Jump to content

Keep getting "access to malicious website blocked" messages


Recommended Posts

Here are the log files from DDS.SCR:

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 8
Boot Device: \Device\HarddiskVolume1
Install Date: 7/12/2013 1:59:45 PM
System Uptime: 9/15/2013 4:12:19 PM (449 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. |  | X401A1
Processor: Intel® Celeron® CPU B830 @ 1.80GHz | SOCKET 0 | 1800/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 119 GiB total, 70.712 GiB free.
D: is FIXED (NTFS) - 158 GiB total, 157.73 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP14: 9/23/2013 3:02:56 AM - Scheduled Checkpoint
RP15: 10/1/2013 4:13:41 AM - Scheduled Checkpoint
.
==== Installed Programs ======================
.
Adobe Flash Player 11 Plugin
Adobe Reader X MUI
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ares 2.2.4
Ares 3.1.7.3042
ASUS InstantOn
ASUS LifeFrame3
ASUS Live Update
ASUS Power4Gear Hybrid
ASUS Smart Gesture
ASUS Splendid Video Enhancement Technology
ASUS Tutor
ASUS Virtual Camera
AsusVibe2.0
ATK Package
Avira Free Antivirus
Avira SearchFree Toolbar plus Web Protection
Bonjour
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Intel® Manageability Engine Firmware Recovery Agent
Intel® Management Engine Components
Intel® Processor Graphics
Intel® SDK for OpenCL - CPU Only Runtime Package
Intel® Trusted Connect Service Client
iTunes
Malwarebytes Anti-Malware version 1.75.0.1300
McAfee Internet Security
Microsoft Mouse and Keyboard Center
Microsoft Office
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Mozilla Firefox 24.0 (x86 en-US)
Mozilla Maintenance Service
MSXML 4.0 SP2 Parser and SDK
OLYMPUS Digital Camera Updater
OLYMPUS Viewer 3
OpenOffice.org 3.1
Qualcomm Atheros Client Installation Program
Ralink RT2860 Wireless LAN Card
RealDownloader
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealNetworks - Microsoft Visual C++ 2010 Runtime
RealPlayer
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek PCIE Card Reader
RealUpgrade 1.1
SceneSwitch
Shared C Run-time for x64
WebStorage
Windows Driver Package - ASUS (ATP) Mouse  (10/29/2012 1.0.0.148)
Windows Driver Package - OLYMPUS IMAGING CORP. Camera Communication Driver Package (09/09/2009 1.0.0.0)
WinFlash
.
==== End Of File ===========================
 

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16688
Run by Judy at 9:28:41 on 2013-10-04
Microsoft Windows 8  6.2.9200.0.1252.1.1033.18.3980.1523 [GMT -4:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Outdated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
.
============== Running Processes ===============
.
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\dwm.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSWinService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
C:\windows\system32\mfevtps.exe
C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Windows\system32\taskhostex.exe
C:\Program Files\ASUS\P4G\BatteryLife.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\dashost.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\Ares\Ares.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSPanel.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSService.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Windows\system32\wwahost.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\WindowsApps\microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe\LiveComm.exe
C:\Program Files\mcafee.com\agent\mcagent.exe
C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe
C:\Windows\notepad.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.


mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
BHO: Avira SearchFree Toolbar plus Web Protection: {41564952-412D-5637-00A7-7A786E7484D7} -
TB: Avira SearchFree Toolbar plus Web Protection: {41564952-412D-5637-00A7-7A786E7484D7} -
TB: Avira SearchFree Toolbar plus Web Protection: {41564952-412D-5637-00A7-7A786E7484D7} -
uRun: [OV3_Monitor] -NoStart
uRun: [ares] "C:\Program Files (x86)\Ares\Ares.exe" -h
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
mRun: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.6.112\AsusWSPanel.exe /S
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [WebStorage] C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\ASUSWSLoader.exe
mRun: [OV3_Monitor] "C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe" /OS
StartupFolder: C:\Users\Judy\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\ASUSVI~1.LNK - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
TCP: NameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{1A2E8BDC-6B21-4509-88CE-069DF6B8B085} : DHCPNameServer = 192.168.1.1 192.168.1.1
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll
SSODL: WebCheck - <orphaned>
x64-Run: [AuditSHD] C:\Windows\System32\oobe\auditshd.exe
x64-Run: [igfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.etsy.com/your/shops/AngelsNEverlastings/stats?ref=ys_ln_shop_stats|https://www.facebook.com/|https://mail.google.com/mail/?hl=en&shva=1#inbox|https://login.yahoo.com/config/login_verify2?&.src=ym&.intl=us
FF - plugin: c:\PROGRA~2\mcafee\msc\npMcSnFFPl.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll
FF - ExtSQL: 2013-09-22 15:58; toolbar@shopathome.com; C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\extensions\toolbar@shopathome.com
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-7-5 645952]
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\Drivers\mfehidk.sys [2012-6-22 771536]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\System32\Drivers\mfewfpk.sys [2012-6-22 340216]
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-7 17536]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-7-17 84024]
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-7-17 108088]
R2 APNMCP;Ask Update Service;C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [2013-7-26 168400]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]
R2 ASUS InstantOn;ASUS InstantOn Service;C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-4-13 277120]
R2 Asus WebStorage Windows Service;Asus WebStorage Windows Service;C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSWinService.exe [2013-6-26 71680]
R2 avgntflt;avgntflt;C:\Windows\System32\Drivers\avgntflt.sys [2013-7-17 105344]
R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 Intel® ME Service;Intel® ME Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [2012-12-19 129856]
R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2012-12-19 166720]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-7-28 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-7-28 701512]
R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2013-7-12 201304]
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2013-7-12 201304]
R2 McOobeSv;McAfee OOBE Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2013-7-12 201304]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2013-7-12 201304]
R2 McShield;McAfee McShield;C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe [2012-8-4 241456]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe [2012-8-4 218760]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Windows\System32\mfevtps.exe [2012-8-4 182752]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-4-16 39056]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-12-19 365376]
R3 ATP;ASUS PS/2 Port Input Device;C:\Windows\System32\Drivers\AsusTP.sys [2012-10-31 61824]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\System32\Drivers\cfwids.sys [2012-6-22 70112]
R3 HIDSwitch;ASUS Wireless Radio Control;C:\Windows\System32\Drivers\AsHIDSwitch64.sys [2012-8-28 21152]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2012-8-28 342528]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-7-28 25928]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\Drivers\mfeavfk.sys [2012-6-22 309840]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\System32\Drivers\mfefirek.sys [2012-6-22 515968]
R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;C:\Windows\System32\Drivers\RtsBaStor.sys [2012-12-19 294544]
R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-12-19 690832]
S0 mfeelamk;McAfee Inc. mfeelamk;C:\Windows\System32\Drivers\mfeelamk.sys [2012-6-18 69168]
S1 avkmgr;avkmgr;C:\Windows\System32\Drivers\avkmgr.sys [2013-7-17 28600]
S2 AntiVirWebService;Avira Web Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [2013-7-17 815160]
S2 avnetflt;avnetflt;C:\Windows\System32\Drivers\avnetflt.sys [2013-7-17 82136]
S3 HipShieldK;McAfee Inc. HipShieldK;C:\Windows\System32\Drivers\HipShieldK.sys [2013-7-12 196440]
S3 McAWFwk;McAfee Activation Service;C:\PROGRA~1\mcafee\msc\mcawfwk.exe [2012-8-4 332080]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\System32\Drivers\mferkdet.sys [2012-6-22 106552]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\Drivers\netr28x.sys [2012-12-19 1951304]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\Windows\System32\Drivers\WUDFRd.sys [2012-7-25 198656]
.
=============== File Associations ===============
.
FileExt: .txt: textfile="C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE" "%1" [userChoice]
.
=============== Created Last 30 ================
.
2013-10-02 21:32:25    290480    ----a-w-    C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10219.bin
2013-09-16 00:43:17    --------    d-----w-    C:\OLYMPUS
2013-09-11 17:31:08    144896    ----a-w-    C:\Windows\System32\tssdisai.dll
2013-09-11 07:36:59    447488    ----a-w-    C:\Windows\System32\wwansvc.dll
.
==================== Find3M  ====================
.
2013-09-18 23:26:35    78296    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-18 23:26:35    694232    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2013-09-15 20:15:12    428    ----a-w-    C:\Users\Judy\AppData\Roaming\sp_data.sys
2013-08-29 12:21:20    82136    ----a-w-    C:\Windows\System32\drivers\avnetflt.sys
2013-08-29 12:21:20    105344    ----a-w-    C:\Windows\System32\drivers\avgntflt.sys
2013-08-21 04:12:06    2241024    ----a-w-    C:\Windows\System32\wininet.dll
2013-08-21 04:11:59    915968    ----a-w-    C:\Windows\System32\uxtheme.dll
2013-08-21 04:11:59    53760    ----a-w-    C:\Windows\System32\UXInit.dll
2013-08-21 04:11:07    3959296    ----a-w-    C:\Windows\System32\jscript9.dll
2013-08-21 04:11:04    67072    ----a-w-    C:\Windows\System32\iesetup.dll
2013-08-21 04:11:04    136704    ----a-w-    C:\Windows\System32\iesysprep.dll
2013-08-21 02:34:51    2706432    ----a-w-    C:\Windows\System32\mshtml.tlb
2013-08-21 02:06:11    1767936    ----a-w-    C:\Windows\SysWow64\wininet.dll
2013-08-21 02:06:06    44032    ----a-w-    C:\Windows\SysWow64\UXInit.dll
2013-08-21 02:05:28    2876928    ----a-w-    C:\Windows\SysWow64\jscript9.dll
2013-08-21 02:05:25    61440    ----a-w-    C:\Windows\SysWow64\iesetup.dll
2013-08-21 02:05:25    109056    ----a-w-    C:\Windows\SysWow64\iesysprep.dll
2013-08-21 01:43:54    2706432    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2013-08-20 23:52:56    534528    ----a-w-    C:\Windows\SysWow64\uxtheme.dll
2013-08-16 05:41:13    58200    ----a-w-    C:\Windows\System32\drivers\dam.sys
2013-08-16 05:39:26    2371728    ----a-w-    C:\Windows\System32\WSService.dll
2013-08-16 05:32:48    209200    ----a-w-    C:\Windows\System32\NotificationUI.exe
2013-08-16 05:22:22    40448    ----a-w-    C:\Windows\System32\wuapp.exe
2013-08-16 05:22:11    4917760    ----a-w-    C:\Windows\System32\sppsvc.exe
2013-08-16 05:20:30    105984    ----a-w-    C:\Windows\System32\WinSetupUI.dll
2013-08-15 22:43:21    35328    ----a-w-    C:\Windows\SysWow64\wuapp.exe
2013-08-15 22:43:07    84992    ----a-w-    C:\Windows\SysWow64\wudriver.dll
2013-08-15 22:43:07    126976    ----a-w-    C:\Windows\SysWow64\wuwebv.dll
2013-08-15 22:43:03    562688    ----a-w-    C:\Windows\SysWow64\WSShared.dll
2013-08-15 22:43:03    159232    ----a-w-    C:\Windows\SysWow64\WSSync.dll
2013-08-15 22:43:02    83968    ----a-w-    C:\Windows\SysWow64\OEMLicense.dll
2013-08-15 22:43:02    167424    ----a-w-    C:\Windows\SysWow64\WSClient.dll
2013-08-15 22:43:02    143872    ----a-w-    C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll
2013-08-15 22:43:02    124928    ----a-w-    C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-08-15 22:42:52    76800    ----a-w-    C:\Windows\SysWow64\setupcln.dll
2013-08-15 22:42:47    91648    ----a-w-    C:\Windows\SysWow64\sppc.dll
2013-08-03 04:30:14    4038144    ----a-w-    C:\Windows\System32\win32k.sys
2013-07-29 01:25:05    21    ----a-w-    C:\Users\Judy\AppData\Roaming\my_intel.sys
2013-07-17 10:05:38    28600    ----a-w-    C:\Windows\System32\drivers\avkmgr.sys
2013-07-16 09:41:26    499712    ----a-w-    C:\Windows\SysWow64\msvcp71.dll
2013-07-16 09:41:26    348160    ----a-w-    C:\Windows\SysWow64\msvcr71.dll
2013-07-13 06:18:21    337408    ----a-w-    C:\Windows\System32\wintrust.dll
2013-07-13 06:16:06    68096    ----a-w-    C:\Windows\System32\cryptsvc.dll
2013-07-13 06:16:06    1889280    ----a-w-    C:\Windows\System32\crypt32.dll
2013-07-13 06:15:53    98304    ----a-w-    C:\Windows\System32\apprepsync.dll
2013-07-13 06:15:53    124416    ----a-w-    C:\Windows\System32\apprepapi.dll
2013-07-13 04:24:58    261120    ----a-w-    C:\Windows\SysWow64\wintrust.dll
2013-07-13 04:23:11    1568256    ----a-w-    C:\Windows\SysWow64\crypt32.dll
2013-07-13 04:23:03    87040    ----a-w-    C:\Windows\SysWow64\apprepapi.dll
2013-07-13 04:23:03    74240    ----a-w-    C:\Windows\SysWow64\apprepsync.dll
2013-07-09 08:04:07    120144    ----a-w-    C:\Windows\System32\drivers\msgpioclx.sys
2013-07-09 06:18:21    439488    ----a-w-    C:\Windows\System32\WerFault.exe
2013-07-09 06:07:17    2233168    ----a-w-    C:\Windows\System32\drivers\tcpip.sys
2013-07-09 04:25:45    385768    ----a-w-    C:\Windows\SysWow64\WerFault.exe
2013-07-09 03:57:19    245760    ----a-w-    C:\Windows\SysWow64\LocationApi.dll
2013-07-08 22:46:00    543744    ----a-w-    C:\Windows\System32\wwanmm.dll
2013-07-08 22:46:00    414208    ----a-w-    C:\Windows\System32\wwanconn.dll
2013-07-08 22:46:00    370688    ----a-w-    C:\Windows\System32\Wwanadvui.dll
2013-07-08 22:45:16    312832    ----a-w-    C:\Windows\System32\LocationApi.dll
.
============= FINISH:  9:30:50.17 ===============

Thank you.

