Jump to content

Im infected with malware


Recommended Posts

Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

 
 
 
Scan with FRST in normal mode

Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start --> Computer (right click) --> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.

 

 

 

Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.

  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )

    [*]Leave everything else as it is. [*]Close all other running programs as well as your Browser. [*]Click the Scan button & wait for it to finish. [*]Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post. [*]Save it where you can easily find it, such as your desktop. [*]Please post the content of the ark.txt here.


**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Link to post
Share on other sites

frst.txt

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-03-2014 01

Ran by Royal (administrator) on ROYAL-PC on 08-03-2014 14:04:20

Running from C:\Users\Royal\Downloads

Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)

Internet Explorer Version 11

Boot Mode: Normal

The only official download link for FRST:

Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/

Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/

Download link from any site other than Bleeping Computer is unpermitted or outdated.

See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe

(AMD) C:\Windows\system32\atiesrxx.exe

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Just Develop It) C:\Program Files (x86)\MyPC Backup\BackupStack.exe

() C:\Program Files (x86)\LPT\srpts.exe

() C:\Program Files (x86)\Re-markit-soft\Re-markit157.exe

() C:\Program Files (x86)\Mega Browse\updateMegaBrowse.exe

(AMD) C:\Windows\system32\atieclxx.exe

() C:\Program Files (x86)\Re-markit-soft\Re-markit_wd.exe

() C:\Program Files (x86)\LPT\srptm.exe

(Systweak Inc) C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe

() C:\Program Files (x86)\Mega Browse\bin\utilMegaBrowse.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

(Smartbar) C:\Users\Royal\AppData\Local\Smartbar\Application\Muvic.exe

(PC Utilities Software Limited) C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe

(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE

(MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe

(PC Utilities Software Limited) C:\Program Files (x86)\Optimizer Pro\OptProReminder.exe

(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe

() C:\Users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsApp.exe

(Weather Notifications, LLC) C:\Users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlerts.exe

(TeamViewer GmbH) C:\Users\Royal\AppData\Local\Temp\TeamViewer\Version9\TeamViewer.exe

(TeamViewer GmbH) C:\Users\Royal\AppData\Local\Temp\TeamViewer\Version9\tv_w32.exe

(TeamViewer GmbH) C:\Users\Royal\AppData\Local\Temp\TeamViewer\Version9\tv_x64.exe

(TeamViewer GmbH) c:\users\royal\appdata\local\temp\teamviewer\version9\TeamViewer_Desktop.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

() C:\Users\Royal\AppData\Local\Smartbar\Application\Lrcnta.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

() C:\Users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsBrowser.exe

(Microsoft Corporation) C:\Windows\system32\wbem\WMIADAP.EXE

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)

HKLM\...\Run: [synTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)

HKLM-x32\...\Run: [sunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)

HKU\.DEFAULT\...\Policies\Explorer: [NoDriveAutoRun] 0xFFFFFF03

HKU\S-1-5-21-1242493167-1881160721-3933183209-1000\...\Run: [browser Infrastructure Helper] - C:\Users\Royal\AppData\Local\Smartbar\Application\Muvic.exe [28192 2014-02-25] (Smartbar)

HKU\S-1-5-21-1242493167-1881160721-3933183209-1000\...\Run: [Optimizer Pro] - C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [135160 2014-01-28] (PC Utilities Software Limited)

HKU\S-1-5-21-1242493167-1881160721-3933183209-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1

HKU\S-1-5-21-1242493167-1881160721-3933183209-1000\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1

HKU\S-1-5-21-1242493167-1881160721-3933183209-1000\...\Policies\Explorer: [NoResolveSearch] 1

HKU\S-1-5-21-1242493167-1881160721-3933183209-1000\...\Policies\Explorer: [NoInternetOpenWith] 1

HKU\S-1-5-21-1242493167-1881160721-3933183209-1000\...\Policies\Explorer: [HideSCAHealth] 1

HKU\S-1-5-21-1242493167-1881160721-3933183209-1000\...\Policies\Explorer: [NoDriveAutoRun] 0xFFFFFF03

HKU\S-1-5-21-1242493167-1881160721-3933183209-1000\...\MountPoints2: {9be4d3c4-1dbf-11e2-be39-806e6f6e6963} - D:\setup.exe

AppInit_DLLs: C:\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll => C:\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll [2681648 2014-03-06] ()

AppInit_DLLs-x32: c:\program files (x86)\optimizer pro\optprocrash.dll => c:\program files (x86)\optimizer pro\optprocrash.dll [2961368 2014-03-06] ()

Startup: C:\Users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk

ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)

Startup: C:\Users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Severe Weather Alerts App.lnk

ShortcutTarget: Severe Weather Alerts App.lnk -> C:\Users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsApp.exe ()

Startup: C:\Users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Severe Weather Alerts.lnk

ShortcutTarget: Severe Weather Alerts.lnk -> C:\Users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlerts.exe (Weather Notifications, LLC)

GroupPolicy: Group Policy on Chrome detected C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\user.js

FF DefaultSearchEngine: Bing

FF SelectedSearchEngine: Mysearchdial

FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll ()

FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)

FF Plugin: @microsoft.com/GENUINE - disabled No File

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)

FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()

FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()

FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)

FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)

FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)

FF Plugin-x32: @microsoft.com/GENUINE - disabled No File

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)

FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF SearchPlugin: C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\searchplugins\bingp.xml

FF SearchPlugin: C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\searchplugins\Mysearchdial.xml

FF SearchPlugin: C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\searchplugins\Web Search.xml

FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml

FF Extension: media enhance - C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com [2014-03-06]

FF Extension: Video-for-PC-1.2 - C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com [2014-03-06]

FF Extension: No Name - C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\Extensions\staged [2014-03-07]

FF Extension: Muvic - C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\Extensions\{3d45363c-d41c-7232-0a7b-86846627c592} [2014-03-07]

FF Extension: Ghostery - C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\Extensions\firefox@ghostery.com.xpi [2013-08-02]

FF Extension: Mega Browse - C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\Extensions\{29b136c9-938d-4d3d-8df8-d649d9b74d02}.xpi [2014-03-07]

FF Extension: Adblock Plus - C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-05-26]

FF HKCU\...\Firefox\Extensions: [{6df319e1-31f2-4ed6-acbc-5823e62f993f}] - C:\Program Files (x86)\Re-markit-soft\157.xpi

FF Extension: Re-markit - C:\Program Files (x86)\Re-markit-soft\157.xpi [2014-03-06]

Chrome:

=======

CHR DefaultSearchKeyword: mysearchdial.com

CHR DefaultSearchProvider: Mysearchdial

CHR DefaultSearchURL: http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=cmi_14_10_CH&cd=2XzuyEtN2Y1L1QzuzzyEtAyEzyyByByC0AtC0CtA0FtA0ByEtN0D0Tzu0SyBzyyBtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0FyE0AtD0E0CtAtG0E0CyCyCtGtDyEtBzytGyE0EyByDtGyDzyzztDyCtBtDzy0A0C0CyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAtCtDtA0FzytDzytGtB0BzytCtGtCyCtBtCtGzz0AtC0DtGtBtAtDtByCyEyB0FtCyD0BtA2Q&cr=999030109&ir=

CHR DefaultNewTabURL:

CHR Extension: (Google Docs) - C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-21]

CHR Extension: (Google Drive) - C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-21]

CHR Extension: (YouTube) - C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-21]

CHR Extension: (Google Search) - C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-21]

CHR Extension: (Re-markit) - C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcpfhaghaadpjpgocojgnlhjcieeooel [2014-03-06]

CHR Extension: (media enhance) - C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo [2014-03-07]

CHR Extension: (Video-for-PC-1.2) - C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna [2014-03-06]

CHR Extension: (Google Wallet) - C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-21]

CHR Extension: (Gmail) - C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-21]

CHR HKCU\...\Chrome\Extension: [ahilkiibpgjnonbhdfkkgjddddmapala] - C:\Users\Royal\AppData\Local\CRE\ahilkiibpgjnonbhdfkkgjddddmapala.crx [2014-01-21]

CHR HKLM-x32\...\Chrome\Extension: [ahilkiibpgjnonbhdfkkgjddddmapala] - C:\Users\Royal\AppData\Local\CRE\ahilkiibpgjnonbhdfkkgjddddmapala.crx [2014-01-21]

CHR HKLM-x32\...\Chrome\Extension: [igjjkeeamkpihpncmmbgdkhdnjpcfmfb] - C:\Program Files (x86)\FriendsChecker\Chrome\common.crx [2014-01-21]

CHR HKLM\SOFTWARE\Policies\Google: Policy restriction MD5 is legit

C:\Windows\SysWOW64\wininit.exe => MD5 is legit

C:\Windows\explorer.exe

[2011-05-07 14:01] - [2011-05-07 15:45] - 6451200 ____A (Microsoft Corporation) 9CB4B7CE6A51C6F0B148B6F244F8BE2E

C:\Windows\SysWOW64\explorer.exe

[2011-05-07 14:01] - [2011-05-07 15:46] - 6195712 ____A (Microsoft Corporation) 1D27E95A126A421CF47EFF43D75C6F0E

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\rpcss.dll

[2011-05-07 13:46] - [2011-05-07 13:46] - 0512000 ____A (Microsoft Corporation) 225EFEE8960E554F3AB9A4A91790C039

ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2014-03-01 08:52

==================== End Of Log ============================

addition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2014 01

Ran by Royal at 2014-03-08 14:05:58

Running from C:\Users\Royal\Downloads

Boot Mode: Normal

==========================================================

==================== Security Center ========================

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Acoustica Mixcraft 6 (HKLM-x32\...\Acoustica Mixcraft 6) (Version: b217 - Acoustica)

Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated)

Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated)

Adobe Reader XI (11.0.05) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.05 - Adobe Systems Incorporated)

Advanced System Protector (HKLM-x32\...\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1) (Version: 2.1.1000.12594 - Systweak Software) C:\Program Files (x86)\media enhance\media enhance-chromeinstaller.exe [2014-03-06] (feven)

Task: {E46FF33A-4527-4A59-8B9D-612EC4F01490} - System32\Tasks\Video-for-PC-1.2-enabler => C:\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-enabler.exe [2014-03-06] (fun-games)

Task: {EAF60506-8818-4E62-8917-E813AFA880F4} - System32\Tasks\Video-for-PC-1.2-codedownloader => C:\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-codedownloader.exe [2014-03-06] (fun-games)

Task: {EC5DF502-B455-4E60-8450-4313B3310E33} - System32\Tasks\Video-for-PC-1.2-updater => C:\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-updater.exe [2014-03-06] (fun-games)

Task: {ECDE4B50-70F0-4A36-AF39-877429A5119E} - System32\Tasks\media enhance-updater => C:\Program Files (x86)\media enhance\media enhance-updater.exe [2014-03-06] (feven)

Task: {FEA3629D-6927-4BB7-A489-6FC3A2978296} - System32\Tasks\media enhance-enabler => C:\Program Files (x86)\media enhance\media enhance-enabler.exe [2014-03-06] (feven) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

Task: C:\Windows\Tasks\APSnotifierCA.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\media enhance-chromeinstaller.job => C:\Program Files (x86)\media enhance\media enhance-chromeinstaller.exe

Task: C:\Windows\Tasks\media enhance-codedownloader.job => C:\Program Files (x86)\media enhance\media enhance-codedownloader.exe

Task: C:\Windows\Tasks\media enhance-enabler.job => C:\Program Files (x86)\media enhance\media enhance-enabler.exe C:\Program Files (x86)\media enhance\media enhance-firefoxinstaller.exe

Task: C:\Windows\Tasks\media enhance-updater.job => C:\Program Files (x86)\media enhance\media enhance-updater.exe

Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\Royal\AppData\Roaming\MySearchDial\UpdateProc\UpdateTask.exe C:\Program Files (x86)\Re-markit-soft\ReMar.exe C:\Program Files (x86)\Re-markit-soft\Re-markit_wd.exe C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe C:\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-chromeinstaller.exe

Task: C:\Windows\Tasks\Video-for-PC-1.2-codedownloader.job => C:\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-codedownloader.exe

Task: C:\Windows\Tasks\Video-for-PC-1.2-enabler.job => C:\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-enabler.exe

Task: C:\Windows\Tasks\Video-for-PC-1.2-firefoxinstaller.job => C:\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-firefoxinstaller.exe

Task: C:\Windows\Tasks\Video-for-PC-1.2-updater.job => C:\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-updater.exe

==================== Loaded Modules (whitelisted) =============

2014-02-18 07:32 - 2014-02-18 07:32 - 01102336 _____ () C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll

2014-02-18 07:38 - 2014-02-18 07:38 - 00012288 _____ () C:\Program Files (x86)\MyPC Backup\GetText.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00036384 _____ () C:\Program Files (x86)\LPT\srpts.exe

2014-03-06 19:28 - 2014-03-06 19:28 - 00195072 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markit157.exe

2014-03-07 13:45 - 2014-03-07 13:45 - 00111904 _____ () C:\Program Files (x86)\Mega Browse\updateMegaBrowse.exe

2014-03-06 19:28 - 2014-03-06 19:28 - 00093696 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markit_wd.exe

2014-02-25 11:54 - 2014-02-25 11:54 - 00023072 _____ () C:\Program Files (x86)\LPT\srptm.exe

2014-03-08 13:58 - 2014-03-08 13:58 - 00111904 _____ () C:\Program Files (x86)\Mega Browse\bin\utilMegaBrowse.exe

2013-07-08 23:02 - 2013-07-08 23:02 - 00348384 _____ () C:\Users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsApp.exe

2013-07-08 23:02 - 2013-07-08 23:02 - 00076000 _____ () C:\Users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsAppAPI.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00022560 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Lrcnta.exe

2013-07-08 23:02 - 2013-07-08 23:02 - 00114920 _____ () C:\Users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsBrowser.exe

2014-03-06 19:29 - 2014-03-06 19:29 - 00186496 _____ () c:\program files (x86)\optimizer pro\optprocrashSvc.dll

2014-03-06 19:29 - 2014-03-06 19:29 - 02961368 _____ () c:\program files (x86)\optimizer pro\optprocrash.dll

2012-08-27 22:33 - 2012-08-27 22:33 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

2012-08-27 22:33 - 2012-08-27 22:33 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00072224 _____ () C:\Program Files (x86)\LPT\srpt.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00023072 _____ () C:\Program Files (x86)\LPT\srptc.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00018976 _____ () C:\Program Files (x86)\LPT\Smartbar.Common.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00056864 _____ () C:\Program Files (x86)\LPT\srut.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00061472 _____ () C:\Program Files (x86)\LPT\sppsm.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00154656 _____ () C:\Program Files (x86)\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00027168 _____ () C:\Program Files (x86)\LPT\Smartbar.Personalization.Common.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00165408 _____ () C:\Program Files (x86)\LPT\Smartbar.Infrastructure.Utilities.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00043552 _____ () C:\Program Files (x86)\LPT\srbu.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00025120 _____ () C:\Program Files (x86)\LPT\srpdm.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00036896 _____ () C:\Program Files (x86)\LPT\Smartbar.Monetization.Proxy.ProxyService.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00046624 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00069152 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\srau.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00165408 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 01286176 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00067104 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\spbl.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00154656 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00014368 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\siem.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00061472 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\sppsm.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00696864 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00014880 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00078880 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00027168 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00056864 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\srut.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00029216 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\srsbs.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00065568 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00030752 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\srom.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00030752 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\smtu.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00038944 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\smta.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00024096 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\sgml.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00043552 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\srbu.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00061984 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00025120 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\srpdm.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00043552 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\MACTrackBarLib.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00035360 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00193056 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\sgmu.dll

2014-02-25 11:51 - 2014-02-25 11:51 - 00061440 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll

2014-02-25 11:54 - 2014-02-25 11:54 - 00255008 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\srns.dll

2014-03-04 21:43 - 2014-03-01 20:35 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\chrome_elf.dll

2014-03-04 21:43 - 2014-03-01 20:35 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\libglesv2.dll

2014-03-04 21:43 - 2014-03-01 20:35 - 00100168 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\libegl.dll

2014-03-04 21:43 - 2014-03-01 20:35 - 04061000 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\pdf.dll

2014-03-04 21:43 - 2014-03-01 20:35 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll

2014-03-04 21:43 - 2014-03-01 20:35 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ffmpegsumo.dll

2014-02-25 11:53 - 2014-02-25 11:53 - 00030240 _____ () C:\Users\Royal\AppData\Local\Smartbar\Application\lrcnt.dll

2014-03-04 21:43 - 2014-03-01 20:35 - 13632840 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Microsoft:d4OBf3BmDTzAsf8LRJiWc

AlternateDataStreams: C:\ProgramData\Microsoft:givSO4pqlw7GDC8Fr3XgNlFYHM9

AlternateDataStreams: C:\ProgramData\Microsoft:gJQSD9NXNhVErU24MAVr6GY

AlternateDataStreams: C:\ProgramData\Microsoft:ttQAiR076kUSWXW0RXGfZsjR

AlternateDataStreams: C:\ProgramData\Microsoft:xBb5f12nCJK3D20Ei6NU

AlternateDataStreams: C:\Users\Royal\Cookies:zShEV3KMA6HvedQujwTQXFU

AlternateDataStreams: C:\Users\Royal\Local Settings:5BQJTDvoudBdot7eqfCIyGcw

AlternateDataStreams: C:\Users\Royal\AppData\Local:5BQJTDvoudBdot7eqfCIyGcw

AlternateDataStreams: C:\Users\Royal\AppData\Local\Application Data:5BQJTDvoudBdot7eqfCIyGcw

AlternateDataStreams: C:\Users\Royal\AppData\Local\Temp:5qAJxDjdCrhNvifVTtaWlHtH

==================== Safe Mode (whitelisted) ===================

==================== Disabled items from MSCONFIG ==============

==================== Faulty Device Manager Devices =============

Name: PCI Device

Description: PCI Device

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

==================== Event log errors: =========================

Application errors:

==================

Error: (03/08/2014 02:05:59 PM) (Source: VSS) (User: )

Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

.

Operation:

Instantiating VSS server

Error: (03/08/2014 02:05:59 PM) (Source: VSS) (User: )

Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

]

Operation:

Instantiating VSS server

Error: (03/08/2014 02:04:20 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT AUTHORITY)

Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (03/08/2014 02:04:20 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT AUTHORITY)

Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (03/08/2014 01:58:59 PM) (Source: WinMgmt) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/07/2014 07:59:31 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT AUTHORITY)

Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (03/07/2014 07:59:31 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT AUTHORITY)

Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (03/07/2014 07:55:31 PM) (Source: WinMgmt) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/07/2014 07:42:43 PM) (Source: VSS) (User: )

Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

.

Operation:

Instantiating VSS server

Error: (03/07/2014 07:42:43 PM) (Source: VSS) (User: )

Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

]

Operation:

Instantiating VSS server

System errors:

=============

Error: (03/06/2014 07:30:51 PM) (Source: Service Control Manager) (User: )

Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the xDark Installer service, but this action failed with the following error:

%%1056

Error: (03/06/2014 07:29:26 PM) (Source: Service Control Manager) (User: )

Description: The Ask Update Service service terminated unexpectedly. It has done this 1 time(s).

Error: (03/06/2014 07:28:51 PM) (Source: Service Control Manager) (User: )

Description: The xDark Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

Error: (03/06/2014 07:09:31 PM) (Source: EventLog) (User: )

Description: The previous system shutdown at 10:16:27 PM on ‎3/‎4/‎2014 was unexpected.

Error: (03/04/2014 09:41:13 PM) (Source: Service Control Manager) (User: )

Description: The Google Update Service (gupdate) service hung on starting.

Error: (03/04/2014 09:36:36 PM) (Source: EventLog) (User: )

Description: The previous system shutdown at 4:45:23 PM on ‎3/‎2/‎2014 was unexpected.

Error: (03/02/2014 08:41:37 AM) (Source: EventLog) (User: )

Description: The previous system shutdown at 12:50:13 AM on ‎3/‎2/‎2014 was unexpected.

Error: (03/01/2014 09:07:52 AM) (Source: EventLog) (User: )

Description: The previous system shutdown at 8:59:12 AM on ‎3/‎1/‎2014 was unexpected.

