot be opened. It may be in use

by another application or operating system.

2015-02-04, 14:00
The format of notepad made that impossible to read, word wrap must have been checked?

One thing I picked up on

Best Buy pc app <-- is this in your add/remove programs list?
If you find that please uninstall.

I could tell some things were removed others not, let's try something different.

http://i.imgur.com/3GlqbMn.png HitmanPro

Please download HitmanPro (x32) (http://dl.surfright.nl/HitmanPro.exe) / HitmanPro (x64) (http://dl.surfright.nl/HitmanPro_x64.exe) and save the file to your Desktop.
Right-Click HitmanPro.exe / HitmanPro_x64.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Click Next, and agree to the End User License Agreement (EULA) if prompted.
Place a checkmark next to No, I only want to perform a one-time scan to check this computer.
Click Next.
The scan will start, and will typically take no longer than 2-3 minutes.
Upon completion, click on the drop-down menu of the found entries (if any) and select: Apply to all => Ignore <=.
Click Next.
Click Save Log, and select your Desktop as the location. Copy the contents of the log and paste in your next reply.

Note: If a drop-down menu is not present after the scan is complete, please do not delete the detected items. Close the HitmanPro window. Navigate to C:\ProgramData\HitmanPro\Logs, open the log, copy the contents and paste in your next reply.

2015-02-04, 14:15
juliet i'm sorry about the log not saved right, as for the best buy you asked about, no it is not in my programs and i have not seen that or anything of their name. hope this one is right...btw, pc is running much smoother and seems the worst of the problems are gone. it is still very sketchy and jumpy when scrolling. it never did that. may be a sorry mouse. hitman still says it's creating a restore point...can i close it?


Computer name . . . . : BRIDGES1
Windows . . . . . . . :
User name . . . . . . : Bridges1\Dad
UAC . . . . . . . . . : Disabled
License . . . . . . . : Free

Scan date . . . . . . : 2015-02-04 06:03:57
Scan mode . . . . . . : Normal
Scan duration . . . . : 3m 39s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No

Threats . . . . . . . : 0
Traces . . . . . . . : 43

Objects scanned . . . : 1,875,901
Files scanned . . . . : 43,824
Remnants scanned . . : 386,749 files / 1,445,328 keys

Suspicious files ____________________________________________________________

Size . . . . . . . : 2,130,432 bytes
Age . . . . . . . : 6.4 days (2015-01-28 19:56:05)
Entropy . . . . . : 7.5
SHA-256 . . . . . : 4FF2D9D33D5023F1C1407722E3FA368593201F4D69976E2236CD12935BFF35E3
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.

Size . . . . . . . : 2,131,456 bytes
Age . . . . . . . : 0.8 days (2015-02-03 10:51:10)
Entropy . . . . . : 7.5
SHA-256 . . . . . : 75A43C7DCD832E78EE09AFE27A6C3C8EF33470D1323A781EEC04E13E4F3197A0
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
0.0s C:\Users\Dad\Desktop\FRST-OlderVersion\FRST64.exe
0.0s C:\Users\Dad\Desktop\FRST-OlderVersion\FRST64.exe
1.0s C:\Users\Dad\Desktop\FRST-OlderVersion\FRST-OlderVersion\
21.3s C:\Users\Dad\Desktop\FRST-OlderVersion\FRST.txt
21.3s C:\Users\Dad\Desktop\FRST-OlderVersion\FRST.txt
21.3s C:\Users\Dad\Desktop\FRST-OlderVersion\FRST.txt
21.3s C:\Users\Dad\Desktop\FRST-OlderVersion\FRST.txt

Size . . . . . . . : 2,131,456 bytes
Age . . . . . . . : 1.8 days (2015-02-02 11:36:45)
Entropy . . . . . : 7.5
SHA-256 . . . . . : 75A43C7DCD832E78EE09AFE27A6C3C8EF33470D1323A781EEC04E13E4F3197A0
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Users\Dad\Desktop\FRST64.exe
Forensic Cluster
0.0s C:\Users\Dad\Desktop\FRST64.exe
0.9s C:\Users\Dad\Desktop\FRST-OlderVersion\