Judy

Link to post
Share on other sites

  • Replies 74
  • Created
  • Last Reply

Top Posters In This Topic

Uninstall the following P2P software:

 

Ares

 

Next,

 

There are two security systems running on your system, Avira and McAfee. I`d recommend that you uninstall one or the other, your choice..

 

Next,

 

Download AdwCleaner by Xplode from here: http://www.bleepingcomputer.com/download/adwcleaner/ and save to your Desktop.

 

  • Double click on AdwCleaner.exe to run the tool.
  • Vista/Windows 7/8 users right-click and select Run As Administrator
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Uncheck any elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review.
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted (if necessary):
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.

 

Next,

 

Download Farbar Recovery Scan Tool and save it to your desktop.

 

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Link to post
Share on other sites

I uninstalled the Ares and I uninstalled the Mcafee.

I downloaded the file adwcleaner but it didn't save to my desktop and now I don't know how to find it :(

I'm somewhat unfamiliar with windows 8 and where to find and run my programs. 

Since I uninstalled the Ares - I haven't gotten any more access messages.

Link to post
Share on other sites

P2P applications and software are notorious for browser hijacking, never use or trust them....

 

Regarding where the downloads went, for Internet explorer open tools > view downloads > a new window will open, that will tell you where the download went. Also in bottom lefthand corner of that window select > options. A new window opens, use the browse function to set where you want downloads to go in future....

 

For Firefox select tools from the menu bar > then downloads. In the new window select the file icon on that download and will open the folder where the download went.

To set where downloads go in future. Select tools from menu bar > then options . In the new window under the General tab you can set your Home page also set where downloads go....

 

Does that help you?

Link to post
Share on other sites

Here is the log file from the adwcleaner:- Please review:

# AdwCleaner v3.006 - Report created 04/10/2013 at 20:20:47
# Updated 01/10/2013 by Xplode
# Operating System : Windows 8  (64 bits)
# Username : Judy - JUDYS
# Running from : C:\Users\Judy\Downloads\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : CltMngSvc
Service Found : DefaultTabUpdate
Service Found : FastFreeConverterUpdt

***** [ Files / Folders ] *****

File Found : C:\END
File Found : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\addon@defaulttab.com.xpi
File Found : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\searchplugins\Conduit.xml
File Found : C:\Users\Judy\Desktop\Optimizer Pro.lnk
File Found : C:\Windows\System32\Tasks\AmiUpdXp
File Found : C:\Windows\Tasks\AmiUpdXp.job
Folder Found : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\{0134af61-7a0c-4649-aeca-90d776060cb3}
Folder Found : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\{1122b43d-30ee-403f-9bfa-3cc99b0caddd}
Folder Found : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\{1122b43d-30ee-403f-9bfa-3cc99b0caddd}
Folder Found : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\tidynetwork@tidynetwork
Folder Found C:\Program Files (x86)\Conduit
Folder Found C:\Program Files (x86)\Fast Free Converter
Folder Found C:\Program Files (x86)\File Type Helper
Folder Found C:\Program Files (x86)\KeyBar_1.12
Folder Found C:\Program Files (x86)\MixiDJ_V30
Folder Found C:\Program Files (x86)\MixiDJ_V30
Folder Found C:\Program Files (x86)\optimizer pro
Folder Found C:\Program Files (x86)\Searchprotect
Folder Found C:\Program Files (x86)\TidyNetwork.com
Folder Found C:\ProgramData\Conduit
Folder Found C:\Users\Judy\AppData\Local\Conduit
Folder Found C:\Users\Judy\AppData\Local\SwvUpdater
Folder Found C:\Users\Judy\AppData\Local\Temp\CT3291325
Folder Found C:\Users\Judy\AppData\Local\Temp\CT3298566
Folder Found C:\Users\Judy\AppData\LocalLow\Conduit
Folder Found C:\Users\Judy\AppData\LocalLow\Fast Free Converter
Folder Found C:\Users\Judy\AppData\LocalLow\KeyBar_1.12
Folder Found C:\Users\Judy\AppData\LocalLow\MixiDJ_V30
Folder Found C:\Users\Judy\AppData\LocalLow\MixiDJ_V30
Folder Found C:\Users\Judy\AppData\Roaming\DefaultTab
Folder Found C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\CT3291325
Folder Found C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\CT3298566
Folder Found C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\StumbleUpon
Folder Found C:\Users\Judy\AppData\Roaming\optimizer pro
Folder Found C:\Users\Judy\AppData\Roaming\Searchprotect
Folder Found C:\Users\Judy\Documents\optimizer pro

***** [ Shortcuts ] *****


***** [ Registry ] *****

Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL
Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\DefaultTab
Key Found : HKCU\Software\AppDataLow\Software\KeyBar_1.12
Key Found : HKCU\Software\AppDataLow\Software\MixiDJ_V30
Key Found : HKCU\Software\AppDataLow\Software\smartbar
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Default Tab
Key Found : HKCU\Software\DefaultTab
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0134AF61-7A0C-4649-AECA-90D776060CB3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}
Key Found : HKCU\Software\Optimizer Pro
Key Found : HKCU\Software\SearchProtect
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\Default Tab
Key Found : [x64] HKCU\Software\DefaultTab
Key Found : [x64] HKCU\Software\Optimizer Pro
Key Found : [x64] HKCU\Software\SearchProtect
Key Found : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Found : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{0134AF61-7A0C-4649-AECA-90D776060CB3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{0A51D53C-6F3C-426E-B789-2A21526E6546}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B422F1BC-9ADB-48A7-8B13-00C176039DC5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DAA6D527-6513-453E-A4E6-DA2BFA6C7A75}
Key Found : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser
Key Found : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser.1
Key Found : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX
Key Found : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1
Key Found : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3291325
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3298566
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\Default Tab
Key Found : HKLM\Software\Fast Free Converter
Key Found : HKLM\Software\KeyBar_1.12
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0AABFDFA-D890-4A0F-8F0E-CAFCBA6997BB}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2A8C2EFC-E397-42A7-85DC-CB59A555A172}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F1764333-7BD4-482F-B285-CB6AED608310}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FD868581-5FF2-45E3-9C6D-8868036EECEC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0134AF61-7A0C-4649-AECA-90D776060CB3}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B422F1BC-9ADB-48A7-8B13-00C176039DC5}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0A51D53C-6F3C-426E-B789-2A21526E6546}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DAA6D527-6513-453E-A4E6-DA2BFA6C7A75}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fast Free Converter
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Found : HKLM\Software\MixiDJ_V30
Key Found : HKLM\Software\SearchProtect
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0134AF61-7A0C-4649-AECA-90D776060CB3}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}]
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Optimizer Pro]
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [searchProtect]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{0134AF61-7A0C-4649-AECA-90D776060CB3}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{0134AF61-7A0C-4649-AECA-90D776060CB3}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{1122B43D-30EE-403F-9BFA-3CC99B0CADDD}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [searchProtectAll]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [extension@FastFreeConverter.com]

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16688



-\\ Mozilla Firefox v24.0 (en-US)

[ File : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\prefs.js ]

Line Found : user_pref("CT3291325.FF19Solved", "true");
Line Found : user_pref("CT3291325.UserID", "UN21321490703165473");
Line Found : user_pref("CT3291325.browser.search.defaultthis.engineName", "true");
Line Found : user_pref("CT3291325.fullUserID", "UN21321490703165473.IN.20131004194818");
Line Found : user_pref("CT3291325.installDate", "04/10/2013 19:48:29");
Line Found : user_pref("CT3291325.installSessionId", "{06705A9B-36BB-4A37-B6AD-316E6BCC20B0}");
Line Found : user_pref("CT3291325.installSp", "TRUE");
Line Found : user_pref("CT3291325.installerVersion", "1.7.101.1");
Line Found : user_pref("CT3291325.keyword", "true");


Line Found : user_pref("CT3291325.originalSearchEngine", "MixiDJ V30 Customized Web Search");
Line Found : user_pref("CT3291325.originalSearchEngineName", "MixiDJ V30 Customized Web Search");
Line Found : user_pref("CT3291325.searchRevert", "false");
Line Found : user_pref("CT3291325.searchUserMode", "2");
Line Found : user_pref("CT3291325.smartbar.homepage", "true");
Line Found : user_pref("CT3291325.versionFromInstaller", "10.20.103.6");
Line Found : user_pref("CT3291325.xpeMode", "0");
Line Found : user_pref("CT3298566.FF19Solved", "true");
Line Found : user_pref("CT3298566.UserID", "UN42223595572937915");
Line Found : user_pref("CT3298566.browser.search.defaultthis.engineName", "true");
Line Found : user_pref("CT3298566.fullUserID", "UN42223595572937915.IN.20131004130715");
Line Found : user_pref("CT3298566.installDate", "04/10/2013 13:07:21");
Line Found : user_pref("CT3298566.installSessionId", "{BACEF4DA-45EE-48BA-BCBF-432AB8AB92D6}");
Line Found : user_pref("CT3298566.installSp", "TRUE");
Line Found : user_pref("CT3298566.installerVersion", "1.7.1.7");
Line Found : user_pref("CT3298566.keyword", "true");

Line Found : user_pref("CT3298566.originalSearchAddressUrl", "");
Line Found : user_pref("CT3298566.originalSearchEngine", "");
Line Found : user_pref("CT3298566.originalSearchEngineName", "");
Line Found : user_pref("CT3298566.searchRevert", "false");
Line Found : user_pref("CT3298566.searchUserMode", "2");
Line Found : user_pref("CT3298566.smartbar.homepage", "true");
Line Found : user_pref("CT3298566.versionFromInstaller", "10.20.1.8");
Line Found : user_pref("CT3298566.xpeMode", "0");


Line Found : user_pref("browser.search.defaultenginename", "KeyBar 1.12 Customized Web Search");
Line Found : user_pref("browser.search.defaultthis.engineName", "KeyBar 1.12 Customized Web Search");

Line Found : user_pref("browser.search.selectedEngine", "KeyBar 1.12 Customized Web Search");

Line Found : user_pref("extensions.sahtb.searchEngineNameCurrent", "KeyBar 1.12 Customized Web Search");
Line Found : user_pref("extensions.sahtb.searchEngineNameSAH", "Web Search");


Line Found : user_pref("smartbar.addressBarOwnerCTID", "CT3291325");


Line Found : user_pref("smartbar.defaultSearchOwnerCTID", "CT3291325");
Line Found : user_pref("smartbar.homePageOwnerCTID", "CT3291325");
Line Found : user_pref("smartbar.machineId", "RCAUN2SWLROIMNCYWW6AUPLKUTL8AZCWRQEUX3PT+PFLLX6KTHGWOPP9/6P5AZZQLDAZ6WQZOMHJ+J5J+PKO9W");

Line Found : user_pref("smartbar.pciMachineID", "PCI\\VEN_10EC&DEV_8168&SUBSYS_14F71043&REV_0A\\4&9EA52C7&0&02E3");
Line Found : user_pref("smartbar.plainMachineId", "50:46:5D:96:22:6EBFEBFBFF000206A7");

*************************

AdwCleaner[R0].txt - [15957 octets] - [04/10/2013 20:20:47]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [16018 octets] ##########
 

Link to post
Share on other sites

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by Judy (administrator) on JUDYS on 05-10-2013 05:37:38
Running from C:\Users\Judy\Downloads
Windows 8 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
() C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSWinService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(BrowserSafeguard) C:\Program Files (x86)\Browsersafeguard\BrowserSafeguard.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSPanel.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSService.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Whilokii) C:\Program Files (x86)\Whilokii\updateWhilokii.exe
(Systweak) C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\loggingserver.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
() C:\Users\Judy\Downloads\ZipExtractorSetup.exe
() C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
() C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe
() C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe
(MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [AuditSHD] - C:\windows\system32\oobe\auditshd.exe [31232 2012-07-25] (Microsoft Corporation)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-20] (Realtek Semiconductor)
HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS)
HKLM-x32\...\Runonce: [Del574046] - cmd.exe /Q /D /c del "C:\Users\Judy\AppData\Local\Temp\0.del" [x]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [OV3_Monitor] - -NoStart
HKCU\...\Run: [ares] - "C:\Program Files (x86)\Ares\Ares.exe" -h
HKCU\...\Run: [browserSafeguard] - C:\Program Files (x86)\Browsersafeguard\Browsersafeguard.exe [565248 2013-10-01] (BrowserSafeguard)
HKCU\...\Runonce: [Del574046] - cmd.exe /Q /D /c del "C:\Users\Judy\AppData\Local\Temp\0.del"
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-08-04] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.6.112\AsusWSPanel.exe /S
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2013-07-16] (RealNetworks, Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-29] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [WebStorage] - C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\ASUSWSLoader.exe [56640 2013-06-26] ()
HKLM-x32\...\Run: [OV3_Monitor] - C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe [55656 2013-07-29] (OLYMPUS IMAGING CORP.)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2404376 2013-10-05] ()
AppInit_DLLs:   [2404376 2013-10-05] ()
AppInit_DLLs-x32: c:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll c:\progra~2\optimi~1\optpro~1.dll [ ] ()
Startup: C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
Startup: C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:49204;https=127.0.0.1:49204
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=FEE21E85DE70412C&affID=125026&tsp=5026
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=FEE21E85DE70412C&affID=125026&tsp=5026
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={7DFBE9DB-CFE3-49CF-BD36-98E02E569CFE}&mid=755cfbcc63a547d39d30810f1b72cb9d-0ac5f548f87773ae34739c06f1e58a3fc1be2c1d〈=en&ds=co011&coid=avgtbdisco&pr=sa&d=2013-10-05 05:22:48&v=17.0.0.12&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {A0A9FFC7-089A-4BBD-9471-F64126B6A6CE} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3291325&CUI=UN23043998551441928&UM=2
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Whilokii - {204df522-9a96-4a72-abb0-60f7a216d6d2} - C:\Program Files (x86)\Whilokii\Whilokiibho.dll (Whilokii)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO-x32: searchgol Helper Object - {8F547BDD-FCD4-48F8-A06F-573D6F404A3C} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\bh\searchgol.dll (Montera Technologeis LTD)
BHO-x32: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.0.0.12\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
BHO-x32: Fast Free Converter 4.1 - {C3E50543-BC36-4C80-8070-38A97E02DEB2} - C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\FastFreeConverter.dll (Fast Free Converter)
BHO-x32: GreatArcadeHits Add-on - {D0C21091-FF8E-432C-9006-0540E81BA9D7} - C:\Users\Judy\AppData\Local\GreatArcadeHits\GreatArcadeHitsIE.dll (GreatArcadeHits)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.0.0.12\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKLM-x32 - searchgol Toolbar - {00078E95-3A4A-4137-8DE7-2824908D1C17} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\searchgolTlbr.dll (Montera Technologeis LTD)
Toolbar: HKCU -  No Name - {41564952-412D-5637-00A7-7A786E7484D7} -  No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll (AVG Secure Search)

