Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-02-2014 01
Ran by John (administrator) on SAMIAM-PC on 15-02-2014 14:13:38
Running from C:\Users\John\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\OAcat.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\oasrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\OAui.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\2.1.121\SSScheduler.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\OAhlp.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Alcor Micro Corp.) C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
(cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Memeo Inc.) C:\Program Files (x86)\Memeo\AutoBackupPro\MemeoBackup.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [DellStage] - C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe [2195824 2012-02-01] ()
HKLM\...\Run: [IntelliPoint] - c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [itype] - c:\Program Files\Microsoft IntelliType Pro\itype.exe [1873256 2011-08-10] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [@OnlineArmor GUI] - C:\Program Files (x86)\Online Armor\OAui.exe [7558464 2014-01-26] (Emsisoft GmbH)
HKLM-x32\...\Run: [VolPanel] - C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [SPIRunE] - Rundll32 SPIRunE.dll,RunDLLEntry
HKLM-x32\...\Run: [StartCCC] - c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-05-17] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
HKLM-x32\...\Run: [ShwiconXP9106] - C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe [237568 2010-03-10] (Alcor Micro Corp.)
HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2010-10-01] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] - C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [50472 2010-09-17] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe [75048 2010-10-26] (cyberlink)
HKLM-x32\...\Run: [RoxWatchTray] - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-09-04] (Sonic Solutions)
HKLM-x32\...\Run: [Memeo Backup Premium] - C:\Program Files (x86)\Memeo\AutoBackupPro\MemeoLauncher2.exe [136416 2010-07-28] (Memeo Inc.)
HKLM-x32\...\Run: [AppleSyncNotifier] - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [Nikon Message Center 2] - C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [619008 2010-05-25] (Nikon Corporation)
HKLM-x32\...\Run: [AccuWeatherWidget] - C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [968048 2012-02-01] ()
HKLM-x32\...\Run: [EMET Notifier] - C:\Program Files (x86)\EMET\EMET_notifier.exe [152152 2012-05-09] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\615\G2AWinLogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
HKU\S-1-5-21-1190624232-1164676516-3757976289-1000\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-1190624232-1164676516-3757976289-1000\...\Run: [MobileDocuments] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
HKU\S-1-5-21-1190624232-1164676516-3757976289-1000\...\Run: [CAHeadless] - C:\Program Files (x86)\Adobe\Elements 11 Organizer\CAHeadless\ElementsAutoAnalyzer.exe [840784 2012-09-17] (Adobe Systems Incorporated)
HKU\S-1-5-21-1190624232-1164676516-3757976289-1000\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1100120 2013-03-20] (Garmin Ltd or its subsidiaries)
Startup: C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9B0166BFD00BCF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.com/
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0C1ECA7F-6B3A-43FB-BFE1-AEC8654036A0} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {C5006BF6-4F86-47E8-93C1-9D838643AD2C} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
DPF: HKLM-x32 {0742B9EF-8C83-41CA-BFBA-830A59E23533}
https://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {29C885DE-E209-4832-9387-E4A986A60B89}
https://www1.laurisonline.com/scanning/IWWebGetSig.CAB
DPF: HKLM-x32 {2AB1C516-D654-4D3A-B3D6-2185BBCEB409}
https://myhrweb.tmhs.org/+CSCOL+/relayp.cab
DPF: HKLM-x32 {49312E18-AA92-4CC2-BB97-55DEA7BCADD6}
https://support.dell.com/systemprofiler/SysProExe.CAB
DPF: HKLM-x32 {55963676-2F5E-4BAF-AC28-CF26AA587566}
https://sslvpn.tmhs.org/CACHE/stc/1/binaries/vpnweb.cab
DPF: HKLM-x32 {699F5A74-6F8A-4AC8-B88A-B992A09A0A6D}
https://www1.laurisonline.com/scanning/IWWebScanSmall.CAB
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {75C38814-0319-44E3-8FE8-41042ACCD180}
https://www1.laurisonline.com/scanning/IWWebGetVoice.CAB
DPF: HKLM-x32 {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3}
http://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: HKLM-x32 {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - No File
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - No File
Handler-x32: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 71.252.0.12
FireFox:
========
FF ProfilePath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\266lf5zo.default-1388406428191
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: NoScript - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\266lf5zo.default-1388406428191\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-24]
FF Extension: Adblock Plus - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\266lf5zo.default-1388406428191\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-24]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (Coupons Inc., Coupon Printer Manager ) - C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll No File
CHR Plugin: (Coupons Inc., Coupon Printer Manager ) - C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll No File
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (Google Wallet) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-12]
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-17] (Adobe Systems Incorporated)
S2 CLKMSVC10_9EC60124; C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [236016 2010-10-26] (CyberLink)
S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [186200 2013-03-20] (Garmin Ltd or its subsidiaries)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\2.1.121\McCHSvc.exe [227232 2010-09-03] (McAfee, Inc.)
