Jump to content

auntiem

Members
  • Content Count

    154
  • Joined

  • Last visited

About auntiem

  • Rank
    Member
  • Birthday April 6

Contact Methods

  • Website URL
    http://
  • ICQ
    0

Profile Information

  • Gender
    Female

Previous Fields

  • TechExpress Link:
    http://www.pcpitstop.com/techexpress.asp?id=K4JLMWV6QLMSTCLU
  • Teams:
    Nothing Selected
  1. Satchfan Sorry it took me longer to response, lost the password to pcpitstop, and had to get a new one. Below is what you asked for: Quarantined these:PUP.Optional.InstallCore, C:\Users\Evelyn\Downloads\Gimpshop(1).exe, , [abed181f3960e84ebda33b140bf64ab6], PUP.Optional.InstallCore, C:\Users\Evelyn\Downloads\Gimpshop.exe, , [42560f289ffa1521362ab39cef12ed13], Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 1/9/2016 Scan Time: 2:21 PM Logfile: threats.txt Administrator: Yes Version: 2.2.0.1024 Malware Database: v2016.01.09.04 Rootkit Database: v2016.01.09.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 10 CPU: x64 File System: NTFS User: Evelyn Scan Type: Threat Scan Result: Completed Objects Scanned: 339006 Time Elapsed: 12 min, 20 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 2 PUP.Optional.InstallCore, C:\Users\Evelyn\Downloads\Gimpshop(1).exe, , [abed181f3960e84ebda33b140bf64ab6], PUP.Optional.InstallCore, C:\Users\Evelyn\Downloads\Gimpshop.exe, , [42560f289ffa1521362ab39cef12ed13], Physical Sectors: 0 (No malicious items detected) (end)
  2. thanks for the help, computer is working great. Have a good evening.
  3. Sorry it took longer, Zoek deleted my Dashlane password manger and I had to reinstall it. Fix result of Farbar Recovery Scan Tool (x64) Version:31-12-2015 Ran by Evelyn (2016-01-02 20:59:49) Run:1 Running from C:\Users\Evelyn\Desktop Loaded Profiles: Evelyn (Available Profiles: Evelyn) Boot Mode: Normal ============================================== fixlist content: ***************** ShortcutWithArgument: C:\Users\Evelyn\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Wow HomePage.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://us.wow.com/?ncid=txtlnkusaolc00000290&s_pt=source9&s_chn=100&s_chn2=zytDyE0C0EyDtB0ByCyEtB0BtB0EzzyC2RtBtDtCyDtCtBtCyBtBtByEzytAtBtBzyyD EmptyTemp: ***************** C:\Users\Evelyn\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Wow HomePage.lnk => Shortcut argument removed successfully. EmptyTemp: => 384.1 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 21:01:00 ==== Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Evelyn on Sat 01/02/2016 at 22:12:08.43. Microsoft Windows 10 Home 10.0.10586 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Evelyn\Desktop\zoek.exe [scan all users] [script inserted] ==== Older Logs ====================== C:\zoek-results2016-01-03-030112.log 560 bytes ==== System Restore Info ====================== 1/2/2016 10:14:07 PM Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~3\Comms deleted successfully C:\Users\Evelyn\AppData\Local\ActiveSync deleted successfully C:\Users\Evelyn\AppData\Local\NetworkTiles deleted successfully C:\Users\Evelyn\AppData\Local\Skype deleted successfully C:\Users\Evelyn\AppData\Local\VirtualStore deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Batch Command(s) Run By Tool====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~3\UpdaterLog.txt deleted C:\PROGRA~3\Package Cache deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Users\Evelyn\AppData\Roaming\Mozilla\Firefox\Profiles\awq9scwc.default\jetpack deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\Dashlane.exe" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\DashlanePlugin.exe" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWApplication.3.6.0.97092.dll" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWData.3.6.0.97092.dll" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebug.3.6.0.97092.dll" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebugDll_win32.3.6.0.97092.dll" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWExternLib.3.6.0.97092.dll" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Kwift_DP.3.6.0.97092.dll" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib.3.6.0.97092.dll" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLibData.3.6.0.97092.dll" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib_win.3.6.0.97092.dll" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWUtils.3.6.0.97092.dll" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}" deleted "C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components" deleted ==== Firefox Extensions ====================== ProfilePath: C:\Users\Evelyn\AppData\Roaming\Mozilla\Firefox\Profiles\awq9scwc.default - Dashlane - %ProfilePath%\extensions\jetpack-extension@dashlane.com.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\Evelyn\AppData\Roaming\Mozilla\Firefox\Profiles\awq9scwc.default 70858ED7836E5C849D33576A84DC8CCF - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll - Shockwave Flash 74CC642C7448B3EC4F925E8D76ADD2E7 - C:\Users\Evelyn\AppData\Roaming\PCPitstop\PC Matic Plugin\1.0.0.1\npPCMaticPlugin.1.0.0.1.dll - PC Matic Plugin ==== Chromium Look ====================== Dashlane - Evelyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3674350177-2331041835-1869989430-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{42D79B50-CC4A-4A8E-860F-BE674AF053A2} deleted successfully HKEY_USERS\S-1-5-21-3674350177-2331041835-1869989430-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{42D79B50-CC4A-4A8E-860F-BE674AF053A2} deleted successfully HKEY_USERS\S-1-5-21-3674350177-2331041835-1869989430-1000\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5B236E3E-80B2-4322-B6A2-529D751B7FB1} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{42D79B50-CC4A-4A8E-860F-BE674AF053A2} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42D79B50-CC4A-4A8E-860F-BE674AF053A2} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86391634-A94B-4355-8397-3D85C2F942DA} deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\43619368B49A55343879D3582C9F24AD deleted successfully ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Evelyn\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Evelyn\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Evelyn\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Evelyn\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Evelyn\AppData\Local\Mozilla\Firefox\Profiles\awq9scwc.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=4781 folders=494 315816044 bytes) ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Evelyn\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on Sat 01/02/2016 at 22:54:50.90 ======================
  4. Sorry ....but...I did too Clarify ok you want me to run Run Farbar Recovery Scan Tool again right? and open notepad ( how do I do this?) and copy and paste what you put in it. save the files as fixlist.txt ( is this from the Farbar recovery Scan tool? Sorry...I'm sure you explained it right, but I'm a blond...lol
  5. Satchfan, Thank you for your fast response, and for your help. Below is the Frst.txt and Addition.txt you asked for. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:31-12-2015 Ran by Evelyn (administrator) on EVELYN-PC (31-12-2015 14:47:58) Running from C:\Users\Evelyn\Desktop Loaded Profiles: Evelyn (Available Profiles: Evelyn) Platform: Windows 10 Home Version 1511 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Edge) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Emsisoft Ltd) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe ( ) C:\Windows\System32\lxeccoms.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecmon.exe () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\ezprint.exe (Emsisoft Ltd) C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe () C:\Users\Evelyn\AppData\Roaming\Dashlane\Dashlane.exe () C:\Users\Evelyn\AppData\Roaming\Dashlane\DashlanePlugin.exe (Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6525.42271.0_x64__8wekyb3d8bbwe\HxMail.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6525.42271.0_x64__8wekyb3d8bbwe\HxTsr.exe () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1512.54020.0_x64__8wekyb3d8bbwe\Calculator.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6525.42271.0_x64__8wekyb3d8bbwe\HxCalendarAppImm.exe (Microsoft Corporation) C:\Windows\System32\PickerHost.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [synTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1808168 2009-06-18] (Synaptics Incorporated) HKLM\...\Run: [lxecmon.exe] => C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecmon.exe [772712 2013-01-23] () HKLM\...\Run: [EzPrint] => C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\ezprint.exe [150264 2013-01-23] () HKLM\...\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft anti-malware\a2guard.exe [9135984 2015-11-24] (Emsisoft Ltd) HKLM-x32\...\Run: [PowerDVD15Agent] => C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe [950296 2015-03-19] (CyberLink Corp.) HKLM-x32\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4377256 2015-09-04] (Fitbit, Inc.) HKU\S-1-5-21-3674350177-2331041835-1869989430-1000\...\Run: [Dashlane] => C:\Users\Evelyn\AppData\Roaming\Dashlane\Dashlane.exe [227712 2015-12-07] () HKU\S-1-5-21-3674350177-2331041835-1869989430-1000\...\Run: [DashlanePlugin] => C:\Users\Evelyn\AppData\Roaming\Dashlane\DashlanePlugin.exe [285568 2015-12-07] () HKU\S-1-5-21-3674350177-2331041835-1869989430-1000\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4377256 2015-09-04] (Fitbit, Inc.) HKU\S-1-5-21-3674350177-2331041835-1869989430-1000\...\Run: [skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50385536 2015-12-17] (Skype Technologies S.A.) HKU\S-1-5-21-3674350177-2331041835-1869989430-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8590760 2015-12-08] (Piriform Ltd) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{287b51e9-cadb-44ff-afc0-7846e0875a27}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation) BHO-x32: Dashlane BHO -> {42D79B50-CC4A-4A8E-860F-BE674AF053A2} -> C:\Users\Evelyn\AppData\Roaming\Dashlane\ie\Dashlanei.dll [2015-12-07] (Dashlane) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Evelyn\AppData\Roaming\Mozilla\Firefox\Profiles\awq9scwc.default FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2015-12-28] () FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-28] () FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.) FF Extension: Dashlane - C:\Users\Evelyn\AppData\Roaming\Mozilla\Firefox\Profiles\awq9scwc.default\Extensions\jetpack-extension@dashlane.com.xpi [2015-12-23] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08] [not signed] Chrome: ======= CHR Profile: C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-10] CHR Extension: (Google Docs) - C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-10] CHR Extension: (Google Drive) - C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-24] CHR Extension: (YouTube) - C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-10] CHR Extension: (Google Search) - C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-24] CHR Extension: (Dashlane) - C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2015-11-30] CHR Extension: (Google Sheets) - C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-10] CHR Extension: (Google Docs Offline) - C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-24] CHR Extension: (Chrome Web Store Payments) - C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-10] CHR Extension: (Gmail) - C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-10] Additional scan result of Farbar Recovery Scan Tool (x64) Version:31-12-2015 Ran by Evelyn (2015-12-31 14:58:14) Running from C:\Users\Evelyn\Desktop Windows 10 Home (X64) (2015-11-30 15:48:35) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3674350177-2331041835-1869989430-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3674350177-2331041835-1869989430-503 - Limited - Disabled) Evelyn (S-1-5-21-3674350177-2331041835-1869989430-1000 - Administrator - Enabled) => C:\Users\Evelyn Guest (S-1-5-21-3674350177-2331041835-1869989430-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3674350177-2331041835-1869989430-1002 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Emsisoft Anti-Malware (Enabled - Up to date) {2F44E1F9-850B-1C7A-0E56-EB2E0A3E20C9} AS: Emsisoft Anti-Malware (Enabled - Up to date) {9425001D-A331-13F4-34E6-D05C71B96A74} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated) Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated) CCleaner (HKLM\...\CCleaner) (Version: 5.13 - Piriform) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.98.60.50 - Conexant) CyberLink PowerDVD 15 (HKLM-x32\...\{DE85B8F3-D088-4D6E-A970-EE0BC7883A66}) (Version: 15.0.1510.58 - CyberLink Corp.) Dashlane (HKU\S-1-5-21-3674350177-2331041835-1869989430-1000\...\Dashlane) (Version: 3.6.0.97092 - Dashlane SAS) Emsisoft Anti-Malware (HKLM-x32\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 10.0 - Emsisoft Ltd.) Fitbit Connect (HKLM-x32\...\{9EC69368-C1C7-48BA-AD93-01EFC142DDF9}) (Version: 2.0.0.6630 - Fitbit Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.106 - Google Inc.) Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDA_HSF) (Version: 7.80.4.50 - Conexant Systems) Lexmark Pro800-Pro900 Series (HKLM\...\Lexmark Pro800-Pro900 Series) (Version: - Lexmark International, Inc.) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Mozilla Firefox 43.0.3 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 43.0.3 (x86 en-US)) (Version: 43.0.3 - Mozilla) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation) Skype™ 7.17 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.17.105 - Skype Technologies S.A.) SP45990 - Wallpaper Picture Position Enabler for Windows 7 (HKLM-x32\...\{86391634-A94B-4355-8397-3D85C2F942DA}) (Version: 1.0.0 - Hewlett-Packard International Pte. Ltd.) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1200 - SUPERAntiSpyware.com) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 13.2.2.0 - Synaptics Incorporated) VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3674350177-2331041835-1869989430-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Evelyn\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {090E4D9B-253C-4965-A043-AC0118017010} - System32\Tasks\{2D570583-D660-4817-BDFA-70DE626ED63B} => pcalua.exe -a E:\Setup.EXE -d E:\ Task: {0CFE2E40-6A97-48C5-9F38-DE82315CF1B0} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto Task: {1B5526DA-80F0-43D2-B94D-A44A459EED86} - System32\Tasks\SUPERAntiSpyware Scheduled Task fa65f2c0-ca47-49e0-8d22-e8b6af1bf0bb => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {214EC0DC-0593-468F-8BC7-2FDEEB3A0375} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-12-12] (Microsoft Corporation) Task: {220216E8-0DEF-401D-89E7-DFF28AD66052} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-10] (Google Inc.) Task: {4CF27C25-8BD9-4700-8EBC-F9C283434AEC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-12-08] (Piriform Ltd) Task: {9AB93F75-003E-460C-A8F0-B8695A0AA363} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-28] (Adobe Systems Incorporated) Task: {B0EA4761-CFFB-40A5-A5CE-CDBF7176C02C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated) Task: {B8D46003-B3E0-462C-B7BC-2E041A1CC8FB} - System32\Tasks\SUPERAntiSpyware Scheduled Task ba58ffec-463c-4c22-b12f-576ce6148278 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {C7F9F01E-B835-4525-AA21-ED65D727E9FD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-10] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task ba58ffec-463c-4c22-b12f-576ce6148278.