FireFox:
========
FF ProfilePath: C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default
FF user.js: detected! => C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\user.js
FF NewTab: about:blank
FF DefaultSearchEngine: AVG Secure Search
FF SelectedSearchEngine: AVG Secure Search

FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.12\\npsitesafety.dll (AVG Technologies)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.2.32 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.2.32 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF SearchPlugin: C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\searchplugins\safeguard-secure-search.xml
FF SearchPlugin: C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\searchplugins\searchgol.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml
FF Extension: No Name - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\ffxtlbr@babylon.com
FF Extension: SearchGol - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\ffxtlbr@searchgol.com
FF Extension: ShopAtHome.com Toolbar - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\toolbar@shopathome.com
FF Extension: firefox - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\firefox@whilokii.net.xpi
FF Extension: pricepeep - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\pricepeep@getpricepeep.com.xpi
FF Extension: toolbar_AVIRA-V7 - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
FF Extension: No Name - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi
FF HKLM-x32\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.0.0.12
FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.0.0.12
FF HKLM-x32\...\Firefox\Extensions: [extension@FastFreeConverter.com] - C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\extension@FastFreeConverter.com
FF Extension: Fast Free Converter - C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\extension@FastFreeConverter.com
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKCU\...\Firefox\Extensions: [{B21F5E31-B8E8-41CD-B74C-168A71A10E49}] - C:\Users\Judy\AppData\Local\GreatArcadeHits\gahff.xpi
FF Extension: No Name - C:\Users\Judy\AppData\Local\GreatArcadeHits\gahff.xpi

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-29] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-29] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [815160 2013-08-29] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSWinService.exe [71680 2013-06-26] ()
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [38440 2013-09-19] (Just Develop It)
R2 BitGuard; C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [2845664 2013-09-23] ()
R2 FastFreeConverterUpdt; C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe [687104 2012-11-26] ()
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
R2 Update Whilokii; C:\Program Files (x86)\Whilokii\updateWhilokii.exe [65304 2013-10-04] (Whilokii)
R2 vToolbarUpdater17.0.12; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe [1734680 2013-10-05] (AVG Secure Search)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-01] (Microsoft Corporation)
S2 70e6ca8c; "c:\progra~2\optimi~1\OptProCrash.exe" [x]

==================== Drivers (Whitelisted) ====================

R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-08-29] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132088 2013-08-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [82136 2013-08-29] (Avira Operations GmbH & Co. KG)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-01] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
U0 msahci;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-05 05:36 - 2013-10-05 05:36 - 01954124 _____ (Farbar) C:\Users\Judy\Downloads\FRST64.exe
2013-10-05 05:36 - 2013-10-05 05:36 - 00000000 ____D C:\FRST
2013-10-05 05:33 - 2013-10-05 05:33 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
2013-10-05 05:32 - 2013-10-05 05:32 - 00003378 _____ C:\Windows\System32\Tasks\EPUpdater
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\Users\Judy\AppData\Roaming\BabSolution
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\ProgramData\BitGuard
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\Program Files (x86)\searchgol
2013-10-05 05:31 - 2013-10-05 05:31 - 00000002 _____ C:\END
2013-10-05 05:31 - 2013-10-05 05:31 - 00000000 ____D C:\Program Files (x86)\File Type Helper
2013-10-05 05:31 - 2013-10-05 05:31 - 00000000 ____D C:\Program Files (x86)\Fast Free Converter
2013-10-05 05:30 - 2013-10-05 05:30 - 00000000 ____D C:\ProgramData\Babylon
2013-10-05 05:27 - 2013-10-05 05:33 - 00001089 _____ C:\Users\Judy\Desktop\MyPC Backup.lnk
2013-10-05 05:27 - 2013-10-05 05:33 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2013-10-05 05:27 - 2013-10-05 05:27 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-10-05 05:23 - 2013-10-05 05:24 - 00000000 ____D C:\Users\Judy\AppData\Local\AVG SafeGuard toolbar
2013-10-05 05:22 - 2013-10-05 05:22 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2013-10-05 05:22 - 2013-10-05 05:22 - 00003746 _____ C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2013-10-05 05:22 - 2013-10-05 05:22 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-10-05 05:22 - 2013-10-05 05:22 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2013-10-05 05:21 - 2013-10-05 05:21 - 00003120 _____ C:\Windows\System32\Tasks\Advanced System Protector_startup
2013-10-05 05:21 - 2013-10-05 05:21 - 00001203 _____ C:\Users\Public\Desktop\Advanced System Protector.lnk
2013-10-05 05:21 - 2013-10-05 05:21 - 00000000 ____D C:\ProgramData\Systweak
2013-10-05 05:21 - 2013-10-05 05:21 - 00000000 ____D C:\Program Files (x86)\Advanced System Protector
2013-10-05 05:21 - 2012-07-25 12:03 - 00016896 _____ C:\Windows\system32\sasnative64.exe
2013-10-05 05:20 - 2013-10-05 05:21 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Systweak
2013-10-05 05:20 - 2013-10-05 05:20 - 00003310 _____ C:\Windows\System32\Tasks\Advanced System Protector
2013-10-05 05:20 - 2013-10-05 05:20 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
2013-10-05 05:20 - 2013-10-05 05:20 - 00003008 _____ C:\Windows\System32\Tasks\RegClean Pro_UPDATES
2013-10-05 05:20 - 2013-10-05 05:20 - 00002852 _____ C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
2013-10-05 05:20 - 2013-10-05 05:20 - 00001052 _____ C:\Users\Public\Desktop\RegClean Pro.lnk
2013-10-05 05:20 - 2013-10-05 05:20 - 00000294 _____ C:\Windows\Tasks\RegClean Pro_UPDATES.job
2013-10-05 05:20 - 2013-10-05 05:20 - 00000286 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2013-10-05 05:20 - 2013-10-05 05:20 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
2013-10-05 05:20 - 2013-07-22 16:07 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe
2013-10-05 05:19 - 2013-10-05 05:30 - 00001112 _____ C:\Users\Public\Desktop\Open It!.lnk
2013-10-05 05:19 - 2013-10-05 05:19 - 00003102 _____ C:\Windows\System32\Tasks\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000280 _____ C:\Windows\Tasks\GreatArcadeHits.job
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Users\Judy\AppData\Local\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\Whilokii
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\PricePeep
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\OpenIt
2013-10-05 05:18 - 2013-10-05 05:29 - 00002638 _____ C:\Windows\System32\Tasks\DigitalSite
2013-10-05 05:18 - 2013-10-05 05:29 - 00000300 _____ C:\Windows\Tasks\DigitalSite.job
2013-10-05 05:18 - 2013-10-05 05:18 - 00000000 ____D C:\Users\Judy\AppData\Roaming\DigitalSite
2013-10-05 05:16 - 2013-10-05 05:16 - 00749248 _____ C:\Users\Judy\Downloads\ZipExtractorSetup.exe
2013-10-04 20:19 - 2013-10-05 05:08 - 00000000 ____D C:\AdwCleaner
2013-10-04 20:19 - 2013-10-04 20:19 - 01045226 _____ C:\Users\Judy\Downloads\AdwCleaner.exe
2013-10-04 19:49 - 2013-10-04 19:49 - 00000258 __RSH C:\Users\Judy\ntuser.pol
2013-10-04 13:09 - 2013-10-04 19:46 - 00000000 ____D C:\Program Files (x86)\Browsersafeguard
2013-10-04 13:09 - 2013-10-04 13:09 - 00003850 _____ C:\Windows\System32\Tasks\BrowserSafeguard Update Task
2013-10-04 13:05 - 2013-10-04 13:05 - 02059560 _____ (ExpressInstaller) C:\Users\Judy\Desktop\Setup.exe
2013-10-04 09:31 - 2013-10-04 20:01 - 00021919 _____ C:\Users\Judy\Desktop\dds.txt
2013-10-04 09:31 - 2013-10-04 20:01 - 00003207 _____ C:\Users\Judy\Desktop\attach.txt
2013-10-04 09:27 - 2013-10-04 09:27 - 00688992 ____R (Swearware) C:\Users\Judy\Downloads\dds.scr
2013-09-19 08:58 - 2013-09-19 08:58 - 00000000 ____D C:\Users\Judy\Documents\ASUS
2013-09-18 07:39 - 2013-10-05 05:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-15 20:49 - 2013-09-15 20:49 - 00000193 _____ C:\Windows\WORDPAD.INI
2013-09-15 20:43 - 2013-09-15 20:43 - 00001131 _____ C:\Users\Judy\Desktop\OLYMPUS Viewer 3.lnk
2013-09-15 20:43 - 2013-09-15 20:43 - 00000000 ____D C:\OLYMPUS
2013-09-15 20:18 - 2013-09-15 20:34 - 101288296 _____ (OLYMPUS IMAGING CORP.) C:\Users\Judy\Downloads\OV3Setup(1).exe
2013-09-15 16:12 - 2013-09-15 16:12 - 00298952 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-15 15:53 - 2013-09-15 15:53 - 00184053 _____ C:\Users\Judy\Desktop\beachcombing photo.htm
2013-09-14 09:25 - 2013-09-15 15:25 - 97671483 _____ C:\Windows\SysWOW64\윯ꡪLø
2013-09-11 13:31 - 2013-08-07 01:15 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2013-09-11 03:41 - 2013-08-16 01:41 - 00058200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys
2013-09-11 03:41 - 2013-08-16 01:39 - 02371728 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2013-09-11 03:41 - 2013-08-16 01:39 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2013-09-11 03:41 - 2013-08-16 01:32 - 00209200 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2013-09-11 03:41 - 2013-08-16 01:22 - 04917760 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2013-09-11 03:41 - 2013-08-16 01:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2013-09-11 03:41 - 2013-08-16 01:21 - 03275776 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 01621504 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WSSync.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2013-09-11 03:41 - 2013-08-16 01:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00083968 _____ C:\Windows\SysWOW64\OEMLicense.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-09-11 03:41 - 2013-08-15 18:43 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2013-09-11 03:41 - 2013-08-15 18:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll
2013-09-11 03:41 - 2013-08-15 18:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll
2013-09-11 03:38 - 2013-08-21 00:12 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-11 03:38 - 2013-08-21 00:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-11 03:38 - 2013-08-21 00:11 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-11 03:38 - 2013-08-20 22:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-11 03:38 - 2013-08-20 22:06 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-11 03:38 - 2013-08-20 22:06 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-11 03:38 - 2013-08-20 22:06 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-11 03:38 - 2013-08-20 21:43 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-11 03:38 - 2013-08-20 19:52 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2013-09-11 03:37 - 2013-07-09 02:18 - 00439488 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2013-09-11 03:37 - 2013-07-09 00:25 - 00385768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2013-09-11 03:37 - 2013-07-08 18:46 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2013-09-11 03:37 - 2013-07-05 20:16 - 01025024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2013-09-11 03:37 - 2013-07-02 20:23 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2013-09-11 03:37 - 2013-07-02 20:22 - 02839552 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2013-09-11 03:37 - 2013-07-02 20:22 - 01300480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-09-11 03:37 - 2013-07-02 20:11 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2013-09-11 03:37 - 2013-07-02 20:10 - 02273792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2013-09-11 03:37 - 2013-06-29 01:43 - 00327512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2013-09-11 03:37 - 2013-06-24 18:54 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2013-09-11 03:37 - 2013-06-19 01:36 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\winmmbase.dll
2013-09-11 03:37 - 2013-06-19 01:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll
2013-09-11 03:37 - 2013-06-18 18:38 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll
2013-09-11 03:37 - 2013-06-11 19:26 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2013-09-11 03:37 - 2013-06-10 15:15 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-09-11 03:37 - 2013-06-10 15:15 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2013-09-11 03:37 - 2013-06-10 15:15 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-09-11 03:36 - 2013-08-03 00:30 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-11 03:36 - 2013-07-09 04:04 - 00120144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpioclx.sys
2013-09-11 03:36 - 2013-07-08 23:57 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll
2013-09-11 03:36 - 2013-07-08 18:46 - 00543744 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll
2013-09-11 03:36 - 2013-07-08 18:46 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Wwanadvui.dll
2013-09-11 03:36 - 2013-07-08 18:45 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll
2013-09-11 03:36 - 2013-07-02 20:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2013-09-11 03:36 - 2013-07-02 20:11 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-09-11 03:36 - 2013-07-01 18:08 - 00387583 _____ C:\Windows\system32\ApnDatabase.xml
2013-09-11 03:36 - 2013-06-30 18:30 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\openfiles.exe
2013-09-11 03:36 - 2013-06-30 18:29 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\openfiles.exe
2013-09-11 03:36 - 2013-06-29 02:15 - 00195416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2013-09-11 03:36 - 2013-06-29 02:15 - 00125784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2013-09-11 03:36 - 2013-06-28 21:12 - 01022464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-09-11 03:36 - 2013-06-25 23:01 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2013-09-11 03:36 - 2013-06-25 22:59 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2013-09-11 03:36 - 2013-06-24 18:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-09-11 03:36 - 2013-06-24 18:54 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2013-09-11 03:36 - 2013-06-18 18:38 - 00160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmmbase.dll
2013-09-11 03:36 - 2013-06-11 19:43 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2013-09-11 03:36 - 2013-06-10 17:17 - 00096512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2013-09-11 03:36 - 2013-06-10 15:16 - 00888832 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-09-11 03:36 - 2013-06-10 15:10 - 00702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-09-11 03:36 - 2013-06-10 15:10 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-09-11 03:36 - 2013-06-06 04:03 - 00119040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2013-09-06 08:48 - 2013-10-05 05:10 - 00000384 _____ C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Judy.job
2013-09-06 08:48 - 2013-10-05 03:07 - 00002940 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Judy
2013-09-06 08:48 - 2013-10-05 03:07 - 00000378 _____ C:\Windows\Tasks\ReclaimerUpdateFiles_Judy.job
2013-09-06 08:48 - 2013-10-04 09:13 - 00002936 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Judy
2013-09-06 08:48 - 2013-10-04 09:13 - 00000374 _____ C:\Windows\Tasks\ReclaimerUpdateXML_Judy.job
2013-09-06 08:48 - 2013-09-06 08:48 - 00003602 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Judy
2013-09-06 08:48 - 2013-09-06 08:48 - 00002644 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Judy