S2 MemeoBackgroundService; C:\Program Files (x86)\Memeo\AutoBackupPro\MemeoBackgroundService.exe [25824 2010-07-28] (Memeo)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
R2 OAcat; C:\Program Files (x86)\Online Armor\OAcat.exe [584864 2014-01-26] (Emsisoft GmbH)
R2 SvcOnlineArmor; C:\Program Files (x86)\Online Armor\oasrv.exe [4457688 2014-01-26] (Emsisoft GmbH)
S2 AntiVirSchedulerService; "C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" [X]
S2 AntiVirService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" [X]
==================== Drivers (Whitelisted) ====================
S3 hcw85cir; C:\Windows\system32\drivers\hcw85cir3.sys [32768 2009-09-11] (Hauppauge Computer Works, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
R1 OADevice; C:\Windows\SysWow64\Drivers\OADriver.sys [64720 2014-01-26] ()
R1 oahlpXX; C:\Windows\syswow64\drivers\oahlp64.sys [62008 2014-01-26] ()
R1 OAmon; C:\Windows\SysWOW64\Drivers\OAmon.sys [52360 2014-01-26] (Emsisoft)
R3 OAnet; C:\Windows\System32\DRIVERS\oanet.sys [35368 2014-01-26] (Emsisoft)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-10] (Corel Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
S3 PCDSRVC{D3412D80-CF3B4A27-06020200}_0; \??\c:\program files\my dell\pcdsrvc_x64.pkms [X]
S1 SDHookDriver; \??\C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookDrv64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-15 14:13 - 2014-02-15 14:13 - 00023017 _____ () C:\Users\John\Downloads\FRST.txt
2014-02-15 14:12 - 2014-02-15 14:13 - 00000000 ____D () C:\FRST
2014-02-15 14:12 - 2014-02-15 14:12 - 02152960 _____ (Farbar) C:\Users\John\Downloads\FRST64.exe
2014-02-15 14:12 - 2014-02-15 14:12 - 02152960 _____ (Farbar) C:\Users\John\Downloads\FRST64(1).exe
2014-02-15 13:52 - 2014-02-15 13:52 - 13670584 _____ (Microsoft Corporation) C:\Users\John\Downloads\mseinstall(3).exe
2014-02-15 12:35 - 2014-02-15 12:35 - 05556104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-02-15 11:38 - 2014-02-15 11:41 - 00000000 ____D () C:\3f36c4d9689e4843352e9a94080d05b3
2014-02-15 03:09 - 2014-02-15 03:12 - 00000000 ____D () C:\0c378261dcaff05fc93ca17e9a
2014-02-15 03:06 - 2014-02-15 03:09 - 00000000 ____D () C:\249c6060b3580f371cb7eb1cf8
2014-02-14 03:00 - 2014-02-14 03:04 - 00000000 ____D () C:\8647feed28fa7470a2d6e1f2795c60
2014-02-13 03:06 - 2014-02-13 03:08 - 00000000 ____D () C:\4218f922e2c92d124ae48a
2014-02-13 03:03 - 2014-02-13 03:05 - 00000000 ____D () C:\3665ad80702030052f87adff89a55f
2014-01-24 18:40 - 2014-02-15 11:24 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-01-24 18:40 - 2014-01-24 18:40 - 00000000 ____D () C:\Program Files (x86)\McAfee Security Scan
2014-01-24 18:39 - 2014-01-24 18:39 - 00005175 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-24 18:39 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-24 18:39 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-24 18:39 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-24 18:39 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-24 18:29 - 2014-01-24 18:36 - 00000000 ____D () C:\ProgramData\OnlineArmor
2014-01-24 18:29 - 2014-01-24 18:29 - 00000000 ____D () C:\Users\John\AppData\Roaming\OnlineArmor
2014-01-24 18:28 - 2014-01-29 16:41 - 00000000 ____D () C:\Program Files (x86)\Online Armor
2014-01-24 18:28 - 2014-01-26 03:01 - 00064720 _____ () C:\Windows\SysWOW64\Drivers\OADriver.sys
2014-01-24 18:28 - 2014-01-26 03:01 - 00062008 _____ () C:\Windows\SysWOW64\Drivers\oahlp64.sys
2014-01-24 18:28 - 2014-01-26 03:01 - 00052360 _____ (Emsisoft) C:\Windows\SysWOW64\Drivers\OAmon.sys
2014-01-24 18:28 - 2014-01-26 03:01 - 00035368 _____ (Emsisoft) C:\Windows\system32\Drivers\OAnet.sys