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task fa65f2c0-ca47-49e0-8d22-e8b6af1bf0bb.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Evelyn\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Wow HomePage.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://us.wow.com/?ncid=txtlnkusaolc00000290&s_pt=source9&s_chn=100&s_chn2=zytDyE0C0EyDtB0ByCyEtB0BtB0EzzyC2RtBtDtCyDtCtBtCyBtBtByEzytAtBtBzyyD ==================== Loaded Modules (Whitelisted) ============== 2015-07-29 22:30 - 2009-11-04 12:18 - 00189440 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\lxecdrpp.dll 2015-10-30 02:18 - 2015-10-30 02:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-12-02 23:21 - 2015-11-22 05:47 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2015-12-02 23:21 - 2015-11-22 05:47 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-12-27 16:20 - 2015-12-06 22:33 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-12-27 16:19 - 2015-12-06 23:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2015-12-27 16:19 - 2015-12-06 23:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2015-12-27 16:19 - 2015-12-06 23:00 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll 2015-12-27 16:20 - 2015-12-06 22:37 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2015-12-27 16:20 - 2015-12-06 22:34 - 00936448 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2015-12-27 16:20 - 2015-12-06 22:34 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2015-12-27 16:20 - 2015-12-06 22:36 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-07-29 22:28 - 2013-01-23 12:35 - 00772712 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecmon.exe 2015-07-29 22:28 - 2013-01-23 12:35 - 00150264 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\ezprint.exe 2015-07-30 01:38 - 2015-12-07 04:30 - 00227712 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\Dashlane.exe 2015-07-30 01:38 - 2015-12-07 04:30 - 00285568 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\DashlanePlugin.exe 2015-12-16 23:59 - 2015-12-17 00:02 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-12-10 11:13 - 2015-12-10 11:17 - 00012800 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2015-12-10 11:13 - 2015-12-10 11:17 - 11542016 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2015-11-20 11:43 - 2015-11-20 11:44 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2015-12-29 16:59 - 2015-12-29 17:00 - 03682816 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1512.54020.0_x64__8wekyb3d8bbwe\Calculator.exe 2015-07-29 22:28 - 2010-04-01 11:23 - 00389120 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecscw.dll 2015-07-29 22:28 - 2009-05-27 06:16 - 00192512 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecdatr.dll 2015-07-29 22:28 - 2010-04-01 11:24 - 01159168 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecDRS.dll 2015-07-29 22:28 - 2009-03-09 23:43 - 00155648 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxeccaps.dll 2015-07-29 22:28 - 2010-04-05 04:56 - 00716954 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Epwizard.DLL 2015-07-29 22:28 - 2010-04-05 04:55 - 00159890 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\customui.dll 2015-07-29 22:28 - 2010-04-05 04:54 - 00123033 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Eputil.DLL 2015-07-29 22:28 - 2010-04-05 04:55 - 00061604 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Epfunct.DLL 2015-07-29 22:28 - 2010-04-05 04:54 - 00143502 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Imagutil.DLL 2015-07-29 22:28 - 2010-04-05 04:56 - 02203803 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\EPWizRes.dll 2015-07-29 22:28 - 2010-04-05 04:56 - 00045221 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\epstring.dll 2015-07-29 22:28 - 2010-04-05 04:56 - 00094359 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\EPOEMDll.dll 2015-07-29 22:28 - 2009-04-07 13:25 - 00409600 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\iptk.dll 2015-07-29 22:28 - 2009-03-02 08:25 - 00151552 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecptp.dll 2015-12-07 04:29 - 2015-12-07 04:29 - 00343424 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebugDll_win32.3.6.0.97092.dll 2015-12-07 04:29 - 2015-12-07 04:29 - 00423296 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebug.3.6.0.97092.dll 2015-12-07 04:29 - 2015-12-07 04:29 - 00446336 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWUtils.3.6.0.97092.dll 2015-12-07 04:29 - 2015-12-07 04:29 - 31325056 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWExternLib.3.6.0.97092.dll 2015-12-07 04:29 - 2015-12-07 04:29 - 00276352 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib_win.3.6.0.97092.dll 2015-12-07 04:29 - 2015-12-07 04:29 - 05866880 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWData.3.6.0.97092.dll 2015-12-07 04:29 - 2015-12-07 04:29 - 06901120 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWApplication.3.6.0.97092.dll 2015-12-07 04:29 - 2015-12-07 04:29 - 13324160 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib.3.6.0.97092.dll 2015-12-07 04:29 - 2015-12-07 04:29 - 02136448 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLibData.3.6.0.97092.dll 2015-12-07 04:29 - 2015-12-07 04:29 - 00338304 _____ () C:\Users\Evelyn\AppData\Roaming\Dashlane\3.6.0.97092\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Kwift_DP.3.6.0.97092.dll 2014-12-11 16:40 - 2014-12-11 16:40 - 40622592 ____R () C:\Program Files (x86)\Fitbit Connect\libcef.dll 2015-12-05 10:21 - 2015-12-05 10:21 - 00933056 ____R () C:\Program Files (x86)\Skype\Phone\ssScreenVVS2.dll 2015-12-16 23:59 - 2015-12-17 00:02 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2015-12-16 23:59 - 2015-12-17 00:02 - 21845504 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkyWrap.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-29 22:29 - 2015-07-29 22:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3674350177-2331041835-1869989430-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Evelyn\Downloads\2015 Church picture of Fran Allie and Bella.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [TCP Query User{FC91B2DA-48D7-4F07-AE65-46A8F4B97D74}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [uDP Query User{3CA48A04-CD47-4FD7-9B9F-EE3270F1E63F}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{4EA47832-ECCA-4647-8B9F-027D818BCAC7}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [uDP Query User{3AE97769-E8FE-4096-A9EE-49365307BDE3}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{FFD5425B-D58B-42CF-9AE2-FF33BA9EA50F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{5A36FF4F-1352-4601-9C26-5DC030F4DE2D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{3E5E66AF-8B17-4721-8A56-37B862C2E6AD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Restore Points ========================= 12-12-2015 20:57:34 Windows Update 23-12-2015 17:41:24 Scheduled Checkpoint 28-12-2015 14:20:17 Windows Update 29-12-2015 21:40:10 Revo Uninstaller's restore point - Mozilla Firefox 43.0.1 (x86 en-US) 30-12-2015 23:43:14 JRT Pre-Junkware Removal 30-12-2015 23:51:32 JRT Pre-Junkware Removal ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/31/2015 02:38:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: EVELYN-PC) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (12/31/2015 12:14:53 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (12/31/2015 12:49:24 AM) (Source: ESENT) (EventID: 455) (User: ) Description: CCleaner64 (1168) testing: Error -1032 (0xfffffbf8) occurred while opening logfile C:\Users\Evelyn\AppData\Local\Microsoft\Windows\WebCache\V01.log. Error: (12/31/2015 12:49:24 AM) (Source: ESENT) (EventID: 490) (User: ) Description: CCleaner64 (1168) testing: An attempt to open the file "C:\Users\Evelyn\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8). Error: (12/30/2015 11:51:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (12/30/2015 11:43:31 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (12/30/2015 10:26:39 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: EVELYN-PC) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (12/30/2015 06:05:38 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: EVELYN-PC) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (12/30/2015 05:19:02 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: EVELYN-PC) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (12/30/2015 05:02:36 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: EVELYN-PC) Description: Activation of app Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. System errors: ============= Error: (12/31/2015 01:02:49 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: ) Description: 4 Error: (12/31/2015 12:59:38 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Access_235e3 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/31/2015 12:59:38 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Storage_235e3 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/31/2015 12:59:38 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Contact Data_235e3 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/31/2015 12:59:38 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Sync Host_235e3 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (12/30/2015 11:30:52 PM) (Source: DCOM) (EventID: 10016) (User: EVELYN-PC) Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Evelyn-PCEvelynS-1-5-21-3674350177-2331041835-1869989430-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (12/30/2015 11:30:52 PM) (Source: DCOM) (EventID: 10016) (User: EVELYN-PC) Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Evelyn-PCEvelynS-1-5-21-3674350177-2331041835-1869989430-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (12/30/2015 11:30:48 PM) (Source: DCOM) (EventID: 10016) (User: EVELYN-PC) Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Evelyn-PCEvelynS-1-5-21-3674350177-2331041835-1869989430-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (12/30/2015 11:30:45 PM) (Source: DCOM) (EventID: 10016) (User: EVELYN-PC) Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Evelyn-PCEvelynS-1-5-21-3674350177-2331041835-1869989430-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (12/30/2015 11:28:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The lxecCATSCustConnectService service failed to start due to the following error: %%1053 CodeIntegrity: =================================== Date: 2015-12-30 18:06:10.914 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-29 18:22:38.322 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-28 14:35:55.293 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-11 17:07:39.858 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-10 11:03:45.403 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-09 12:04:47.087 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-03 10:34:48.034 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-11-30 21:56:22.849 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-11-30 10:37:25.587 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-11-30 10:34:48.699 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Pentium® Dual-Core CPU T4300 @ 2.10GHz Percentage of memory in use: 68% Total physical RAM: 3003.19 MB Available physical RAM: 956.95 MB Total Virtual: 3707.19 MB Available Virtual: 1098.45 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:453.22 GB) (Free:389.32 GB) NTFS ==>[system with boot components (obtained from drive)] Drive d: (RECOVERY) (Fixed) (Total:11.91 GB) (Free:1.99 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: CBA410DA) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=453.2 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) Partition 4: (Not Active) - (Size=11.9 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================
  6. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.1 (11.24.2015) Operating System: Windows 10 Home x64 Ran by Evelyn (Administrator) on Wed 12/30/2015 at 23:43:10.81 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 0 Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Wed 12/30/2015 at 23:49:02.99 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  7. # AdwCleaner v5.027 - Logfile created 30/12/2015 at 23:26:41 # Updated 30/12/2015 by Xplode # Database : 2015-12-30.1 [server] # Operating system : Windows 10 Home (x64) # Username : Evelyn - EVELYN-PC # Running from : C:\Users\Evelyn\Desktop\AdwCleaner.exe # Option : Cleaning # Support : http://toolslib.net/forum ***** [ Services ] ***** ***** [ Folders ] ***** [-] Folder Deleted : C:\Program Files (x86)\SystemHealer [-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Healer [-] Folder Deleted : C:\Users\Evelyn\AppData\Roaming\System Healer ***** [ Files ] ***** ***** [ DLLs ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled tasks ] ***** ***** [ Registry ] ***** [-] Key Deleted : HKCU\Software\PRODUCTSETUP [-] Key Deleted : HKCU\Software\System Healer [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemHealer [-] Key Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.com/search?q=viewpoint+forum&form=WNSGPH&qs=PA&cvid=4676b37cde024e8381a20fad3150c997&pq=view%20point&sbts=1438813072987&nclid=xbfcJVGAF0MyhhpldpXXFA%3D%3D&ts=1438813072987 [-] Key Deleted : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\powerdvd.en.softonic.com [-] Key Deleted : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\softonic.com [-] Key Deleted : HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\powerdvd.en.softonic.com [-] Key Deleted : HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\softonic.com ***** [ Web browsers ] ***** [-] [C:\Users\Evelyn\AppData\Roaming\Mozilla\Firefox\Profiles\awq9scwc.default\prefs.js] [Preference] Deleted : user_pref("extensions.dashlane.safesearchcapable", false); [-] [C:\Users\Evelyn\AppData\Roaming\Mozilla\Firefox\Profiles\awq9scwc.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "televisionfanatic@mindspark.com"); [-] [C:\Users\Evelyn\AppData\Local\Google\Chrome\User Data\Default\Web Data] [search Provider] Deleted : aol.com ************************* :: "Tracing" keys removed :: Winsock settings cleared ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [2679 bytes] ##########
  8. Thank you caintry_boy for your fast reply. Will do the things you said to do, and thanks again.
  9. I some how got WOW search ( Wow home page) on my computer. How can I tell if I deleted it all from my computer? I read that's it's a browser hijacker. Can someone help please and tell me what to download and see if it's ALL OFF my computer.
