Results 1 to 2 of 2

Thread: hello again guys malware adware and spyware removal help

  1. #1
    Junior Member
    Join Date
    Jul 2014
    Posts
    5

    Default hello again guys malware adware and spyware removal help

    Hey guys, my father and I had a falling out. Needless to say, he doesnt want to proceed with the work you guys had layed out for us. So, I figured I could atleast try and get my machine clean. Any help would be greatly appreciated. For some reason aswMBR isnt working correctly, it wont update the virus definitions and it wont allow me to scan at all. Any Ideas?



    FRST LOG
    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-08-2014
    Ran by waynehunterq (administrator) on WAYNEHUNTERQ-PC on 06-08-2014 23:57:51
    Running from C:\Users\waynehunterq\Desktop\Virus Recovery Folder
    Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
    Internet Explorer Version 11
    Boot Mode: Normal

    The only official download link for FRST:
    Download link for 32-Bit version: http://www.bleepingcomputer.com/down...an-tool/dl/81/
    Download link for 64-Bit Version: http://www.bleepingcomputer.com/down...an-tool/dl/82/
    Download link from any site other than Bleeping Computer is unpermitted or outdated.
    See tutorial for FRST: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
    (AMD) C:\Windows\System32\atiesrxx.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
    (Fuyu LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
    (Anvisoft) C:\Program Files (x86)\Anvisoft\Cloud System Booster\extentions\Toolbox\Startup booster\StartupTimeSrv.exe
    (AMD) C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
    (AMD) C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
    (Anvisoft) C:\Program Files (x86)\Anvisoft\Cloud System Booster\CSBSvc.exe
    (Anvisoft) C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASD2Srv.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
    (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
    () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
    (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
    () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
    () C:\Users\waynehunterq\AppData\Roaming\VOPackage\VOsrv.exe
    () C:\Program Files (x86)\PassShowS\PassShowl.exe
    () C:\Program Files (x86)\SupTab\HpUI.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
    (Anvisoft) C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASD2.exe
    (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
    (Wajam Internet Technologies Inc.) C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe
    (RCP) C:\Program Files (x86)\RCP\RegCleanPro.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
    (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    (Anvisoft) C:\Program Files (x86)\Anvisoft\Cloud System Booster\CloudSystemBooster.exe
    () C:\Program Files (x86)\SupTab\Loader32.exe
    () C:\Program Files (x86)\SupTab\Loader64.exe
    (Anvisoft Corporation) C:\Program Files (x86)\Anvisoft\Cloud System Booster\extentions\Toolbox\Anvi RAM Booster\Anvi_RAM_Booster.exe
    (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe
    () C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe
    (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
    (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
    (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.PurBrowse64.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BrowserAdapter.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (AMD) C:\Windows\SysWOW64\WinMsgBalloonServer.exe
    (AMD) C:\Windows\SysWOW64\WinMsgBalloonClient.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    () C:\Program Files (x86)\Deal Keeper\updateDealKeeper.exe
    (Microsoft Corporation) C:\Windows\ehome\mcupdate.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
    HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-08-09] (VIA)
    HKLM-x32\...\Run: [AnyProtect Scanner] => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [16987136 2014-07-27] (AnyProtect.com)
    HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296520 2014-07-28] (RealNetworks, Inc.)
    HKLM\...\Policies\Explorer: [HideSCAHealth] 1
    HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-05-21] (Microsoft Corporation)
    HKU\.DEFAULT\...\Policies\Explorer: [HideSCAHealth] 1
    HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [GoogleChromeAutoLaunch_D1AED79CDC80A08C4FCDB94506043851] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488 2014-07-15] (Google Inc.)
    HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [24477056 2014-06-27] (Google)
    HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [CloudSystemBooster] => C:\Program Files (x86)\Anvisoft\Cloud System Booster\CloudSystemBooster.exe [527544 2014-05-29] (Anvisoft)
    HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [mmonitor] => C:\Program Files (x86)\Anvisoft\Cloud System Booster\extentions\toolbox\Anvi RAM Booster\Anvi_RAM_Booster.exe [1681080 2013-12-23] (Anvisoft Corporation)
    HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2014-04-12] (Google Inc.)
    HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
    HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\Policies\Explorer: [HideSCAHealth] 1
    HKU\S-1-5-21-2235072853-4185849235-691160065-1000\...\MountPoints2: {e89b7deb-151d-11e4-bdfb-94de80ce65ca} - F:\setup.exe -a
    IFEO\bitguard.exe: [Debugger] tasklist.exe
    IFEO\bprotect.exe: [Debugger] tasklist.exe
    IFEO\bpsvc.exe: [Debugger] tasklist.exe
    IFEO\browserdefender.exe: [Debugger] tasklist.exe
    IFEO\browserprotect.exe: [Debugger] tasklist.exe
    IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
    IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
    IFEO\jumpflip: [Debugger] tasklist.exe
    IFEO\protectedsearch.exe: [Debugger] tasklist.exe
    IFEO\searchinstaller.exe: [Debugger] tasklist.exe
    IFEO\searchprotection.exe: [Debugger] tasklist.exe
    IFEO\searchprotector.exe: [Debugger] tasklist.exe
    IFEO\searchsettings.exe: [Debugger] tasklist.exe
    IFEO\searchsettings64.exe: [Debugger] tasklist.exe
    IFEO\snapdo.exe: [Debugger] tasklist.exe
    IFEO\stinst32.exe: [Debugger] tasklist.exe
    IFEO\stinst64.exe: [Debugger] tasklist.exe
    IFEO\umbrella.exe: [Debugger] tasklist.exe
    IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
    IFEO\volaro: [Debugger] tasklist.exe
    IFEO\vonteera: [Debugger] tasklist.exe
    IFEO\websteroids.exe: [Debugger] tasklist.exe
    IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk
    ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)
    ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
    ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
    ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
    ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
    ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
    GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7EA35A4DC056CF01
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istart123.com/?type=hp&ts...5PXXXX9VMRXS5P
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.calcitapp.info/
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.v9.com/web/?type=ds&ts=1406390791&from=air&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&i=psd&t=346463446&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istart123.com/?type=hp&ts...5PXXXX9VMRXS5P
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istart123.com/?type=hp&ts...5PXXXX9VMRXS5P
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.v9.com/web/?type=ds&ts=1406390791&from=air&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&i=psd&t=346463446&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istart123.com/?type=hp&ts...5PXXXX9VMRXS5P
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://websearch.calcitapp.info/
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe
    SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
    SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
    SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL =
    SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
    SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
    SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://rocket-find.com/results.php?f=4&q={searchTerms}&a=rckt_ir_14_30_ie&cd=2XzuyEtN2Y1L1QzuzyyE0D0EzztD0C0EyCyD0C0AyD0E0EtBtN0D0Tzu0SzytAtAtN1L2XzutBtFtBtCtFtCyEtFyEtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyE0CtDyBzz0D0FtDtG0BtC0B0BtGyCyCtDyBtGtD0B0AyCtGyD0B0AyEzzyD0A0EzzzytAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0A0DtA0F0CtD0BtGtDzz0FyEtG0AyD0A0AtGzz0CyBtCtGyD0AyE0EyEyDzyzytAzzyByD2Q&cr=1349864551&ir=
    SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://rocket-find.com/results.php?f=4&q={searchTerms}&a=rckt_ir_14_30_ie&cd=2XzuyEtN2Y1L1QzuzyyE0D0EzztD0C0EyCyD0C0AyD0E0EtBtN0D0Tzu0SzytAtAtN1L2XzutBtFtBtCtFtCyEtFyEtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyE0CtDyBzz0D0FtDtG0BtC0B0BtGyCyCtDyBtGtD0B0AyCtGyD0B0AyEzzyD0A0EzzzytAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0A0DtA0F0CtD0BtGtDzz0FyEtG0AyD0A0AtGzz0CyBtCtGyD0AyE0EyEyDzyzytAzzyByD2Q&cr=1349864551&ir=
    SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istart123.com/web/?type=ds&ts=1406472932&from=ymb&uid=ST3160318AS_9VMRXS5PXXXX9VMRXS5P&q={searchTerms}
    BHO: No Name -> {181F2C09-56DD-4F98-86D7-59BA2BC59B5A} -> No File
    BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll (RealDownloader)
    BHO: ShopSave ToolbarBHO -> {6CC4BF79-7708-4ECB-8F2B-A11264A67989} -> C:\Program Files (x86)\ShopSave Toolbar\2.1.2\KangoBHO64.dll (Kango)
    BHO: No Name -> {7D1B27B2-3DE0-4F26-94A0-E14FDB06D292} -> No File
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    BHO: CostMin -> {AAC25859-AD45-D406-F3AB-2A1280536BE6} -> C:\Program Files (x86)\CostMin\QvFQg39u.x64.dll ()
    BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg64.dll (Google Inc.)
    BHO-x32: No Name -> {181F2C09-56DD-4F98-86D7-59BA2BC59B5A} -> No File
    BHO-x32: Deal Keeper -> {1ec8187a-6435-44e3-bbe4-6ce6d3c69254} -> C:\Program Files (x86)\Deal Keeper\DealKeeperbho.dll (Deal Keeper)
    BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
    BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited)
    BHO-x32: ShopSave ToolbarBHO -> {6CC4BF79-7708-4ECB-8F2B-A11264A67989} -> C:\Program Files (x86)\ShopSave Toolbar\2.1.2\KangoBHO.dll (Kango)
    BHO-x32: No Name -> {7D1B27B2-3DE0-4F26-94A0-E14FDB06D292} -> No File
    BHO-x32: PassShow -> {A1067C25-D623-DD31-A82F-A717FA2046EC} -> C:\Program Files (x86)\PassShowS\173.dll ()
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    BHO-x32: CostMin -> {AAC25859-AD45-D406-F3AB-2A1280536BE6} -> C:\Program Files (x86)\CostMin\QvFQg39u.dll ()
    BHO-x32: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
    BHO-x32: No Name -> {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} -> No File
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    Toolbar: HKLM - ShopSave Toolbar - {033BE5FC-ED4C-48A0-8F07-E0128384D828} - C:\Program Files (x86)\ShopSave Toolbar\2.1.2\KangoBHO64.dll (Kango)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62

    FireFox:
    ========
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin-x32: @real.com/nppl3260;version=17.0.11.0 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=17.0.11 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
    FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.11 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
    FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=17.0.11 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
    FF Plugin-x32: @real.com/nprpplugin;version=17.0.11.0 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer Cloud)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin HKCU: anvisoft.com/AdblockPlugin - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll (Anvisoft)
    FF HKLM-x32\...\Firefox\Extensions: [{1DD9AC48-0855-4AE7-9934-159B4377FFA2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
    FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-07-28]
    FF HKCU\...\Firefox\Extensions: [{C516109B-6EA1-337C-2C31-0D60F65A73F0}] - C:\Program Files (x86)\PassShowS\173.xpi
    FF Extension: PassShow - C:\Program Files (x86)\PassShowS\173.xpi [2014-06-30]

