PDA

View Full Version : Infected with JS/Redirector.cv



Lanzo
2015-04-18, 20:50
Hi There,

I think my computer is infected with this Vrus/Trojan as this is what has been picked up by Mcaffee Anti virus.

Also I am having to log in from a different computer as I am unable to enter user name and password for this and other forums.

Here are the logs from the infected computer.

**************************************************

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-04-2015 01
Ran by Lan (administrator) on DAVES-PC on 18-04-2015 18:15:18
Running from C:\Users\Lan\Desktop
Loaded Profiles: Lan (Available profiles: Lan)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Program Files (x86)\Polar\Daemon\polard.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe
() C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
(Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
() C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
(SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\McTray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(SupportSoft, Inc.) C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [3200672 2010-06-30] (Dell Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10918504 2010-06-15] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [392048 2010-06-05] (Alps Electric Co., Ltd.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation)
HKLM-x32\...\Run: [Dell DataSafe Online] => C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe [1807680 2010-02-09] ()
HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [409744 2009-06-24] (Creative Technology Ltd)
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [498160 2009-10-15] ()
HKLM-x32\...\Run: [DellSupportCenter] => C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe [206064 2009-05-21] (SupportSoft, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [421160 2011-03-07] (Apple Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [ApnUpdater] => C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1561768 2012-05-04] (Ask)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [McAfeeUpdaterUI] => C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe [161088 2011-01-12] (McAfee, Inc.)
HKLM-x32\...\Run: [ShStatEXE] => C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE [215360 2011-01-12] (McAfee, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] => C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe [559616 2011-10-14] (Dell)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-2538772055-807052659-4255878346-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-2538772055-807052659-4255878346-1000\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [4280184 2012-03-08] (Microsoft Corporation)
HKU\S-1-5-21-2538772055-807052659-4255878346-1000\...\Run: [Polar Sync] => [X]
HKU\S-1-5-21-2538772055-807052659-4255878346-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22038120 2014-08-27] (Skype Technologies S.A.)
HKU\S-1-5-21-2538772055-807052659-4255878346-1000\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248176 2014-06-05] (TomTom)
HKU\S-1-5-21-2538772055-807052659-4255878346-1000\...\MountPoints2: {649dd088-cb24-11e3-9cdc-f04da2a9f971} - F:\HTC_Sync_Manager_PC.exe
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Lan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2538772055-807052659-4255878346-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
SearchScopes: HKU\S-1-5-21-2538772055-807052659-4255878346-1000 -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=05EAE370-52C2-4DA7-8B3B-EC1EF341C14F&apn_sauid=D733377F-E635-4137-BDE5-0641697C7837
SearchScopes: HKU\S-1-5-21-2538772055-807052659-4255878346-1000 -> {DFF76810-4974-4537-A87F-729407F78CEA} URL = http://search.yahoo.com/search?p={searchTerms}&b={startPage?}&fr=ie8
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20121116202331.dll [2012-11-16] (McAfee, Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-08-06] (Skype Technologies S.A.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll [2009-01-26] (Safer Networking Limited)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll No File
BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20121116202333.dll [2012-11-16] (McAfee, Inc.)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-08-06] (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-04-01] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll No File
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-04-01] (Microsoft Corporation.)
Toolbar: HKU\S-1-5-21-2538772055-807052659-4255878346-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Handler-x32: http - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation)
Handler-x32: http - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation)
Handler-x32: https - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation)
Handler-x32: https - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation)
Handler-x32: ipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-08-06] (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-08-06] (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2011-03-06] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-06-22] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-06-22] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-11]
CHR Extension: (Google Docs) - C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-11]
CHR Extension: (Google Drive) - C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-11]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-11]
CHR Extension: (YouTube) - C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-11]
CHR Extension: (Google Search) - C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-11]
CHR Extension: (Google Sheets) - C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-11]
CHR Extension: (Google Wallet) - C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-11]
CHR Extension: (Gmail) - C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-11]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2009-06-09] (Stardock Corporation) [File not signed]
R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-08-04] (Nero AG)
R2 McAfeeFramework; C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe [120128 2011-01-12] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [190256 2012-11-16] (McAfee, Inc.)
R2 McTaskManager; C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe [209760 2011-01-12] (McAfee, Inc.)
R2 mfevtp; C:\windows\system32\mfevtps.exe [156248 2012-11-16] (McAfee, Inc.)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 Polar Daemon; C:\Program Files (x86)\Polar\Daemon\polard.exe [419536 2012-12-12] ()
R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1919256 2015-02-12] (IBM Corp.)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 f1f78e38; "C:\windows\system32\rundll32.exe" "c:\progra~3\winspeed\WinSpeedSvc.dll",service