Size . . . . . . . : 401,920 bytes
Age . . . . . . . : 1.4 days (2015-02-02 20:03:09)
Entropy . . . . . : 7.9
SHA-256 . . . . . : 520E765E9043243127BE3D7B7210D32E2D1994866DC7A0F57EC05FA480D6D062
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
-5.8s C:\Users\Dad\Desktop\MiniToolBox.exe
-5.8s C:\Users\Dad\Desktop\MiniToolBox.exe
-5.8s C:\Users\Dad\Desktop\MiniToolBox.exe
-5.8s C:\Users\Dad\Desktop\MiniToolBox.exe
-5.8s C:\Users\Dad\Desktop\MiniToolBox.exe
-5.8s C:\Users\Dad\Desktop\MiniToolBox.exe
-5.8s C:\Users\Dad\Desktop\MiniToolBox.exe
-5.8s C:\Users\Dad\Desktop\MiniToolBox.exe
-5.8s C:\Users\Dad\Desktop\MiniToolBox.exe
-5.8s C:\Users\Dad\Desktop\MiniToolBox.exe
-5.8s C:\Users\Dad\Desktop\MiniToolBox.exe

Potential Unwanted Programs _________________________________________________

C:\rei\ (ReimageRepair)
C:\rei\cfl.rei (ReimageRepair)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\ (DomalQ)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\ (DomalQ)
HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}\ (FLV Player)
HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}\ (FLV Player)
HKU\S-1-5-19\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}\ (FLV Player)
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ (PCOptimizerPro)
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\StormWatchApp.exe (StormWatch)
HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ (PCOptimizerPro)
HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Wow6432Node\CLSID\{BEBBC426-4F16-4567-8FE1-BE198C982027}\ (Speedial)
HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Wow6432Node\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ (PCOptimizerPro)

Cookies _____________________________________________________________________


2015-02-04, 16:31
Well, found a few things

C:\OEM\BBYAP\Best Buy pc app Setup.exe
This came preinstalled without your knowledge or your permission.

I don't know if I set a script to remove it if it can.

stay away from reg fix / booster type programmes. Reimage Repair
Full explanation as to why here: http://library.techguy.org/wiki/Registry_Cleaners

Uninstall Reimage Repair


Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

C:\Program Files (x86)\Common Files\LogiShrd\Installer\{D40EB009-0499-459c-A8AF-C9C110766215}\uninstall.exe
C:\Program Files (x86)\Adobe\52df7d05-df7b-4abf-8cb0-684d1a20a3e7.dll
C:\Program Files (x86)\52df7d05-df7b-4abf-8cb0-684d1a20a3e7\5a89858f-5858-4f90-a59a-a2378246373a.dll
REG: Reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}"
REG: Reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"
REG: Reg delete "HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}"
REG: Reg delete "HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}"
REG: Reg delete "HKU\S-1-5-19\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}"
REG: Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}"
REG: Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\StormWatchApp.exe"
REG: Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}"
REG: Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Wow6432Node\CLSID\{BEBBC426-4F16-4567-8FE1-BE198C982027}"
REG: Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Wow6432Node\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}"

Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


If there are any personal files, pics, etc. on your computer you cannot live without, back them up now just as a precaution.
Emergency Backup Procedure - Tech Support Forum (http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/306529-emergency-backup-procedure.html)

Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

How to use ComboFix (http://www.bleepingcomputer.com/combofix/how-to-use-combofix)

Download ComboFix from here:
Link 1 (http://www.bleepingcomputer.com/download/combofix/)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
Link 3 (http://subs.geekstogo.com/ComboFix.exe)

Place ComboFix.exe on your Desktop <--Important

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

You can get help on disabling your protection programs here (http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/490111-how-disable-your-security-applications.html)
Double click on ComboFix.exe & follow the prompts.
You may be asked to install or update the Recovery Console (http://en.wikipedia.org/wiki/Recovery_Console) (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)
Your desktop may go blank. This is normal. It will return when ComboFix is done. Combofix may need to reboot your computer more than once to do its job this is normal.
When finished, it shall produce a log for you. Post that log in your next reply

Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

Ensure your AntiVirus and AntiSpyware applications are re-enabled.

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
If there are Internet issues after running ComboFix:
Internet Explorer:
Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" and check to "Automatically detect settings". Also clear any proxy address and port. ok, apply (only if applicable), ok.
Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection. "No Proxy" should be selected, unless you have one set up yourself.
Select -> Tools menu -> then "Options", then go to "Change Proxy Settings", then "LAN Settings" , then take out the check mark for "Use a proxy server for your LAN" if set, unless you set this up yourself.
Launch Safari
Go to general settings menu
Then in Preferences/ Advanced
Then on line click Proxies change settings ...
Click Internet Options, then click the Connections tab, click Network Settings.
Disable option (uncheck) for the use of proxy server ...