    Chrome:
    =======
    CHR HomePage: hxxp://websearch.calcitapp.info/
    CHR StartupUrls: "hxxp://websearch.calcitapp.info/"
    CHR NewTab: "chrome-extension://pelmeidfhdlhlbjimpabfcbnnojbboma/index.html"
    CHR DefaultSearchKeyword: v9
    CHR DefaultNewTabURL:
    CHR Extension: (Google Drive) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-28]
    CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-28]
    CHR Extension: (RealPlayer Downloader) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-07-17]
    CHR Extension: (AnviAdblock) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhmiofmipcpmhgihiecmpiekcacigpgb [2014-07-26]
    CHR Extension: (Google Wallet) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-14]
    CHR Extension: (PassShow) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\peebhdfiangfgjfgcllikhdckkhibbcb [2014-06-30]
    CHR Extension: (Quick start) - C:\Users\waynehunterq\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [2014-07-27]
    CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\WAYNEH~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-05-21]
    CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2014-06-10]
    CHR HKLM-x32\...\Chrome\Extension: [lhmiofmipcpmhgihiecmpiekcacigpgb] - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\chrome.crx [2014-04-29]
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R2 AnviStartupTime; C:\Program Files (x86)\Anvisoft\Cloud System Booster\extentions\Toolbox\Startup booster\StartupTimeSrv.exe [193256 2013-05-07] (Anvisoft)
    R2 AnviCsbSvc; C:\Program Files (x86)\Anvisoft\Cloud System Booster\CSBSvc.exe [42680 2014-05-29] (Anvisoft)
    S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
    R2 ASD2Svc; C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASD2Srv.exe [1206504 2014-05-28] (Anvisoft)
    R2 be0fb33b; c:\Program Files (x86)\Supporter\SupporterSvc.dll [174416 2014-07-27] () [File not signed]
    R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173792 2014-06-03] (Microsoft Corp.)
    R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [702344 2014-07-27] (Cherished Technololgy LIMITED)
    R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
    R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
    R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-06-10] ()
    R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-07-28] (RealNetworks, Inc.)
    R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [23552 2014-06-10] () [File not signed]
    R2 servervo; C:\Users\waynehunterq\AppData\Roaming\VOPackage\VOsrv.exe [71680 2014-07-27] () [File not signed]
    R2 Update Deal Keeper; C:\Program Files (x86)\Deal Keeper\updateDealKeeper.exe [323320 2014-08-06] ()
    R2 Util Deal Keeper; C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe [323320 2014-08-06] ()
    R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-03] (VIA Technologies, Inc.)
    R2 Wajam Internet Enhancer Service; C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe [303616 2014-07-31] (Wajam Internet Technologies Inc.) [File not signed]
    R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [535936 2014-07-27] (Fuyu LIMITED)
    S2 pcregservice; C:\Program Files\pcreg\pcreg.exe [X]
    S2 pennybee; "C:\PROGRA~3\pennybee\pennybee.exe" /task=4 /InstallOn=0 /closebr=0 /active=24 /update=24 /interval=2880 /pubId=1004 /affId=10040007 /appId=116 /uId=3EBDC1B9-8EFC-4D16-94F5-8E71B540A678 /version=1.1.0.13 /Override=0 /regAppName=pennybee /curSID= /logf=\10040007_loger_25_07_19_58_38_-1170997570.txt /mac=94DE80CE65CA /tst=none /ts2=1 [X]
    S2 sssvc; "C:\Program Files (x86)\SearchSnacks\Service\sssvc.exe" [X]
    S2 Update sizlsearch; "C:\Program Files (x86)\sizlsearch\updatesizlsearch.exe" [X]
    S2 Util sizlsearch; "C:\Program Files (x86)\sizlsearch\bin\utilsizlsearch.exe" [X]
    S2 wpennybeed; "C:\PROGRA~3\pennybee\wpennybeed.exe" -scm [X]