Error: (03/01/2014 06:54:36 AM) (Source: EventLog) (User: )

Description: The previous system shutdown at 8:30:44 PM on ‎2/‎28/‎2014 was unexpected.

Error: (02/28/2014 07:44:56 PM) (Source: EventLog) (User: )

Description: The previous system shutdown at 9:12:31 PM on ‎2/‎26/‎2014 was unexpected.

Microsoft Office Sessions:

=========================

Error: (03/08/2014 02:05:59 PM) (Source: VSS)(User: )

Description: CoCreateInstance0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Operation:

Instantiating VSS server

Error: (03/08/2014 02:05:59 PM) (Source: VSS)(User: )

Description: {e579ab5f-1cc4-44b4-bed9-de0991ff0623}IVssCoordinatorEx20x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Operation:

Instantiating VSS server

Error: (03/08/2014 02:04:20 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT AUTHORITY)

Description: WmiApRplWmiApRpl8F20300004D070000

Error: (03/08/2014 02:04:20 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT AUTHORITY)

Description: Performance1637070000000000000000000009030000

Error: (03/08/2014 01:58:59 PM) (Source: WinMgmt)(User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/07/2014 07:59:31 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT AUTHORITY)

Description: WmiApRplWmiApRpl8F20300004D070000

Error: (03/07/2014 07:59:31 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT AUTHORITY)

Description: Performance1637070000000000000000000009030000

Error: (03/07/2014 07:55:31 PM) (Source: WinMgmt)(User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/07/2014 07:42:43 PM) (Source: VSS)(User: )

Description: CoCreateInstance0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Operation:

Instantiating VSS server

Error: (03/07/2014 07:42:43 PM) (Source: VSS)(User: )

Description: {e579ab5f-1cc4-44b4-bed9-de0991ff0623}IVssCoordinatorEx20x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Operation:

Instantiating VSS server

==================== Memory info ===========================

Percentage of memory in use: 60%

Total physical RAM: 3561.37 MB

Available physical RAM: 1419.21 MB

Total Pagefile: 7120.92 MB

Available Pagefile: 4440.38 MB

Total Virtual: 8192 MB

Available Virtual: 8191.77 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:433.28 GB) NTFS

Drive d: (REALRESULTSPRESENTATION) (CDROM) (Total:2.74 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 915B52F3)

Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Link to post
Share on other sites

ark.txt

GMER 2.1.19357 - http://www.gmer.net

Rootkit scan 2014-03-08 14:17:28

Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\0000005d TOSHIBA_ rev.MH00 465.76GB

Running: sqpvevjs.exe; Driver: C:\Users\Royal\AppData\Local\Temp\pglorpow.sys

---- Devices - GMER 2.1 ----

Device \FileSystem\Ntfs \Ntfs fffffa8003fde2c0

Device \Driver\usbehci \Device\USBFDO-3 fffffa8004b482c0

Device \Driver\usbehci \Device\USBPDO-1 fffffa8004b482c0

Device \Driver\amd_sata \Device\RaidPort0 fffffa8003fd82c0

Device \Driver\cdrom \Device\CdRom0 fffffa80048cb2c0

Device \Driver\NetBT \Device\NetBT_Tcpip_{E3740108-B89B-4D26-87AC-7BD0BBF4F64E} fffffa80049292c0

Device \Driver\usbohci \Device\USBFDO-4 fffffa8004b462c0

Device \Driver\usbohci \Device\USBFDO-0 fffffa8004b462c0

Device \Driver\usbohci \Device\USBPDO-2 fffffa8004b462c0

Device \Driver\NetBT \Device\NetBT_Tcpip_{580EA88C-8816-4AE5-B502-E7A58610BCEC} fffffa80049292c0

Device \Driver\NetBT \Device\NetBT_Tcpip_{5D01E21E-9970-49D2-A71D-40DF726C1984} fffffa80049292c0

Device \Driver\usbehci \Device\USBPDO-3 fffffa8004b482c0

Device \Driver\usbehci \Device\USBFDO-1 fffffa8004b482c0

Device \Driver\amd_sata \Device\0000005d fffffa8003fd82c0

Device \Driver\NetBT \Device\NetBt_Wins_Export fffffa80049292c0

Device \Driver\amd_sata \Device\ScsiPort0 fffffa8003fd82c0

Device \Driver\usbohci \Device\USBPDO-4 fffffa8004b462c0

Device \Driver\usbohci \Device\USBFDO-2 fffffa8004b462c0

Device \Driver\usbohci \Device\USBPDO-0 fffffa8004b462c0

Device \Driver\amd_sata \Device\0000005e fffffa8003fd82c0

---- Trace I/O - GMER 2.1 ----

Trace ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys >>UNKNOWN [0xfffffa8003fda2c0] \Device\Harddisk0\DR0[0xfffffa80047b9060] fffffa80047b9060

Trace 3 CLASSPNP.SYS[fffff88001a5443f] -> nt!IofCallDriver -> [0xfffffa80047b8b10] fffffa80047b8b10

Trace 5 hpdskflt.sys[fffff88001441189] -> nt!IofCallDriver -> [0xfffffa8004740ac0] fffffa8004740ac0

Trace \Driver\amd_xata[0xfffffa8004081470] -> IRP_MJ_CREATE -> 0xfffffa8003fda2c0 fffffa8003fda2c0

Trace 7 amd_xata.sys[fffff88000e46d00] -> nt!IofCallDriver -> \Device\0000005d[0xfffffa800473c540] fffffa800473c540

Trace \Driver\amd_sata[0xfffffa8004081cb0] -> IRP_MJ_CREATE -> 0xfffffa8003fd82c0 fffffa8003fd82c0

---- Processes - GMER 2.1 ----

Library C:\Users\Royal\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll (*** suspicious ***) @ C:\Users\Royal\AppData\Local\Smartbar\Application\Muvic.exe [3576](2014-02-25 17:51:04) 0000000068ff0000

---- Registry - GMER 2.1 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792

---- EOF - GMER 2.1 ----

Link to post
Share on other sites

Combofix

Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe



When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.

Link to post
Share on other sites

combofix.txt

ComboFix 14-03-10.01 - Royal 03/10/2014 19:56:04.1.2 - x64

State of Independence Windows 7 xDark™ v4.3 RG Deluxe 6.1.7601.1.1252.1.1033.18.3561.1986 [GMT -5:00]

Running from: c:\users\Royal\Desktop\ComboFix.exe

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\END

c:\program files (x86)\Video-for-PC-1.2\ViDEo-for-pc-1.2-bho.dll

c:\users\Royal\AppData\Local\AnyProtectScannerSetup.exe

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0\2

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_lndipknmjijnalnkamonmljeaojdbpna_0

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_lndipknmjijnalnkamonmljeaojdbpna_0\1

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\background.html

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\chromeCoreFilesIndex.txt

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\crossriderManifest.json

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\manifest.xml

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins.json

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\1_base.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\102_dealply_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\103_intext_5_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\104_jollywallet_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\13_CrossriderAppUtils.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\14_CrossriderUtils.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\155_ibario_pops_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\17_jQuery.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\177_crossriderDashboard.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\182_openUrl.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\183_tabsWrapper.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\184_noproblemppc_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\19_CHAppAPIWrapper.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\190_pops_5_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\191_ciuvo_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\195_icm_convertmedia_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\207_dbWrapper.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\21_debug.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\22_resources.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\220_icm_base_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\230_revizer_ws_dynamic_b2b_2_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\28_initializer.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\4_jquery_1_7_1.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\47_resources_background.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\64_appApiMessage.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\7_hooks.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\72_appApiValidation.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\78_CrossriderInfo.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\80_CHPopupAppAPI.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\9_search_engine_hook.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\91_monetizationLoader.js.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\93_superfish_no_coupons_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\97_resourceApiWrapper.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\userCode\background.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\userCode\extension.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\icons\actions\1.png

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\icons\icon128.png

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\icons\icon16.png

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\icons\icon48.png

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\api\chrome.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\api\cookie.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\api\message.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\api\monitor.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\api\pageAction.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\api\pageActionBG.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\background.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\app_api.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\bg_app_api.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\consts.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\cookie_store.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\crossriderAPI.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\delegate.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\events.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\extensionDataStore.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\installer.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\logFile.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\logging.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\onBGDocumentLoad.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\popupResource\newPopup.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\popupResource\popup.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\reports.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\storageWrapper.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\updateManager.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\util.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\lib\xhr.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\main.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\js\platformVersion.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\manifest.json

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\popup.html

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\background.html

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\chromeCoreFilesIndex.txt

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\crossriderManifest.json

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\manifest.xml

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins.json

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\1_base.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\102_dealply_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\103_intext_5_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\104_jollywallet_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\13_CrossriderAppUtils.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\14_CrossriderUtils.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\17_jQuery.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\177_crossriderDashboard.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\178_revizer_ws_dynamic_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\179_revizer_p_dynamic_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\180_bpo_serp_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\182_openUrl.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\183_tabsWrapper.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\184_noproblemppc_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\19_CHAppAPIWrapper.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\190_pops_5_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\191_ciuvo_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\195_icm_convertmedia_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\207_dbWrapper.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\21_debug.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\22_resources.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\220_icm_base_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\221_icm_downloads_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\223_imonomy_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\28_initializer.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\4_jquery_1_7_1.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\47_resources_background.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\64_appApiMessage.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\7_hooks.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\72_appApiValidation.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\78_CrossriderInfo.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\80_CHPopupAppAPI.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\9_search_engine_hook.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\91_monetizationLoader.js.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\93_superfish_no_coupons_m.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\97_resourceApiWrapper.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\userCode\background.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\userCode\extension.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\icons\actions\1.png

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\icons\icon128.png

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\icons\icon16.png

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\icons\icon48.png

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\api\chrome.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\api\cookie.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\api\message.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\api\monitor.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\api\pageAction.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\api\pageActionBG.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\background.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\app_api.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\bg_app_api.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\consts.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\cookie_store.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\crossriderAPI.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\delegate.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\events.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\extensionDataStore.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\installer.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\logFile.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\logging.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\onBGDocumentLoad.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\popupResource\newPopup.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\popupResource\popup.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\reports.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\storageWrapper.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\updateManager.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\util.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\lib\xhr.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\main.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\js\platformVersion.js

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\manifest.json

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\popup.html

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\000005.ldb

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\000008.ldb

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\000011.ldb

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\000015.log

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\CURRENT

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\LOCK

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\LOG

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\LOG.old

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\MANIFEST-000013

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lndipknmjijnalnkamonmljeaojdbpna

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lndipknmjijnalnkamonmljeaojdbpna\000016.ldb

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lndipknmjijnalnkamonmljeaojdbpna\000019.log

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lndipknmjijnalnkamonmljeaojdbpna\CURRENT

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lndipknmjijnalnkamonmljeaojdbpna\LOCK

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lndipknmjijnalnkamonmljeaojdbpna\LOG

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lndipknmjijnalnkamonmljeaojdbpna\LOG.old

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lndipknmjijnalnkamonmljeaojdbpna\MANIFEST-000017

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0.localstorage-journal

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0.localstorage

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lndipknmjijnalnkamonmljeaojdbpna_0.localstorage-journal

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lndipknmjijnalnkamonmljeaojdbpna_0.localstorage

c:\users\Royal\AppData\Local\Google\Chrome\User Data\Default\Preferences

c:\users\Royal\AppData\Local\Microsoft\Windows\Temporary Internet Files\Mega Browse_iels

c:\users\Royal\AppData\Local\nsd2ADA.tmp

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome.manifest

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\asyncDB.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\background.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\browserAction.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\contextMenu.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\dbManager.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\dom_bg.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\fileManager.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefox.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefoxNotifications.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefoxOmnibox.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\message.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\pageAction.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\request.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\tabs.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\webRequest.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\windowsMessagingHandler.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\background.html

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\baseObject.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\browser.xul

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\addressBarChangeObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\console.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\consts.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\delegate.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\extensionDataStore.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\folderIOWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\httpObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\IDBWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\installer.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\logFile.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\prefs.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\progressListenerObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\registry.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\reloadObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\reports.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\requestObject.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\searchSettings.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\uninstallObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\updateManager.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\utils.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\xhr.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\dialog.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\ffCoreFilesIndex.txt

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\main.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.xul

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\platformVersion.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\search_dialog.xul

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults\preferences\prefs.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\manifest.xml

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins.json

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\1_base.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\102_dealply_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\103_intext_5_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\104_jollywallet_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\13_CrossriderAppUtils.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\14_CrossriderUtils.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\155_ibario_pops_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\16_FFAppAPIWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\17_jQuery.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\177_crossriderDashboard.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\182_openUrl.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\183_tabsWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\184_noproblemppc_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\190_pops_5_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\191_ciuvo_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\195_icm_convertmedia_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\207_dbWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\21_debug.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\22_resources.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\220_icm_base_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\230_revizer_ws_dynamic_b2b_2_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\246_setup.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\28_initializer.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\4_jquery_1_7_1.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\47_resources_background.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\64_appApiMessage.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\7_hooks.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\72_appApiValidation.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\78_CrossriderInfo.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\9_search_engine_hook.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\91_monetizationLoader.js.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\93_superfish_no_coupons_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\98_omniCommands.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\userCode\background.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\userCode\extension.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\install.rdf

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale\en-US\translations.dtd

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button1.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button2.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button3.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button4.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button5.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\crossrider_statusbar.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon128.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon16.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon24.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon48.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\panelarrow-up.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\popup.html

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\skin.css

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\update.css

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome.manifest

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\asyncDB.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\background.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\browserAction.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\contextMenu.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\dbManager.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\dom_bg.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\fileManager.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\firefox.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\firefoxNotifications.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\firefoxOmnibox.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\message.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\pageAction.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\request.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\tabs.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\webRequest.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\windowsMessagingHandler.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\background.html

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\baseObject.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\browser.xul

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\addressBarChangeObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\console.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\consts.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\delegate.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\extensionDataStore.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\folderIOWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\httpObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\IDBWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\installer.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\logFile.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\prefs.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\progressListenerObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\registry.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\reloadObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\reports.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\requestObject.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\searchSettings.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\uninstallObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\updateManager.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\utils.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\xhr.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\dialog.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\ffCoreFilesIndex.txt

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\main.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\options.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\options.xul

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\platformVersion.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\search_dialog.xul

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\defaults\preferences\prefs.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\manifest.xml

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins.json

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\1_base.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\102_dealply_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\103_intext_5_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\104_jollywallet_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\119_similar_web_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\123_intext_adv_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\13_CrossriderAppUtils.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\14_CrossriderUtils.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\16_FFAppAPIWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\17_jQuery.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\177_crossriderDashboard.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\178_revizer_ws_dynamic_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\179_revizer_p_dynamic_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\180_bpo_serp_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\182_openUrl.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\183_tabsWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\184_noproblemppc_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\190_pops_5_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\191_ciuvo_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\195_icm_convertmedia_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\207_dbWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\21_debug.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\22_resources.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\220_icm_base_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\221_icm_downloads_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\223_imonomy_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\246_setup.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\28_initializer.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\4_jquery_1_7_1.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\47_resources_background.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\64_appApiMessage.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\7_hooks.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\72_appApiValidation.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\78_CrossriderInfo.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\9_search_engine_hook.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\91_monetizationLoader.js.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\93_superfish_no_coupons_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\98_omniCommands.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\userCode\background.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\userCode\extension.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\install.rdf

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\locale\en-US\translations.dtd

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\button1.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\button2.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\button3.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\button4.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\button5.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\crossrider_statusbar.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\icon128.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\icon16.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\icon24.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\icon48.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\panelarrow-up.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\popup.html

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\skin.css

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\update.css

.

.

((((((((((((((((((((((((( Files Created from 2014-02-11 to 2014-03-11 )))))))))))))))))))))))))))))))

.

.

2014-03-11 01:08 . 2014-03-11 01:08 -------- d-----w- c:\users\Default\AppData\Local\temp

2014-03-08 20:03 . 2014-03-08 20:06 -------- d-----w- C:\FRST

2014-03-08 02:05 . 2014-02-17 19:30 1031560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3812B880-443E-469F-9BA3-0CAE17528064}\gapaengine.dll

2014-03-08 02:05 . 2014-02-06 09:01 10536864 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E484415F-A141-41B7-97AC-606281DF094D}\mpengine.dll

2014-03-08 01:16 . 2014-03-08 01:16 -------- d-----w- c:\programdata\Systweak

2014-03-08 01:16 . 2014-03-08 01:16 -------- d-----w- c:\program files (x86)\Advanced System Protector

2014-03-08 01:16 . 2012-07-25 18:03 16896 ----a-w- c:\windows\system32\sasnative64.exe

2014-03-08 01:16 . 2014-03-08 19:58 -------- d-----w- c:\program files (x86)\Mega Browse

2014-03-08 01:15 . 2014-01-21 23:28 20312 ----a-w- c:\windows\system32\roboot64.exe

2014-03-08 01:15 . 2014-03-08 01:16 -------- d-----w- c:\users\Royal\AppData\Roaming\systweak

2014-03-08 01:15 . 2014-03-08 01:15 -------- d-----w- c:\users\Royal\AppData\Roaming\mysearchdial

2014-03-08 01:15 . 2014-03-08 01:15 -------- d-----w- c:\program files (x86)\Mysearchdial

2014-03-08 01:15 . 2014-03-08 01:15 -------- d-----w- c:\program files (x86)\RegClean Pro

2014-03-07 01:31 . 2014-03-08 01:17 -------- d-----w- c:\program files (x86)\AnyProtectEx

2014-03-07 01:31 . 2014-03-07 01:31 -------- d-----w- c:\users\Royal\AppData\Roaming\VOPackage

2014-03-07 01:30 . 2014-03-07 01:31 -------- d-----w- c:\program files (x86)\LPT

2014-03-07 01:30 . 2014-03-07 01:31 -------- d-----w- c:\program files (x86)\media enhance

2014-03-07 01:29 . 2014-03-11 01:02 -------- d-----w- c:\program files (x86)\Video-for-PC-1.2

2014-03-07 01:29 . 2014-03-07 01:29 -------- d-----w- c:\users\Royal\AppData\Roaming\Optimizer Pro

2014-03-07 01:29 . 2014-03-08 01:54 -------- d-----w- c:\program files (x86)\MyPC Backup

2014-03-07 01:29 . 2014-03-07 01:29 -------- d-----w- c:\program files (x86)\Optimizer Pro

2014-03-07 01:29 . 2014-03-08 01:16 -------- d-----w- c:\users\Royal\AppData\Local\LPT

2014-03-07 01:29 . 2014-03-07 01:29 -------- d-----w- c:\users\Royal\AppData\Local\Smartbar

2014-03-07 01:29 . 2014-03-07 01:29 -------- d-----w- c:\users\Royal\AppData\Local\Weather_Notifications,_LL

2014-03-07 01:28 . 2014-03-07 01:29 -------- d-----w- c:\program files (x86)\Re-markit-soft

2014-03-07 01:28 . 2014-03-11 00:59 -------- d-----w- c:\users\Royal\AppData\Local\SevereWeatherAlerts

2014-03-07 01:26 . 2014-03-07 01:26 -------- d-----w- c:\program files (x86)\Common Files\Java

2014-03-07 01:26 . 2014-03-07 01:26 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2014-03-07 01:20 . 2014-02-06 09:01 10536864 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2014-02-23 13:16 . 2013-12-21 09:53 548864 ----a-w- c:\windows\system32\vbscript.dll

2014-02-23 13:16 . 2013-12-21 08:56 454656 ----a-w- c:\windows\SysWow64\vbscript.dll

2014-02-16 16:40 . 2013-12-06 02:31 1880576 ----a-w- c:\windows\system32\msxml3.dll

2014-02-16 16:40 . 2013-12-06 02:31 2048 ----a-w- c:\windows\system32\msxml3r.dll

2014-02-16 16:40 . 2013-12-06 01:58 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll

2014-02-16 16:40 . 2013-12-06 01:58 1236480 ----a-w- c:\windows\SysWow64\msxml3.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2014-02-24 00:52 . 2012-10-26 03:53 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2014-02-24 00:52 . 2012-10-26 03:53 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2014-02-23 13:24 . 2012-10-24 10:12 88567024 ----a-w- c:\windows\system32\MRT.exe

2014-02-17 19:30 . 2012-11-29 00:12 1031560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll

2014-01-19 07:33 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe

2013-12-29 21:24 . 2013-12-29 21:24 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe

2013-12-29 21:24 . 2013-12-29 21:24 194048 ----a-w- c:\windows\SysWow64\elshyph.dll

2013-12-29 21:24 . 2013-12-29 21:24 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe

2013-12-29 21:24 . 2013-12-29 21:24 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll

2013-12-29 21:24 . 2013-12-29 21:24 235008 ----a-w- c:\windows\system32\elshyph.dll

2013-12-29 21:24 . 2013-12-29 21:24 182272 ----a-w- c:\windows\SysWow64\msls31.dll

2013-12-29 21:24 . 2013-12-29 21:24 62464 ----a-w- c:\windows\SysWow64\tdc.ocx

2013-12-29 21:24 . 2013-12-29 21:24 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll

2013-12-29 21:24 . 2013-12-29 21:24 337408 ----a-w- c:\windows\SysWow64\html.iec

2013-12-29 21:24 . 2013-12-29 21:24 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll

2013-12-29 21:24 . 2013-12-29 21:24 151552 ----a-w- c:\windows\SysWow64\iexpress.exe

2013-12-29 21:24 . 2013-12-29 21:24 139264 ----a-w- c:\windows\SysWow64\wextract.exe

2013-12-29 21:24 . 2013-12-29 21:24 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll

2013-12-29 21:24 . 2013-12-29 21:24 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll

2013-12-29 21:24 . 2013-12-29 21:24 36352 ----a-w- c:\windows\SysWow64\imgutil.dll

2013-12-29 21:24 . 2013-12-29 21:24 13312 ----a-w- c:\windows\SysWow64\mshta.exe

2013-12-29 21:24 . 2013-12-29 21:24 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll

2013-12-29 21:24 . 2013-12-29 21:24 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll

2013-12-29 21:24 . 2013-12-29 21:24 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe

2013-12-29 21:24 . 2013-12-29 21:24 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll

2013-12-29 21:24 . 2013-12-29 21:24 942592 ----a-w- c:\windows\system32\jsIntl.dll

2013-12-29 21:24 . 2013-12-29 21:24 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe

2013-12-29 21:24 . 2013-12-29 21:24 247808 ----a-w- c:\windows\system32\msls31.dll

2013-12-29 21:24 . 2013-12-29 21:24 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe

2013-12-29 21:24 . 2013-12-29 21:24 52224 ----a-w- c:\windows\system32\msfeedsbs.dll

2013-12-29 21:24 . 2013-12-29 21:24 48640 ----a-w- c:\windows\system32\mshtmler.dll

2013-12-29 21:24 . 2013-12-29 21:24 13312 ----a-w- c:\windows\system32\msfeedssync.exe

2013-12-29 21:24 . 2013-12-29 21:24 131072 ----a-w- c:\windows\system32\IEAdvpack.dll

2013-12-29 21:24 . 2013-12-29 21:24 105984 ----a-w- c:\windows\system32\iesysprep.dll

2013-12-29 21:24 . 2013-12-29 21:24 81408 ----a-w- c:\windows\system32\icardie.dll

2013-12-29 21:24 . 2013-12-29 21:24 77312 ----a-w- c:\windows\system32\tdc.ocx

2013-12-29 21:24 . 2013-12-29 21:24 616104 ----a-w- c:\windows\system32\ieapfltr.dat

2013-12-29 21:24 . 2013-12-29 21:24 453120 ----a-w- c:\windows\system32\dxtmsft.dll

2013-12-29 21:24 . 2013-12-29 21:24 413696 ----a-w- c:\windows\system32\html.iec

2013-12-29 21:24 . 2013-12-29 21:24 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll

2013-12-29 21:24 . 2013-12-29 21:24 296960 ----a-w- c:\windows\system32\dxtrans.dll

2013-12-29 21:24 . 2013-12-29 21:24 84992 ----a-w- c:\windows\system32\mshtmled.dll

2013-12-29 21:24 . 2013-12-29 21:24 30208 ----a-w- c:\windows\system32\licmgr10.dll

2013-12-29 21:24 . 2013-12-29 21:24 263376 ----a-w- c:\windows\system32\iedkcs32.dll

2013-12-29 21:24 . 2013-12-29 21:24 243200 ----a-w- c:\windows\system32\webcheck.dll

2013-12-29 21:24 . 2013-12-29 21:24 235520 ----a-w- c:\windows\system32\url.dll

2013-12-29 21:24 . 2013-12-29 21:24 167424 ----a-w- c:\windows\system32\iexpress.exe

2013-12-29 21:24 . 2013-12-29 21:24 143872 ----a-w- c:\windows\system32\wextract.exe

2013-12-29 21:24 . 2013-12-29 21:24 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll

2013-12-29 21:24 . 2013-12-29 21:24 101376 ----a-w- c:\windows\system32\inseng.dll

2013-12-29 21:24 . 2013-12-29 21:24 83968 ----a-w- c:\windows\system32\MshtmlDac.dll

2013-12-29 21:24 . 2013-12-29 21:24 774144 ----a-w- c:\windows\system32\jscript.dll

2013-12-29 21:24 . 2013-12-29 21:24 62464 ----a-w- c:\windows\system32\pngfilt.dll

2013-12-29 21:24 . 2013-12-29 21:24 48128 ----a-w- c:\windows\system32\imgutil.dll

2013-12-29 21:24 . 2013-12-29 21:24 147968 ----a-w- c:\windows\system32\occache.dll

2013-12-29 21:24 . 2013-12-29 21:24 13824 ----a-w- c:\windows\system32\mshta.exe

2013-12-29 21:24 . 2013-12-29 21:24 135680 ----a-w- c:\windows\system32\iepeers.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[7] 2009-07-14 . 1A47D52E303B7543E4E6026595B95422 . 1297408 . . [2001.12.8530.16385] .. c:\windows\winsxs\amd64_microsoft-windows-com-complus.res_31bf3856ad364e35_6.1.7600.16385_none_88a5cc7effe2dfca\comres.dll

[-] 2011-05-08 . 455BF4FE89F9EF9AECD1781EB87FB6F7 . 1312768 . . [2001.12.8530.16385] .. c:\windows\system32\comres.dll

.

[-] 2011-05-07 . 9CB4B7CE6A51C6F0B148B6F244F8BE2E . 6451200 . . [6.1.7600.16385] .. c:\windows\explorer.exe

[7] 2011-05-07 . 332FEAB1435662FC6C672E25BEB37BE3 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe

[7] 2011-05-07 . 3B69712041F3D63605529BD66DC00C48 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe

[7] 2010-11-21 . AC4C51EB24AA95B77F705AB159189E24 . 2872320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

.

[-] 2011-05-08 . 3F653D870A391612B32090F92ABC9AAA . 614912 . . [6.1.7600.16385] .. c:\windows\regedit.exe

[7] 2009-07-14 . 2E2C937846A0B8789E5E91739284D17A . 427008 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5023a70bf589ad3e\regedit.exe

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110411411150}]

2014-03-07 01:31 509144 ----a-w- c:\program files (x86)\media enhance\media enhance-bho.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}]

2010-11-21 03:24 297808 ----a-w- c:\windows\System32\mscoree.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{4e6cd411-ce62-4584-97ff-6afbcf6900af}]

2014-03-07 19:45 249632 ----a-w- c:\program files (x86)\Mega Browse\MegaBrowseBHO.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}]

2014-03-08 01:15 279960 ----a-w- c:\program files (x86)\Mysearchdial\1.8.29.0\bh\mysearchdial.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]

"{3004627E-F8E9-4E8B-909D-316753CBA923}"= "c:\program files (x86)\Mysearchdial\1.8.29.0\mysearchdialTlbr.dll" [2014-03-08 288664]

.

[HKEY_CLASSES_ROOT\clsid\{3004627e-f8e9-4e8b-909d-316753cba923}]

[HKEY_CLASSES_ROOT\mysearchdial.mysearchdialdskBnd.1]

[HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]

[HKEY_CLASSES_ROOT\mysearchdial.mysearchdialdskBnd]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Browser Infrastructure Helper"="c:\users\Royal\AppData\Local\Smartbar\Application\Muvic.exe" [2014-02-25 28192]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]

.

c:\users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

MyPC Backup.lnk - c:\program files (x86)\MyPC Backup\MyPC Backup.exe [2014-2-18 2889256]

Severe Weather Alerts App.lnk - c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsApp.exe [2013-7-9 348384]

Severe Weather Alerts.lnk - c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlerts.exe /restart [2013-7-1 84184]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"EnableLUA"= 0 (0x0)

"EnableSecureUIAPaths"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"EnableVirtualization"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"SynchronousMachineGroupPolicy"= 1 (0x1)

"SynchronousUserGroupPolicy"= 1 (0x1)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoResolveTrack"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R2 70e6ca8c;Optimizer Pro Crash Monitor;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]

R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]

R3 MAUSBPRODUCER;Service for M-Audio Producer;c:\windows\system32\DRIVERS\MAudioProducer.sys;c:\windows\SYSNATIVE\DRIVERS\MAudioProducer.sys [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]

R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\drivers\Synth3dVsc.sys;c:\windows\SYSNATIVE\drivers\Synth3dVsc.sys [x]

R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]

R4 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]

R4 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]

S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]

S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]

S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmpfd.sys [x]

S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]

S2 BackupStack;Computer Backup (MyPC Backup);c:\program files (x86)\MyPC Backup\BackupStack.exe;c:\program files (x86)\MyPC Backup\BackupStack.exe [x]

S2 LPTSystemUpdater;LPT System Updater Service;c:\program files (x86)\LPT\srpts.exe;c:\program files (x86)\LPT\srpts.exe [x]

S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]

S2 Re-markit;Re-markit;c:\program files (x86)\Re-markit-soft\Re-markit157.exe;c:\program files (x86)\Re-markit-soft\Re-markit157.exe [x]

S2 Update Mega Browse;Update Mega Browse;c:\program files (x86)\Mega Browse\updateMegaBrowse.exe;c:\program files (x86)\Mega Browse\updateMegaBrowse.exe [x]

S2 Util Mega Browse;Util Mega Browse;c:\program files (x86)\Mega Browse\bin\utilMegaBrowse.exe;c:\program files (x86)\Mega Browse\bin\utilMegaBrowse.exe [x]

S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x]

S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]

S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]

S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]

S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2014-03-05 03:39 1150280 ----a-w- c:\program files (x86)\Google\Chrome\Application\33.0.1750.146\Installer\chrmstp.exe

.

Contents of the 'Scheduled Tasks' folder

.

2014-03-11 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-26 00:52]

.

2014-03-08 c:\windows\Tasks\APSnotifierCA.job

- c:\program files (x86)\AnyProtectEx\AnyProtect.exe [2014-03-07 01:17]

.

2014-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-22 03:19]

.

2014-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-22 03:19]

.

2014-03-11 c:\windows\Tasks\media enhance-chromeinstaller.job

- c:\program files (x86)\media enhance\media enhance-chromeinstaller.exe [2014-03-07 01:30]

.

2014-03-11 c:\windows\Tasks\media enhance-codedownloader.job

- c:\program files (x86)\media enhance\media enhance-codedownloader.exe [2014-03-07 01:31]

.

2014-03-11 c:\windows\Tasks\media enhance-enabler.job

- c:\program files (x86)\media enhance\media enhance-enabler.exe [2014-03-07 01:31]

.

2014-03-11 c:\windows\Tasks\media enhance-firefoxinstaller.job

- c:\program files (x86)\media enhance\media enhance-firefoxinstaller.exe [2014-03-07 01:31]

.

2014-03-11 c:\windows\Tasks\media enhance-updater.job

- c:\program files (x86)\media enhance\media enhance-updater.exe [2014-03-07 01:31]

.

2014-03-11 c:\windows\Tasks\MySearchDial.job

- c:\users\Royal\AppData\Roaming\MySearchDial\UpdateProc\UpdateTask.exe [2013-04-12 14:10]

.

2014-03-11 c:\windows\Tasks\Re-markit Update.job

- c:\program files (x86)\Re-markit-soft\ReMar.exe [2014-03-07 01:28]

.

2014-03-11 c:\windows\Tasks\Re-markit_wd.job

- c:\program files (x86)\Re-markit-soft\Re-markit_wd.exe [2014-03-07 01:28]

.

2014-03-08 c:\windows\Tasks\RegClean Pro_DEFAULT.job

- c:\program files (x86)\RegClean Pro\RegCleanPro.exe [2014-03-08 23:28]

.

2014-03-08 c:\windows\Tasks\RegClean Pro_UPDATES.job

- c:\program files (x86)\RegClean Pro\RegCleanPro.exe [2014-03-08 23:28]

.

2014-03-11 c:\windows\Tasks\Video-for-PC-1.2-chromeinstaller.job

- c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-chromeinstaller.exe [2014-03-07 01:30]

.

2014-03-11 c:\windows\Tasks\Video-for-PC-1.2-codedownloader.job

- c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-codedownloader.exe [2014-03-07 01:30]

.

2014-03-11 c:\windows\Tasks\Video-for-PC-1.2-enabler.job

- c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-enabler.exe [2014-03-07 01:31]

.

2014-03-11 c:\windows\Tasks\Video-for-PC-1.2-firefoxinstaller.job

- c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-firefoxinstaller.exe [2014-03-07 01:30]

.

2014-03-11 c:\windows\Tasks\Video-for-PC-1.2-updater.job

- c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-updater.exe [2014-03-07 01:31]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyServer = http=127.0.0.1:13828

TCP: DhcpNameServer = 24.220.0.10 24.220.0.11 192.168.1.1

FF - ProfilePath - c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\

FF - prefs.js: browser.search.selectedEngine - Mysearchdial

FF - user.js: extensions.irmysearch.aflt - cmi_14_10_CH

FF - user.js: extensions.irmysearch.instlRef - 140305_a

FF - user.js: extensions.irmysearch.cr - 999030109

FF - user.js: extensions.irmysearch.cd - 2XzuyEtN2Y1L1QzuzzyEtAyEzyyByByC0AtC0CtA0FtA0ByEtN0D0Tzu0SyBzyyBtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0FyE0AtD0E0CtAtG0E0CyCyCtGtDyEtBzytGyE0EyByDtGyDzyzztDyCtBtDzy0A0C0CyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAtCtDtA0FzytDzytGtB0BzytCtGtCyCtBtCtGzz0AtC0DtGtBtAtDtByCyEyB0FtCyD0BtA2Q

FF - user.js: extensions.mysearchdial.hmpg - true

FF - user.js: extensions.mysearchdial.dfltSrch - true

FF - user.js: extensions.mysearchdial.srchPrvdr - Mysearchdial

FF - user.js: extensions.mysearchdial.dnsErr - true

FF - user.js: extensions.mysearchdial_i.newTab - false

FF - user.js: extensions.mysearchdial.id - 84349776A1C3F3B4

FF - user.js: extensions.mysearchdial.instlDay - 16136

FF - user.js: extensions.mysearchdial.vrsn - 1.8.29.0

FF - user.js: extensions.mysearchdial.vrsni - 1.8.29.0

FF - user.js: extensions.mysearchdial_i.vrsnTs - 1.8.29.019:15:4

FF - user.js: extensions.mysearchdial.prtnrId - mysearchdial

FF - user.js: extensions.mysearchdial.prdct - mysearchdial

FF - user.js: extensions.mysearchdial.aflt - cmi_14_10_CH

FF - user.js: extensions.mysearchdial_i.smplGrp - none

FF - user.js: extensions.mysearchdial.tlbrId - base

FF - user.js: extensions.mysearchdial.instlRef - 140305_a

FF - user.js: extensions.mysearchdial.dfltLng -

FF - user.js: extensions.mysearchdial.appId - {CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}

FF - user.js: extensions.mysearchdial.excTlbr - false

FF - user.js: extensions.mysearchdial.cr - 999030109

FF - user.js: extensions.mysearchdial.cd - 2XzuyEtN2Y1L1QzuzzyEtAyEzyyByByC0AtC0CtA0FtA0ByEtN0D0Tzu0SyBzyyBtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0FyE0AtD0E0CtAtG0E0CyCyCtGtDyEtBzytGyE0EyByDtGyDzyzztDyCtBtDzy0A0C0CyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAtCtDtA0FzytDzytGtB0BzytCtGtCyCtBtCtGzz0AtC0DtGtBtAtDtByCyEyB0FtCyD0BtA2Q

FF - user.js: extensions.mysearchdial.AL - 2

user_pref(extensions.autoDisableScopes,14);

.

- - - - ORPHANS REMOVED - - - -

.

BHO-{11111111-1111-1111-1111-110511151178} - c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-bho.dll

HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start

HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_70_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_70_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_70_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_70_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.12"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2014-03-10 20:25:57

ComboFix-quarantined-files.txt 2014-03-11 01:25

.

Pre-Run: 465,052,176,384 bytes free

Post-Run: 470,800,347,136 bytes free

.

- - End Of File - - A624AD6381397FA5039ECA45A3EBE7D3

A36C5E4F47E84449FF07ED3517B43A31

Link to post
Share on other sites

uh oh - much work to do! :wacko:

 

 

Combofix scripting

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Download the attached CFScript.txt and save it to the location where Combofix is.


CFScriptB-4.gif


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

 

 

No Antivirus Program installed!

I don't see an Anti Virus Program running on your machine.

Download and install an antivirus program, and make sure that you keep it updated New viruses come out every minute, so it is essential that you have the latest signatures for your antivirus program to provide you with the best possible protection from malicious software.

Two good antivirus programs free for non-commercial home use are
Avast!
or
Microsoft Security Essentials

Note: You should only have one antivirus installed at a time. Having more than one antivirus program installed at once is likely to cause conflicts and may well decrease your overall protection as well as impairing the performance of your PC.