  10. Juliet, I Don't want you think I'm not still with you...but... will have to do this later. Have the FLU, and I had the shot. Said good thing, because I have it BAD. So please understand, will do this when I get feeling better.
  11. Do not know if this matters are helps but...when using Internet Explorer and getting the goggle layout. When I go to favorite and click on the ones with the internet explorer emblem the e comes up in the address bar. Don't know if this will help or not, just letting you know. Oh and windows updates works with this . THANK YOU SO MUCH FOR YOUR HELP, and your fast response. Example below when clicking on something in my favorites.
  12. Computer is running ok except for the internet explorer thing. Yes First after doing things you said when going to Internet Explorer it said Internet Explorer stopped working A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available Than after rebooting when clicking on Internet Explorer the Google thing happened. Done what you said: First, click on the 'Start Menu' and type in 'Default Programs'. Hit 'Enter'. Click on 'Set Your Default Programs'. Click on 'Internet Explorer'. Click on 'Set This Program As Default'. Then, select the appropriate extensions and protocols. Hit 'Save'. Below is the scan you asked for: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-01-2014 03 Ran by Owner (administrator) on OWNER-PC on 18-01-2014 12:18:43 Running from C:\Users\Owner\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.117.0\BBSvc.EXE (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe (Lexmark International, Inc.) C:\Windows\System32\spool\drivers\x64\3\lxecserv.exe ( ) C:\Windows\System32\lxeccoms.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe (Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\McciCMService.exe (Alcatel-Lucent) C:\Program Files\Common Files\Motive\McciCMService.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (NETGEAR) C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe (PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (PlumChoice, Inc.) C:\Program Files (x86)\Cox, Inc\Cox PC HealthCheck\PCMonitoringService.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecmon.exe () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\ezprint.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe () C:\Users\Owner\AppData\Roaming\Dashlane\Dashlane.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE () C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (Smilebox, Inc.) C:\Users\Owner\AppData\Roaming\Smilebox\SmileboxTray.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files (x86)\CalendarPal\CalendarPal.exe (PlumChoice, Inc.) C:\Program Files (x86)\Cox, Inc\Cox PC HealthCheck\DesktopClient.exe (PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe () C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (McAfee, Inc.) C:\Program Files\McAfee\MSM\McSmtFwk.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.117.0\SeaPort.EXE (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [lxecmon.exe] - C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecmon.exe [770728 2010-05-17] () HKLM\...\Run: [EzPrint] - C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\ezprint.exe [148280 2010-05-17] () HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [495104 2009-07-13] (Conexant Systems, Inc.) HKLM\...\Run: [inboxAce Home Page Guard 64 bit] - "C:\PROGRA~2\InboxAce_1g\bar\1.bin\AppIntegrator64.exe" HKLM\...\Run: [CouponXplorer Home Page Guard 64 bit] - "C:\PROGRA~2\CouponXplorer_5z\bar\1.bin\AppIntegrator64.exe" HKLM\...\Run: [synTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1234216 2008-03-28] (Synaptics, Inc.) HKLM-x32\...\Run: [Lexmark Pro800-Pro900 Series] - C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\fm3032.exe [316072 2010-05-17] () HKLM-x32\...\Run: [sSDMonitor] - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [105120 2012-08-21] (PC Tools) HKLM-x32\...\Run: [bingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [1858152 2012-03-30] (Microsoft Corp.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2012-02-20] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [537512 2013-09-24] (McAfee, Inc.) HKLM-x32\...\Run: [mcpltui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [537512 2013-09-24] (McAfee, Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.) HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-01-14] (Hewlett-Packard) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKCU\...\Run: [smartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-05-14] () HKCU\...\Run: [Dashlane] - C:\Users\Owner\AppData\Roaming\Dashlane\Dashlane.exe [277688 2014-01-07] () HKCU\...\Run: [sUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563608 2014-01-17] (SUPERAntiSpyware) HKCU\...\Run: [NETGEARGenie] - C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe [1044224 2013-04-07] () HKCU\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [456768 2013-10-18] (BillP Studios) HKCU\...\Run: [smileboxTray] - C:\Users\Owner\AppData\Roaming\Smilebox\SmileboxTray.exe [305448 2013-04-02] (Smilebox, Inc.) HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1099608 2013-03-12] (Garmin Ltd or its subsidiaries) HKCU\...\Run: [CalendarPal] - C:\Program Files (x86)\CalendarPal\CalendarPal.exe [1122304 2008-05-21] () HKCU\...\Policies\Explorer: [NoInstrumentation] 1 MountPoints2: E - E:\LaunchU3.exe -a MountPoints2: {74b9d064-e4df-11e1-871c-00262db0d1c4} - "E:\WD SmartWare.exe" autoplay=true MountPoints2: {a576b1c3-f87d-11e2-beb4-00262db0d1c4} - E:\iStudio.exe Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Cox PC HealthCheck.lnk ShortcutTarget: Cox PC HealthCheck.lnk -> C:\Program Files (x86)\Cox, Inc\Cox PC HealthCheck\DesktopClient.exe (PlumChoice, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xD0A9EC8DF340CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank URLSearchHook: HKCU - (No Name) - {cce665dd-f6dd-4808-968e-eaec971f70ef} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {405EF553-8129-4121-95A8-5DA2F4921E10} URL = http://bing.quebles.com/?r=2&q={searchTerms}&pw={startPage?} SearchScopes: HKCU - {94B299CF-33F6-47E5-B706-DDD162C18E23} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Speckie - {8CE7F568-67FA-4432-BA39-F5AFD68E7B8B} - C:\Users\Owner\AppData\Roaming\Speckie\bin64\Speckie64.dll (Versoworks Pty Ltd) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.117.0\amd64\BingExt.dll (Microsoft Corporation.) BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll () BHO-x32: Dashlane BHO - {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Owner\AppData\Roaming\Dashlane\ie\Dashlanei.dll (Dashlane) BHO-x32: Speckie - {8CE7F568-67FA-4432-BA39-F5AFD68E7B8B} - C:\Users\Owner\AppData\Roaming\Speckie\bin32\Speckie32.dll (Versoworks Pty Ltd) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll () BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.117.0\BingExt.dll (Microsoft Corporation.) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.117.0\amd64\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll () Toolbar: HKLM-x32 - Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Owner\AppData\Roaming\Dashlane\ie\KWIEBar.dll (Dashlane) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.117.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKCU - No Name - {CCE665DD-F6DD-4808-968E-EAEC971F70EF} - No File Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\9cht6u4l.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.11.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\npmcsnffpl64.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @CouponXplorer_5z.com/Plugin - C:\Program Files (x86)\CouponXplorer_5z\bar\1.bin\NP5zStub.dll No File FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @InboxAce_1g.com/Plugin - C:\Program Files (x86)\InboxAce_1g\bar\1.bin\NP1gStub.dll No File FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\npmcsnffpl.dll () FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @Motive.com/NpMotive,version=1.0 - C:\Program Files (x86)\Motive\npMotive.dll (Alcatel-Lucent) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: CouponXplorer - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\9cht6u4l.default\Extensions\5zffxtbr@CouponXplorer_5z.com [2013-12-14] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-20] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-20] FF HKLM-x32\...\Firefox\Extensions: [5zffxtbr@CouponXplorer_5z.com] - C:\Program Files (x86)\CouponXplorer_5z\bar\1.bin FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2013-10-14] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2013-10-14] Chrome: ======= CHR HomePage: CHR Extension: (SiteAdvisor) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-10-28] CHR Extension: (Skype Click to Call) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-07-11] CHR Extension: (Google Wallet) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-05] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09] ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com) R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [151656 2012-03-30] (Microsoft Corp.) R2 COX CommunicationsMonitoringService; C:\Program Files (x86)\Cox, Inc\Cox PC HealthCheck\PCMonitoringService.exe [15104 2012-10-31] (PlumChoice, Inc.) R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [185688 2013-03-12] (Garmin Ltd or its subsidiaries) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 lxecCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\lxecserv.exe [45736 2010-04-14] (Lexmark International, Inc.) R2 lxec_device; C:\Windows\system32\lxeccoms.exe [1052328 2010-04-14] ( ) R2 lxec_device; C:\Windows\SysWOW64\lxeccoms.exe [598696 2010-04-14] ( ) R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [121616 2013-10-02] (McAfee, Inc.) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178048 2013-09-24] (McAfee, Inc.) R2 McciCMService64; C:\Program Files\Common Files\Motive\McciCMService.exe [517632 2010-06-23] (Alcatel-Lucent) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1017016 2013-09-20] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-11-04] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-11-04] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-06-20] (Microsoft Corporation) R2 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [232192 2013-04-07] (NETGEAR) R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [794272 2012-08-21] (PC Tools) R2 Spooler; C:\Windows\SysWOW64\spoolsv.exe [0 2013-08-07] () S2 CouponXplorer_5zService; C:\PROGRA~2\CouponXplorer_5z\bar\1.bin\5zbarsvc.exe [x] ==================== Drivers (Whitelisted) ==================== R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-11-04] (McAfee, Inc.) S3 FlyUsb; C:\Windows\System32\DRIVERS\FlyUsb.sys [24576 2007-06-19] (LeapFrog) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179792 2013-11-04] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311120 2013-11-04] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519576 2013-11-04] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [782360 2013-11-04] (McAfee, Inc.) R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [390552 2013-09-20] (McAfee, Inc.) S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [95984 2013-09-20] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343696 2013-11-04] (McAfee, Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation) S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2010-06-23] (Printing Communications Assoc., Inc. (PCAUSA)) S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2010-06-23] (Printing Communications Assoc., Inc. (PCAUSA)) R2 NPF; C:\Windows\system32\drivers\npf.sys [35344 2013-09-16] (CACE Technologies, Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Brother Industries Ltd.) S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x] S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x] S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x] S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-18 12:18 - 2014-01-18 12:19 - 00022661 _____ C:\Users\Owner\Desktop\FRST.txt 2014-01-18 12:18 - 2014-01-18 12:18 - 00000000 ____D C:\FRST 2014-01-18 12:15 - 2014-01-18 12:15 - 02076160 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe 2014-01-18 00:55 - 2014-01-18 00:55 - 00000346 _____ C:\Windows\PFRO.log 2014-01-18 00:31 - 2014-01-18 00:31 - 01037068 _____ (Thisisu) C:\Users\Owner\Downloads\JRT(2).exe 2014-01-18 00:19 - 2014-01-18 00:19 - 00000000 ____D C:\Windows\ERUNT 2014-01-18 00:18 - 2014-01-18 00:18 - 01037068 _____ (Thisisu) C:\Users\Owner\Downloads\JRT(1).exe 2014-01-18 00:14 - 2014-01-18 00:15 - 01037068 _____ (Thisisu) C:\Users\Owner\Downloads\JRT.exe 2014-01-17 23:57 - 2014-01-18 00:03 - 00000000 ____D C:\AdwCleaner 2014-01-17 21:26 - 2014-01-17 21:26 - 00065232 _____ C:\Users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-17 21:25 - 2014-01-17 21:25 - 00000000 _____ C:\Windows\setuperr.log 2014-01-17 21:24 - 2014-01-18 12:00 - 00000280 _____ C:\Windows\setupact.log 2014-01-17 21:24 - 2014-01-17 21:25 - 00693576 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-17 19:12 - 2014-01-17 19:12 - 00015057 _____ C:\Users\Owner\Desktop\hijackthis.log 2014-01-17 15:51 - 2014-01-17 19:12 - 00000000 ____D C:\Users\Owner\Downloads\HJT 2014-01-17 15:30 - 2014-01-17 15:30 - 00000000 ____D C:\HJT 2014-01-17 12:35 - 2014-01-17 13:16 - 00000000 ____D C:\Windows\pss 2014-01-17 12:29 - 2014-01-17 12:43 - 00000332 _____ C:\Windows\Tasks\HPCeeScheduleForOwner.job 2014-01-17 12:29 - 2014-01-17 12:29 - 00003186 _____ C:\Windows\System32\Tasks\HPCeeScheduleForOwner 2014-01-17 11:25 - 2014-01-17 11:27 - 00000000 ____D C:\391679d514eaa995715c 2014-01-17 10:00 - 2013-11-26 20:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-17 10:00 - 2013-11-26 20:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-17 10:00 - 2013-11-26 06:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-17 09:59 - 2013-11-26 20:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-17 09:59 - 2013-11-26 20:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-17 09:59 - 2013-11-26 20:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-17 09:59 - 2013-11-26 20:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-17 09:59 - 2013-11-26 20:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-17 09:59 - 2013-11-26 05:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-09 22:11 - 2014-01-09 22:11 - 00032098 _____ C:\Users\Owner\Documents\cc_20140109_221136.reg 