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
    R1 asd2fsm; C:\Windows\System32\DRIVERS\asd2fsm.sys [48656 2014-05-28] (Anvisoft)
    R1 Asdids; C:\Windows\System32\DRIVERS\asdids.sys [47632 2014-05-28] (Anvisoft)
    R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
    R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-06-12] (NetFilterSDK.com)
    R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
    R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
    R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [231112 2013-01-02] (VIA Technologies, Inc.)
    R2 webinstr; C:\Windows\system32\Drivers\webinstr.sys [57528 2014-06-10] (Corsica)
    R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [301256 2013-01-02] (VIA Technologies, Inc.)
    R1 {55dce8ba-9dec-4013-937e-adbf9317d990}Gw64; C:\Windows\System32\drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}Gw64.sys [61072 2014-07-25] (StdLib)
    S3 gdrv; \??\C:\Windows\gdrv.sys [X]
    S1 {9d5747ee-0448-4681-8337-1555de75a3b6}Gw64; system32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}Gw64.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2014-08-06 23:59 - 2014-08-06 23:59 - 05185536 _____ (AVAST Software) C:\Users\waynehunterq\Desktop\aswMBR.exe
    2014-08-06 23:58 - 2014-08-06 23:59 - 05185536 _____ (AVAST Software) C:\Users\waynehunterq\Downloads\aswMBR.exe
    2014-08-06 23:56 - 2014-08-06 23:56 - 02094080 _____ (Farbar) C:\Users\waynehunterq\Downloads\FRST64.exe
    2014-08-06 23:52 - 2014-08-06 23:52 - 00001332 _____ () C:\Users\waynehunterq\Desktop\Clean Registry for Free!.lnk
    2014-08-06 23:51 - 2014-08-06 23:51 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP3.job
    2014-08-06 23:51 - 2014-08-06 23:51 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP2.job
    2014-08-06 23:50 - 2014-08-06 23:50 - 00003368 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
    2014-08-06 23:50 - 2014-08-06 23:50 - 00003248 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000
    2014-08-01 19:58 - 2014-08-06 23:48 - 00000168 _____ () C:\Windows\setupact.log
    2014-08-01 19:58 - 2014-08-01 19:58 - 00000000 _____ () C:\Windows\setuperr.log
    2014-07-31 23:03 - 2014-07-31 23:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam
    2014-07-31 23:03 - 2014-07-31 23:03 - 00000000 ____D () C:\Program Files (x86)\Wajam
    2014-07-31 23:02 - 2014-07-31 23:02 - 00002222 _____ () C:\Users\Public\Desktop\Google Earth.lnk
    2014-07-31 23:02 - 2014-07-31 23:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    2014-07-31 23:01 - 2014-07-31 23:01 - 00000000 ____D () C:\Program Files (x86)\ShopSave Toolbar
    2014-07-31 23:00 - 2014-07-31 23:00 - 00000000 ____D () C:\ProgramData\smdmf
    2014-07-31 23:00 - 2014-07-31 23:00 - 00000000 ____D () C:\Program Files (x86)\Settings Manager
    2014-07-31 03:32 - 2014-07-31 03:32 - 00000045 _____ () C:\Users\waynehunterq\AppData\Roaming\WB.CFG
    2014-07-29 17:07 - 2014-07-29 17:07 - 00000000 ____D () C:\Program Files (x86)\PennyBee
    2014-07-29 16:28 - 2014-08-06 23:51 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
    2014-07-28 17:13 - 2014-07-28 17:13 - 00000000 ____D () C:\Program Files (x86)\RealNetworks
    2014-07-28 17:10 - 2014-07-28 17:10 - 00201800 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
    2014-07-28 17:09 - 2014-07-28 17:09 - 00278600 _____ (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
    2014-07-28 17:07 - 2014-07-28 17:07 - 00505416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
    2014-07-28 06:22 - 2014-07-28 17:21 - 00003390 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
    2014-07-28 06:22 - 2014-07-28 17:21 - 00003270 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000
    2014-07-28 06:22 - 2014-07-28 06:22 - 00003410 _____ () C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
    2014-07-27 12:10 - 2014-07-27 16:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FREESOFTTODAY
    2014-07-27 12:10 - 2014-07-27 12:10 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\fst_us_181
    2014-07-27 12:10 - 2014-07-27 12:10 - 00000000 ____D () C:\Program Files (x86)\fst_us_181
    2014-07-27 11:15 - 2014-07-25 16:19 - 00061072 _____ (StdLib) C:\Windows\system32\Drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}Gw64.sys
    2014-07-27 10:12 - 2014-07-27 10:12 - 00002928 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.scan.results
    2014-07-27 10:12 - 2014-07-27 10:12 - 00001176 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.scan.quick.results
    2014-07-27 10:12 - 2014-07-27 10:12 - 00000318 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.uninstall.scan.results
    2014-07-27 10:10 - 2014-07-31 23:17 - 00000000 ____D () C:\Program Files (x86)\Deal Keeper
    2014-07-27 10:10 - 2014-07-27 10:10 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2014-07-27 10:10 - 2014-07-27 10:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
    2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Windows\system32\Macromed
    2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
    2014-07-27 10:09 - 2014-07-27 10:11 - 00000000 ____D () C:\Program Files (x86)\AnyProtectEx
    2014-07-27 10:09 - 2014-07-25 10:13 - 00575544 _____ (ClickMeIn Limited) C:\Users\waynehunterq\AppData\Local\AnyProtectScannerSetup.exe
    2014-07-27 09:57 - 2014-07-27 12:09 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\VOPackage
    2014-07-27 09:57 - 2014-07-27 09:57 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
    2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\istart123
    2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
    2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\Program Files (x86)\Supporter
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Torch
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Packages
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Comodo
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Chromatic Browser
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Chromatic Browser
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\ProgramData\CostMin
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\ProgramData\1b82de639df9d971
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Program Files (x86)\CostMin
    2014-07-27 09:23 - 2014-07-27 09:24 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\vlc
    2014-07-27 00:03 - 2014-08-06 23:58 - 00000000 ____D () C:\FRST
    2014-07-26 23:57 - 2014-07-29 18:50 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro
    2014-07-26 23:57 - 2014-07-29 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
    2014-07-26 23:56 - 2014-07-26 23:56 - 00003632 _____ () C:\Windows\System32\Tasks\Sparta WW1
    2014-07-26 23:56 - 2014-07-26 23:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\sparta111
    2014-07-26 23:56 - 2014-07-26 23:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sparta
    2014-07-26 23:55 - 2014-07-26 23:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Sparta
    2014-07-26 18:54 - 2014-05-08 04:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
    2014-07-26 18:54 - 2014-05-08 04:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
    2014-07-26 18:54 - 2014-01-08 21:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
    2014-07-26 18:54 - 2014-01-03 17:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
    2014-07-26 11:28 - 2014-07-26 11:29 - 10304417 _____ () C:\Users\waynehunterq\Downloads\240P_400K_1027280 (1).mp4
    2014-07-26 11:26 - 2014-07-26 11:27 - 03735208 _____ () C:\Users\waynehunterq\Downloads\144P_150K_1027280.3gp
    2014-07-26 11:17 - 2014-07-26 11:17 - 00000458 _____ () C:\Windows\Tasks\SpeedyPC Registration3.job
    2014-07-26 11:17 - 2014-07-26 11:17 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\SpeedyPC Software
    2014-07-26 11:17 - 2014-07-26 11:17 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\DriverCure
    2014-07-26 11:12 - 2014-07-31 11:11 - 00003740 _____ () C:\Windows\System32\Tasks\DriverRestore_ScheduledScan
    2014-07-26 11:12 - 2014-07-31 11:11 - 00003592 _____ () C:\Windows\System32\Tasks\DriverRestore_DailyScan
    2014-07-26 11:12 - 2014-07-26 11:12 - 00000585 _____ () C:\Windows\Tasks\SpeedyPC Pro_sch_94F6518D-14DF-11E4-A166-94DE80CE65CA.job
    2014-07-26 11:12 - 2014-07-26 11:12 - 00000478 _____ () C:\Windows\Tasks\SpeedyPC Update Version3_triggeronce.job
    2014-07-26 11:12 - 2014-07-26 11:12 - 00000478 _____ () C:\Windows\Tasks\SpeedyPC Update Version3.job
    2014-07-26 11:12 - 2014-07-26 11:12 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedyPC Software
    2014-07-26 11:11 - 2014-07-26 11:12 - 00000000 ____D () C:\ProgramData\SpeedyPC Software
    2014-07-26 11:11 - 2014-07-26 11:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
    2014-07-26 11:11 - 2014-07-26 11:11 - 00000000 ____D () C:\Program Files (x86)\SpeedyPC Software
    2014-07-26 11:11 - 2014-07-01 12:37 - 00020872 _____ (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS
    2014-07-26 11:10 - 2014-07-31 13:11 - 00000000 ____D () C:\Program Files (x86)\DriverRestore
    2014-07-26 11:09 - 2014-07-26 11:09 - 00000000 ____D () C:\Program Files\SearchSnacks
    2014-07-26 11:09 - 2014-07-26 11:09 - 00000000 ____D () C:\Program Files (x86)\SearchSnacks
    2014-07-26 11:08 - 2014-07-27 09:57 - 00000000 ____D () C:\ProgramData\IePluginServices
    2014-07-26 11:08 - 2014-07-26 22:17 - 00000000 ____D () C:\Program Files (x86)\PCTechHotline
    2014-07-26 11:08 - 2014-07-26 14:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Fix Speed with PC Tech Hotline
    2014-07-26 11:08 - 2014-07-26 13:27 - 00000000 ____D () C:\Program Files (x86)\PCFixSpeed
    2014-07-26 11:08 - 2014-07-26 11:09 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\PCFixSpeed
    2014-07-26 11:08 - 2014-07-26 11:08 - 00000000 ____D () C:\ProgramData\PCFixSpeed
    2014-07-26 11:07 - 2014-07-27 09:57 - 00000000 ____D () C:\Program Files (x86)\SupTab
    2014-07-26 11:07 - 2014-07-26 11:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiDefMedia
    2014-07-26 11:06 - 2014-07-26 11:06 - 00000000 ____D () C:\Program Files (x86)\HiDefMedia
    2014-07-26 10:28 - 2014-07-26 10:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2014-07-26 10:24 - 2014-07-26 10:24 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
    2014-07-26 10:24 - 2014-07-26 10:24 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
    2014-07-26 10:06 - 2014-07-26 10:13 - 00000000 ____D () C:\Windows\system32\MRT
    2014-07-26 10:06 - 2014-06-26 17:40 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2014-07-26 09:57 - 2013-10-01 20:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
    2014-07-26 09:56 - 2013-10-01 21:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
    2014-07-26 09:56 - 2013-10-01 21:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
    2014-07-26 09:56 - 2013-10-01 21:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
    2014-07-26 09:56 - 2013-10-01 20:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
    2014-07-26 09:56 - 2013-10-01 20:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
    2014-07-26 09:56 - 2013-10-01 20:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
    2014-07-26 09:56 - 2013-10-01 19:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
    2014-07-26 09:56 - 2013-10-01 19:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
    2014-07-26 09:56 - 2013-10-01 19:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
    2014-07-26 09:56 - 2013-10-01 19:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
    2014-07-26 09:56 - 2013-10-01 19:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
    2014-07-26 09:56 - 2013-10-01 18:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
    2014-07-26 09:56 - 2013-10-01 18:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
    2014-07-26 09:56 - 2013-10-01 18:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
    2014-07-26 09:56 - 2013-10-01 17:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
    2014-07-26 09:54 - 2012-08-23 09:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
    2014-07-26 09:54 - 2012-08-23 09:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
    2014-07-26 09:54 - 2012-08-23 06:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
    2014-07-26 09:54 - 2012-08-23 05:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
    2014-07-26 09:36 - 2013-09-24 21:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
    2014-07-26 09:36 - 2013-09-24 20:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
    2014-07-26 09:31 - 2012-05-04 06:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
    2014-07-26 09:31 - 2012-05-04 04:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2014-07-26 09:29 - 2014-07-26 09:29 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Anvisoft
    2014-07-26 09:28 - 2014-07-26 09:28 - 00003548 _____ () C:\Windows\System32\Tasks\Csb_AutoScan_Task
    2014-07-26 09:14 - 2014-07-26 09:14 - 00003748 _____ () C:\Windows\System32\Tasks\ASD_Schedule
    2014-07-26 09:07 - 2014-08-06 23:48 - 00000000 ____D () C:\ProgramData\boost_interprocess
    2014-07-26 09:07 - 2014-07-26 09:14 - 00003304 _____ () C:\Windows\System32\Tasks\ASD_Main
    2014-07-26 09:06 - 2014-07-26 14:20 - 00000000 ____D () C:\ProgramData\Anvisoft
    2014-07-26 09:06 - 2014-07-26 09:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft
    2014-07-26 09:06 - 2014-07-26 09:06 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
    2014-07-26 09:06 - 2014-05-28 21:03 - 00048656 _____ (Anvisoft) C:\Windows\system32\Drivers\asd2fsm.sys
    2014-07-26 08:42 - 2014-07-26 08:42 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-WAYNEHUNTERQ-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
    2014-07-26 08:41 - 2014-07-26 08:41 - 00000000 ____D () C:\RegBackup
    2014-07-26 08:40 - 2014-08-06 23:57 - 00000000 ____D () C:\Users\waynehunterq\Desktop\Virus Recovery Folder
    2014-07-26 08:40 - 2014-07-26 08:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
    2014-07-26 08:40 - 2014-07-26 08:40 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
    2014-07-25 23:33 - 2014-07-25 23:33 - 00010666 _____ () C:\Users\waynehunterq\Downloads\pixel.htm
    2014-07-25 21:49 - 2014-07-25 21:49 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp23588
    2014-07-25 19:33 - 2014-07-25 19:34 - 02578135 _____ () C:\Users\waynehunterq\Downloads\shortshortts.wmv