==================== One Month Modified Files and Folders =======

2013-10-05 05:36 - 2013-10-05 05:36 - 01954124 _____ (Farbar) C:\Users\Judy\Downloads\FRST64.exe
2013-10-05 05:36 - 2013-10-05 05:36 - 00000000 ____D C:\FRST
2013-10-05 05:33 - 2013-10-05 05:33 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
2013-10-05 05:33 - 2013-10-05 05:27 - 00001089 _____ C:\Users\Judy\Desktop\MyPC Backup.lnk
2013-10-05 05:33 - 2013-10-05 05:27 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2013-10-05 05:33 - 2013-09-18 07:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-05 05:32 - 2013-10-05 05:32 - 00003378 _____ C:\Windows\System32\Tasks\EPUpdater
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\Users\Judy\AppData\Roaming\BabSolution
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\ProgramData\BitGuard
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\Program Files (x86)\searchgol
2013-10-05 05:31 - 2013-10-05 05:31 - 00000002 _____ C:\END
2013-10-05 05:31 - 2013-10-05 05:31 - 00000000 ____D C:\Program Files (x86)\File Type Helper
2013-10-05 05:31 - 2013-10-05 05:31 - 00000000 ____D C:\Program Files (x86)\Fast Free Converter
2013-10-05 05:30 - 2013-10-05 05:30 - 00000000 ____D C:\ProgramData\Babylon
2013-10-05 05:30 - 2013-10-05 05:19 - 00001112 _____ C:\Users\Public\Desktop\Open It!.lnk
2013-10-05 05:29 - 2013-10-05 05:18 - 00002638 _____ C:\Windows\System32\Tasks\DigitalSite
2013-10-05 05:29 - 2013-10-05 05:18 - 00000300 _____ C:\Windows\Tasks\DigitalSite.job
2013-10-05 05:27 - 2013-10-05 05:27 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-10-05 05:27 - 2013-07-12 14:02 - 00000000 ___RD C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-05 05:24 - 2013-10-05 05:23 - 00000000 ____D C:\Users\Judy\AppData\Local\AVG SafeGuard toolbar
2013-10-05 05:22 - 2013-10-05 05:22 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2013-10-05 05:22 - 2013-10-05 05:22 - 00003746 _____ C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2013-10-05 05:22 - 2013-10-05 05:22 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-10-05 05:22 - 2013-10-05 05:22 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2013-10-05 05:22 - 2013-07-13 19:23 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-05 05:21 - 2013-10-05 05:21 - 00003120 _____ C:\Windows\System32\Tasks\Advanced System Protector_startup
2013-10-05 05:21 - 2013-10-05 05:21 - 00001203 _____ C:\Users\Public\Desktop\Advanced System Protector.lnk
2013-10-05 05:21 - 2013-10-05 05:21 - 00000000 ____D C:\ProgramData\Systweak
2013-10-05 05:21 - 2013-10-05 05:21 - 00000000 ____D C:\Program Files (x86)\Advanced System Protector
2013-10-05 05:21 - 2013-10-05 05:20 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Systweak
2013-10-05 05:20 - 2013-10-05 05:20 - 00003310 _____ C:\Windows\System32\Tasks\Advanced System Protector
2013-10-05 05:20 - 2013-10-05 05:20 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
2013-10-05 05:20 - 2013-10-05 05:20 - 00003008 _____ C:\Windows\System32\Tasks\RegClean Pro_UPDATES
2013-10-05 05:20 - 2013-10-05 05:20 - 00002852 _____ C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
2013-10-05 05:20 - 2013-10-05 05:20 - 00001052 _____ C:\Users\Public\Desktop\RegClean Pro.lnk
2013-10-05 05:20 - 2013-10-05 05:20 - 00000294 _____ C:\Windows\Tasks\RegClean Pro_UPDATES.job
2013-10-05 05:20 - 2013-10-05 05:20 - 00000286 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2013-10-05 05:20 - 2013-10-05 05:20 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
2013-10-05 05:19 - 2013-10-05 05:19 - 00003102 _____ C:\Windows\System32\Tasks\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000280 _____ C:\Windows\Tasks\GreatArcadeHits.job
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Users\Judy\AppData\Local\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\Whilokii
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\PricePeep
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\OpenIt
2013-10-05 05:18 - 2013-10-05 05:18 - 00000000 ____D C:\Users\Judy\AppData\Roaming\DigitalSite
2013-10-05 05:16 - 2013-10-05 05:16 - 00749248 _____ C:\Users\Judy\Downloads\ZipExtractorSetup.exe
2013-10-05 05:14 - 2012-07-26 03:28 - 00848230 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-05 05:12 - 2013-08-09 15:03 - 00000000 ____D C:\Users\Judy\AppData\Roaming\WebStorage
2013-10-05 05:11 - 2013-07-16 05:42 - 00003332 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-251038213-2808898551-1881861744-1001
2013-10-05 05:11 - 2013-07-16 05:42 - 00003196 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-251038213-2808898551-1881861744-1001
2013-10-05 05:11 - 2013-07-12 14:02 - 00000428 _____ C:\Users\Judy\AppData\Roaming\sp_data.sys
2013-10-05 05:10 - 2013-09-06 08:48 - 00000384 _____ C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Judy.job
2013-10-05 05:10 - 2012-12-19 19:46 - 00000868 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-10-05 05:09 - 2012-08-01 21:20 - 00022028 _____ C:\Windows\PFRO.log
2013-10-05 05:09 - 2012-07-26 03:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-05 05:08 - 2013-10-04 20:19 - 00000000 ____D C:\AdwCleaner
2013-10-05 05:08 - 2012-07-26 01:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2013-10-05 05:02 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\system32\sru
2013-10-05 03:25 - 2013-07-12 13:59 - 01440623 _____ C:\Windows\WindowsUpdate.log
2013-10-05 03:07 - 2013-09-06 08:48 - 00002940 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Judy
2013-10-05 03:07 - 2013-09-06 08:48 - 00000378 _____ C:\Windows\Tasks\ReclaimerUpdateFiles_Judy.job
2013-10-04 20:19 - 2013-10-04 20:19 - 01045226 _____ C:\Users\Judy\Downloads\AdwCleaner.exe
2013-10-04 20:01 - 2013-10-04 09:31 - 00021919 _____ C:\Users\Judy\Desktop\dds.txt
2013-10-04 20:01 - 2013-10-04 09:31 - 00003207 _____ C:\Users\Judy\Desktop\attach.txt
2013-10-04 19:49 - 2013-10-04 19:49 - 00000258 __RSH C:\Users\Judy\ntuser.pol
2013-10-04 19:49 - 2013-07-12 13:59 - 00000000 ____D C:\Users\Judy
2013-10-04 19:49 - 2012-07-26 04:12 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-10-04 19:49 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2013-10-04 19:46 - 2013-10-04 13:09 - 00000000 ____D C:\Program Files (x86)\Browsersafeguard
2013-10-04 13:38 - 2013-07-12 14:08 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-251038213-2808898551-1881861744-1001
2013-10-04 13:09 - 2013-10-04 13:09 - 00003850 _____ C:\Windows\System32\Tasks\BrowserSafeguard Update Task
2013-10-04 13:05 - 2013-10-04 13:05 - 02059560 _____ (ExpressInstaller) C:\Users\Judy\Desktop\Setup.exe
2013-10-04 13:00 - 2012-08-04 22:25 - 00000000 ____D C:\ProgramData\McAfee
2013-10-04 12:59 - 2013-07-12 14:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-04 12:57 - 2012-07-26 04:12 - 00000000 ___HD C:\Windows\ELAMBKUP
2013-10-04 11:01 - 2012-12-19 19:46 - 00000870 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2013-10-04 09:27 - 2013-10-04 09:27 - 00688992 ____R (Swearware) C:\Users\Judy\Downloads\dds.scr
2013-10-04 09:13 - 2013-09-06 08:48 - 00002936 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Judy
2013-10-04 09:13 - 2013-09-06 08:48 - 00000374 _____ C:\Windows\Tasks\ReclaimerUpdateXML_Judy.job
2013-10-03 13:53 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-09-19 08:58 - 2013-09-19 08:58 - 00000000 ____D C:\Users\Judy\Documents\ASUS
2013-09-19 08:58 - 2013-07-12 14:00 - 00000000 ____D C:\Users\Judy\AppData\Local\VirtualStore
2013-09-19 08:58 - 2013-07-12 13:59 - 00000000 ____D C:\Users\Judy\AppData\Local\ASUS
2013-09-18 19:26 - 2013-07-16 04:56 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-18 19:26 - 2013-07-16 04:56 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-18 17:16 - 2013-07-12 14:14 - 00000000 ____D C:\Users\Judy\AppData\Local\Mozilla
2013-09-15 21:19 - 2013-08-22 06:41 - 00021504 _____ C:\Users\Judy\Desktop\linkouture feature.odt
2013-09-15 20:49 - 2013-09-15 20:49 - 00000193 _____ C:\Windows\WORDPAD.INI
2013-09-15 20:43 - 2013-09-15 20:43 - 00001131 _____ C:\Users\Judy\Desktop\OLYMPUS Viewer 3.lnk
2013-09-15 20:43 - 2013-09-15 20:43 - 00000000 ____D C:\OLYMPUS
2013-09-15 20:43 - 2013-07-12 18:37 - 00000000 ____D C:\Program Files (x86)\OLYMPUS
2013-09-15 20:34 - 2013-09-15 20:18 - 101288296 _____ (OLYMPUS IMAGING CORP.) C:\Users\Judy\Downloads\OV3Setup(1).exe
2013-09-15 16:12 - 2013-09-15 16:12 - 00298952 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-15 15:53 - 2013-09-15 15:53 - 00184053 _____ C:\Users\Judy\Desktop\beachcombing photo.htm
2013-09-15 15:25 - 2013-09-14 09:25 - 97671483 _____ C:\Windows\SysWOW64\윯ꡪLø
2013-09-14 08:06 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\rescache
2013-09-14 05:50 - 2012-07-26 01:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2013-09-14 04:46 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\WinStore
2013-09-14 04:46 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-09-14 04:46 - 2012-07-26 01:38 - 00000000 ____D C:\Windows\system32\oobe
2013-09-11 04:26 - 2013-08-13 23:36 - 00000000 ____D C:\Windows\system32\MRT
2013-09-11 04:24 - 2013-07-13 15:36 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-10 12:23 - 2013-07-13 19:23 - 00003718 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-06 08:48 - 2013-09-06 08:48 - 00003602 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Judy
2013-09-06 08:48 - 2013-09-06 08:48 - 00002644 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Judy
2013-09-06 05:47 - 2013-07-16 05:40 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Real
2013-09-06 05:47 - 2013-07-16 05:34 - 00000000 ____D C:\ProgramData\Real

Some content of TEMP:
====================
C:\Users\Judy\AppData\Local\Temp\BackupSetup.exe
C:\Users\Judy\AppData\Local\Temp\checktbexist.exe
C:\Users\Judy\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Judy\AppData\Local\Temp\helper.exe
C:\Users\Judy\AppData\Local\Temp\mconduitinstaller.exe
C:\Users\Judy\AppData\Local\Temp\MouseKeyboardCenterx64_1033.exe
C:\Users\Judy\AppData\Local\Temp\newsetup.exe
C:\Users\Judy\AppData\Local\Temp\nsc6D08.exe
C:\Users\Judy\AppData\Local\Temp\nsd53FD.exe
C:\Users\Judy\AppData\Local\Temp\nsj49D8.exe
C:\Users\Judy\AppData\Local\Temp\nsmA79B.exe
C:\Users\Judy\AppData\Local\Temp\nsn617C.exe
C:\Users\Judy\AppData\Local\Temp\nsq49B7.exe
C:\Users\Judy\AppData\Local\Temp\nsrCC9B.exe
C:\Users\Judy\AppData\Local\Temp\nsu52E2.exe
C:\Users\Judy\AppData\Local\Temp\oi_{AABF4922-3F40-417A-9057-2B0B438863B7}.exe
C:\Users\Judy\AppData\Local\Temp\Quarantine.exe
C:\Users\Judy\AppData\Local\Temp\SPStub.exe
C:\Users\Judy\AppData\Local\Temp\sqlite3.exe
C:\Users\Judy\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\Judy\AppData\Local\Temp\vcredist_x64.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-09-30 03:00

==================== End Of Log ============================

 