2014-01-09 18:22 - 2014-01-09 18:22 - 00000000 ____D C:\SUPERDelete 2013-12-23 16:25 - 2013-12-23 16:25 - 11171960 _____ (LeapFrog Enterprises, Inc.) C:\Users\Owner\Downloads\LeapFrogConnectSetup_Tag.exe 2013-12-23 16:25 - 2013-12-23 16:25 - 00000000 ____D C:\Windows\35B15182D1344F4182BB59B83F596487.TMP 2013-12-23 16:15 - 2013-12-23 16:15 - 11171960 _____ (LeapFrog Enterprises, Inc.) C:\Users\Owner\Downloads\LeapFrogConnectSetup_LeapReader.exe 2013-12-23 16:15 - 2013-12-23 16:15 - 00000950 _____ C:\Users\Public\Desktop\LeapFrog Connect.lnk 2013-12-23 16:14 - 2013-12-23 16:14 - 00000000 ____D C:\Program Files\DIFX 2013-12-23 16:13 - 2013-12-23 16:14 - 00000000 ____D C:\Program Files (x86)\LeapFrog 2013-12-23 16:13 - 2013-12-23 16:13 - 00000000 ____D C:\ProgramData\Leapfrog 2013-12-23 16:12 - 2013-12-23 16:12 - 11171960 _____ (LeapFrog Enterprises, Inc.) C:\Users\Owner\Downloads\LeapFrogConnectSetup_LeapsterExplorer.exe 2013-12-20 20:46 - 2013-12-20 20:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-01-18 12:19 - 2014-01-18 12:18 - 00022661 _____ C:\Users\Owner\Desktop\FRST.txt 2014-01-18 12:18 - 2014-01-18 12:18 - 00000000 ____D C:\FRST 2014-01-18 12:16 - 2012-07-28 21:26 - 00000896 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-18 12:15 - 2014-01-18 12:15 - 02076160 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe 2014-01-18 12:11 - 2009-07-13 23:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-18 12:11 - 2009-07-13 23:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-18 12:06 - 2013-10-14 17:22 - 00001846 _____ C:\Users\Public\Desktop\McAfee Security Center.lnk 2014-01-18 12:05 - 2012-02-09 18:52 - 02074495 _____ C:\Windows\WindowsUpdate.log 2014-01-18 12:01 - 2012-02-14 19:23 - 00229201 ____H C:\ProgramData\lxecscan.log 2014-01-18 12:00 - 2014-01-17 21:24 - 00000280 _____ C:\Windows\setupact.log 2014-01-18 12:00 - 2012-11-08 22:33 - 00000302 _____ C:\Windows\Tasks\RMAutoUpdate.job 2014-01-18 12:00 - 2012-07-28 21:26 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-18 12:00 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-18 02:00 - 2013-07-10 16:11 - 00000510 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 0fede45e-e614-4edb-96db-b5cfa8057305.job 2014-01-18 01:21 - 2012-07-01 09:29 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-18 01:11 - 2013-07-10 16:11 - 00000510 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task b0dc51e7-0fb1-41e1-a40c-98b52b0ce4e3.job 2014-01-18 00:55 - 2014-01-18 00:55 - 00000346 _____ C:\Windows\PFRO.log 2014-01-18 00:31 - 2014-01-18 00:31 - 01037068 _____ (Thisisu) C:\Users\Owner\Downloads\JRT(2).exe 2014-01-18 00:19 - 2014-01-18 00:19 - 00000000 ____D C:\Windows\ERUNT 2014-01-18 00:18 - 2014-01-18 00:18 - 01037068 _____ (Thisisu) C:\Users\Owner\Downloads\JRT(1).exe 2014-01-18 00:15 - 2014-01-18 00:14 - 01037068 _____ (Thisisu) C:\Users\Owner\Downloads\JRT.exe 2014-01-18 00:03 - 2014-01-17 23:57 - 00000000 ____D C:\AdwCleaner 2014-01-17 21:26 - 2014-01-17 21:26 - 00065232 _____ C:\Users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-17 21:25 - 2014-01-17 21:25 - 00000000 _____ C:\Windows\setuperr.log 2014-01-17 21:25 - 2014-01-17 21:24 - 00693576 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-17 19:12 - 2014-01-17 19:12 - 00015057 _____ C:\Users\Owner\Desktop\hijackthis.log 2014-01-17 19:12 - 2014-01-17 15:51 - 00000000 ____D C:\Users\Owner\Downloads\HJT 2014-01-17 19:00 - 2012-03-15 18:00 - 00000432 _____ C:\Windows\SysWOW64\AppLog.log 2014-01-17 18:55 - 2012-08-27 16:01 - 00533504 ___SH C:\Users\Owner\Downloads\Thumbs.db 2014-01-17 15:30 - 2014-01-17 15:30 - 00000000 ____D C:\HJT 2014-01-17 13:16 - 2014-01-17 12:35 - 00000000 ____D C:\Windows\pss 2014-01-17 12:43 - 2014-01-17 12:29 - 00000332 _____ C:\Windows\Tasks\HPCeeScheduleForOwner.job 2014-01-17 12:29 - 2014-01-17 12:29 - 00003186 _____ C:\Windows\System32\Tasks\HPCeeScheduleForOwner 2014-01-17 12:26 - 2012-02-14 21:46 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log 2014-01-17 12:25 - 2012-02-16 17:13 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-01-17 11:27 - 2014-01-17 11:25 - 00000000 ____D C:\391679d514eaa995715c 2014-01-17 11:27 - 2013-08-08 21:49 - 00000000 ____D C:\Windows\system32\MRT 2014-01-17 11:25 - 2012-02-09 19:07 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-17 09:50 - 2013-07-10 16:10 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2014-01-17 09:48 - 2009-07-14 00:08 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-09 22:11 - 2014-01-09 22:11 - 00032098 _____ C:\Users\Owner\Documents\cc_20140109_221136.reg 2014-01-09 19:53 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache 2014-01-09 18:22 - 2014-01-09 18:22 - 00000000 ____D C:\SUPERDelete 2014-01-09 18:12 - 2012-11-17 14:27 - 00002028 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2014-01-09 14:25 - 2013-04-05 12:09 - 00001915 _____ C:\Users\Owner\Desktop\Dashlane.lnk 2014-01-09 14:25 - 2013-04-05 12:09 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Dashlane 2014-01-08 13:25 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-23 16:28 - 2009-07-14 00:13 - 00783400 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-23 16:25 - 2013-12-23 16:25 - 11171960 _____ (LeapFrog Enterprises, Inc.) C:\Users\Owner\Downloads\LeapFrogConnectSetup_Tag.exe 2013-12-23 16:25 - 2013-12-23 16:25 - 00000000 ____D C:\Windows\35B15182D1344F4182BB59B83F596487.TMP 2013-12-23 16:15 - 2013-12-23 16:15 - 11171960 _____ (LeapFrog Enterprises, Inc.) C:\Users\Owner\Downloads\LeapFrogConnectSetup_LeapReader.exe 2013-12-23 16:15 - 2013-12-23 16:15 - 00000950 _____ C:\Users\Public\Desktop\LeapFrog Connect.lnk 2013-12-23 16:14 - 2013-12-23 16:14 - 00000000 ____D C:\Program Files\DIFX 2013-12-23 16:14 - 2013-12-23 16:13 - 00000000 ____D C:\Program Files (x86)\LeapFrog 2013-12-23 16:13 - 2013-12-23 16:13 - 00000000 ____D C:\ProgramData\Leapfrog 2013-12-23 16:12 - 2013-12-23 16:12 - 11171960 _____ (LeapFrog Enterprises, Inc.) C:\Users\Owner\Downloads\LeapFrogConnectSetup_LeapsterExplorer.exe 2013-12-21 14:39 - 2013-03-23 20:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-20 20:46 - 2013-12-20 20:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-20 11:10 - 2012-10-17 11:28 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Skype Some content of TEMP: ==================== C:\Users\Owner\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-09 19:43 ==================== End Of Log ============================ Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-01-2014 03 Ran by Owner at 2014-01-18 12:19:56 Running from C:\Users\Owner\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AV: Microsoft Security Essentials (Disabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Disabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} ==================== Installed Programs ====================== Adobe AIR (x32 Version: 3.5.0.880 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.5.0.880 - Adobe Systems Incorporated) Hidden Adobe Download Assistant (x32 Version: 1.2.3 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.2.3 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) (x32 Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (x32 Version: 11.6.3.633 - Adobe Systems, Inc.) Apple Application Support (x32 Version: 2.1.7 - Apple Inc.) Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.) Atheros Driver Installation Program (x32 Version: 9.0 - Atheros) Bing Bar (x32 Version: 7.3.117.0 - Microsoft Corporation) Bing Desktop (x32 Version: 1.1.165.0 - Microsoft Corporation) CalendarPal (x32 Version: - Cloudeight Internet LLC) CCleaner (Version: 3.15 - Piriform) Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.) Conexant HD Audio (Version: 4.98.60.50 - Conexant) ConvertHelper 2.2 (x32 Version: - DownloadHelper) Coupon Printer for Windows (x32 Version: 5.0.0.2 - Coupons.com Incorporated) <==== ATTENTION CouponXplorer Firefox Toolbar (x32 Version: - Mindspark Interactive Network) <==== ATTENTION Cox PC HealthCheck (x32 Version: 5.5.19.0 - PlumChoice, Inc) Dashlane (HKCU Version: 2.3.3.52783 - Dashlane SAS) Elevated Installer (x32 Version: 2.1.11 - Garmin Ltd or its subsidiaries) Hidden ESET Online Scanner v3 (x32 Version: - ) Garmin Communicator Plugin x64 (Version: 4.0.3 - Garmin Ltd or its subsidiaries) Garmin Express (x32 Version: 2.1.11 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 2.1.11 - Garmin Ltd or its subsidiaries) Hidden Garmin Update Service (x32 Version: 2.1.11 - Garmin Ltd or its subsidiaries) Hidden Google Chrome (x32 Version: 32.0.1700.76 - Google Inc.) Google Earth (x32 Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP Product Detection (x32 Version: 11.14.0004 - HP) HP Support Assistant (x32 Version: 7.0.39.15 - Hewlett-Packard Company) InboxAce Firefox Toolbar (x32 Version: - Mindspark Interactive Network) Java 7 Update 11 (64-bit) (Version: 7.0.110 - Oracle) LeapFrog Connect (x32 Version: 5.2.4.18506 - LeapFrog) LeapFrog Connect (x32 Version: 5.2.4.18506 - LeapFrog) Hidden LeapFrog LeapReader Plugin (x32 Version: 5.2.4.18512 - LeapFrog) Hidden LeapFrog Leapster Explorer Plugin (x32 Version: 5.2.1.18456 - LeapFrog) Hidden LeapFrog Tag Plugin (x32 Version: 5.1.26.18340 - LeapFrog) Hidden Lexmark Printable Web (x32 Version: 1.0.0.0 - ) Lexmark Pro800-Pro900 Series (Version: - Lexmark International, Inc.) Lexmark Toolbar (x32 Version: 4.3.37.0 - ) McAfee SecurityCenter (x32 Version: 12.8.856 - McAfee, Inc.) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Click-to-Run 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Click-to-Run 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - English (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU Version: 17.0.2003.1112 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox 26.0 (x86 en-US) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MP3 Rocket Download (x32 Version: 2.3.7.8 - ) NETGEAR Genie (x32 Version: 2.2.28.24.exe - NETGEAR Inc.) OpenOffice.org 3.3 (x32 Version: 3.3.9567 - OpenOffice.org) PC Tools Registry Mechanic 11.1 (x32 Version: 11.1 - PC Tools) Picasa 3 (x32 Version: 3.9 - Google, Inc.) QuickTime (x32 Version: 7.72.80.56 - Apple Inc.) Revo Uninstaller 1.95 (x32 Version: 1.95 - VS Revo Group) SAMSUNG Intelli-studio (x32 Version: 3.1.32.1 - Samsung Electronics Co., Ltd.) Shared C Run-time for x64 (Version: 10.0.0 - McAfee) Skype Click to Call (x32 Version: 6.13.13771 - Skype Technologies S.A.) Skype™ 6.10 (x32 Version: 6.10.104 - Skype Technologies S.A.) Speckie (Version: 5.6.0 - Versoworks) SUPERAntiSpyware (Version: 5.6.1020 - SUPERAntiSpyware.com) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (Version: 11.0.7.0 - Synaptics) Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapReader Plugin) (x32 Version: - LeapFrog) Use the entry named LeapFrog Connect to uninstall (LeapFrog Leapster Explorer Plugin) (x32 Version: - LeapFrog) Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin) (x32 Version: 5.1.26.18340 - LeapFrog) VLC media player 1.1.11 (x32 Version: 1.1.11 - VideoLAN) Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0) (Version: 11/05/2008 1.1.1.0 - LeapFrog) Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012) (Version: 09/10/2009 02.03.05.012 - Leapfrog) Windows Live Sync (x32 Version: 14.0.8117.416 - Microsoft Corporation) WinPatrol (Version: 29.0.2013 - BillP Studios) WinZip 17.0 (Version: 17.0.10381 - WinZip Computing, S.L. ) YTD Toolbar v7.0 (x32 Version: 7.0 - Spigot, Inc.) ==================== Restore Points ========================= 02-01-2014 03:44:56 Created by PC Tools Registry Mechanic 04-01-2014 16:30:16 Windows Update 08-01-2014 01:39:37 Windows Update 09-01-2014 23:10:12 Revo Uninstaller's restore point - Iminent 10-01-2014 00:01:25 Created by PC Tools Registry Mechanic 11-01-2014 03:28:36 Windows Update 17-01-2014 14:50:52 Windows Update 17-01-2014 16:25:01 Windows Update 18-01-2014 06:41:12 Windows Update ==================== Hosts content: ========================== 2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0B79F19C-7FEE-41EF-99B2-2C75C2BD5F99} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {0E899488-8578-43D3-B5EF-01F3630263CD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {1329B59F-0FBD-454F-A0FD-8A178EBDF217} - System32\Tasks\RMAutoUpdate => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\SULauncher.exe [2012-08-21] (PC Tools) Task: {1C414F66-77E8-4F6F-A9D1-219CDC751246} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1888085416-2387315268-2958175980-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe Task: {28E616A5-F6FC-425C-B6EC-8A7004A87B3F} - System32\Tasks\SUPERAntiSpyware Scheduled Task b0dc51e7-0fb1-41e1-a40c-98b52b0ce4e3 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-05-23] (SUPERAdBlocker.com) Task: {2FBB1439-28C3-4E3A-9D7B-1DBEA896F965} - System32\Tasks\task1592583 => C:\Users\Owner\AppData\Local\Temp\0.9627837814513025.exe <==== ATTENTION Task: {36A2C498-52AF-469C-8D3C-71BE69645788} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {3CC10157-2A5B-4408-8024-A07071FBB8B8} - System32\Tasks\SpeedyPC Pro => C:\Program Files (x86)\SpeedyPC Software\SpeedyPC\SpeedyPC.exe Task: {4021396E-86FF-4840-9DBB-0F30E4EF6A2D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-28] (Google Inc.) Task: {54DBF6A6-6D6E-455F-9A52-3FEE6972AEDF} - System32\Tasks\{D778E9BB-490E-4D3D-BEB2-06CE36232B6C} => Chrome.exe Task: {5E714059-30E2-40AB-9071-275A63CE7889} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1888085416-2387315268-2958175980-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe Task: {671F478B-4233-4F5C-8B43-3DAC2FD65438} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {7A3F49FC-F1DB-49B4-AD3A-93724FC3B64D} - System32\Tasks\0 => Iexplore.exe <==== ATTENTION Task: {7B472E86-AC40-4F71-BECE-50EA7F63FB51} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe Task: {85F2DDD5-097C-4760-81A6-6794A69B4486} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard) Task: {8610154D-F1E8-4E74-BE07-ED1A393D6EA0} - System32\Tasks\{A2B6EAAC-CF9A-416B-A5DD-12F26F949DBE} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe Task: {889FE0FD-E554-480D-97C8-9DB112F4366E} - \UpdaterEX No Task File Task: {918A8018-6AF5-49C3-BE28-6AA9A1065A3F} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1888085416-2387315268-2958175980-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe Task: {943B592E-D0B1-4D82-A3BE-93C9070F7D45} - System32\Tasks\4704 => Wscript.exe C:\Users\Owner\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION Task: {A076A197-67E8-46FE-8FB6-463451A490EE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-28] (Google Inc.) Task: {B7CE3510-EFA8-47BF-A615-F879F252CCF8} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-09-23] (Hewlett-Packard Company) Task: {CE1DA054-7F9C-43DE-AC33-8D39111505FB} - System32\Tasks\{F441A607-219C-4562-867C-57461BD3D548} => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {D5AB1C2F-5630-42AF-9D77-BD45A06D47AC} - System32\Tasks\HPCeeScheduleForOwner => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13] (Hewlett-Packard) Task: {DA46FFD3-1283-4D5B-A073-560F92A199FE} - System32\Tasks\SUPERAntiSpyware Scheduled Task 0fede45e-e614-4edb-96db-b5cfa8057305 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-05-23] (SUPERAdBlocker.com) Task: {FE36A3C7-F5E7-428D-9393-64DA0DA3B6FD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HPCeeScheduleForOwner.