    2014-07-24 19:00 - 2014-07-24 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp3241
    2014-07-23 19:00 - 2014-07-23 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp16151
    2014-07-22 19:00 - 2014-07-22 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp28793
    2014-07-22 13:49 - 2014-07-22 13:49 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp717
    2014-07-22 06:20 - 2014-07-26 09:44 - 00000000 ____D () C:\Windows\Minidump
    2014-07-22 03:34 - 2014-07-26 14:22 - 00003078 _____ () C:\Windows\System32\Tasks\Advanced System Protector_startup
    2014-07-22 03:34 - 2014-07-22 03:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector
    2014-07-22 03:33 - 2014-07-26 14:29 - 00000176 _____ () C:\Windows\Tasks\Tempo Runner.job
    2014-07-22 03:33 - 2014-07-22 03:34 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Media Player Classic
    2014-07-22 03:33 - 2014-07-22 03:34 - 00000000 ____D () C:\ProgramData\Systweak
    2014-07-22 03:33 - 2014-07-22 03:34 - 00000000 ____D () C:\Program Files (x86)\ASP
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\unpacked11047
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\StormFall
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rocket
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp11037
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\StormFall
    2014-07-22 03:33 - 2012-07-25 12:03 - 00016896 _____ () C:\Windows\system32\sasnative64.exe
    2014-07-22 03:32 - 2014-08-06 23:56 - 00003090 _____ () C:\Windows\System32\Tasks\RegClean Pro
    2014-07-22 03:32 - 2014-07-31 23:05 - 00000272 _____ () C:\Windows\Tasks\RegClean Pro_DEFAULT.job
    2014-07-22 03:32 - 2014-07-31 23:04 - 00000280 _____ () C:\Windows\Tasks\RegClean Pro_UPDATES.job
    2014-07-22 03:32 - 2014-07-26 14:16 - 00000000 ____D () C:\ProgramData\pennybee
    2014-07-22 03:32 - 2014-07-25 19:59 - 00000760 _____ () C:\Windows\Tasks\pennybee Runner.job
    2014-07-22 03:32 - 2014-07-22 03:34 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Systweak
    2014-07-22 03:32 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Rocket
    2014-07-22 03:32 - 2014-07-22 03:32 - 00003556 _____ () C:\Windows\System32\Tasks\Rocket Updater
    2014-07-22 03:32 - 2014-07-22 03:32 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\RocketUpdater
    2014-07-22 03:31 - 2014-07-31 23:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
    2014-07-22 03:31 - 2014-07-31 23:04 - 00000000 ____D () C:\Program Files (x86)\RCP
    2014-07-22 03:31 - 2014-07-22 03:32 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Essentials Codec Pack
    2014-07-22 03:31 - 2014-07-22 03:32 - 00000000 ____D () C:\Program Files (x86)\WSE Rocket
    2014-07-22 03:31 - 2014-07-22 03:32 - 00000000 ____D () C:\Program Files (x86)\Essentials Codec Pack
    2014-07-22 03:31 - 2014-07-17 11:42 - 00020328 _____ () C:\Windows\system32\roboot64.exe
    2014-07-22 03:30 - 2014-07-22 03:30 - 00683360 _____ () C:\Users\waynehunterq\Downloads\MediaCodec.exe
    2014-07-22 03:30 - 2014-07-22 03:30 - 00683360 _____ () C:\Users\waynehunterq\Downloads\MediaCodec (1).exe
    2014-07-17 12:30 - 2014-07-17 12:30 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\RealNetworks
    2014-07-17 12:29 - 2014-07-17 12:29 - 00000000 ____D () C:\ProgramData\RealNetworks
    2014-07-17 12:28 - 2014-07-28 17:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
    2014-07-17 12:28 - 2014-07-28 17:13 - 00000000 ____D () C:\Program Files (x86)\Real
    2014-07-17 12:28 - 2014-07-17 12:28 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
    2014-07-17 12:27 - 2014-07-28 17:21 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Real
    2014-07-17 12:27 - 2014-07-28 17:11 - 00000000 ____D () C:\ProgramData\Real
    2014-07-09 14:45 - 2014-06-29 21:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2014-07-09 14:45 - 2014-06-29 21:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2014-07-09 14:45 - 2014-06-20 15:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2014-07-09 14:45 - 2014-06-18 20:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2014-07-09 14:45 - 2014-06-18 19:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2014-07-09 14:45 - 2014-06-18 19:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2014-07-09 14:45 - 2014-06-18 19:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2014-07-09 14:45 - 2014-06-18 18:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2014-07-09 14:45 - 2014-06-18 18:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2014-07-09 14:45 - 2014-06-18 18:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2014-07-09 14:45 - 2014-06-18 18:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2014-07-09 14:45 - 2014-06-18 18:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2014-07-09 14:45 - 2014-06-18 18:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2014-07-09 14:45 - 2014-06-18 18:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2014-07-09 14:45 - 2014-06-18 18:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2014-07-09 14:45 - 2014-06-18 18:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2014-07-09 14:45 - 2014-06-18 17:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2014-07-09 14:45 - 2014-06-18 17:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2014-07-09 14:45 - 2014-06-18 17:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2014-07-09 14:45 - 2014-06-18 17:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2014-07-09 14:45 - 2014-06-18 17:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2014-07-09 14:45 - 2014-06-17 21:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
    2014-07-09 14:45 - 2014-06-17 20:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
    2014-07-09 14:45 - 2014-06-17 20:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2014-07-09 14:45 - 2014-06-06 05:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
    2014-07-09 14:45 - 2014-06-06 04:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
    2014-07-09 14:45 - 2014-05-30 03:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2014-07-09 14:45 - 2014-05-30 03:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2014-07-09 14:45 - 2014-05-30 03:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2014-07-09 14:45 - 2014-05-30 03:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2014-07-09 14:45 - 2014-05-30 03:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2014-07-09 14:45 - 2014-05-30 03:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2014-07-09 14:45 - 2014-05-30 03:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2014-07-09 14:45 - 2014-05-30 02:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2014-07-09 14:45 - 2014-05-30 02:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2014-07-09 14:45 - 2014-05-30 02:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2014-07-09 14:45 - 2014-05-30 02:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2014-07-09 14:45 - 2014-05-30 02:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2014-07-09 14:45 - 2014-05-30 02:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2014-07-09 14:45 - 2014-05-30 02:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2014-07-09 14:45 - 2014-05-30 01:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
    2014-07-09 14:44 - 2014-06-20 14:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2014-07-09 14:44 - 2014-06-18 20:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2014-07-09 14:44 - 2014-06-18 20:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2014-07-09 14:44 - 2014-06-18 19:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2014-07-09 14:44 - 2014-06-18 19:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2014-07-09 14:44 - 2014-06-18 19:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2014-07-09 14:44 - 2014-06-18 19:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2014-07-09 14:44 - 2014-06-18 19:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2014-07-09 14:44 - 2014-06-18 19:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2014-07-09 14:44 - 2014-06-18 19:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2014-07-09 14:44 - 2014-06-18 19:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2014-07-09 14:44 - 2014-06-18 19:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2014-07-09 14:44 - 2014-06-18 19:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2014-07-09 14:44 - 2014-06-18 19:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2014-07-09 14:44 - 2014-06-18 18:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2014-07-09 14:44 - 2014-06-18 18:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2014-07-09 14:44 - 2014-06-18 18:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2014-07-09 14:44 - 2014-06-18 18:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2014-07-09 14:44 - 2014-06-18 18:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2014-07-09 14:44 - 2014-06-18 18:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2014-07-09 14:44 - 2014-06-18 18:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2014-07-09 14:44 - 2014-06-18 18:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2014-07-09 14:44 - 2014-06-18 18:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2014-07-09 14:44 - 2014-06-18 18:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2014-07-09 14:44 - 2014-06-18 18:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2014-07-09 14:44 - 2014-06-18 18:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2014-07-09 14:44 - 2014-06-18 18:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2014-07-09 14:44 - 2014-06-18 18:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2014-07-09 14:44 - 2014-06-18 17:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2014-07-09 14:44 - 2014-06-18 17:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2014-07-09 14:44 - 2014-06-18 17:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2014-07-09 14:44 - 2014-06-18 17:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2014-07-09 14:44 - 2014-06-18 17:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2014-07-09 14:44 - 2014-06-18 17:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2014-07-09 14:44 - 2014-06-18 17:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2014-07-09 14:44 - 2014-06-18 17:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2014-07-09 14:44 - 2014-06-18 17:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2014-07-09 14:44 - 2014-06-05 09:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2014-07-09 14:44 - 2014-06-05 09:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2014-07-09 14:44 - 2014-06-05 09:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2014-08-06 23:59 - 2014-08-06 23:59 - 05185536 _____ (AVAST Software) C:\Users\waynehunterq\Desktop\aswMBR.exe
    2014-08-06 23:59 - 2014-08-06 23:58 - 05185536 _____ (AVAST Software) C:\Users\waynehunterq\Downloads\aswMBR.exe
    2014-08-06 23:58 - 2014-07-27 00:03 - 00000000 ____D () C:\FRST
    2014-08-06 23:57 - 2014-07-26 08:40 - 00000000 ____D () C:\Users\waynehunterq\Desktop\Virus Recovery Folder
    2014-08-06 23:57 - 2014-04-12 21:32 - 01213241 _____ () C:\Windows\WindowsUpdate.log
    2014-08-06 23:56 - 2014-08-06 23:56 - 02094080 _____ (Farbar) C:\Users\waynehunterq\Downloads\FRST64.exe
    2014-08-06 23:56 - 2014-07-22 03:32 - 00003090 _____ () C:\Windows\System32\Tasks\RegClean Pro
    2014-08-06 23:52 - 2014-08-06 23:52 - 00001332 _____ () C:\Users\waynehunterq\Desktop\Clean Registry for Free!.lnk
    2014-08-06 23:51 - 2014-08-06 23:51 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP3.job
    2014-08-06 23:51 - 2014-08-06 23:51 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP2.job
    2014-08-06 23:51 - 2014-07-29 16:28 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
    2014-08-06 23:50 - 2014-08-06 23:50 - 00003368 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
    2014-08-06 23:50 - 2014-08-06 23:50 - 00003248 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000
    2014-08-06 23:50 - 2014-05-21 05:28 - 00000000 ___RD () C:\Users\waynehunterq\Google Drive
    2014-08-06 23:50 - 2009-07-13 21:34 - 00000505 _____ () C:\Windows\win.ini
    2014-08-06 23:48 - 2014-08-01 19:58 - 00000168 _____ () C:\Windows\setupact.log
    2014-08-06 23:48 - 2014-07-26 09:07 - 00000000 ____D () C:\ProgramData\boost_interprocess
    2014-08-06 23:48 - 2014-06-30 21:17 - 00000398 _____ () C:\Windows\Tasks\PassShow Update.job
    2014-08-06 23:48 - 2014-06-30 21:17 - 00000378 _____ () C:\Windows\Tasks\PassShow_wd.job
    2014-08-06 23:48 - 2014-04-12 22:35 - 00000906 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-08-06 23:48 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2014-08-04 21:05 - 2009-07-13 23:45 - 00014464 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2014-08-04 21:05 - 2009-07-13 23:45 - 00014464 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2014-08-01 20:25 - 2014-04-12 22:35 - 00000910 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-08-01 19:58 - 2014-08-01 19:58 - 00000000 _____ () C:\Windows\setuperr.log
    2014-07-31 23:17 - 2014-07-27 10:10 - 00000000 ____D () C:\Program Files (x86)\Deal Keeper
    2014-07-31 23:05 - 2014-07-22 03:32 - 00000272 _____ () C:\Windows\Tasks\RegClean Pro_DEFAULT.job
    2014-07-31 23:04 - 2014-07-22 03:32 - 00000280 _____ () C:\Windows\Tasks\RegClean Pro_UPDATES.job
    2014-07-31 23:04 - 2014-07-22 03:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
    2014-07-31 23:04 - 2014-07-22 03:31 - 00000000 ____D () C:\Program Files (x86)\RCP
    2014-07-31 23:03 - 2014-07-31 23:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam
    2014-07-31 23:03 - 2014-07-31 23:03 - 00000000 ____D () C:\Program Files (x86)\Wajam
    2014-07-31 23:03 - 2014-04-12 23:09 - 00002273 _____ () C:\Install.log
    2014-07-31 23:02 - 2014-07-31 23:02 - 00002222 _____ () C:\Users\Public\Desktop\Google Earth.lnk
    2014-07-31 23:02 - 2014-07-31 23:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    2014-07-31 23:02 - 2014-04-12 22:35 - 00000000 ____D () C:\Program Files (x86)\Google
    2014-07-31 23:01 - 2014-07-31 23:01 - 00000000 ____D () C:\Program Files (x86)\ShopSave Toolbar
    2014-07-31 23:00 - 2014-07-31 23:00 - 00000000 ____D () C:\ProgramData\smdmf
    2014-07-31 23:00 - 2014-07-31 23:00 - 00000000 ____D () C:\Program Files (x86)\Settings Manager
    2014-07-31 23:00 - 2014-04-13 18:26 - 00000358 _____ () C:\Windows\Tasks\bench-sys.job