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-04-17] (Malwarebytes Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [153952 2012-11-16] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [217696 2012-11-16] (McAfee, Inc.)
U3 mfeavfk01; No ImagePath
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [607152 2012-11-16] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [97960 2012-11-16] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [281544 2012-11-16] (McAfee, Inc.)
S3 MosIrUsb; C:\Windows\System32\DRIVERS\MosIrUsb.sys [27648 2007-10-11] ()
R1 RapportCerberus_80128; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_80128.sys [844440 2015-02-25] (IBM Corp.)
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [445816 2015-02-12] (IBM Corp.)
R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [535576 2015-02-12] (IBM Corp.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [558872 2015-02-12] (IBM Corp.)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 RT-USB; C:\Windows\System32\drivers\RT-USB64.SYS [97152 2014-05-12] (Ross-Tech LLC)
S3 STIrUsb; C:\Windows\System32\DRIVERS\irstusb.sys [33792 2008-01-19] (SigmaTel, Inc.)
S3 StMp3Recx64; C:\Windows\System32\Drivers\StMp3Recx64.sys [26112 2007-01-12] (Generic)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-18 18:15 - 2015-04-18 18:15 - 00023082 _____ () C:\Users\Lan\Desktop\FRST.txt
2015-04-18 18:15 - 2015-04-18 18:15 - 00000000 ____D () C:\Users\Lan\Desktop\FRST-OlderVersion
2015-04-17 21:18 - 2015-04-17 21:59 - 00030464 _____ () C:\Users\Lan\Downloads\Addition.txt
2015-04-17 21:14 - 2015-04-17 22:01 - 00019641 _____ () C:\Users\Lan\Downloads\FRST.txt
2015-04-17 21:13 - 2015-04-18 18:15 - 00000000 ____D () C:\FRST
2015-04-17 21:08 - 2015-04-18 18:15 - 02098176 _____ (Farbar) C:\Users\Lan\Desktop\FRST64.exe
2015-04-17 20:57 - 2015-04-17 20:58 - 02097664 _____ (Farbar) C:\Users\Lan\FRST64.exe
2015-04-17 15:50 - 2015-04-17 15:50 - 00000000 ____D () C:\Users\Lan\AppData\Local\{B25194E5-0405-4937-B6F1-FAAF4DA03D84}
2015-04-16 06:46 - 2015-04-16 21:09 - 00000000 ____D () C:\Users\Lan\AppData\Local\{669F68B2-B800-42B0-AB29-77688B4AEB1D}
2015-04-15 22:13 - 2015-04-02 01:17 - 00389808 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-04-15 22:13 - 2015-04-02 00:49 - 00342704 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-04-15 22:13 - 2015-03-13 05:32 - 24980480 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-04-15 22:13 - 2015-03-13 05:25 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-04-15 22:13 - 2015-03-13 05:25 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-04-15 22:13 - 2015-03-13 05:09 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-04-15 22:13 - 2015-03-13 05:08 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-04-15 22:13 - 2015-03-13 05:08 - 00417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-04-15 22:13 - 2015-03-13 05:08 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-04-15 22:13 - 2015-03-13 05:07 - 02886144 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-04-15 22:13 - 2015-03-13 05:06 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-04-15 22:13 - 2015-03-13 05:00 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-04-15 22:13 - 2015-03-13 04:59 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-04-15 22:13 - 2015-03-13 04:55 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-04-15 22:13 - 2015-03-13 04:54 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-04-15 22:13 - 2015-03-13 04:54 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-04-15 22:13 - 2015-03-13 04:53 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-04-15 22:13 - 2015-03-13 04:50 - 06025216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-04-15 22:13 - 2015-03-13 04:44 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-04-15 22:13 - 2015-03-13 04:42 - 19695616 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-04-15 22:13 - 2015-03-13 04:42 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-04-15 22:13 - 2015-03-13 04:40 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-04-15 22:13 - 2015-03-13 04:32 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 22:13 - 2015-03-13 04:28 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-04-15 22:13 - 2015-03-13 04:28 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-04-15 22:13 - 2015-03-13 04:27 - 00340992 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-04-15 22:13 - 2015-03-13 04:27 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-04-15 22:13 - 2015-03-13 04:27 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-04-15 22:13 - 2015-03-13 04:26 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-04-15 22:13 - 2015-03-13 04:26 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-04-15 22:13 - 2015-03-13 04:23 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-04-15 22:13 - 2015-03-13 04:22 - 02278400 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-04-15 22:13 - 2015-03-13 04:20 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-04-15 22:13 - 2015-03-13 04:20 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-04-15 22:13 - 2015-03-13 04:17 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-04-15 22:13 - 2015-03-13 04:16 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-04-15 22:13 - 2015-03-13 04:15 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-04-15 22:13 - 2015-03-13 04:08 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-04-15 22:13 - 2015-03-13 04:07 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-04-15 22:13 - 2015-03-13 04:06 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-04-15 22:13 - 2015-03-13 04:05 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-04-15 22:13 - 2015-03-13 04:05 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-04-15 22:13 - 2015-03-13 04:01 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-04-15 22:13 - 2015-03-13 04:00 - 14397440 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-04-15 22:13 - 2015-03-13 03:57 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-04-15 22:13 - 2015-03-13 03:56 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-04-15 22:13 - 2015-03-13 03:54 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-04-15 22:13 - 2015-03-13 03:49 - 04305408 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-04-15 22:13 - 2015-03-13 03:45 - 02358784 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-04-15 22:13 - 2015-03-13 03:44 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-04-15 22:13 - 2015-03-13 03:43 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-04-15 22:13 - 2015-03-13 03:42 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-04-15 22:13 - 2015-03-13 03:34 - 12825600 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-04-15 22:13 - 2015-03-13 03:33 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-04-15 22:13 - 2015-03-13 03:22 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-04-15 22:13 - 2015-03-13 03:20 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-04-15 22:13 - 2015-03-13 03:16 - 01311232 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-04-15 22:13 - 2015-03-13 03:14 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-04-15 22:05 - 2015-03-25 04:24 - 03298816 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-04-15 22:05 - 2015-03-25 04:24 - 02553856 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-04-15 22:05 - 2015-03-25 04:24 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-04-15 22:05 - 2015-03-25 04:24 - 00191488 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-04-15 22:05 - 2015-03-25 04:24 - 00098304 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-04-15 22:05 - 2015-03-25 04:24 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-04-15 22:05 - 2015-03-25 04:24 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-04-15 22:05 - 2015-03-25 04:24 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-04-15 22:05 - 2015-03-25 04:23 - 00135168 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-04-15 22:05 - 2015-03-25 04:23 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-04-15 22:05 - 2015-03-25 04:23 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-04-15 22:05 - 2015-03-25 04:00 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-04-15 22:05 - 2015-03-25 04:00 - 00173056 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-04-15 22:05 - 2015-03-25 04:00 - 00092672 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-04-15 22:05 - 2015-03-25 04:00 - 00033792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-04-15 22:05 - 2015-03-25 04:00 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-04-15 22:05 - 2015-02-25 04:18 - 00754688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2015-04-15 22:02 - 2015-03-23 04:25 - 00769536 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-04-15 22:02 - 2015-03-23 04:25 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-04-15 22:02 - 2015-03-23 04:24 - 00957952 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-04-15 22:02 - 2015-03-23 04:24 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-04-15 22:02 - 2015-03-23 04:24 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-04-15 22:02 - 2015-03-23 04:24 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-04-15 22:02 - 2015-03-23 04:24 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-04-15 22:02 - 2015-03-23 04:17 - 01111552 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-04-15 22:02 - 2015-03-10 04:25 - 01882624 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-04-15 22:02 - 2015-03-10 04:21 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-04-15 22:02 - 2015-03-10 04:08 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-04-15 22:02 - 2015-03-10 04:05 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-04-15 22:02 - 2015-03-05 06:12 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-04-15 22:02 - 2015-03-05 05:05 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-04-15 22:01 - 2015-03-17 06:22 - 05557696 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-04-15 22:01 - 2015-03-17 06:22 - 00155576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-04-15 22:01 - 2015-03-17 06:22 - 00095672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-04-15 22:01 - 2015-03-17 06:19 - 01727904 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-04-15 22:01 - 2015-03-17 06:17 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-04-15 22:01 - 2015-03-17 06:17 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-04-15 22:01 - 2015-03-17 06:17 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-04-15 22:01 - 2015-03-17 06:16 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-04-15 22:01 - 2015-03-17 06:16 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-04-15 22:01 - 2015-03-17 06:16 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-04-15 22:01 - 2015-03-17 06:15 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-04-15 22:01 - 2015-03-17 06:15 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-04-15 22:01 - 2015-03-17 06:15 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-04-15 22:01 - 2015-03-17 06:13 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-04-15 22:01 - 2015-03-17 06:13 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 06:01 - 03976632 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-04-15 22:01 - 2015-03-17 06:01 - 03920824 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-04-15 22:01 - 2015-03-17 05:59 - 01309696 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-04-15 22:01 - 2015-03-17 05:57 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-04-15 22:01 - 2015-03-17 05:57 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-04-15 22:01 - 2015-03-17 05:57 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-04-15 22:01 - 2015-03-17 05:57 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-04-15 22:01 - 2015-03-17 05:57 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-04-15 22:01 - 2015-03-17 05:57 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-04-15 22:01 - 2015-03-17 05:57 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-04-15 22:01 - 2015-03-17 05:57 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-04-15 22:01 - 2015-03-17 05:57 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-04-15 22:01 - 2015-03-17 05:56 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-04-15 22:01 - 2015-03-17 05:56 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-04-15 22:01 - 2015-03-17 05:56 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-04-15 22:01 - 2015-03-17 05:56 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-04-15 22:01 - 2015-03-17 05:56 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-04-15 22:01 - 2015-03-17 05:56 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-04-15 22:01 - 2015-03-17 05:56 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-04-15 22:01 - 2015-03-17 05:53 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-04-15 22:01 - 2015-03-17 05:53 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 05:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 04:45 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-04-15 22:01 - 2015-03-17 04:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-04-15 22:01 - 2015-03-17 04:43 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 04:43 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 04:43 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 22:01 - 2015-03-17 04:43 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-15 21:48 - 2015-03-04 05:55 - 00367552 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2015-04-15 21:48 - 2015-03-04 05:41 - 00079360 _____ (Microsoft Corporation) C:\windows\system32\clfsw32.dll
2015-04-15 21:48 - 2015-03-04 05:10 - 00058880 _____ (Microsoft Corporation) C:\windows\SysWOW64\clfsw32.dll
2015-04-15 21:15 - 2015-04-15 21:15 - 00000000 ____D () C:\Users\Lan\AppData\Local\TrayClient
2015-04-14 17:34 - 2015-04-15 17:52 - 00000000 ____D () C:\Users\Lan\AppData\Local\{B97CF4A6-1904-4FCF-A15A-C8B3FD511CB2}
2015-04-13 16:17 - 2015-04-13 16:17 - 00000000 ____D () C:\Users\Lan\AppData\Local\{CDB12371-CE10-4FC1-BA29-122C56BF65BE}
2015-04-12 16:06 - 2015-04-15 21:15 - 00000000 ____D () C:\Program Files (x86)\TrayClient
2015-04-12 16:05 - 2015-04-12 16:05 - 00000000 ____D () C:\Users\Lan\AppData\Roaming\plesome
2015-04-05 03:02 - 2015-04-05 03:02 - 00000000 ___SD () C:\windows\SysWOW64\GWX
2015-04-05 03:02 - 2015-04-05 03:02 - 00000000 ___SD () C:\windows\system32\GWX
2015-03-30 06:36 - 2015-04-12 21:01 - 00000000 ____D () C:\Users\Lan\AppData\Local\{35D7F017-687A-4E61-B6C1-D0DAE9C7ADA6}
2015-03-26 21:19 - 2015-03-29 10:20 - 00000000 ____D () C:\Users\Lan\AppData\Local\{C689357B-30A8-4825-8002-37B49384EEFD}
2015-03-24 07:49 - 2015-03-26 04:01 - 00000000 ____D () C:\Users\Lan\AppData\Local\{EC73A233-157C-43C0-BAAB-317D418B61BE}
2015-03-24 07:43 - 2015-03-24 07:43 - 00277584 _____ () C:\windows\Minidump\032415-48719-01.dmp
2015-03-22 13:12 - 2015-04-09 14:30 - 00010921 _____ () C:\Users\Lan\Documents\Dionne Period.xlsx

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-18 18:04 - 2010-11-02 19:10 - 01158743 _____ () C:\windows\WindowsUpdate.log
2015-04-18 18:00 - 2009-07-14 05:45 - 00022704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-18 18:00 - 2009-07-14 05:45 - 00022704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-18 17:53 - 2011-08-13 23:36 - 00000892 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-18 17:37 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\AppCompat
2015-04-18 17:36 - 2012-10-23 20:37 - 00000000 ____D () C:\QUARANTINE
2015-04-18 17:30 - 2014-03-29 19:26 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-04-18 17:27 - 2011-08-13 23:36 - 00000888 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-17 22:40 - 2013-09-21 20:02 - 00034304 _____ () C:\Users\Lan\Documents\Copy of Pass.xls
2015-04-17 21:48 - 2011-09-07 18:57 - 00000000 ____D () C:\Users\Lan\AppData\Roaming\Skype
2015-04-17 21:02 - 2011-04-05 18:52 - 00000000 ___RD () C:\Users\Lan
2015-04-17 16:25 - 2014-08-26 22:56 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-17 15:49 - 2012-08-10 22:02 - 00000000 ____D () C:\Users\Lan\Tracing
2015-04-17 15:47 - 2014-08-13 13:54 - 00000000 ____D () C:\Users\Lan\AppData\Local\HTC MediaHub
2015-04-17 15:46 - 2011-04-05 18:56 - 00000000 ____D () C:\Users\Default\AppData\Local\SoftThinks
2015-04-17 15:46 - 2011-04-05 18:56 - 00000000 ____D () C:\Users\Default User\AppData\Local\SoftThinks
2015-04-17 15:46 - 2010-11-02 20:18 - 00000000 ____D () C:\Program Files (x86)\Dell DataSafe Local Backup
2015-04-17 15:45 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-04-17 15:45 - 2009-07-14 05:51 - 00119404 _____ () C:\windows\setupact.log
2015-04-16 00:06 - 2014-12-12 04:19 - 00000000 ____D () C:\windows\system32\appraiser
2015-04-16 00:06 - 2014-05-01 03:02 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-04-16 00:06 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2015-04-16 00:05 - 2011-04-05 23:28 - 00476170 _____ () C:\windows\PFRO.log
2015-04-15 23:09 - 2011-04-05 23:04 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-15 23:06 - 2012-10-13 22:06 - 00773968 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2015-04-15 23:06 - 2009-07-14 06:13 - 00773968 _____ () C:\windows\system32\PerfStringBackup.INI
2015-04-15 23:00 - 2013-08-09 03:09 - 00000000 ____D () C:\windows\system32\MRT
2015-04-15 22:52 - 2011-05-03 21:08 - 128913832 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-04-15 22:52 - 2009-07-14 03:34 - 00000478 _____ () C:\windows\win.ini
2015-04-14 20:47 - 2014-03-29 19:26 - 00778416 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-04-14 20:47 - 2014-03-29 19:26 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-04-14 20:47 - 2011-09-24 15:20 - 00142512 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-12 17:21 - 2011-04-07 19:27 - 00000000 ____D () C:\Users\Lan\AppData\Local\Adobe
2015-04-07 14:33 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\NDF
2015-03-30 14:36 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2015-03-24 07:48 - 2009-07-14 06:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD
2015-03-24 07:43 - 2012-12-08 18:32 - 00000000 ____D () C:\windows\Minidump
2015-03-24 07:43 - 2012-12-08 18:31 - 482812832 _____ () C:\windows\MEMORY.DMP