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\Windows\Tasks\RMAutoUpdate.job => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\SULauncher.exe Task: C:\Windows\Tasks\SpeedyPC Pro.job => C:\Program Files (x86)\SpeedyPC Software\SpeedyPC\SpeedyPC.exe Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 0fede45e-e614-4edb-96db-b5cfa8057305.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task b0dc51e7-0fb1-41e1-a40c-98b52b0ce4e3.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Loaded Modules (whitelisted) ============= 2012-02-14 19:23 - 2009-11-04 08:17 - 00280576 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxecdr.dll 2012-02-14 19:23 - 2009-05-18 08:32 - 01416192 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxecptpc.dll 2012-02-14 19:23 - 2009-11-04 08:19 - 00198656 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxecdrui.dll 2012-02-14 19:23 - 2009-11-09 03:36 - 00142336 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxecPRPR.DLL 2012-10-28 19:35 - 2012-10-28 19:35 - 00155648 _____ () C:\Program Files (x86)\Cox, Inc\Cox PC HealthCheck\SmartDisk.dll 2012-02-14 19:21 - 2010-04-01 12:23 - 00389120 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecscw.dll 2012-02-14 19:20 - 2009-05-27 07:16 - 00192512 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecdatr.dll 2012-02-14 19:21 - 2010-04-01 12:24 - 01159168 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecDRS.dll 2012-02-14 19:21 - 2009-03-10 00:43 - 00155648 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxeccaps.dll 2012-02-14 19:18 - 2009-02-20 03:48 - 00381440 _____ () C:\Windows\system32\lxecsm.dll 2012-02-14 19:18 - 2009-02-20 03:48 - 00023552 _____ () C:\Windows\system32\lxecsmr.dll 2012-02-14 19:21 - 2010-04-05 05:56 - 00716954 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Epwizard.DLL 2012-02-14 19:21 - 2010-04-05 05:55 - 00159890 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\customui.dll 2012-02-14 19:21 - 2010-04-05 05:54 - 00123033 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Eputil.DLL 2012-02-14 19:21 - 2010-04-05 05:54 - 00143502 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Imagutil.DLL 2012-02-14 19:21 - 2010-04-05 05:55 - 00061604 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\Epfunct.DLL 2012-02-14 19:21 - 2010-04-05 05:56 - 02203803 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\EPWizRes.dll 2012-02-14 19:21 - 2010-04-05 05:56 - 00045221 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\epstring.dll 2012-02-14 19:21 - 2010-04-05 05:56 - 00094359 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\EPOEMDll.dll 2012-02-14 19:21 - 2009-04-07 14:25 - 00409600 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\iptk.dll 2012-02-14 19:21 - 2009-03-02 09:25 - 00151552 _____ () C:\Program Files (x86)\Lexmark Pro800-Pro900 Series\lxecptp.dll 2014-01-07 09:08 - 2014-01-07 09:08 - 00225976 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebugDll_win32.2.3.3.52783.dll 2014-01-07 09:08 - 2014-01-07 09:08 - 00362680 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebug.2.3.3.52783.dll 2014-01-07 09:08 - 2014-01-07 09:08 - 00419512 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWUtils.2.3.3.52783.dll 2014-01-07 09:08 - 2014-01-07 09:08 - 28105912 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWExternLib.2.3.3.52783.dll 2014-01-07 09:08 - 2014-01-07 09:08 - 00265912 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib_win.2.3.3.52783.dll 2014-01-07 09:08 - 2014-01-07 09:08 - 04791480 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWData.2.3.3.52783.dll 2014-01-07 09:08 - 2014-01-07 09:08 - 04240568 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWApplication.2.3.3.52783.dll 2013-02-19 01:46 - 2013-02-19 01:46 - 00011362 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\mingwm10.dll 2013-02-19 01:46 - 2013-02-19 01:46 - 00043008 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libgcc_s_dw2-1.dll 2013-02-19 01:46 - 2013-02-19 01:46 - 02537472 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\QtCore4.dll 2013-02-19 01:46 - 2013-02-19 01:46 - 09814016 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\QtGui4.dll 2013-06-04 20:22 - 2013-06-04 20:22 - 00481280 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\Genie.dll 2013-03-27 03:42 - 2013-03-27 03:42 - 01553920 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\SvtNetworkTool.dll 2013-02-19 01:46 - 2013-02-19 01:46 - 01140224 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\QtNetwork4.dll 2013-02-19 01:46 - 2013-02-19 01:46 - 00399360 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\QtXml4.dll 2013-05-09 22:12 - 2013-05-09 22:12 - 00229888 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Airprint.dll 2013-03-27 03:43 - 2013-03-27 03:43 - 01067520 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Internet.dll 2013-05-28 01:21 - 2013-05-28 01:21 - 04334592 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Map.dll 2013-03-27 03:52 - 2013-03-27 03:52 - 00500736 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_NetworkProblem.dll 2013-03-27 03:50 - 2013-03-27 03:50 - 00186368 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DragonNetTool.dll 2013-03-27 03:51 - 2013-03-27 03:51 - 01198080 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_ParentalControl.dll 2013-05-14 21:56 - 2013-05-14 21:56 - 08432128 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Resource.dll 2013-04-28 01:25 - 2013-04-28 01:25 - 01205760 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_RouterConfiguration.dll 2013-03-27 03:42 - 2013-03-27 03:42 - 00088064 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\QRCode.dll 2013-03-27 03:51 - 2013-03-27 03:51 - 00641536 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Statistics.dll 2013-05-14 00:18 - 2013-05-14 00:18 - 00931840 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Ui.dll 2013-03-27 03:49 - 2013-03-27 03:49 - 00438272 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Wireless.dll 2013-02-19 01:46 - 2013-02-19 01:46 - 00083456 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qgif4.dll 2013-02-19 01:46 - 2013-02-19 01:46 - 00083456 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qico4.dll 2013-02-19 01:46 - 2013-02-19 01:46 - 00287232 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qjpeg4.dll 2013-03-27 03:42 - 2013-03-27 03:42 - 00137728 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DiagnosePlugin.dll 2013-03-26 21:58 - 2013-03-26 21:58 - 00139264 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DiagnoseDll.dll 2012-11-29 04:56 - 2012-11-29 04:56 - 03332720 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\drivers\libntgr_api.dll 2013-03-26 21:58 - 2013-03-26 21:58 - 00072192 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\SVTUtils.DLL 2013-03-26 21:58 - 2013-03-26 21:58 - 00074752 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\NetcardApi.dll 2013-03-26 21:58 - 2013-03-26 21:58 - 00136704 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\airprintdll.dll 2013-03-27 03:51 - 2013-03-27 03:51 - 00714240 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_Update.dll 2013-03-27 03:49 - 2013-03-27 03:49 - 00485376 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_WirelessExport.dll 2013-03-27 03:49 - 2013-03-27 03:49 - 00116224 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\WSetupApiPlugin.dll 2013-03-26 21:58 - 2013-03-26 21:58 - 00066560 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\WSetupDll.dll 2013-10-19 23:31 - 2013-07-15 12:29 - 00620718 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll 2012-10-31 13:29 - 2012-10-31 13:29 - 00221184 _____ () C:\Program Files (x86)\Cox, Inc\Cox PC HealthCheck\AgentBase.XmlSerializers.dll 2013-12-20 20:46 - 2013-12-20 20:46 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-01-07 09:08 - 2014-01-07 09:08 - 00224952 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Dashlanef_260.2.3.3.52783.dll 2014-01-07 09:08 - 2014-01-07 09:08 - 12264120 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib.2.3.3.52783.dll 2014-01-07 09:08 - 2014-01-07 09:08 - 01912504 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLibData.2.3.3.52783.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1 AlternateDataStreams: C:\Users\Owner\Downloads\Thank you for ordering CalendarPal.eml:OECustomProperty AlternateDataStreams: C:\Users\Owner\Downloads\Very interesting historical photos.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/18/2014 01:29:48 AM) (Source: Application Error) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.16428, time stamp: 0x525b664c Faulting module name: KWIEBar.dll, version: 2.3.3.52783, time stamp: 0x52cc0a1f Exception code: 0xc0000005 Fault offset: 0x00002f92 Faulting process id: 0xf38 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Error: (01/18/2014 01:27:45 AM) (Source: Application Error) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.16428, time stamp: 0x525b664c Faulting module name: KWIEBar.dll, version: 2.3.3.52783, time stamp: 0x52cc0a1f Exception code: 0xc0000005 Fault offset: 0x00002f92 Faulting process id: 0x16f0 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Error: (01/18/2014 01:26:51 AM) (Source: Application Error) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.16428, time stamp: 0x525b664c Faulting module name: KWIEBar.dll, version: 2.3.3.52783, time stamp: 0x52cc0a1f Exception code: 0xc0000005 Fault offset: 0x00002f92 Faulting process id: 0x19e8 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Error: (01/18/2014 01:26:50 AM) (Source: Application Error) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.16428, time stamp: 0x525b664c Faulting module name: KWIEBar.dll, version: 2.3.3.52783, time stamp: 0x52cc0a1f Exception code: 0xc0000005 Fault offset: 0x00002f92 Faulting process id: 0x134c Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Error: (01/18/2014 01:26:50 AM) (Source: Application Error) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.16428, time stamp: 0x525b664c Faulting module name: KWIEBar.dll, version: 2.3.3.52783, time stamp: 0x52cc0a1f Exception code: 0xc0000005 Fault offset: 0x00002f92 Faulting process id: 0xfb8 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Error: (01/18/2014 01:26:30 AM) (Source: Application Error) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.16428, time stamp: 0x525b664c Faulting module name: KWIEBar.dll, version: 2.3.3.52783, time stamp: 0x52cc0a1f Exception code: 0xc0000005 Fault offset: 0x00002f92 Faulting process id: 0x19f4 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Error: (01/18/2014 01:23:44 AM) (Source: Application Error) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.16428, time stamp: 0x525b664c Faulting module name: KWIEBar.dll, version: 2.3.3.52783, time stamp: 0x52cc0a1f Exception code: 0xc0000005 Fault offset: 0x00002f92 Faulting process id: 0x19d8 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Error: (01/18/2014 01:23:04 AM) (Source: Application Error) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.16428, time stamp: 0x525b664c Faulting module name: KWIEBar.dll, version: 2.3.3.52783, time stamp: 0x52cc0a1f Exception code: 0xc0000005 Fault offset: 0x00002f92 Faulting process id: 0x870 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting m
  13. ok now when I click internet explorer screen shot below
  14. Internet Explorer stopped working A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available