    2014-07-31 23:00 - 2014-04-12 21:40 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\CrashDumps
    2014-07-31 22:26 - 2014-04-13 18:26 - 00000358 _____ () C:\Windows\Tasks\bench-S-1-5-21-2235072853-4185849235-691160065-1000.job
    2014-07-31 19:57 - 2014-07-04 14:42 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\serv
    2014-07-31 13:11 - 2014-07-26 11:10 - 00000000 ____D () C:\Program Files (x86)\DriverRestore
    2014-07-31 11:11 - 2014-07-26 11:12 - 00003740 _____ () C:\Windows\System32\Tasks\DriverRestore_ScheduledScan
    2014-07-31 11:11 - 2014-07-26 11:12 - 00003592 _____ () C:\Windows\System32\Tasks\DriverRestore_DailyScan
    2014-07-31 03:32 - 2014-07-31 03:32 - 00000045 _____ () C:\Users\waynehunterq\AppData\Roaming\WB.CFG
    2014-07-31 00:21 - 2014-04-13 00:18 - 00000000 ____D () C:\Program Files (x86)\File Type Assistant
    2014-07-29 19:19 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
    2014-07-29 18:50 - 2014-07-26 23:57 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro
    2014-07-29 18:43 - 2014-07-26 23:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
    2014-07-29 17:07 - 2014-07-29 17:07 - 00000000 ____D () C:\Program Files (x86)\PennyBee
    2014-07-28 17:21 - 2014-07-28 06:22 - 00003390 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
    2014-07-28 17:21 - 2014-07-28 06:22 - 00003270 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000
    2014-07-28 17:21 - 2014-07-17 12:27 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Real
    2014-07-28 17:13 - 2014-07-28 17:13 - 00000000 ____D () C:\Program Files (x86)\RealNetworks
    2014-07-28 17:13 - 2014-07-17 12:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
    2014-07-28 17:13 - 2014-07-17 12:28 - 00000000 ____D () C:\Program Files (x86)\Real
    2014-07-28 17:11 - 2014-07-17 12:27 - 00000000 ____D () C:\ProgramData\Real
    2014-07-28 17:10 - 2014-07-28 17:10 - 00201800 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
    2014-07-28 17:09 - 2014-07-28 17:09 - 00278600 _____ (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
    2014-07-28 17:07 - 2014-07-28 17:07 - 00505416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
    2014-07-28 06:22 - 2014-07-28 06:22 - 00003410 _____ () C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000
    2014-07-27 16:45 - 2014-07-27 12:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FREESOFTTODAY
    2014-07-27 12:10 - 2014-07-27 12:10 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\fst_us_181
    2014-07-27 12:10 - 2014-07-27 12:10 - 00000000 ____D () C:\Program Files (x86)\fst_us_181
    2014-07-27 12:09 - 2014-07-27 09:57 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\VOPackage
    2014-07-27 10:12 - 2014-07-27 10:12 - 00002928 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.scan.results
    2014-07-27 10:12 - 2014-07-27 10:12 - 00001176 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.scan.quick.results
    2014-07-27 10:12 - 2014-07-27 10:12 - 00000318 _____ () C:\Users\waynehunterq\AppData\Roaming\aps.uninstall.scan.results
    2014-07-27 10:11 - 2014-07-27 10:09 - 00000000 ____D () C:\Program Files (x86)\AnyProtectEx
    2014-07-27 10:10 - 2014-07-27 10:10 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2014-07-27 10:10 - 2014-07-27 10:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
    2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Windows\system32\Macromed
    2014-07-27 10:10 - 2014-07-27 10:10 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
    2014-07-27 09:57 - 2014-07-27 09:57 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
    2014-07-27 09:57 - 2014-07-26 11:08 - 00000000 ____D () C:\ProgramData\IePluginServices
    2014-07-27 09:57 - 2014-07-26 11:07 - 00000000 ____D () C:\Program Files (x86)\SupTab
    2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\istart123
    2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
    2014-07-27 09:56 - 2014-07-27 09:56 - 00000000 ____D () C:\Program Files (x86)\Supporter
    2014-07-27 09:55 - 2014-04-12 22:33 - 00001623 _____ () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Torch
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Packages
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Comodo
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Chromatic Browser
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\HomeGroupUser$
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Chromatic Browser
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Guest
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Users\Administrator
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\ProgramData\CostMin
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\ProgramData\1b82de639df9d971
    2014-07-27 09:54 - 2014-07-27 09:54 - 00000000 ____D () C:\Program Files (x86)\CostMin
    2014-07-27 09:54 - 2014-04-12 22:35 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Google
    2014-07-27 09:24 - 2014-07-27 09:23 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\vlc
    2014-07-27 04:49 - 2014-04-13 18:26 - 00000258 __RSH () C:\ProgramData\ntuser.pol
    2014-07-27 00:50 - 2014-05-20 02:09 - 00000000 ____D () C:\Program Files (x86)\sizlsearch
    2014-07-26 23:56 - 2014-07-26 23:56 - 00003632 _____ () C:\Windows\System32\Tasks\Sparta WW1
    2014-07-26 23:56 - 2014-07-26 23:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\sparta111
    2014-07-26 23:56 - 2014-07-26 23:56 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sparta
    2014-07-26 23:56 - 2014-07-26 23:55 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Sparta
    2014-07-26 23:53 - 2009-07-14 00:13 - 00782470 _____ () C:\Windows\system32\PerfStringBackup.INI
    2014-07-26 22:17 - 2014-07-26 11:08 - 00000000 ____D () C:\Program Files (x86)\PCTechHotline
    2014-07-26 19:37 - 2014-07-04 15:52 - 00000000 ____D () C:\ProgramData\WeCareReminder
    2014-07-26 18:40 - 2009-07-13 22:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
    2014-07-26 18:39 - 2009-07-13 23:45 - 00273872 _____ () C:\Windows\system32\FNTCACHE.DAT
    2014-07-26 14:29 - 2014-07-22 03:33 - 00000176 _____ () C:\Windows\Tasks\Tempo Runner.job
    2014-07-26 14:27 - 2014-06-30 21:42 - 00000000 ___SD () C:\Windows\system32\CompatTel
    2014-07-26 14:27 - 2009-07-14 02:45 - 00000000 ____D () C:\Program Files\Windows Journal
    2014-07-26 14:27 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
    2014-07-26 14:27 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\Dism
    2014-07-26 14:27 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
    2014-07-26 14:22 - 2014-07-22 03:34 - 00003078 _____ () C:\Windows\System32\Tasks\Advanced System Protector_startup
    2014-07-26 14:22 - 2014-04-13 18:23 - 00003720 _____ () C:\Windows\System32\Tasks\pcreg
    2014-07-26 14:22 - 2014-04-13 18:23 - 00000000 ____D () C:\Program Files\pcreg
    2014-07-26 14:22 - 2014-04-13 00:19 - 00003946 _____ () C:\Windows\System32\Tasks\ProgramUpdateCheck
    2014-07-26 14:21 - 2014-04-12 21:38 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\SevereWeatherAlerts
    2014-07-26 14:20 - 2014-07-26 09:06 - 00000000 ____D () C:\ProgramData\Anvisoft
    2014-07-26 14:19 - 2014-07-26 11:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Fix Speed with PC Tech Hotline
    2014-07-26 14:16 - 2014-07-22 03:32 - 00000000 ____D () C:\ProgramData\pennybee
    2014-07-26 13:27 - 2014-07-26 11:08 - 00000000 ____D () C:\Program Files (x86)\PCFixSpeed
    2014-07-26 12:53 - 2014-05-20 02:16 - 00000000 ____D () C:\Program Files\suprasavings
    2014-07-26 11:29 - 2014-07-26 11:28 - 10304417 _____ () C:\Users\waynehunterq\Downloads\240P_400K_1027280 (1).mp4
    2014-07-26 11:27 - 2014-07-26 11:26 - 03735208 _____ () C:\Users\waynehunterq\Downloads\144P_150K_1027280.3gp
    2014-07-26 11:24 - 2014-04-13 18:23 - 00000000 ____D () C:\Temp
    2014-07-26 11:17 - 2014-07-26 11:17 - 00000458 _____ () C:\Windows\Tasks\SpeedyPC Registration3.job
    2014-07-26 11:17 - 2014-07-26 11:17 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\SpeedyPC Software
    2014-07-26 11:17 - 2014-07-26 11:17 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\DriverCure
    2014-07-26 11:12 - 2014-07-26 11:12 - 00000585 _____ () C:\Windows\Tasks\SpeedyPC Pro_sch_94F6518D-14DF-11E4-A166-94DE80CE65CA.job
    2014-07-26 11:12 - 2014-07-26 11:12 - 00000478 _____ () C:\Windows\Tasks\SpeedyPC Update Version3_triggeronce.job
    2014-07-26 11:12 - 2014-07-26 11:12 - 00000478 _____ () C:\Windows\Tasks\SpeedyPC Update Version3.job
    2014-07-26 11:12 - 2014-07-26 11:12 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedyPC Software
    2014-07-26 11:12 - 2014-07-26 11:11 - 00000000 ____D () C:\ProgramData\SpeedyPC Software
    2014-07-26 11:11 - 2014-07-26 11:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
    2014-07-26 11:11 - 2014-07-26 11:11 - 00000000 ____D () C:\Program Files (x86)\SpeedyPC Software
    2014-07-26 11:09 - 2014-07-26 11:09 - 00000000 ____D () C:\Program Files\SearchSnacks
    2014-07-26 11:09 - 2014-07-26 11:09 - 00000000 ____D () C:\Program Files (x86)\SearchSnacks
    2014-07-26 11:09 - 2014-07-26 11:08 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\PCFixSpeed
    2014-07-26 11:08 - 2014-07-26 11:08 - 00000000 ____D () C:\ProgramData\PCFixSpeed
    2014-07-26 11:07 - 2014-07-26 11:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiDefMedia
    2014-07-26 11:06 - 2014-07-26 11:06 - 00000000 ____D () C:\Program Files (x86)\HiDefMedia
    2014-07-26 10:28 - 2014-07-26 10:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2014-07-26 10:24 - 2014-07-26 10:24 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
    2014-07-26 10:24 - 2014-07-26 10:24 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
    2014-07-26 10:13 - 2014-07-26 10:06 - 00000000 ____D () C:\Windows\system32\MRT
    2014-07-26 09:44 - 2014-07-22 06:20 - 00000000 ____D () C:\Windows\Minidump
    2014-07-26 09:29 - 2014-07-26 09:29 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Anvisoft
    2014-07-26 09:28 - 2014-07-26 09:28 - 00003548 _____ () C:\Windows\System32\Tasks\Csb_AutoScan_Task
    2014-07-26 09:18 - 2014-06-01 11:50 - 00000000 ___RD () C:\Users\waynehunterq\Desktop\Icons
    2014-07-26 09:17 - 2014-04-12 21:38 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Severe Weather Alerts
    2014-07-26 09:14 - 2014-07-26 09:14 - 00003748 _____ () C:\Windows\System32\Tasks\ASD_Schedule
    2014-07-26 09:14 - 2014-07-26 09:07 - 00003304 _____ () C:\Windows\System32\Tasks\ASD_Main
    2014-07-26 09:09 - 2014-04-12 22:29 - 00000000 ____D () C:\Windows\Panther
    2014-07-26 09:07 - 2014-07-26 09:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft
    2014-07-26 09:06 - 2014-07-26 09:06 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
    2014-07-26 08:42 - 2014-07-26 08:42 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-WAYNEHUNTERQ-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
    2014-07-26 08:41 - 2014-07-26 08:41 - 00000000 ____D () C:\RegBackup
    2014-07-26 08:40 - 2014-07-26 08:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
    2014-07-26 08:40 - 2014-07-26 08:40 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
    2014-07-25 23:33 - 2014-07-25 23:33 - 00010666 _____ () C:\Users\waynehunterq\Downloads\pixel.htm
    2014-07-25 21:49 - 2014-07-25 21:49 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp23588
    2014-07-25 19:59 - 2014-07-22 03:32 - 00000760 _____ () C:\Windows\Tasks\pennybee Runner.job
    2014-07-25 19:58 - 2009-07-14 00:08 - 00032546 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
    2014-07-25 19:34 - 2014-07-25 19:33 - 02578135 _____ () C:\Users\waynehunterq\Downloads\shortshortts.wmv
    2014-07-25 16:19 - 2014-07-27 11:15 - 00061072 _____ (StdLib) C:\Windows\system32\Drivers\{55dce8ba-9dec-4013-937e-adbf9317d990}Gw64.sys
    2014-07-25 10:13 - 2014-07-27 10:09 - 00575544 _____ (ClickMeIn Limited) C:\Users\waynehunterq\AppData\Local\AnyProtectScannerSetup.exe
    2014-07-24 19:00 - 2014-07-24 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp3241
    2014-07-23 19:00 - 2014-07-23 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp16151
    2014-07-22 19:00 - 2014-07-22 19:00 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp28793
    2014-07-22 13:49 - 2014-07-22 13:49 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp717
    2014-07-22 03:34 - 2014-07-22 03:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector
    2014-07-22 03:34 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Media Player Classic
    2014-07-22 03:34 - 2014-07-22 03:33 - 00000000 ____D () C:\ProgramData\Systweak
    2014-07-22 03:34 - 2014-07-22 03:33 - 00000000 ____D () C:\Program Files (x86)\ASP
    2014-07-22 03:34 - 2014-07-22 03:32 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Systweak
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\unpacked11047
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\StormFall
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rocket
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\tmp11037
    2014-07-22 03:33 - 2014-07-22 03:33 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\StormFall
    2014-07-22 03:33 - 2014-07-22 03:32 - 00000000 ____D () C:\Users\waynehunterq\AppData\Local\Rocket
    2014-07-22 03:32 - 2014-07-22 03:32 - 00003556 _____ () C:\Windows\System32\Tasks\Rocket Updater
    2014-07-22 03:32 - 2014-07-22 03:32 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\RocketUpdater
    2014-07-22 03:32 - 2014-07-22 03:31 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Essentials Codec Pack
    2014-07-22 03:32 - 2014-07-22 03:31 - 00000000 ____D () C:\Program Files (x86)\WSE Rocket
    2014-07-22 03:32 - 2014-07-22 03:31 - 00000000 ____D () C:\Program Files (x86)\Essentials Codec Pack
    2014-07-22 03:30 - 2014-07-22 03:30 - 00683360 _____ () C:\Users\waynehunterq\Downloads\MediaCodec.exe
    2014-07-22 03:30 - 2014-07-22 03:30 - 00683360 _____ () C:\Users\waynehunterq\Downloads\MediaCodec (1).exe
    2014-07-17 12:30 - 2014-07-17 12:30 - 00000000 ____D () C:\Users\waynehunterq\AppData\Roaming\RealNetworks
    2014-07-17 12:29 - 2014-07-17 12:29 - 00000000 ____D () C:\ProgramData\RealNetworks
    2014-07-17 12:28 - 2014-07-17 12:28 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
    2014-07-17 11:42 - 2014-07-22 03:31 - 00020328 _____ () C:\Windows\system32\roboot64.exe
    2014-07-16 05:47 - 2009-07-14 00:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games