2015-02-04, 18:07
ComboFix 15-02-02.01 - Dad 02/04/2015 9:56.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6048.4045 [GMT -6:00]
Running from: c:\users\Dad\Desktop\ComboFix.exe
AV: ESET Smart Security 8.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Spybot - Search and Destroy *Disabled/Outdated* {20A26C15-1AF0-7CA3-9380-FAB824A7EE0D}
FW: ESET Personal firewall *Disabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 8.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
((((((((((((((((((((((((( Files Created from 2015-01-04 to 2015-02-04 )))))))))))))))))))))))))))))))
2015-02-04 16:01 . 2015-02-04 16:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-02-04 12:03 . 2015-02-04 12:16 -------- d-----w- c:\programdata\HitmanPro
2015-02-03 22:17 . 2015-02-03 22:17 -------- d-----w- c:\program files\ESET
2015-02-03 22:08 . 2015-02-03 22:08 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2015-02-03 18:52 . 2014-12-15 10:13 11870360 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2BB5E2F1-828B-4410-B6E5-40BBF42B9911}\mpengine.dll
2015-02-03 01:28 . 2015-02-03 01:28 -------- d-----w- c:\program files (x86)\ESET
2015-01-31 02:48 . 2015-01-31 02:48 -------- d-----w- c:\users\Dad\AppData\Local\VS Revo Group
2015-01-31 02:48 . 2015-01-31 02:48 -------- d-----w- c:\programdata\VS Revo Group
2015-01-31 02:48 . 2009-12-30 16:21 31800 ----a-w- c:\windows\system32\drivers\revoflt.sys
2015-01-31 02:48 . 2015-01-31 02:48 -------- d-----w- c:\program files\VS Revo Group
2015-01-29 01:51 . 2015-01-29 01:51 -------- d-----w- c:\programdata\Winferno
2015-01-29 01:19 . 2015-01-29 01:19 -------- d-----w- c:\program files (x86)\Karaoke Builder Player
2015-01-29 00:15 . 2015-02-04 01:54 -------- d-----w- c:\program files (x86)\52df7d05-df7b-4abf-8cb0-684d1a20a3e7
2015-01-29 00:15 . 2015-02-03 23:42 -------- d-----w- c:\programdata\fpebkpiipncfojhgaddgnofadahpmcjm
2015-01-28 23:54 . 2015-01-28 23:54 -------- d-----w- c:\users\Dad\AppData\Roaming\Publish Providers
2015-01-28 23:35 . 2015-01-28 23:54 -------- d-----w- c:\users\Dad\AppData\Roaming\Sony
2015-01-28 15:21 . 2015-01-28 15:26 -------- d-----w- c:\program files\Common Files\VST3
2015-01-28 15:21 . 2015-01-28 15:21 -------- d-----w- c:\program files\Common Files\Steinberg
2015-01-26 08:53 . 2015-01-26 08:53 -------- d-----w- c:\program files (x86)\Common Files\Java
2015-01-25 05:58 . 2008-07-12 14:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2015-01-16 00:43 . 2014-12-19 03:06 210432 ----a-w- c:\windows\system32\profsvc.dll
2015-01-16 00:43 . 2014-12-06 04:17 303616 ----a-w- c:\windows\system32\nlasvc.dll
2015-01-16 00:43 . 2014-12-06 03:50 52224 ----a-w- c:\windows\SysWow64\nlaapi.dll
2015-01-16 00:43 . 2014-12-06 03:50 156672 ----a-w- c:\windows\SysWow64\ncsi.dll
2015-01-16 00:43 . 2014-12-19 01:46 141312 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2015-01-16 00:43 . 2014-12-11 17:47 87040 ----a-w- c:\windows\system32\TSWbPrxy.exe
2015-01-16 00:42 . 2014-12-12 05:35 5553592 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-01-16 00:42 . 2014-12-12 05:11 3971512 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2015-01-16 00:42 . 2014-12-12 05:31 503808 ----a-w- c:\windows\system32\srcore.dll
2015-01-16 00:42 . 2014-12-12 05:31 50176 ----a-w- c:\windows\system32\srclient.dll
2015-01-16 00:42 . 2014-12-12 05:31 296960 ----a-w- c:\windows\system32\rstrui.exe
2015-01-16 00:42 . 2014-12-12 05:11 3916728 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2015-01-16 00:42 . 2014-12-12 05:07 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2015-01-16 00:40 . 2015-01-16 00:40 -------- d-----w- c:\users\Dad\AppData\Local\ESET
2015-01-07 22:10 . 2015-01-07 22:22 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-01-05 18:21 . 2014-12-13 05:09 144384 ----a-w- c:\windows\system32\ieUnatt.exe
2015-01-05 18:21 . 2014-12-13 03:33 115712 ----a-w- c:\windows\SysWow64\ieUnatt.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2015-02-04 06:46 . 2014-08-23 02:33 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-02-04 06:46 . 2014-08-23 02:33 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-02-03 22:02 . 2014-10-16 16:35 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-01-26 08:52 . 2014-10-16 21:38 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-01-16 09:00 . 2012-03-31 02:51 113365784 ----a-w- c:\windows\system32\MRT.exe
2015-01-08 15:55 . 2010-11-21 03:27 298120 ------w- c:\windows\system32\MpSigStub.exe