  15. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Home Premium x64 Ran by Owner on Sat 01/18/2014 at 0:32:04.08 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\caphyon Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\caphyon Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4623A8C4-150D-4983-8982-68C01E7D6541} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5E3EB385-F12C-44B9-8CE7-F4446D9EBD5A} ~~~ Files Successfully deleted: [File] C:\Windows\syswow64\sho145C.tmp Successfully deleted: [File] C:\Windows\syswow64\sho1584.tmp Successfully deleted: [File] C:\Windows\syswow64\sho1585.tmp Successfully deleted: [File] C:\Windows\syswow64\sho1DA3.tmp Successfully deleted: [File] C:\Windows\syswow64\sho256B.tmp Successfully deleted: [File] C:\Windows\syswow64\sho471E.tmp Successfully deleted: [File] C:\Windows\syswow64\sho5B2C.tmp Successfully deleted: [File] C:\Windows\syswow64\sho6C6B.tmp Successfully deleted: [File] C:\Windows\syswow64\sho761C.tmp Successfully deleted: [File] C:\Windows\syswow64\sho77FF.tmp Successfully deleted: [File] C:\Windows\syswow64\sho7EFF.tmp Successfully deleted: [File] C:\Windows\syswow64\sho8546.tmp Successfully deleted: [File] C:\Windows\syswow64\sho8A64.tmp Successfully deleted: [File] C:\Windows\syswow64\sho9A8E.tmp Successfully deleted: [File] C:\Windows\syswow64\shoA10.tmp Successfully deleted: [File] C:\Windows\syswow64\shoECF.tmp ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader" Successfully deleted: [Folder] "C:\Program Files (x86)\couponalert_2pei" Successfully deleted: [Folder] "C:\Program Files (x86)\coupons" Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader" Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{00625B2D-DB0A-4EB3-B2E5-96BFAFC0C052} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{00937074-1E68-4369-8EF8-C8DDFDD4BDD7} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{00E1BC11-069F-46F4-BEBE-3EC09220A82F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{00E553F7-C51D-417F-BB37-09AF104689A3} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{01570733-E592-4E33-A047-DAEB588A99DB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{01A5F566-6A08-438B-A58C-D7CCD629E112} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0248081D-F52E-4A57-B1A2-597A27ADEAB0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{025ACEEF-C23F-49C5-9038-44166C00C6F1} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{02CF0028-C03B-4E1C-9708-E27CB78BCEB8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0333D984-A470-4635-B8CC-FD0682835FA6} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{040F3D64-1496-4616-A7C6-C3F8E43FDA14} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{04476D5C-5550-4B2E-BDC5-4D186D65F082} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{044E79A4-687E-4027-8B9D-9FBEB186F435} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{048EAB86-3E6C-4A14-9A71-6729726B791E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{04D44AD5-E5FD-4781-BAC5-CB41D83725E0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0513C3E3-57DB-450A-818A-212807CE2AEC} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0525C55C-4F31-475C-AF8E-D55CDD986A15} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{060CF789-09B2-4558-B7FA-1B945857C58B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{06215B4A-D560-4E00-9B3E-A7DA64F52D73} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{068B0232-96A4-4EC0-A413-691116920CDB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{06FE81ED-7B37-459A-830D-56387D67E740} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{086D5A21-048B-4C47-A5FD-1C30E51DC4BB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{09C356E8-E89E-4466-B7CB-728631B94E38} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0A431782-673B-431A-A8B8-28CB854FA71F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0A4677BB-F837-49C7-AFC3-A24E5B5F2D70} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0A46F6A3-F2E1-4FFE-B0DF-DE35C5B062F2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0ADADB20-E6F2-44A2-8B54-AACA47C08744} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0AFD106F-DA3F-4287-81F5-72F31DE3ABC2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0B645F0C-6ABB-43A1-B6B9-DE7B3389EA5E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0C518470-129A-4DB2-B9E9-9DC878F0129C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0CCE737C-1B9D-42DC-865B-0A7F225B6680} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0E723192-9581-4AE0-ACB1-E230BEF6D24E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0E75C476-9AD2-4857-9CB6-AD309199868B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0EF45574-2340-4EB5-9EF8-3C63086DBC47} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{0FEE5C83-0C68-4F5E-A600-8204205E2229} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1071E446-31F7-491E-B9CB-7B10E4521594} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1086CA0F-7D74-43F7-8BEA-DB3A9E270F62} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{11EC1650-4C38-440F-B2BF-3B5DF469D7F7} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{12261723-C7B0-42D6-A737-F075E4C85B0F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{12E76FE5-EB9C-402D-B71B-29848A06FAD2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{135983E5-F736-43B2-8E7A-FA432542F897} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1531B084-46EF-4AF0-AB07-C2354AE259B9} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1608E6E5-FCE1-40D3-B03F-74AD18612D04} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{17A4268A-DE6A-4B3E-823C-5643303C3A40} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{18654DB5-64D3-48EE-B8D5-B79964F04B03} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{18AC3F8A-5EB6-48A0-93D8-1C9AD8BB3C1E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{18BF9739-11DC-4863-9DF1-6D9A8D727193} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{192772D3-B39A-4713-B42B-415881D5AF00} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1953A629-1F1E-4E3E-AAA1-CFCE96D17265} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1A71DA4C-3FD6-4FC3-8309-BFE5481B0EC6} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1B5C01EE-9FF9-4D49-A1AF-9D26A06795A2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1C34BBD2-A33E-4B99-B005-A973A7CB89A7} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1C5EAB37-1747-4F1B-BCF7-1EE782F902F5} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1CAB519D-015B-4255-A662-97CCF08B085D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1E17AD9A-3EA9-4670-85A2-5BA64FACA35D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{1FB936C3-D791-447F-9853-A8DBC664D5C8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{20174EA1-3E17-4444-B576-6E92C6137D18} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2037C73C-DD6F-4410-9A34-9C64FF65A695} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{214C2665-FB69-46BA-AA3E-8407FE564CDD} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{219C3ACD-2FE4-458C-939B-16ECBCCAB42F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{219F7564-4121-440D-AFF1-29D0588EE906} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{21EEE30E-7C48-412F-9764-814C3685506A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{222BF39B-4CE5-4266-932D-9146737AF5BB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{22472D57-9647-46FA-BA16-BD5285DEEF8A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{22E55365-B861-4359-9CCC-C014B57E4901} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{22FF301F-79A5-43ED-9C6B-6775923C9663} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{237B8285-0CB7-4C44-B512-F70A39C047A3} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{24181589-2506-41DB-B67A-99486DFCBC8C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2427FBFE-D6C1-4EB3-A167-E5709E36CD23} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{246BCA36-F3E4-4352-9C31-1D0F5FE436C4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2522A3AE-5392-46B4-AF00-B2E2D718726B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{253A64A1-CEAF-4F8C-8E08-3508DA7D2E2D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{255A919D-4482-47D9-8367-BC68CE162BBA} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{258F7DAE-A068-4F8D-9A7A-A78DB09B5712} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{25CB7241-9A6C-49D6-A92C-9FD73000D862} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{25CDC2CB-DF05-4483-8AC8-A43277693DA2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2637ED96-04D0-4F28-800F-69362B080383} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{267B502E-6979-4D52-A903-98388904A9F5} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{27493951-30B9-48AC-9FD9-76E6D3BD7813} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{283A3F96-DBF4-44E2-B54E-7E8952E09D4E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{289FB045-E98C-4EB9-B044-04D8EEBBA6ED} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{29594BEC-2859-45B4-A878-87B9A6FE4752} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2990FF04-AB9C-4601-B92B-A04DA1601E1E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2A4F93D8-1BC9-495B-81DF-AFE6E6A9089F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2A673BC9-70D0-46E7-A03C-B04F8D418E70} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2A7CC74E-B27C-4161-BBA0-06187AA478DA} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2ACE3456-EEA2-4169-8F6B-94AF02806BFD} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2B4F2CC3-82C5-460B-B5BD-C2A5299EE59B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2B5928FF-D5A9-414A-BFFA-A77C2427E1C8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2B63EE1A-FA46-4879-8851-AEE30203877E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2C271DB0-73BF-44FA-AFF5-A0795E22848B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2D5A7C96-A864-4A47-9D53-F86308106C86} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2D76C0C2-DD46-4A7F-88B0-A40300C268E7} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2D799C88-66F0-42F6-9D21-AA50840A633D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2DE3C935-D79B-41D8-8E84-A277C0B540B1} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2EF810C1-0EE7-4EA7-B108-0774B2AD766B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2F6EF1A8-3A2C-48F9-85E0-1084C9E4B4C8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2F7B9270-611E-43C3-9171-4590392C64FF} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{2FF654A1-E6F8-4634-AEC4-EE51C2BD6B5B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{31AEA2D9-F9E2-48AE-AAC0-732AB5C208A0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{31E323B9-CAA1-46F2-91EC-A5DAC3EFDA7E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{31F6130C-608A-43AF-948C-8F2CDA0F7DE3} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3201D73A-696E-4CD9-80A3-7562FB2ACB2C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{322E5AEF-98A4-44B1-BDF1-00FD8750E231} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{334B3B20-4CAA-4747-B8D9-70C04EB05519} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{339EBDD6-9867-48EE-8E06-EAF8902D1C56} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3498FEDC-09BB-415E-92EB-9BB10CC61E4A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{34B7B7F8-B8B6-4C81-B23E-A003B6162F2A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{34D3759C-D7BC-4E7C-B3DE-B78FBB70F53E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{34ECABE3-F05C-45AC-8E07-591FB0D27657} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{34F89F21-3B50-42AD-823B-960B4D61C314} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{350B4872-A314-4129-A5FD-6089429AD23B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{35156ACA-2886-46F1-901D-7008CDFA3E6C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{357C258B-F512-4123-8ED8-1E5F2F785D4A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3608F264-F107-42B4-A99E-8F5ECB2F7072} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{36750DEE-43A7-421C-A721-DB250A7A69B7} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{36C51C5B-5D06-41DD-9C1F-92D1B84205D4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{371FA6DF-A43B-4BC9-96F6-CB92F87674D0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{38FEA8B6-FF9F-48E4-98D8-E41036DCCBFB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3924094E-1F9D-4D28-8FD7-0215B3AE0DCC} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{39F3D501-0BAF-4104-A873-16CB148B1944} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{39FD783D-F9B9-42F3-AD2E-48EAA3DB0772} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3A3E7F5C-FEE4-42B9-995D-952F8F8B687B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3AAC5801-29B9-4498-8B49-DD13BD7544CA} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3B49F9FF-8247-4476-AEE9-21894D5B058B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3CA9D0F0-696D-4040-966D-4DEEB91BB450} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3DB4254D-153A-4C95-A9D8-F084D99F52FF} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3E4337B0-5CB5-40B8-A552-C200B5125AF6} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3E44F6A5-F328-4B47-A63E-39E0BDB9BE40} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{3F58FC9B-A91C-423F-B460-E98785BB9F40} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{40A735C7-1035-47F2-8820-B8740864BBF4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{40DACE69-91E6-4F0B-89C5-15B3FD848252} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{40F6E0B2-10C1-4609-8B0E-FB090BCF0A25} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{419D0A8F-A75C-4DFA-A065-9CC03A45AB19} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{41DC1ECD-D3C1-47CF-AC01-2C3E619DD531} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{424882BF-7086-4906-91A7-C4B6F1D667FB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{440196CE-B603-465F-ADEA-515FD4222374} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{456F5240-86F7-4DFD-A9A0-3719EC933500} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{476790E0-AB04-49B3-94D0-EB40325930AF} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{47F96E21-0A05-41A5-8062-82773BF32EEF} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{480BCF84-1354-4273-A087-E4E308A90D43} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{49C95B6A-94E4-4E1A-9C64-5FA202E49BEA} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4AE30BC6-EAA0-4105-B22A-CDC165BC64B4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4B84C9FD-81C8-4139-BCB6-E611C069AEA4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4BAB4A34-E17F-44B4-B91B-3BBA68E38E90} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4BE1C798-5C2F-452E-B42A-6F5C21064F16} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4C1D6B8E-4368-452F-9B1E-BA02266C1629} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4C201EAC-C0B1-47EB-9E5D-C79E7D21037B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4C55944D-0C86-4D58-978C-62E77EB5BCDC} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4C6BE955-4346-4AFD-949B-E83AFCFD690B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4C7D41DB-000E-40D9-AA84-D5C7651F346B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4CFB247F-11BA-4687-A5A6-E2CB0240AB00} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4D2C73EB-0113-42C9-ADF9-D21B7DF30F84} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4DB8CC0A-EB24-48FA-9C5C-F0145BDAE768} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4E22C687-0C87-47AF-B565-DA252CFBF083} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4F05A253-7573-4DA8-B66A-2D6EEB52C48B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{4F8A5D77-9699-4322-B6E5-55D3D32C1553} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{50999915-671C-487F-8D93-5A80FE9DE2B0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{509AB861-D193-4040-A50D-F7A7F30B82D6} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{511CECEE-4433-440A-962A-FEB5D2CC41C0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{536CFE47-F674-448B-A4BB-4DF78E4F0838} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{54573C26-1CDC-4D00-BF00-E3CE12AD7D8C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{54E35132-D33E-4224-8E6E-A201A0A407A4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{558E1DC2-694A-47FE-B0ED-34EA9480FB69} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{56BDBBEA-D723-4DA1-A682-F3A9AAC8130A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{56C93FB1-358E-455D-9A26-0CF2AF21F4A1} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5815DE33-D488-4681