    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2014-07-29 19:12

    ==================== End Of Log ============================





    Addition LOG
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-08-2014
    Ran by waynehunterq at 2014-08-07 00:00:41
    Running from C:\Users\waynehunterq\Desktop\Virus Recovery Folder
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 13.0.0.83 - Adobe Systems Incorporated)
    Adobe AIR (x32 Version: 13.0.0.83 - Adobe Systems Incorporated) Hidden
    Adobe Flash Player 11 ActiveX (HKLM-x32\...\{41042E28-CCA1-4147-869F-9E928B38F04C}) (Version: 11.9.900.170 - Adobe Systems Incorporated)
    Advanced-System Protector (HKLM-x32\...\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1) (Version: 2.1.1000.13665 - Systweak Software)
    AMD Catalyst Install Manager (HKLM\...\{60BBC176-C393-6033-837E-B6BF4CDCBFB9}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
    Anvi Smart Defender 2.2 (HKLM-x32\...\Anvi Smart Defender) (Version: 2.2 - Anvisoft)
    AnyProtect (HKLM-x32\...\AnyProtect) (Version: 1.0.0.1 - CMI Limited) <==== ATTENTION
    Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
    Bing Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.470.0 - Microsoft Corporation)
    Buzzdock (HKLM\...\{ac225167-00fc-452d-94c5-bb93600e7d9a}) (Version: - Alactro LLC) <==== ATTENTION
    Cloud System Booster (HKLM-x32\...\Cloud System Booster) (Version: 3.3 - Anvisoft)
    CostMin (HKLM-x32\...\{2F5F003B-C71B-72E3-42B4-DE51AB079EB2}) (Version: 3.3.0.1900 - CostMin)
    COTM App by We-Care.com v4.1.29.2 (HKLM-x32\...\{18753869-2CAE-44DD-B98A-0A8AC24B0D57}) (Version: 4.1.29.2 - We-Care.com)
    Deal Keeper (HKLM\...\Deal Keeper) (Version: 2014.07.27.142853 - Deal Keeper) <==== ATTENTION
    DriverRestore (HKLM\...\DriverRestore) (Version: 1.0 - 383 Media, Inc.)
    File Type Assistant (HKLM-x32\...\Trusted Software Assistant_is1) (Version: 2014.5.6.0 - ) <==== ATTENTION
    Free All-In-One Media Player (HKLM-x32\...\Free Media Player_is1) (Version: - Free Software Group)
    FreeSoftToday 025.181 (HKLM-x32\...\fst_us_181_is1) (Version: - FREESOFTTODAY) <==== ATTENTION
    FrostWire 5.7.4 (HKLM-x32\...\FrostWire 5) (Version: 5.7.4.1 - FrostWire LLC)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
    Google Drive (HKLM-x32\...\{75939021-3B68-419D-8DC1-E9823BFF9658}) (Version: 1.16.7009.9618 - Google, Inc.)
    Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
    Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
    Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
    HiDef Media Player 1.1.12 (HKLM-x32\...\HiDef Media Player) (Version: 1.1.12 - HiDefMedia)
    istart123 uninstall (HKLM-x32\...\istart123 uninstall) (Version: - istart123)
    Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
    Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
    Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
    ModifyRegistry version 0.1 (HKLM-x32\...\{1D5BE6B5-7FD4-4A78-90F2-AF6B53BC8C1C}_is1) (Version: 0.1 - VIA Technologies, Inc.)
    ON_OFF Charge B12.1025.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE)
    Optimizer Pro v3.2 (HKLM-x32\...\Optimizer Pro_is1) (Version: - ) <==== ATTENTION
    PassShow (HKLM-x32\...\D653625D-A4F4-672A-F0EA-5B7F3331AB76) (Version: - PassShow-software) <==== ATTENTION
    PC Fix Speed with PC Tech Hotline 1.2.0.42 (HKLM-x32\...\{F7B34B38-02A6-44D5-B8CC-06EB3B8ACFC9}_is1) (Version: 1.2.0.42 - Crawler, LLC)
    Penny Bee (HKCU\...\pennybee) (Version: 3.0.0.0 - pennybee)
    PennyBee (HKLM-x32\...\PennyBee) (Version: 1.0.1.0 - PennyBee)
    Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
    RAIDXpert (HKLM-x32\...\InstallShield_{8A4A80C2-87B1-44FB-BC24-9168930EB150}) (Version: 3.3.1540.19 - AMD)
    RAIDXpert (x32 Version: 3.3.1540.19 - AMD) Hidden
    RealDownloader (x32 Version: 17.0.11 - RealNetworks, Inc.) Hidden
    RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
    RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
    RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
    RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.10 - RealNetworks)
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek)
    RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
    RegClean-Pro (HKLM-x32\...\RegClean-Pro_is1) (Version: 6.21 - Systweak Inc) <==== ATTENTION
    Remote Desktop Access (VuuPC) (HKLM-x32\...\VOPackage) (Version: 1.0.0.0 - CMI Limited) <==== ATTENTION
    Rocket (HKCU\...\Rocket) (Version: 31.0.1650.23 - Rocket) <==== ATTENTION
    Search Snacks (HKLM-x32\...\SearchSnacks) (Version: 1.9.0.5 - Search Snacks)
    Severe Weather Alerts (HKCU\...\Severe Weather Alerts) (Version: 1.26.0.0 - Weather Notifications, LLC) <==== ATTENTION
    ShopSave Toolbar (HKLM-x32\...\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}) (Version: 2.1.2 - KangoExtensions) <==== ATTENTION
    sizlsearch (HKLM\...\sizlsearch) (Version: 2014.05.19.235641 - sizlsearch)
    Sparta (HKCU\...\Sparta) (Version: - Sparta)
    SpeedyPC Pro (HKLM-x32\...\{604CD5A1-4520-4844-B064-A3D884B77E91}) (Version: 3.2.5.0 - SpeedyPC Software) <==== ATTENTION
    Start Savin (HKLM-x32\...\35450_Start Savin) (Version: 1.0 - App Squad)
    StormFall (HKCU\...\StormFall) (Version: - StormFall)
    Supporter 1.80 (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{be0fb33b}) (Version: - Costmin) <==== ATTENTION
    suprasavings (HKLM\...\suprasavings) (Version: 2.0.1 - suprasavings) <==== ATTENTION
    Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 1.9.0 - Tweaking.com)
    UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
    VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
    Wajam (HKLM-x32\...\Wajam) (Version: 2.12 (i2.4) - Wajam) <==== ATTENTION
    WebInternetSecurity (HKCU\...\webinternetsecurity) (Version: - WebInternetSecurity) <==== ATTENTION
    Windows Essentials Media Codec Pack 4.7 [64-Bit] (HKLM-x32\...\Windows Essentials Media Codec Pack) (Version: 4.7 - Media Codec)
    WindowsMangerProtect20.0.0.502 (HKLM-x32\...\WindowsMangerProtect) (Version: 20.0.0.502 - WindowsProtect LIMITED) <==== ATTENTION
    World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
    WSE Rocket (HKLM-x32\...\WSE Rocket) (Version: - WSE Rocket) <==== ATTENTION

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


    ==================== Restore Points =========================

    27-07-2014 08:03:38 Windows Update
    28-07-2014 00:00:14 Windows Backup
    30-07-2014 23:07:39 Windows Update
    07-08-2014 04:58:36 Windows Backup

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-13 21:34 - 2014-07-22 03:32 - 00004512 ____A C:\Windows\system32\Drivers\etc\hosts
    127.0.0.1 capitalimonline.com
    127.0.0.1 www.verifi-infonet.com
    127.0.0.1 www.forsil-srl.com
    127.0.0.1 trustedppiclaims.co.uk
    127.0.0.1 ftp.signara.org
    127.0.0.1 buy-fifa-ultimateteam-coins.com
    127.0.0.1 pay.pal-schutz.com
    127.0.0.1 swqk3xftx38.h149.pp39dk.com
    127.0.0.1 robertoleal.es
    127.0.0.1 verifi-infonet.com
    127.0.0.1 ssl.paypal.secure.your.billing.information.mytrickworld.com
    127.0.0.1 lastminute-ibiza.net
    127.0.0.1 myaccount.aol.com.onlineaccounts.upgrade.online.billing.account.update.alcaldiadearaure.gob.ve
    127.0.0.1 www.rhnp.org
    127.0.0.1 173.214.178.24
    127.0.0.1 bit.ly
    127.0.0.1 www.axisengneering.com
    127.0.0.1 www.positive-eft.com
    127.0.0.1 hw0vrcfmu0fpd.com
    127.0.0.1 www.art3c.com.tw
    127.0.0.1 www.kielkoppfest.harzwinter.net
    127.0.0.1 www.battle.net-account.asxp.cn.com
    127.0.0.1 mgstrategiesstudio.com
    127.0.0.1 http://www.paypal.com.p2jdb5zb17llxg...n71m8gjun1.com
    127.0.0.1 paypal.com.update.account.toughbook.cl
    127.0.0.1 www.lappen-123.no
    127.0.0.1 www.paypal-update.visitasgratis.info
    127.0.0.1 stromarket.ru
    127.0.0.1 www.ocevap.com

    There are 65 more lines.