2015-01-07 23:35 . 2014-10-16 16:35 96472 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-01-04 21:12 . 2012-03-29 18:09 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2014-11-27 01:43 . 2015-01-04 21:24 389296 ----a-w- c:\windows\system32\iedkcs32.dll
2014-11-22 03:13 . 2015-01-04 21:24 25059840 ----a-w- c:\windows\system32\mshtml.dll
2014-11-22 03:06 . 2015-01-04 21:24 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-11-22 03:06 . 2015-01-04 21:24 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-11-22 02:50 . 2015-01-04 21:24 66560 ----a-w- c:\windows\system32\iesetup.dll
2014-11-22 02:50 . 2015-01-04 21:24 580096 ----a-w- c:\windows\system32\vbscript.dll
2014-11-22 02:49 . 2015-01-04 21:24 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-11-22 02:49 . 2015-01-04 21:24 2885120 ----a-w- c:\windows\system32\iertutil.dll
2014-11-22 02:48 . 2015-01-04 21:24 88064 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-11-22 02:41 . 2015-01-04 21:24 54784 ----a-w- c:\windows\system32\jsproxy.dll
2014-11-22 02:40 . 2015-01-04 21:24 34304 ----a-w- c:\windows\system32\iernonce.dll
2014-11-22 02:37 . 2015-01-04 21:24 633856 ----a-w- c:\windows\system32\ieui.dll
2014-11-22 02:35 . 2015-01-04 21:24 114688 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-11-22 02:34 . 2015-01-04 21:24 814080 ----a-w- c:\windows\system32\jscript9diag.dll
2014-11-22 02:34 . 2015-01-04 21:24 6039552 ----a-w- c:\windows\system32\jscript9.dll
2014-11-22 02:26 . 2015-01-04 21:24 968704 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-11-22 02:22 . 2015-01-04 21:24 490496 ----a-w- c:\windows\system32\dxtmsft.dll
2014-11-22 02:20 . 2015-01-04 21:24 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-11-22 02:14 . 2015-01-04 21:24 77824 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-11-22 02:09 . 2015-01-04 21:24 199680 ----a-w- c:\windows\system32\msrating.dll
2014-11-22 02:08 . 2015-01-04 21:24 92160 ----a-w- c:\windows\system32\mshtmled.dll
2014-11-22 02:07 . 2015-01-04 21:24 501248 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-11-22 02:07 . 2015-01-04 21:24 62464 ----a-w- c:\windows\SysWow64\iesetup.dll
2014-11-22 02:06 . 2015-01-04 21:24 47616 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2014-11-22 02:05 . 2015-01-04 21:24 64000 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-11-22 02:05 . 2015-01-04 21:24 316928 ----a-w- c:\windows\system32\dxtrans.dll
2014-11-22 01:54 . 2015-01-04 21:24 620032 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2014-11-22 01:49 . 2015-01-04 21:24 718848 ----a-w- c:\windows\system32\ie4uinit.exe
2014-11-22 01:49 . 2015-01-04 21:24 800768 ----a-w- c:\windows\system32\msfeeds.dll
2014-11-22 01:47 . 2015-01-04 21:24 1359360 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-11-22 01:46 . 2015-01-04 21:24 2125312 ----a-w- c:\windows\system32\inetcpl.cpl
2014-11-22 01:43 . 2015-01-04 21:24 14412800 ----a-w- c:\windows\system32\ieframe.dll
2014-11-22 01:40 . 2015-01-04 21:24 60416 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-11-22 01:29 . 2015-01-04 21:24 4299264 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-11-22 01:28 . 2015-01-04 21:24 2358272 ----a-w- c:\windows\system32\wininet.dll
2014-11-22 01:22 . 2015-01-04 21:24 2052096 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-11-22 01:21 . 2015-01-04 21:24 1155072 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2014-11-22 01:15 . 2015-01-04 21:24 1548288 ----a-w- c:\windows\system32\urlmon.dll
2014-11-22 01:03 . 2015-01-04 21:24 800768 ----a-w- c:\windows\system32\ieapfltr.dll
2014-11-22 01:00 . 2015-01-04 21:24 1888256 ----a-w- c:\windows\SysWow64\wininet.dll
2014-11-11 03:09 . 2015-01-04 21:23 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-11-11 03:08 . 2014-12-04 18:27 241152 ----a-w- c:\windows\system32\pku2u.dll
2014-11-11 03:08 . 2014-12-04 18:27 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-11-11 02:44 . 2015-01-04 21:23 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-11-11 02:44 . 2014-12-04 18:27 186880 ----a-w- c:\windows\SysWow64\pku2u.dll
2014-11-11 02:44 . 2014-12-04 18:27 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-11-11 01:46 . 2014-12-31 23:30 119296 ----a-w- c:\windows\system32\drivers\tdx.sys
2014-11-08 03:16 . 2015-01-04 21:19 2048 ----a-w- c:\windows\system32\tzres.dll
2014-11-08 02:45 . 2015-01-04 21:19 2048 ----a-w- c:\windows\SysWow64\tzres.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