==================== Files in the root of some directories =======

2011-10-21 20:33 - 2011-10-21 20:33 - 0007605 _____ () C:\Users\Lan\AppData\Local\Resmon.ResmonCfg
2011-09-07 19:01 - 2011-09-07 19:01 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2014-12-31 13:22 - 2015-01-01 14:27 - 0007841 _____ () C:\ProgramData\hpzinstall.log

Files to move or delete:
====================
C:\Users\Lan\FRST64.exe


Some content of TEMP:
====================
C:\Users\Lan\AppData\Local\Temp\APNSetup.exe
C:\Users\Lan\AppData\Local\Temp\ebccabfbdfbcg.exe
C:\Users\Lan\AppData\Local\Temp\ICReinstall_photomerge-4.2.2.exe
C:\Users\Lan\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Lan\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\Lan\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Lan\AppData\Local\Temp\n8iyaj3w.dll
C:\Users\Lan\AppData\Local\Temp\optprosetup.exe
C:\Users\Lan\AppData\Local\Temp\ose00000.exe
C:\Users\Lan\AppData\Local\Temp\ose00001.exe
C:\Users\Lan\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Lan\AppData\Local\Temp\UpdaterCopy.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-05 15:16

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-04-2015 01
Ran by Lan at 2015-04-18 18:16:45
Running from C:\Users\Lan\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: McAfee VirusScan Enterprise (Enabled - Up to date) {86355677-4064-3EA7-ABB3-1B136EB04637}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee VirusScan Enterprise Antispyware Module (Enabled - Up to date) {3D54B793-665E-3129-9103-206115370C8A}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
AapptooUU (HKLM-x32\...\{01B91C29-337A-1FFD-7CFC-473451D2F861}) (Version: - ApptoU) <==== ATTENTION
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.2.0.2070 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Photoshop Elements 8.0 (HKLM-x32\...\Adobe Photoshop Elements 8.0) (Version: 8.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
Apple Application Support (HKLM-x32\...\{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}) (Version: 1.5.0 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{8F473675-D702-45F9-8EBC-342B40C17BF5}) (Version: 3.4.0.25 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.15.2.0 - Ask.com) <==== ATTENTION
Ask Toolbar Updater (HKU\S-1-5-21-2538772055-807052659-4255878346-1000\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.1.23037 - Ask.com) <==== ATTENTION
Audacity 1.3.13 (Unicode) (HKLM-x32\...\Audacity 1.3 Beta (Unicode)_is1) (Version: - Audacity Team)
Bing Bar (HKLM-x32\...\{449CE12D-E2C7-4B97-B19E-55D163EA9435}) (Version: 7.0.619.0 - Microsoft Corporation)
Bonjour (HKLM\...\{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}) (Version: 2.0.4.0 - Apple Inc.)
Canon MP Navigator 3.1 (HKLM-x32\...\MP Navigator 3.1) (Version: - )
Canon MP140 series (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series) (Version: - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell)
Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell)
Dell DataSafe Online (HKLM-x32\...\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.2.0011 - Dell, Inc.)
Dell Dock (HKLM-x32\...\Dell Dock) (Version: - Stardock Corporation)
Dell Dock (Version: 2.0 - Stardock Corporation) Hidden
Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell Support Center (Support Software) (HKLM-x32\...\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}) (Version: 2.5.09100 - Dell)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1107.101.209 - ALPS ELECTRIC CO., LTD.)
Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 1.40.05 - Creative Technology Ltd)
GetDiscountApp (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - GetDiscountApp) <==== ATTENTION
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
GoToAssist 8.0.0.514 (HKLM-x32\...\GoToAssist) (Version: - )
HTC BMP USB Driver (HKLM-x32\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
HTC Driver Installer (HKLM-x32\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.13.0.003 - HTC Corporation)
HTC Sync Manager (HKLM-x32\...\{231D0C79-98A6-4693-A366-36DE7D7346EC}) (Version: 3.1.24.5 - HTC)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.2202 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.4.1002 - Intel Corporation)
IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC)
iTunes (HKLM\...\{9545E9DB-6F4C-4404-BF25-E221BE8B44C5}) (Version: 10.2.1.1 - Apple Inc.)
J2SE Runtime Environment 5.0 Update 17 (HKLM-x32\...\{3248F0A8-6813-11D6-A77B-00B0D0150170}) (Version: 1.5.0.170 - Sun Microsystems, Inc.)
Java 7 Update 21 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217017FF}) (Version: 7.0.210 - Oracle)
Java(TM) 6 Update 18 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416018F0}) (Version: 6.0.180 - Sun Microsystems, Inc.)
Java(TM) 6 Update 20 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416020FF}) (Version: 6.0.200 - Sun Microsystems, Inc.)
Java(TM) 6 Update 33 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216033FF}) (Version: 6.0.330 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LAME v3.98.3 for Audacity (HKLM-x32\...\LAME for Audacity_is1) (Version: - )
Live! Cam Avatar Creator (HKLM-x32\...\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.3009.1 - Creative Technology Ltd)
LoJack Factory Installer (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 1.0.0 - Absolute Software)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
McAfee Agent (HKLM-x32\...\{2AAB21C2-4CDA-4189-A0EC-5ED666113F84}) (Version: 4.5.0.1810 - McAfee, Inc.)
McAfee VirusScan Enterprise (HKLM-x32\...\{CE15D1B6-19B6-4D4D-8F43-CF5D2C3356FF}) (Version: 8.8.00000 - McAfee, Inc.)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Project 2000 (HKLM-x32\...\{2DFE1608-BDCA-11D1-B7AE-00C04FB92F3D}) (Version: 9.00.3821 - Microsoft Corporation)
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs (HKLM-x32\...\{90120000-00B2-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
plesome (HKLM-x32\...\{0e54a17d-5e58-4556-6665-932929b567cf}) (Version: 1.0.0 - someautu) <==== ATTENTION!
Polar Daemon (HKLM-x32\...\{2BA9320D-E061-4C71-ACCB-AC0E9D4FC82B}) (Version: 2.2.20000 - Polar Electro Oy)
Polar ProTrainer (HKLM-x32\...\{DF7DBA84-0A55-11D6-A0A6-6A7573736972}) (Version: 5.40.170 - )
Polar WebLink 2.4.13 (HKLM-x32\...\{A1ABB265-926B-481C-8A51-8125566DFE82}) (Version: 02.49.0004 - Polar Electro Oy)
Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.06.02 - Dell Inc.)
QuickTime (HKLM-x32\...\{57752979-A1C9-4C02-856B-FBB27AC4E02C}) (Version: 7.69.80.9 - Apple Inc.)
Rapport (Version: 3.5.1201.94 - Trusteer) Hidden
Rapport (x32 Version: 3.5.1404.75 - Trusteer) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6136 - Realtek Semiconductor Corp.)
Roxio Burn (HKLM-x32\...\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.01 - Roxio)
saferweb (HKLM-x32\...\{5F488658-35A7-2AB8-A756-560BA8F103C3}) (Version: - "") <==== ATTENTION
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.11.13307 - Skype Technologies S.A.)
Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
SopCast 3.2.9 (HKLM-x32\...\SopCast) (Version: 3.2.9 - www.sopcast.com)
Spelling Dictionaries Support For Adobe Reader 9 (HKLM-x32\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
TomTom HOME (HKLM-x32\...\{7A2BB1C8-903D-4585-9F3B-CADD67D07D37}) (Version: 2.9.8 - TomTom)
TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1404.75 - Trusteer)
VCDS Release 11.11.5 (HKLM-x32\...\VCDS Release 11.11) (Version: 11.11.5 - Ross-Tech)
VCDS Release 12.12.3 (HKLM-x32\...\VCDS Release 12.12) (Version: 12.12.3 - Ross-Tech)
VCDS Release 14.10.1 (HKLM-x32\...\VCDS Release) (Version: 14.10.1 - Ross-Tech)
WildTangent Games (HKLM-x32\...\WildTangent dell Master Uninstall) (Version: 1.0.0.71 - WildTangent)
Windows Driver Package - Ross-Tech USB Driver Package (05/12/2014 2.10.00) (HKLM\...\88B02C4BD09AA7910C55C4E74BE8F036244B5CF9) (Version: 05/12/2014 2.10.00 - Ross-Tech)
Windows Driver Package - Ross-Tech USB Driver Package (06/16/2010 2.06.02) (HKLM\...\F2D626F9A8E5C6126BED6EBD3E3504D0B2AB8443) (Version: 06/16/2010 2.06.02 - Ross-Tech)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2538772055-807052659-4255878346-1000_Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InprocServer32 -> C:\Users\Lan\AppData\Roaming\plesome\enat.dll () <==== ATTENTION

==================== Restore Points =========================

20-03-2015 18:30:29 Windows Update
26-03-2015 04:01:05 Windows Update
31-03-2015 06:51:56 Windows Update
03-04-2015 11:40:34 Windows Update
05-04-2015 03:00:28 Windows Update
14-04-2015 20:43:28 Windows Update
15-04-2015 22:35:30 Windows Update

