Jump to content

My ScorpianSaverMalady


Recommended Posts

Welcome to the forum, first.....try to uninstall it from your add/remove programs.

Then........

Lets clean out any adware/spyware now: (this will require a reboot so save all your work)

Please download AdwCleaner by Xplode and save to your Desktop.

Make sure you click on download buttons that look similar to this, not "sponsored ad links":

bleep-crop.jpg

  • Double click on AdwCleaner.exe to run the tool.

    Vista/Windows 7/8 users right-click and select Run As Administrator

  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you may want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review. (all items found are adware/spyware/foistware)
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted:
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.
Next..................

Open up Malwarebytes > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a Quick Scan with Malwarebytes Anti-Malware, post the report.

Make sure that everything is checked, and click Remove Selected.

Next........

Clean out temp files by using disk cleanup or.........

Download, install and run CCleaner free to clean out temp files.

Here's a Tutorial if needed.

You may want to uncheck "cookies" and please stay away from the registry cleaner.

Last......

Please download Farbar Recovery Scan Tool and save it to a folder. (use correct version for your system.....Which system am I using?)

Please make sure you click download buttons that look similar to this, not "sponsored ad links":

bleep-crop.jpg

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
  • MrC
Link to post
Share on other sites

# AdwCleaner v3.014 - Report created 07/12/2013 at 05:59:17
# Updated 01/12/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Ed - ED-PC
# Running from : C:\Users\Ed\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : Level Quality Watcher

***** [ Files / Folders ] *****

Folder Deleted : C:\Searchprotect
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\DealPlyLive
Folder Deleted : C:\ProgramData\NCH Software
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\DealPly
Folder Deleted : C:\Program Files (x86)\DealPlyLive
Folder Deleted : C:\Program Files (x86)\Level Quality Watcher
Folder Deleted : C:\Program Files (x86)\NCH Software
Folder Deleted : C:\Program Files (x86)\Searchprotect
Folder Deleted : C:\Program Files\Level Quality Watcher
Folder Deleted : C:\Users\Ed\AppData\Local\Conduit
Folder Deleted : C:\Users\Ed\AppData\Local\DealPlyLive
Folder Deleted : C:\Users\Ed\AppData\Local\Smartbar
Folder Deleted : C:\Users\Ed\AppData\Local\Temp\Smartbar
Folder Deleted : C:\Users\Ed\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Ed\AppData\LocalLow\Smartbar
Folder Deleted : C:\Users\Ed\AppData\Roaming\DealPly
Folder Deleted : C:\Users\Ed\AppData\Roaming\NCH Software
File Deleted : C:\Users\Ed\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Program Files (x86)\Mozilla Firefox\nsprotector.js
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\nsprotector.js
File Deleted : C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\6v87ty6l.default\searchplugins\safeguard-secure-search.xml
File Deleted : C:\Windows\Tasks\Dealply.job
File Deleted : C:\Windows\System32\Tasks\Dealply

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\conduit.com
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [browser Infrastructure Helper]
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.bho
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dealplylive.exe
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2549263
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DealPlyLive
Key Deleted : HKCU\Software\SearchProtect
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\smartbarbackup
Key Deleted : HKCU\Software\smartbarlog
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DealPlyLive
Key Deleted : HKLM\Software\InstallIQ

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v25.0.1 (en-US)

[ File : C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\6v87ty6l.default\prefs.js ]

Line Deleted : user_pref("CT2549263_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1385729924004,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");

Line Deleted : user_pref("Smartbar.ConduitSearchEngineList", "");
Line Deleted : user_pref("Smartbar.ConduitSearchUrlList", "");
Line Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT2549263");
Line Deleted : user_pref("smartbar.machineId", "OFW3H60C3TSOE3OCLUQNG6GDJYR1JVYSBXPGKBSY8NRBFSV7JHJJMZ20O1KVIMXQG2MPXOC5NUWYLWUDAKD0JW");

-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [7909 octets] - [07/12/2013 05:55:54]
AdwCleaner[s0].txt - [7746 octets] - [07/12/2013 05:59:17]

########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [7806 octets] ##########
 

 

My note:

 

IE wouldn't let me copy and paste. FireFox did! Easy peasy!

 

Ed

Link to post
Share on other sites

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.12.07.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16428
Ed :: ED-PC [administrator]

12/7/2013 6:30:20 AM
MBAM-log-2013-12-07 (06-40-12).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 227281
Time elapsed: 8 minute(s), 15 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 6
HKCR\AppID\AdpeakProxy.exe (PUP.Optional.Adpeak) -> No action taken.
HKCR\Wow6432Node\AppID\AdpeakProxy.exe (PUP.Optional.Adpeak) -> No action taken.
HKLM\SOFTWARE\Adpeak, Inc. (PUP.Optional.AdpeakProxy) -> No action taken.
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{19DC5AB8-0792-4875-8F1B-896C5A9CE6AE} (PUP.Optional.Adpeak) -> No action taken.
HKLM\SOFTWARE\Wow6432Node\Adpeak, Inc. (PUP.Optional.Adpeak) -> No action taken.
HKLM\SOFTWARE\Wow6432Node\Wow6432Node\Adpeak, Inc. (PUP.Optional.Adpeak) -> No action taken.

Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19DC5AB8-0792-4875-8F1B-896C5A9CE6AE}|DisplayName (PUP.Optional.Adpeak) -> Data: Level Quality Watcher -> No action taken.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 108
C:\Users\Ed\AppData\Local\Temp\ct2549263 (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263 (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\images (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox\images (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\res (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\api (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\msd (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\js\resources (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spbd (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spbd\images (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spsd (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spsd\images (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gadgetFrame (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\img (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\img (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\APPLICATION_BUTTON (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\APPLICATION_BUTTON\Js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\APPLICATION_BUTTON\resources (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\plugins (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\img (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\js\resources (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\dark (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\light (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\Optimizer (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\Optimizer\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\agreement (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\css\custom-theme (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\images (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\menu_dlg (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\css\custom-theme (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\resources (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\buildSettings (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\Css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\resources (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\view (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\view\script (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\view\style (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\view\style\rsx (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\img (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\resources (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\core (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.alerts (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.alerts\images (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\sl (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\components (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\defaults (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\defaults\preferences (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\lib (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\META-INF (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\modules (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\Plugins (PUP.Optional.Conduit.A) -> No action taken.