CFScript.txt

Link to post
Share on other sites

I already have MSE installed. It might of been disabled/blocked from one of the malware programs which stopped you from seeing it?

combofix.txt

ComboFix 14-03-10.01 - Royal 03/11/2014 18:18:29.2.2 - x64

State of Independence Windows 7 xDark™ v4.3 RG Deluxe 6.1.7601.1.1252.1.1033.18.3561.2386 [GMT -5:00]

Running from: c:\users\Royal\Desktop\ComboFix.exe

Command switches used :: c:\users\Royal\Desktop\CFScript.txt

AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}

SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

FILE ::

"c:\users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk"

"c:\windows\Tasks\media enhance-chromeinstaller.job"

"c:\windows\Tasks\media enhance-codedownloader.job"

"c:\windows\Tasks\media enhance-enabler.job"

"c:\windows\Tasks\media enhance-updater.job"

"c:\windows\Tasks\MySearchDial.job"

"c:\windows\Tasks\Re-markit Update.job"

"c:\windows\Tasks\Re-markit_wd.job"

"c:\windows\Tasks\RegClean Pro_DEFAULT.job"

"c:\windows\Tasks\RegClean Pro_UPDATES.job"

"c:\windows\Tasks\Video-for-PC-1.2-chromeinstaller.job"

"c:\windows\Tasks\Video-for-PC-1.2-codedownloader.job"

"c:\windows\Tasks\Video-for-PC-1.2-enabler.job"

"c:\windows\Tasks\Video-for-PC-1.2-firefoxinstaller.job"

"c:\windows\Tasks\Video-for-PC-1.2-updater.job"

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\program files (x86)\Advanced System Protector

c:\program files (x86)\Advanced System Protector\AdvancedSystemProtector.exe

c:\program files (x86)\Advanced System Protector\AdvancedSystemProtector.exe.config

c:\program files (x86)\Advanced System Protector\AppResource.dll

c:\program files (x86)\Advanced System Protector\asp.ico

c:\program files (x86)\Advanced System Protector\AspManager.exe

c:\program files (x86)\Advanced System Protector\aspsys.dll

c:\program files (x86)\Advanced System Protector\ASPUninstall.exe

c:\program files (x86)\Advanced System Protector\categories.ini

c:\program files (x86)\Advanced System Protector\Chinese_asp_ZH-CN.ini

c:\program files (x86)\Advanced System Protector\Chinese_uninst.ini

c:\program files (x86)\Advanced System Protector\clamunpack\clamscan.exe

c:\program files (x86)\Advanced System Protector\clamunpack\libclamav.dll

c:\program files (x86)\Advanced System Protector\clamunpack\readme.txt

c:\program files (x86)\Advanced System Protector\Communication.dll

c:\program files (x86)\Advanced System Protector\danish_asp_DA.ini

c:\program files (x86)\Advanced System Protector\Danish_uninst.ini

c:\program files (x86)\Advanced System Protector\dutch_asp_NL.ini

c:\program files (x86)\Advanced System Protector\Dutch_uninst.ini

c:\program files (x86)\Advanced System Protector\eng_asp_en.ini

c:\program files (x86)\Advanced System Protector\eng_uninst.ini

c:\program files (x86)\Advanced System Protector\filetypehelper.exe

c:\program files (x86)\Advanced System Protector\Finnish_asp_FI.ini

c:\program files (x86)\Advanced System Protector\Finnish_uninst_fi.ini

c:\program files (x86)\Advanced System Protector\french_asp_FR.ini

c:\program files (x86)\Advanced System Protector\French_uninst.ini

c:\program files (x86)\Advanced System Protector\german_asp_DE.ini

c:\program files (x86)\Advanced System Protector\German_uninst.ini

c:\program files (x86)\Advanced System Protector\greek_uninst_el.ini

c:\program files (x86)\Advanced System Protector\Interop.IWshRuntimeLibrary.dll

c:\program files (x86)\Advanced System Protector\italian_asp_IT.ini

c:\program files (x86)\Advanced System Protector\Italian_uninst.ini

c:\program files (x86)\Advanced System Protector\japanese_asp_JA.ini

c:\program files (x86)\Advanced System Protector\Japanese_uninst.ini

c:\program files (x86)\Advanced System Protector\korean_uninst_ko.ini

c:\program files (x86)\Advanced System Protector\loading_withWhiteBG.avi

c:\program files (x86)\Advanced System Protector\Microsoft.Win32.TaskScheduler.DLL

c:\program files (x86)\Advanced System Protector\norwegian_asp_NO.ini

c:\program files (x86)\Advanced System Protector\Norwegian_uninst.ini

c:\program files (x86)\Advanced System Protector\polish_uninst_pl.ini

c:\program files (x86)\Advanced System Protector\portugese_uninst_pt.ini

c:\program files (x86)\Advanced System Protector\portuguese_asp_PT-BR.ini

c:\program files (x86)\Advanced System Protector\Portuguese_uninst.ini

c:\program files (x86)\Advanced System Protector\russian_asp_ru.ini

c:\program files (x86)\Advanced System Protector\russian_uninst_ru.ini

c:\program files (x86)\Advanced System Protector\scandll.dll

c:\program files (x86)\Advanced System Protector\spanish_asp_ES.ini

c:\program files (x86)\Advanced System Protector\spanish_uninst.ini

c:\program files (x86)\Advanced System Protector\SSDPTstub.exe

c:\program files (x86)\Advanced System Protector\swedish_asp_SV.ini

c:\program files (x86)\Advanced System Protector\swedish_uninst.ini

c:\program files (x86)\Advanced System Protector\System.Core.dll

c:\program files (x86)\Advanced System Protector\System.Data.SQLite.dll

c:\program files (x86)\Advanced System Protector\TPS.ico

c:\program files (x86)\Advanced System Protector\traditionalcn_uninst_zh-tw.ini

c:\program files (x86)\Advanced System Protector\Troubleshooter\asp-fixer.com

c:\program files (x86)\Advanced System Protector\Troubleshooter\asp-fixer.exe

c:\program files (x86)\Advanced System Protector\Troubleshooter\asp-fixer.pif

c:\program files (x86)\Advanced System Protector\Troubleshooter\asp-fixer.scr

c:\program files (x86)\Advanced System Protector\Troubleshooter\ASP-Troubleshooter.chm

c:\program files (x86)\Advanced System Protector\Troubleshooter\firefox.com

c:\program files (x86)\Advanced System Protector\Troubleshooter\iexplore.exe

c:\program files (x86)\Advanced System Protector\Troubleshooter\iexplore.lnk

c:\program files (x86)\Advanced System Protector\Turkish_uninst_tr.ini

c:\program files (x86)\Advanced System Protector\unins000.dat

c:\program files (x86)\Advanced System Protector\unins000.exe

c:\program files (x86)\Advanced System Protector\unins000.msg

c:\program files (x86)\Advanced System Protector\unrar.dll

c:\program files (x86)\Advanced System Protector\Xceed.Compression.dll

c:\program files (x86)\Advanced System Protector\Xceed.Compression.Formats.dll

c:\program files (x86)\Advanced System Protector\Xceed.FileSystem.dll

c:\program files (x86)\Advanced System Protector\Xceed.Zip.dll

c:\program files (x86)\AnyProtectEx

c:\program files (x86)\AnyProtectEx\AnyProtect.exe

c:\program files (x86)\AnyProtectEx\AnyProtectTrayIcon.exe

c:\program files (x86)\AnyProtectEx\log.ap

c:\program files (x86)\AnyProtectEx\product.guid

c:\program files (x86)\AnyProtectEx\Uninstall.exe

c:\program files (x86)\LPT

c:\program files (x86)\LPT\Configs\BrowserSettings.xml

c:\program files (x86)\LPT\Configs\LPTMapping.xml

c:\program files (x86)\LPT\Configs\Timers.xml

c:\program files (x86)\LPT\FiddlerCore.dll

c:\program files (x86)\LPT\HtmlAgilityPack.dll

c:\program files (x86)\LPT\linmsl.exe

c:\program files (x86)\LPT\LPTInstaller.msi

c:\program files (x86)\LPT\lrrot.dll

c:\program files (x86)\LPT\Newtonsoft.Json.dll

c:\program files (x86)\LPT\Proxy.pac

c:\program files (x86)\LPT\PublisherSettings.xml

c:\program files (x86)\LPT\Resources\LPT.xml

c:\program files (x86)\LPT\Smartbar.Common.dll

c:\program files (x86)\LPT\Smartbar.Communication.dll

c:\program files (x86)\LPT\Smartbar.Communication.NamedPipe.dll

c:\program files (x86)\LPT\Smartbar.Infrastructure.Utilities.dll

c:\program files (x86)\LPT\Smartbar.Monetization.Proxy.ProxyRemover.exe

c:\program files (x86)\LPT\Smartbar.Monetization.Proxy.ProxyService.dll

c:\program files (x86)\LPT\Smartbar.Personalization.Common.dll

c:\program files (x86)\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll

c:\program files (x86)\LPT\sppsm.dll

c:\program files (x86)\LPT\spusm.dll

c:\program files (x86)\LPT\srbs.dll

c:\program files (x86)\LPT\srbu.dll

c:\program files (x86)\LPT\sreu.dll

c:\program files (x86)\LPT\srpdm.dll

c:\program files (x86)\LPT\srprl.dll

c:\program files (x86)\LPT\srpt.dll

c:\program files (x86)\LPT\srptc.dll

c:\program files (x86)\LPT\srptm.exe

c:\program files (x86)\LPT\srptm.exe.config

c:\program files (x86)\LPT\srpts.exe

c:\program files (x86)\LPT\srut.dll

c:\program files (x86)\LPT\System.Data.SQLite.dll

c:\program files (x86)\LPT\UserSettings.xml

c:\program files (x86)\LPT\XMLOperations.xml

c:\program files (x86)\media enhance

c:\program files (x86)\media enhance\44150.crx

c:\program files (x86)\media enhance\44150.xpi

c:\program files (x86)\media enhance\background.html

c:\program files (x86)\media enhance\Installer.log

c:\program files (x86)\media enhance\media enhance-bg.exe

c:\program files (x86)\media enhance\media enhance-bho.dll

c:\program files (x86)\media enhance\media enhance-bho64.dll

c:\program files (x86)\media enhance\media enhance-chromeinstaller.exe

c:\program files (x86)\media enhance\media enhance-codedownloader.exe

c:\program files (x86)\media enhance\media enhance-enabler.exe

c:\program files (x86)\media enhance\media enhance-firefoxinstaller.exe

c:\program files (x86)\media enhance\media enhance-updater.exe

c:\program files (x86)\media enhance\media enhance.ico

c:\program files (x86)\media enhance\Uninstall.exe

c:\program files (x86)\media enhance\utils.exe

c:\program files (x86)\Mega Browse

c:\program files (x86)\Mega Browse\0

c:\program files (x86)\Mega Browse\7za.exe

c:\program files (x86)\Mega Browse\bin\MegaBrowse.BrowserFilter.Helper.dll

c:\program files (x86)\Mega Browse\bin\MegaBrowse.BrowserFilter.Helper.dll.old.ce8333be-290a-4e24-b60e-b566df67ea9b

c:\program files (x86)\Mega Browse\bin\MegaBrowseBrowserFilter.exe

c:\program files (x86)\Mega Browse\bin\plugins\MegaBrowse.BrowserFilterG.dll

c:\program files (x86)\Mega Browse\bin\plugins\MegaBrowse.FFUpdate.dll

c:\program files (x86)\Mega Browse\bin\sqlite3.dll

c:\program files (x86)\Mega Browse\bin\utilMegaBrowse.exe

c:\program files (x86)\Mega Browse\bin\utilMegaBrowse.InstallState

c:\program files (x86)\Mega Browse\MegaBrowse.ico

c:\program files (x86)\Mega Browse\MegaBrowseBHO.dll

c:\program files (x86)\Mega Browse\MegaBrowseUninstall.exe

c:\program files (x86)\Mega Browse\updateMegaBrowse.exe

c:\program files (x86)\Mega Browse\updateMegaBrowse.InstallState

c:\program files (x86)\MyPC Backup

c:\program files (x86)\MyPC Backup\aff.conf

c:\program files (x86)\MyPC Backup\AlphaVSS.51.x86.dll

c:\program files (x86)\MyPC Backup\AlphaVSS.52.x64.dll

c:\program files (x86)\MyPC Backup\AlphaVSS.52.x86.dll

c:\program files (x86)\MyPC Backup\AlphaVSS.60.x64.dll

c:\program files (x86)\MyPC Backup\AlphaVSS.60.x86.dll

c:\program files (x86)\MyPC Backup\AlphaVSS.Common.dll

c:\program files (x86)\MyPC Backup\AWSSDK.dll

c:\program files (x86)\MyPC Backup\BackupStack.exe

c:\program files (x86)\MyPC Backup\Config\api.ts2

c:\program files (x86)\MyPC Backup\Configuration Updater.exe

c:\program files (x86)\MyPC Backup\Crypto32.dll

c:\program files (x86)\MyPC Backup\Crypto64.dll

c:\program files (x86)\MyPC Backup\Database\mpcb_backup_conf.db

c:\program files (x86)\MyPC Backup\Database\mpcb_backup_id.db

c:\program files (x86)\MyPC Backup\Database\mpcb_file_cache.db

c:\program files (x86)\MyPC Backup\Database\mpcb_queues.db

c:\program files (x86)\MyPC Backup\Database\mpcb_settings.db

c:\program files (x86)\MyPC Backup\Database\mpcb_sig_cache.db

c:\program files (x86)\MyPC Backup\Database\mpcb_version_queue.db

c:\program files (x86)\MyPC Backup\de_DE.mo

c:\program files (x86)\MyPC Backup\diffstack.dll

c:\program files (x86)\MyPC Backup\es_ES.mo

c:\program files (x86)\MyPC Backup\fr_FR.mo

c:\program files (x86)\MyPC Backup\GetText.dll

c:\program files (x86)\MyPC Backup\it_IT.mo

c:\program files (x86)\MyPC Backup\log\AUTH.log

c:\program files (x86)\MyPC Backup\log\BACKOFF.log

c:\program files (x86)\MyPC Backup\log\BACKUP.log

c:\program files (x86)\MyPC Backup\log\BACKUP_COMPLETE.log

c:\program files (x86)\MyPC Backup\log\CLIENT.log

c:\program files (x86)\MyPC Backup\log\GRID_RECOVERY.log

c:\program files (x86)\MyPC Backup\log\GRID_RECOVERY_INIT.log

c:\program files (x86)\MyPC Backup\log\NETWORK_SHARES.log

c:\program files (x86)\MyPC Backup\log\REMOTING.log

c:\program files (x86)\MyPC Backup\log\REQUEST.log

c:\program files (x86)\MyPC Backup\log\SERVICE.log

c:\program files (x86)\MyPC Backup\log\SHELL.log

c:\program files (x86)\MyPC Backup\log\UPDATER.log

c:\program files (x86)\MyPC Backup\log\UTC_MIGRATION.log

c:\program files (x86)\MyPC Backup\log\WAIT_HANDLES.log

c:\program files (x86)\MyPC Backup\LogicNP.EZShellExtensions.dll

c:\program files (x86)\MyPC Backup\MPCBClient.dll

c:\program files (x86)\MyPC Backup\MPCBContextMenu.dll

c:\program files (x86)\MyPC Backup\MPCBIconOverlays.dll

c:\program files (x86)\MyPC Backup\MyPC Backup.exe

c:\program files (x86)\MyPC Backup\mypcbackup.ico

c:\program files (x86)\MyPC Backup\ObjectListView.dll

c:\program files (x86)\MyPC Backup\pt_PT.mo

c:\program files (x86)\MyPC Backup\RegisterExtensionDotNet20_x64.exe

c:\program files (x86)\MyPC Backup\RegisterExtensionDotNet20_x86.exe

c:\program files (x86)\MyPC Backup\Resources\keycache\_29837e3e-2e20-46da-8b4b-725c395a54f8_backupKeyCache.block

c:\program files (x86)\MyPC Backup\Resources\keycache\_29837e3e-2e20-46da-8b4b-725c395a54f8_backupKeyCache.tree

c:\program files (x86)\MyPC Backup\Resources\keycache\_614297ea-8363-4aa2-8346-571d004b287c_backupKeyCache.block

c:\program files (x86)\MyPC Backup\Resources\keycache\_614297ea-8363-4aa2-8346-571d004b287c_backupKeyCache.tree

c:\program files (x86)\MyPC Backup\Resources\keycache\_6592385e-f129-4ba3-8dca-cda251f2abfb_backupKeyCache.block

c:\program files (x86)\MyPC Backup\Resources\keycache\_6592385e-f129-4ba3-8dca-cda251f2abfb_backupKeyCache.tree