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {172B7426-B554-4A8D-9C19-3B3C7AB5EB4E} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-14] (Adobe Systems Incorporated)
Task: {3D4DEBD7-A26F-47C8-A2BE-8E4F3E51633D} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {434D8095-0873-4CB5-A302-175165303896} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
Task: {6F8E271B-3DFA-4181-B7E6-C1696E79FDC2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-13] (Google Inc.)
Task: {7418439A-ADBF-4D2A-BD17-6969F5EEB1B2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-13] (Google Inc.)
Task: {798B503E-C43A-459B-A9F8-E16D87B5D431} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {7C6B9C37-55F8-45CF-8A8D-C73AC758E516} - System32\Tasks\{43DE22BB-00B7-4D28-A23A-FD65BC0E1F0D} => pcalua.exe -a C:\Users\Lan\Downloads\HP_Vista_SF_Ph1.exe -d C:\Users\Lan\Downloads
Task: {91444CE1-05DB-4842-A657-4C8FDD3E651E} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {92496AAC-7A64-4FFC-A3DD-5E1DF03F2E03} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {97D6C0F0-EBB6-4649-A640-0063E1521C87} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {A8E42481-B5C5-4528-B276-20A576AB24C0} - System32\Tasks\{5378C27B-9FA0-4193-BB76-EEAC0A1A9236} => pcalua.exe -a C:\Users\Lan\Downloads\reflash_package.exe -d C:\Users\Lan\Downloads
Task: {C275EC79-328B-437B-A8B3-960001EFB8C1} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {DDC3D4FD-7E5D-4143-83A1-A061688BB09B} - System32\Tasks\LoJack for Laptops Install => C:\Program Files (x86)\Absolute Software\LoJack Install\FactoryInstaller.exe [2009-11-26] (Absolute Software)
Task: {EDDB27D2-9E1B-4585-BDDA-5C05CB0BF20C} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {F8D81E00-9EEB-4A9E-8889-A9981CDE426E} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2012-05-04] () <==== ATTENTION
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2015-04-01 20:43 - 2015-04-01 20:43 - 00172544 _____ () C:\Users\Lan\AppData\Roaming\plesome\enat.dll
2013-10-17 15:27 - 2013-10-17 15:27 - 00166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
2012-12-12 16:20 - 2012-12-12 16:20 - 00419536 _____ () C:\Program Files (x86)\Polar\Daemon\polard.exe
2014-08-06 13:42 - 2014-08-06 13:42 - 00821600 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
2010-11-02 20:18 - 2011-08-18 17:05 - 02751808 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
2014-10-16 04:16 - 2014-10-16 04:16 - 00472576 _____ () C:\windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\c29d8779b3a3599f44e21e017541cd0c\VistaBridgeLibrary.ni.dll
2010-02-09 19:34 - 2010-02-09 19:34 - 01807680 _____ () C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
2009-10-15 09:10 - 2009-10-15 09:10 - 00498160 _____ () C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
2014-08-06 13:40 - 2014-08-06 13:40 - 00031080 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DbAccess.dll
2014-08-06 13:41 - 2014-08-06 13:41 - 00607376 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\sqlite3.dll
2014-08-06 13:41 - 2014-08-06 13:41 - 00059752 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NAdvLog.dll
2014-08-06 13:41 - 2014-08-06 13:41 - 00036216 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NFileCacheDBAccess.dll
2014-08-06 13:42 - 2014-08-06 13:42 - 00080248 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\ninstallerhelper.dll
2014-08-06 13:44 - 2014-08-06 13:44 - 00129376 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\zlib1.dll
2014-08-06 13:46 - 2014-08-06 13:46 - 00223592 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DevConnMon.dll
2007-04-18 20:30 - 2007-04-18 20:30 - 00393216 _____ () C:\Program Files (x86)\McAfee\Common Framework\cryptocme2.dll
2007-04-18 20:30 - 2007-04-18 20:30 - 00471040 _____ () C:\Program Files (x86)\McAfee\Common Framework\ccme_base.dll
2011-01-12 17:05 - 2011-01-12 17:05 - 00065536 _____ () C:\Program Files (x86)\McAfee\Common Framework\boost_thread-vc80-mt-1_32.dll
2014-03-23 17:04 - 2014-03-23 17:04 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll
2011-01-12 09:08 - 2011-01-12 09:08 - 00150032 _____ () C:\Program Files (x86)\McAfee\VirusScan Enterprise\WscAv.dll
2012-12-12 16:20 - 2012-12-12 16:20 - 03483856 _____ () C:\Program Files (x86)\Polar\Daemon\libpolar.dll
2010-02-09 19:34 - 2010-02-09 19:34 - 00275776 _____ () C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll
2010-02-09 19:34 - 2010-02-09 19:34 - 00058688 _____ () C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll
2010-02-09 19:34 - 2010-02-09 19:34 - 00095552 _____ () C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll
2010-02-09 19:34 - 2010-02-09 19:34 - 00152896 _____ () C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll
2010-02-09 19:34 - 2010-02-09 19:34 - 00017728 _____ () C:\Program Files (x86)\Dell DataSafe Online\cpputils.dll
2011-02-06 11:32 - 2011-02-06 11:32 - 00067872 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-16 04:04 - 2014-10-16 04:04 - 00170496 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\9419a7c2030ade01725f8fd9344e218d\IsdiInterop.ni.dll
2010-11-02 19:46 - 2010-06-08 16:44 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2015-04-01 20:43 - 2015-04-01 20:43 - 00144384 _____ () C:\Users\Lan\AppData\Roaming\plesome\oftuget.dll
2013-02-14 16:46 - 2013-02-14 16:46 - 01044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2538772055-807052659-4255878346-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Lan\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-2538772055-807052659-4255878346-500 - Administrator - Disabled)
Guest (S-1-5-21-2538772055-807052659-4255878346-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2538772055-807052659-4255878346-1002 - Limited - Enabled)
Lan (S-1-5-21-2538772055-807052659-4255878346-1000 - Administrator - Enabled) => C:\Users\Lan

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/18/2015 00:39:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 20093

Error: (04/18/2015 00:39:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 20093

Error: (04/18/2015 00:39:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (04/18/2015 00:39:17 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 17253

Error: (04/18/2015 00:39:17 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 17253

Error: (04/18/2015 00:39:17 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (04/18/2015 00:39:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 12682

Error: (04/18/2015 00:39:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 12682

Error: (04/18/2015 00:39:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (04/18/2015 00:39:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10654


System errors:
=============
Error: (04/18/2015 05:27:43 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (04/18/2015 05:27:43 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (04/18/2015 05:27:42 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (04/18/2015 05:27:41 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (04/18/2015 05:27:40 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (04/18/2015 00:38:57 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (04/18/2015 00:38:55 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (04/18/2015 00:38:53 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (04/18/2015 10:38:13 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.

Error: (04/18/2015 10:38:13 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.


Microsoft Office Sessions:
=========================
Error: (04/18/2015 00:39:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 20093

Error: (04/18/2015 00:39:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 20093

Error: (04/18/2015 00:39:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (04/18/2015 00:39:17 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 17253

Error: (04/18/2015 00:39:17 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 17253

Error: (04/18/2015 00:39:17 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (04/18/2015 00:39:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 12682

Error: (04/18/2015 00:39:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 12682

Error: (04/18/2015 00:39:13 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (04/18/2015 00:39:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10654


==================== Memory info ===========================

Processor: Pentium(R) Dual-Core CPU T4500 @ 2.30GHz
Percentage of memory in use: 45%
Total physical RAM: 4058.36 MB
Available physical RAM: 2194.84 MB
Total Pagefile: 8114.92 MB
Available Pagefile: 5103.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:283.34 GB) (Free:201.25 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 51ED4EC9)
Partition 1: (Not Active) - (Size=100 MB) - (Type=DE)
Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=283.3 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Juliet
2015-04-18, 22:34
Please go to add/remove programs list, uninstall
AapptooUU

Or you can use

Please download and install Revo Uninstaller Free (http://www.revouninstaller.com/)

Double click Revo Uninstaller to run it.
From the list of programs double click on AapptooUU
When prompted if you want to uninstall click Yes.
Be sure the Moderate option is selected then click Next.
The program will run, If prompted again click Yes
when the built-in uninstaller is finished click on Next.
Once the program has searched for leftovers click Next.
Check/tick the bolded items only on the list then click Delete
when prompted click on Yes and then on next.
put a check on any folders that are found and select delete
when prompted select yes then on next
Once done click Finish.



Then please do the same for
Ask Toolbar Updater
plesome
saferweb

~~~~

Please uninstall all these versions of Java since they are all out of date
Java 7 Update 21
Java(TM) 6 Update 18
Java(TM) 6 Update 20
Java(TM) 6 Update 33

We can install the most recent later.

~~~~~~~`

If McAfee trys to block tools, please temporarily disable it to allow the tools to run.

Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG




start
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-2538772055-807052659-4255878346-1000 -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=05EAE370-52C2-4DA7-8B3B-EC1EF341C14F&apn_sauid=D733377F-E635-4137-BDE5-0641697C7837
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll No File
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-04-01] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll No File
Toolbar: HKU\S-1-5-21-2538772055-807052659-4255878346-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
S2 f1f78e38; "C:\windows\system32\rundll32.exe" "c:\progra~3\winspeed\WinSpeedSvc.dll",service
c:\progra~3\winspeed\WinSpeedSvc.dll
C:\Users\Lan\AppData\Local\Temp\APNSetup.exe
C:\Users\Lan\AppData\Local\Temp\ebccabfbdfbcg.exe
C:\Users\Lan\AppData\Local\Temp\ICReinstall_photomerge-4.2.2.exe
C:\Users\Lan\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Lan\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\Lan\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Lan\AppData\Local\Temp\n8iyaj3w.dll
C:\Users\Lan\AppData\Local\Temp\optprosetup.exe
C:\Users\Lan\AppData\Local\Temp\ose00000.exe
C:\Users\Lan\AppData\Local\Temp\ose00001.exe
C:\Users\Lan\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Lan\AppData\Local\Temp\UpdaterCopy.exe
AapptooUU (HKLM-x32\...\{01B91C29-337A-1FFD-7CFC-473451D2F861}) (Version: - ApptoU) <==== ATTENTION
C:\Users\Lan\AppData\Roaming\plesome
CustomCLSID: HKU\S-1-5-21-2538772055-807052659-4255878346-1000_Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InprocServer32 -> C:\Users\Lan\AppData\Roaming\plesome\enat.dll () <==== ATTENTION
Task: {F8D81E00-9EEB-4A9E-8889-A9981CDE426E} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2012-05-04] () <==== ATTENTION
C:\Users\Lan\AppData\Roaming\plesome\enat.dll
C:\Users\Lan\AppData\Roaming\plesome\oftuget.dll
EmptyTemp:
Hosts:
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~~~``

http://i.imgur.com/BY4dvz9.png AdwCleaner

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) and save the file to your Desktop.
Right-Click AdwCleaner.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Follow the prompts.
Click Scan.
Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
Follow the prompts and allow your computer to reboot.
After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.

-- File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


http://imageshack.us/a/img841/7292/thisisujrt.gif
Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/) to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.


~~~~~~~~~~`
please post
Fixlog.txt
C:\AdwCleaner.txt
JRT.txt

Lanzo
2015-04-19, 00:19
Thank you, I can now log in from the infected machine.

Java 6 Update 20 & Java 7 update 21 won't uninstall.

Attached are the requested logs

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-04-2015 01
Ran by Lan at 2015-04-18 21:16:02 Run:1
Running from C:\Users\Lan\Desktop
Loaded Profiles: Lan (Available profiles: Lan)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-2538772055-807052659-4255878346-1000 -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=05EAE370-52C2-4DA7-8B3B-EC1EF341C14F&apn_sauid=D733377F-E635-4137-BDE5-0641697C7837
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll No File
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-04-01] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll No File
Toolbar: HKU\S-1-5-21-2538772055-807052659-4255878346-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
S2 f1f78e38; "C:\windows\system32\rundll32.exe" "c:\progra~3\winspeed\WinSpeedSvc.dll",service
c:\progra~3\winspeed\WinSpeedSvc.dll
C:\Users\Lan\AppData\Local\Temp\APNSetup.exe
C:\Users\Lan\AppData\Local\Temp\ebccabfbdfbcg.exe
C:\Users\Lan\AppData\Local\Temp\ICReinstall_photomerge-4.2.2.exe
C:\Users\Lan\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Lan\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\Lan\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Lan\AppData\Local\Temp\n8iyaj3w.dll
C:\Users\Lan\AppData\Local\Temp\optprosetup.exe
C:\Users\Lan\AppData\Local\Temp\ose00000.exe
C:\Users\Lan\AppData\Local\Temp\ose00001.exe
C:\Users\Lan\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Lan\AppData\Local\Temp\UpdaterCopy.exe
AapptooUU (HKLM-x32\...\{01B91C29-337A-1FFD-7CFC-473451D2F861}) (Version: - ApptoU) <==== ATTENTION
C:\Users\Lan\AppData\Roaming\plesome
CustomCLSID: HKU\S-1-5-21-2538772055-807052659-4255878346-1000_Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InprocServer32 -> C:\Users\Lan\AppData\Roaming\plesome\enat.dll () <==== ATTENTION
Task: {F8D81E00-9EEB-4A9E-8889-A9981CDE426E} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2012-05-04] () <==== ATTENTION
C:\Users\Lan\AppData\Roaming\plesome\enat.dll
C:\Users\Lan\AppData\Roaming\plesome\oftuget.dll
EmptyTemp:
Hosts:
End
*****************

Restore point was successfully created.
Processes closed successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
"HKU\S-1-5-21-2538772055-807052659-4255878346-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}" => Key deleted successfully.
HKCR\CLSID\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => Key not found.
HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => Key not found.
HKCR\Wow6432Node\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}" => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => Key not found.
HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => Key not found.
HKU\S-1-5-21-2538772055-807052659-4255878346-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => value deleted successfully.
HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found.
f1f78e38 => Service deleted successfully.
"c:\progra~3\winspeed\WinSpeedSvc.dll" => File/Directory not found.
C:\Users\Lan\AppData\Local\Temp\APNSetup.exe => Moved successfully.
C:\Users\Lan\AppData\Local\Temp\ebccabfbdfbcg.exe => Moved successfully.
C:\Users\Lan\AppData\Local\Temp\ICReinstall_photomerge-4.2.2.exe => Moved successfully.
C:\Users\Lan\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe => Moved successfully.
C:\Users\Lan\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe => Moved successfully.
C:\Users\Lan\AppData\Local\Temp\jre-8u31-windows-au.exe => Moved successfully.
C:\Users\Lan\AppData\Local\Temp\n8iyaj3w.dll => Moved successfully.
C:\Users\Lan\AppData\Local\Temp\optprosetup.exe => Moved successfully.
C:\Users\Lan\AppData\Local\Temp\ose00000.exe => Moved successfully.
C:\Users\Lan\AppData\Local\Temp\ose00001.exe => Moved successfully.
C:\Users\Lan\AppData\Local\Temp\SkypeSetup.exe => Moved successfully.
C:\Users\Lan\AppData\Local\Temp\UpdaterCopy.exe => Moved successfully.
AapptooUU (HKLM-x32\...\{01B91C29-337A-1FFD-7CFC-473451D2F861}) (Version: - ApptoU) <==== ATTENTION => Error: No automatic fix found for this entry.
"C:\Users\Lan\AppData\Roaming\plesome" => File/Directory not found.
HKU\S-1-5-21-2538772055-807052659-4255878346-1000_Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090} => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F8D81E00-9EEB-4A9E-8889-A9981CDE426E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8D81E00-9EEB-4A9E-8889-A9981CDE426E}" => Key deleted successfully.
C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar" => Key deleted successfully.
"C:\Users\Lan\AppData\Roaming\plesome\enat.dll" => File/Directory not found.
"C:\Users\Lan\AppData\Roaming\plesome\oftuget.dll" => File/Directory not found.
Hosts was reset successfully.
EmptyTemp: => Removed 5.2 GB temporary data.


The system needed a reboot.

==== End of Fixlog 21:21:02 ====

# AdwCleaner v4.201 - Logfile created 18/04/2015 at 21:41:10
# Updated 08/04/2015 by Xplode
# Database : 2015-04-18.3 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Lan - DAVES-PC
# Running from : C:\Users\Lan\Desktop\adwcleaner_4.201.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Inbox
Folder Deleted : C:\ProgramData\4d09ce8d5400296d
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\ProgramData\Uniblue
Folder Deleted : C:\ProgramData\WinSpeed
Folder Deleted : C:\ProgramData\AapptooUU
Folder Deleted : C:\ProgramData\saferweb
Folder Deleted : C:\Program Files (x86)\Ask.com
Folder Deleted : C:\Program Files (x86)\AskPartnerNetwork
Folder Deleted : C:\Program Files (x86)\AapptooUU
Folder Deleted : C:\Program Files (x86)\saferweb
Folder Deleted : C:\windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}
Folder Deleted : C:\Users\Lan\AppData\Local\AskPartnerNetwork
Folder Deleted : C:\Users\Lan\AppData\Local\Ilivid Player
Folder Deleted : C:\Users\Lan\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Lan\AppData\LocalLow\HPAppData

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\driverscanner
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\SOFTWARE\APN
Key Deleted : HKLM\SOFTWARE\AskToolbar
Key Deleted : HKLM\SOFTWARE\Uniblue
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F488658-35A7-2AB8-A756-560BA8F103C3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90120000-00B2-0409-0000-0000000FF1CE}
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17728


-\\ Google Chrome v39.0.2171.95

[C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://uk.ask.com/web?q={searchTerms}
[C:\Users\Lan\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=05EAE370-52C2-4DA7-8B3B-EC1EF341C14F&apn_sauid=D733377F-E635-4137-BDE5-0641697C7837

*************************

AdwCleaner[R0].txt - [7414 bytes] - [18/04/2015 21:35:28]
AdwCleaner[S0].txt - [7055 bytes] - [18/04/2015 21:41:10]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7114 bytes] ##########

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.5.8 (04.17.2015:1)
OS: Windows 7 Home Premium x64
Ran by Lan on 18/04/2015 at 22:00:50.89
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\low rights\elevationpolicy\{a5aa24ea-11b8-4113-95ae-9ed71deaf12a}
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9