2014-01-24 18:27 - 2014-01-24 18:27 - 30185256 _____ (Emsisoft GmbH ) C:\Users\John\Downloads\OnlineArmorSetup(1).exe
2014-01-24 18:26 - 2014-01-24 18:27 - 30185256 _____ (Emsisoft GmbH ) C:\Users\John\Downloads\OnlineArmorSetup.exe
2014-01-24 08:14 - 2014-01-24 08:14 - 00282992 _____ (Mozilla) C:\Users\John\Downloads\Firefox Setup Stub 26.0(1).exe
2014-01-24 08:13 - 2014-01-24 08:20 - 00000000 ____D () C:\Users\John\AppData\Local\Mozilla
2014-01-24 08:12 - 2014-02-15 14:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-01-24 08:12 - 2014-01-24 18:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-24 08:12 - 2014-01-24 08:16 - 00001153 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-01-23 18:41 - 2014-01-23 18:41 - 00282992 _____ (Mozilla) C:\Users\John\Downloads\Firefox Setup Stub 26.0 (1).exe
2014-01-23 18:16 - 2014-01-23 18:16 - 00282992 _____ (Mozilla) C:\Users\John\Downloads\Firefox Setup Stub 26.0.exe
==================== One Month Modified Files and Folders =======
2014-02-15 14:13 - 2014-02-15 14:13 - 00023017 _____ () C:\Users\John\Downloads\FRST.txt
2014-02-15 14:13 - 2014-02-15 14:12 - 00000000 ____D () C:\FRST
2014-02-15 14:13 - 2009-07-13 23:45 - 00014240 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-15 14:13 - 2009-07-13 23:45 - 00014240 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-15 14:12 - 2014-02-15 14:12 - 02152960 _____ (Farbar) C:\Users\John\Downloads\FRST64.exe
2014-02-15 14:12 - 2014-02-15 14:12 - 02152960 _____ (Farbar) C:\Users\John\Downloads\FRST64(1).exe
2014-02-15 14:11 - 2009-07-14 00:10 - 01554876 _____ () C:\Windows\WindowsUpdate.log
2014-02-15 14:10 - 2013-12-27 18:22 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-02-15 14:09 - 2014-01-24 08:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-15 14:07 - 2011-02-01 17:44 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-15 14:06 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-15 14:06 - 2009-07-13 23:51 - 00080868 _____ () C:\Windows\setupact.log
2014-02-15 13:53 - 2011-07-31 10:26 - 00002198 _____ () C:\Windows\epplauncher.mif
2014-02-15 13:52 - 2014-02-15 13:52 - 13670584 _____ (Microsoft Corporation) C:\Users\John\Downloads\mseinstall(3).exe
2014-02-15 13:48 - 2011-02-01 17:44 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-15 13:35 - 2012-10-20 12:13 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-15 12:35 - 2014-02-15 12:35 - 05556104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-02-15 12:35 - 2012-10-20 12:13 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-15 12:35 - 2012-10-20 12:13 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-15 12:35 - 2011-05-16 20:43 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-15 11:41 - 2014-02-15 11:38 - 00000000 ____D () C:\3f36c4d9689e4843352e9a94080d05b3
2014-02-15 11:30 - 2011-01-19 21:34 - 00000000 ____D () C:\ProgramData\Sonic
2014-02-15 11:27 - 2013-09-21 10:44 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-02-15 11:25 - 2011-01-25 17:42 - 00000000 ____D () C:\Users\John
2014-02-15 11:24 - 2014-01-24 18:40 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-02-15 11:24 - 2011-02-10 16:28 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-15 11:24 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\AppCompat
2014-02-15 11:23 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\registration
2014-02-15 03:12 - 2014-02-15 03:09 - 00000000 ____D () C:\0c378261dcaff05fc93ca17e9a
2014-02-15 03:09 - 2014-02-15 03:06 - 00000000 ____D () C:\249c6060b3580f371cb7eb1cf8
2014-02-14 08:45 - 2011-07-23 15:54 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster
2014-02-14 08:45 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-02-14 08:45 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