c:\program files (x86)\MyPC Backup\RestartExplorer.exe

c:\program files (x86)\MyPC Backup\Service Start.exe

c:\program files (x86)\MyPC Backup\Shared Stack.dll

c:\program files (x86)\MyPC Backup\Signup Wizard.exe

c:\program files (x86)\MyPC Backup\syncicon.ico

c:\program files (x86)\MyPC Backup\syncing.ico

c:\program files (x86)\MyPC Backup\tick.ico

c:\program files (x86)\MyPC Backup\uninst.exe

c:\program files (x86)\MyPC Backup\UnRegisterExtensions.exe

c:\program files (x86)\MyPC Backup\Updater.exe

c:\program files (x86)\MyPC Backup\x64\System.Data.SQLite.dll

c:\program files (x86)\MyPC Backup\x86\System.Data.SQLite.dll

c:\program files (x86)\Mysearchdial

c:\program files (x86)\Mysearchdial\1.8.29.0\bh\mysearchdial.dll

c:\program files (x86)\Mysearchdial\1.8.29.0\FavIcon.ico

c:\program files (x86)\Mysearchdial\1.8.29.0\mysearchdialApp.dll

c:\program files (x86)\Mysearchdial\1.8.29.0\mysearchdialEng.dll

c:\program files (x86)\Mysearchdial\1.8.29.0\mysearchdialsrv.exe

c:\program files (x86)\Mysearchdial\1.8.29.0\mysearchdialTlbr.dll

c:\program files (x86)\Mysearchdial\1.8.29.0\Sqlite3.dll

c:\program files (x86)\Mysearchdial\1.8.29.0\uninst.dat

c:\program files (x86)\Mysearchdial\1.8.29.0\uninstall.exe

c:\program files (x86)\Optimizer Pro

c:\program files (x86)\Optimizer Pro\bg_new1.bmp

c:\program files (x86)\Optimizer Pro\CookiesException.txt

c:\program files (x86)\Optimizer Pro\English.ini

c:\program files (x86)\Optimizer Pro\file_id.diz

c:\program files (x86)\Optimizer Pro\HomePage.url

c:\program files (x86)\Optimizer Pro\itdownload.dll

c:\program files (x86)\Optimizer Pro\OptimizerPro.chm

c:\program files (x86)\Optimizer Pro\OptimizerPro.exe

c:\program files (x86)\Optimizer Pro\OptProCrash.dll

c:\program files (x86)\Optimizer Pro\OptProCrash_x64.dll

c:\program files (x86)\Optimizer Pro\optprocrashSvc.dll

c:\program files (x86)\Optimizer Pro\OptProGuard.exe

c:\program files (x86)\Optimizer Pro\OptProLauncher.exe

c:\program files (x86)\Optimizer Pro\OptProReminder.exe

c:\program files (x86)\Optimizer Pro\OptProSchedule.exe

c:\program files (x86)\Optimizer Pro\OptProSmartScan.exe

c:\program files (x86)\Optimizer Pro\OptProStart.exe

c:\program files (x86)\Optimizer Pro\OptProUninstaller.exe

c:\program files (x86)\Optimizer Pro\scan.gif

c:\program files (x86)\Optimizer Pro\sqlite3.dll

c:\program files (x86)\Optimizer Pro\StartupList.txt

c:\program files (x86)\Optimizer Pro\unins000.dat

c:\program files (x86)\Optimizer Pro\unins000.exe

c:\program files (x86)\Optimizer Pro\unins000.msg

c:\program files (x86)\Re-markit-soft

c:\program files (x86)\Re-markit-soft\157.crx

c:\program files (x86)\Re-markit-soft\157.dat

c:\program files (x86)\Re-markit-soft\157.xpi

c:\program files (x86)\Re-markit-soft\a.db

c:\program files (x86)\Re-markit-soft\b.db

c:\program files (x86)\Re-markit-soft\Re-markit_wd.exe

c:\program files (x86)\Re-markit-soft\Re-markit157.bin

c:\program files (x86)\Re-markit-soft\Re-markit157.exe

c:\program files (x86)\Re-markit-soft\Re-markit157.ini

c:\program files (x86)\Re-markit-soft\ReMar.exe

c:\program files (x86)\Re-markit-soft\Sqlite3.dll

c:\program files (x86)\Re-markit-soft\Uninstall.exe

c:\program files (x86)\RegClean Pro

c:\program files (x86)\RegClean Pro\Chinese_rcp.ini

c:\program files (x86)\RegClean Pro\Chinese_uninst.ini

c:\program files (x86)\RegClean Pro\CleanSchedule.exe

c:\program files (x86)\RegClean Pro\Danish_rcp.ini

c:\program files (x86)\RegClean Pro\Danish_uninst.ini

c:\program files (x86)\RegClean Pro\Dutch_rcp.ini

c:\program files (x86)\RegClean Pro\Dutch_uninst.ini

c:\program files (x86)\RegClean Pro\eng_rcp.ini

c:\program files (x86)\RegClean Pro\eng_uninst.ini

c:\program files (x86)\RegClean Pro\Finnish_rcp_fi.ini

c:\program files (x86)\RegClean Pro\Finnish_uninst_fi.ini

c:\program files (x86)\RegClean Pro\French_rcp.ini

c:\program files (x86)\RegClean Pro\French_uninst.ini

c:\program files (x86)\RegClean Pro\German_rcp.ini

c:\program files (x86)\RegClean Pro\German_uninst.ini

c:\program files (x86)\RegClean Pro\greek_rcp_el.ini

c:\program files (x86)\RegClean Pro\greek_uninst_el.ini

c:\program files (x86)\RegClean Pro\install_left_image.bmp

c:\program files (x86)\RegClean Pro\isxdl.dll

c:\program files (x86)\RegClean Pro\Italian_rcp.ini

c:\program files (x86)\RegClean Pro\Italian_uninst.ini

c:\program files (x86)\RegClean Pro\Japanese_rcp.ini

c:\program files (x86)\RegClean Pro\Japanese_uninst.ini

c:\program files (x86)\RegClean Pro\korean_rcp_ko.ini

c:\program files (x86)\RegClean Pro\korean_uninst_ko.ini

c:\program files (x86)\RegClean Pro\Norwegian_rcp.ini

c:\program files (x86)\RegClean Pro\Norwegian_uninst.ini

c:\program files (x86)\RegClean Pro\polish_rcp_pl.ini

c:\program files (x86)\RegClean Pro\polish_uninst_pl.ini

c:\program files (x86)\RegClean Pro\portugese_rcp_pt.ini

c:\program files (x86)\RegClean Pro\portugese_uninst_pt.ini

c:\program files (x86)\RegClean Pro\Portuguese_rcp.ini

c:\program files (x86)\RegClean Pro\Portuguese_uninst.ini

c:\program files (x86)\RegClean Pro\RCPUninstall.exe

c:\program files (x86)\RegClean Pro\RegCleanPro.dll

c:\program files (x86)\RegClean Pro\RegCleanPro.exe

c:\program files (x86)\RegClean Pro\russian_rcp_ru.ini

c:\program files (x86)\RegClean Pro\russian_uninst_ru.ini

c:\program files (x86)\RegClean Pro\Spanish_rcp.ini

c:\program files (x86)\RegClean Pro\spanish_uninst.ini

c:\program files (x86)\RegClean Pro\SSDPTstub.exe

c:\program files (x86)\RegClean Pro\Swedish_rcp.ini

c:\program files (x86)\RegClean Pro\swedish_uninst.ini

c:\program files (x86)\RegClean Pro\systweakasp.exe

c:\program files (x86)\RegClean Pro\TPS.ico

c:\program files (x86)\RegClean Pro\TraditionalCn_rcp_zh-tw.ini

c:\program files (x86)\RegClean Pro\traditionalcn_uninst_zh-tw.ini

c:\program files (x86)\RegClean Pro\turkish_rcp_tr.ini

c:\program files (x86)\RegClean Pro\Turkish_uninst_tr.ini

c:\program files (x86)\RegClean Pro\unins000.dat

c:\program files (x86)\RegClean Pro\unins000.exe

c:\program files (x86)\RegClean Pro\unins000.msg

c:\program files (x86)\RegClean Pro\xmllite.dll

c:\program files (x86)\Video-for-PC-1.2

c:\program files (x86)\Video-for-PC-1.2\51578.crx

c:\program files (x86)\Video-for-PC-1.2\51578.xpi

c:\program files (x86)\Video-for-PC-1.2\background.html

c:\program files (x86)\Video-for-PC-1.2\Installer.log

c:\program files (x86)\Video-for-PC-1.2\Uninstall.exe

c:\program files (x86)\Video-for-PC-1.2\utils.exe

c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-bg.exe

c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-bho64.dll

c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-chromeinstaller.exe

c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-codedownloader.exe

c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-enabler.exe

c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-firefoxinstaller.exe

c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-updater.exe

c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2.ico

c:\programdata\Systweak

c:\programdata\Systweak\Advanced System Protector\AddonSafelist

c:\programdata\Systweak\Advanced System Protector\log.xslt

c:\users\Royal\AppData\Local\LPT

c:\users\Royal\AppData\Local\LPT\Configs\BrowserSettings.xml

c:\users\Royal\AppData\Local\LPT\Configs\LPTMapping.xml

c:\users\Royal\AppData\Local\LPT\Configs\Timers.xml

c:\users\Royal\AppData\Local\LPT\FiddlerCore.dll

c:\users\Royal\AppData\Local\LPT\HtmlAgilityPack.dll

c:\users\Royal\AppData\Local\LPT\linmsl.exe

c:\users\Royal\AppData\Local\LPT\LPTInstaller.msi

c:\users\Royal\AppData\Local\LPT\Newtonsoft.Json.dll

c:\users\Royal\AppData\Local\LPT\Proxy.pac

c:\users\Royal\AppData\Local\LPT\PublisherSettings.xml

c:\users\Royal\AppData\Local\LPT\Resources\LPT.xml

c:\users\Royal\AppData\Local\LPT\Smartbar.Common.dll

c:\users\Royal\AppData\Local\LPT\Smartbar.Communication.dll

c:\users\Royal\AppData\Local\LPT\Smartbar.Communication.NamedPipe.dll

c:\users\Royal\AppData\Local\LPT\Smartbar.Infrastructure.Utilities.dll

c:\users\Royal\AppData\Local\LPT\Smartbar.Monetization.Proxy.ProxyRemover.exe

c:\users\Royal\AppData\Local\LPT\Smartbar.Monetization.Proxy.ProxyService.dll

c:\users\Royal\AppData\Local\LPT\Smartbar.Personalization.Common.dll

c:\users\Royal\AppData\Local\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll

c:\users\Royal\AppData\Local\LPT\sppsm.dll

c:\users\Royal\AppData\Local\LPT\spusm.dll

c:\users\Royal\AppData\Local\LPT\srbs.dll

c:\users\Royal\AppData\Local\LPT\srbu.dll

c:\users\Royal\AppData\Local\LPT\sreu.dll

c:\users\Royal\AppData\Local\LPT\srpdm.dll

c:\users\Royal\AppData\Local\LPT\srprl.dll

c:\users\Royal\AppData\Local\LPT\srpt.dll

c:\users\Royal\AppData\Local\LPT\srptc.dll

c:\users\Royal\AppData\Local\LPT\srptm.exe

c:\users\Royal\AppData\Local\LPT\srptm.exe.config

c:\users\Royal\AppData\Local\LPT\srut.dll

c:\users\Royal\AppData\Local\LPT\UserSettings.xml

c:\users\Royal\AppData\Local\SevereWeatherAlerts

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.0.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.1.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.10.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.11.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.12.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.13.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.14.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.15.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.16.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.17.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.18.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.19.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.2.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.20.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.21.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.22.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.23.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.24.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.25.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.26.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.27.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.28.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.29.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.3.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.30.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.31.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.32.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.33.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.34.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.35.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.36.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.37.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.38.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.39.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.4.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.40.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.41.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.42.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.43.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.44.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.45.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.46.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.47.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.48.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.49.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.5.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.50.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.51.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.52.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.53.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.54.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.55.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.56.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.57.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.58.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.59.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.6.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.60.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.61.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.62.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.63.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.64.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.65.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.66.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.67.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.68.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.69.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.7.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.70.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.71.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.72.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.73.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.8.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0308135843\3689.9.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.0.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.1.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.10.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.11.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.12.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.13.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.14.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.15.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.16.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.2.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.3.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.4.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.5.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.6.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.7.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.8.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\0310194913\3691.9.tmp

c:\users\Royal\AppData\Local\SevereWeatherAlerts\ICSharpCode.SharpZipLib.dll

c:\users\Royal\AppData\Local\SevereWeatherAlerts\mod.SevereWeatherAlertsApp0.dat

c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlerts.exe

c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlerts.exe.config

c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsApp.exe

c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsApp0.dat

c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsAppAPI.dll

c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsBrowser.exe

c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsK.dat.U.dat

c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsU.dat

c:\users\Royal\AppData\Local\SevereWeatherAlerts\SWAUpdater.exe

c:\users\Royal\AppData\Local\SevereWeatherAlerts\uninstall.exe

c:\users\Royal\AppData\Local\Smartbar

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\bg.html

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\bg.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\CSS\border.css

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\down-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\down-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\down-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\down.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\fb.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\fblike.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\gmail.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\google.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\googleplus.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\hide-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\hide-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\hide-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\left.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\maximize-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\maximize-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\maximize-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\mgsplusvideo.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\minimize-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\minimize-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\minimize-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\pinit.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\right.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\searchBox.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\show-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\show-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\show-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\twitter.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\up-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\up-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\up-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\up.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\alxbl.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\BackPageRemove.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\defaultBlockList.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\documentEvents.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\externalJS.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\FBImagePreview.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\filters.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\generalBackButtonDetection.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\InternalJS.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\jquery-1.9.0.min.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\PluginWrapper.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\publisherDefinitions.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\ta.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\tabReload.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\TopFrameJS.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\trans.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\manifest.json

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\options.htm

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\options.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\popup.html

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\popup.js

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\PublisherImages\Muvic.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\PublisherImages\Muvic128.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\PublisherImages\Muvic16.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\PublisherImages\Muvic48.png

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\redirect.html

c:\users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\redirect.js

c:\users\Royal\AppData\Local\Smartbar\Application\ar\Smartbar.Resources.LanguageSettings.resources.dll

c:\users\Royal\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll

c:\users\Royal\AppData\Local\Smartbar\Application\BrowserHelper.exe

c:\users\Royal\AppData\Local\Smartbar\Application\BrowserHelper.exe.config

c:\users\Royal\AppData\Local\Smartbar\Application\ChromeHost.exe

c:\users\Royal\AppData\Local\Smartbar\Application\Configs\QueryParameters.xml

c:\users\Royal\AppData\Local\Smartbar\Application\Configs\XmlSideBySideProtocol.xml

c:\users\Royal\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll

c:\users\Royal\AppData\Local\Smartbar\Application\DomainBlackList.xml

c:\users\Royal\AppData\Local\Smartbar\Application\es\Smartbar.Resources.LanguageSettings.resources.dll

c:\users\Royal\AppData\Local\Smartbar\Application\FiddlerCore.dll

c:\users\Royal\AppData\Local\Smartbar\Application\fr\Smartbar.Resources.LanguageSettings.resources.dll

c:\users\Royal\AppData\Local\Smartbar\Application\he\Smartbar.Resources.LanguageSettings.resources.dll

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome.manifest

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\BackPageRemove.js

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\externalJS.js

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\FBImagePreview.js

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\FirefoxExtensionMain.css

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\FirefoxExtensionMain.js

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\FirefoxExtensionMain.xul

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\down-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\down-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\down-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\down.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\fb.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\fblike.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\gmail.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\googleplus.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\hide-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\hide-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\hide-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\left.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\maximize-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\maximize-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\maximize-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\mgsplusvideo.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\minimize-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\minimize-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\minimize-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\pinit.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\right.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\searchBox.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\show-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\show-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\show-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\twitter.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\up-1.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\up-2.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\up-3.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\up.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\InternalJS.js

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\jquery-1.5.1.min.js

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\publisherDefinitions.js

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages\Muvic.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages\Muvic_small.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages\Muvic128.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages\Muvic16.png

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\ISmartbarFireFoxRemotePlugin.xpt

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_22.dll

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_23.dll

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_24.dll

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_25.dll

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_26.dll

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_27.dll

c:\users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\install.rdf

c:\users\Royal\AppData\Local\Smartbar\Application\HtmlAgilityPack.dll

c:\users\Royal\AppData\Local\Smartbar\Application\IEButton.png

c:\users\Royal\AppData\Local\Smartbar\Application\Interop.SHDocVw.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Interop.WMPLib.dll

c:\users\Royal\AppData\Local\Smartbar\Application\it\Smartbar.Resources.LanguageSettings.resources.dll

c:\users\Royal\AppData\Local\Smartbar\Application\lrcnt.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Lrcnta.exe

c:\users\Royal\AppData\Local\Smartbar\Application\MACTrackBarLib.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Microsoft.mshtml.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.Common.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.Logging.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Microsoft.Practices.ObjectBuilder.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Muvic.exe

c:\users\Royal\AppData\Local\Smartbar\Application\Muvic.exe.config

c:\users\Royal\AppData\Local\Smartbar\Application\NDde.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Newtonsoft.Json.dll

c:\users\Royal\AppData\Local\Smartbar\Application\nl\Smartbar.Resources.LanguageSettings.resources.dll

c:\users\Royal\AppData\Local\Smartbar\Application\ProductsRemovalTool.exe

c:\users\Royal\AppData\Local\Smartbar\Application\Proxy.pac

c:\users\Royal\AppData\Local\Smartbar\Application\pt\Smartbar.Resources.LanguageSettings.resources.dll

c:\users\Royal\AppData\Local\Smartbar\Application\RegAsm.exe

c:\users\Royal\AppData\Local\Smartbar\Application\ru\Smartbar.Resources.LanguageSettings.resources.dll

c:\users\Royal\AppData\Local\Smartbar\Application\sb.host.json

c:\users\Royal\AppData\Local\Smartbar\Application\sgml.dll

c:\users\Royal\AppData\Local\Smartbar\Application\sgmu.dll

c:\users\Royal\AppData\Local\Smartbar\Application\sidb.dll

c:\users\Royal\AppData\Local\Smartbar\Application\siem.dll

c:\users\Royal\AppData\Local\Smartbar\Application\sipb.dll

c:\users\Royal\AppData\Local\Smartbar\Application\sismlp.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Common.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Communication.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Communication.NamedPipe.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Monetization.Proxy.ProxyRemover.exe

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Monetization.Proxy.ProxyService.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.XmlSerializers.dll

c:\users\Royal\AppData\Local\Smartbar\Application\Smartbar.Resources.Translations.dll

c:\users\Royal\AppData\Local\Smartbar\Application\SmartbarInstallationIcon.ico

c:\users\Royal\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll

c:\users\Royal\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll

c:\users\Royal\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll

c:\users\Royal\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll

c:\users\Royal\AppData\Local\Smartbar\Application\SmartbarShortcutIcon.ico

c:\users\Royal\AppData\Local\Smartbar\Application\SmartbarVersionsHelper.exe

c:\users\Royal\AppData\Local\Smartbar\Application\SmartbarVersionsHelper.exe.config

c:\users\Royal\AppData\Local\Smartbar\Application\smta.dll

c:\users\Royal\AppData\Local\Smartbar\Application\smtu.dll

c:\users\Royal\AppData\Local\Smartbar\Application\spbe.dll

c:\users\Royal\AppData\Local\Smartbar\Application\spbl.dll

c:\users\Royal\AppData\Local\Smartbar\Application\sppsm.dll

c:\users\Royal\AppData\Local\Smartbar\Application\spsm.dll

c:\users\Royal\AppData\Local\Smartbar\Application\spusm.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srau.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srbhu.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srbs.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srbu.dll

c:\users\Royal\AppData\Local\Smartbar\Application\sreu.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srgu.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srns.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srom.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srpdm.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srprl.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srpu.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srsbs.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srsbsau.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srsl.dll

c:\users\Royal\AppData\Local\Smartbar\Application\sruhs.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srus.dll

c:\users\Royal\AppData\Local\Smartbar\Application\srut.dll

c:\users\Royal\AppData\Local\Smartbar\Application\System.Data.SQLite.dll

c:\users\Royal\AppData\Local\Smartbar\Application\tr\Smartbar.Resources.LanguageSettings.resources.dll