-B747-53CF7D4E8F99} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5844D643-B2C9-4F75-AD0B-39C163789109} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{596E38C9-C5B8-4434-8F8D-931F6639ACE3} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{599A0BF3-50BA-4548-883A-2204C9D759EC} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5B1782E8-7169-4799-8D19-EE5A63301DDC} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5C3273CA-E22A-4D16-8A9E-573274FCD099} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5CF66E14-E0ED-44DE-90F4-7CACE5399B69} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5D148568-ED56-4C88-B684-82E36D879DB3} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5D276680-3AC4-45E0-88BA-B7286CB2EB76} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5D2D3BAA-A71C-4271-B3CD-D34E4A163737} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5D5D1440-1B99-4FA6-9171-5D3AA416C37F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5E3E767E-9A93-47C2-BDF3-AF724081694D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5E900FFA-1CA4-468D-AD03-9328D99BD4EA} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5EF3D3EC-CBDA-48A0-B911-B2D1631B5675} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5EF4C231-BAD3-49B0-960E-CDFD95A8A47F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5EF627B7-361F-4901-8F8F-37A09FE1F722} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5F800407-C0D6-4E92-917E-5C9754BEC7DB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5FF48720-FD35-4B42-97F8-4C2CD0A70D2E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{5FF5A725-4D0C-40E6-BF8F-3B0EB5B75F49} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{62057904-D591-480E-AF9E-AE806B9E7668} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{6217797B-E98A-4215-A093-8BE83CF7DB1B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{62F0B04A-EB97-4702-A404-499B9E71C43B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{631CD499-FFCC-4A11-B0BF-7331B31B3260} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{6321CA51-14D2-4F52-9BC3-8162711EA514} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{63395500-E5C7-45D4-8685-EA4A80E0194B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{6342A6B9-C5C5-4621-B2B2-04798396C75A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{63777C63-F783-4196-BCAE-5EB24A441C5A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{640459CD-AAE1-422A-8F2D-CB8169D728BB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{64AFE4C9-CFC4-468D-8FF3-C3DD0B9BB57F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{665AE848-A023-4393-B507-70C1BE52F802} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{6866B05C-67B5-451D-84AD-C22290F7A085} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{6C15B2BF-6423-4BB3-9BE9-7FE82EF6395B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{6E505EB9-2763-4AF0-BE1B-B2222AA51241} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{6EC3B819-DB70-4687-9EA5-ECED75F32BEA} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{6EE4A048-1CB1-4735-A88A-D090521B93B5} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{6FB1C016-93C0-45DA-A9FE-94BC9DCCDCD7} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{71099828-DF42-4842-BF05-C9C8BA3C8D46} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7147B449-CEBD-4109-AB47-294A0518F16A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{71600BF3-B36F-40F3-BA46-95B3280CC682} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{71969278-666B-4CF0-9259-865D6B1131D4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{71D4D2F6-3822-4AAA-AE1E-98DC725AEECD} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{72830578-8BB7-490D-B8CC-1180E7FE757D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{73725FBF-C0C7-49DB-A3C0-A2E657600464} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7386B445-F4FC-4FF3-A8AF-CFE5DC97B142} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{73C13CEA-0AFE-491B-A908-73728E92D1A2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{745526AC-7A7C-4F59-87C9-F94EE66BF97D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7483066D-B73D-4A54-8391-E8EB2A8F11F0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{749E06C0-9A7E-41DB-8C1F-6C984095BE56} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{749EBF3C-7D83-450B-B1A0-7A7A61240111} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{75098A07-2A94-4AD4-A1D9-9D30A7A9CD38} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{750D6EEF-4897-4878-9739-2224D52E42D6} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{756DA0FA-BDD2-4B20-B84D-A8F35A02D821} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{76BA8DC6-1348-4C8C-A7A3-929215422142} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{76D32D29-0E75-49CF-BC68-A98D62CF6561} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{76F9B7FC-27EC-4349-B694-ADF088E72566} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{775F4DA0-7C14-45E1-A934-59D693BF9F8D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{77B751EE-3E33-4209-81AA-12934D869413} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{77E58C33-27B9-44B8-A1B9-15684874C613} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{78A78CD1-9CF3-40E3-8B51-DCBBF32A9A1C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7A0A0819-FAFF-458B-9A53-3E680B1852DE} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7A267D49-5092-465D-8DA8-0A889F8D0018} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7A301A2E-B83F-4485-9EFE-B7C431F07AA5} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7D59321C-05AF-48A8-838F-66CB42102B5F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7D9D7B0F-BFB8-44CF-BFB4-5E6EC9B42B44} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7DBDEEB1-D436-4CFE-AE44-79DCEF78DD5C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7E00F575-7910-4BF8-8DF2-23771079BBF2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7EB6D3A4-9140-4873-9763-81BF32251B96} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7EC6F25D-D829-41AA-8987-AE6EC5DD321E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{7EEE9805-BE05-419A-8D7A-9492AE313357} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{81A0D944-9D9E-48DD-8B2B-70CB8571AD01} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{81BB1BA5-922F-4FD4-8C3A-2E62B52E349A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{81D1B490-A082-44B8-8DF8-ECA700C275DC} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8221CB76-3BD3-404B-B5AB-FA64F375BFC2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{83546BC2-19F6-4AF4-AB60-DDA5D82D2058} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{838AEF7E-682F-4B99-955E-13839168A362} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{83D4BB5D-32CC-4C02-9F48-DA6B621B863C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{84869E2B-9B6D-492F-B71B-FD7D7EC8FE2D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{857D5D58-F3F0-4480-8315-B159071A291F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{85914C58-5525-417E-9995-18C80772BD6C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{85AC5B68-EBAD-4430-8D33-D6FD4283056F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{862F9BC1-1718-479D-AA71-79BE3156FCE2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8631816F-BD82-4C0A-92A2-DF162CAC9B90} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{869BFA3B-C575-4F2B-830A-19738AD4AC55} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{879C3A1C-F3F6-4ADF-A4CC-0C709E9016C5} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{882B8972-7D67-4AA4-B558-66CE8CEA82AD} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8838D7C9-07B3-4CAF-B813-BE4FE5D6459D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{886EA5A5-4D8B-4605-A207-D110A3B43CC7} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8938ECD1-C5C7-4DD1-B685-9C622CB4ED7C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8A1F64A1-CC21-4DB3-946D-D94A82731013} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8A2B7B6D-406B-41D2-A114-0225659F644D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8B0B5727-48B1-41D8-88B8-1FDCCC7ED487} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8C3497A5-67DD-4134-8883-8854B371E6BA} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8C762619-72AD-4E4B-B567-69658E70EE59} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8D05E6E5-BCB5-461E-BC3B-C708F2A128FB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8D0FB2BC-F8A3-413A-B0BD-8E01FBB170E6} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8D814791-5C11-4AD6-99C7-1466E5197878} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8DEFF883-1760-44F5-9BE7-FE536E35F6FB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8E7970B1-2A85-4CDD-9BCD-BB1EE2E1FDCF} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8EBA8482-4F1E-483C-B7BA-D7AE238E02BC} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8F25B4F5-4187-477A-8AD6-2B705F93F125} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8F6770CB-664B-4258-8797-0DF9B8FEBCC4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8FDA312C-814F-4288-BBF5-CA92CE9898D8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{8FFDF529-CD4E-4B09-8A9C-EA70F976AD40} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{901CC142-024E-49F2-BE00-3B3A1C031F01} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{910EA266-D4BD-4E7A-AD91-F692C216C87E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{923D6015-4E49-4E84-B191-48EEB278FD74} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{942361AB-0267-4C8F-AF41-3C507B72A302} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{9550F79B-04DE-4E80-8A09-EFC23FB583E3} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{956A9C14-92A4-4157-8799-6D24CD0671C0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{9664C4D0-6E36-4D99-956E-DF680D573CF8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{968B013E-59F2-4BF9-8C9F-CB5EDD5AA2C1} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{96983AD4-C058-499F-9AE5-60E5A7E51BC4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{96B96817-972D-45E4-945E-394A8EAD272E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{96ECF067-82A3-4338-8604-03E0C76C2DB3} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{972662E4-98C1-4635-889B-0F2928AD658D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{975557F3-159A-4C41-969C-37C868EF1F79} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{97C98797-BE74-4146-99F3-964CF85938E5} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{98BE094C-35FB-403C-A43F-0E3927C43086} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{998F755D-4088-44DC-9035-C69822A2C8B4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{9A299F07-0DA0-4220-89ED-0E8C5351A822} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{9A46E37B-CDFC-41A4-9AB9-C187CAF441B4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{9A7E052D-4C3C-415E-BBAB-109F128F22D3} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{9AADC452-C9A6-4A80-876C-26A4A8B94078} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{9AFA0A7F-2A26-4D7D-B1A4-2700625F0177} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{9B8630A1-9AD1-49B7-92E9-D1405074581C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{9B975143-7F49-458E-BDD3-7901EEEE322D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{9DDD15BB-7FF4-4713-B2E9-7FADF308BFB1} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{9F3F9A12-8FC6-4B42-A6C6-C4E9A58737E1} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A10F17EE-9C87-4CB7-A002-10860FEA2285} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A1943AA4-E8C7-42BA-93A3-804F1FE6EDBD} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A2446C30-09A9-4C55-A925-CC1140412D70} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A26122D8-E4C6-4C23-83C9-2A83E06E919F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A2CC48B2-03CA-4ACD-91CB-EE813FADBEC9} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A42A6C98-A698-4447-AB55-1CC014A63796} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A4CB2F63-95F2-4A74-8034-6CB3EEB8DC9D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A4D19638-4E76-478A-B8AB-44A2C9ABE3A4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A4D39E04-09AF-4FFA-9F7B-398CC338D1A2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A5598740-A87D-4DC3-A57E-F88D4613C501} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A57AF832-CFE6-4772-BF87-FEB394A33C46} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A5A1ACC6-883F-4BCA-88D5-54FE14272590} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A6063F9B-498A-4118-A218-0BE30CCB9800} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A6BC9A89-9C0F-4768-90E8-DA5B4CA52AD2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A6F3B26F-C38A-4E31-83BD-40ADAC34433A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A89D6767-A804-4889-A85C-326AFD7BBD97} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A9A53655-FAA0-441A-94CE-730F316E2EDD} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{A9FF12E4-75CA-4672-99D0-668B54DB4C29} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AA5933B8-3BEB-4076-A30E-22EAE9BDDB5F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AA8A2890-0779-40CB-BB2D-9874F4C74854} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AA9F7350-64B4-408D-86F1-A99817C2DC2B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AC22FE1C-AA9F-4CE1-A491-738ED78D3381} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{ACE13282-6DE6-4A4F-8308-DDD4E3FF9C05} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AD082523-36E3-46CB-AD59-169DAEC0D89C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AD38AEA2-ED4E-49D7-BEDD-4F7D3743A9BE} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{ADB435A7-2740-4BFE-959D-D816D35B64E7} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AE7D79E3-604F-4603-B88A-91B5473EDFDC} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AE7E59FE-A447-49CA-9666-8AF0FAF835E7} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AF12AD05-EE8F-4A8A-9182-E97F9C91776B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AF550F22-BBD7-4273-9892-89EF58C9BFC0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AF6748C3-2D9D-40A1-A8F7-EB2812CBA7DB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{AFAECF2A-1BB5-4316-9CCA-7EF263CEB119} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B122E21F-06F0-4B0C-9630-E3D323D60E07} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B15D1DAD-8F20-4642-8C66-9938DD71E3CA} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