    ==================== Scheduled Tasks (whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

    Task: {014E5A52-9DE4-4ACF-A6BB-C70CDEFC2233} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-12] (Google Inc.)
    Task: {03513526-5A1A-46A6-973E-49D06396908D} - System32\Tasks\pcreg => C:\Program Files\pcreg\service.exe
    Task: {154B95FB-CB85-4537-A9D1-5D51313CA3EB} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-06-10] (RealNetworks, Inc.)
    Task: {2ABD568F-CAFC-4C30-A578-BF344B9A7C8F} - System32\Tasks\bench-S-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\Bench\Updater\updater.exe [2014-03-27] () <==== ATTENTION
    Task: {42135C2B-4484-4958-8633-DF0CD0FAAE73} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe [2014-07-16] (Systweak)
    Task: {4EF8989B-696F-45C3-9576-EA114C00DFE5} - System32\Tasks\ASD_Main => C:/Program Files (x86)/Anvisoft/Anvi Smart Defender/ASD2.exe [2014-05-28] (Anvisoft)
    Task: {4FEBC66C-E3B6-4CF7-9F9A-09132DED1D42} - System32\Tasks\PassShow_wd => C:\Program Files (x86)\PassShowS\PassShowl.exe [2014-06-30] () <==== ATTENTION
    Task: {5056BD37-B44A-4B74-84E9-162750B19586} - System32\Tasks\DriverRestore_DailyScan => C:\Program Files (x86)\DriverRestore\DriverRestore.exe [2014-07-06] ()
    Task: {528569A1-44B4-4543-9A3B-6575C36451CF} - System32\Tasks\PassShow Update => C:\Program Files (x86)\PassShowS\PassShowG38.exe [2014-06-30] () <==== ATTENTION
    Task: {5BD6371A-AC56-4D13-9D16-8577DAA01885} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-06-10] (RealNetworks, Inc.)
    Task: {626A5E02-6F76-4FE5-AD90-FB708E5C64E6} - System32\Tasks\Sparta WW1 => Chrome.exe --kiosk http://plarium.com/play/en/sparta/to...;publisherID=9
    Task: {6E696841-DD78-44EA-95FB-650AD1A6E7DF} - System32\Tasks\DriverRestore_ScheduledScan => C:\Program Files (x86)\DriverRestore\DriverRestore.exe [2014-07-06] ()
    Task: {7739AE33-2144-4189-8051-1AA3E5CCB4B1} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-06-10] (RealNetworks, Inc.)
    Task: {791E9AAD-2E64-4E0E-8DAC-D8BBCBCE3F98} - System32\Tasks\ProgramRefresh-ATFST => C:\Program Files (x86)\File Type Assistant\tsasetup.exe [2014-05-07] ( ) <==== ATTENTION
    Task: {7E41D011-4B35-4B82-80C9-B00233622256} - System32\Tasks\bench-sys => C:\Program Files (x86)\Bench\Updater\updater.exe [2014-03-27] () <==== ATTENTION
    Task: {8F740334-D45A-49CC-8081-2E74D56EEE2C} - System32\Tasks\ASD_Schedule => C:/Program Files (x86)/Anvisoft/Anvi Smart Defender/ASD2.exe [2014-05-28] (Anvisoft)
    Task: {91502108-7823-4669-8E9D-26C9F66C03EA} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
    Task: {9C6518F7-7332-427A-9544-55DF6B612927} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-12] (Google Inc.)
    Task: {E0255F48-B4A5-46BE-B453-521B6BAD410F} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-07-17] (RCP)
    Task: {E3C034E6-3579-4543-AEBA-D45356710DCB} - System32\Tasks\Rocket Updater => C:\Users\waynehunterq\AppData\Roaming\RocketUpdater\UpdateProc\UpdateTask.exe [2013-04-12] ()
    Task: {E7B9136D-66B6-4312-BDE9-02CDE55954BB} - System32\Tasks\ProgramUpdateCheck => C:\Program Files (x86)\File Type Assistant\TSAssist.exe [2014-05-06] (FTA ApS) <==== ATTENTION
    Task: {ED3A10DA-8279-45E6-AEA7-FCAE53BC715E} - System32\Tasks\Csb_AutoScan_Task => C:/Program Files (x86)/Anvisoft/Cloud System Booster/CloudSystemBooster.exe [2014-05-29] (Anvisoft)
    Task: {F45FEB23-C672-4B49-B13E-3795EFFD302E} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-06-10] (RealNetworks, Inc.)
    Task: {F829A5BC-D52D-4E54-84C4-19E633AF23B0} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2235072853-4185849235-691160065-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-06-10] (RealNetworks, Inc.)
    Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
    Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
    Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
    Task: C:\Windows\Tasks\bench-S-1-5-21-2235072853-4185849235-691160065-1000.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
    Task: C:\Windows\Tasks\bench-sys.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\PassShow Update.job => C:\Program Files (x86)\PassShowS\PassShowG38.exe <==== ATTENTION
    Task: C:\Windows\Tasks\PassShow_wd.job => C:\Program Files (x86)\PassShowS\PassShowl.exe <==== ATTENTION
    Task: C:\Windows\Tasks\pennybee Runner.job => C:\PROGRA~3\pennybee\pennybee.exe
    Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RCP\RegCleanPro.exe
    Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RCP\RegCleanPro.exe
    Task: C:\Windows\Tasks\SpeedyPC Pro_sch_94F6518D-14DF-11E4-A166-94DE80CE65CA.job => C:\Program Files (x86)\SpeedyPC Software\SpeedyPC\SpeedyPC.exe <==== ATTENTION
    Task: C:\Windows\Tasks\SpeedyPC Registration3.job => C:\Program Files (x86)\Common Files\SpeedyPC Software\UUS3\UUS3.dll <==== ATTENTION
    Task: C:\Windows\Tasks\SpeedyPC Update Version3.job => c:\program files (x86)\common files\speedypc software\uus3\SpeedyPC_Update3.exe <==== ATTENTION
    Task: C:\Windows\Tasks\SpeedyPC Update Version3_triggeronce.job => c:\program files (x86)\common files\speedypc software\uus3\SpeedyPC_Update3.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Tempo Runner.job => C:\PROGRA~3\pennybee\pennybee.exe

    ==================== Loaded Modules (whitelisted) =============

    2014-06-10 17:50 - 2014-06-10 17:50 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
    2014-06-10 22:03 - 2014-06-10 22:03 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
    2014-07-27 09:58 - 2014-07-27 09:58 - 00071680 _____ () C:\Users\waynehunterq\AppData\Roaming\VOPackage\VOsrv.exe
    2014-07-23 16:32 - 2014-07-26 11:07 - 00106376 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll64.dll
    2014-06-30 21:17 - 2014-06-30 21:17 - 00100864 _____ () C:\Program Files (x86)\PassShowS\PassShowl.exe
    2014-07-23 16:32 - 2014-07-26 11:07 - 00732040 _____ () C:\Program Files (x86)\SupTab\HpUI.exe
    2014-07-16 11:16 - 2014-07-16 11:16 - 00064000 _____ () C:\Program Files (x86)\SupTab\Loader32.exe
    2014-07-16 10:55 - 2014-07-16 10:55 - 00073216 _____ () C:\Program Files (x86)\SupTab\Loader64.exe
    2014-07-27 11:14 - 2014-08-06 23:48 - 00323320 _____ () C:\Program Files (x86)\Deal Keeper\bin\utilDealKeeper.exe
    2014-04-12 23:08 - 2012-08-09 05:55 - 00078480 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
    2014-04-12 23:08 - 2012-08-09 05:55 - 00386192 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
    2014-07-27 11:15 - 2014-08-06 11:25 - 00286968 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.PurBrowse64.exe
    2014-07-27 11:15 - 2014-08-06 23:31 - 00095528 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeper.BrowserAdapter.exe
    2014-07-27 09:28 - 2014-08-06 23:53 - 00323320 _____ () C:\Program Files (x86)\Deal Keeper\updateDealKeeper.exe
    2011-07-22 14:48 - 2011-07-22 14:48 - 00516096 _____ () C:\Program Files (x86)\AMD\RAIDXpert\bin\libxml2.dll
    2014-05-27 02:02 - 2014-05-27 02:02 - 00500968 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\http_hook.dll
    2014-04-29 21:04 - 2014-04-29 21:04 - 00088080 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\libglog.dll
    2014-05-27 02:02 - 2014-05-27 02:02 - 01039080 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASD2Engine.dll
    2014-04-29 21:04 - 2014-04-29 21:04 - 00038928 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\fuzzy.dll
    2014-04-29 21:04 - 2014-04-29 21:04 - 00093712 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\zlibwapi.dll
    2014-05-27 02:02 - 2014-05-27 02:02 - 00135400 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ExtractImpl.dll
    2014-05-27 02:02 - 2014-05-27 02:02 - 00437480 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\InnoExtractDll.dll
    2014-05-27 02:02 - 2014-05-27 02:02 - 00030440 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\UnpackImpl.dll
    2014-05-27 02:02 - 2014-05-27 02:02 - 00259816 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\pyunpacker.dll
    2014-05-27 02:02 - 2014-05-27 02:02 - 00041704 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\fsmlib.dll
    2014-04-29 20:27 - 2014-04-29 20:27 - 00649744 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\sqlite3.dll
    2014-07-27 09:56 - 2014-07-27 09:56 - 00174416 _____ () c:\Program Files (x86)\Supporter\SupporterSvc.dll
    2014-07-27 09:56 - 2014-07-27 09:56 - 04312064 _____ () c:\Program Files (x86)\Supporter\Supporter.dll
    2014-07-28 17:09 - 2014-07-28 17:09 - 00861784 _____ () c:\program files (x86)\real\realplayer\RPDS\Plugins\cldplin.dll
    2014-05-27 02:02 - 2014-05-27 02:02 - 00305896 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\UserProfile.dll
    2014-05-28 04:25 - 2014-05-28 04:25 - 00776936 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\CoreScan.dll
    2014-05-27 02:02 - 2014-05-27 02:02 - 00125672 _____ () C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\FileSearcher.dll
    2014-07-23 16:32 - 2014-07-26 11:07 - 00093576 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll
    2014-05-29 01:47 - 2014-05-29 01:47 - 00018616 _____ () C:\Program Files (x86)\Anvisoft\Cloud System Booster\Public.dll
    2013-11-27 04:33 - 2013-11-27 04:33 - 00156344 _____ () C:\Program Files (x86)\Anvisoft\Cloud System Booster\ui.dll
    2013-11-27 04:33 - 2013-11-27 04:33 - 00090808 _____ () C:\Program Files (x86)\Anvisoft\Cloud System Booster\libglognc.dll
    2014-05-29 01:47 - 2014-05-29 01:47 - 00028856 _____ () C:\Program Files (x86)\Anvisoft\Cloud System Booster\extentions\TestExtention.dll
    2014-08-06 23:48 - 2014-08-06 23:48 - 00098816 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32api.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00110080 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\pywintypes27.dll
    2014-08-06 23:48 - 2014-08-06 23:48 - 00364544 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\pythoncom27.dll
    2014-08-06 23:48 - 2014-08-06 23:48 - 00045568 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_socket.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 01160704 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_ssl.pyd
    2014-08-06 23:48 - 2014-08-06 23:48 - 00320512 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32com.shell.shell.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00713216 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_hashlib.pyd
    2014-08-06 23:48 - 2014-08-06 23:48 - 01175040 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._core_.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00805888 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._gdi_.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00811008 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._windows_.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 01062400 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._controls_.pyd
    2014-08-06 23:48 - 2014-08-06 23:48 - 00735232 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._misc_.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00128512 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_elementtree.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00127488 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\pyexpat.pyd
    2014-08-06 23:48 - 2014-08-06 23:48 - 00557056 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\pysqlite2._sqlite.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00007168 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\hashobjs_ext.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00087552 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_ctypes.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00119808 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32file.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00108544 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32security.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00018432 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32event.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00038912 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32inet.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00070656 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._html2.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00167936 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32gui.pyd
    2014-08-06 23:48 - 2014-08-06 23:48 - 00011264 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32crypt.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00027136 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\_multiprocessing.pyd
    2014-08-06 23:48 - 2014-08-06 23:48 - 00122368 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._wizard.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00010240 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\select.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00024064 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32pipe.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00686080 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\unicodedata.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00025600 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32pdh.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00525640 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\windows._lib_cacheinvalidation.pyd
    2014-08-06 23:48 - 2014-08-06 23:48 - 00035840 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32process.pyd
    2014-08-06 23:49 - 2014-08-06 23:49 - 00017408 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32profile.pyd
    2014-08-06 23:48 - 2014-08-06 23:48 - 00022528 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\win32ts.pyd
    2014-08-06 23:48 - 2014-08-06 23:48 - 00078336 _____ () C:\Users\waynehunterq\AppData\Local\Temp\_MEI31602\wx._animate.pyd
    2014-07-27 11:15 - 2014-08-06 23:31 - 00195320 _____ () C:\Program Files (x86)\Deal Keeper\bin\DealKeeperBAApp.dll
    2014-07-18 15:28 - 2014-07-15 04:24 - 00718664 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libglesv2.dll
    2014-07-18 15:28 - 2014-07-15 04:24 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libegl.dll
    2014-07-18 15:28 - 2014-07-15 04:24 - 08537928 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll
    2014-07-18 15:28 - 2014-07-15 04:24 - 00353096 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll
    2014-07-18 15:28 - 2014-07-15 04:24 - 01732936 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll
    2014-07-18 15:28 - 2014-07-15 04:24 - 14664008 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll

    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (whitelisted) =============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


    ==================== MSCONFIG/TASK MANAGER disabled items =========

    (Currently there is no automatic fix for this section.)


    ==================== Faulty Device Manager Devices =============

    Name: Teredo Tunneling Pseudo-Interface
    Description: Microsoft Teredo Tunneling Adapter
    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
    Manufacturer: Microsoft
    Service: tunnel
    Problem: : This device cannot start. (Code10)
    Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
    On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

    Name: {9d5747ee-0448-4681-8337-1555de75a3b6}Gw64
    Description: {9d5747ee-0448-4681-8337-1555de75a3b6}Gw64
    Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Manufacturer:
    Service: {9d5747ee-0448-4681-8337-1555de75a3b6}Gw64
    Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
    Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
    Devices stay in this state if they have been prepared for removal.
    After you remove the device, this error disappears.Remove the device, and this error should be resolved.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (07/31/2014 11:00:26 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: SettingsManagerSetup.exe, version: 5.0.0.0, time stamp: 0x51a70926
    Faulting module name: Helper.DLL, version: 0.0.0.0, time stamp: 0x53da3fb9
    Exception code: 0xc0000005
    Fault offset: 0x00159005
    Faulting process id: 0xb6c
    Faulting application start time: 0xSettingsManagerSetup.exe0
    Faulting application path: SettingsManagerSetup.exe1
    Faulting module path: SettingsManagerSetup.exe2
    Report Id: SettingsManagerSetup.exe3

    Error: (07/31/2014 01:12:53 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17207, time stamp: 0x53a20c50
    Faulting module name: urlmon.dll, version: 11.0.9600.17207, time stamp: 0x53a20e1a
    Exception code: 0xc0000005
    Fault offset: 0x00042d30
    Faulting process id: 0x159c
    Faulting application start time: 0xIEXPLORE.EXE0
    Faulting application path: IEXPLORE.EXE1
    Faulting module path: IEXPLORE.EXE2
    Report Id: IEXPLORE.EXE3

    Error: (07/31/2014 09:04:04 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program IEXPLORE.EXE version 11.0.9600.17207 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 2554

    Start Time: 01cfacc68de2c711

    Termination Time: 18

    Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    Report Id:

    Error: (07/31/2014 08:52:58 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program IEXPLORE.EXE version 11.0.9600.17207 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 1c6c

    Start Time: 01cfacc049f9e666

    Termination Time: 23

    Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    Report Id:

    Error: (07/31/2014 05:28:59 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program IEXPLORE.EXE version 11.0.9600.17207 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 2be4

    Start Time: 01cfaca33a7e9f5a

    Termination Time: 45

    Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    Report Id:

    Error: (07/31/2014 00:06:16 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
    Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (07/30/2014 00:01:51 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
    Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (07/29/2014 07:17:59 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17207, time stamp: 0x53a20c50
    Faulting module name: urlmon.dll, version: 11.0.9600.17207, time stamp: 0x53a20e1a
    Exception code: 0xc0000005
    Fault offset: 0x00042d30
    Faulting process id: 0x2bd8
    Faulting application start time: 0xIEXPLORE.EXE0
    Faulting application path: IEXPLORE.EXE1
    Faulting module path: IEXPLORE.EXE2
    Report Id: IEXPLORE.EXE3

    Error: (07/29/2014 07:15:41 PM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
    Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (07/29/2014 06:46:24 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17207, time stamp: 0x53a20c50
    Faulting module name: urlmon.dll, version: 11.0.9600.17207, time stamp: 0x53a20e1a
    Exception code: 0xc0000005
    Fault offset: 0x00042d30
    Faulting process id: 0x33c
    Faulting application start time: 0xIEXPLORE.EXE0
    Faulting application path: IEXPLORE.EXE1
    Faulting module path: IEXPLORE.EXE2
    Report Id: IEXPLORE.EXE3


    System errors:
    =============
    Error: (08/06/2014 11:49:47 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
    %%-2147467259

    Error: (08/06/2014 11:49:47 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Function Discovery Resource Publication service terminated with the following error:
    %%-2147467259

    Error: (08/06/2014 11:48:38 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
    Description: The following boot-start or system-start driver(s) failed to load:
    {9d5747ee-0448-4681-8337-1555de75a3b6}Gw64

    Error: (08/06/2014 11:48:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The wpennybeed service failed to start due to the following error:
    %%2

    Error: (08/06/2014 11:48:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Util sizlsearch service failed to start due to the following error:
    %%2

    Error: (08/06/2014 11:48:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Update sizlsearch service failed to start due to the following error:
    %%2

    Error: (08/06/2014 11:48:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Search Snacks Client Service service failed to start due to the following error:
    %%2

    Error: (08/06/2014 11:48:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The pennybee service failed to start due to the following error:
    %%2

    Error: (08/06/2014 11:48:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The pcregservice Service service failed to start due to the following error:
    %%2

    Error: (08/04/2014 09:04:52 PM) (Source: DCOM) (EventID: 10010) (User: )
    Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}


    Microsoft Office Sessions:
    =========================
    Error: (07/31/2014 11:00:26 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: SettingsManagerSetup.exe5.0.0.051a70926Helper.DLL0.0.0.053da3fb9c000000500159005b6c01cfad3d171288c2C:\Users\WAYNEH~1\AppData\Local\Temp\nshD4D8.tmp\SettingsManagerSetup.exeC:\Users\WAYNEH~1\AppData\Local\Temp\nshD788.tmp\Helper.DLL5dede387-1930-11e4-ac80-94de80ce65ca

    Error: (07/31/2014 01:12:53 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: IEXPLORE.EXE11.0.9600.1720753a20c50urlmon.dll11.0.9600.1720753a20e1ac000000500042d30159c01cfaceaeb71987eC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dll49646401-18de-11e4-ac80-94de80ce65ca

    Error: (07/31/2014 09:04:04 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: IEXPLORE.EXE11.0.9600.17207255401cfacc68de2c71118C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    Error: (07/31/2014 08:52:58 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: IEXPLORE.EXE11.0.9600.172071c6c01cfacc049f9e66623C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    Error: (07/31/2014 05:28:59 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: IEXPLORE.EXE11.0.9600.172072be401cfaca33a7e9f5a45C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    Error: (07/31/2014 00:06:16 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"C:\Windows\Installer\{20C2051A-1ACA-48B4-9BA5-24625DCBD880}\recordingmanager.exe

    Error: (07/30/2014 00:01:51 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"C:\Windows\Installer\{20C2051A-1ACA-48B4-9BA5-24625DCBD880}\recordingmanager.exe

    Error: (07/29/2014 07:17:59 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: IEXPLORE.EXE11.0.9600.1720753a20c50urlmon.dll11.0.9600.1720753a20e1ac000000500042d302bd801cfab8350eefef0C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dllf5db6c40-177e-11e4-ac80-94de80ce65ca

    Error: (07/29/2014 07:15:41 PM) (Source: SideBySide) (EventID: 33) (User: )
    Description: rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"C:\Windows\Installer\{20C2051A-1ACA-48B4-9BA5-24625DCBD880}\recordingmanager.exe

    Error: (07/29/2014 06:46:24 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: IEXPLORE.EXE11.0.9600.1720753a20c50urlmon.dll11.0.9600.1720753a20e1ac000000500042d3033c01cfab80cd63fc2aC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\syswow64\urlmon.dll8c365dc6-177a-11e4-ac80-94de80ce65ca


    ==================== Memory info ===========================

    Percentage of memory in use: 45%
    Total physical RAM: 5629.55 MB
    Available physical RAM: 3086.29 MB
    Total Pagefile: 11257.29 MB
    Available Pagefile: 8448.05 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.85 MB

    ==================== Drives ================================

    Drive c: (New Volume) (Fixed) (Total:149.05 GB) (Free:74.17 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
    Drive e: (LIBRARY) (Removable) (Total:14.9 GB) (Free:12.32 GB) FAT32

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 8D688C24)
    Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (Size: 15 GB) (Disk ID: 00000000)

    Partition: GPT Partition Type.

    ==================== End Of Log ============================

  2. #2
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,708

    Default

    Hello Hunterkiller,

    Last topic closed due to lack of feedback: http://forums.spybot.info/showthread...and-adware-lol

    Also see: http://forums.spybot.info/showthread...766#post455766

    Quote Originally Posted by Hunterkiller View Post
    Hey guys, my father and I had a falling out. Needless to say, he doesnt want to proceed with the work you guys had layed out for us. So, I figured I could atleast try and get my machine clean. Any help would be greatly appreciated. For some reason aswMBR isnt working correctly, it wont update the virus definitions and it wont allow me to scan at all. Any Ideas?
    Under the circumstances it might be best if you take the machine to a technician.

    Best regards.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •