i haven't intentionally d'loaded anything except quicktime which i thought i needed but didn't. that's all tho and was just this morning. the yahoo search engine has now shown up in IE. grrrrrr!
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015
Ran by Dad at 2015-02-03 10:52:05
Running from C:\Users\Dad\Desktop\FRST-OlderVersion
Boot Mode: Safe Mode (with Networking)
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Spybot - Search and Destroy (Disabled - Out of date) {20A26C15-1AF0-7CA3-9380-FAB824A7EE0D}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.7.1.19610 - Adobe Systems Incorporated)
Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version: - )
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe PDF ePub DRM Removal 4.7.1 (HKLM-x32\...\{C9DD56CA-BAE9-452A-AFE9-834C7770D1A3}) (Version: 4.7.1 - EPUBSOFT)
Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.0.150 - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audio Recorder for Free v12.9.8 (HKLM-x32\...\Audio Recorder for Free_is1) (Version: - Copyright(C) 2006-2012 AudioToolMedia Software.)
BEHRINGER UFX 1394 Drivers v6.11.0.0 (HKLM-x32\...\BEHRINGER UFX 1394 Drivers v6.11.0.0) (Version: 6.11.0.0 - BEHRINGER)
Belkin Setup and Router Monitor (HKLM-x32\...\Belkin Setup and Router Monitor_is1) (Version: - )
Best Buy pc app (Version: 3.3.0.0 - Best Buy) Hidden
Best Buy pc app (x32 Version: 3.3.0.0 - Best Buy) Hidden
Bing Bar (HKLM-x32\...\{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}) (Version: 7.3.124.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CameraHelperMsi (x32 Version: 13.50.854.0 - Logitech) Hidden
Canon MP Navigator 3.0 (HKLM-x32\...\MP Navigator 3.0) (Version: - )
Canon MP160 (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 4.16 - Piriform)
CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.2531.52 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Defraggler (HKLM\...\Defraggler) (Version: 2.15 - Piriform)
Dropbox (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
Dwyco CDC-X version 2.10 (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Dwyco CDC-X_is1) (Version: 2.10 - Dwyco, Inc.)
Easy Thumbnails (Remove only) (HKLM-x32\...\Easy Thumbnails_is1) (Version: 3.0 - Fookes Software)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Etron USB3.0 Host Controller (x32 Version: 0.103 - Etron Technology) Hidden
Freemake Video Converter version 3.1.0 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 3.1.0 - Ellora Assets Corporation)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gateway Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Gateway Incorporated)
Gateway Registration (HKLM-x32\...\Gateway Registration) (Version: 1.04.3503 - Gateway Incorporated)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Talk Plugin (HKLM-x32\...\{C77CC230-7417-3F01-B70D-52583DC9FEC9}) (Version: 5.40.2.0 - Google)
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
Google+ Auto Backup (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Google+ Auto Backup) (Version: 1.0.26.151 - Google, Inc.)
Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3505 - Gateway Incorporated)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Gateway Incorporated)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2353 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
iTunes (HKLM\...\{0225AD21-F3E2-4916-BFF3-65D3F9052582}) (Version: 11.0.2.26 - Apple Inc.)
Java 7 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217065FF}) (Version: 7.0.650 - Oracle)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Karaoke Builder Player 3.0 (HKLM-x32\...\Karaoke Builder Player 3.0) (Version: - )
Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.0 - Logitech Inc.)
LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden
Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5131.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyFreeCodec (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MyFreeCodec) (Version: - )
Noise Reduction Plug-In 2.0 (HKLM-x32\...\{B94515E1-2DD6-11E2-849E-F04DA23A5C58}) (Version: 2.0.515 - Sony)
Paltalk Ad Remover 4.0 (HKLM-x32\...\Paltalk Ad Remover_is1) (Version: - The Anubis Group (T.A.G.))
Paltalk Messenger 11.4 (HKLM-x32\...\Paltalk Messenger) (Version: 11.4.564.16191 - AVM Software Inc.)
Peace Art App 2 version 1.1 (HKLM-x32\...\{36756AF9-18F1-467A-AE37-62BC72A0029A}_is1) (Version: 1.1 - Kelly Anne)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.2 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Switch Sound File Converter (HKLM-x32\...\Switch) (Version: - NCH Software)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Taplika (HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Taplika) (Version: 31.0.1650.23 - Taplika) <==== ATTENTION!
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 2.0.0 - Tweaking.com)
VisioForge Video Capture SDK Delphi Redist (x32 Version: 6.2.0.2 - VisioForge) Hidden
Welcome Center (HKLM-x32\...\Gateway Welcome Center) (Version: 1.02.3504 - Gateway Incorporated)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Dad\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Dad\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2107755742-302254199-1763176924-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dad\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
==================== Restore Points =========================
25-01-2015 19:00:17 Windows Backup
27-01-2015 10:01:28 Windows Update
27-01-2015 18:34:21 Installed Samsung Kies3
28-01-2015 09:27:57 Removed Samsung Kies
28-01-2015 22:51:57 Removed Sound Forge Pro 10.0
30-01-2015 20:48:48 Revo Uninstaller Pro's restore point - Google Chrome
30-01-2015 20:54:54 Windows Update
02-02-2015 11:29:56 Windows Backup
03-02-2015 08:22:48 Installed QuickTime 7
03-02-2015 10:19:10 Revo Uninstaller Pro's restore point - Mozilla Firefox 35.0.1 (x86 en-US)
03-02-2015 10:19:44 Revo Uninstaller Pro's restore point - Mozilla Firefox 35.0.1 (x86 en-US)
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 20:34 - 2015-01-30 20:54 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0642325B-D49D-4797-BC3D-2F56533546BB} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {09EEC63B-21B8-4656-86A9-CCDD9C10A77F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-04] (Google Inc.)
Task: {3300F4CE-D879-4D35-8449-19AFCAB8A938} - System32\Tasks\WSE_Taplika => C:\Users\Dad\AppData\Roaming\WSE_TA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {346B439C-CE11-4CE0-B14C-D2FD4E18F124} - System32\Tasks\{1DD8B5E2-C122-4D1F-9758-9B0F5D4479E4} => pcalua.exe -a "C:\Users\Dad\Desktop\My Documents\mp160win64111ea23.exe" -d "C:\Users\Dad\Desktop\My Documents"
Task: {3EB83F69-6812-41E2-A848-7F3A8D689E89} - System32\Tasks\Wise Turbo Checker => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe
Task: {474B6DAF-131A-4A72-908B-2653EDE97FBF} - System32\Tasks\ArcadeGiant Updater => C:\Users\Dad\AppData\Local\ArcadeGiant\updater.exe [2015-02-03] (ArcadeGiant) <==== ATTENTION
Task: {490D819C-47D5-456C-A5EB-EEFBD6B58C82} - System32\Tasks\{62ACF029-05DB-43E9-B5E0-E093E965ED01} => C:\Program Files (x86)\Paltalk Messenger\paltalk.exe [2014-06-24] (AVM Software Inc.)
Task: {57F10B8A-E6DC-41AF-836F-3D3323A974EC} - System32\Tasks\{8438242B-619B-42CD-9AD1-2D389FF75225} => C:\Program Files (x86)\Paltalk Messenger\paltalk.exe [2014-06-24] (AVM Software Inc.)
Task: {65FBC813-8ECD-4300-99D3-4822AFCDAFE9} - System32\Tasks\{F2D720B6-011A-46ED-9209-2320052E5916} => pcalua.exe -a C:\PROGRA~2\Yahoo!\MESSEN~1\UNWISE.EXE -c /U C:\PROGRA~2\Yahoo!\MESSEN~1\INSTALL.LOG
Task: {89903DAE-62F9-4E24-BF41-F181F8031DD0} - System32\Tasks\AgSupport => Rundll32.exe C:\Users\Dad\AppData\Local\ARCADE~1\AgHelp.dll,Start
Task: {8C25C726-0EDD-419C-ABAE-AB81DD4A8954} - System32\Tasks\{DF80F471-10C4-4247-BCB7-5B67BA005FD2} => pcalua.exe -a C:\Users\Dad\Desktop\ts_webcam.exe -d C:\Users\Dad\Desktop
Task: {8D943107-6A50-440B-8E05-7B77AD0A1BEB} - System32\Tasks\{D9E1C870-B7E8-4995-8A98-D579504F6B41} => C:\Program Files (x86)\Paltalk Messenger\paltalk.exe [2014-06-24] (AVM Software Inc.)
Task: {91183DFD-7C1C-4471-B424-93FFA034740B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001UA => C:\Users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe [2015-02-03] (Google Inc.)
Task: {AE3C4923-DF05-46BF-9F7D-71972FD7EF73} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-03] (Adobe Systems Incorporated)
Task: {B0C3D0A2-E90E-41D9-A2AA-D31480DA3178} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-04] (Google Inc.)
Task: {B8D04CC6-6343-45C9-B405-F55D65E7D99C} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {CB7581B8-8545-4786-B62C-1567DBFA5960} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
Task: {CE4612D6-865E-46E6-A8C8-E78BF08ACC3D} - System32\Tasks\NBAgent => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
Task: {E6392F7E-8094-4810-A3A2-612265F0F48F} - System32\Tasks\{F126331D-C6F2-47BE-94F5-C17820994183} => pcalua.exe -a "C:\Program Files (x86)\NCH Software\Recordpad\uninst.exe"
Task: {E738236C-04D2-4CBD-818D-A308E1376E2E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001Core => C:\Users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe [2015-02-03] (Google Inc.)
Task: {ED36A8FB-B1CF-421E-8C67-F352A7A69286} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {F4FE48D0-691E-474D-9BF8-E1EE2DC18853} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {FF5AE516-004E-406B-8236-DF11EE525F5D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-07-23] (Piriform Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001Core.job => C:\Users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001UA.job => C:\Users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe
Task: C:\Windows\Tasks\WSE_Taplika.job => C:\Users\Dad\AppData\Roaming\WSE_TA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
==================== Loaded Modules (whitelisted) =============
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Behringer UFX 1394 Control Panel.lnk => C:\Windows\pss\Behringer UFX 1394 Control Panel.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Dad^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Dad^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk => C:\Windows\pss\Logitech . Product Registration.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Dad^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PalTalk.lnk => C:\Windows\pss\PalTalk.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: ConduitFloatingPlugin_lcnnhcneegeeojhgpfijnlnocjdmlaon => "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Dad\AppData\Roaming\ValueApps\CH\TBVerifier.dll",RunConduitFloatingPlugin lcnnhcneegeeojhgpfijnlnocjdmlaon
MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
MSCONFIG\startupreg: Hotkey Utility => C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: InstaLAN => "C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" startup
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: Messenger (Yahoo!) => "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
MSCONFIG\startupreg: Obrona Block Ads => "C:\Users\Dad\AppData\Local\Obrona Block Ads\ObronaBlockAds.exe" --hidden
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
MSCONFIG\startupreg: smoother => C:\Users\Dad\AppData\Roaming\Booster-Web\Booster-Web-Installer.exe
MSCONFIG\startupreg: SoftonicAssistant => "C:\Users\Dad\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe"
MSCONFIG\startupreg: SpybotSD TeaTimer => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
========================= Accounts: ==========================
Administrator (S-1-5-21-2107755742-302254199-1763176924-500 - Administrator - Disabled)
Dad (S-1-5-21-2107755742-302254199-1763176924-1001 - Administrator - Enabled) => C:\Users\Dad
Guest (S-1-5-21-2107755742-302254199-1763176924-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2107755742-302254199-1763176924-1003 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Microsoft Teredo Tunneling Adapter #2
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/03/2015 10:27:06 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/03/2015 10:26:27 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe" ; Description = Revo Uninstaller Pro's restore point - QuickTime 2015 Packages; Error = 0x8007043c).
Error: (02/03/2015 10:25:36 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (02/03/2015 10:21:31 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/03/2015 10:19:44 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {baae700c-cc61-4732-9a8c-1e02bd7b1d13}
Error: (02/03/2015 10:19:10 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {baae700c-cc61-4732-9a8c-1e02bd7b1d13}
Error: (02/03/2015 09:24:22 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: dsisetup464480652.exe, version: 0.0.0.0, time stamp: 0x2a425e19
Faulting module name: dsisetup464480652.exe, version: 0.0.0.0, time stamp: 0x2a425e19
Exception code: 0xc0000005
Fault offset: 0x00002810
Faulting process id: 0x1d18
Faulting application start time: 0xdsisetup464480652.exe0
Faulting application path: dsisetup464480652.exe1
Faulting module path: dsisetup464480652.exe2
Report Id: dsisetup464480652.exe3
Error: (02/03/2015 04:33:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 35.0.1.5500, time stamp: 0x54c1f9f3
Faulting module name: mozalloc.dll, version: 35.0.1.5500, time stamp: 0x54c1f224
Exception code: 0x80000003
Fault offset: 0x00001425
Faulting process id: 0x59c
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Error: (02/02/2015 08:46:46 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Information only.
Error: The server returned an invalid or unrecognized response
ErrorCode: 14007(0x36b7).
Error: (02/02/2015 08:30:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (02/03/2015 10:27:42 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068
Error: (02/03/2015 10:27:42 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068
Error: (02/03/2015 10:27:42 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068
Error: (02/03/2015 10:27:34 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068
Error: (02/03/2015 10:27:34 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068
Error: (02/03/2015 10:27:34 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068
Error: (02/03/2015 10:27:28 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068
Error: (02/03/2015 10:27:28 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068
Error: (02/03/2015 10:27:28 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068
Error: (02/03/2015 10:25:40 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068
Microsoft Office Sessions:
=========================
Error: (02/03/2015 10:27:06 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/03/2015 10:26:27 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe" Revo Uninstaller Pro's restore point - QuickTime 2015 Packages0x8007043c
Error: (02/03/2015 10:25:36 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Dad\Desktop\esetsmartinstaller_enu.exe
Error: (02/03/2015 10:21:31 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/03/2015 10:19:44 AM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {baae700c-cc61-4732-9a8c-1e02bd7b1d13}
Error: (02/03/2015 10:19:10 AM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {baae700c-cc61-4732-9a8c-1e02bd7b1d13}
Error: (02/03/2015 09:24:22 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: dsisetup464480652.exe0.0.0.02a425e19dsisetup464480652.exe0.0.0.02a425e19c0000005000028101d1801d03fc5737b318eC:\Users\Dad\AppData\Local\dsisetup464480652.exeC:\Users\Dad\AppData\Local\dsisetup464480652.exeba6f92f1-abb8-11e4-a7fe-02060d5d6465
Error: (02/03/2015 04:33:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe35.0.1.550054c1f9f3mozalloc.dll35.0.1.550054c1f224800000030000142559c01d03f9cba71a908C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll2556d749-ab90-11e4-a7fe-02060d5d6465
Error: (02/02/2015 08:46:46 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Error: The server returned an invalid or unrecognized response
ErrorCode: 14007(0x36b7).
Error: (02/02/2015 08:30:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 15%
Total physical RAM: 6048.28 MB
Available physical RAM: 5106.27 MB
Total Pagefile: 12094.74 MB
Available Pagefile: 11220.72 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: (Gateway) (Fixed) (Total:918.41 GB) (Free:807.56 GB) NTFS
Drive d: (MAN_OF_STEEL) (CDROM) (Total:7.57 GB) (Free:0 GB) UDF
Drive k: (FreeAgent GoFlex Drive) (Fixed) (Total:465.76 GB) (Free:0.04 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 5D81C09C)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=918.4 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 465.8 GB) (Disk ID: 4E80EAC4)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by Dad (administrator) on BRIDGES1 on 03-02-2015 10:51:31
Running from C:\Users\Dad\Desktop\FRST-OlderVersion
Loaded Profiles: Dad (Available profiles: Dad)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Taplika)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\RunOnce: [WSE_Taplika] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Dad\AppData\Roaming\WSE_Taplika\UpdateProc\bkup.dat"
HKLM-x32\...\RunOnce: [DelTr96190] => cmd.exe /c rd /s /q "C:\Users\Dad\AppData\Roaming\WSE_Taplika"
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Run: [GoogleChromeAutoLaunch_C1DAAF30A00C843105EF5E39636EB999] => C:\Users\Dad\AppData\Local\Taplika\Application\taplika.exe [754176 2014-11-06] ()
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Run: [Google Update] => C:\Users\Dad\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2015-02-03] (Google Inc.)
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Run: [Google+ Auto Backup] => C:\Users\Dad\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [3746120 2014-08-12] (Google Inc.)
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [WSE_Taplika] => [X]
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [DelTr96190] => cmd.exe /c rd /s /q "C:\Users\Dad\AppData\Roaming\WSE_Taplika"
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [ArcadeGiant508] => cmd.exe /c rmdir "C:\Users\Dad\AppData\Local\ArcadeGiant" /s /q
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\RunOnce: [ArcadeGiant120] => cmd.exe /s /c reg delete "HKCU\Software\AppDataLow\ArcadeGiant" /f
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MountPoints2: {474142ab-da60-11e1-b2fb-e840f20c0b8d} - J:\EasySuite.exe
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MountPoints2: {474142ae-da60-11e1-b2fb-e840f20c0b8d} - E:\EasySuite.exe
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\...\MountPoints2: {474142b1-da60-11e1-b2fb-e840f20c0b8d} - E:\EasySuite.exe
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-2107755742-302254199-1763176924-1001\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://g.msn.com/1me10IE10ENUS/MSN_WCP
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {4C4C7AAB-5854-4241-A414-E2F1EF119C4A} URL = http://www.dnsbasic.com/?prt=DNSBASIC111&sp=&keywords={searchTerms}
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.42.129
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396
FF DefaultSearchEngine: Taplika
FF SearchEngineOrder.1: Yahoo
FF SearchEngineOrder.2:
FF SelectedSearchEngine: Taplika
FF Homepage: hxxp://taplika.com/?f=1&a=tlk_dwndlm_15_06_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtBtD0CtD0Bzz0D0FyE0DtAtN0D0Tzu0StCtCtBzytN1L2XzutAtFyBtFtBtFtDtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StByD0AtDtAyEyBzytGzyyD0F0FtG0Ezy0F0BtG0EyCtA0BtGyCzytB0ByC0AtByBtDtA0A0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyB0FyCzz0E0AtDtG0AzyyB0CtGyE0C0C0BtGzy0Ezy0FtGyEyByCyEtCtCyD0AtDtCyEtA2Q&cr=1534779659&ir=
FF NetworkProxy: "type", 4
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2107755742-302254199-1763176924-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Dad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKU\S-1-5-21-2107755742-302254199-1763176924-1001: @talk.google.com/O1DPlugin -> C:\Users\Dad\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKU\S-1-5-21-2107755742-302254199-1763176924-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Dad\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-2107755742-302254199-1763176924-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Dad\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Dad\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Dad\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\searchplugins\Taplika.xml
FF Extension: Booster Web - C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\fen9gfz2.default-1409800020396\Extensions\jid1-U7omKQ6kQfxMaQ@jetpack [2015-01-28]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-26]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-08-01]
FF Extension: No Name - C:\PROGRA~2\MOZILL~1\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
StartMenuInternet: FIREFOX.EXE - firefox.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AffinegyService; C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe [563104 2011-11-14] (Affinegy, Inc.)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-12] (DEVGURU Co., LTD.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 cleanhlp; C:\Users\Dad\Desktop\bin\cleanhlp64.sys [57024 2015-02-02] (Emsisoft GmbH)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-30] (Malwarebytes Corporation)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [22528 2011-08-02] (Apple Inc.) [File not signed]
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-11] (Microsoft Corporation)
S3 RTL8192su; system32\DRIVERS\RTL8192su.sys [X]
S3 sxuptp; system32\DRIVERS\sxuptp.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-03 09:24 - 2015-02-03 09:24 - 00022528 _____ () C:\Users\Dad\AppData\Local\dsisetup464480652.exe
2015-02-03 08:28 - 2015-02-03 09:33 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001UA.job
2015-02-03 08:28 - 2015-02-03 08:33 - 00000848 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001Core.job
2015-02-03 08:28 - 2015-02-03 08:28 - 00880784 _____ (Google Inc.) C:\Users\Dad\Desktop\GoogleVoiceAndVideoSetup.exe
2015-02-03 08:28 - 2015-02-03 08:28 - 00003870 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001UA
2015-02-03 08:23 - 2015-02-03 10:23 - 00000284 _____ () C:\Windows\Tasks\WSE_Taplika.job
2015-02-03 08:23 - 2015-02-03 09:24 - 00000000 ____D () C:\Users\Dad\AppData\Local\Taplika
2015-02-03 08:23 - 2015-02-03 08:23 - 00003220 _____ () C:\Windows\System32\Tasks\WSE_Taplika
2015-02-03 08:23 - 2015-02-03 08:23 - 00001852 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk
2015-02-03 08:23 - 2015-02-03 08:23 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Taplika
2015-02-03 08:23 - 2015-02-03 08:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-02-03 08:22 - 2015-02-03 08:23 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\WSE_Taplika
2015-02-03 08:22 - 2015-02-03 08:23 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2015-02-03 08:22 - 2015-02-03 08:22 - 00003128 _____ () C:\Windows\System32\Tasks\ArcadeGiant Updater
2015-02-03 08:21 - 2015-02-03 08:22 - 00000000 ____D () C:\Users\Dad\AppData\Local\ArcadeGiant
2015-02-03 08:21 - 2015-02-03 08:21 - 41945432 _____ (Apple Inc.) C:\Users\Dad\Downloads\QuickTime Setup [1].exe
2015-02-03 08:21 - 2015-02-03 08:21 - 00003254 _____ () C:\Windows\System32\Tasks\AgSupport
2015-02-02 20:04 - 2015-02-02 20:04 - 00037714 _____ () C:\Windows\SysWOW64\Result.txt
2015-02-02 20:03 - 2015-02-02 20:03 - 00401920 _____ (Farbar) C:\Users\Dad\Desktop\MiniToolBox.exe
2015-02-02 19:28 - 2015-02-02 19:28 - 00000000 ____D () C:\Program Files (x86)\ESET
2015-02-02 19:27 - 2015-02-02 19:27 - 02347384 _____ (ESET) C:\Users\Dad\Desktop\esetsmartinstaller_enu.exe
2015-02-02 19:18 - 2015-02-02 19:18 - 00001048 _____ () C:\Users\Dad\Desktop\fixlist-1.txt
2015-02-02 14:03 - 2015-02-02 14:03 - 00004176 _____ () C:\Users\Dad\Desktop\a2scan_150202-120104.txt
2015-02-02 11:58 - 2015-02-02 11:58 - 00000694 _____ () C:\Users\Dad\Desktop\Start Emsisoft Emergency Kit.lnk
2015-02-02 11:57 - 2015-02-02 14:03 - 00000000 ____D () C:\Users\Dad\Desktop\bin
2015-02-02 11:57 - 2015-02-02 00:13 - 00432328 ____N (Emsisoft GmbH) C:\Users\Dad\Desktop\Start Emergency Kit Scanner.exe
2015-02-02 11:57 - 2015-02-02 00:13 - 00432328 ____N (Emsisoft GmbH) C:\Users\Dad\Desktop\Start Commandline Scanner.exe
2015-02-02 11:57 - 2015-02-02 00:13 - 00423064 ____N (Emsisoft GmbH) C:\Users\Dad\Desktop\Start BlitzBlank.exe
2015-02-02 11:57 - 2015-02-02 00:13 - 00004079 ____N () C:\Users\Dad\Desktop\readme.txt
2015-02-02 11:56 - 2015-02-02 11:57 - 170235400 _____ () C:\Users\Dad\Desktop\EmsisoftEmergencyKit.exe
2015-02-02 11:36 - 2015-02-03 10:51 - 00000000 ____D () C:\Users\Dad\Desktop\FRST-OlderVersion
2015-01-30 20:58 - 2015-01-30 20:58 - 02194432 _____ () C:\Users\Dad\Desktop\AdwCleaner.exe
2015-01-30 20:48 - 2015-02-02 11:33 - 00001237 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2015-01-30 20:48 - 2015-01-30 20:48 - 00000000 ____D () C:\Users\Dad\AppData\Local\VS Revo Group
2015-01-30 20:48 - 2015-01-30 20:48 - 00000000 ____D () C:\ProgramData\VS Revo Group
2015-01-30 20:48 - 2015-01-30 20:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2015-01-30 20:48 - 2015-01-30 20:48 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-01-30 20:48 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2015-01-30 20:47 - 2015-01-30 20:47 - 10801480 _____ (VS Revo Group ) C:\Users\Dad\Desktop\RevoUninProSetup.exe
2015-01-28 19:58 - 2015-01-28 19:58 - 00000567 _____ () C:\Users\Dad\Desktop\aswMBR.txt
2015-01-28 19:56 - 2015-02-02 11:36 - 02131456 _____ (Farbar) C:\Users\Dad\Desktop\FRST64.exe
2015-01-28 19:56 - 2015-01-28 19:56 - 05198336 _____ (AVAST Software) C:\Users\Dad\Desktop\aswMBR.exe
2015-01-28 19:56 - 2015-01-28 19:56 - 00055206 _____ () C:\Users\Dad\Desktop\FRST.txt
2015-01-28 19:56 - 2015-01-28 19:56 - 00027818 _____ () C:\Users\Dad\Desktop\Addition.txt
2015-01-28 19:54 - 2015-01-28 19:54 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-BRIDGES1-Windows-7-Home-Premium-(64-bit).dat
2015-01-28 19:53 - 2015-01-28 19:53 - 00002242 _____ () C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2015-01-28 19:52 - 2015-01-28 19:52 - 04712336 _____ () C:\Users\Dad\Desktop\tweaking.com_registry_backup_setup.exe
2015-01-28 19:51 - 2015-01-28 19:51 - 00000000 ____D () C:\ProgramData\Winferno
2015-01-28 19:47 - 2015-01-26 02:52 - 00272296 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2015-01-28 19:47 - 2015-01-26 02:52 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2015-01-28 19:47 - 2015-01-26 02:52 - 00176552 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2015-01-28 19:46 - 2015-01-28 09:45 - 00387200 _____ (Catalytix Web Services) C:\Windows\system32\CatWSPrx64.dll
2015-01-28 19:46 - 2015-01-28 09:45 - 00330808 _____ (Catalytix Web Services) C:\Windows\SysWOW64\CatWSPrx.dll
2015-01-28 19:19 - 2015-01-28 19:19 - 02930092 _____ (Gisburne Media) C:\Users\Dad\Desktop\kbplayer.exe
2015-01-28 19:19 - 2015-01-28 19:19 - 00000000 ____D () C:\Program Files (x86)\Karaoke Builder Player
2015-01-28 18:15 - 2015-01-28 18:15 - 00000000 ____D () C:\ProgramData\fpebkpiipncfojhgaddgnofadahpmcjm
2015-01-28 18:15 - 2015-01-28 18:15 - 00000000 ____D () C:\Program Files (x86)\52df7d05-df7b-4abf-8cb0-684d1a20a3e7
2015-01-28 17:54 - 2015-01-28 17:54 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Publish Providers
2015-01-28 17:35 - 2015-01-28 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-01-28 17:35 - 2015-01-28 17:54 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Sony
2015-01-28 17:35 - 2015-01-28 17:50 - 00000000 ____D () C:\Users\Dad\AppData\Local\Sony
2015-01-28 17:35 - 2015-01-28 17:35 - 00000000 ____D () C:\ProgramData\Sony
2015-01-28 17:35 - 2015-01-28 17:35 - 00000000 ____D () C:\Program Files (x86)\Sony
2015-01-28 09:34 - 2015-01-28 09:34 - 00389912 _____ (AnalogX, LLC) C:\Users\Dad\Downloads\autotune [1].exe
2015-01-28 09:21 - 2015-01-28 09:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voxengo
2015-01-28 09:21 - 2015-01-28 09:26 - 00000000 ____D () C:\Program Files\Voxengo
2015-01-28 09:21 - 2015-01-28 09:26 - 00000000 ____D () C:\Program Files\Common Files\VST3
2015-01-28 09:21 - 2015-01-28 09:21 - 00000000 ____D () C:\Program Files\Common Files\Steinberg
2015-01-27 18:34 - 2015-01-27 18:34 - 00001976 _____ () C:\Users\Public\Desktop\Samsung Kies 3.lnk
2015-01-26 21:26 - 2015-02-03 10:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-25 14:50 - 2015-01-25 14:50 - 00003106 _____ () C:\Windows\System32\Tasks\{DF80F471-10C4-4247-BCB7-5B67BA005FD2}
2015-01-24 23:58 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2015-01-15 18:43 - 2014-12-18 21:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-15 18:43 - 2014-12-18 19:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-15 18:43 - 2014-12-11 11:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-15 18:43 - 2014-12-05 22:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-15 18:43 - 2014-12-05 21:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-15 18:43 - 2014-12-05 21:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-15 18:42 - 2014-12-11 23:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-15 18:42 - 2014-12-11 23:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-15 18:42 - 2014-12-11 23:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-15 18:42 - 2014-12-11 23:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-15 18:42 - 2014-12-11 23:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-15 18:42 - 2014-12-11 23:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-15 18:42 - 2014-12-11 23:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-15 18:40 - 2015-01-15 18:40 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\ESET
2015-01-15 18:40 - 2015-01-15 18:40 - 00000000 ____D () C:\Users\Dad\AppData\Local\ESET
2015-01-07 16:10 - 2015-01-07 16:22 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-01-07 12:03 - 2015-01-07 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2015-01-05 12:21 - 2014-12-12 23:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-01-05 12:21 - 2014-12-12 21:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-01-04 15:25 - 2014-10-17 20:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-01-04 15:25 - 2014-10-17 19:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2015-01-04 15:24 - 2014-11-26 19:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-01-04 15:24 - 2014-11-26 19:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-01-04 15:24 - 2014-11-21 21:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-01-04 15:24 - 2014-11-21 21:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-01-04 15:24 - 2014-11-21 21:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-01-04 15:24 - 2014-11-21 20:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-01-04 15:24 - 2014-11-21 20:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-01-04 15:24 - 2014-11-21 20:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-01-04 15:24 - 2014-11-21 20:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-01-04 15:24 - 2014-11-21 20:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-01-04 15:24 - 2014-11-21 20:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-01-04 15:24 - 2014-11-21 20:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-01-04 15:24 - 2014-11-21 20:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-01-04 15:24 - 2014-11-21 20:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-01-04 15:24 - 2014-11-21 20:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-01-04 15:24 - 2014-11-21 20:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-01-04 15:24 - 2014-11-21 20:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-01-04 15:24 - 2014-11-21 20:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-01-04 15:24 - 2014-11-21 20:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-01-04 15:24 - 2014-11-21 20:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-01-04 15:24 - 2014-11-21 20:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-01-04 15:24 - 2014-11-21 20:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-01-04 15:24 - 2014-11-21 20:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-01-04 15:24 - 2014-11-21 20:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-01-04 15:24 - 2014-11-21 20:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-01-04 15:24 - 2014-11-21 20:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-01-04 15:24 - 2014-11-21 20:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-01-04 15:24 - 2014-11-21 20:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-01-04 15:24 - 2014-11-21 20:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-01-04 15:24 - 2014-11-21 19:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-01-04 15:24 - 2014-11-21 19:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-01-04 15:24 - 2014-11-21 19:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-01-04 15:24 - 2014-11-21 19:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-01-04 15:24 - 2014-11-21 19:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-01-04 15:24 - 2014-11-21 19:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-01-04 15:24 - 2014-11-21 19:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-01-04 15:24 - 2014-11-21 19:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-01-04 15:24 - 2014-11-21 19:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-01-04 15:24 - 2014-11-21 19:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-01-04 15:24 - 2014-11-21 19:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-01-04 15:24 - 2014-11-21 19:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-01-04 15:24 - 2014-11-21 19:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-01-04 15:24 - 2014-11-21 19:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-01-04 15:24 - 2014-11-21 19:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-01-04 15:24 - 2014-11-21 19:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-01-04 15:24 - 2014-11-21 19:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-01-04 15:24 - 2014-11-21 19:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-01-04 15:24 - 2014-11-21 19:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-01-04 15:24 - 2014-11-21 19:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-01-04 15:24 - 2014-11-21 19:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-01-04 15:24 - 2014-11-21 19:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-01-04 15:24 - 2014-11-21 19:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-01-04 15:24 - 2014-11-21 18:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-01-04 15:24 - 2014-11-21 18:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-01-04 15:23 - 2014-11-10 21:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-01-04 15:23 - 2014-11-10 20:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-01-04 15:22 - 2014-10-29 20:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2015-01-04 15:22 - 2014-10-29 19:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2015-01-04 15:22 - 2014-10-02 20:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-01-04 15:22 - 2014-10-02 20:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-01-04 15:22 - 2014-10-02 20:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-01-04 15:22 - 2014-10-02 20:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-01-04 15:22 - 2014-10-02 20:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-01-04 15:22 - 2014-10-02 19:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2015-01-04 15:22 - 2014-10-02 19:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2015-01-04 15:22 - 2014-10-02 19:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2015-01-04 15:22 - 2014-10-02 19:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2015-01-04 15:22 - 2014-10-02 19:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2015-01-04 15:19 - 2014-11-07 21:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-01-04 15:19 - 2014-11-07 20:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-01-04 15:12 - 2015-01-04 15:13 - 00000340 _____ () C:\Windows\LkmdfCoInst.log
2015-01-04 11:02 - 2015-01-04 11:02 - 00000000 __SHD () C:\Users\Dad\AppData\Local\EmieBrowserModeList
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-03 10:51 - 2014-10-14 12:26 - 00000000 ____D () C:\FRST
2015-02-03 10:30 - 2009-07-13 23:13 - 00783464 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-03 10:21 - 2014-10-16 10:25 - 00155336 _____ () C:\Windows\PFRO.log
2015-02-03 10:21 - 2014-09-04 19:35 - 00008850 _____ () C:\Windows\setupact.log
2015-02-03 10:21 - 2014-02-11 16:00 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-03 10:21 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-03 10:20 - 2014-01-07 20:18 - 01421856 _____ () C:\Windows\WindowsUpdate.log
2015-02-03 10:16 - 2012-03-31 17:15 - 00000000 ____D () C:\Users\Dad\AppData\Local\Apple Computer
2015-02-03 09:43 - 2014-08-22 20:33 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-03 09:43 - 2013-01-04 20:52 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-03 09:24 - 2014-12-02 22:37 - 00000010 _____ () C:\Users\Dad\AppData\Local\DSI.DAT
2015-02-03 09:24 - 2012-04-06 02:18 - 00000000 ____D () C:\Users\Dad\AppData\Local\CrashDumps
2015-02-03 09:23 - 2014-02-13 10:52 - 00000136 _____ () C:\Users\Dad\AppData\Roaming\WB.CFG
2015-02-03 09:19 - 2014-02-09 16:47 - 03417600 ___SH () C:\Users\Dad\Desktop\Thumbs.db
2015-02-03 08:40 - 2014-02-13 10:57 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
2015-02-03 08:40 - 2012-10-03 00:44 - 00000000 ____D () C:\Users\Dad\AppData\Local\Google
2015-02-03 08:28 - 2012-10-03 00:44 - 00003474 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2107755742-302254199-1763176924-1001Core
2015-02-03 08:28 - 2012-03-29 11:48 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Mozilla
2015-02-03 05:31 - 2014-11-09 11:54 - 00000000 ____D () C:\Users\Dad\AppData\Local\Adobe
2015-02-03 05:31 - 2014-08-22 20:33 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-03 05:31 - 2014-08-22 20:33 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-03 05:31 - 2014-08-22 20:33 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-02 20:37 - 2009-07-13 22:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-02 20:37 - 2009-07-13 22:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-02 14:00 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-02-02 11:29 - 2014-01-04 07:24 - 00000398 _____ () C:\Windows\Tasks\Wise Turbo Checker.job
2015-01-30 21:02 - 2014-10-16 10:35 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-30 21:00 - 2014-10-15 08:47 - 00000000 ____D () C:\AdwCleaner
2015-01-30 20:56 - 2012-07-11 11:56 - 00000000 ____D () C:\Program Files (x86)\Yahoo!
2015-01-30 20:55 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2015-01-30 20:49 - 2013-01-04 20:52 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-28 22:52 - 2012-03-29 14:47 - 00000000 ____D () C:\ProgramData\Yahoo!
2015-01-28 22:51 - 2011-11-08 02:41 - 00000000 ____D () C:\ProgramData\Norton
2015-01-28 21:31 - 2014-12-04 13:31 - 00000000 ____D () C:\Users\Dad\Documents\Audio Recorder for Free
2015-01-28 21:31 - 2014-12-02 19:16 - 00000000 ____D () C:\Users\Dad\Desktop\My Recordings
2015-01-28 19:46 - 2014-10-16 15:37 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-28 19:19 - 2014-12-09 16:32 - 00001112 _____ () C:\Users\Public\Desktop\Karaoke Builder Player.lnk
2015-01-28 19:11 - 2011-11-08 02:40 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-28 18:47 - 2014-05-23 02:40 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2015-01-28 18:47 - 2009-07-13 22:45 - 00271752 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-28 14:51 - 2012-03-29 14:02 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2015-01-28 09:28 - 2013-12-22 18:31 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Samsung
2015-01-28 09:28 - 2013-12-04 21:28 - 00000000 ____D () C:\Program Files (x86)\Samsung
2015-01-27 14:28 - 2014-02-08 19:02 - 00000000 ____D () C:\Users\Dad\Desktop\Samsung pics
2015-01-27 08:06 - 2014-12-09 11:08 - 00000000 ____D () C:\Users\Dad\Desktop\CDG.zip files
2015-01-26 05:26 - 2014-09-14 12:12 - 00000000 ____D () C:\Users\Dad\Desktop\CDG
2015-01-26 02:54 - 2013-10-17 16:34 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-26 02:52 - 2014-10-16 15:38 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-26 01:04 - 2014-08-04 23:52 - 02162696 _____ () C:\console.log
2015-01-25 14:57 - 2014-01-14 12:38 - 00059600 _____ () C:\Users\Dad\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-24 22:59 - 2014-11-03 14:51 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dwyco CDC-X
2015-01-16 03:03 - 2013-08-16 02:00 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-16 03:00 - 2012-03-30 20:51 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-15 18:34 - 2012-07-18 19:56 - 00001945 _____ () C:\Windows\epplauncher.mif
2015-01-08 09:55 - 2010-11-20 21:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-07 17:35 - 2014-10-16 10:35 - 00096472 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-05 18:25 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\rescache
2015-01-05 15:49 - 2013-08-07 09:19 - 00000000 ___RD () C:\Users\Dad\Dropbox
2015-01-05 15:49 - 2013-07-07 09:31 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Dropbox
2015-01-04 15:35 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-01-04 15:12 - 2012-03-29 12:09 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2015-01-04 15:11 - 2012-03-29 11:32 - 00000000 ____D () C:\Users\Dad
2015-01-04 15:08 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2015-01-04 15:07 - 2015-01-03 16:38 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Avg_Update_1014av
2015-01-04 15:07 - 2015-01-03 16:38 - 00000000 ____D () C:\ProgramData\Avg_Update_1014av
2015-01-04 15:07 - 2015-01-03 16:31 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-04 15:07 - 2014-12-09 16:32 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Karaoke Builder
2015-01-04 15:07 - 2014-10-14 12:20 - 00000000 ____D () C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2015-01-04 15:07 - 2014-10-14 12:20 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2015-01-04 15:07 - 2014-08-22 12:20 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-01-04 15:07 - 2014-07-04 13:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Peace Art App
2015-01-04 15:07 - 2014-05-23 02:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec
2015-01-04 15:07 - 2014-01-10 23:00 - 00000000 ____D () C:\Program Files (x86)\Paltalk Messenger
2015-01-04 15:07 - 2013-04-29 03:49 - 00000000 ____D () C:\Program Files\Bonjour
2015-01-04 15:07 - 2013-04-29 03:49 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2015-01-04 15:07 - 2012-08-19 16:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
2015-01-04 15:07 - 2012-04-05 11:30 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2015-01-04 15:07 - 2012-02-06 05:15 - 00000000 ____D () C:\ProgramData\Temp
2015-01-04 15:07 - 2011-11-08 02:31 - 00000000 ___HD () C:\ProgramData\{37272A44-A110-4EB7-A5EF-88B2A05A08C4}
2015-01-04 15:07 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\servicing
2015-01-04 15:07 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-01-04 15:06 - 2014-08-22 12:21 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2015-01-04 15:06 - 2013-03-16 02:01 - 00000000 __SHD () C:\Windows\SysWOW64\%APPDATA%
2015-01-04 15:06 - 2012-04-06 02:18 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2015-01-04 15:06 - 2011-11-08 02:41 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\winrm
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\WCN
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\slmgr
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\winrm
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\WCN
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\slmgr
2015-01-04 15:06 - 2010-11-21 01:06 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2015-01-04 15:06 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\SysWOW64\WindowsPowerShell
2015-01-04 15:06 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\system32\WindowsPowerShell
2015-01-04 15:06 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Web
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Vss
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\spp
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Speech
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\NetworkList
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Msdtc
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\InstallShield
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\IME
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\com
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\sysprep
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\spp
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\spool
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Speech
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\SMI
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\oobe
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\NetworkList
2015-01-04 15:06 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\registration
2015-01-04 15:05 - 2014-10-19 15:30 - 00000000 ____D () C:\Users\Dad\Documents\Dwyco
2015-01-04 15:05 - 2014-10-15 08:54 - 00000000 ____D () C:\Windows\ERUNT
2015-01-04 15:05 - 2014-05-02 02:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-01-04 15:05 - 2014-04-18 18:06 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information
2015-01-04 15:05 - 2013-03-16 02:01 - 00000000 __SHD () C:\Windows\system32\%APPDATA%
2015-01-04 15:05 - 2012-02-06 04:53 - 00000000 ____D () C:\Windows\NAPP_Dism_Log
2015-01-04 15:05 - 2011-11-08 02:41 - 00000000 ____D () C:\Windows\system32\Macromed
2015-01-04 15:05 - 2011-11-08 02:33 - 00000000 ____D () C:\Windows\es
2015-01-04 15:05 - 2011-11-08 02:31 - 00000000 ____D () C:\Windows\oem
2015-01-04 15:05 - 2009-07-13 23:32 - 00000000 ____D () C:\Windows\Performance
2015-01-04 15:05 - 2009-07-13 22:45 - 00000000 ____D () C:\Windows\Setup
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 __RSD () C:\Windows\Media
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\MUI
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Msdtc
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\migwiz
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\IME
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\com
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Speech
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\security
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\schemas
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Resources
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\PLA
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\IME
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Help
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Globalization
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\Branding
2015-01-04 15:05 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\AppCompat
2015-01-04 15:04 - 2014-12-02 18:54 - 00000000 ____D () C:\Program Files (x86)\PreSonus
2015-01-04 15:04 - 2014-10-16 10:35 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-04 15:04 - 2014-08-01 23:23 - 00000000 ____D () C:\Program Files\Logitech
2015-01-04 15:04 - 2014-04-18 20:20 - 00000000 ____D () C:\Program Files (x86)\Canon
2015-01-04 15:04 - 2014-04-18 18:05 - 00000000 ___HD () C:\Program Files\CanonBJ
2015-01-04 15:04 - 2013-09-18 01:41 - 00000000 ____D () C:\Program Files\behringer
2015-01-04 15:04 - 2013-08-07 23:30 - 00000000 ____D () C:\Program Files (x86)\AVS4YOU
2015-01-04 15:04 - 2013-05-13 16:12 - 00000000 ____D () C:\Program Files (x86)\EPUBSOFT
2015-01-04 15:04 - 2013-04-29 09:46 - 00000000 ____D () C:\Program Files\iTunes
2015-01-04 15:04 - 2013-04-29 09:46 - 00000000 ____D () C:\Program Files\iPod
2015-01-04 15:04 - 2013-04-29 09:46 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-01-04 15:04 - 2013-03-16 02:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-01-04 15:04 - 2013-03-16 02:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-01-04 15:04 - 2012-10-20 15:41 - 00000000 ____D () C:\Program Files (x86)\Belkin
2015-01-04 15:04 - 2012-09-17 10:56 - 00000000 ____D () C:\Program Files (x86)\Outsim
2015-01-04 15:04 - 2012-09-17 10:50 - 00000000 ____D () C:\Program Files (x86)\Image-Line
2015-01-04 15:04 - 2012-04-15 16:50 - 00000000 ____D () C:\Program Files\Defraggler
2015-01-04 15:04 - 2012-04-15 16:49 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-04 15:04 - 2012-04-06 10:37 - 00000000 ____D () C:\Program Files (x86)\Freemake
2015-01-04 15:04 - 2012-04-06 02:06 - 00000000 ____D () C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2015-01-04 15:04 - 2012-04-05 11:35 - 00000000 __RHD () C:\MSOCache
2015-01-04 15:04 - 2012-04-05 11:30 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-01-04 15:04 - 2012-03-29 17:20 - 00000000 ____D () C:\Program Files (x86)\Logitech
2015-01-04 15:04 - 2012-03-29 15:08 - 00000000 ____D () C:\Program Files (x86)\The Anubis Group
2015-01-04 15:04 - 2012-03-29 12:09 - 00000000 ____D () C:\Program Files\Common Files\Logishrd
2015-01-04 15:04 - 2012-02-06 05:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2015-01-04 15:04 - 2012-02-06 05:15 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2015-01-04 15:04 - 2012-02-06 05:12 - 00000000 ____D () C:\Program Files\Realtek
2015-01-04 15:04 - 2012-02-06 05:10 - 00000000 ____D () C:\Program Files (x86)\Etron Technology
2015-01-04 15:04 - 2012-02-06 05:07 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-01-04 15:04 - 2012-02-06 04:58 - 00000000 ____D () C:\Program Files\Common Files\Intel
2015-01-04 15:04 - 2011-11-08 02:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-01-04 15:04 - 2011-11-08 02:32 - 00000000 ____D () C:\Program Files\Windows Live
2015-01-04 15:04 - 2011-11-08 02:32 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-01-04 15:04 - 2011-11-08 02:31 - 00000000 ____D () C:\Program Files\Gateway
2015-01-04 15:04 - 2011-11-08 02:31 - 00000000 ____D () C:\Program Files (x86)\Gateway
2015-01-04 15:04 - 2011-11-08 02:24 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-04 15:04 - 2011-11-08 02:24 - 00000000 ____D () C:\Program Files (x86)\Intel
2015-01-04 15:04 - 2011-11-08 02:15 - 00000000 ___HD () C:\OEM
2015-01-04 15:04 - 2011-08-17 21:01 - 00000000 ___HD () C:\dad
2015-01-04 15:04 - 2011-08-17 20:39 - 00000000 ____D () C:\C_
2015-01-04 15:04 - 2010-11-21 01:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Defender
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Reference Assemblies
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\MSBuild
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Microsoft Games
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\DVD Maker
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2015-01-04 15:04 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Windows NT
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files\Common Files\SpeechEngines
2015-01-04 15:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Program Files (x86)\Windows NT
2015-01-04 14:51 - 2015-01-03 16:34 - 00000000 ____D () C:\ProgramData\AVG2015
==================== Files in the root of some directories =======
2013-08-07 06:12 - 2014-11-16 00:53 - 0001181 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.1.txt
2013-08-07 06:12 - 2014-03-30 11:59 - 0000919 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.2.txt
2013-08-07 06:12 - 2014-03-29 18:54 - 0001181 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.3.txt
2013-08-07 06:12 - 2013-08-07 06:34 - 0000919 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.4.txt
2013-08-07 06:12 - 2013-08-07 06:12 - 0001181 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.5.txt
2013-08-07 06:12 - 2014-12-02 18:47 - 0000919 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.txt
2013-08-07 06:12 - 2014-12-02 18:47 - 0000000 _____ () C:\Users\Dad\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt
2012-05-12 15:58 - 2012-05-12 15:58 - 0024597 _____ () C:\Users\Dad\AppData\Roaming\UserTile.png
2014-09-01 02:18 - 2014-09-01 02:18 - 0001248 _____ () C:\Users\Dad\AppData\Roaming\UZNYUL
2014-02-13 10:52 - 2015-02-03 09:23 - 0000136 _____ () C:\Users\Dad\AppData\Roaming\WB.CFG
2014-09-01 02:18 - 2014-09-01 02:18 - 0002086 _____ () C:\Users\Dad\AppData\Roaming\WTPQZFD
2012-04-14 21:46 - 2014-01-03 22:33 - 0119296 _____ () C:\Users\Dad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-02 22:37 - 2015-02-03 09:24 - 0000010 _____ () C:\Users\Dad\AppData\Local\DSI.DAT
2015-02-03 09:24 - 2015-02-03 09:24 - 0022528 _____ () C:\Users\Dad\AppData\Local\dsisetup464480652.exe
2012-08-18 05:51 - 2012-08-18 05:51 - 0004028 _____ () C:\Users\Dad\AppData\Local\HWVendorDetection.log
2013-01-10 08:07 - 2013-01-10 08:07 - 0000866 _____ () C:\Users\Dad\AppData\Local\recently-used.xbel
2012-07-16 06:22 - 2014-01-11 09:02 - 0007629 _____ () C:\Users\Dad\AppData\Local\Resmon.ResmonCfg
2012-03-29 12:09 - 2012-03-29 12:09 - 0017408 _____ () C:\Users\Dad\AppData\Local\WebpageIcons.db
2013-04-11 00:27 - 2013-04-11 00:27 - 0000000 _____ () C:\ProgramData\2a3b3a3028372a59_c
2012-11-19 02:10 - 2012-11-19 02:10 - 0000105 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
Some content of TEMP:
====================
C:\Users\Dad\AppData\Local\Temp\SpOrder.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-16 09:14
==================== End Of Log ============================