2014-08-17 04:09 131480 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
2014-08-17 04:09 131480 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
2014-08-17 04:09 131480 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
2014-08-17 04:09 131480 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
2014-08-17 04:09 131480 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
2014-08-17 04:09 131480 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
2014-08-17 04:09 131480 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
2014-08-17 04:09 131480 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"RequireSignedAppInit_DLLs"=0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
R2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\\BBSvc.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
R3 cleanhlp;cleanhlp;c:\users\Dad\Desktop\bin\cleanhlp64.sys;c:\users\Dad\Desktop\bin\cleanhlp64.sys [x]
R3 CompFilter64;UVCCompositeFilter;c:\windows\system32\DRIVERS\lvbflt64.sys;c:\windows\SYSNATIVE\DRIVERS\lvbflt64.sys [x]
R3 GREGService;GREGService;c:\program files (x86)\Gateway\Registration\GREGsvc.exe;c:\program files (x86)\Gateway\Registration\GREGsvc.exe [x]
R3 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x]
R3 Live Updater Service;Live Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys;c:\windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 sxuptp;SXUPTP Driver;c:\windows\system32\DRIVERS\sxuptp.sys;c:\windows\SYSNATIVE\DRIVERS\sxuptp.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
R3 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 usbrndis6;USB RNDIS6 Adapter;c:\windows\system32\DRIVERS\usb80236.sys;c:\windows\SYSNATIVE\DRIVERS\usb80236.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 ss_conn_service;SAMSUNG Mobile Connectivity Service;c:\program files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe;c:\program files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [x]
S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\\SeaPort.exe [x]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
S3 LVUVC64;Logitech HD Webcam C310(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
Contents of the 'Scheduled Tasks' folder
2015-02-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-23 06:46]
2015-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-05 02:52]
2015-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-05 02:52]
2015-02-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001Core.job
- c:\users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe [2015-02-03 14:28]
2015-02-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001UA.job
- c:\users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe [2015-02-03 14:28]
--------- X64 Entries -----------
2014-08-17 04:10 164760 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
2014-08-17 04:10 164760 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
2014-08-17 04:10 164760 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
2014-08-17 04:10 164760 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
2014-08-17 04:10 164760 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
2014-08-17 04:10 164760 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
2014-08-17 04:10 164760 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
2014-08-17 04:10 164760 ----a-w- c:\users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2014-10-01 5595336]
------- Supplementary Scan -------
uLocal Page = c:\windows\system32\blank.htm
mDefault_Page_URL = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
TCP: DhcpNameServer =
FF - ProfilePath - c:\users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\
FF - prefs.js: browser.startup.homepage - www.msn.com
FF - prefs.js: network.proxy.type - 4
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
Notify-SDWinLogon - SDWinLogon.dll
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
AddRemove-MyFreeCodec - c:\program files (x86)\MyFree Codec\1.0b beta\uninstall.exe
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_296.ocx, 1"
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_296.ocx, 1"
@Denied: (A 2) (Everyone)
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
@Denied: (Full) (Everyone)
Completion time: 2015-02-04 10:04:30
ComboFix-quarantined-files.txt 2015-02-04 16:04
Pre-Run: 866,500,796,416 bytes free
Post-Run: 868,102,971,392 bytes free
- - End Of File - - 9A3DF6A25FEA5106BBC5F0857BAF3D66

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015
Ran by Dad at 2015-02-04 09:01:26 Run:9
Running from C:\Users\Dad\Desktop
Loaded Profiles: Dad (Available profiles: Dad)
Boot Mode: Normal

Content of fixlist:
C:\Program Files (x86)\Common Files\LogiShrd\Installer\{D40EB009-0499-459c-A8AF-C9C110766215}\uninstall.exe
C:\Program Files (x86)\Adobe\52df7d05-df7b-4abf-8cb0-684d1a20a3e7.dll
C:\Program Files (x86)\52df7d05-df7b-4abf-8cb0-684d1a20a3e7\5a89858f-5858-4f90-a59a-a2378246373a.dll
REG: Reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}"
REG: Reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"
REG: Reg delete "HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}"
REG: Reg delete "HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}"
REG: Reg delete "HKU\S-1-5-19\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}"
REG: Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}"
REG: Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\StormWatchApp.exe"
REG: Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}"
REG: Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Wow6432Node\CLSID\{BEBBC426-4F16-4567-8FE1-BE198C982027}"
REG: Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Wow6432Node\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}"

Processes closed successfully.
C:\Program Files (x86)\Common Files\LogiShrd\Installer\{D40EB009-0499-459c-A8AF-C9C110766215}\uninstall.exe => Moved successfully.
"C:\Program Files (x86)\Adobe\52df7d05-df7b-4abf-8cb0-684d1a20a3e7.dll" => File/Directory not found.
"C:\Program Files (x86)\52df7d05-df7b-4abf-8cb0-684d1a20a3e7\5a89858f-5858-4f90-a59a-a2378246373a.dll" => File/Directory not found.

========= Reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}" =========

Permanently delete the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298} (Yes/No)? The operation completed successfully.

========= End of Reg: =========

========= Reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}" =========

Permanently delete the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} (Yes/No)? The operation completed successfully.

========= End of Reg: =========

========= Reg delete "HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}" =========

Permanently delete the registry key HKEY_USERS\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} (Yes/No)? The operation completed successfully.

========= End of Reg: =========

========= Reg delete "HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}" =========

Permanently delete the registry key HKEY_USERS\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} (Yes/No)? ERROR: The system was unable to find the specified registry key or value.

========= End of Reg: =========

========= Reg delete "HKU\S-1-5-19\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}" =========

Permanently delete the registry key HKEY_USERS\S-1-5-19\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} (Yes/No)? The operation completed successfully.

========= End of Reg: =========

========= Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}" =========

Permanently delete the registry key HKEY_USERS\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} (Yes/No)? The operation completed successfully.

========= End of Reg: =========

========= Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\StormWatchApp.exe" =========

Permanently delete the registry key HKEY_USERS\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\StormWatchApp.exe (Yes/No)? ERROR: The system was unable to find the specified registry key or value.

========= End of Reg: =========

========= Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}" =========

Permanently delete the registry key HKEY_USERS\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} (Yes/No)? ERROR: The system was unable to find the specified registry key or value.

========= End of Reg: =========

========= Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Wow6432Node\CLSID\{BEBBC426-4F16-4567-8FE1-BE198C982027}" =========

Permanently delete the registry key HKEY_USERS\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Wow6432Node\CLSID\{BEBBC426-4F16-4567-8FE1-BE198C982027} (Yes/No)? The operation completed successfully.

========= End of Reg: =========

========= Reg delete "HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Wow6432Node\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}" =========

Permanently delete the registry key HKEY_USERS\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\Wow6432Node\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} (Yes/No)? The operation completed successfully.

========= End of Reg: =========

EmptyTemp: => Removed 457.5 MB temporary data.

The system needed a reboot.

==== End of Fixlog 09:01:35 ====

2015-02-04, 20:44
Tell me whats happening now?

2015-02-04, 23:56
well juliet everything seems to be doing fine. i've had one window pop up in 3 days now, it starts fine and runs good...sometimes it seems to drag a little loading a page but...we want it now and high speed internet has spoiled us. i don't think it will surf fast enough but what at some point we'll think it's dragging. i can't think of any hiccups these last few days i'd want to tell you about. it may very well have been taken care of by a heckuva nurse! it could be time to go home from the hospital. i guess if there is any clutter left hiding from the party it will show up at some point? i guess if so, i sure know where to go. what say you?