Error: (10/05/2013 05:38:34 AM) (Source: Application Error) (User: )
Description: Faulting application name: RealPlay.exe, version: 16.0.2.32, time stamp: 0x516dab77
Faulting module name: bitguard.dll, version: 2.6.1694.246, time stamp: 0x52402c3e
Exception code: 0xc0000005
Fault offset: 0x0017966f
Faulting process id: 0xd98
Faulting application start time: 0xRealPlay.exe0
Faulting application path: RealPlay.exe1
Faulting module path: RealPlay.exe2
Report Id: RealPlay.exe3
Faulting package full name: RealPlay.exe4
Faulting package-relative application ID: RealPlay.exe5

Error: (10/05/2013 05:37:35 AM) (Source: Application Error) (User: )
Description: Faulting application name: RealPlay.exe, version: 16.0.2.32, time stamp: 0x516dab77
Faulting module name: bitguard.dll, version: 2.6.1694.246, time stamp: 0x52402c3e
Exception code: 0xc0000005
Fault offset: 0x0017966f
Faulting process id: 0x8c4
Faulting application start time: 0xRealPlay.exe0
Faulting application path: RealPlay.exe1
Faulting module path: RealPlay.exe2
Report Id: RealPlay.exe3
Faulting package full name: RealPlay.exe4
Faulting package-relative application ID: RealPlay.exe5

Error: (10/05/2013 05:37:33 AM) (Source: Application Error) (User: )
Description: Faulting application name: RealPlay.exe, version: 16.0.2.32, time stamp: 0x516dab77
Faulting module name: bitguard.dll, version: 2.6.1694.246, time stamp: 0x52402c3e
Exception code: 0xc0000005
Fault offset: 0x0017966f
Faulting process id: 0x8c4
Faulting application start time: 0xRealPlay.exe0
Faulting application path: RealPlay.exe1
Faulting module path: RealPlay.exe2
Report Id: RealPlay.exe3
Faulting package full name: RealPlay.exe4
Faulting package-relative application ID: RealPlay.exe5

Error: (10/05/2013 05:35:35 AM) (Source: Application Error) (User: )
Description: Faulting application name: RealPlay.exe, version: 16.0.2.32, time stamp: 0x516dab77
Faulting module name: bitguard.dll, version: 2.6.1694.246, time stamp: 0x52402c3e
Exception code: 0xc0000005
Fault offset: 0x0017966f
Faulting process id: 0xb88
Faulting application start time: 0xRealPlay.exe0
Faulting application path: RealPlay.exe1
Faulting module path: RealPlay.exe2
Report Id: RealPlay.exe3
Faulting package full name: RealPlay.exe4
Faulting package-relative application ID: RealPlay.exe5

Error: (10/05/2013 05:35:33 AM) (Source: Application Error) (User: )
Description: Faulting application name: RealPlay.exe, version: 16.0.2.32, time stamp: 0x516dab77
Faulting module name: bitguard.dll, version: 2.6.1694.246, time stamp: 0x52402c3e
Exception code: 0xc0000005
Fault offset: 0x0017966f
Faulting process id: 0xb88
Faulting application start time: 0xRealPlay.exe0
Faulting application path: RealPlay.exe1
Faulting module path: RealPlay.exe2
Report Id: RealPlay.exe3
Faulting package full name: RealPlay.exe4
Faulting package-relative application ID: RealPlay.exe5

Error: (10/05/2013 05:34:35 AM) (Source: Application Error) (User: )
Description: Faulting application name: RealPlay.exe, version: 16.0.2.32, time stamp: 0x516dab77
Faulting module name: bitguard.dll, version: 2.6.1694.246, time stamp: 0x52402c3e
Exception code: 0xc0000005
Fault offset: 0x0017966f
Faulting process id: 0x1788
Faulting application start time: 0xRealPlay.exe0
Faulting application path: RealPlay.exe1
Faulting module path: RealPlay.exe2
Report Id: RealPlay.exe3
Faulting package full name: RealPlay.exe4
Faulting package-relative application ID: RealPlay.exe5

Error: (10/05/2013 05:34:33 AM) (Source: Application Error) (User: )
Description: Faulting application name: RealPlay.exe, version: 16.0.2.32, time stamp: 0x516dab77
Faulting module name: bitguard.dll, version: 2.6.1694.246, time stamp: 0x52402c3e
Exception code: 0xc0000005
Fault offset: 0x0017966f
Faulting process id: 0x1788
Faulting application start time: 0xRealPlay.exe0
Faulting application path: RealPlay.exe1
Faulting module path: RealPlay.exe2
Report Id: RealPlay.exe3
Faulting package full name: RealPlay.exe4
Faulting package-relative application ID: RealPlay.exe5

Error: (10/05/2013 05:33:38 AM) (Source: Application Error) (User: )
Description: Faulting application name: RealPlay.exe, version: 16.0.2.32, time stamp: 0x516dab77
Faulting module name: bitguard.dll, version: 2.6.1694.246, time stamp: 0x52402c3e
Exception code: 0xc0000005
Fault offset: 0x0017966f
Faulting process id: 0x8c0
Faulting application start time: 0xRealPlay.exe0
Faulting application path: RealPlay.exe1
Faulting module path: RealPlay.exe2
Report Id: RealPlay.exe3
Faulting package full name: RealPlay.exe4
Faulting package-relative application ID: RealPlay.exe5

Error: (10/05/2013 05:33:34 AM) (Source: Application Error) (User: )
Description: Faulting application name: RealPlay.exe, version: 16.0.2.32, time stamp: 0x516dab77
Faulting module name: bitguard.dll, version: 2.6.1694.246, time stamp: 0x52402c3e
Exception code: 0xc0000005
Fault offset: 0x0017966f
Faulting process id: 0x8c0
Faulting application start time: 0xRealPlay.exe0
Faulting application path: RealPlay.exe1
Faulting module path: RealPlay.exe2
Report Id: RealPlay.exe3
Faulting package full name: RealPlay.exe4
Faulting package-relative application ID: RealPlay.exe5


System errors:
=============
Error: (10/05/2013 05:31:13 AM) (Source: Service Control Manager) (User: )
Description: The FastFreeConverterUpdt service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Error: (10/04/2013 07:50:30 PM) (Source: Service Control Manager) (User: )
Description: The FastFreeConverterUpdt service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Error: (10/04/2013 01:01:24 PM) (Source: Service Control Manager) (User: )
Description: The Asus WebStorage Windows Service service hung on starting.

Error: (09/15/2013 04:17:50 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: {3A185DDE-E020-4985-A8F2-E27CDC4A0F3A}

Error: (09/15/2013 04:14:09 PM) (Source: Service Control Manager) (User: )
Description: The Avira Web Protection service terminated with the following service-specific error:
%%1

Error: (09/15/2013 04:13:12 PM) (Source: Service Control Manager) (User: )
Description: The avnetflt service failed to start due to the following error:
%%5

Error: (09/15/2013 04:12:56 PM) (Source: Service Control Manager) (User: )
Description: The avgntflt service failed to start due to the following error:
%%5

Error: (09/15/2013 04:12:56 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 3:44:28 PM on ‎9/‎15/‎2013 was unexpected.

Error: (09/14/2013 05:49:10 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: {3A185DDE-E020-4985-A8F2-E27CDC4A0F3A}

Error: (09/14/2013 05:45:35 AM) (Source: Service Control Manager) (User: )
Description: The Avira Web Protection service terminated with the following service-specific error:
%%1


Microsoft Office Sessions:
=========================
Error: (10/05/2013 05:38:36 AM) (Source: Application Error)(User: )
Description: RealPlay.exe16.0.2.32516dab77bitguard.dll2.6.1694.24652402c3ec00000050017966fd9801cec1aea86e3e0eC:\Program Files (x86)\Real\RealPlayer\RealPlay.exec:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dlle7edcca1-2da1-11e3-be8a-50465d96226e

Error: (10/05/2013 05:38:34 AM) (Source: Application Error)(User: )
Description: RealPlay.exe16.0.2.32516dab77bitguard.dll2.6.1694.24652402c3ec00000050017966fd9801cec1aea86e3e0eC:\Program Files (x86)\Real\RealPlayer\RealPlay.exec:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dlle6bbf2ba-2da1-11e3-be8a-50465d96226e

Error: (10/05/2013 05:37:35 AM) (Source: Application Error)(User: )
Description: RealPlay.exe16.0.2.32516dab77bitguard.dll2.6.1694.24652402c3ec00000050017966f8c401cec1ae84a6cacfC:\Program Files (x86)\Real\RealPlayer\RealPlay.exec:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dllc3c9ad00-2da1-11e3-be8a-50465d96226e

Error: (10/05/2013 05:37:33 AM) (Source: Application Error)(User: )
Description: RealPlay.exe16.0.2.32516dab77bitguard.dll2.6.1694.24652402c3ec00000050017966f8c401cec1ae84a6cacfC:\Program Files (x86)\Real\RealPlayer\RealPlay.exec:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dllc2961979-2da1-11e3-be8a-50465d96226e

Error: (10/05/2013 05:35:35 AM) (Source: Application Error)(User: )
Description: RealPlay.exe16.0.2.32516dab77bitguard.dll2.6.1694.24652402c3ec00000050017966fb8801cec1ae3d21c5b8C:\Program Files (x86)\Real\RealPlayer\RealPlay.exec:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll7c35cf50-2da1-11e3-be8a-50465d96226e

Error: (10/05/2013 05:35:33 AM) (Source: Application Error)(User: )
Description: RealPlay.exe16.0.2.32516dab77bitguard.dll2.6.1694.24652402c3ec00000050017966fb8801cec1ae3d21c5b8C:\Program Files (x86)\Real\RealPlayer\RealPlay.exec:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll7af0e2ac-2da1-11e3-be8a-50465d96226e

Error: (10/05/2013 05:34:35 AM) (Source: Application Error)(User: )
Description: RealPlay.exe16.0.2.32516dab77bitguard.dll2.6.1694.24652402c3ec00000050017966f178801cec1ae195e7a7cC:\Program Files (x86)\Real\RealPlayer\RealPlay.exec:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll5876ca7f-2da1-11e3-be8a-50465d96226e

Error: (10/05/2013 05:34:33 AM) (Source: Application Error)(User: )
Description: RealPlay.exe16.0.2.32516dab77bitguard.dll2.6.1694.24652402c3ec00000050017966f178801cec1ae195e7a7cC:\Program Files (x86)\Real\RealPlayer\RealPlay.exec:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll572e33ae-2da1-11e3-be8a-50465d96226e

Error: (10/05/2013 05:33:38 AM) (Source: Application Error)(User: )
Description: RealPlay.exe16.0.2.32516dab77bitguard.dll2.6.1694.24652402c3ec00000050017966f8c001cec1adf59d525bC:\Program Files (x86)\Real\RealPlayer\RealPlay.exec:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll3647d1e4-2da1-11e3-be8a-50465d96226e

Error: (10/05/2013 05:33:34 AM) (Source: Application Error)(User: )
Description: RealPlay.exe16.0.2.32516dab77bitguard.dll2.6.1694.24652402c3ec00000050017966f8c001cec1adf59d525bC:\Program Files (x86)\Real\RealPlayer\RealPlay.exec:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll33c8cfe0-2da1-11e3-be8a-50465d96226e


==================== Memory info ===========================

Percentage of memory in use: 44%
Total physical RAM: 3979.82 MB
Available physical RAM: 2204.79 MB
Total Pagefile: 9611.82 MB
Available Pagefile: 7541.99 MB
Total Virtual: 8192 MB
Available Virtual: 8191.77 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:119.23 GB) (Free:70.53 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: (Data) (Fixed) (Total:157.84 GB) (Free:157.73 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 298 GB) (Disk ID: 16FCC5F2)

Partition: GPT Partition Type
==================== End Of Log ============================

Link to post
Share on other sites

Download attached fixlist.txt file and save it to the Desktop, or the folder you saved FRST into.

NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

 

Run FRST/FRST64 and press the Fix button just once and wait.

The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

 

Next,

 

Run Malwarebytes, check for updates then run a quick scan. Post that log.

 

Next,

 

Download Dr Web Cureit from here http://www.freedrweb.com/cureit save to your desktop. (Scroll to bottom of page)

 

  • The file will be randomly named
  • Reboot to safe mode
  • Run Dr Web
  • Tick the I agree box and select continue
  • Click select objects for scanning
     
    drwebselect.JPG
     
  • Tick all boxes as shown
  • Click the wrench and select automatically apply actions to threats
     
    drwebfolders.JPG
     
  • Press start scan
  • The scan will now commence
     
    drwebscan.JPG
     
  • Once the scan has finished click open report
     
    drwebscancomplete.JPG
     
  • A notepad will open
  • Select File > Save as..
  • Save it to your desktop

 

Attach the log to your next reply…

 

Kevin

fixlist.txt

Link to post
Share on other sites

Is this what I was suppose to get?  Didn;t seem to run anything just a log file:

Start
HKLM-x32\...\Runonce: [Del574046] - cmd.exe /Q /D /c del "C:\Users\Judy\AppData\Local\Temp\0.del" [x]
HKCU\...\Run: [ares] - "C:\Program Files (x86)\Ares\Ares.exe" -h
HKCU\...\Run: [browserSafeguard] - C:\Program Files (x86)\Browsersafeguard\Browsersafeguard.exe [565248 2013-10-01] (BrowserSafeguard)
HKCU\...\Runonce: [Del574046] - cmd.exe /Q /D /c del "C:\Users\Judy\AppData\Local\Temp\0.del"
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchgol...125026&tsp=5026
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.searchgol...125026&tsp=5026
Toolbar: HKLM-x32 - searchgol Toolbar - {00078E95-3A4A-4137-8DE7-2824908D1C17} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\searchgolTlbr.dll (Montera Technologeis LTD)
Toolbar: HKCU -  No Name - {41564952-412D-5637-00A7-7A786E7484D7} -  No File
FF Extension: No Name - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\ffxtlbr@babylon.com
FF Extension: SearchGol - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\ffxtlbr@searchgol.com
FF Extension: ShopAtHome.com Toolbar - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\toolbar@shopathome.com
FF Extension: No Name - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi
FF HKCU\...\Firefox\Extensions: [{B21F5E31-B8E8-41CD-B74C-168A71A10E49}] - C:\Users\Judy\AppData\Local\GreatArcadeHits\gahff.xpi
FF Extension: No Name - C:\Users\Judy\AppData\Local\GreatArcadeHits\gahff.xpi
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.)
R2 BitGuard; C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [2845664 2013-09-23] ()
S2 70e6ca8c; "c:\progra~2\optimi~1\OptProCrash.exe" [x]
U0 msahci;
C:\Program Files (x86)\Ares
C:\Program Files (x86)\Browsersafeguard
C:\Program Files (x86)\AskPartnerNetwork
C:\ProgramData\BitGuard
C:\Users\Judy\AppData\Local\Temp\BackupSetup.exe
C:\Users\Judy\AppData\Local\Temp\checktbexist.exe
C:\Users\Judy\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Judy\AppData\Local\Temp\helper.exe
C:\Users\Judy\AppData\Local\Temp\mconduitinstaller.exe
C:\Users\Judy\AppData\Local\Temp\MouseKeyboardCenterx64_1033.exe
C:\Users\Judy\AppData\Local\Temp\newsetup.exe
C:\Users\Judy\AppData\Local\Temp\nsc6D08.exe
C:\Users\Judy\AppData\Local\Temp\nsd53FD.exe
C:\Users\Judy\AppData\Local\Temp\nsj49D8.exe
C:\Users\Judy\AppData\Local\Temp\nsmA79B.exe
C:\Users\Judy\AppData\Local\Temp\nsn617C.exe
C:\Users\Judy\AppData\Local\Temp\nsq49B7.exe
C:\Users\Judy\AppData\Local\Temp\nsrCC9B.exe
C:\Users\Judy\AppData\Local\Temp\nsu52E2.exe
C:\Users\Judy\AppData\Local\Temp\oi_{AABF4922-3F40-417A-9057-2B0B438863B7}.exe
C:\Users\Judy\AppData\Local\Temp\Quarantine.exe
C:\Users\Judy\AppData\Local\Temp\SPStub.exe
C:\Users\Judy\AppData\Local\Temp\sqlite3.exe
C:\Users\Judy\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\Judy\AppData\Local\Temp\vcredist_x64.exe
End
 

I now have an AVG search page on firefox and I'm getting a browser change notice asking if I want to approve change.  It doesn't identify as from my avira - what should I do with that?

Link to post
Share on other sites

Did you set up the proxy?? If not, reset the browsers:

 

Check for proxy server settings in your browser, the following are the most common used.

 

Internet Explorer:

Tools Menu -> Internet Options  -> Connections Tab ->Lan Settings > uncheck "use a proxy server" and check to "Automatically detect settings". Also clear any proxy address and port. ok, apply (only if applicable), ok.

Firefox:

Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection. "No Proxy" should be selected, unless you have one set up yourself.

 

Chrome:

Select -> Tools menu ->  then "Options", then  go to "Change Proxy Settings", then "LAN Settings" , then  take out the check mark for "Use a proxy server for your LAN" if set, unless you set this up yourself.

 

Safari


Launch Safari
Go to general settings menu
Then in Preferences/ Advanced
Then on line click Proxies change settings ...
Click Internet Options, then click the Connections tab, click Network Settings.
Disable option (uncheck) for the use of proxy server ...

Link to post
Share on other sites

Is this the log from that FRST program:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-10-2013
Ran by Judy at 2013-10-05 07:56:23 Run:1
Running from C:\Users\Judy\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKLM-x32\...\Runonce: [Del574046] - cmd.exe /Q /D /c del "C:\Users\Judy\AppData\Local\Temp\0.del" [x]
HKCU\...\Run: [ares] - "C:\Program Files (x86)\Ares\Ares.exe" -h
HKCU\...\Run: [browserSafeguard] - C:\Program Files (x86)\Browsersafeguard\Browsersafeguard.exe [565248 2013-10-01] (BrowserSafeguard)
HKCU\...\Runonce: [Del574046] - cmd.exe /Q /D /c del "C:\Users\Judy\AppData\Local\Temp\0.del"
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchgol...125026&tsp=5026
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.searchgol...125026&tsp=5026
Toolbar: HKLM-x32 - searchgol Toolbar - {00078E95-3A4A-4137-8DE7-2824908D1C17} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\searchgolTlbr.dll (Montera Technologeis LTD)
Toolbar: HKCU -  No Name - {41564952-412D-5637-00A7-7A786E7484D7} -  No File
FF Extension: No Name - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\ffxtlbr@babylon.com
FF Extension: SearchGol - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\ffxtlbr@searchgol.com
FF Extension: ShopAtHome.com Toolbar - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\toolbar@shopathome.com
FF Extension: No Name - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi
FF HKCU\...\Firefox\Extensions: [{B21F5E31-B8E8-41CD-B74C-168A71A10E49}] - C:\Users\Judy\AppData\Local\GreatArcadeHits\gahff.xpi
FF Extension: No Name - C:\Users\Judy\AppData\Local\GreatArcadeHits\gahff.xpi
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.)
R2 BitGuard; C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [2845664 2013-09-23] ()
S2 70e6ca8c; "c:\progra~2\optimi~1\OptProCrash.exe" [x]
U0 msahci;
C:\Program Files (x86)\Ares
C:\Program Files (x86)\Browsersafeguard
C:\Program Files (x86)\AskPartnerNetwork
C:\ProgramData\BitGuard
C:\Users\Judy\AppData\Local\Temp\BackupSetup.exe
C:\Users\Judy\AppData\Local\Temp\checktbexist.exe
C:\Users\Judy\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Judy\AppData\Local\Temp\helper.exe
C:\Users\Judy\AppData\Local\Temp\mconduitinstaller.exe
C:\Users\Judy\AppData\Local\Temp\MouseKeyboardCenterx64_1033.exe
C:\Users\Judy\AppData\Local\Temp\newsetup.exe
C:\Users\Judy\AppData\Local\Temp\nsc6D08.exe
C:\Users\Judy\AppData\Local\Temp\nsd53FD.exe
C:\Users\Judy\AppData\Local\Temp\nsj49D8.exe
C:\Users\Judy\AppData\Local\Temp\nsmA79B.exe
C:\Users\Judy\AppData\Local\Temp\nsn617C.exe
C:\Users\Judy\AppData\Local\Temp\nsq49B7.exe
C:\Users\Judy\AppData\Local\Temp\nsrCC9B.exe
C:\Users\Judy\AppData\Local\Temp\nsu52E2.exe
C:\Users\Judy\AppData\Local\Temp\oi_{AABF4922-3F40-417A-9057-2B0B438863B7}.exe
C:\Users\Judy\AppData\Local\Temp\Quarantine.exe
C:\Users\Judy\AppData\Local\Temp\SPStub.exe
C:\Users\Judy\AppData\Local\Temp\sqlite3.exe
C:\Users\Judy\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\Judy\AppData\Local\Temp\vcredist_x64.exe
End

*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\Del574046 => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ares => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\BrowserSafeguard => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Del574046 => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ApnTBMon => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{00078E95-3A4A-4137-8DE7-2824908D1C17} => Value deleted successfully.
HKCR\Wow6432Node\CLSID\{00078E95-3A4A-4137-8DE7-2824908D1C17} => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{41564952-412D-5637-00A7-7A786E7484D7} => Value deleted successfully.
HKCR\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found.
C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\ffxtlbr@babylon.com not found.
C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\ffxtlbr@searchgol.com => Moved successfully.
C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\toolbar@shopathome.com => Moved successfully.
C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi => Moved successfully.
HKCU\Software\Mozilla\Firefox\Extensions\\{B21F5E31-B8E8-41CD-B74C-168A71A10E49} => Value deleted successfully.
C:\Users\Judy\AppData\Local\GreatArcadeHits\gahff.xpi => Moved successfully.
APNMCP => Service deleted successfully.
BitGuard => Service deleted successfully.
70e6ca8c => Service deleted successfully.
msahci => Service deleted successfully.
"C:\Program Files (x86)\Ares" => File/Directory not found.
C:\Program Files (x86)\Browsersafeguard => Moved successfully.
C:\Program Files (x86)\AskPartnerNetwork => Moved successfully.

"C:\ProgramData\BitGuard" directory move:

Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.settings" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\bl" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\dm" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\uninstall.exe" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\00" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\01" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\02" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\03" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\10" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\11" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\12" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\13" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\20" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\21" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\22" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\23" => Scheduled to move on reboot.
Could not move "C:\ProgramData\BitGuard" directory. => Scheduled to move on reboot.

C:\Users\Judy\AppData\Local\Temp\BackupSetup.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\checktbexist.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\fp_pl_pfs_installer.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\helper.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\mconduitinstaller.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\MouseKeyboardCenterx64_1033.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\newsetup.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\nsc6D08.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\nsd53FD.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\nsj49D8.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\nsmA79B.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\nsn617C.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\nsq49B7.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\nsrCC9B.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\nsu52E2.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\oi_{AABF4922-3F40-417A-9057-2B0B438863B7}.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\SPStub.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\sqlite3.exe => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\System.Data.SQLite.dll => Moved successfully.
C:\Users\Judy\AppData\Local\Temp\vcredist_x64.exe => Moved successfully.

=========== Result of Scheduled Files to move ===========

"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.settings" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\bl" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\dm" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\uninstall.exe" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\00" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\01" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\02" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\03" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\10" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\11" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\12" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\13" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\20" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\21" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\22" => File could not move.
"C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\23" => File could not move.
"C:\ProgramData\BitGuard" => Directory could not move.

==== End of Fixlog ====

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by Judy (administrator) on JUDYS on 05-10-2013 07:51:56
Running from C:\Users\Judy\Downloads
Windows 8 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
() C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSWinService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(BrowserSafeguard) C:\Program Files (x86)\Browsersafeguard\BrowserSafeguard.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSPanel.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSService.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Whilokii) C:\Program Files (x86)\Whilokii\updateWhilokii.exe
(Systweak) C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\loggingserver.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
() C:\Users\Judy\Downloads\ZipExtractorSetup.exe
() C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe
() C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe
() C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe
(MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RealPlay.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [AuditSHD] - C:\windows\system32\oobe\auditshd.exe [31232 2012-07-25] (Microsoft Corporation)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-20] (Realtek Semiconductor)
HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS)
HKLM-x32\...\Runonce: [Del574046] - cmd.exe /Q /D /c del "C:\Users\Judy\AppData\Local\Temp\0.del" [x]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [OV3_Monitor] - -NoStart
HKCU\...\Run: [ares] - "C:\Program Files (x86)\Ares\Ares.exe" -h
HKCU\...\Run: [browserSafeguard] - C:\Program Files (x86)\Browsersafeguard\Browsersafeguard.exe [565248 2013-10-01] (BrowserSafeguard)
HKCU\...\Runonce: [Del574046] - cmd.exe /Q /D /c del "C:\Users\Judy\AppData\Local\Temp\0.del"
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-08-04] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.6.112\AsusWSPanel.exe /S
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2013-07-16] (RealNetworks, Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-29] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [WebStorage] - C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\ASUSWSLoader.exe [56640 2013-06-26] ()
HKLM-x32\...\Run: [OV3_Monitor] - C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe [55656 2013-07-29] (OLYMPUS IMAGING CORP.)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2404376 2013-10-05] ()
AppInit_DLLs:   [2404376 2013-10-05] ()
AppInit_DLLs-x32: c:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll c:\progra~2\optimi~1\optpro~1.dll [ ] ()
Startup: C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
Startup: C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:49204;https=127.0.0.1:49204
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=FEE21E85DE70412C&affID=125026&tsp=5026
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=FEE21E85DE70412C&affID=125026&tsp=5026
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={7DFBE9DB-CFE3-49CF-BD36-98E02E569CFE}&mid=755cfbcc63a547d39d30810f1b72cb9d-0ac5f548f87773ae34739c06f1e58a3fc1be2c1d〈=en&ds=co011&coid=avgtbdisco&pr=sa&d=2013-10-05 05:22:48&v=17.0.0.12&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {A0A9FFC7-089A-4BBD-9471-F64126B6A6CE} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3291325&CUI=UN23043998551441928&UM=2
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Whilokii - {204df522-9a96-4a72-abb0-60f7a216d6d2} - C:\Program Files (x86)\Whilokii\Whilokiibho.dll (Whilokii)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO-x32: searchgol Helper Object - {8F547BDD-FCD4-48F8-A06F-573D6F404A3C} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\bh\searchgol.dll (Montera Technologeis LTD)
BHO-x32: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.0.0.12\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
BHO-x32: Fast Free Converter 4.1 - {C3E50543-BC36-4C80-8070-38A97E02DEB2} - C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\FastFreeConverter.dll (Fast Free Converter)
BHO-x32: GreatArcadeHits Add-on - {D0C21091-FF8E-432C-9006-0540E81BA9D7} - C:\Users\Judy\AppData\Local\GreatArcadeHits\GreatArcadeHitsIE.dll (GreatArcadeHits)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.0.0.12\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKLM-x32 - searchgol Toolbar - {00078E95-3A4A-4137-8DE7-2824908D1C17} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\searchgolTlbr.dll (Montera Technologeis LTD)
Toolbar: HKCU -  No Name - {41564952-412D-5637-00A7-7A786E7484D7} -  No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll (AVG Secure Search)

FireFox:
========
FF ProfilePath: C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default
FF user.js: detected! => C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\user.js

FF DefaultSearchEngine: AVG Secure Search
FF SelectedSearchEngine: AVG Secure Search

FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.12\\npsitesafety.dll (AVG Technologies)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.2.32 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.2.32 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF SearchPlugin: C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\searchplugins\safeguard-secure-search.xml
FF SearchPlugin: C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\searchplugins\searchgol.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml
FF Extension: SearchGol - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\ffxtlbr@searchgol.com
FF Extension: ShopAtHome.com Toolbar - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\toolbar@shopathome.com
FF Extension: firefox - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\firefox@whilokii.net.xpi
FF Extension: pricepeep - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\pricepeep@getpricepeep.com.xpi
FF Extension: toolbar_AVIRA-V7 - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
FF Extension: No Name - C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\chwmmje5.default\Extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi
FF HKLM-x32\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.0.0.12
FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.0.0.12
FF HKLM-x32\...\Firefox\Extensions: [extension@FastFreeConverter.com] - C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\extension@FastFreeConverter.com
FF Extension: Fast Free Converter - C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\extension@FastFreeConverter.com
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKCU\...\Firefox\Extensions: [{B21F5E31-B8E8-41CD-B74C-168A71A10E49}] - C:\Users\Judy\AppData\Local\GreatArcadeHits\gahff.xpi
FF Extension: No Name - C:\Users\Judy\AppData\Local\GreatArcadeHits\gahff.xpi

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-29] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-29] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [815160 2013-08-29] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.0.1.213\AsusWSWinService.exe [71680 2013-06-26] ()
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [38440 2013-09-19] (Just Develop It)
R2 BitGuard; C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [2845664 2013-09-23] ()
R2 FastFreeConverterUpdt; C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe [687104 2012-11-26] ()
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
R2 Update Whilokii; C:\Program Files (x86)\Whilokii\updateWhilokii.exe [65304 2013-10-04] (Whilokii)
R2 vToolbarUpdater17.0.12; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe [1734680 2013-10-05] (AVG Secure Search)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-01] (Microsoft Corporation)
S2 70e6ca8c; "c:\progra~2\optimi~1\OptProCrash.exe" [x]

==================== Drivers (Whitelisted) ====================

R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-08-29] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132088 2013-08-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-07-17] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [82136 2013-08-29] (Avira Operations GmbH & Co. KG)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-01] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
U0 msahci;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-05 07:01 - 2013-10-05 07:01 - 00003283 _____ C:\Users\Judy\Downloads\fixlist.txt
2013-10-05 06:29 - 2013-10-05 06:29 - 00000091 _____ C:\Users\Judy\AppData\Roaming\WB.CFG
2013-10-05 06:29 - 2013-10-05 06:29 - 00000006 _____ C:\Users\Judy\AppData\Roaming\WBPU-TTL.DAT
2013-10-05 05:39 - 2013-10-05 05:40 - 00026246 _____ C:\Users\Judy\Downloads\Addition.txt
2013-10-05 05:36 - 2013-10-05 05:36 - 01954124 _____ (Farbar) C:\Users\Judy\Downloads\FRST64.exe
2013-10-05 05:36 - 2013-10-05 05:36 - 00000000 ____D C:\FRST
2013-10-05 05:33 - 2013-10-05 05:33 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
2013-10-05 05:32 - 2013-10-05 05:32 - 00003378 _____ C:\Windows\System32\Tasks\EPUpdater
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\Users\Judy\AppData\Roaming\BabSolution
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\ProgramData\BitGuard
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\Program Files (x86)\searchgol
2013-10-05 05:31 - 2013-10-05 05:31 - 00000002 _____ C:\END
2013-10-05 05:31 - 2013-10-05 05:31 - 00000000 ____D C:\Program Files (x86)\File Type Helper
2013-10-05 05:31 - 2013-10-05 05:31 - 00000000 ____D C:\Program Files (x86)\Fast Free Converter
2013-10-05 05:30 - 2013-10-05 05:30 - 00000000 ____D C:\ProgramData\Babylon
2013-10-05 05:27 - 2013-10-05 05:33 - 00001089 _____ C:\Users\Judy\Desktop\MyPC Backup.lnk
2013-10-05 05:27 - 2013-10-05 05:33 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2013-10-05 05:27 - 2013-10-05 05:27 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-10-05 05:23 - 2013-10-05 05:24 - 00000000 ____D C:\Users\Judy\AppData\Local\AVG SafeGuard toolbar
2013-10-05 05:22 - 2013-10-05 05:22 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2013-10-05 05:22 - 2013-10-05 05:22 - 00003746 _____ C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2013-10-05 05:22 - 2013-10-05 05:22 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-10-05 05:22 - 2013-10-05 05:22 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2013-10-05 05:21 - 2013-10-05 05:21 - 00003120 _____ C:\Windows\System32\Tasks\Advanced System Protector_startup
2013-10-05 05:21 - 2013-10-05 05:21 - 00001203 _____ C:\Users\Public\Desktop\Advanced System Protector.lnk
2013-10-05 05:21 - 2013-10-05 05:21 - 00000000 ____D C:\ProgramData\Systweak
2013-10-05 05:21 - 2013-10-05 05:21 - 00000000 ____D C:\Program Files (x86)\Advanced System Protector
2013-10-05 05:21 - 2012-07-25 12:03 - 00016896 _____ C:\Windows\system32\sasnative64.exe
2013-10-05 05:20 - 2013-10-05 05:21 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Systweak
2013-10-05 05:20 - 2013-10-05 05:20 - 00003310 _____ C:\Windows\System32\Tasks\Advanced System Protector
2013-10-05 05:20 - 2013-10-05 05:20 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
2013-10-05 05:20 - 2013-10-05 05:20 - 00003008 _____ C:\Windows\System32\Tasks\RegClean Pro_UPDATES
2013-10-05 05:20 - 2013-10-05 05:20 - 00002852 _____ C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
2013-10-05 05:20 - 2013-10-05 05:20 - 00001052 _____ C:\Users\Public\Desktop\RegClean Pro.lnk
2013-10-05 05:20 - 2013-10-05 05:20 - 00000294 _____ C:\Windows\Tasks\RegClean Pro_UPDATES.job
2013-10-05 05:20 - 2013-10-05 05:20 - 00000286 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2013-10-05 05:20 - 2013-10-05 05:20 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
2013-10-05 05:20 - 2013-07-22 16:07 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe
2013-10-05 05:19 - 2013-10-05 07:49 - 00000280 _____ C:\Windows\Tasks\GreatArcadeHits.job
2013-10-05 05:19 - 2013-10-05 05:30 - 00001112 _____ C:\Users\Public\Desktop\Open It!.lnk
2013-10-05 05:19 - 2013-10-05 05:19 - 00003102 _____ C:\Windows\System32\Tasks\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Users\Judy\AppData\Local\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\Whilokii
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\PricePeep
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\OpenIt
2013-10-05 05:18 - 2013-10-05 07:29 - 00000300 _____ C:\Windows\Tasks\DigitalSite.job
2013-10-05 05:18 - 2013-10-05 05:29 - 00002638 _____ C:\Windows\System32\Tasks\DigitalSite
2013-10-05 05:18 - 2013-10-05 05:18 - 00000000 ____D C:\Users\Judy\AppData\Roaming\DigitalSite
2013-10-05 05:16 - 2013-10-05 05:16 - 00749248 _____ C:\Users\Judy\Downloads\ZipExtractorSetup.exe
2013-10-04 20:19 - 2013-10-05 05:08 - 00000000 ____D C:\AdwCleaner
2013-10-04 20:19 - 2013-10-04 20:19 - 01045226 _____ C:\Users\Judy\Downloads\AdwCleaner.exe
2013-10-04 19:49 - 2013-10-04 19:49 - 00000258 __RSH C:\Users\Judy\ntuser.pol
2013-10-04 13:09 - 2013-10-04 19:46 - 00000000 ____D C:\Program Files (x86)\Browsersafeguard
2013-10-04 13:09 - 2013-10-04 13:09 - 00003850 _____ C:\Windows\System32\Tasks\BrowserSafeguard Update Task
2013-10-04 13:05 - 2013-10-04 13:05 - 02059560 _____ (ExpressInstaller) C:\Users\Judy\Desktop\Setup.exe
2013-10-04 09:31 - 2013-10-04 20:01 - 00021919 _____ C:\Users\Judy\Desktop\dds.txt
2013-10-04 09:31 - 2013-10-04 20:01 - 00003207 _____ C:\Users\Judy\Desktop\attach.txt
2013-10-04 09:27 - 2013-10-04 09:27 - 00688992 ____R (Swearware) C:\Users\Judy\Downloads\dds.scr
2013-09-19 08:58 - 2013-09-19 08:58 - 00000000 ____D C:\Users\Judy\Documents\ASUS
2013-09-18 07:39 - 2013-10-05 05:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-15 20:49 - 2013-09-15 20:49 - 00000193 _____ C:\Windows\WORDPAD.INI
2013-09-15 20:43 - 2013-09-15 20:43 - 00001131 _____ C:\Users\Judy\Desktop\OLYMPUS Viewer 3.lnk
2013-09-15 20:43 - 2013-09-15 20:43 - 00000000 ____D C:\OLYMPUS
2013-09-15 20:18 - 2013-09-15 20:34 - 101288296 _____ (OLYMPUS IMAGING CORP.) C:\Users\Judy\Downloads\OV3Setup(1).exe
2013-09-15 16:12 - 2013-09-15 16:12 - 00298952 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-15 15:53 - 2013-09-15 15:53 - 00184053 _____ C:\Users\Judy\Desktop\beachcombing photo.htm
2013-09-14 09:25 - 2013-09-15 15:25 - 97671483 _____ C:\Windows\SysWOW64\윯ꡪLø
2013-09-11 13:31 - 2013-08-07 01:15 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2013-09-11 03:41 - 2013-08-16 01:41 - 00058200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys
2013-09-11 03:41 - 2013-08-16 01:39 - 02371728 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2013-09-11 03:41 - 2013-08-16 01:39 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2013-09-11 03:41 - 2013-08-16 01:32 - 00209200 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2013-09-11 03:41 - 2013-08-16 01:22 - 04917760 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2013-09-11 03:41 - 2013-08-16 01:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2013-09-11 03:41 - 2013-08-16 01:21 - 03275776 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 01621504 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WSSync.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2013-09-11 03:41 - 2013-08-16 01:21 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2013-09-11 03:41 - 2013-08-16 01:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00083968 _____ C:\Windows\SysWOW64\OEMLicense.dll
2013-09-11 03:41 - 2013-08-15 18:43 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-09-11 03:41 - 2013-08-15 18:43 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2013-09-11 03:41 - 2013-08-15 18:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll
2013-09-11 03:41 - 2013-08-15 18:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll
2013-09-11 03:38 - 2013-08-21 00:12 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-11 03:38 - 2013-08-21 00:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-11 03:38 - 2013-08-21 00:11 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-11 03:38 - 2013-08-21 00:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-11 03:38 - 2013-08-20 22:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-11 03:38 - 2013-08-20 22:06 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-11 03:38 - 2013-08-20 22:06 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-11 03:38 - 2013-08-20 22:06 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-11 03:38 - 2013-08-20 22:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-11 03:38 - 2013-08-20 21:43 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-11 03:38 - 2013-08-20 19:52 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2013-09-11 03:37 - 2013-07-09 02:18 - 00439488 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2013-09-11 03:37 - 2013-07-09 00:25 - 00385768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2013-09-11 03:37 - 2013-07-08 18:46 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2013-09-11 03:37 - 2013-07-05 20:16 - 01025024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2013-09-11 03:37 - 2013-07-02 20:23 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2013-09-11 03:37 - 2013-07-02 20:22 - 02839552 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2013-09-11 03:37 - 2013-07-02 20:22 - 01300480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-09-11 03:37 - 2013-07-02 20:11 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2013-09-11 03:37 - 2013-07-02 20:10 - 02273792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2013-09-11 03:37 - 2013-06-29 01:43 - 00327512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2013-09-11 03:37 - 2013-06-24 18:54 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2013-09-11 03:37 - 2013-06-19 01:36 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\winmmbase.dll
2013-09-11 03:37 - 2013-06-19 01:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll
2013-09-11 03:37 - 2013-06-18 18:38 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll
2013-09-11 03:37 - 2013-06-11 19:26 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2013-09-11 03:37 - 2013-06-10 15:15 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-09-11 03:37 - 2013-06-10 15:15 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2013-09-11 03:37 - 2013-06-10 15:15 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-09-11 03:36 - 2013-08-03 00:30 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-11 03:36 - 2013-07-09 04:04 - 00120144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpioclx.sys
2013-09-11 03:36 - 2013-07-08 23:57 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll
2013-09-11 03:36 - 2013-07-08 18:46 - 00543744 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll
2013-09-11 03:36 - 2013-07-08 18:46 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Wwanadvui.dll
2013-09-11 03:36 - 2013-07-08 18:45 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll
2013-09-11 03:36 - 2013-07-02 20:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2013-09-11 03:36 - 2013-07-02 20:11 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-09-11 03:36 - 2013-07-01 18:08 - 00387583 _____ C:\Windows\system32\ApnDatabase.xml
2013-09-11 03:36 - 2013-06-30 18:30 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\openfiles.exe
2013-09-11 03:36 - 2013-06-30 18:29 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\openfiles.exe
2013-09-11 03:36 - 2013-06-29 02:15 - 00195416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2013-09-11 03:36 - 2013-06-29 02:15 - 00125784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2013-09-11 03:36 - 2013-06-28 21:12 - 01022464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-09-11 03:36 - 2013-06-25 23:01 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2013-09-11 03:36 - 2013-06-25 22:59 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2013-09-11 03:36 - 2013-06-24 18:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-09-11 03:36 - 2013-06-24 18:54 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2013-09-11 03:36 - 2013-06-18 18:38 - 00160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmmbase.dll
2013-09-11 03:36 - 2013-06-11 19:43 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2013-09-11 03:36 - 2013-06-10 17:17 - 00096512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2013-09-11 03:36 - 2013-06-10 15:16 - 00888832 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-09-11 03:36 - 2013-06-10 15:10 - 00702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-09-11 03:36 - 2013-06-10 15:10 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-09-11 03:36 - 2013-06-06 04:03 - 00119040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2013-09-06 08:48 - 2013-10-05 05:10 - 00000384 _____ C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Judy.job
2013-09-06 08:48 - 2013-10-05 03:07 - 00002940 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Judy
2013-09-06 08:48 - 2013-10-05 03:07 - 00000378 _____ C:\Windows\Tasks\ReclaimerUpdateFiles_Judy.job
2013-09-06 08:48 - 2013-10-04 09:13 - 00002936 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Judy
2013-09-06 08:48 - 2013-10-04 09:13 - 00000374 _____ C:\Windows\Tasks\ReclaimerUpdateXML_Judy.job
2013-09-06 08:48 - 2013-09-06 08:48 - 00003602 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Judy
2013-09-06 08:48 - 2013-09-06 08:48 - 00002644 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Judy