2014-02-14 08:43 - 2012-06-25 06:33 - 00000000 ____D () C:\ProgramData\McAfee
2014-02-14 08:43 - 2011-02-06 16:29 - 00000000 ____D () C:\ProgramData\Apple
2014-02-14 08:43 - 2011-01-19 21:22 - 00000000 ____D () C:\ProgramData\Adobe
2014-02-14 08:42 - 2012-10-20 12:20 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-02-14 08:42 - 2011-05-14 14:26 - 00000000 ___RD () C:\MSOCache
2014-02-14 03:04 - 2014-02-14 03:00 - 00000000 ____D () C:\8647feed28fa7470a2d6e1f2795c60
2014-02-13 14:34 - 2011-01-26 16:50 - 00000000 ____D () C:\Users\John\AppData\Local\Adobe
2014-02-13 03:08 - 2014-02-13 03:06 - 00000000 ____D () C:\4218f922e2c92d124ae48a
2014-02-13 03:05 - 2014-02-13 03:03 - 00000000 ____D () C:\3665ad80702030052f87adff89a55f
2014-01-30 03:01 - 2013-08-15 02:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-30 03:00 - 2011-01-30 08:51 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-29 16:41 - 2014-01-24 18:28 - 00000000 ____D () C:\Program Files (x86)\Online Armor
2014-01-26 03:01 - 2014-01-24 18:28 - 00064720 _____ () C:\Windows\SysWOW64\Drivers\OADriver.sys
2014-01-26 03:01 - 2014-01-24 18:28 - 00062008 _____ () C:\Windows\SysWOW64\Drivers\oahlp64.sys
2014-01-26 03:01 - 2014-01-24 18:28 - 00052360 _____ (Emsisoft) C:\Windows\SysWOW64\Drivers\OAmon.sys
2014-01-26 03:01 - 2014-01-24 18:28 - 00035368 _____ (Emsisoft) C:\Windows\system32\Drivers\OAnet.sys
2014-01-25 09:09 - 2013-12-27 13:02 - 00001079 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2014-01-24 18:40 - 2014-01-24 18:40 - 00000000 ____D () C:\Program Files (x86)\McAfee Security Scan
2014-01-24 18:40 - 2013-10-20 10:51 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-24 18:39 - 2014-01-24 18:39 - 00005175 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-24 18:39 - 2011-01-19 21:15 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-24 18:36 - 2014-01-24 18:29 - 00000000 ____D () C:\ProgramData\OnlineArmor
2014-01-24 18:33 - 2014-01-24 08:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-24 18:33 - 2011-01-19 23:10 - 00321520 _____ () C:\Windows\PFRO.log
2014-01-24 18:29 - 2014-01-24 18:29 - 00000000 ____D () C:\Users\John\AppData\Roaming\OnlineArmor
2014-01-24 18:27 - 2014-01-24 18:27 - 30185256 _____ (Emsisoft GmbH ) C:\Users\John\Downloads\OnlineArmorSetup(1).exe
2014-01-24 18:27 - 2014-01-24 18:26 - 30185256 _____ (Emsisoft GmbH ) C:\Users\John\Downloads\OnlineArmorSetup.exe
2014-01-24 08:20 - 2014-01-24 08:13 - 00000000 ____D () C:\Users\John\AppData\Local\Mozilla
2014-01-24 08:16 - 2014-01-24 08:12 - 00001153 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-01-24 08:14 - 2014-01-24 08:14 - 00282992 _____ (Mozilla) C:\Users\John\Downloads\Firefox Setup Stub 26.0(1).exe
2014-01-23 18:41 - 2014-01-23 18:41 - 00282992 _____ (Mozilla) C:\Users\John\Downloads\Firefox Setup Stub 26.0 (1).exe
2014-01-23 18:28 - 2009-07-14 00:13 - 00786578 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-01-23 18:16 - 2014-01-23 18:16 - 00282992 _____ (Mozilla) C:\Users\John\Downloads\Firefox Setup Stub 26.0.exe
2014-01-19 02:33 - 2011-08-06 22:09 - 00270496 _____ (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-01-16 03:18 - 2009-07-13 23:45 - 03479968 _____ () C:\Windows\system32\FNTCACHE.DAT
Files to move or delete:
====================
C:\ProgramData\PKP_DLes.DAT
C:\ProgramData\PKP_DLet.DAT
C:\ProgramData\PKP_DLev.DAT
Some content of TEMP:
====================
C:\Users\John\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\John\AppData\Local\Temp\mssinstaller.exe
C:\Users\John\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-08 14:11
==================== End Of Log ============================