B16D9A66-71CF-4298-AAC1-C2487265BE46} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B2285785-1D9B-4BD5-A7FC-49A811A45947} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B325F240-37A1-4A7A-BE7C-A60CC940A11F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B51BFD1F-1608-444A-9835-CF8B0D5144B5} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B5318E56-C3A6-4406-A4E3-669196EBC201} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B551E28D-B56E-4717-9295-133F5FA7CC61} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B5CCEB29-8F3C-4067-AEFF-F3E855E028AD} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B6C98815-067E-41F1-B7D5-6F05E72E60CA} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B7413ECE-9841-478F-91F0-146C378DADB8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B7AB617D-7BA1-4733-95BB-E7FE0F5757F6} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B8B25C36-9A5A-4934-84B6-0FBFB1AEAEF6} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B8D97507-CFC7-4B4B-A083-EB8CCB4F4C6F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B95E9FAA-CE93-47C3-9CE7-3424B0CB242F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{B96ECFD8-BF48-4690-AA0B-95252AB37966} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BA37319A-57B6-4A18-B23D-21EBBB40996D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BA751215-DBFD-4D71-AC78-D77EB9C63E6D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BABFF3B6-8170-4D86-BE11-012505A30527} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BB18DDC0-12CB-4364-8DBF-23F2A9F5E970} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BB9ADB49-235F-47FC-88E3-23796271C582} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BC40B076-F281-471D-AAFC-262938E1235F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BCADD1F0-B686-48A7-ACE2-9CB763FB8C98} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BCAE0730-5072-45B4-AE9D-A83F1090AA52} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BD05A674-4A60-40CA-80F4-238D3C2841C4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BD430F18-7337-4FBE-B863-95567455061B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BD7CA5EA-7D58-4F6A-B4D0-A18782B1B292} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BDF5BAF4-B1FA-4683-8AAC-7BBD6B130E05} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{BF4CF2CB-09C0-422D-8644-E1940D1CD4A0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C09AE942-BF11-43C8-81A9-F8105F8EA21D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C0D54F1F-B19C-463F-85EB-BA2297CFB042} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C14F6EBB-84CD-48E1-A084-064154EDEDDC} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C1686FC6-E970-46CC-97A0-79CD5A8D8C4A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C226FCDD-5A00-494B-AF78-D5250BDF46A4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C29892E6-C4A5-4B80-B5B1-E24AC8ACEF52} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C2C685CF-1552-4C69-B047-DDBDBB20450C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C3968A55-9C09-4E36-882A-89F9A2BCFFD1} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C3C214AD-AF1E-4E90-8004-1FD9CC9372B8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C3D9590B-9113-457A-A93E-39AE35F3A087} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C40E13E6-E3BB-4FA3-BB96-B49FA5EBD295} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C46BF0D3-1ABA-483A-8A87-3710B45950A2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C47A4A81-789F-4B9A-B7E8-1EB57AC89083} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C5A31B12-5283-4860-97D2-0664EE6CA316} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C5C006D7-6B0C-4EB1-8256-07C7B7437BAE} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C5D4CC6E-B8DC-41D7-9BF5-367BC7C13B12} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C5FF3BBE-0CAA-41EE-9519-A8F9D65093D1} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C6076A13-BD05-4DE8-BCC7-12A5471E832E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C6176120-DD25-4F6B-8D50-D3DD15471EE4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C6B10564-9306-4211-9062-E04B67BCFA5B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C6C04FA9-C252-4EEF-8705-E6AFDD851AB6} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C7AE8440-CFF5-4541-86EA-4A46BCDE2FB2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C8466841-545C-4504-BED6-B625B058828C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C8ABC16E-BCDC-4D2C-930C-567CC3E2E679} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C968967B-B130-446F-8432-3E2B5516F306} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C974A567-BF60-4B00-89D3-C94A61B57743} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{C9D48DF6-0C9C-47E9-BF5F-FA2E0D1B2D2C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CA782BFF-9D8F-45DE-B2C2-34393CF73BA6} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CAB1DFFD-FDE9-4310-8F7C-BD3336D46A57} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CB1774CF-F98A-4FB8-8F01-46DAC9A8D167} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CB28ED3A-F746-4F22-A410-95FF590A2D1F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CBDA466C-BAFB-4885-B6D4-F6AC5313723E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CC108416-7FBD-49B2-B4DA-5DB342E2D8AE} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CCAC57C6-2F25-4BDE-ABE3-B17FA3DB080D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CCB493A0-8DF9-46D0-9C0D-57D1BE3D64EE} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CD4738F9-42B4-4B69-A7DA-8815B0D895EB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CD4B66BB-5DE9-40B8-B4EF-C176198B0EDB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CD6E0C73-D14C-4383-9F8C-3B1E88FD13B8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CD7D5760-D83E-490A-8685-9507562890BC} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CDD7FFBE-F3D0-42A0-BE0A-F3454272AD9B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CEC9984D-BA47-4C18-A8B1-0EE269F894EA} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CF49DEA6-B59F-4DD6-8A4A-F817F689C7F4} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{CFBC91BE-0E82-49A9-A2DE-184347E0BEEB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D0B812FD-ABE8-4819-9465-CAE51408F3F0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D0D0D125-F86C-4A86-B4ED-9C271C730890} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D275D0CE-3EE5-4796-9757-E93F1288ECB8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D294AC43-A58C-4BD0-9A94-B1EF83BDF541} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D34E3378-7032-47B7-BF51-B92DF2401A29} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D45FDE8F-0BD2-4FD1-8235-B868B23FCFFC} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D4677601-BB15-4F9C-A12C-FF1EBBC2CC7A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D468A0C4-49D2-4478-8170-7984A68FAA6F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D4F7C603-D3CD-4D20-BFC5-EA1D68A30540} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D54E5CA8-6D92-41AC-8E62-470F541C4B18} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D8184202-496C-4BD0-A12C-8698C44F4868} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D966B912-0912-448B-97DF-B6CE7EAE5E17} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{D9B2A024-A938-4686-AF49-E29BC2BFF193} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{DA6DFD3E-B511-4982-BC05-9A36F65D9106} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{DA8E09A7-4310-4091-9142-79CDF5C57B1E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{DB3B58EB-73FB-4189-9BBD-3552F5D70BA8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{DB8E9AE0-542D-47AC-8B3A-027D2D07E6A2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{DBDF0A8C-0E95-47C0-BE72-AADEFD66932C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{DC156930-3298-4741-AF7E-81B592F35358} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{DD0A689F-9880-4CA2-8757-2DA3D0DD7682} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{DD7E344D-61FC-4F02-96E1-BF60A40CDC5E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{DEA58AC5-7FB2-4963-A311-3B2BAC74B4C1} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{DF339188-3486-4CC0-8323-93ADAFA3F479} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E03A8C27-24F7-4A93-AB96-3E67C5D0C995} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E04FB245-93FC-45C9-97B1-FCA9ECA9E3A8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E19A2EB8-43B2-474A-9766-C7A1FA5EB69B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E3F16B9E-6669-4F5D-8929-EC48A9B87742} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E461D695-A3FC-4E63-8F5C-16638277A06F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E4931727-F7C3-4898-AFE9-EAB8E79B32DF} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E5BC8410-D295-4A2C-BB00-1403352DE0B2} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E69134A1-38E3-47BD-9450-E6ECD5A0FDE9} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E696321E-13F4-44C8-BA5C-008BF5794A6E} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E757B305-1ED8-4ADE-A6D3-75892AF279A8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E7E0B858-D712-4E3D-B8A6-A28009A6F2C1} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E8513365-FD34-421B-B609-4E13DB15038D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{E917D6E2-6EDF-48E1-A3D2-80744484DD3F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{EAEFD212-C871-43AE-A7E5-C9225C123C6B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{EC00348E-5B2B-473E-AD8F-86CB303B2F05} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{EC3002ED-64E3-4C11-BD08-B33345D4555C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{EC69D4BD-0D3B-4EF5-9AAC-18DCB6114662} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{ED52022F-1550-4B29-BA46-1361DE9AB9E8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{EDE5DCB8-5246-4571-9EFF-DE48B0147DB9} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{EE066ED0-6391-4395-A6E1-DA31DC294E7A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{EEF1A6B9-9786-48AA-A323-6F7AAB879D8A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{EF827DD9-D48E-43C4-9538-25B458515CDD} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F05E5EA5-B10B-4690-8DAB-A02CC9D371F5} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F1BB7832-FAFD-49FC-ADB1-666CE7EBCC6D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F2967166-6FA0-4DF0-88EC-A1CF2EF65E41} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F3BE6A43-9401-4FDB-A089-2D7FD2C421E1} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F42D9459-2DBF-4AAE-BD57-CAE22F86AC8C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F483A0E2-43A6-4E06-9123-95FDB3FD6295} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F4FCEA2C-FE1C-429F-AA0F-50E644DE08CF} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F5030320-C1FE-4000-9FC3-2D36BCFC9B5B} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F56BD432-D8E4-4DFC-BD2B-38C2A487DB6C} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F599865C-6647-495B-9997-35FC6B6CBDA8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F5B7713F-1F8E-44DB-B92D-1C2ACDDB73F8} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F8154BEE-790B-4D00-B92D-77E0C0192CD7} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F86AE4D3-A01C-46ED-8A39-368174AE2B5F} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F90FAAFD-9573-47A5-908B-979A75069175} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F92748B6-6FF9-4F64-B5FF-F9D5CA5F6224} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{F997F681-DAB5-4BB5-B3E2-A7E1183C9E9A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{FA1BED1E-0E02-4B92-B052-E50264F3FE1A} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{FA68AF05-B722-48F9-B6B9-67F8CC561C08} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{FA9E64B3-5A99-4DEF-BCE3-33061496CCA0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{FAE89444-812D-470A-B8E5-DFB9672C0F5D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{FB8E09D7-4FC8-4A5F-A467-22800E8C49DB} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{FC8235BB-C93E-41C6-B42B-C8D1D92A6EF0} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{FCAA34D5-B390-46F2-A4F3-D409DCEB1D8D} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{FCF66510-4C4C-4E64-B553-34985BF6AEFD} Successfully deleted: [Empty Folder] C:\Users\Owner\appdata\local\{FDAAE60D-8C2F-4B10-A440-1A788C03C4B1} ~~~ FireFox Successfully deleted the following from C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\9cht6u4l.default\prefs.js user_pref("extensions.toolbar.mindspark._5zMembers_.BUTTON_STRUCTURE", "[{\"b\":220476011,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":220476012,\"c\":\"mindspark.enterse user_pref("extensions.toolbar.mindspark._5zMembers_.firstKnownVersion", "5.75.3.1275"); user_pref("extensions.toolbar.mindspark._5zMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?n=780b6198&p2=^AFA^xpi000^YYA^"); user_pref("extensions.toolbar.mindspark._5zMembers_.initialized", true); user_pref("extensions.toolbar.mindspark._5zMembers_.installation.contextKey", ""); user_pref("extensions.toolbar.mindspark._5zMembers_.installation.installDate", "2014011800"); user_pref("extensions.toolbar.mindspark._5zMembers_.installation.partnerId", "^AFA^xpi000^YYA^"); user_pref("extensions.toolbar.mindspark._5zMembers_.installation.partnerSubId", ""); user_pref("extensions.toolbar.mindspark._5zMembers_.installation.success", false); user_pref("extensions.toolbar.mindspark._5zMembers_.isCompliantUninstallImplementation", true); user_pref("extensions.toolbar.mindspark._5zMembers_.lastKnownVersion", "5.75.3.1275"); user_pref("extensions.toolbar.mindspark._5zMembers_.options.defaultSearch", false); user_pref("extensions.toolbar.mindspark._5zMembers_.options.homePageEnabled", false); user_pref("extensions.toolbar.mindspark._5zMembers_.options.keywordEnabled", false); user_pref("extensions.toolbar.mindspark._5zMembers_.options.tabEnabled", false); user_pref("extensions.toolbar.mindspark._5zMembers_.toolbarCollapsed", false); user_pref("extensions.toolbar.mindspark.lastInstalled", "couponxplorer@mindspark.com"); Emptied folder: C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\9cht6u4l.default\minidumps [221 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Sat 01/18/2014 at 0:52:43.10 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
×
×
  • Create New...