==================== One Month Modified Files and Folders =======

2013-10-05 07:49 - 2013-10-05 05:19 - 00000280 _____ C:\Windows\Tasks\GreatArcadeHits.job
2013-10-05 07:29 - 2013-10-05 05:18 - 00000300 _____ C:\Windows\Tasks\DigitalSite.job
2013-10-05 07:22 - 2013-07-13 19:23 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-05 07:01 - 2013-10-05 07:01 - 00003283 _____ C:\Users\Judy\Downloads\fixlist.txt
2013-10-05 07:00 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\system32\sru
2013-10-05 06:29 - 2013-10-05 06:29 - 00000091 _____ C:\Users\Judy\AppData\Roaming\WB.CFG
2013-10-05 06:29 - 2013-10-05 06:29 - 00000006 _____ C:\Users\Judy\AppData\Roaming\WBPU-TTL.DAT
2013-10-05 05:40 - 2013-10-05 05:39 - 00026246 _____ C:\Users\Judy\Downloads\Addition.txt
2013-10-05 05:36 - 2013-10-05 05:36 - 01954124 _____ (Farbar) C:\Users\Judy\Downloads\FRST64.exe
2013-10-05 05:36 - 2013-10-05 05:36 - 00000000 ____D C:\FRST
2013-10-05 05:33 - 2013-10-05 05:33 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
2013-10-05 05:33 - 2013-10-05 05:27 - 00001089 _____ C:\Users\Judy\Desktop\MyPC Backup.lnk
2013-10-05 05:33 - 2013-10-05 05:27 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2013-10-05 05:33 - 2013-09-18 07:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-05 05:32 - 2013-10-05 05:32 - 00003378 _____ C:\Windows\System32\Tasks\EPUpdater
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\Users\Judy\AppData\Roaming\BabSolution
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\ProgramData\BitGuard
2013-10-05 05:32 - 2013-10-05 05:32 - 00000000 ____D C:\Program Files (x86)\searchgol
2013-10-05 05:31 - 2013-10-05 05:31 - 00000002 _____ C:\END
2013-10-05 05:31 - 2013-10-05 05:31 - 00000000 ____D C:\Program Files (x86)\File Type Helper
2013-10-05 05:31 - 2013-10-05 05:31 - 00000000 ____D C:\Program Files (x86)\Fast Free Converter
2013-10-05 05:30 - 2013-10-05 05:30 - 00000000 ____D C:\ProgramData\Babylon
2013-10-05 05:30 - 2013-10-05 05:19 - 00001112 _____ C:\Users\Public\Desktop\Open It!.lnk
2013-10-05 05:29 - 2013-10-05 05:18 - 00002638 _____ C:\Windows\System32\Tasks\DigitalSite
2013-10-05 05:27 - 2013-10-05 05:27 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-10-05 05:27 - 2013-07-12 14:02 - 00000000 ___RD C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-05 05:24 - 2013-10-05 05:23 - 00000000 ____D C:\Users\Judy\AppData\Local\AVG SafeGuard toolbar
2013-10-05 05:22 - 2013-10-05 05:22 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2013-10-05 05:22 - 2013-10-05 05:22 - 00003746 _____ C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2013-10-05 05:22 - 2013-10-05 05:22 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-10-05 05:22 - 2013-10-05 05:22 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2013-10-05 05:21 - 2013-10-05 05:21 - 00003120 _____ C:\Windows\System32\Tasks\Advanced System Protector_startup
2013-10-05 05:21 - 2013-10-05 05:21 - 00001203 _____ C:\Users\Public\Desktop\Advanced System Protector.lnk
2013-10-05 05:21 - 2013-10-05 05:21 - 00000000 ____D C:\ProgramData\Systweak
2013-10-05 05:21 - 2013-10-05 05:21 - 00000000 ____D C:\Program Files (x86)\Advanced System Protector
2013-10-05 05:21 - 2013-10-05 05:20 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Systweak
2013-10-05 05:20 - 2013-10-05 05:20 - 00003310 _____ C:\Windows\System32\Tasks\Advanced System Protector
2013-10-05 05:20 - 2013-10-05 05:20 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
2013-10-05 05:20 - 2013-10-05 05:20 - 00003008 _____ C:\Windows\System32\Tasks\RegClean Pro_UPDATES
2013-10-05 05:20 - 2013-10-05 05:20 - 00002852 _____ C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
2013-10-05 05:20 - 2013-10-05 05:20 - 00001052 _____ C:\Users\Public\Desktop\RegClean Pro.lnk
2013-10-05 05:20 - 2013-10-05 05:20 - 00000294 _____ C:\Windows\Tasks\RegClean Pro_UPDATES.job
2013-10-05 05:20 - 2013-10-05 05:20 - 00000286 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2013-10-05 05:20 - 2013-10-05 05:20 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
2013-10-05 05:19 - 2013-10-05 05:19 - 00003102 _____ C:\Windows\System32\Tasks\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Users\Judy\AppData\Local\GreatArcadeHits
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\Whilokii
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\PricePeep
2013-10-05 05:19 - 2013-10-05 05:19 - 00000000 ____D C:\Program Files (x86)\OpenIt
2013-10-05 05:18 - 2013-10-05 05:18 - 00000000 ____D C:\Users\Judy\AppData\Roaming\DigitalSite
2013-10-05 05:16 - 2013-10-05 05:16 - 00749248 _____ C:\Users\Judy\Downloads\ZipExtractorSetup.exe
2013-10-05 05:14 - 2012-07-26 03:28 - 00848230 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-05 05:12 - 2013-08-09 15:03 - 00000000 ____D C:\Users\Judy\AppData\Roaming\WebStorage
2013-10-05 05:11 - 2013-07-16 05:42 - 00003332 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-251038213-2808898551-1881861744-1001
2013-10-05 05:11 - 2013-07-16 05:42 - 00003196 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-251038213-2808898551-1881861744-1001
2013-10-05 05:11 - 2013-07-12 14:02 - 00000428 _____ C:\Users\Judy\AppData\Roaming\sp_data.sys
2013-10-05 05:10 - 2013-09-06 08:48 - 00000384 _____ C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Judy.job
2013-10-05 05:10 - 2012-12-19 19:46 - 00000868 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-10-05 05:09 - 2012-08-01 21:20 - 00022028 _____ C:\Windows\PFRO.log
2013-10-05 05:09 - 2012-07-26 03:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-05 05:08 - 2013-10-04 20:19 - 00000000 ____D C:\AdwCleaner
2013-10-05 05:08 - 2012-07-26 01:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2013-10-05 03:25 - 2013-07-12 13:59 - 01440623 _____ C:\Windows\WindowsUpdate.log
2013-10-05 03:07 - 2013-09-06 08:48 - 00002940 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Judy
2013-10-05 03:07 - 2013-09-06 08:48 - 00000378 _____ C:\Windows\Tasks\ReclaimerUpdateFiles_Judy.job
2013-10-04 20:19 - 2013-10-04 20:19 - 01045226 _____ C:\Users\Judy\Downloads\AdwCleaner.exe
2013-10-04 20:01 - 2013-10-04 09:31 - 00021919 _____ C:\Users\Judy\Desktop\dds.txt
2013-10-04 20:01 - 2013-10-04 09:31 - 00003207 _____ C:\Users\Judy\Desktop\attach.txt
2013-10-04 19:49 - 2013-10-04 19:49 - 00000258 __RSH C:\Users\Judy\ntuser.pol
2013-10-04 19:49 - 2013-07-12 13:59 - 00000000 ____D C:\Users\Judy
2013-10-04 19:49 - 2012-07-26 04:12 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-10-04 19:49 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2013-10-04 19:46 - 2013-10-04 13:09 - 00000000 ____D C:\Program Files (x86)\Browsersafeguard
2013-10-04 13:38 - 2013-07-12 14:08 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-251038213-2808898551-1881861744-1001
2013-10-04 13:09 - 2013-10-04 13:09 - 00003850 _____ C:\Windows\System32\Tasks\BrowserSafeguard Update Task
2013-10-04 13:05 - 2013-10-04 13:05 - 02059560 _____ (ExpressInstaller) C:\Users\Judy\Desktop\Setup.exe
2013-10-04 13:00 - 2012-08-04 22:25 - 00000000 ____D C:\ProgramData\McAfee
2013-10-04 12:59 - 2013-07-12 14:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-04 12:57 - 2012-07-26 04:12 - 00000000 ___HD C:\Windows\ELAMBKUP
2013-10-04 11:01 - 2012-12-19 19:46 - 00000870 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2013-10-04 09:27 - 2013-10-04 09:27 - 00688992 ____R (Swearware) C:\Users\Judy\Downloads\dds.scr
2013-10-04 09:13 - 2013-09-06 08:48 - 00002936 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Judy
2013-10-04 09:13 - 2013-09-06 08:48 - 00000374 _____ C:\Windows\Tasks\ReclaimerUpdateXML_Judy.job
2013-10-03 13:53 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-09-19 08:58 - 2013-09-19 08:58 - 00000000 ____D C:\Users\Judy\Documents\ASUS
2013-09-19 08:58 - 2013-07-12 14:00 - 00000000 ____D C:\Users\Judy\AppData\Local\VirtualStore
2013-09-19 08:58 - 2013-07-12 13:59 - 00000000 ____D C:\Users\Judy\AppData\Local\ASUS
2013-09-18 19:26 - 2013-07-16 04:56 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-18 19:26 - 2013-07-16 04:56 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-18 17:16 - 2013-07-12 14:14 - 00000000 ____D C:\Users\Judy\AppData\Local\Mozilla
2013-09-15 21:19 - 2013-08-22 06:41 - 00021504 _____ C:\Users\Judy\Desktop\linkouture feature.odt
2013-09-15 20:49 - 2013-09-15 20:49 - 00000193 _____ C:\Windows\WORDPAD.INI
2013-09-15 20:43 - 2013-09-15 20:43 - 00001131 _____ C:\Users\Judy\Desktop\OLYMPUS Viewer 3.lnk
2013-09-15 20:43 - 2013-09-15 20:43 - 00000000 ____D C:\OLYMPUS
2013-09-15 20:43 - 2013-07-12 18:37 - 00000000 ____D C:\Program Files (x86)\OLYMPUS
2013-09-15 20:34 - 2013-09-15 20:18 - 101288296 _____ (OLYMPUS IMAGING CORP.) C:\Users\Judy\Downloads\OV3Setup(1).exe
2013-09-15 16:12 - 2013-09-15 16:12 - 00298952 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-15 15:53 - 2013-09-15 15:53 - 00184053 _____ C:\Users\Judy\Desktop\beachcombing photo.htm
2013-09-15 15:25 - 2013-09-14 09:25 - 97671483 _____ C:\Windows\SysWOW64\윯ꡪLø
2013-09-14 08:06 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\rescache
2013-09-14 05:50 - 2012-07-26 01:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2013-09-14 04:46 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\WinStore
2013-09-14 04:46 - 2012-07-26 04:12 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-09-14 04:46 - 2012-07-26 01:38 - 00000000 ____D C:\Windows\system32\oobe
2013-09-11 04:26 - 2013-08-13 23:36 - 00000000 ____D C:\Windows\system32\MRT
2013-09-11 04:24 - 2013-07-13 15:36 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-10 12:23 - 2013-07-13 19:23 - 00003718 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-06 08:48 - 2013-09-06 08:48 - 00003602 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Judy
2013-09-06 08:48 - 2013-09-06 08:48 - 00002644 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Judy
2013-09-06 05:47 - 2013-07-16 05:40 - 00000000 ____D C:\Users\Judy\AppData\Roaming\Real
2013-09-06 05:47 - 2013-07-16 05:34 - 00000000 ____D C:\ProgramData\Real

Some content of TEMP:
====================
C:\Users\Judy\AppData\Local\Temp\BackupSetup.exe
C:\Users\Judy\AppData\Local\Temp\checktbexist.exe
C:\Users\Judy\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Judy\AppData\Local\Temp\helper.exe
C:\Users\Judy\AppData\Local\Temp\mconduitinstaller.exe
C:\Users\Judy\AppData\Local\Temp\MouseKeyboardCenterx64_1033.exe
C:\Users\Judy\AppData\Local\Temp\newsetup.exe
C:\Users\Judy\AppData\Local\Temp\nsc6D08.exe
C:\Users\Judy\AppData\Local\Temp\nsd53FD.exe
C:\Users\Judy\AppData\Local\Temp\nsj49D8.exe
C:\Users\Judy\AppData\Local\Temp\nsmA79B.exe
C:\Users\Judy\AppData\Local\Temp\nsn617C.exe
C:\Users\Judy\AppData\Local\Temp\nsq49B7.exe
C:\Users\Judy\AppData\Local\Temp\nsrCC9B.exe
C:\Users\Judy\AppData\Local\Temp\nsu52E2.exe
C:\Users\Judy\AppData\Local\Temp\oi_{AABF4922-3F40-417A-9057-2B0B438863B7}.exe
C:\Users\Judy\AppData\Local\Temp\Quarantine.exe
C:\Users\Judy\AppData\Local\Temp\SPStub.exe
C:\Users\Judy\AppData\Local\Temp\sqlite3.exe
C:\Users\Judy\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\Judy\AppData\Local\Temp\vcredist_x64.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-09-30 03:00

==================== End Of Log ============================

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.