2015-02-05, 01:36
well juliet everything seems to be doing fine. i've had one window pop up in 3 days now, it starts fine and runs good...sometimes it seems to drag a little loading a page but...we want it now and high speed internet has spoiled us. i don't think it will surf fast enough but what at some point we'll think it's dragging. i can't think of any hiccups these last few days i'd want to tell you about. it may very well have been taken care of by a heckuva nurse! it could be time to go home from the hospital. i guess if there is any clutter left hiding from the party it will show up at some point? i guess if so, i sure know where to go. what say you?

it may very well have been taken care of by a heckuva nurse! <--LOL!

Don't know how old the machine is, or if you had a brand new one if surfing would be instant, but this is probably our end result.

I can say that if anything is left, like you say, it will rear it's ugly head then you can come back to us :)

Let's get rid of these tools and quarantine folders now. Then I'll send you on your merry way.



Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix)
or from here http://www.bleepingcomputer.com/download/delfix/ and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:

Activate UAC
Remove disinfection tools
Create registry backup
Purge system restore

Click the Run button.

-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


Answers to common security questions - Best Practices (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/) by quietman7, MVP
How Malware Spreads - How did I get infected? (http://www.bleepingcomputer.com/forums/t/287710/how-malware-spreads-how-did-i-get-infected/) by quietman7, MVP
Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/) by Lawrence Abrams, MVP
How to Prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html) by miekiemoes, MVP
How to backup and restore your data using Cobian Backup (http://www.bleepingcomputer.com/tutorials/backup-and-restore-data-with-cobian-backup/) by YourHighness
Slow Computer/browser? It May Not Be Malware (http://www.bleepingcomputer.com/forums/t/87058/slow-computerbrowser-check-here-first;-it-may-not-be-malware/) by quietman7, MVP

The following programmes come highly recommended in the security community.

http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xKsUqI5A.png.pagespeed.ic.vn1Hlvqi8h.jpgAdBlock (https://adblockplus.org/en/firefox) is a browser add-on that blocks annoying banners, pop-ups and video ads.
http://i.imgur.com/E8I37RF.pngCryptoPrevent (https://www.foolishit.com/) places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
http://i.imgur.com/EG85Vjt.png Malwarebytes Anti-Exploit (https://www.malwarebytes.org/antiexploit/) (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpgMalwarebytes Anti-Malware Premium (https://www.malwarebytes.org/) (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xjv4nhMJ.png.pagespeed.ic.A5YbWn1eDO.png NoScript (http://noscript.net/) is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
http://i.imgur.com/3O8r9Uq.png (http://www.sandboxie.com/) Sandboxie (http://www.sandboxie.com/) isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/DgW1XL2.png.pagespeed.ce.v1OlJl_ZAS.png Secuina PSI (http://secunia.com/vulnerability_scanning/personal/) will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xj1OLIec.png.pagespeed.ic.k6hhwopU0q.jpg SpywareBlaster (https://www.brightfort.com/spywareblaster.html) is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xJEP5iWI.png.pagespeed.ic.4tmM1lM7DQ.pngWeb of Trust (https://www.mywot.com/) (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

2015-02-05, 23:14
ok juliet...you have been an awesome help here. my pc is a gateway DX 4860 intel i3-2120 with 6.00GB and is about 3 years old...maybe 4. it's always been pretty fast. one thing i notice is scrolling...i have a cheap walmart mouse, is it is very sketchy and will hang, then take off. is this maybe something still hanging around or just normal for a cheap mouse?

2015-02-05, 23:37
gosh, don't know.

Also please download Windows Repair (all in one) from here (http://www.tweaking.com/content/page/windows_repair_all_in_one.html)

Install the program then go to step 4 and create a new system restore point and new registry backup.

Go to Step 2 and allow it to run CheckDisk by clicking on Do It button:

On the the Start Repairs tab => Click the Start

Please ensure that ONLY items seen in the image below are ticked as indicated (they're all checked by default):

Click on box next to the Restart System when Finished. Then click on Start.

2015-02-06, 06:22
uh oh! i don't know what's happened here...everything was fine. i dl the windows repair and ran it as said, i added some of the add ons you posted adblock, wot, noscript and secuina. went to eat, came back on and it took forever for firefox to open, and when it did it would just run and freeze up. i restarted again and went to system restore and ran it back to i think it was 8 am and it restored. on restarting i went to open firefox and it was slower than ever, once it opened i tried a game that uses java and opens in another window which would not load. i tried to close things and they all just freeze so i tried task mgr to kill firefox and my desktop went opaque white with a window saying the program windows is not responding, click to wait or close. i'd have to manually turn my pc off, cross my fingers and it came back on in safe mode with networking. i hope this is just some settings got jumbled somehow but i'm as scared as i was when all this started.