~~~ Files



~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\SooftCoup
Successfully deleted: [Folder] C:\ProgramData\pcdr
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{0002AA71-0787-478B-95EC-990975210809}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{01418302-0A3B-4603-9391-F7DD33BC9C01}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{035F6E89-FEB1-4BBF-A43A-227630D838A4}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{038BB6B5-D223-478B-9617-5A28CF9F12BD}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{047648D3-E646-4406-B525-03FBCC96E5E4}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{053DC380-3399-4CB2-B50D-587B0AE4050F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{058964AF-BDC3-4953-9983-F7C304A736CE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{07108AA2-D916-4C4B-A69B-68E79C599354}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{0748C270-25DB-475B-B8BB-E4587A418553}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{07822DC8-0611-4B08-9986-181813A1FB9B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{09416E91-4D14-4899-9FF7-736B6176540A}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{0A04DC00-E087-4B0B-9B4E-111B11A95A48}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{0AA5626A-1934-4E39-B825-CEF5AE56A48C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{0B5A0274-1964-4F8E-B84C-E393EEFED61C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{0DC60F49-5146-44D7-A6F7-BAB898B90714}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{0E082034-FC6A-488A-8435-437C3CC047A4}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{0E2A7D15-919E-41FF-9A13-0DD9A635F4E0}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{0EBA9CCD-EF73-45A8-8397-450821E40E05}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{0FF43042-AA76-4623-9E51-ABC8D3B735B4}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{11C72E80-C4DE-42A7-A955-13C28BF1E25D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{11E9086F-D20B-4347-86BB-1A2EB3F56787}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{127AA05E-3618-4BC0-AA7D-8154F9409F12}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{131B28D0-36A4-4A36-BCDD-1FCE5CC4BC59}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{1353FC38-1C3C-4D33-9092-987FD252B845}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{13690BAB-7E28-4289-B522-23709FF6FC4A}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{1432CD0F-CEB1-473C-980F-A5E97AABD181}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{143623B3-438B-479B-AFB7-2FD809D28B8A}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{16CF46BA-A40E-4E3E-9D50-B741F8CE7401}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{17440CDC-69B9-4DE5-9BBB-898739EF2B25}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{1C0D5311-9C0E-4D0B-BCED-A9DB0C4C82E1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{1E91D6F9-3AD7-4481-9BA4-C3D47D87C0B2}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{202E08AD-1091-4F8C-BDA8-34C2C1E86BCF}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{2179E561-FA37-494F-AD22-0BA18F264618}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{22593C4C-E4EB-416A-939E-DC6109FF824A}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{2261C0C1-93B2-4626-A17A-405AE7BD6B85}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{2342F1B6-6355-4FF1-B6FD-5D4A575CFA87}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{25F301C9-CFA9-4D77-A819-D1E3E5718958}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{25F34270-B27F-4E7E-88A3-9C7518CCBAC2}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{26031F24-D99D-429E-B3E1-AF5AEA53CFBE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{287126BB-F551-4538-A922-3F6179C5FBB2}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{2895B4EB-2DAD-46AC-8588-D18D78DA3176}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{28F0893C-1802-4A7B-84F6-9109C133A4EE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{295BA46B-796E-4DA6-9604-DA8AE6C5CE47}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{2B998FD0-60D9-46A0-9E16-6661AABE2EB9}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{2D73518F-1712-4C1A-B501-4E468B9ED797}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{2DA6F24A-8A5C-44F5-9326-90C2AC03A093}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{2F4064F2-ACA1-47B6-957D-0EFA0C93D902}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{2F714A4F-EBF0-4E4D-8697-EDD04697EC06}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3231A0CB-E113-424E-AD7D-5C8D7A6AE405}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{329582B4-6472-43C3-95BF-493E4A1EFF6B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{330A7312-601D-420C-BA8A-E242B4FA0611}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3363E08C-695D-470E-B34B-D09C885A1283}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{34D71B92-EA82-476C-AE9F-6B5CAC24D1E1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{35149563-C789-4819-A955-93AF0A662B2F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3542D274-246A-4F91-9C60-CB74DBD21C96}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{35D7F017-687A-4E61-B6C1-D0DAE9C7ADA6}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{36EB0AD6-CD23-49AA-8828-BE18E2441015}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3832FA39-47CF-4E46-AE27-D6E8562A6404}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{396094CE-CA8D-45F4-9A89-8031B9660010}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{39881FF0-3D29-4083-9062-BD7F15418C18}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3A845AEE-530D-4BB1-857A-11B918C44702}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3B4CED3E-7C88-490E-9A45-F3AFFD3D027E}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3B8E076F-BC54-4965-8616-39E45C73FA08}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3BFCE72D-DA30-4152-8A0C-44A46538B28C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3CF7B826-2DC3-4B18-9169-247FA43EAFCD}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3D484AEE-145F-432B-8062-413E9BAEA8D9}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3D96C302-08ED-476F-B0A5-7E2B1B740A2C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3DD3FD9D-7E84-497E-B0A9-D93A86C15A8D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3E520A13-E414-4AE7-A563-E0D57B328ED2}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3E79530A-4099-4283-96E0-A6379F4D9513}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3EDD23F1-8867-4316-BD9C-5F22A68779A1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3F0045D4-8B89-4C2F-8ABE-8BFE57CC2F66}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{3F782AB4-C925-4717-BD72-438909946F02}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{41E7B7D3-BA31-42BC-BC4A-7980C583FB36}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{43A69B41-AEB1-4463-A6CA-DFFF34A70A73}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{43FF24EE-1476-4789-94FB-C5943017ABFF}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{44A8AF11-E6BC-47DC-8B40-697ADA4C85ED}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{452C4C50-2A5E-46DC-BED0-AAD6E4C523EA}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{466A421C-5B63-4230-8317-44DA04E5B225}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4672D16B-8E6A-4726-846A-02C77448AF52}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4827F2DB-2C62-4903-BE45-A4D6D659B914}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4837B068-845A-493D-AEB4-8B05BF30A001}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{48A0352E-0CF2-4949-94AC-5E6CCEF4896D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{49616E3C-8896-4FB4-BB19-F8B19B80FFD9}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{496A515F-4D69-4D4D-89E4-FCEFDB18082B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4970497E-0D3F-4A2B-AC0A-A7B7643EAF69}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4A9E2385-BF87-4355-ADEF-F00A883B5018}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4B8D9648-1C8F-4049-AC1A-96426433EAA3}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4C45D3F3-3B1D-4927-87D6-5E84E6B45CD3}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4C772856-2BD6-49B5-8375-AC1A73A74F4D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4CFD00B7-73C6-4EE8-8129-0998E129CA72}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4DDA66E0-93C6-4B07-8893-B08D8BFF4827}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4EBB5511-CFD6-49DF-892A-45F5C0BF173F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4EE6FB00-DA1C-49BF-A6D6-6E2D7A10E239}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4F00618E-D503-464F-ADAA-BD3BC36D9BE4}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{4F8A564E-B5FA-4059-87DB-3599666E3979}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{504E2E0E-2613-42E8-92D4-991AA527056D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{528724A4-1FA7-463C-8C86-C529A1F63F11}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5340F5A9-C5C0-47A8-931F-360C07C1A55F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5508636F-AE7F-4631-A011-1E914C7CF295}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{555B74DF-3C97-44A4-9FE8-739B273D25E3}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{55AEF745-9275-4743-BC32-2268539CC8A0}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{55BA90FE-59E8-41DE-BEC6-45533B55C5A9}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{55CC56AA-5170-4D13-8C57-45F1D5E23015}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{55EA0B16-C44D-434A-8F6D-F29DE9659281}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5614EE91-6624-4BEE-905F-14DC7168393D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{56E4EC9B-1A0B-4E9D-941C-515F4FB7DC41}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{57656D40-47E3-483F-9E0C-B1001B68FC39}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{58845C47-97D7-4FA3-ADBE-83466EB2B06E}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{591D34E8-B1D4-4002-A257-EACD87DD89AC}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5951D14F-F9AA-401A-9BB2-F7EE0A687486}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{596770D3-79A4-4D0E-8BAD-8812A8F5820C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5A34E5F1-C8F2-46EA-B8FE-B426E4A6B3DD}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5AB85003-43BC-4194-A1EC-2D2F97A18F06}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5B9B271C-8539-407E-85BA-5E84CEF281B1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5D4F3913-240B-4C3B-9137-613E97DCC8DA}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5DB54F7B-B4DA-41F0-8434-F14D397DE36F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5E21CBB9-90D9-4CFF-8005-44B5B8449CCA}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5EA8A492-E6B5-4980-B9C2-B376E56DB342}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5EB15CC0-E07F-4BF4-A37A-4DA5A92B75F5}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5EB50236-0BC1-455B-8C7E-1E6737DD0821}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5EFC80CB-BC4D-43EA-ABCA-CCBEB01C0D45}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{5FE1C5EA-619B-4044-ACC0-DBE350E55232}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{608B3225-28A7-4FD7-AB55-06E7D7815E62}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6224689C-E14C-4D32-AFF4-5E48351B06B0}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{63ABFED0-CC3B-4E09-8188-446EF8C1B389}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{63EC93DF-CA7A-49FC-9787-41ADF7D77417}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{644ECAC0-4CBA-4624-8151-54F384A7A34E}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{65FADEE5-10C9-47C0-81CD-EA32EBE15414}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{661C344A-E95A-4656-9A3C-8B6F77D76A1F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6640008F-AB5A-4490-8000-9156A74D327D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{669F68B2-B800-42B0-AB29-77688B4AEB1D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{67700D34-910A-4FB0-B697-5E7DD6FF11F6}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{67956D1A-C780-4376-95B4-BE6F667EA34B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{685F0169-F45E-42DE-BC09-BA6472927BF3}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6920C903-8B1A-4F46-AEF5-E4FA5E607724}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{69C0359C-6781-4C6A-B7F5-ADCDEE8C3A1C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6AA7160B-BCCC-4D03-A048-ED59242B8DBA}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6AA7DE50-48AF-4232-B725-502A9C50F7DE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6B8B1D2E-E046-4F97-B5F4-F066D27A3CC5}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6B915135-2F4D-4F1D-A808-4E77F6323EA1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6CE8B2EB-4454-4908-8DFD-F12A947A7E50}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6CF5FC09-7E66-4CC4-A6E4-4803E4ED501D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6D31AE12-5772-42BA-A1BD-555E003FD5A5}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6E25C188-5792-40D5-ADE7-6DE809F96D3C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{6ECE31AE-DF2F-4D36-8714-F94B3E25FD92}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7223B6C8-E52E-4900-BE0D-55ACC5C4CEEE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{724BFBCE-BDA9-460E-B320-F315C06460B8}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7411FE22-C2BC-45AF-AC92-7E6F3D247F5B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{74A1F9AF-06BF-46BF-B74D-EB107CA2370E}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7555EECA-EEFB-4392-B954-C66A6EEF3A85}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{76784470-F02C-4554-A882-946BD3D35A42}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{76CAB5FF-63A6-4024-92A6-FEA77F35D02B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{76EC34B1-5C4D-4ED8-8896-4F72AF953F24}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{77FF9CA6-0DE2-4B9F-81AA-19F7AADE8A00}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{79A46B58-CFF4-4340-81EE-AC2E69833924}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{79B1F349-BE4F-4A10-B550-274C9ABE6B4D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{79B450AC-82EB-4FDE-9AA4-D595F582D50E}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7A6C328C-1D42-4D0E-BEF7-E2FF50E63319}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7AB8F374-653E-4D11-BA00-5C14B9C99BAC}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7ACA7A80-2DD6-40AF-BD9B-FFEF4C04E0B8}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7ADE1A2E-D493-4FC1-9404-CB14C0895CB9}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7B17ADC1-07C9-483A-8E1F-E0893715EDBB}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7B1E6E52-BEED-48BF-AF70-D0BE223E1A9B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7C72B362-A3D5-4A2C-AFB1-5D397A4F9AC3}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7CAA3D84-69E4-49C8-ADE6-EBC2A213A299}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7D776E0F-8C6F-4550-81B3-1544E030A699}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7F92DF07-C9EB-45A1-9D14-