Files Detected: 422
C:\temp\InstallServices64.msi (PUP.Optional.Adpeak) -> No action taken.
C:\temp\scorpionsaver.exe (PUP.Optional.ScorpionSaver) -> No action taken.
C:\temp\ScorpionSaver.msi (PUP.Optional.Adpeak) -> No action taken.
C:\Windows\System32\AdpeakProxy.dll (PUP.Optional.Adpeak) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\Installer.exe (PUP.Optional.SmartBar.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\nsa84AC.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\nsh5912.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\nsk5253.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\SecondStepInstaller.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\SPStub.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ToolbarHelper.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\Downloads\7zip_installer_d793026.exe (PUP.Optional.InstallIQ.A) -> No action taken.
C:\Users\Ed\Downloads\Updater_Setup.exe (PUP.Optional.iBryte) -> No action taken.
C:\Windows\Installer\19792f9.msi (PUP.Optional.Adpeak) -> No action taken.
C:\Windows\Installer\197b35c.msi (PUP.Optional.SmartBar.A) -> No action taken.
C:\Windows\SysWOW64\AdpeakProxy.dll (PUP.Optional.Adpeak) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\AdpeakProxyr.log (PUP.Optional.AdpeakProxy) -> No action taken.
C:\Windows\Temp\AdpeakProxy.log (PUP.Optional.AdpeakProxy) -> No action taken.
C:\Windows\Temp\AdpeakProxyr.log (PUP.Optional.AdpeakProxy) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome.manifest (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\install.rdf (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\sspv.txt (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\version.txt (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\BrowserContextMenuManager.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\ConduitAbstractionLayer.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\ConduitAbstractionLayerBack.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\ConduitAbstractionLayerFront.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\popup.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\popup.xul (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\popupTransparent.xul (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\preferences.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\preferences.xul (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\toolbarOverlay.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\toolbarOverlay.xul (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tooltips.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\version.xul (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\autoComplete.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\httpObserver.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\umRecovery.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\upgradeManager.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\uninstallObserver.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\MozillaRetentionDialog.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\RetentionDialog.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\css\MozillaRetentionDialog.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\css\RetentionDialog.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\images\2.0--spec--kicker.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\images\content-pattern.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\images\content-sep.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\images\OK-Button-Default.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\images\OK-Button-MouseOver.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\images\OK-Button-OnClick.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\images\x.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\js\MozillaRetentionDialog.view.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\logic\uninstall\dialog\js\RetentionDialog.view.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\backstage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\searchversion.txt (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\version.txt (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\al.view.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox\aboutBox.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox\images\conduit-logo-OLD.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox\images\conduit-logo.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox\images\OK-Button-Default.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox\images\OK-Button-MouseOver.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox\images\OK-Button-OnClick.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox\images\truste.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox\images\x.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\aboutBox\js\aboutBox.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\appManager.controller.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\appManager.model.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\appManager.view.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\css\toolbar.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\ajax-loader.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\buttonSprites.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\chevron_sprites.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\fallback24.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\ie8_mouseover_button.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\ie8_onclick_button.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\loader-icon.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\menu_arrow.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\minibrowser.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\minibrowser24.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\mp_sprites.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\new_chevron_sprites.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\rounded_corners_left_transparent.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\rounded_corners_left_white.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\rounded_corners_left_white_34.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\rounded_corners_right_transparent.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\rounded_corners_right_white.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\rounded_corners_right_white_34.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\separator.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\separator_hover.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\img\uus.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ac\res\yoxscroll.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\api\toolbarapi.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\api\webAppApi.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\api\webAppApiFront.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\msd\excanvas.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\msd\trusted.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\msd\trusted.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\msd\untrusted.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\msd\untrusted.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\msd\untrusted.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\options.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\css\jquery.jscrollpane.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\css\options.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\css\reset.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\bg-hide-click.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\bg-hide.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\checkbox-check-off.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\checkbox-check-on.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\conduit-logo.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\ic_Closer.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\ic_Closer_hover.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\minibrowser.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\scroller.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\sprite-ok-button.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\truste.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\images\x.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\js\html5SupportIe.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\js\options.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\js\resources\html5shiv.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\js\resources\jquery.jscrollpane.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\options\js\resources\jquery.mousewheel.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\js\searchProtectorManager.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spbd\bubble.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spbd\bubble.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spbd\main.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spbd\images\information.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spbd\images\x-default-LTR.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spbd\images\x-default-RTL.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spbd\images\x-mouseover-LTR.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spbd\images\x-mouseover-RTL.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spsd\main.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spsd\SearchProtector.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spsd\settings.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spsd\images\ok-button.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spsd\images\separation-line.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\sp\spsd\images\warning.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menus.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\popups.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\DialogsAPI.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\excanvas.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\generalDialogStyle.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\PIE.htc (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\settings.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\main.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\ToolbarFirstTimeDialog.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\ToolbarFirstTimeDialog.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images\app-store-icon.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images\arrow.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images\dialog_tip_left.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images\dialog_tip_right.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images\divider.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images\emailNotifier.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images\facebook.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images\radio.GIF (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images\Thumbs.db (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images\truste_welcome.GIF (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\dlg\ftd\images\weather.GIF (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gadgetFrame\gf.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gadgetFrame\lgf.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\gf.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\lgf.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\css\gf.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\css\gf_ie.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\img\ie_back.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\img\loader.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\img\resize.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\img\sprites.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\js\gf.view.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\gf\js\lgf.view.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\popup.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\css\menu.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\img\arrow-down-strong.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\img\arrow-down.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\img\arrow-left-strong.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\img\arrow-left.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\img\arrow-right-strong.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\img\arrow-right.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\img\arrows.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\js\jquery.ellipsis.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\js\jquery.scrollTo-1.4.2-min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\js\menu.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\js\renderHandler.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\js\scrollers.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\ui\menu\js\showHandler.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\browserAppApi.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\APPLICATION_BUTTON\bgpage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\APPLICATION_BUTTON\Js\bgpage.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\APPLICATION_BUTTON\resources\defaultEngineImage.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\bgPage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\popup.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\css\en.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\css\en_rtl.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\css\jquery.jscrollpane.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\AccountManager.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\bgPage.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\EN.model.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\IMAPExecuter.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\Inboxer.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\Invoker.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\MailDecoder.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\MailMerger.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\POP3Executer.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\Popup.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\providerHelper.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\Providers.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\sdk.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\SettingsManager.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\Timer.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\Translation.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\Utils.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\plugins\jquery.jscrollpane.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\plugins\jquery.mousewheel.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\plugins\jquery.text-overflow.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\EMAIL_NOTIFIER\js\plugins\jquery.watermark.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\bgpage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\embedded.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\popup.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\css\embedded.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\css\popup.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\css\reset.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\js\bgpage.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\js\embedded.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\js\higlighter_script.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\HIGHLIGHTER\js\popup.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\bgpage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\popup.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\css\popup.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\img\arrows.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\img\badges.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\img\icons.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\js\bgpage.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\js\popup.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\js\sdk.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\js\resources\jquery.text-overflow.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\js\resources\jquery.tmpl.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\js\resources\webAppUtils.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\MULTI_RSS\js\resources\xml2json.custom.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\bgpage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\embedded.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\NotificationPopup.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\Settings.htm (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\Settings.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\css\gadget.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\css\general.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\css\Main.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\css\newMain.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\css\settings.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\css\ui.stepper.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\closeIcon.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\downArrow.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\settingsIcon.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\upArrow.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\dark\close.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\dark\Next.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\dark\Next_hover.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\dark\powered-by.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\dark\Prev.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\dark\Prev_hover.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\dark\settings.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\light\close.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\light\Next.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\light\Next_hover.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\light\powered-by.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\light\Prev.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\light\Prev_hover.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\images\light\settings.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\AppName.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\bgpage.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\bgpageEarly.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\commons.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\jquery.ezmark.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\notification.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\NotificationSettings.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\notificationUIManger.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\sdk.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\Settings.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\stepper.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\NOTIFICATION\js\ToolbarAndAppsSettings.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\Optimizer\bgpage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\Optimizer\js\bgpage.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\bgpage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\bgpage.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\pg_offers.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\pg_offers.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\agreement\agree.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\agreement\agree.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\agreement\Close.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\agreement\Image.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\agreement\Logo.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\agreement\OK_Btn.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\agreement\Topbg.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\css\gadget.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\css\ie7styles.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\css\iestyle.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\css\custom-theme\jquery-ui-1.8.10.custom.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\images\icon.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\menu_dlg\email.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\menu_dlg\h.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\menu_dlg\info.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\menu_dlg\pg_dlg.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\menu_dlg\v.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\PRICE_GONG\menu_dlg\x.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\bgpage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\embedded.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\popup2.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\css\gadget.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\css\jquery.jscrollpane.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\css\reset.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\css\stations.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\css\custom-theme\jquery-ui-1.8.10.custom.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\bgpage.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\bgpageEarly.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\embedded.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\embeddedEarly.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\localization.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\player.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\popup.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\resources\BrowserDetect.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\resources\jquery-ui-1.8.10.custom.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\resources\jquery.jscrollpane.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\resources\jquery.mousewheel.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\resources\jquery.scrollTo-1.4.2-min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\resources\radioCommon.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\resources\sdk.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\resources\system.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\RADIO_PLAYER\js\resources\utils.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\bgpage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\embedded.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\information.popup.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\buildSettings\SearchApp_Ant.xml (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\Css\information.popup.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\js\bgpage.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\js\common.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\js\contentManager.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\js\historyProvider.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\js\information.popup.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\js\layoutManager.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\js\sdk.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\js\searchListener.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\js\selectionListener.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\js\suggestProvider.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\resources\buttonSprites.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\resources\defaultEngineImage.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\resources\dropdownButton.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\resources\history--x-default.jpg (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\resources\history--x-default.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\resources\history--x-mouseover.jpg (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\resources\history--x-mouseover.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\resources\removeButton.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\resources\removeButtonHover.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\view\script\view.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\view\style\default.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\view\style\rsx\dd-arrow.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\SEARCH\view\style\rsx\ie8.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\bgpage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\popup.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\popup.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\img\icons.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\img\inbox.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\img\scroll_down.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\img\scroll_up.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\js\bgpage.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\js\Config.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\js\localization.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\js\popup.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\js\sdk.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\js\Utils.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\resources\ajax-loader.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\resources\icons.png (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\resources\jquery.tmpl.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\resources\yManager.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\TWITTER\resources\yStore.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\bgpage.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\popup.html (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\css\gadget.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\css\ie7styles.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\css\iestyle.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\js\bgpage.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\js\common.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\js\date-functions.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\js\gadget.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\js\jquery.autocomplete.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\js\jquery.textshadow.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\js\logic.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\js\main.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\al\wa\WEATHER\js\xPath.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\core\corelibs.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\core\framework.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\core\utils.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\al.view.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\al.viewPerformanceLog.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\background.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\ie_fix.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.tmpl.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.xml2json.custom.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.xml2json.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\json2.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\json2.min.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\script2injectEmbedded.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\script2injectPopup.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.alerts\jquery.alerts.css (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.alerts\jquery.alerts.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.alerts\images\help.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.alerts\images\important.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.alerts\images\info.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\lib\jquery.alerts\images\title.gif (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\chrome\CT2549263\content\tb\sl\serviceLayer.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\components\autoCompleteManager.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\defaults\preferences\defaults.js (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\lib\log4conduit.jsm (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\lib\log4moz.jsm (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\META-INF\manifest.mf (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\META-INF\zigbert.rsa (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\META-INF\zigbert.sf (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\modules\BackStage.jsm (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\modules\Commons.jsm (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\modules\FrontStage.jsm (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\Plugins\np-mswmp.dll (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ed\AppData\Local\Temp\ct2549263\Plugins\npConduitFirefoxPlugin.dll (PUP.Optional.Conduit.A) -> No action taken.

(end)
 

My note:

 

Malwarebytes scan report. Prior to clicking remove all selected!

 

Ed

 

Link to post
Share on other sites

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-12-2013 2
Ran by Ed (administrator) on ED-PC on 07-12-2013 11:36:10
Running from C:\Users\Ed\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Logitech, Inc.) C:\Program Files\Logitech\SolarApp\L4301_Solar.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(AWS Convergence Technologies, Inc.) C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Akamai Technologies, Inc.) C:\Users\Ed\AppData\Local\Akamai\netsession_win.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointG\SetPointII.exe
(Akamai Technologies, Inc.) C:\Users\Ed\AppData\Local\Akamai\netsession_win.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
(Weather Display) C:\wdisplay\WeatherD.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Nikon Corporation) C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\NBCore.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\redirector.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11905128 2011-06-28] (Realtek Semiconductor)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [CmPCIaudio] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\CMICNFG3.dll,CMICtrlWnd
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [shadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2273056 2013-11-29] (NVIDIA Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
HKCU\...\Run: [EADM] - C:\Program Files (x86)\Origin\Origin.exe [3551576 2013-11-20] (Electronic Arts)
HKCU\...\Run: [Weather] - C:\Program Files (x86)\AWS\WeatherBug\Weather.exe [1652736 2011-10-05] (AWS Convergence Technologies, Inc.)
HKCU\...\Run: [steam] - C:\Program Files (x86)\Steam\Steam.exe [1823656 2013-12-03] (Valve Corporation)
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Ed\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [uploader] - C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe [122984 2013-05-30] (Seagate Technology LLC)
HKCU\...\Run: [Delphi 3#Autostart] - C:\wdisplay\WeatherD.exe [4547584 2007-01-10] (Weather Display)
HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1093464 2013-08-22] (Garmin Ltd or its subsidiaries)
HKCU\...\Run: [GoogleChromeAutoLaunch_404A292356CD737C6DBBBC5FB82F732B] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [863184 2013-12-03] (Google Inc.)
HKLM-x32\...\Run: [bingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2249352 2013-06-27] (Microsoft Corp.)
HKLM-x32\...\Run: [Nikon Transfer Monitor] - C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe [479232 2009-09-15] (Nikon Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ConnectionCenter] - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [371864 2012-04-05] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [DBAgent] - C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [1517640 2013-05-30] (Seagate Technology LLC)
HKLM-x32\...\Run: [Nikon Message Center 2] - C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM-x32\...\Run: [sunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
AppInit_DLLs-x32: C:\PROGRA~2\Citrix\ICACLI~1\RSHook.dll [257176 2012-04-05] (Citrix Systems, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA3AD20708E30CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE9MSE&PC=UP09
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.facebook.com/
http://biohazardclan.com/index.php
http://movies.netflix.com/WiHome?movieid=70044256
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
BHO: Expat Shield Class - {3706EE7C-3CAD-445D-8A43-03EBC3B75908} - C:\Program Files (x86)\Expat Shield\HssIE\ExpatIE_64.dll No File
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
DPF: HKLM-x32 {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab
DPF: HKLM-x32 {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76

FireFox:
========
FF ProfilePath: C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\6v87ty6l.default
FF Homepage: hxxp://www.cnn.com/?refresh=1|https://www.facebook.com/|hxxp://biohazardclan.com/index.php|hxxp://movies.netflix.com/WiHome?movieid=70044256
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @Citrix.com/npican - C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=1.122.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.138.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\6v87ty6l.default\searchplugins\expat-shield-customized-web-search.xml
FF Extension: searchy - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\6v87ty6l.default\Extensions\searchy@searchy.xpi
FF Extension: defaults - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\6v87ty6l.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi

Chrome:
=======

 

My note:

 

The program errored. Line 9357. It had a location also, but I didn't get that down. Computer seems OK now.

 

Ed

Link to post
Share on other sites

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-12-2013 02
Ran by Ed (administrator) on ED-PC on 08-12-2013 07:31:38
Running from C:\Users\Ed\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Logitech, Inc.) C:\Program Files\Logitech\SolarApp\L4301_Solar.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
() C:\Program Files\Core Temp\Core Temp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(AWS Convergence Technologies, Inc.) C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
(Akamai Technologies, Inc.) C:\Users\Ed\AppData\Local\Akamai\netsession_win.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointG\SetPointII.exe
(Akamai Technologies, Inc.) C:\Users\Ed\AppData\Local\Akamai\netsession_win.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Weather Display) C:\wdisplay\WeatherD.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(Nikon Corporation) C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\NBCore.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Farbar) C:\Users\Ed\Downloads\FRST64(2).exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11905128 2011-06-28] (Realtek Semiconductor)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech, Inc.)
HKLM\...\Run: [CmPCIaudio] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\CMICNFG3.dll,CMICtrlWnd
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [shadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2273056 2013-11-29] (NVIDIA Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
HKCU\...\Run: [EADM] - C:\Program Files (x86)\Origin\Origin.exe [3551576 2013-11-20] (Electronic Arts)
HKCU\...\Run: [Weather] - C:\Program Files (x86)\AWS\WeatherBug\Weather.exe [1652736 2011-10-05] (AWS Convergence Technologies, Inc.)
HKCU\...\Run: [steam] - C:\Program Files (x86)\Steam\Steam.exe [1823656 2013-12-03] (Valve Corporation)
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Ed\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [uploader] - C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe [122984 2013-05-30] (Seagate Technology LLC)
HKCU\...\Run: [Delphi 3#Autostart] - C:\wdisplay\WeatherD.exe [4547584 2007-01-10] (Weather Display)
HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1093464 2013-08-22] (Garmin Ltd or its subsidiaries)
HKCU\...\Run: [GoogleChromeAutoLaunch_404A292356CD737C6DBBBC5FB82F732B] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [863184 2013-12-03] (Google Inc.)
HKLM-x32\...\Run: [bingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2249352 2013-06-27] (Microsoft Corp.)
HKLM-x32\...\Run: [Nikon Transfer Monitor] - C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe [479232 2009-09-15] (Nikon Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ConnectionCenter] - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [371864 2012-04-05] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [DBAgent] - C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [1517640 2013-05-30] (Seagate Technology LLC)
HKLM-x32\...\Run: [Nikon Message Center 2] - C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM-x32\...\Run: [sunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
AppInit_DLLs-x32: C:\PROGRA~2\Citrix\ICACLI~1\RSHook.dll [257176 2012-04-05] (Citrix Systems, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA3AD20708E30CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE9MSE&PC=UP09
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.facebook.com/
http://biohazardclan.com/index.php
http://movies.netflix.com/WiHome?movieid=70044256
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
BHO: Expat Shield Class - {3706EE7C-3CAD-445D-8A43-03EBC3B75908} - C:\Program Files (x86)\Expat Shield\HssIE\ExpatIE_64.dll No File
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
DPF: HKLM-x32 {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab
DPF: HKLM-x32 {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76

FireFox:
========
FF ProfilePath: C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\6v87ty6l.default
FF Homepage: hxxp://www.cnn.com/?refresh=1|https://www.facebook.com/|hxxp://biohazardclan.com/index.php|hxxp://movies.netflix.com/WiHome?movieid=70044256
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @Citrix.com/npican - C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=1.122.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.138.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\6v87ty6l.default\searchplugins\expat-shield-customized-web-search.xml
FF Extension: searchy - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\6v87ty6l.default\Extensions\searchy@searchy.xpi
FF Extension: defaults - C:\Users\Ed\AppData\Roaming\Mozilla\Firefox\Profiles\6v87ty6l.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi

Chrome:
=======
CHR DefaultSearchKeyword: google.com
CHR DefaultSearchProvider: Google
CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}
CHR Extension: (Google Wallet) - C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0

==================== Services (Whitelisted) =================

R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-27] (Microsoft Corp.)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [220504 2013-08-22] (Garmin Ltd or its subsidiaries)
R2 L4301_Solar; C:\Program Files\Logitech\SolarApp\L4301_Solar.exe [405744 2013-01-30] (Logitech, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1370912 2013-11-29] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15128352 2013-11-29] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-26] ()
R2 Seagate Dashboard Services; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe [16000 2013-05-30] (Seagate Technology LLC)

==================== Drivers (Whitelisted) ====================

S3 cmuda3; C:\Windows\System32\drivers\cmudax3.sys [1155072 2012-06-17] (C-Media Inc)
S3 dgderdrv; C:\Windows\SysWow64\drivers\dgderdrv.sys [20032 2011-08-23] (Devguru Co., Ltd)
S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [91352 2013-12-03] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-10-30] (NVIDIA Corporation)
R3 ALSysIO; \??\C:\Users\Ed\AppData\Local\Temp\ALSysIO64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-08 07:31 - 2013-12-08 07:31 - 01927772 _____ (Farbar) C:\Users\Ed\Downloads\FRST64(2).exe
2013-12-07 18:08 - 2013-12-07 18:08 - 00000000 ____D C:\Users\Ed\AppData\Local\{ACA299CB-3F13-4965-A0DB-5EAFF6BECAC3}
2013-12-07 17:48 - 2013-12-07 17:48 - 01927514 _____ (Farbar) C:\Users\Ed\Downloads\FRST64(1).exe
2013-12-07 11:56 - 2013-12-07 18:13 - 00000672 _____ C:\Windows\setupact.log
2013-12-07 11:56 - 2013-12-07 11:56 - 00000000 _____ C:\Windows\setuperr.log
2013-12-07 11:34 - 2013-12-08 07:32 - 00018759 _____ C:\Users\Ed\Downloads\FRST.txt
2013-12-07 11:34 - 2013-12-07 11:34 - 00000000 ____D C:\FRST
2013-12-07 11:33 - 2013-12-07 11:33 - 01927514 _____ (Farbar) C:\Users\Ed\Downloads\FRST64.exe
2013-12-07 07:01 - 2013-12-07 07:01 - 03541544 _____ (Piriform Ltd) C:\Users\Ed\Downloads\ccsetup408_slim.exe
2013-12-07 05:55 - 2013-12-07 05:59 - 00000000 ____D C:\AdwCleaner
2013-12-07 04:39 - 2013-12-07 04:39 - 00000000 ____D C:\Users\Ed\AppData\Local\{764D0C03-A94C-460B-8719-4A5CB90C0B62}
2013-12-06 12:15 - 2013-12-06 12:15 - 00000000 ____D C:\Users\Ed\AppData\Local\{615825AD-93DB-49CD-8628-4E29C112AF90}
2013-12-05 18:52 - 2013-12-05 18:52 - 00165376 _____ C:\Users\Ed\Desktop\SystemLook_x64.exe
2013-12-05 18:49 - 2013-12-05 18:49 - 01110034 _____ C:\Users\Ed\Desktop\AdwCleaner.exe
2013-12-05 17:16 - 2013-12-05 17:16 - 00000000 ____D C:\Users\Ed\AppData\Local\{D42481F5-132D-4129-B9CC-E1E3FA4644BB}
2013-12-05 04:26 - 2013-12-05 04:26 - 00000000 ____D C:\Users\Ed\AppData\Local\{8840809B-3803-4EAB-AADF-4A3D93BC3D97}
2013-12-04 14:37 - 2013-12-04 14:37 - 00000000 ____D C:\Users\Ed\AppData\Local\{F1D2929C-E8A5-4C89-B64E-E03327C6BC8B}
2013-12-03 15:51 - 2013-12-03 15:51 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Ed\Downloads\mbar-1.07.0.1007.exe
2013-12-03 15:49 - 2013-12-03 15:49 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-12-03 15:48 - 2013-12-03 15:51 - 00000000 ____D C:\Users\Ed\Desktop\mbar
2013-12-03 13:52 - 2013-12-03 13:52 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-03 13:52 - 2013-12-03 13:52 - 00000000 ____D C:\Users\Ed\AppData\Roaming\Malwarebytes
2013-12-03 13:52 - 2013-12-03 13:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-03 13:52 - 2013-12-03 13:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-03 13:52 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-03 13:51 - 2013-12-03 13:51 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Ed\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-03 12:55 - 2013-12-03 12:55 - 00000000 ____D C:\Users\Ed\AppData\Local\{E3FF9AFD-0F5E-4EEB-8C55-A2422809F330}
2013-12-03 03:46 - 2013-10-30 11:03 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-12-03 03:46 - 2013-10-30 11:02 - 00032544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-12-02 16:24 - 2013-12-02 16:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{18780AD5-65BF-4D53-95B9-CA84BC185B66}
2013-12-02 04:24 - 2013-12-02 04:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{984015BD-2B92-4A96-BDE2-900DD6AC1D87}
2013-12-01 13:45 - 2013-12-01 13:45 - 00000000 ____D C:\Users\Ed\AppData\Local\{54C9D2E8-34B7-4758-8F0C-A6B51103CAAC}
2013-11-30 17:15 - 2013-11-30 17:15 - 00000000 ____D C:\Users\Ed\AppData\Local\{51A6B635-8A53-4D7E-9406-0A698DACF36D}
2013-11-30 11:56 - 2013-12-07 05:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-30 07:05 - 2013-11-30 07:05 - 03956736 _____ C:\Users\Ed\Downloads\tqsl-2.0.msi
2013-11-30 05:14 - 2013-11-30 05:15 - 00000000 ____D C:\Users\Ed\AppData\Local\{1E065FE7-A20D-4241-8392-CE7820631FDF}
2013-11-29 11:57 - 2013-11-29 11:57 - 00000000 ____D C:\Users\Ed\AppData\Local\ESN
2013-11-29 07:32 - 2013-12-04 14:35 - 00000000 ____D C:\Windows\system32\appmgmt
2013-11-29 06:18 - 2013-11-29 06:18 - 00000000 ____D C:\Users\Ed\AppData\Local\{D80F444C-B810-4FBC-BB02-099696FC2757}
2013-11-28 20:19 - 2013-11-28 20:19 - 00000000 ____D C:\Users\Ed\AppData\Local\{0137348C-977F-4B5E-8FDC-63E6A6501574}
2013-11-28 07:05 - 2013-11-28 07:06 - 00000000 ____D C:\Users\Ed\AppData\Local\{46F8D2FF-13A4-4308-A289-548DCF306266}
2013-11-27 14:53 - 2013-10-16 10:18 - 00439296 _____ (Adpeak, Inc.) C:\Windows\system32\AdpeakProxy64.dll
2013-11-27 03:24 - 2013-11-27 03:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{C1855F00-81C4-444F-A273-986BCAB20646}
2013-11-26 12:33 - 2013-11-26 12:33 - 00000000 ____D C:\Users\Ed\AppData\Local\{0BDD6E47-23FC-4EBF-8FAC-540D5CD09112}
2013-11-26 03:03 - 2013-11-26 03:03 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:03 - 2013-11-26 03:03 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:03 - 2013-11-26 03:03 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:03 - 2013-11-26 03:03 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:03 - 2013-11-26 03:03 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:03 - 2013-11-26 03:03 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:03 - 2013-11-26 03:03 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:03 - 2013-11-26 03:03 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:03 - 2013-11-26 03:03 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:03 - 2013-11-26 03:03 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:03 - 2013-11-26 03:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-11-26 03:02 - 2013-11-26 03:02 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-11-26 03:02 - 2013-11-26 03:02 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-11-26 03:02 - 2013-11-26 03:02 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-11-26 03:02 - 2013-11-26 03:02 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-11-26 03:02 - 2013-11-26 03:02 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-11-26 03:02 - 2013-11-26 03:02 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-11-25 17:15 - 2013-11-25 17:15 - 00000000 ____D C:\Users\Ed\AppData\Local\{27916ED4-233F-4CC9-BE5F-741F4BB96BAC}
2013-11-25 03:25 - 2013-11-25 03:25 - 00000000 ____D C:\Users\Ed\AppData\Local\{9726D7F3-2222-47CC-B98A-609A3F247C99}
2013-11-24 09:56 - 2013-11-24 09:56 - 00000000 ____D C:\Users\Ed\AppData\Local\{DD812169-74DC-4E45-BB81-B85713AA93D5}
2013-11-23 18:46 - 2013-11-23 18:46 - 00000000 ____D C:\Users\Ed\AppData\Local\{0F2C103A-69BC-4211-B217-0ECD8E448E9B}
2013-11-23 06:45 - 2013-11-23 06:45 - 00000000 ____D C:\Users\Ed\AppData\Local\{78D154F9-6508-4C27-BFAC-495ACFBD3B19}
2013-11-22 15:57 - 2013-11-22 15:57 - 00000000 ____D C:\Users\Ed\AppData\Local\{F3EB8D23-3421-41EA-A4F0-2C031A07C1B8}
2013-11-22 03:57 - 2013-11-22 03:57 - 00000000 ____D C:\Users\Ed\AppData\Local\{2FA74BB0-29A1-48CA-8E02-B176F4BC9B3D}
2013-11-21 15:57 - 2013-11-21 15:57 - 00000000 ____D C:\Users\Ed\AppData\Local\{4B5B377B-24C6-4460-A7EB-DB4A01F8B538}
2013-11-21 15:37 - 2013-11-21 15:41 - 02577579 _____ C:\Users\Ed\Downloads\Win-EQF_PATCH_233_SETUP.exe
2013-11-21 03:56 - 2013-11-21 03:57 - 00000000 ____D C:\Users\Ed\AppData\Local\{34EB0392-FC8D-44AE-AADE-B4A8F4C1037D}
2013-11-20 15:56 - 2013-11-20 15:56 - 00000000 ____D C:\Users\Ed\AppData\Local\{33CE4836-325F-44AA-BE94-B9E5A2A3E161}
2013-11-20 03:56 - 2013-11-20 03:56 - 00000000 ____D C:\Users\Ed\AppData\Local\{ABCB8EB9-D5D9-4435-BE3C-9F8875126C1F}
2013-11-20 03:52 - 2013-11-14 05:55 - 30361888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 22951200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 15862272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 12613408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-11-20 03:52 - 2013-11-14 05:55 - 11600432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 11514624 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 09691888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 09619872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433182.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433182.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00707360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00657184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00609568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00562464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00357152 _____ C:\Windows\system32\NvIFROpenGL.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00314656 _____ C:\Windows\SysWOW64\NvIFROpenGL.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-11-20 03:52 - 2013-11-14 05:55 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-11-19 13:27 - 2013-11-19 13:27 - 00000000 ____D C:\Users\Ed\AppData\Local\{DB3D6AB5-C69B-44EB-B6C7-9138F0D54C2F}
2013-11-18 16:24 - 2013-11-18 16:25 - 00000000 ____D C:\Users\Ed\AppData\Local\{3525B242-EDDB-47A4-9EEB-67D97B19A660}
2013-11-18 04:24 - 2013-11-18 04:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{8E5EE1FA-61DD-4D15-8387-BBCAC83865ED}
2013-11-17 06:20 - 2013-11-17 06:20 - 00000000 ____D C:\Users\Ed\AppData\Local\{1D11FDA9-84CE-42BA-AD7F-61546CD17E55}
2013-11-16 10:29 - 2013-11-16 10:29 - 00000802 _____ C:\Users\Public\Desktop\World of Warplanes.lnk
2013-11-16 09:38 - 2013-11-16 09:38 - 00000000 ____D C:\Users\Ed\AppData\Local\{7E29528B-F6C1-45F5-ACE6-782E79162091}
2013-11-15 15:53 - 2013-11-15 15:53 - 00000000 ____D C:\Users\Ed\AppData\Local\{41BF8198-E23B-40A4-AD55-8FE13C4CD77E}
2013-11-15 03:52 - 2013-11-15 03:52 - 00000000 ____D C:\Users\Ed\AppData\Local\{ED97C73B-2013-4381-A5FD-D62D112AA896}
2013-11-14 14:54 - 2013-11-14 14:54 - 03820824 _____ C:\Users\Ed\Downloads\battlelog-web-plugins_2.3.1_125.exe
2013-11-14 11:45 - 2013-11-14 11:45 - 00000000 ____D C:\Users\Ed\AppData\Local\{23335C86-A43B-4E36-8FC9-B19DCAB9462D}
2013-11-13 15:54 - 2013-11-13 15:54 - 00000000 ____D C:\Users\Ed\AppData\Local\{8D6147D5-84D3-4F88-B231-A8D47DC28AFE}
2013-11-13 04:10 - 2013-10-11 20:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-13 04:10 - 2013-10-11 20:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-13 04:10 - 2013-10-11 20:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 04:10 - 2013-10-11 20:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-13 04:10 - 2013-10-11 20:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-13 04:10 - 2013-10-05 14:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-13 04:10 - 2013-10-05 13:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-13 04:10 - 2013-10-02 20:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 04:10 - 2013-10-02 20:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-13 04:10 - 2013-09-27 19:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-13 04:10 - 2013-09-24 20:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-13 04:10 - 2013-09-24 20:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-13 04:10 - 2013-09-24 20:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-13 04:10 - 2013-09-24 20:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-13 04:10 - 2013-09-24 20:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-13 04:10 - 2013-09-24 20:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-13 04:10 - 2013-09-24 20:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-13 04:10 - 2013-09-24 20:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-13 04:10 - 2013-09-24 19:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-13 04:10 - 2013-09-24 19:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-13 04:10 - 2013-09-24 19:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-13 04:10 - 2013-09-24 19:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-13 04:10 - 2013-09-24 19:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-13 04:10 - 2013-07-04 06:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-13 03:54 - 2013-11-13 03:54 - 00000000 ____D C:\Users\Ed\AppData\Local\{F53800AB-3D2A-4438-ACF7-C94081C4D4D1}
2013-11-12 16:24 - 2013-12-03 03:48 - 00000000 ____D C:\Users\Ed\AppData\Local\NVIDIA Corporation
2013-11-12 15:53 - 2013-11-12 15:54 - 00000000 ____D C:\Users\Ed\AppData\Local\{1259A913-C936-4E96-8DA1-7F087514AC33}
2013-11-11 13:32 - 2013-11-11 13:32 - 00000000 ____D C:\Users\Ed\AppData\Local\{7D84B7E6-A806-4350-9D24-C8BC45197AB2}
2013-11-10 18:50 - 2013-11-10 18:50 - 00000000 ____D C:\Users\Ed\AppData\Local\{D90F83FA-0728-4C6D-B7A7-4879FF96E991}
2013-11-10 06:50 - 2013-11-10 06:50 - 00000000 ____D C:\Users\Ed\AppData\Local\{D89E8686-F589-4D3E-9318-C9E1C7273180}
2013-11-09 18:49 - 2013-11-09 18:49 - 00000000 ____D C:\Users\Ed\AppData\Local\{6C64EE28-A29D-4EB4-B42D-B5156845BD95}
2013-11-09 06:49 - 2013-11-09 06:49 - 00000000 ____D C:\Users\Ed\AppData\Local\{FFF63677-E3C6-4F42-97D1-F397420883D2}
2013-11-08 15:24 - 2013-11-08 15:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{FE593ADB-732C-474F-9A9D-6719EB8B20B1}
2013-11-08 03:24 - 2013-11-08 03:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{7C64967F-157B-4EA0-BDDE-083F87AA4A9D}

==================== One Month Modified Files and Folders =======

2013-12-08 07:32 - 2013-12-07 11:34 - 00018759 _____ C:\Users\Ed\Downloads\FRST.txt
2013-12-08 07:31 - 2013-12-08 07:31 - 01927772 _____ (Farbar) C:\Users\Ed\Downloads\FRST64(2).exe
2013-12-08 06:57 - 2012-08-29 19:07 - 00000890 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-08 06:36 - 2012-05-12 18:13 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-08 03:57 - 2012-08-29 19:07 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-08 03:37 - 2012-05-12 06:57 - 02046204 _____ C:\Windows\WindowsUpdate.log
2013-12-08 01:15 - 2009-07-13 22:45 - 00023120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-08 01:15 - 2009-07-13 22:45 - 00023120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-07 18:16 - 2013-10-01 17:37 - 00003010 _____ C:\Windows\System32\Tasks\EVGAPrecision
2013-12-07 18:14 - 2012-05-13 05:00 - 00000000 ____D C:\Program Files (x86)\Steam
2013-12-07 18:13 - 2013-12-07 11:56 - 00000672 _____ C:\Windows\setupact.log
2013-12-07 18:12 - 2012-05-12 18:26 - 00000000 ____D C:\Program Files (x86)\Origin
2013-12-07 18:12 - 2009-07-13 23:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-07 18:08 - 2013-12-07 18:08 - 00000000 ____D C:\Users\Ed\AppData\Local\{ACA299CB-3F13-4965-A0DB-5EAFF6BECAC3}
2013-12-07 17:48 - 2013-12-07 17:48 - 01927514 _____ (Farbar) C:\Users\Ed\Downloads\FRST64(1).exe
2013-12-07 16:29 - 2012-05-12 18:17 - 00000000 ____D C:\Users\Ed\AppData\Roaming\TS3Client
2013-12-07 13:36 - 2012-05-12 20:37 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-12-07 11:56 - 2013-12-07 11:56 - 00000000 _____ C:\Windows\setuperr.log
2013-12-07 11:34 - 2013-12-07 11:34 - 00000000 ____D C:\FRST
2013-12-07 11:33 - 2013-12-07 11:33 - 01927514 _____ (Farbar) C:\Users\Ed\Downloads\FRST64.exe
2013-12-07 07:58 - 2012-05-12 07:53 - 00000000 ____D C:\Windows\Panther
2013-12-07 07:01 - 2013-12-07 07:01 - 03541544 _____ (Piriform Ltd) C:\Users\Ed\Downloads\ccsetup408_slim.exe
2013-12-07 07:01 - 2012-11-09 17:14 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-07 07:01 - 2012-11-09 17:14 - 00000000 ____D C:\Program Files\CCleaner
2013-12-07 05:59 - 2013-12-07 05:55 - 00000000 ____D C:\AdwCleaner
2013-12-07 05:59 - 2013-11-30 11:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-07 04:39 - 2013-12-07 04:39 - 00000000 ____D C:\Users\Ed\AppData\Local\{764D0C03-A94C-460B-8719-4A5CB90C0B62}
2013-12-06 12:15 - 2013-12-06 12:15 - 00000000 ____D C:\Users\Ed\AppData\Local\{615825AD-93DB-49CD-8628-4E29C112AF90}
2013-12-05 18:52 - 2013-12-05 18:52 - 00165376 _____ C:\Users\Ed\Desktop\SystemLook_x64.exe
2013-12-05 18:49 - 2013-12-05 18:49 - 01110034 _____ C:\Users\Ed\Desktop\AdwCleaner.exe
2013-12-05 17:16 - 2013-12-05 17:16 - 00000000 ____D C:\Users\Ed\AppData\Local\{D42481F5-132D-4129-B9CC-E1E3FA4644BB}
2013-12-05 16:18 - 2012-05-12 20:37 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-12-05 04:26 - 2013-12-05 04:26 - 00000000 ____D C:\Users\Ed\AppData\Local\{8840809B-3803-4EAB-AADF-4A3D93BC3D97}
2013-12-04 14:38 - 2009-07-13 23:13 - 00778834 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-04 14:37 - 2013-12-04 14:37 - 00000000 ____D C:\Users\Ed\AppData\Local\{F1D2929C-E8A5-4C89-B64E-E03327C6BC8B}
2013-12-04 14:35 - 2013-11-29 07:32 - 00000000 ____D C:\Windows\system32\appmgmt
2013-12-04 14:29 - 2012-11-29 15:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-03 15:51 - 2013-12-03 15:51 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Ed\Downloads\mbar-1.07.0.1007.exe
2013-12-03 15:51 - 2013-12-03 15:48 - 00000000 ____D C:\Users\Ed\Desktop\mbar
2013-12-03 15:49 - 2013-12-03 15:49 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-12-03 13:52 - 2013-12-03 13:52 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-03 13:52 - 2013-12-03 13:52 - 00000000 ____D C:\Users\Ed\AppData\Roaming\Malwarebytes
2013-12-03 13:52 - 2013-12-03 13:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-03 13:52 - 2013-12-03 13:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-03 13:51 - 2013-12-03 13:51 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Ed\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-03 13:02 - 2012-05-15 06:23 - 00000000 ____D C:\Users\Ed\AppData\Local\Adobe
2013-12-03 13:02 - 2012-05-12 18:13 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-03 13:01 - 2012-05-12 18:13 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-03 13:01 - 2012-05-12 18:13 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-03 12:55 - 2013-12-03 12:55 - 00000000 ____D C:\Users\Ed\AppData\Local\{E3FF9AFD-0F5E-4EEB-8C55-A2422809F330}
2013-12-03 03:52 - 2012-08-29 19:07 - 00003886 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-03 03:52 - 2012-08-29 19:07 - 00003634 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-03 03:48 - 2013-11-12 16:24 - 00000000 ____D C:\Users\Ed\AppData\Local\NVIDIA Corporation
2013-12-03 03:48 - 2013-06-23 17:20 - 00000000 ____D C:\Users\Ed\AppData\Local\NVIDIA
2013-12-03 03:48 - 2012-10-16 03:10 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-12-03 03:48 - 2012-05-12 16:31 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-03 03:47 - 2012-05-12 16:31 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-12-03 03:47 - 2012-05-12 16:30 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-12-02 16:24 - 2013-12-02 16:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{18780AD5-65BF-4D53-95B9-CA84BC185B66}
2013-12-02 04:24 - 2013-12-02 04:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{984015BD-2B92-4A96-BDE2-900DD6AC1D87}
2013-12-01 13:45 - 2013-12-01 13:45 - 00000000 ____D C:\Users\Ed\AppData\Local\{54C9D2E8-34B7-4758-8F0C-A6B51103CAAC}
2013-12-01 05:40 - 2012-05-15 07:54 - 00000000 ____D C:\Users\Ed\AppData\Local\Mozilla
2013-11-30 17:15 - 2013-11-30 17:15 - 00000000 ____D C:\Users\Ed\AppData\Local\{51A6B635-8A53-4D7E-9406-0A698DACF36D}
2013-11-30 07:05 - 2013-11-30 07:05 - 03956736 _____ C:\Users\Ed\Downloads\tqsl-2.0.msi
2013-11-30 05:15 - 2013-11-30 05:14 - 00000000 ____D C:\Users\Ed\AppData\Local\{1E065FE7-A20D-4241-8392-CE7820631FDF}
2013-11-29 20:36 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\rescache
2013-11-29 17:03 - 2013-10-01 16:29 - 00000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2013-11-29 11:57 - 2013-11-29 11:57 - 00000000 ____D C:\Users\Ed\AppData\Local\ESN
2013-11-29 11:43 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\system32\NDF
2013-11-29 11:00 - 2012-08-29 19:07 - 00000000 ____D C:\Program Files\Google
2013-11-29 11:00 - 2012-08-29 19:07 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-29 10:56 - 2013-10-28 16:05 - 01096480 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2013-11-29 10:56 - 2013-10-28 16:05 - 00979744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2013-11-29 07:29 - 2012-08-29 19:07 - 00000000 ____D C:\Users\Ed\AppData\Local\Google
2013-11-29 06:18 - 2013-11-29 06:18 - 00000000 ____D C:\Users\Ed\AppData\Local\{D80F444C-B810-4FBC-BB02-099696FC2757}
2013-11-28 20:19 - 2013-11-28 20:19 - 00000000 ____D C:\Users\Ed\AppData\Local\{0137348C-977F-4B5E-8FDC-63E6A6501574}
2013-11-28 17:38 - 2012-05-13 07:12 - 00000020 ____H C:\ProgramData\PKP_DLdu.DAT
2013-11-28 07:59 - 2012-05-13 03:32 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-11-28 07:06 - 2013-11-28 07:05 - 00000000 ____D C:\Users\Ed\AppData\Local\{46F8D2FF-13A4-4308-A289-548DCF306266}
2013-11-27 22:16 - 2012-05-13 03:36 - 00000000 ____D C:\Users\Ed\AppData\Local\WeatherBug
2013-11-27 03:24 - 2013-11-27 03:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{C1855F00-81C4-444F-A273-986BCAB20646}
2013-11-26 12:33 - 2013-11-26 12:33 - 00000000 ____D C:\Users\Ed\AppData\Local\{0BDD6E47-23FC-4EBF-8FAC-540D5CD09112}
2013-11-26 03:24 - 2012-05-12 16:11 - 00001417 _____ C:\Users\Ed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-26 03:21 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-26 03:03 - 2013-11-26 03:03 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:03 - 2013-11-26 03:03 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:03 - 2013-11-26 03:03 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:03 - 2013-11-26 03:03 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:03 - 2013-11-26 03:03 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:03 - 2013-11-26 03:03 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:03 - 2013-11-26 03:03 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:03 - 2013-11-26 03:03 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:03 - 2013-11-26 03:03 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:03 - 2013-11-26 03:03 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:03 - 2013-11-26 03:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:03 - 2013-11-26 03:03 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:03 - 2013-11-26 03:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-11-26 03:02 - 2013-11-26 03:02 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-11-26 03:02 - 2013-11-26 03:02 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-11-26 03:02 - 2013-11-26 03:02 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-11-26 03:02 - 2013-11-26 03:02 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-11-26 03:02 - 2013-11-26 03:02 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-11-26 03:02 - 2013-11-26 03:02 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-11-26 03:02 - 2013-11-26 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-11-25 17:15 - 2013-11-25 17:15 - 00000000 ____D C:\Users\Ed\AppData\Local\{27916ED4-233F-4CC9-BE5F-741F4BB96BAC}
2013-11-25 03:25 - 2013-11-25 03:25 - 00000000 ____D C:\Users\Ed\AppData\Local\{9726D7F3-2222-47CC-B98A-609A3F247C99}
2013-11-24 09:56 - 2013-11-24 09:56 - 00000000 ____D C:\Users\Ed\AppData\Local\{DD812169-74DC-4E45-BB81-B85713AA93D5}
2013-11-23 18:46 - 2013-11-23 18:46 - 00000000 ____D C:\Users\Ed\AppData\Local\{0F2C103A-69BC-4211-B217-0ECD8E448E9B}
2013-11-23 06:45 - 2013-11-23 06:45 - 00000000 ____D C:\Users\Ed\AppData\Local\{78D154F9-6508-4C27-BFAC-495ACFBD3B19}
2013-11-22 15:57 - 2013-11-22 15:57 - 00000000 ____D C:\Users\Ed\AppData\Local\{F3EB8D23-3421-41EA-A4F0-2C031A07C1B8}
2013-11-22 03:57 - 2013-11-22 03:57 - 00000000 ____D C:\Users\Ed\AppData\Local\{2FA74BB0-29A1-48CA-8E02-B176F4BC9B3D}
2013-11-21 15:57 - 2013-11-21 15:57 - 00000000 ____D C:\Users\Ed\AppData\Local\{4B5B377B-24C6-4460-A7EB-DB4A01F8B538}
2013-11-21 15:44 - 2012-09-24 06:30 - 00000000 ____D C:\Win-EQF2
2013-11-21 15:41 - 2013-11-21 15:37 - 02577579 _____ C:\Users\Ed\Downloads\Win-EQF_PATCH_233_SETUP.exe
2013-11-21 03:57 - 2013-11-21 03:56 - 00000000 ____D C:\Users\Ed\AppData\Local\{34EB0392-FC8D-44AE-AADE-B4A8F4C1037D}
2013-11-20 15:56 - 2013-11-20 15:56 - 00000000 ____D C:\Users\Ed\AppData\Local\{33CE4836-325F-44AA-BE94-B9E5A2A3E161}
2013-11-20 03:56 - 2013-11-20 03:56 - 00000000 ____D C:\Users\Ed\AppData\Local\{ABCB8EB9-D5D9-4435-BE3C-9F8875126C1F}
2013-11-19 13:27 - 2013-11-19 13:27 - 00000000 ____D C:\Users\Ed\AppData\Local\{DB3D6AB5-C69B-44EB-B6C7-9138F0D54C2F}
2013-11-19 04:21 - 2010-11-20 21:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-19 03:01 - 2012-05-12 16:38 - 00001945 _____ C:\Windows\epplauncher.mif
2013-11-19 03:01 - 2012-05-12 16:38 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-11-19 03:01 - 2012-05-12 16:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2013-11-18 16:25 - 2013-11-18 16:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{3525B242-EDDB-47A4-9EEB-67D97B19A660}
2013-11-18 04:24 - 2013-11-18 04:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{8E5EE1FA-61DD-4D15-8387-BBCAC83865ED}
2013-11-17 06:20 - 2013-11-17 06:20 - 00000000 ____D C:\Users\Ed\AppData\Local\{1D11FDA9-84CE-42BA-AD7F-61546CD17E55}
2013-11-16 14:28 - 2012-06-13 17:14 - 00000000 ____D C:\Users\Ed\AppData\Roaming\wargaming.net
2013-11-16 10:30 - 2012-06-13 17:14 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-11-16 10:29 - 2013-11-16 10:29 - 00000802 _____ C:\Users\Public\Desktop\World of Warplanes.lnk
2013-11-16 10:29 - 2012-06-13 17:14 - 00000000 ____D C:\Games
2013-11-16 09:38 - 2013-11-16 09:38 - 00000000 ____D C:\Users\Ed\AppData\Local\{7E29528B-F6C1-45F5-ACE6-782E79162091}
2013-11-15 15:53 - 2013-11-15 15:53 - 00000000 ____D C:\Users\Ed\AppData\Local\{41BF8198-E23B-40A4-AD55-8FE13C4CD77E}
2013-11-15 03:52 - 2013-11-15 03:52 - 00000000 ____D C:\Users\Ed\AppData\Local\{ED97C73B-2013-4381-A5FD-D62D112AA896}
2013-11-14 14:54 - 2013-11-14 14:54 - 03820824 _____ C:\Users\Ed\Downloads\battlelog-web-plugins_2.3.1_125.exe
2013-11-14 11:45 - 2013-11-14 11:45 - 00000000 ____D C:\Users\Ed\AppData\Local\{23335C86-A43B-4E36-8FC9-B19DCAB9462D}
2013-11-14 05:55 - 2013-11-20 03:52 - 30361888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 22951200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 15862272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 12613408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-11-14 05:55 - 2013-11-20 03:52 - 11600432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 11514624 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 09691888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 09619872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433182.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433182.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00707360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00657184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00609568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00562464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00357152 _____ C:\Windows\system32\NvIFROpenGL.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00314656 _____ C:\Windows\SysWOW64\NvIFROpenGL.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-11-14 05:55 - 2013-11-20 03:52 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-11-14 05:55 - 2013-10-21 15:11 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2013-11-14 05:55 - 2013-10-21 15:11 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2013-11-14 05:55 - 2013-10-21 15:10 - 18293608 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-11-14 05:55 - 2013-10-21 15:10 - 18208624 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-11-14 05:55 - 2013-10-21 15:10 - 15218504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-11-14 05:55 - 2013-10-21 15:10 - 03069608 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-11-14 05:55 - 2013-10-21 15:10 - 02697248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-11-14 05:55 - 2013-10-21 15:10 - 01436528 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-11-14 05:55 - 2013-10-21 15:10 - 00023754 _____ C:\Windows\system32\nvinfo.pb
2013-11-14 03:02 - 2013-08-06 02:00 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 03:01 - 2012-05-12 17:16 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-13 15:54 - 2013-11-13 15:54 - 00000000 ____D C:\Users\Ed\AppData\Local\{8D6147D5-84D3-4F88-B231-A8D47DC28AFE}
2013-11-13 03:54 - 2013-11-13 03:54 - 00000000 ____D C:\Users\Ed\AppData\Local\{F53800AB-3D2A-4438-ACF7-C94081C4D4D1}
2013-11-12 15:54 - 2013-11-12 15:53 - 00000000 ____D C:\Users\Ed\AppData\Local\{1259A913-C936-4E96-8DA1-7F087514AC33}
2013-11-11 13:32 - 2013-11-11 13:32 - 00000000 ____D C:\Users\Ed\AppData\Local\{7D84B7E6-A806-4350-9D24-C8BC45197AB2}
2013-11-11 09:02 - 2013-10-21 15:11 - 06674208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2013-11-11 09:02 - 2013-10-21 15:11 - 03490080 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2013-11-11 09:01 - 2013-10-21 15:11 - 03467927 _____ C:\Windows\system32\nvcoproc.bin
2013-11-11 09:01 - 2013-10-21 15:11 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2013-11-11 09:01 - 2013-10-21 15:11 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2013-11-11 09:01 - 2013-10-21 15:11 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-11-10 18:50 - 2013-11-10 18:50 - 00000000 ____D C:\Users\Ed\AppData\Local\{D90F83FA-0728-4C6D-B7A7-4879FF96E991}
2013-11-10 06:50 - 2013-11-10 06:50 - 00000000 ____D C:\Users\Ed\AppData\Local\{D89E8686-F589-4D3E-9318-C9E1C7273180}
2013-11-09 18:49 - 2013-11-09 18:49 - 00000000 ____D C:\Users\Ed\AppData\Local\{6C64EE28-A29D-4EB4-B42D-B5156845BD95}
2013-11-09 06:49 - 2013-11-09 06:49 - 00000000 ____D C:\Users\Ed\AppData\Local\{FFF63677-E3C6-4F42-97D1-F397420883D2}
2013-11-08 15:24 - 2013-11-08 15:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{FE593ADB-732C-474F-9A9D-6719EB8B20B1}
2013-11-08 03:24 - 2013-11-08 03:24 - 00000000 ____D C:\Users\Ed\AppData\Local\{7C64967F-157B-4EA0-BDDE-083F87AA4A9D}

Files to move or delete:
====================
C:\ProgramData\PKP_DLbx.DAT
C:\ProgramData\PKP_DLdu.DAT


Some content of TEMP:
====================
C:\Users\Ed\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-30 00:56

==================== End Of Log ============================

Addition.txt

Link to post
Share on other sites

Download the attached fixlist.txt to the same folder as FRST.

Run FRST.exe and click Fix only once and wait

The tool will create a log (Fixlog.txt) in the folder, please post it to your reply.

Then......

Just Update and run another quick scan with Malwarebytes.

MrC

Link to post
Share on other sites

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-12-2013
Ran by Ed at 2013-12-10 03:27:43 Run:1
Running from C:\Users\Ed\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Windows\system32\AdpeakProxy64.dll
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File

*****************

C:\Windows\system32\AdpeakProxy64.dll => Moved successfully.
HKCR\PROTOCOLS\Filter\application/x-ica => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=euc-jp => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=ISO-8859-1 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=MS936 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=MS949 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=MS950 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=UTF-8 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica; charset=UTF8 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=euc-jp => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=ISO-8859-1 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=MS936 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=MS949 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=MS950 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=UTF-8 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\application/x-ica;charset=UTF8 => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.
HKCR\PROTOCOLS\Filter\ica => Key deleted successfully.
HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => Key not found.

==== End of Fixlog ====

Link to post
Share on other sites

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.