2015-02-06, 07:20
:oops: whew! never mind! i was able to come and dl the windows repair tool again since the system restore lost it and ran the chckdisk and removed the add ons i had added and it all seems good again. (knocking on my head) :laugh: :flowers:

2015-02-06, 13:56
Sounds like something was incompatible, don't know which one.

Download Security Check by screen317 from here (http://screen317.spywareinfoforum.org/SecurityCheck.exe).

Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.

2015-02-07, 02:42
well ever since my last post after i ran the scandisk or tool windows repair used it has seemed to be just fine...we'll see!

Results of screen317's Security Check version 0.99.96
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Spybot - Search and Destroy
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Malwarebytes Anti-Malware version
Java 8 Update 31
Java version 32-bit out of Date!
Java 64-bit 8 Update 31
Adobe Flash Player
Adobe Reader XI
Mozilla Firefox (35.0.1)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Spybot Teatimer.exe is disabled!
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 2%
````````````````````End of Log``````````````````````

2015-02-07, 04:23
I think we're ready to remove tools and quarantine folders?

2015-02-07, 06:45
you da boss! everything seems fine...knock on head...the scroll i told you about has changed completely and is now as smooth as i could want. i haven't noticed any other quirks of any kind and guess i'm ready to say i have no complaints...computers are a wonderful thing and the internet is a lovely place! (far cry from what i was screaming %#@& and &#%@# i was screaming! :lip:) so this is where we break up! i owe you dinner! :oreo: and :flowers: and a movie too! :share:

2015-02-07, 12:33
so this is where we break up! i owe you dinner!
You betcha!

http://i.imgur.com/AFZxnZc.jpg DelFix

Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix)
or from here http://www.bleepingcomputer.com/download/delfix/ and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:

Activate UAC
Remove disinfection tools
Create registry backup
Purge system restore

Click the Run button.

-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


Answers to common security questions - Best Practices (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/) by quietman7, MVP
How Malware Spreads - How did I get infected? (http://www.bleepingcomputer.com/forums/t/287710/how-malware-spreads-how-did-i-get-infected/) by quietman7, MVP
Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/) by Lawrence Abrams, MVP
How to Prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html) by miekiemoes, MVP
How to backup and restore your data using Cobian Backup (http://www.bleepingcomputer.com/tutorials/backup-and-restore-data-with-cobian-backup/) by YourHighness
Slow Computer/browser? It May Not Be Malware (http://www.bleepingcomputer.com/forums/t/87058/slow-computerbrowser-check-here-first;-it-may-not-be-malware/) by quietman7, MVP

The following programmes come highly recommended in the security community.

http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xKsUqI5A.png.pagespeed.ic.vn1Hlvqi8h.jpgAdBlock (https://adblockplus.org/en/firefox) is a browser add-on that blocks annoying banners, pop-ups and video ads.
http://i.imgur.com/E8I37RF.pngCryptoPrevent (https://www.foolishit.com/) places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
http://i.imgur.com/EG85Vjt.png Malwarebytes Anti-Exploit (https://www.malwarebytes.org/antiexploit/) (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpgMalwarebytes Anti-Malware Premium (https://www.malwarebytes.org/) (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xjv4nhMJ.png.pagespeed.ic.A5YbWn1eDO.png NoScript (http://noscript.net/) is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
http://i.imgur.com/3O8r9Uq.png (http://www.sandboxie.com/) Sandboxie (http://www.sandboxie.com/) isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/DgW1XL2.png.pagespeed.ce.v1OlJl_ZAS.png Secuina PSI (http://secunia.com/vulnerability_scanning/personal/) will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xj1OLIec.png.pagespeed.ic.k6hhwopU0q.jpg SpywareBlaster (https://www.brightfort.com/spywareblaster.html) is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xJEP5iWI.png.pagespeed.ic.4tmM1lM7DQ.pngWeb of Trust (https://www.mywot.com/) (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

2015-02-08, 17:06
ok juliet, done deal! unless something pops up here real soon and it looks like everything is fine, this will be the last post for me in this thread. no matter what i put here in ways of saying thanks are insufficient. you and tashi have both been a great help to me in cleaning out this mess and saving my pc. i can't see me affording another anytime soon and is a huge understatement to say it's a relief to me that you, tashi and safer networking helped. i hope you all know how thankful i am and a lot of others i'm sure for all the help...work, you do for us. thanks again! God bless!

2015-02-08, 18:29
You are so welcome (Arkansas neighbor)
We're glad to help :)

2015-02-14, 04:33
Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.