E81035B3B0A1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{7FC40959-F737-44DE-A225-A4B373184743}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{808333E7-B0C3-4641-8A83-768AEAE3D551}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{80B3F827-6595-4276-808F-56E089484F23}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{80FF0259-9E5E-49D5-B4E0-5BD7D8BB2153}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{81A9B941-EFC9-4202-8A2B-FB2C5D5D5164}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{82BC0AE9-4604-4CAC-B7F2-24A6B159C168}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{83D60A75-8162-4EE2-919A-EE9A29A98986}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8448DC48-9CED-4D64-9E8E-D855119B8088}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8503499D-AD5A-423E-8B5E-E2595C86CB68}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{85E695B1-C255-4492-88D2-E46992B7206C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{85F1FAA9-D8AE-4F54-85CA-CB53586F2354}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8647D734-D914-455A-BA4F-6F2E4FDC44AE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8827B6AB-5F54-4C4B-942C-312B70662DD7}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8841A3CB-497A-43D4-BC17-23BE0C8D7AD2}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{886771CD-32C2-4ED5-9356-7603A8899146}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{88C7AE02-68C8-4B62-AFDB-E5CA60094A0E}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{89AD5B10-745A-4C19-8D8B-2DCD0C9C1F3F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8A77FBB5-B52F-4B7B-AC7D-A3DEF6DCD764}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8B14F05C-A217-4318-88F2-925DC997EB70}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8C448F43-62A2-4343-B16A-3C8BD5910614}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8C539249-1AA1-454A-91B5-FC63AD74BEAB}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8C94C69D-7B81-49C2-909A-BC39ABCE631D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8D9A60F8-21EC-4CFC-A0FA-D359BD7025D6}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8DADB066-100F-4D9D-ACBB-717D34121683}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8E3BA40E-4C66-455F-9571-5FDAE7608802}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{8FD14BA7-3120-49B5-9B2A-F7992764A449}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{90893968-3EF5-41BF-A9E8-F75D8868FD98}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{9164536A-FE12-453C-9CB1-5EB6008A031A}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{94D5855B-FEBD-4D98-9CCF-D15900F11EAE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{95D8934F-47F1-40C0-89B4-228D45811673}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{9656B743-EC3B-4440-8725-17599AE88089}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{96E139FD-575E-4489-8A6D-A3B59BB9236A}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{96E159FB-CDD4-40B3-8546-2393DAF628F7}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{977137A8-B797-4976-9623-3D66F6C471EB}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{97750AE5-2533-4196-885C-152B85A5BEC3}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{97F76A01-E6E8-41C1-B62A-5102CB2BEECE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{99954CCF-87AE-4283-8AEC-802717066571}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{9C661CEC-6D37-4EC6-A8A8-6AF46588435F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{9C8E42E5-ACAC-4287-BF9D-B30BB4DBF414}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{9CE0CA38-6913-4E97-852A-3633AEEF87F7}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{9DC3FB5F-5758-40A9-997F-46FEABF15BAD}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{9F885A4D-D125-4E27-B742-4D9100B48BCA}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{9FEF2682-3203-4B39-AB1B-58E81F4703FD}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A0478889-5CF1-4F53-9162-E34112AF4521}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A21A2D25-C0A2-4DDD-AEF1-521D8C0BB24B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A327DF16-3F13-4AC6-A410-FD07FE8CB0D1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A3C893AD-1F77-47EB-93B2-9F37A46A5CFE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A5E036F4-47C5-405D-8892-F03629EDC60B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A622E614-E8D0-46FC-B62E-0B39F0C9CB04}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A6366124-CB42-4E51-AA85-BD7DFFDB5B45}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A70CFEBD-E99A-47F3-933C-96EAF62CF217}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A7ABEF45-A4C9-40BE-8C85-A8B3155E313D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A7C146B2-C46C-4E91-B272-AF70DA257B94}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A8858178-D54A-48AD-8821-248A930968D1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{A8A78FE3-1F66-404E-A8ED-CC5D82E45A56}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{AB574A5B-B7C7-4383-9924-19A34459A6C8}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{AB5C569B-312F-4417-B607-F1F148D6CC4E}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{ABD2DA09-4598-4012-A499-6B279FA9536B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{ACBF9284-3AA3-4CC6-A6C1-C7028CEA3247}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{AE1DF5A9-B088-4FB0-84EE-053C00A2AD7E}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{AE6B2176-999F-429D-A695-C32FEB6A7A85}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{AECAFBFF-7EAA-4793-AF3B-F0A147E93422}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{AFA3245D-E1E4-4CB4-AC99-A2656D7F177A}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B023F662-F858-4B52-8C4D-0F0B8F4F0231}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B1C529E8-6BBC-4EDE-B712-ABC52C04F2D3}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B203E2B4-315A-41ED-8AD7-70F70AA378BC}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B25194E5-0405-4937-B6F1-FAAF4DA03D84}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B28CA917-9E77-4E04-B4A6-5C896E7E181D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B2AEFA4A-E8A6-4C63-B14F-F99E35C5E8EF}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B2D252D0-C5A9-4790-B26C-5D37B35B7F20}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B31D57CB-1328-478F-9E76-9A77A15538D8}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B364267B-B26F-44E4-9303-41A12927ABF5}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B4341B5F-3AE9-4891-96F5-794A666BD1FF}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B4870675-7405-40C5-91D3-E9B21A68D88E}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B71567A2-3934-4A33-B07B-4E56B60303B1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B89407EF-9B5C-4E20-B08A-F4351BF9E2BD}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B908CA14-1995-4AD8-ABE0-DD55A0DD9FA5}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B90AB26B-18FF-41BD-A870-5EB4BC1B789D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{B97CF4A6-1904-4FCF-A15A-C8B3FD511CB2}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{BA737027-C572-44E1-A7ED-B00D73F49012}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{BAB235DA-82CA-43EC-A76C-664F656CF06F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{BAD630C6-DB0C-4570-A41E-5AA9E70C30B1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{BBFAD685-B97B-4F5F-A458-BFB3F25AF897}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{BC6F80BF-C026-4FAC-B08C-E99B6F5060D4}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{BDEABAEC-4AC6-45F9-9DBE-2ECC00BE94EE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{BDF736EE-0ADD-4A86-B263-E9D638AF1E3D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{BEF960EE-C6DD-4E4C-A5EE-F8B64D311FC1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{BF031FC9-E9A3-4762-8748-24437475497A}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C004B963-43AE-43A1-97BD-BF347544942E}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C0A153CC-385C-441B-9F41-988E7356A1C2}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C0B8EB96-FF04-482F-B27A-9CE1DEB62D67}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C0C80584-B010-44F3-B643-A2A8C53E05A1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C104837F-D41F-48CD-AE59-27929A004B91}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C183A816-C3EF-45A4-8161-A36A886F62D5}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C1AD0C1A-4DFD-49C2-AA33-C75A87D607CF}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C27360A8-0A21-4C20-8596-FBC9F0C7F1D3}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C332E828-3212-438E-A7AA-659FDE96C5D1}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C392E23B-06F4-4C65-8370-ED5F3B113092}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C599297D-8F2B-4D73-9D58-1260B5FB6A8D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C5E95F39-7B78-4FA4-AB37-53E58B0EF4DD}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C67B59D7-0618-4488-8263-40277F31F906}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C689357B-30A8-4825-8002-37B49384EEFD}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C6BB2B62-09C0-4A09-A7ED-24E0E17FF92F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C78C47C2-3BA6-48B3-ACE7-EACC05C6FD5B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C8EFAC12-7A00-431F-8894-28FEA9AED2E6}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C90EF8A6-4AC8-4E0D-9B03-1E5E0603F9FA}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{C9184EF7-60AC-46D1-AF79-8A1E0FFD0E7F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{CDAFCCD3-B413-4A83-994D-9EBE281744C2}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{CDB12371-CE10-4FC1-BA29-122C56BF65BE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{CDC1E475-FA6C-40D7-A7B0-8D561B16098E}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{CDE243E1-A55D-4D6E-92C0-0D1AFC1DB0A3}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{CDF3C512-365B-456D-9F14-E7180E4B4083}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{CEF774B7-958E-47C0-8BB0-D7AE99FA3E13}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D089CC61-2DBC-4F63-A97B-A6E84D8B30DC}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D08D34EC-FF20-41A9-8947-1C84F07B5453}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D0D6D001-B65A-463F-86E8-B60FED04E03B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D0FEC8C0-6692-47A9-B9FD-E1A99E3F2C3B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D11AA708-2181-4BB6-84B0-59DC7C6BFF3F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D1CA8C7D-58DF-488C-9D69-145C56CB2E5B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D33978EA-3870-41EB-855C-E213E3778C9C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D34B3288-F1CC-45FD-9301-8D62C192DAAB}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D3F262E0-3B96-410C-AA23-DA6FB30D1DEB}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D5664E58-3C0B-4084-8FB7-85A73485BCAC}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D61C06B9-67D6-47F5-A460-4729E928E80F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{D720C5D0-1895-4724-9E8A-932CBA9C3F8C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{DA4FFABD-67B5-45C5-980F-9721AC87505C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{DAA28A2F-4F4D-4D07-A1AD-07A40CF5CB95}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{DC217DCF-E843-4CBC-A959-E244A42CFAAB}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{DC81ECC1-9194-4084-945B-8EFE356F5721}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{DF71C062-556F-490A-BD95-158942A1C34F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{DFAE4737-8525-498E-A7D1-EA5795005FA8}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{E1121C28-8167-4DC8-BFF7-C5AEE2D77272}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{E1A7BBAC-E93D-479C-A013-3642752D2D5D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{E329BFE0-D4AB-4829-8618-F5CC3B7A9D7C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{E356F27E-0ADB-446F-8583-CF1501797050}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{E42377D1-0E28-417E-840E-0D66862ADE52}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{E5F814D2-B015-408B-B706-C12E48C28BA8}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{E7003B43-AA5D-4024-8B0E-8D0710A92936}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{E9138FA8-CB3F-48D4-8D6C-3711E22CA196}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{E9ACACE8-C557-4C31-B578-DF2D6BA0E80F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{EB301D50-C01A-4E7D-B703-5372B8FD801F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{EB332CE6-7DBD-4CB3-95BE-064DFD3CE7B3}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{EBC044FC-E26F-4D1C-8FE6-1CD1C7360DE0}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{EC73A233-157C-43C0-BAAB-317D418B61BE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{ED2DE4C0-4BD9-4552-BD6E-411AA4B4BE69}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{ED52BB0F-B5AB-4FA9-AF39-6A2DE992770C}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{EE10A230-FFDC-4B74-94D5-D2ED124F05A8}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{EE93E2CB-3591-41EA-BAB7-FC70930785DD}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{EEAFC22D-7467-467A-B48C-9447555A10F7}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{EEC8AF44-FFC0-47DF-8591-5559C5410DA2}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{EEE28667-A8CF-40A4-840F-C96BCCD8DC3B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{EFA4C3C4-3DE0-4D61-8A9D-4444D679AAFE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{F04CCA62-F78B-402E-87DA-F10C7B70066B}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{F0A5E5AF-4AED-46E1-9DD0-EDAEF2D2487D}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{F0DA955B-5D3C-4CC7-8E34-CCD0889375BF}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{F1705169-1BDB-41D6-AD82-36E1076DA218}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{F21C1E9B-C479-4E87-A965-6BCFBE951461}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{F465D5E2-60E2-432B-9075-0856D1EA5FE7}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{F4A67D52-C2E7-4A61-B0CA-2C6279CCF3A9}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{F4E25AFC-11A6-405C-BF72-5AACBC783303}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{F5872072-0851-4BE2-B1BD-11540BC2C4FD}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{F5D72776-C1DD-41C9-9741-2378DFD73395}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{F9A03654-7A96-455F-B04F-9C7A9B1F4391}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{FA2F9921-FB27-4DAF-8EFF-93BBA27B13BE}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{FA4BA098-94FA-4B78-8B64-21D57735A907}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{FB118777-9CE2-4E1C-B8D7-4775D7551A00}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{FB68CCF2-3E08-413E-838D-15531F23914F}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{FD97181D-17F3-485B-9541-C239CAAC3D12}
Successfully deleted: [Empty Folder] C:\Users\Lan\appdata\local\{FFE93303-06A6-458F-8DEB-8BC32A931BAA}





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18/04/2015 at 22:10:20.69
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Juliet
2015-04-19, 13:36
Let's update Malwarebytes and run a new scan.

~~~~~~~~~

Click on Update Now to download the current database definitions, then click the Scan Now >> button.
If you have run this version before, you should see a green note at the top indicating "Your system is fully protected".
You will be prompted to update Malwarebytes...click on the Update Now button.
The THREAT SCAN will automatically begin.
When the scan has completed, the results will be displayed. Click on Quarantine All, then click on Apply Actions.
To complete any actions taken you will be prompted to restart your computer...click on Yes. Failure to reboot normally will prevent Malwarebytes from removing all the malware.
After rebooting the computer, copy and paste the mbam.log in your next reply.

To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 1)

Open Malwarebytes Anti-Malware.
Click the History Tab at the top and select Application Logs.
Select (check) the box next to Scan Log. Choose the most current scan.
Click the View button.
Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.

To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 2)

Open Malwarebytes Anti-Malware.
Click the Scan Tab at the top.
Click the View detailed log link on the right.
Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.

Logs are named by the date of scan in the following format: mbam-log-yyyy-mm-dd and automatically saved to the following locations:
-- XP: C:\Documents and Settings\<Username>\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
-- Vista, Windows 7/8: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd

~~~~~~~~~

Now let's update JAVA

https://java.com/en/download/
Follow the prompts to install the latest version.

~~~~~~~~~~~~~~`

What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.


http://i.imgur.com/GzlsbnV.png ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.


Please run a free online scan with the ESET Online Scanner

US Link: http://www.eset.com/us/online-scanner/
EU Link: http://www.eset.eu/online-scanner/

Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.

Turn off the real time scanner of any existing antivirus program while performing the online scan.
Click the blue Run ESET Online Scanner button
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
Click on Advanced Settings
Make sure that the option Remove found threats is unticked.
Ensure these options are ticked

Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology


Under "Current Scan Targets" > click "change" and ensure all your drives are selected
Click Start
Wait for the scan to finish
When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
Save that text file on your desktop. Attach the log as a reply to your next reply..
Close the ESET online scan, and let me know how things are now.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

Please post
MBAM log
Eset log

Lanzo
2015-04-19, 20:13
ESET smart security downloads for about 10 minutes then says there is a communication error so I haven't yet managed to run a scan.

MWB ran ok with no threats found.

alwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 19/04/2015
Scan Time: 12:29:39
Logfile: MWB.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.04.19.02
Rootkit Database: v2015.03.31.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Lan

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 369444
Time Elapsed: 27 min, 4 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

Juliet
2015-04-19, 20:55
Did you install the latest version of Java?

Can you temporarily disable your antivirus protection to see if that is what hindered the download?

Let's try it this way
~~

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.






Hold down Control and click on the following link to open ESET OnlineScan in a new window.


ESET OnlineScan (http://eset.com/onlinescan)

Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png button.

For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

Click on http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.

Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstallDesktopIcon.png icon on your desktop.

Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png
Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png button.

Accept any security warnings from your browser.
Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png

Make sure that the option "Remove found threats" is Unchecked

Push the Start button.

ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.


When the scan completes, push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png

Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png, and save the file to your desktop using a unique name, such as

ESETScan. Include the contents of this report in your next reply.

Push the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetBack.png button.

Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetFinish.png

Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.

Lanzo
2015-04-21, 00:03
Result of EST scan

C:\FRST\Quarantine\C\Users\Lan\AppData\Local\Temp\ebccabfbdfbcg.exe.xBAD a variant of Win32/OutBrowse.BX potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\Lan\AppData\Local\Temp\ICReinstall_photomerge-4.2.2.exe.xBAD a variant of Win32/InstallCore.QW potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\Lan\AppData\Local\Temp\optprosetup.exe.xBAD multiple threats cleaned by deleting - quarantined
C:\Users\Lan\Downloads\photomerge-4.2.2.exe a variant of Win32/InstallCore.QW potentially unwanted application deleted - quarantined

Juliet
2015-04-21, 00:06
That report looks good.

How's your computer now?

Lanzo
2015-04-21, 00:29
Latest version of JAVA is installed.

Everything else seems fine.

Lanzo

Juliet
2015-04-21, 03:35
http://i.imgur.com/AFZxnZc.jpg DelFix

Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix)
or from here http://www.bleepingcomputer.com/download/delfix/ and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:

Activate UAC
Remove disinfection tools
Create registry backup


Click the Run button.

-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).
~~~~~~~


Answers to common security questions - Best Practices (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/) by quietman7, MVP
How Malware Spreads - How did I get infected? (http://www.bleepingcomputer.com/forums/t/287710/how-malware-spreads-how-did-i-get-infected/) by quietman7, MVP
Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/) by Lawrence Abrams, MVP
How to Prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html) by miekiemoes, MVP
How to backup and restore your data using Cobian Backup (http://www.bleepingcomputer.com/tutorials/backup-and-restore-data-with-cobian-backup/) by YourHighness
Slow Computer/browser? It May Not Be Malware (http://www.bleepingcomputer.com/forums/t/87058/slow-computerbrowser-check-here-first;-it-may-not-be-malware/) by quietman7, MVP


The following programmes come highly recommended in the security community.

http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xKsUqI5A.png.pagespeed.ic.vn1Hlvqi8h.jpgAdBlock (https://adblockplus.org/en/firefox) is a browser add-on that blocks annoying banners, pop-ups and video ads.
http://i.imgur.com/E8I37RF.pngCryptoPrevent (https://www.foolishit.com/) places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
http://i.imgur.com/EG85Vjt.png Malwarebytes Anti-Exploit (https://www.malwarebytes.org/antiexploit/) (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpgMalwarebytes Anti-Malware Premium (https://www.malwarebytes.org/) (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xjv4nhMJ.png.pagespeed.ic.A5YbWn1eDO.png NoScript (http://noscript.net/) is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
http://i.imgur.com/3O8r9Uq.png (http://www.sandboxie.com/) Sandboxie (http://www.sandboxie.com/) isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/DgW1XL2.png.pagespeed.ce.v1OlJl_ZAS.png Secuina PSI (http://secunia.com/vulnerability_scanning/personal/) will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xj1OLIec.png.pagespeed.ic.k6hhwopU0q.jpg SpywareBlaster (https://www.brightfort.com/spywareblaster.html) is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xJEP5iWI.png.pagespeed.ic.4tmM1lM7DQ.pngWeb of Trust (https://www.mywot.com/) (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.


Want to help others? Join the ClassRoom (http://forums.whatthetech.com/What_the_Tech_Classroom_t80368.html) and learn how.

Lanzo
2015-04-21, 22:00
All completed and the computer is running fine.

Thanks again for your help.


Lanzo

Juliet
2015-04-21, 23:07
We're glad to help :)

Juliet
2015-04-22, 13:05
Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.