c:\users\Royal\AppData\Local\Smartbar\Common\Configs\UserInfo.xml

c:\users\Royal\AppData\Local\Smartbar\Common\icons\00659FA4-2CAD-45fc-A8A0-DB7862840BA9.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\00659FA4-2CAD-45fc-A8A0-DB7862840BA9hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\00659FA4-2CAD-45fc-A8A0-DB7862840BA9press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\07a9a58b-c653-4285-a870-1fa70cb6c00c.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\07a9a58b-c653-4285-a870-1fa70cb6c00chover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\07a9a58b-c653-4285-a870-1fa70cb6c00cPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7A.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7Ahover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7Apress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\0E29BC94-7C9B-4A23-B682-81D0D1A806E1.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\0E29BC94-7C9B-4A23-B682-81D0D1A806E1hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\0E29BC94-7C9B-4A23-B682-81D0D1A806E1press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\0FA6F971-16AA-4921-A39F-543C9839CABE.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\0FA6F971-16AA-4921-A39F-543C9839CABEhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\0FA6F971-16AA-4921-A39F-543C9839CABEpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\101FF2F5-9F51-405F-ACBB-D4A5F3601679.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\101FF2F5-9F51-405F-ACBB-D4A5F3601679hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\101FF2F5-9F51-405F-ACBB-D4A5F3601679press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\1A039A19-BD34-4760-8DE0-E9A8E8AA8827.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\1A039A19-BD34-4760-8DE0-E9A8E8AA8827Ehover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\1A039A19-BD34-4760-8DE0-E9A8E8AA8827press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\225323D0-97BB-46E4-85E1-15EA27174BF4.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\225323D0-97BB-46E4-85E1-15EA27174BF4hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\225323D0-97BB-46E4-85E1-15EA27174BF4press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\23E3FEB8-E6FF-4475-811A-805773D02D08.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\23E3FEB8-E6FF-4475-811A-805773D02D08hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\23E3FEB8-E6FF-4475-811A-805773D02D08press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\26E2804B-65B5-47E1-A457-DAA75A2B1370.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\26E2804B-65B5-47E1-A457-DAA75A2B1370hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\26E2804B-65B5-47E1-A457-DAA75A2B1370press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\2C37338C-837B-4846-B50B-E32D70C6A0F5.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\2C37338C-837B-4846-B50B-E32D70C6A0F5hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\2C37338C-837B-4846-B50B-E32D70C6A0F5press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\30657846-199A-4D0D-984D-BE588084F1F6.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\30657846-199A-4D0D-984D-BE588084F1F6hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\30657846-199A-4D0D-984D-BE588084F1F6press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\30DFF8F0-BA79-4360-A3EA-51B6D006133C.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\30DFF8F0-BA79-4360-A3EA-51B6D006133CHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\30DFF8F0-BA79-4360-A3EA-51B6D006133CPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\328F7722-52E8-46A6-9197-B2F27C5142C7.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\328F7722-52E8-46A6-9197-B2F27C5142C7hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\328F7722-52E8-46A6-9197-B2F27C5142C7press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\372FF78B-6E4B-4B38-8E3F-797B4680FB98.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\372FF78B-6E4B-4B38-8E3F-797B4680FB98hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\372FF78B-6E4B-4B38-8E3F-797B4680FB98press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\39028511-3F15-4442-9188-DDC86BE1BBD0.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\39028511-3F15-4442-9188-DDC86BE1BBD0hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\39028511-3F15-4442-9188-DDC86BE1BBD0press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\39079B96-6DD1-42DE-89E6-76F79C8BB4E4.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\39079B96-6DD1-42DE-89E6-76F79C8BB4E4Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\39079B96-6DD1-42DE-89E6-76F79C8BB4E4Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\3C610B86-19DE-4757-B46A-871C9C27FF0A.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\3C610B86-19DE-4757-B46A-871C9C27FF0AHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\3C610B86-19DE-4757-B46A-871C9C27FF0APress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\3DF17372-78B0-4978-81A5-F9D1800C1775.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\3DF17372-78B0-4978-81A5-F9D1800C1775Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\3DF17372-78B0-4978-81A5-F9D1800C1775Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\3f9ac55c-6db5-4c01-9d34-a92da2347be6.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\3f9ac55c-6db5-4c01-9d34-a92da2347be6hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\3f9ac55c-6db5-4c01-9d34-a92da2347be6press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\412D5531-A3E1-40BB-B0C3-71E3C45A4E13.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\412D5531-A3E1-40BB-B0C3-71E3C45A4E13hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\412D5531-A3E1-40BB-B0C3-71E3C45A4E13press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\4a110a71-0e7e-4552-af6e-3ef88b2d6511.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\4a110a71-0e7e-4552-af6e-3ef88b2d6511Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\4a110a71-0e7e-4552-af6e-3ef88b2d6511Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5252af60-ef03-41a8-babe-415dba235478.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5252af60-ef03-41a8-babe-415dba235478Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5252af60-ef03-41a8-babe-415dba235478Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\536b9063-fc09-4e82-8769-73c77317aae6.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\536b9063-fc09-4e82-8769-73c77317aae6hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\536b9063-fc09-4e82-8769-73c77317aae6press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\56591C8E-DA35-4A97-AC9B-5055E0F7089E.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\56591C8E-DA35-4A97-AC9B-5055E0F7089Ehover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\56591C8E-DA35-4A97-AC9B-5055E0F7089Epress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002A.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002Ahover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002Apress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5D0A6D97-85F2-47E9-8F04-04A747B25A0E.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5D0A6D97-85F2-47E9-8F04-04A747B25A0Ehover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5D0A6D97-85F2-47E9-8F04-04A747B25A0Epress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5F488FA5-C35B-44A9-A0E4-2C7B41035780.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5F488FA5-C35B-44A9-A0E4-2C7B41035780hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\5F488FA5-C35B-44A9-A0E4-2C7B41035780press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\65B1A402-FC79-410D-AE1C-AF92E206AC1D.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\65B1A402-FC79-410D-AE1C-AF92E206AC1Dhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\65B1A402-FC79-410D-AE1C-AF92E206AC1Dpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7EC.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7EChover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7ECpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\708d8b1e-6545-474a-9f07-d854acf8ad43.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\708d8b1e-6545-474a-9f07-d854acf8ad43hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\708d8b1e-6545-474a-9f07-d854acf8ad43press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\70F16DCA-C71C-4ECB-994C-D180F2BBF736.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\70F16DCA-C71C-4ECB-994C-D180F2BBF736Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\70F16DCA-C71C-4ECB-994C-D180F2BBF736Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\72CDFC8C-6F2D-4df8-9811-18C4D682C406.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\72CDFC8C-6F2D-4df8-9811-18C4D682C406hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\72CDFC8C-6F2D-4df8-9811-18C4D682C406press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\7CF3BACC-BF1C-4860-BB4E-F1A8440250FE.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\7CF3BACC-BF1C-4860-BB4E-F1A8440250FEhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\7CF3BACC-BF1C-4860-BB4E-F1A8440250FEpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\7fe83ae9-caef-41f0-aa99-d114c0ce3941.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\7fe83ae9-caef-41f0-aa99-d114c0ce3941hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\7fe83ae9-caef-41f0-aa99-d114c0ce3941press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\8217d395-9ebe-4ebb-807c-38cc911a307f.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\8217d395-9ebe-4ebb-807c-38cc911a307fHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\8217d395-9ebe-4ebb-807c-38cc911a307fPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\85CF6427-8441-427A-859A-7A3C72288481.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\85CF6427-8441-427A-859A-7A3C72288481hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\85CF6427-8441-427A-859A-7A3C72288481press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\87442BEF-FD31-405C-A807-650CB7CC8886.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\87442BEF-FD31-405C-A807-650CB7CC8886hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\87442BEF-FD31-405C-A807-650CB7CC8886press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\89582936-094C-4880-B87A-2AF16FC33B2C.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\89582936-094C-4880-B87A-2AF16FC33B2Chover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\89582936-094C-4880-B87A-2AF16FC33B2Cpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\8b3608b1-c2d5-4ad3-a382-33601228c6d3.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\8b3608b1-c2d5-4ad3-a382-33601228c6d3hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\8b3608b1-c2d5-4ad3-a382-33601228c6d3press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\8F4131CE-D4F0-4F08-9102-78C397F3748C.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\8F4131CE-D4F0-4F08-9102-78C397F3748CHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\8F4131CE-D4F0-4F08-9102-78C397F3748CPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\90165d32-a3ef-438c-8625-be9b538b6eba.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\90165d32-a3ef-438c-8625-be9b538b6ebaHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\90165d32-a3ef-438c-8625-be9b538b6ebaPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\925D8F0E-E5EA-45F9-A657-0C14B68C4A61.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\925D8F0E-E5EA-45F9-A657-0C14B68C4A61hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\925D8F0E-E5EA-45F9-A657-0C14B68C4A61press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\929407CC-7E48-47E0-A9F9-A4A167AC24D1.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\929407CC-7E48-47E0-A9F9-A4A167AC24D1hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\929407CC-7E48-47E0-A9F9-A4A167AC24D1press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\95ae73f0-9799-46fd-bceb-57efcb7f0537.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\95ae73f0-9799-46fd-bceb-57efcb7f0537hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\95ae73f0-9799-46fd-bceb-57efcb7f0537press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8C.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8Chover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8Cpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A75C6A50-13B0-4704-AA87-8DD113E31310.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A75C6A50-13B0-4704-AA87-8DD113E31310hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A75C6A50-13B0-4704-AA87-8DD113E31310press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A89DA5A2-D390-47F4-84EF-6044EC8AC368.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A89DA5A2-D390-47F4-84EF-6044EC8AC368hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\A89DA5A2-D390-47F4-84EF-6044EC8AC368press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\a94e6710-6021-4cdc-82de-1c001238bd8f.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\a94e6710-6021-4cdc-82de-1c001238bd8fHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\a94e6710-6021-4cdc-82de-1c001238bd8fPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\B1BEF453-913F-4EC4-B057-A2BB21C09DCB.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\B1BEF453-913F-4EC4-B057-A2BB21C09DCBhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\B1BEF453-913F-4EC4-B057-A2BB21C09DCBpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55F.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55Fhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55Fpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\B81443D4-15F7-4B97-9DC8-3645A012C817.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\B81443D4-15F7-4B97-9DC8-3645A012C817hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\B81443D4-15F7-4B97-9DC8-3645A012C817press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\bc8dcde3-3fd0-4f9b-af5d-15c20f3239ab.ico

c:\users\Royal\AppData\Local\Smartbar\Common\icons\bc8dcde3-3fd0-4f9b-af5d-15c20f3239ab.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\bc8dcde3-3fd0-4f9b-af5d-15c20f3239abhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\bc8dcde3-3fd0-4f9b-af5d-15c20f3239abpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\C0AC006A-9C65-42F9-AE11-D675DCCC6840.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\C0AC006A-9C65-42F9-AE11-D675DCCC6840hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\C0AC006A-9C65-42F9-AE11-D675DCCC6840press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\c1546a00-e42d-4ce7-aac5-5353a895f3cf.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\c1546a00-e42d-4ce7-aac5-5353a895f3cfhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\c1546a00-e42d-4ce7-aac5-5353a895f3cfpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\C438F0F0-525A-4942-8307-6B71E596367D.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\C438F0F0-525A-4942-8307-6B71E596367Dhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\C438F0F0-525A-4942-8307-6B71E596367Dpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\C48E3725-71FB-4824-969A-C6D428C18A2B.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\C48E3725-71FB-4824-969A-C6D428C18A2Bhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\C48E3725-71FB-4824-969A-C6D428C18A2Bpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CCF42F56-0405-4697-A513-AA01DEE5DF02.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CCF42F56-0405-4697-A513-AA01DEE5DF02hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CCF42F56-0405-4697-A513-AA01DEE5DF02press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CE1500FE-6F59-421C-8005-3E137AC051A2.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CE1500FE-6F59-421C-8005-3E137AC051A2hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CE1500FE-6F59-421C-8005-3E137AC051A2press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D13971C4-4DA8-4C4B-87F6-17E97BFE7448.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D13971C4-4DA8-4C4B-87F6-17E97BFE7448hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D13971C4-4DA8-4C4B-87F6-17E97BFE7448press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D2B0680C-17C4-492D-85D7-D4CA3E724D50.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D2B0680C-17C4-492D-85D7-D4CA3E724D50hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D2B0680C-17C4-492D-85D7-D4CA3E724D50press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D469E1BA-B745-45B3-B7EE-378E000E74C8.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D469E1BA-B745-45B3-B7EE-378E000E74C8Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D469E1BA-B745-45B3-B7EE-378E000E74C8Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D5113B95-781C-4737-A26F-3ED3A2CB876F.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D5113B95-781C-4737-A26F-3ED3A2CB876Fhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D5113B95-781C-4737-A26F-3ED3A2CB876Fpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4C.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4Chover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4Cpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\e2870479-a572-412b-8a8f-5604d19b55cd.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\e2870479-a572-412b-8a8f-5604d19b55cdhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\e2870479-a572-412b-8a8f-5604d19b55cdpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E3345571-EEF9-4041-8C24-F7F5A9331C23.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E3345571-EEF9-4041-8C24-F7F5A9331C23hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E3345571-EEF9-4041-8C24-F7F5A9331C23press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\e357f164-c5d8-4257-aab2-fe0cad41c12e.ico

c:\users\Royal\AppData\Local\Smartbar\Common\icons\e357f164-c5d8-4257-aab2-fe0cad41c12e.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\e357f164-c5d8-4257-aab2-fe0cad41c12ehover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\e357f164-c5d8-4257-aab2-fe0cad41c12epress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E458493F-867F-4712-A3AF-D9664ED47C19.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E458493F-867F-4712-A3AF-D9664ED47C19hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E458493F-867F-4712-A3AF-D9664ED47C19press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E52BEFE7-6535-439c-B168-A3B105E4212E.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E52BEFE7-6535-439c-B168-A3B105E4212Ehover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E52BEFE7-6535-439c-B168-A3B105E4212Epress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E8584703-6CA5-4351-82CC-09E40938A066.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E8584703-6CA5-4351-82CC-09E40938A066hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\E8584703-6CA5-4351-82CC-09E40938A066press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\e8967c62-9ea0-4fde-9832-2c10f1d580de.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\e8967c62-9ea0-4fde-9832-2c10f1d580dehover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\e8967c62-9ea0-4fde-9832-2c10f1d580depress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\EA99E20A-FBBA-4197-954B-E2013280A29B.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\EA99E20A-FBBA-4197-954B-E2013280A29Bhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\EA99E20A-FBBA-4197-954B-E2013280A29Bpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F5297DBC-3B3B-4744-A54D-308EAD98D223.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F5297DBC-3B3B-4744-A54D-308EAD98D223hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F5297DBC-3B3B-4744-A54D-308EAD98D223press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\f7fd4890-7f89-4c73-8ff2-52105657cbb6.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\f7fd4890-7f89-4c73-8ff2-52105657cbb6Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\f7fd4890-7f89-4c73-8ff2-52105657cbb6Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BD.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BDhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BDpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F9218572-58F0-4FB9-B0C5-4EA74848D6EC.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F9218572-58F0-4FB9-B0C5-4EA74848D6EChover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F9218572-58F0-4FB9-B0C5-4EA74848D6ECpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7press.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\fac5189f-f2c7-4eed-bae8-011eca170d7b.png

Link to post
Share on other sites

combofix.txt continued

c:\users\Royal\AppData\Local\Smartbar\Common\icons\fac5189f-f2c7-4eed-bae8-011eca170d7bhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\fac5189f-f2c7-4eed-bae8-011eca170d7bpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\FF927FFB-35DC-43A3-A502-690B99FCC056.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\FF927FFB-35DC-43A3-A502-690B99FCC056hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\icons\FF927FFB-35DC-43A3-A502-690B99FCC056press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\00659FA4-2CAD-45fc-A8A0-DB7862840BA9.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\00659FA4-2CAD-45fc-A8A0-DB7862840BA9hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\00659FA4-2CAD-45fc-A8A0-DB7862840BA9press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\07a9a58b-c653-4285-a870-1fa70cb6c00c.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\07a9a58b-c653-4285-a870-1fa70cb6c00c.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\07a9a58b-c653-4285-a870-1fa70cb6c00chover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\07a9a58b-c653-4285-a870-1fa70cb6c00cpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7A.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7Ahover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7Apress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0AE6BC52-0A54-4F53-9848-1FC2D4CE3D3D.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0AE6BC52-0A54-4F53-9848-1FC2D4CE3D3DHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0AE6BC52-0A54-4F53-9848-1FC2D4CE3D3DPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0DB19630-EB33-4B18-8357-78FC2687C788.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0DB19630-EB33-4B18-8357-78FC2687C788hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0DB19630-EB33-4B18-8357-78FC2687C788press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0E29BC94-7C9B-4A23-B682-81D0D1A806E1.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0E29BC94-7C9B-4A23-B682-81D0D1A806E1hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0E29BC94-7C9B-4A23-B682-81D0D1A806E1press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0FA6F971-16AA-4921-A39F-543C9839CABE.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0FA6F971-16AA-4921-A39F-543C9839CABEhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\0FA6F971-16AA-4921-A39F-543C9839CABEpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\101FF2F5-9F51-405F-ACBB-D4A5F3601679.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\101FF2F5-9F51-405F-ACBB-D4A5F3601679hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\101FF2F5-9F51-405F-ACBB-D4A5F3601679press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE081313.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE081313hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE081313press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE08E613.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE08E613hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE08E613press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE131313.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE131313hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE131313press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\1A039A19-BD34-4760-8DE0-E9A8E8AA8827.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\1A039A19-BD34-4760-8DE0-E9A8E8AA8827hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\1A039A19-BD34-4760-8DE0-E9A8E8AA8827press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\2141A104-423C-43EF-A27A-CA0DADB7B9BC.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\2141A104-423C-43EF-A27A-CA0DADB7B9BChover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\2141A104-423C-43EF-A27A-CA0DADB7B9BCpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\225323D0-97BB-46E4-85E1-15EA27174BF4.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\225323D0-97BB-46E4-85E1-15EA27174BF4hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\225323D0-97BB-46E4-85E1-15EA27174BF4press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\23E3FEB8-E6FF-4475-811A-805773D02D08.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\23E3FEB8-E6FF-4475-811A-805773D02D08hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\23E3FEB8-E6FF-4475-811A-805773D02D08press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\26E2804B-65B5-47E1-A457-DAA75A2B1370.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\26E2804B-65B5-47E1-A457-DAA75A2B1370hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\26E2804B-65B5-47E1-A457-DAA75A2B1370press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\28E2C7BC-F857-44D5-A42F-7DD66FAB5EE6.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\28E2C7BC-F857-44D5-A42F-7DD66FAB5EE6hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\28E2C7BC-F857-44D5-A42F-7DD66FAB5EE6press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\2C37338C-837B-4846-B50B-E32D70C6A0F5.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\2C37338C-837B-4846-B50B-E32D70C6A0F5hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\2C37338C-837B-4846-B50B-E32D70C6A0F5press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\2F274118-68DC-4951-92D7-54CD244FE02A.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\2F274118-68DC-4951-92D7-54CD244FE02AHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\2F274118-68DC-4951-92D7-54CD244FE02APress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\30657846-199A-4D0D-984D-BE588084F1F6.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\30657846-199A-4D0D-984D-BE588084F1F6hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\30657846-199A-4D0D-984D-BE588084F1F6press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\30DEBC8A-1CC6-4480-B3E5-C55E214043A8.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\30DEBC8A-1CC6-4480-B3E5-C55E214043A8Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\30DEBC8A-1CC6-4480-B3E5-C55E214043A8Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\30DFF8F0-BA79-4360-A3EA-51B6D006133C.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\30DFF8F0-BA79-4360-A3EA-51B6D006133CHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\30DFF8F0-BA79-4360-A3EA-51B6D006133CPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\328F7722-52E8-46A6-9197-B2F27C5142C7.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\328F7722-52E8-46A6-9197-B2F27C5142C7hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\328F7722-52E8-46A6-9197-B2F27C5142C7press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\372FF78B-6E4B-4B38-8E3F-797B4680FB98.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\372FF78B-6E4B-4B38-8E3F-797B4680FB98hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\372FF78B-6E4B-4B38-8E3F-797B4680FB98press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\389DA7E0-2A26-40AB-ACA4-9417E3B9EF13.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\389DA7E0-2A26-40AB-ACA4-9417E3B9EF13Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\389DA7E0-2A26-40AB-ACA4-9417E3B9EF13Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\39028511-3F15-4442-9188-DDC86BE1BBD0.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\39028511-3F15-4442-9188-DDC86BE1BBD0hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\39028511-3F15-4442-9188-DDC86BE1BBD0press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\39079B96-6DD1-42DE-89E6-76F79C8BB4E4.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\39079B96-6DD1-42DE-89E6-76F79C8BB4E4Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\39079B96-6DD1-42DE-89E6-76F79C8BB4E4Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\3C610B86-19DE-4757-B46A-871C9C27FF0A.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\3C610B86-19DE-4757-B46A-871C9C27FF0AHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\3C610B86-19DE-4757-B46A-871C9C27FF0APress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\3DF17372-78B0-4978-81A5-F9D1800C1775.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\3DF17372-78B0-4978-81A5-F9D1800C1775Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\3DF17372-78B0-4978-81A5-F9D1800C1775Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\3f9ac55c-6db5-4c01-9d34-a92da2347be6.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\3f9ac55c-6db5-4c01-9d34-a92da2347be6.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\3f9ac55c-6db5-4c01-9d34-a92da2347be6hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\3f9ac55c-6db5-4c01-9d34-a92da2347be6press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\412D5531-A3E1-40BB-B0C3-71E3C45A4E13.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\412D5531-A3E1-40BB-B0C3-71E3C45A4E13hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\412D5531-A3E1-40BB-B0C3-71E3C45A4E13press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\47BFF758-9581-4C68-9293-1181A70CDEE8.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\47BFF758-9581-4C68-9293-1181A70CDEE8Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\47BFF758-9581-4C68-9293-1181A70CDEE8Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\48A9C19C-5A4C-4652-A6E7-1C17AEE45675.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\48A9C19C-5A4C-4652-A6E7-1C17AEE45675Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\48A9C19C-5A4C-4652-A6E7-1C17AEE45675Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\4a110a71-0e7e-4552-af6e-3ef88b2d6511.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\4a110a71-0e7e-4552-af6e-3ef88b2d6511.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\4a110a71-0e7e-4552-af6e-3ef88b2d6511Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\4a110a71-0e7e-4552-af6e-3ef88b2d6511Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\511B6809-2468-4A36-A6FC-FC24F05499BE.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\511B6809-2468-4A36-A6FC-FC24F05499BEHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\511B6809-2468-4A36-A6FC-FC24F05499BEPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5252af60-ef03-41a8-babe-415dba235478.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5252af60-ef03-41a8-babe-415dba235478.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5252af60-ef03-41a8-babe-415dba235478Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5252af60-ef03-41a8-babe-415dba235478Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\536b9063-fc09-4e82-8769-73c77317aae6.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\536b9063-fc09-4e82-8769-73c77317aae6.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\536b9063-fc09-4e82-8769-73c77317aae6hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\536b9063-fc09-4e82-8769-73c77317aae6press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\56591C8E-DA35-4A97-AC9B-5055E0F7089E.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\56591C8E-DA35-4A97-AC9B-5055E0F7089Ehover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\56591C8E-DA35-4A97-AC9B-5055E0F7089Epress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002A.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002Ahover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002Apress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5D0A6D97-85F2-47E9-8F04-04A747B25A0E.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5D0A6D97-85F2-47E9-8F04-04A747B25A0Ehover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5D0A6D97-85F2-47E9-8F04-04A747B25A0Epress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5F1B269B-7C66-474F-A473-BE7FA51BE5B2.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5F1B269B-7C66-474F-A473-BE7FA51BE5B2hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5F1B269B-7C66-474F-A473-BE7FA51BE5B2press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5F488FA5-C35B-44A9-A0E4-2C7B41035780.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5F488FA5-C35B-44A9-A0E4-2C7B41035780hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\5F488FA5-C35B-44A9-A0E4-2C7B41035780press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\65B1A402-FC79-410D-AE1C-AF92E206AC1D.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\65B1A402-FC79-410D-AE1C-AF92E206AC1Dhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\65B1A402-FC79-410D-AE1C-AF92E206AC1Dpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\65C4AD03-739F-4EC9-8FFD-457CC4241B9F.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\65C4AD03-739F-4EC9-8FFD-457CC4241B9Fhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\65C4AD03-739F-4EC9-8FFD-457CC4241B9Fpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\684B31D0-535B-45EC-B3D1-15923CF5F790.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\684B31D0-535B-45EC-B3D1-15923CF5F790Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\684B31D0-535B-45EC-B3D1-15923CF5F790Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7EC.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7EChover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7ECpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\708d8b1e-6545-474a-9f07-d854acf8ad43.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\708d8b1e-6545-474a-9f07-d854acf8ad43.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\708d8b1e-6545-474a-9f07-d854acf8ad43hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\708d8b1e-6545-474a-9f07-d854acf8ad43press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\70F16DCA-C71C-4ECB-994C-D180F2BBF736.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\70F16DCA-C71C-4ECB-994C-D180F2BBF736Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\70F16DCA-C71C-4ECB-994C-D180F2BBF736Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\72CDFC8C-6F2D-4df8-9811-18C4D682C406.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\72CDFC8C-6F2D-4df8-9811-18C4D682C406hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\72CDFC8C-6F2D-4df8-9811-18C4D682C406press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\7CF3BACC-BF1C-4860-BB4E-F1A8440250FE.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\7CF3BACC-BF1C-4860-BB4E-F1A8440250FEhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\7CF3BACC-BF1C-4860-BB4E-F1A8440250FEpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\7fe83ae9-caef-41f0-aa99-d114c0ce3941.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\7fe83ae9-caef-41f0-aa99-d114c0ce3941.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\7fe83ae9-caef-41f0-aa99-d114c0ce3941hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\7fe83ae9-caef-41f0-aa99-d114c0ce3941press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8217d395-9ebe-4ebb-807c-38cc911a307f.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8217d395-9ebe-4ebb-807c-38cc911a307f.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8217d395-9ebe-4ebb-807c-38cc911a307fHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8217d395-9ebe-4ebb-807c-38cc911a307fPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\82F730CA-BA1C-4AFB-AC7C-FE4ED6B532FD.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\82F730CA-BA1C-4AFB-AC7C-FE4ED6B532FDHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\82F730CA-BA1C-4AFB-AC7C-FE4ED6B532FDPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\85CF6427-8441-427A-859A-7A3C72288481.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\85CF6427-8441-427A-859A-7A3C72288481hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\85CF6427-8441-427A-859A-7A3C72288481press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\87442BEF-FD31-405C-A807-650CB7CC8886.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\87442BEF-FD31-405C-A807-650CB7CC8886hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\87442BEF-FD31-405C-A807-650CB7CC8886press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\89582936-094c-4880-b87a-2af16fc31313.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\89582936-094c-4880-b87a-2af16fc31313Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\89582936-094c-4880-b87a-2af16fc31313Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\89582936-094C-4880-B87A-2AF16FC33B2C.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\89582936-094C-4880-B87A-2AF16FC33B2Chover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\89582936-094C-4880-B87A-2AF16FC33B2Cpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8b3608b1-c2d5-4ad3-a382-33601228c6d3.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8b3608b1-c2d5-4ad3-a382-33601228c6d3hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8b3608b1-c2d5-4ad3-a382-33601228c6d3press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8D338D8F-3189-41AB-BCFF-2958D48AAA6A.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8D338D8F-3189-41AB-BCFF-2958D48AAA6AHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8D338D8F-3189-41AB-BCFF-2958D48AAA6APress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8F4131CE-D4F0-4F08-9102-78C397F3748C.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8F4131CE-D4F0-4F08-9102-78C397F3748CHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\8F4131CE-D4F0-4F08-9102-78C397F3748CPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\90165d32-a3ef-438c-8625-be9b538b6eba.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\90165d32-a3ef-438c-8625-be9b538b6eba.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\90165d32-a3ef-438c-8625-be9b538b6ebaHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\90165d32-a3ef-438c-8625-be9b538b6ebaPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\925D8F0E-E5EA-45F9-A657-0C14B68C4A61.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\925D8F0E-E5EA-45F9-A657-0C14B68C4A61hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\925D8F0E-E5EA-45F9-A657-0C14B68C4A61press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\929407CC-7E48-47E0-A9F9-A4A167AC24D1.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\929407CC-7E48-47E0-A9F9-A4A167AC24D1hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\929407CC-7E48-47E0-A9F9-A4A167AC24D1press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\95ae73f0-9799-46fd-bceb-57efcb7f0537.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\95ae73f0-9799-46fd-bceb-57efcb7f0537.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\95ae73f0-9799-46fd-bceb-57efcb7f0537hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\95ae73f0-9799-46fd-bceb-57efcb7f0537press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\95D9E2EA-40AD-40B8-95D0-58209F584BBE.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\95D9E2EA-40AD-40B8-95D0-58209F584BBEHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\95D9E2EA-40AD-40B8-95D0-58209F584BBEPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8C.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8Chover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8Cpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A46C5E77-16B5-42A0-8761-C6F861D22308.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A46C5E77-16B5-42A0-8761-C6F861D22308Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A46C5E77-16B5-42A0-8761-C6F861D22308Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A75C6A50-13B0-4704-AA87-8DD113E31310.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A75C6A50-13B0-4704-AA87-8DD113E31310hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A75C6A50-13B0-4704-AA87-8DD113E31310press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A89DA5A2-D390-47F4-84EF-6044EC8AC368.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A89DA5A2-D390-47F4-84EF-6044EC8AC368hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\A89DA5A2-D390-47F4-84EF-6044EC8AC368press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\a94e6710-6021-4cdc-82de-1c001238bd8f.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\a94e6710-6021-4cdc-82de-1c001238bd8f.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\a94e6710-6021-4cdc-82de-1c001238bd8fHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\a94e6710-6021-4cdc-82de-1c001238bd8fPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\B1BEF453-913F-4EC4-B057-A2BB21C09DCB.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\B1BEF453-913F-4EC4-B057-A2BB21C09DCB.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\B1BEF453-913F-4EC4-B057-A2BB21C09DCBhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\B1BEF453-913F-4EC4-B057-A2BB21C09DCBpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55F.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55Fhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55Fpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\B81443D4-15F7-4B97-9DC8-3645A012C817.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\B81443D4-15F7-4B97-9DC8-3645A012C817hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\B81443D4-15F7-4B97-9DC8-3645A012C817press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\BC303DD4-37E7-4242-8DDD-8DEE2171066B.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\BC303DD4-37E7-4242-8DDD-8DEE2171066Bhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\BC303DD4-37E7-4242-8DDD-8DEE2171066Bpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\bc8dcde3-3fd0-4f9b-af5d-15c20f3239ab.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\bc8dcde3-3fd0-4f9b-af5d-15c20f3239ab.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\bc8dcde3-3fd0-4f9b-af5d-15c20f3239abhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\bc8dcde3-3fd0-4f9b-af5d-15c20f3239abpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\BE3608B1-C2D5-4AD3-A382-45635338C6D1.PNG

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\BE3608B1-C2D5-4AD3-A382-45635338C6D1HOVER.PNG

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\BE3608B1-C2D5-4AD3-A382-45635338C6D1PRESS.PNG

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C0AC006A-9C65-42F9-AE11-D675DCCC6840.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C0AC006A-9C65-42F9-AE11-D675DCCC6840hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C0AC006A-9C65-42F9-AE11-D675DCCC6840press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\c1546a00-e42d-4ce7-aac5-5353a895f3cf.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\c1546a00-e42d-4ce7-aac5-5353a895f3cf.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\c1546a00-e42d-4ce7-aac5-5353a895f3cfhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\c1546a00-e42d-4ce7-aac5-5353a895f3cfpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C41AD485-FE91-4EFE-A613-66CB2BA96EAB.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C41AD485-FE91-4EFE-A613-66CB2BA96EABHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C41AD485-FE91-4EFE-A613-66CB2BA96EABPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C438F0F0-525A-4942-8307-6B71E596367D.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C438F0F0-525A-4942-8307-6B71E596367Dhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C438F0F0-525A-4942-8307-6B71E596367Dpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C48E3725-71FB-4824-969A-C6D428C18A2B.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C48E3725-71FB-4824-969A-C6D428C18A2Bhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\C48E3725-71FB-4824-969A-C6D428C18A2Bpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CCF42F56-0405-4697-A513-AA01DEE5DF02.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CCF42F56-0405-4697-A513-AA01DEE5DF02hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CCF42F56-0405-4697-A513-AA01DEE5DF02press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CE1500FE-6F59-421C-8005-3E137AC051A2.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CE1500FE-6F59-421C-8005-3E137AC051A2hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CE1500FE-6F59-421C-8005-3E137AC051A2press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D13971C4-4DA8-4C4B-87F6-17E97BFE7448.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D13971C4-4DA8-4C4B-87F6-17E97BFE7448hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D13971C4-4DA8-4C4B-87F6-17E97BFE7448press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D2B0680C-17C4-492D-85D7-D4CA3E724D50.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D2B0680C-17C4-492D-85D7-D4CA3E724D50hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D2B0680C-17C4-492D-85D7-D4CA3E724D50press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D469E1BA-B745-45B3-B7EE-378E000E74C8.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D469E1BA-B745-45B3-B7EE-378E000E74C8Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D469E1BA-B745-45B3-B7EE-378E000E74C8Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D5113B95-781C-4737-A26F-3ED3A2CB876F.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D5113B95-781C-4737-A26F-3ED3A2CB876FHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D5113B95-781C-4737-A26F-3ED3A2CB876FPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4C.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4Chover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4Cpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e2870479-a572-412b-8a8f-5604d19b55cd.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e2870479-a572-412b-8a8f-5604d19b55cdhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e2870479-a572-412b-8a8f-5604d19b55cdpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E3345571-EEF9-4041-8C24-F7F5A9331C23.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E3345571-EEF9-4041-8C24-F7F5A9331C23hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E3345571-EEF9-4041-8C24-F7F5A9331C23press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e357f164-c5d8-4257-aab2-fe0cad41c12e.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e357f164-c5d8-4257-aab2-fe0cad41c12e.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e357f164-c5d8-4257-aab2-fe0cad41c12ehover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e357f164-c5d8-4257-aab2-fe0cad41c12epress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e3c610dc-deed-47cd-acc0-493d71556c16.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e3c610dc-deed-47cd-acc0-493d71556c16Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e3c610dc-deed-47cd-acc0-493d71556c16Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E458493F-867F-4712-A3AF-D9664ED47C19.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E458493F-867F-4712-A3AF-D9664ED47C19hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E458493F-867F-4712-A3AF-D9664ED47C19press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E52BEFE7-6535-439c-B168-A3B105E4212E.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E52BEFE7-6535-439c-B168-A3B105E4212Ehover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E52BEFE7-6535-439c-B168-A3B105E4212Epress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E8584703-6CA5-4351-82CC-09E40938A066.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E8584703-6CA5-4351-82CC-09E40938A066hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E8584703-6CA5-4351-82CC-09E40938A066press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e8967c62-9ea0-4fde-9832-2c10f1d580de.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e8967c62-9ea0-4fde-9832-2c10f1d580de.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e8967c62-9ea0-4fde-9832-2c10f1d580dehover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\e8967c62-9ea0-4fde-9832-2c10f1d580depress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E9FFB47F-2B3F-430E-8F8D-0B640D6A9564.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E9FFB47F-2B3F-430E-8F8D-0B640D6A9564Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\E9FFB47F-2B3F-430E-8F8D-0B640D6A9564Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\EA99E20A-FBBA-4197-954B-E2013280A29B.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\EA99E20A-FBBA-4197-954B-E2013280A29Bhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\EA99E20A-FBBA-4197-954B-E2013280A29Bpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\EC116BC4-0583-4E07-908A-9D2AD3647177.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\EC116BC4-0583-4E07-908A-9D2AD3647177Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\EC116BC4-0583-4E07-908A-9D2AD3647177Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\EDDB2889-2088-4070-9F17-E71A95D7A1BC.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\EDDB2889-2088-4070-9F17-E71A95D7A1BCHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\EDDB2889-2088-4070-9F17-E71A95D7A1BCPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\f41901a8-2a78-4794-b455-d53a24b37aef.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\f41901a8-2a78-4794-b455-d53a24b37aefHover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\f41901a8-2a78-4794-b455-d53a24b37aefPress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F5297DBC-3B3B-4744-A54D-308EAD98D223.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F5297DBC-3B3B-4744-A54D-308EAD98D223hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F5297DBC-3B3B-4744-A54D-308EAD98D223press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\f7fd4890-7f89-4c73-8ff2-52105657cbb6.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\f7fd4890-7f89-4c73-8ff2-52105657cbb6.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\f7fd4890-7f89-4c73-8ff2-52105657cbb6Hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\f7fd4890-7f89-4c73-8ff2-52105657cbb6Press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BD.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BDhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BDpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F9218572-58F0-4FB9-B0C5-4EA74848D6EC.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F9218572-58F0-4FB9-B0C5-4EA74848D6EChover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F9218572-58F0-4FB9-B0C5-4EA74848D6ECpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7press.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\fac5189f-f2c7-4eed-bae8-011eca170d7b.ico

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\fac5189f-f2c7-4eed-bae8-011eca170d7b.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\fac5189f-f2c7-4eed-bae8-011eca170d7bhover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\fac5189f-f2c7-4eed-bae8-011eca170d7bpress.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\FF927FFB-35DC-43A3-A502-690B99FCC056.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\FF927FFB-35DC-43A3-A502-690B99FCC056hover.png

c:\users\Royal\AppData\Local\Smartbar\Common\iconsWide\FF927FFB-35DC-43A3-A502-690B99FCC056press.png

c:\users\Royal\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.DMP.dll

c:\users\Royal\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.MessengerPlugin.dll

c:\users\Royal\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.NotepadPlugin.dll

c:\users\Royal\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.ScreenCapturePlugin.dll

c:\users\Royal\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll

c:\users\Royal\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WordPlugin.dll

c:\users\Royal\AppData\Local\Smartbar\Common\ServicesPlugins\spup.dll

c:\users\Royal\AppData\Local\Smartbar\DistributionFiles\Configs\IconsSettings.xml

c:\users\Royal\AppData\Local\Smartbar\DistributionFiles\Configs\LocalMethods.xml

c:\users\Royal\AppData\Local\Smartbar\DistributionFiles\Configs\ProfileManager.xml

c:\users\Royal\AppData\Local\Smartbar\DistributionFiles\Configs\PublisherSettings.xml

c:\users\Royal\AppData\Local\Smartbar\DistributionFiles\Configs\UserSettings.xml

c:\users\Royal\AppData\Local\Smartbar\DistributionFiles\Profiles\4526D21E-D80F-420F-B30C-5D31E293D34E.xml

c:\users\Royal\AppData\Local\Weather_Notifications,_LL

c:\users\Royal\AppData\Local\Weather_Notifications,_LL\SevereWeatherAlerts.exe_Url_22jhg1gszunmioj2g50y3clabkghbayq\1.21.0.0\user.config

c:\users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome.manifest

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\asyncDB.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\background.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\browserAction.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\contextMenu.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\dbManager.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\dom_bg.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\fileManager.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\firefox.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\firefoxNotifications.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\firefoxOmnibox.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\message.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\pageAction.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\request.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\tabs.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\webRequest.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\api\windowsMessagingHandler.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\background.html

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\baseObject.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\browser.xul

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\addressBarChangeObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\console.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\consts.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\delegate.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\extensionDataStore.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\folderIOWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\httpObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\IDBWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\installer.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\logFile.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\prefs.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\progressListenerObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\registry.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\reloadObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\reports.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\requestObject.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\searchSettings.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\uninstallObserver.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\updateManager.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\utils.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\xhr.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\dialog.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\ffCoreFilesIndex.txt

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\main.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\options.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\options.xul

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\platformVersion.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\search_dialog.xul

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\defaults\preferences\prefs.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\manifest.xml

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins.json

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\1_base.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\102_dealply_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\103_intext_5_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\104_jollywallet_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\13_CrossriderAppUtils.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\14_CrossriderUtils.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\16_FFAppAPIWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\17_jQuery.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\177_crossriderDashboard.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\178_revizer_ws_dynamic_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\179_revizer_p_dynamic_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\180_bpo_serp_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\182_openUrl.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\183_tabsWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\184_noproblemppc_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\190_pops_5_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\191_ciuvo_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\195_icm_convertmedia_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\207_dbWrapper.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\21_debug.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\22_resources.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\220_icm_base_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\221_icm_downloads_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\223_imonomy_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\28_initializer.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\4_jquery_1_7_1.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\47_resources_background.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\64_appApiMessage.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\7_hooks.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\72_appApiValidation.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\78_CrossriderInfo.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\9_search_engine_hook.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\91_monetizationLoader.js.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\93_superfish_no_coupons_m.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\98_omniCommands.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\userCode\background.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\userCode\extension.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\install.rdf

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\locale\en-US\translations.dtd

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\button1.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\button2.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\button3.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\button4.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\button5.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\crossrider_statusbar.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\icon128.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\icon16.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\icon24.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\icon48.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\panelarrow-up.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\popup.html

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\skin.css

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\skin\update.css

c:\users\Royal\AppData\Roaming\mysearchdial

c:\users\Royal\AppData\Roaming\mysearchdial\UpdateProc\config.dat

c:\users\Royal\AppData\Roaming\mysearchdial\UpdateProc\STTL.DAT

c:\users\Royal\AppData\Roaming\mysearchdial\UpdateProc\TTL.DAT

c:\users\Royal\AppData\Roaming\mysearchdial\UpdateProc\UpdateTask.exe

c:\users\Royal\AppData\Roaming\Optimizer Pro

c:\users\Royal\AppData\Roaming\systweak

c:\users\Royal\AppData\Roaming\systweak\Advanced System Protector\2.1.1000.12594\ASPLog.txt

c:\users\Royal\AppData\Roaming\systweak\Advanced System Protector\Settings.db

c:\users\Royal\AppData\Roaming\systweak\RegClean Pro\Version 6.1\eng_rcp.dat

c:\users\Royal\AppData\Roaming\systweak\RegClean Pro\Version 6.1\ExcludeList.rcp

c:\users\Royal\AppData\Roaming\systweak\RegClean Pro\Version 6.1\log_03-07-2014.log

c:\users\Royal\AppData\Roaming\systweak\RegClean Pro\Version 6.1\log_03-08-2014.log

c:\users\Royal\AppData\Roaming\systweak\RegClean Pro\Version 6.1\rcpupdate.ini

c:\users\Royal\AppData\Roaming\systweak\RegClean Pro\Version 6.1\results.rcp

c:\users\Royal\AppData\Roaming\systweak\RegClean Pro\Version 6.1\TempHLList.rcp

c:\users\Royal\AppData\Roaming\systweak\ssd\SSDPTstub.exe

c:\users\Royal\AppData\Roaming\VOPackage

c:\users\Royal\AppData\Roaming\VOPackage\Uninstall.exe

c:\users\Royal\AppData\Roaming\VOPackage\VOPackage.exe

c:\windows\Tasks\media enhance-chromeinstaller.job

c:\windows\Tasks\media enhance-codedownloader.job

c:\windows\Tasks\media enhance-enabler.job

c:\windows\Tasks\media enhance-updater.job

c:\windows\Tasks\MySearchDial.job

c:\windows\Tasks\Re-markit Update.job

c:\windows\Tasks\Re-markit_wd.job

c:\windows\Tasks\RegClean Pro_DEFAULT.job

c:\windows\Tasks\RegClean Pro_UPDATES.job

c:\windows\Tasks\Video-for-PC-1.2-chromeinstaller.job

c:\windows\Tasks\Video-for-PC-1.2-codedownloader.job

c:\windows\Tasks\Video-for-PC-1.2-enabler.job

c:\windows\Tasks\Video-for-PC-1.2-firefoxinstaller.job

c:\windows\Tasks\Video-for-PC-1.2-updater.job

.

.

--------------- FCopy ---------------

.

c:\windows\winsxs\amd64_microsoft-windows-com-complus.res_31bf3856ad364e35_6.1.7600.16385_none_88a5cc7effe2dfca\comres.dll --> c:\windows\system32\comres.dll

c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe --> c:\windows\explorer.exe

c:\windows\winsxs\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5023a70bf589ad3e\regedit.exe --> c:\windows\regedit.exe

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_70e6ca8c

-------\Service_BackupStack

-------\Service_LPTSystemUpdater

-------\Service_Re-markit

-------\Service_Update Mega Browse

-------\Service_Util Mega Browse

.

.

((((((((((((((((((((((((( Files Created from 2014-02-11 to 2014-03-11 )))))))))))))))))))))))))))))))

.

.

2014-03-11 23:26 . 2014-03-11 23:26 -------- d-----w- c:\users\Default\AppData\Local\temp

2014-03-11 23:11 . 2014-02-06 09:01 10536864 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B426EBC4-4019-4A49-8EE7-74A21B3E9EB0}\mpengine.dll

2014-03-08 20:03 . 2014-03-08 20:06 -------- d-----w- C:\FRST

2014-03-08 02:05 . 2014-02-17 19:30 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3812B880-443E-469F-9BA3-0CAE17528064}\gapaengine.dll

2014-03-08 02:05 . 2014-02-06 09:01 10536864 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2014-03-08 01:16 . 2012-07-25 18:03 16896 ----a-w- c:\windows\system32\sasnative64.exe

2014-03-08 01:15 . 2014-01-21 23:28 20312 ----a-w- c:\windows\system32\roboot64.exe

2014-03-07 01:26 . 2014-03-07 01:26 -------- d-----w- c:\program files (x86)\Common Files\Java

2014-03-07 01:26 . 2014-03-07 01:26 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2014-02-23 13:16 . 2013-12-21 09:53 548864 ----a-w- c:\windows\system32\vbscript.dll

2014-02-23 13:16 . 2013-12-21 08:56 454656 ----a-w- c:\windows\SysWow64\vbscript.dll

2014-02-16 16:40 . 2013-12-06 02:31 1880576 ----a-w- c:\windows\system32\msxml3.dll

2014-02-16 16:40 . 2013-12-06 02:31 2048 ----a-w- c:\windows\system32\msxml3r.dll

2014-02-16 16:40 . 2013-12-06 01:58 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll

2014-02-16 16:40 . 2013-12-06 01:58 1236480 ----a-w- c:\windows\SysWow64\msxml3.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2014-02-24 00:52 . 2012-10-26 03:53 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2014-02-24 00:52 . 2012-10-26 03:53 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2014-02-23 13:24 . 2012-10-24 10:12 88567024 ----a-w- c:\windows\system32\MRT.exe

2014-02-17 19:30 . 2012-11-29 00:12 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll

2014-01-19 07:33 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe

2013-12-29 21:24 . 2013-12-29 21:24 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe

2013-12-29 21:24 . 2013-12-29 21:24 194048 ----a-w- c:\windows\SysWow64\elshyph.dll

2013-12-29 21:24 . 2013-12-29 21:24 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe

2013-12-29 21:24 . 2013-12-29 21:24 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll

2013-12-29 21:24 . 2013-12-29 21:24 235008 ----a-w- c:\windows\system32\elshyph.dll

2013-12-29 21:24 . 2013-12-29 21:24 182272 ----a-w- c:\windows\SysWow64\msls31.dll

2013-12-29 21:24 . 2013-12-29 21:24 62464 ----a-w- c:\windows\SysWow64\tdc.ocx

2013-12-29 21:24 . 2013-12-29 21:24 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll

2013-12-29 21:24 . 2013-12-29 21:24 337408 ----a-w- c:\windows\SysWow64\html.iec

2013-12-29 21:24 . 2013-12-29 21:24 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll

2013-12-29 21:24 . 2013-12-29 21:24 151552 ----a-w- c:\windows\SysWow64\iexpress.exe

2013-12-29 21:24 . 2013-12-29 21:24 139264 ----a-w- c:\windows\SysWow64\wextract.exe

2013-12-29 21:24 . 2013-12-29 21:24 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll

2013-12-29 21:24 . 2013-12-29 21:24 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll

2013-12-29 21:24 . 2013-12-29 21:24 36352 ----a-w- c:\windows\SysWow64\imgutil.dll

2013-12-29 21:24 . 2013-12-29 21:24 13312 ----a-w- c:\windows\SysWow64\mshta.exe

2013-12-29 21:24 . 2013-12-29 21:24 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll

2013-12-29 21:24 . 2013-12-29 21:24 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll

2013-12-29 21:24 . 2013-12-29 21:24 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe

2013-12-29 21:24 . 2013-12-29 21:24 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll

2013-12-29 21:24 . 2013-12-29 21:24 942592 ----a-w- c:\windows\system32\jsIntl.dll

2013-12-29 21:24 . 2013-12-29 21:24 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe

2013-12-29 21:24 . 2013-12-29 21:24 247808 ----a-w- c:\windows\system32\msls31.dll

2013-12-29 21:24 . 2013-12-29 21:24 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe

2013-12-29 21:24 . 2013-12-29 21:24 52224 ----a-w- c:\windows\system32\msfeedsbs.dll

2013-12-29 21:24 . 2013-12-29 21:24 48640 ----a-w- c:\windows\system32\mshtmler.dll

2013-12-29 21:24 . 2013-12-29 21:24 13312 ----a-w- c:\windows\system32\msfeedssync.exe

2013-12-29 21:24 . 2013-12-29 21:24 131072 ----a-w- c:\windows\system32\IEAdvpack.dll

2013-12-29 21:24 . 2013-12-29 21:24 105984 ----a-w- c:\windows\system32\iesysprep.dll

2013-12-29 21:24 . 2013-12-29 21:24 81408 ----a-w- c:\windows\system32\icardie.dll

2013-12-29 21:24 . 2013-12-29 21:24 77312 ----a-w- c:\windows\system32\tdc.ocx

2013-12-29 21:24 . 2013-12-29 21:24 616104 ----a-w- c:\windows\system32\ieapfltr.dat

2013-12-29 21:24 . 2013-12-29 21:24 453120 ----a-w- c:\windows\system32\dxtmsft.dll

2013-12-29 21:24 . 2013-12-29 21:24 413696 ----a-w- c:\windows\system32\html.iec

2013-12-29 21:24 . 2013-12-29 21:24 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll

2013-12-29 21:24 . 2013-12-29 21:24 296960 ----a-w- c:\windows\system32\dxtrans.dll

2013-12-29 21:24 . 2013-12-29 21:24 84992 ----a-w- c:\windows\system32\mshtmled.dll

2013-12-29 21:24 . 2013-12-29 21:24 30208 ----a-w- c:\windows\system32\licmgr10.dll

2013-12-29 21:24 . 2013-12-29 21:24 263376 ----a-w- c:\windows\system32\iedkcs32.dll

2013-12-29 21:24 . 2013-12-29 21:24 243200 ----a-w- c:\windows\system32\webcheck.dll

2013-12-29 21:24 . 2013-12-29 21:24 235520 ----a-w- c:\windows\system32\url.dll

2013-12-29 21:24 . 2013-12-29 21:24 167424 ----a-w- c:\windows\system32\iexpress.exe

2013-12-29 21:24 . 2013-12-29 21:24 143872 ----a-w- c:\windows\system32\wextract.exe

2013-12-29 21:24 . 2013-12-29 21:24 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll

2013-12-29 21:24 . 2013-12-29 21:24 101376 ----a-w- c:\windows\system32\inseng.dll

2013-12-29 21:24 . 2013-12-29 21:24 83968 ----a-w- c:\windows\system32\MshtmlDac.dll

2013-12-29 21:24 . 2013-12-29 21:24 774144 ----a-w- c:\windows\system32\jscript.dll

2013-12-29 21:24 . 2013-12-29 21:24 62464 ----a-w- c:\windows\system32\pngfilt.dll

2013-12-29 21:24 . 2013-12-29 21:24 48128 ----a-w- c:\windows\system32\imgutil.dll

2013-12-29 21:24 . 2013-12-29 21:24 147968 ----a-w- c:\windows\system32\occache.dll

2013-12-29 21:24 . 2013-12-29 21:24 13824 ----a-w- c:\windows\system32\mshta.exe

2013-12-29 21:24 . 2013-12-29 21:24 135680 ----a-w- c:\windows\system32\iepeers.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110511151178}]

c:\program files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-bho.dll [bU]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}]

2010-11-21 03:24 297808 ----a-w- c:\windows\System32\mscoree.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"EnableLUA"= 0 (0x0)

"EnableSecureUIAPaths"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"EnableVirtualization"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"SynchronousMachineGroupPolicy"= 1 (0x1)

"SynchronousUserGroupPolicy"= 1 (0x1)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoResolveTrack"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]

R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]

R3 MAUSBPRODUCER;Service for M-Audio Producer;c:\windows\system32\DRIVERS\MAudioProducer.sys;c:\windows\SYSNATIVE\DRIVERS\MAudioProducer.sys [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]

R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\drivers\Synth3dVsc.sys;c:\windows\SYSNATIVE\drivers\Synth3dVsc.sys [x]

R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]

R4 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]

R4 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]

S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]

S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]

S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmpfd.sys [x]

S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]

S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x]

S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]

S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]

S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2014-03-05 03:39 1150280 ----a-w- c:\program files (x86)\Google\Chrome\Application\33.0.1750.146\Installer\chrmstp.exe

.

Contents of the 'Scheduled Tasks' folder

.

2014-03-11 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-26 00:52]

.

2014-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-22 03:19]

.

2014-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-22 03:19]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912]

"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [bU]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

TCP: DhcpNameServer = 24.220.0.10 24.220.0.11 192.168.1.1

FF - ProfilePath - c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\

user_pref(extensions.autoDisableScopes,14);

.

- - - - ORPHANS REMOVED - - - -

.

BHO-{11111111-1111-1111-1111-110411411150} - c:\program files (x86)\media enhance\media enhance-bho.dll

BHO-{4e6cd411-ce62-4584-97ff-6afbcf6900af} - c:\program files (x86)\Mega Browse\MegaBrowsebho.dll

BHO-{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} - c:\program files (x86)\Mysearchdial\1.8.29.0\bh\mysearchdial.dll

c:\users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Severe Weather Alerts App.lnk - c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsApp.exe

c:\users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Severe Weather Alerts.lnk - c:\users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlerts.exe /restart

AddRemove-00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1 - c:\program files (x86)\Advanced System Protector\unins000.exe

AddRemove-AnyProtect - c:\program files (x86)\AnyProtectEx\uninstall.exe

AddRemove-f39ced07-2290-4c5b-8b63-8530de4bfc17 - c:\program files (x86)\Re-markit-soft\Uninstall.exe

AddRemove-media enhance - c:\program files (x86)\media enhance\Uninstall.exe

AddRemove-mysearchdial - c:\program files (x86)\Mysearchdial\1.8.29.0\uninstall.exe

AddRemove-Optimizer Pro_is1 - c:\program files (x86)\Optimizer Pro\unins000.exe

AddRemove-RegClean Pro_is1 - c:\program files (x86)\RegClean Pro\unins000.exe

AddRemove-Video-for-PC-1.2 - c:\program files (x86)\Video-for-PC-1.2\Uninstall.exe

AddRemove-VOPackage - c:\users\Royal\AppData\Roaming\VOPackage\uninstall.exe

AddRemove-Severe Weather Alerts - c:\users\Royal\AppData\Local\SevereWeatherAlerts\uninstall.exe

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_70_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_70_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_70_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_70_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.12"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe

.

**************************************************************************

.

Completion time: 2014-03-11 18:30:53 - machine was rebooted

ComboFix-quarantined-files.txt 2014-03-11 23:30

.

Pre-Run: 470,807,097,344 bytes free

Post-Run: 471,035,170,816 bytes free

.

- - End Of File - - 40885E96258A726B05B3E9B19A903CB1

A36C5E4F47E84449FF07ED3517B43A31

Link to post
Share on other sites

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe
  • Hit Scan and wait for the scan to finish.
  • Confirm the message but don´t uncheck anything.
  • Hit Clean
  • When the run is finished, it will open up a text file
  • Please post its contents within your next reply
  • You´ll find the log file at C:\AdwCleaner[s1].txt also

 
 
 
Delete junk with JRT

thisisujrt.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

 

 

 

Full System Scan with Malwarebytes Antimalware


  • If not existing, please download
Malwarebytes' Anti-Malware to your desktop. Double-click mbam-setup.exe and follow the prompts to install the program. At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.



If the program is already installed:

  • Run Malwarebytes Antimalware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform fullscan, place a checkmark on all hard drives, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

 

 

 

Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology

[*]Click Scan[*]Wait for the scan to finish[*]If any threats were found, click the 'List of found threats' , then click Export to text file.... [*]Save it to your desktop, then please copy and paste that log as a reply to this topic.

Link to post
Share on other sites

Sorry for the log delays. I didnt have time to run all 4 scans. I did finished 2 tonight Ill complete the malwarebytes and eset scan tomorrow.

 

adwcleaner.txt

# AdwCleaner v3.022 - Report created 13/03/2014 at 19:43:19
# Updated 13/03/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Royal - ROYAL-PC
# Running from : C:\Users\Royal\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
Folder Deleted : C:\Users\Royal\AppData\LocalLow\Mysearchdial
Folder Deleted : C:\Users\Royal\AppData\LocalLow\Smartbar
Folder Deleted : C:\Users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
Folder Deleted : C:\Users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Deleted : C:\Users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
Folder Deleted : C:\Users\Royal\Documents\Optimizer Pro
Folder Deleted : C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcpfhaghaadpjpgocojgnlhjcieeooel
Folder Deleted : C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna
File Deleted : C:\Windows\System32\roboot64.exe
File Deleted : C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\invalidprefs.js
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
File Deleted : C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\searchplugins\bingp.xml
File Deleted : C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\searchplugins\Mysearchdial.xml
File Deleted : C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\searchplugins\Web Search.xml
File Deleted : C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\user.js
File Deleted : C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage
File Deleted : C:\Windows\System32\Tasks\Advanced System Protector_startup
File Deleted : C:\Windows\System32\Tasks\MySearchDial
File Deleted : C:\Windows\System32\Tasks\RegClean Pro
File Deleted : C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
File Deleted : C:\Windows\System32\Tasks\RegClean Pro_UPDATES
File Deleted : C:\Windows\System32\Tasks\Re-markit Update

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Google\Chrome\Extensions\ahilkiibpgjnonbhdfkkgjddddmapala
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ahilkiibpgjnonbhdfkkgjddddmapala
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\igjjkeeamkpihpncmmbgdkhdnjpcfmfb
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\esrv.mysearchdialesrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.mysearchdialesrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.bho
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Key Deleted : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialappCore
Key Deleted : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialappCore.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0044150.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0044150.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0044150.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0051578.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0051578.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0051578.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3004627E-F8E9-4E8B-909D-316753CBA923}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4ED063C9-4A0B-4B44-A9DC-23AFF424A0D3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C358B3D0-B911-41E3-A276-E7D43A6BA56D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411411150}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511151178}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422412250}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522152278}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455415550}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555155578}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466416650}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566156678}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411411150}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511151178}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{219046AE-358F-4CF1-B1FD-2B4DE83642A8}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422412250}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522152278}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455415550}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555155578}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466416650}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566156678}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\installedbrowserextensions
Key Deleted : HKCU\Software\mysearchdial
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\smartbarbackup
Key Deleted : HKCU\Software\smartbarlog
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\DynConIE
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\Software\Freeze.com
Key Deleted : HKLM\Software\InstallCore
Key Deleted : HKLM\Software\InstallIQ
Key Deleted : HKLM\Software\mysearchdial
Key Deleted : HKLM\Software\systweak
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mysearchdial
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [searchAssistant]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [start Page]

-\\ Mozilla Firefox v27.0.1 (en-US)

[ File : C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\prefs.js ]


Line Deleted : user_pref("extensions.crossrider.bic", "1449f3ac1ee8b6a7a072091b1ad32365");
Line Deleted : user_pref("extensions.dynconff.cache.get.adobe.com.content", "<package expire=\"3600\" es=\"914\" pcdids=\"v51_1164_1169_1146_1348_1420\"><content id=\"puConfig_2052A3DD\">\r\n    <newjs>\r\n        <![CDATA[\[...]
Line Deleted : user_pref("extensions.helperbar.BackPageActive", true);
Line Deleted : user_pref("extensions.helperbar.DockingPositionDown", false);
Line Deleted : user_pref("extensions.helperbar.SmartbarDisabled", false);
Line Deleted : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Line Deleted : user_pref("extensions.helperbar.Visibility", false);
Line Deleted : user_pref("extensions.helperbar.backPageCapacity", 3);
Line Deleted : user_pref("extensions.helperbar.backPageCounter", 0);
Line Deleted : user_pref("extensions.helperbar.backPageDay", 7);
Line Deleted : user_pref("extensions.helperbar.backPageLastEvent", "1394068319353");
Line Deleted : user_pref("extensions.helperbar.backPageMinInterval", 15);
Line Deleted : user_pref("extensions.helperbar.barcodeid", "129943");
Line Deleted : user_pref("extensions.helperbar.countryiso", "us");
Line Deleted : user_pref("extensions.helperbar.downloadprovider", "tuguubs_ch");
Line Deleted : user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[{\\\"ExcludeDomains\\\":[\\\"www.browse-search.com\\\"],\\\"hxxpInjection\\\":\\\"hxxp:\\\\\\/\\\\\\/nps.noproblemppc.com\\\\\\/npsb\\\\\\/[...]
Line Deleted : user_pref("extensions.helperbar.fromautoupdate", "false");
Line Deleted : user_pref("extensions.helperbar.installationid", "3d45363c-d41c-7232-0a7b-86846627c592");
Line Deleted : user_pref("extensions.helperbar.installdate", "07/03/2014");
Line Deleted : user_pref("extensions.helperbar.keepAliveLastevent", "1394241119");
Line Deleted : user_pref("extensions.helperbar.lastExternalJsUpdate", "1394241162905");
Line Deleted : user_pref("extensions.helperbar.publisher", "tuguubs");


*************************

AdwCleaner[R0].txt - [19322 octets] - [13/03/2014 19:42:25]
AdwCleaner[s0].txt - [16882 octets] - [13/03/2014 19:43:19]

########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [16943 octets] ##########
 

 

 

 

 

JRT.txt

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 7 Ultimate x64
Ran by Royal on Thu 03/13/2014 at 19:58:05.40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted: [Folder] C:\Users\Royal\AppData\Roaming\mozilla\firefox\profiles\5psf8u1v.default\extensions\staged
Emptied folder: C:\Users\Royal\AppData\Roaming\mozilla\firefox\profiles\5psf8u1v.default\minidumps [55 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 03/13/2014 at 20:05:21.51
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

Link to post
Share on other sites

mbam-log.txt

Malwarebytes Anti-Malware (Trial) 1.75.0.1300

www.malwarebytes.org

Database version: v2014.03.14.07

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 11.0.9600.16521

Royal :: ROYAL-PC [administrator]

Protection: Enabled

3/14/2014 5:54:51 PM

mbam-log-2014-03-14 (17-54-51).txt

Scan type: Full scan (C:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 333062

Time elapsed: 28 minute(s), 17 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 9

HKCR\CLSID\{4e6cd411-ce62-4584-97ff-6afbcf6900af} (PUP.Optional.MegaBrowse.A) -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E6CD411-CE62-4584-97FF-6AFBCF6900AF} (PUP.Optional.MegaBrowse.A) -> Quarantined and deleted successfully.

HKCR\Typelib\{FBC322D5-407E-4854-8C0B-555B951FD8E3} (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.

HKCR\Interface\{0400EBCA-042C-4000-AA89-9713FBEDB671} (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.

HKCU\Software\Mega Browse (PUP.Optional.MegaBrowse.A) -> Quarantined and deleted successfully.

HKCU\Software\AppDataLow\Software\media enhance (PUP.Optional.MediaEnhance.A) -> Quarantined and deleted successfully.

HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths\SevereWeatherAlerts.exe (PUP.Optional.SevereWeatherAlerts.A) -> Quarantined and deleted successfully.

HKLM\Software\media enhance (PUP.Optional.MediaEnhance.A) -> Quarantined and deleted successfully.

HKLM\Software\Mega Browse (PUP.Optional.MegaBrowse.A) -> Quarantined and deleted successfully.

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 3

C:\Users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SEVERE WEATHER ALERTS (PUP.Optional.SevereWeatherAlerts) -> Quarantined and deleted successfully.

C:\Users\Royal\AppData\Local\Google\Chrome\USER DATA\Default\EXTENSIONS\lekgiimbfodefdaoofhlckefjbgpeilo (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.

C:\Users\Royal\AppData\Local\Google\Chrome\USER DATA\Default\EXTENSIONS\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0 (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.

Files Detected: 36

C:\Program Files (x86)\SFXMaker\plugins\7zS.sfx (Trojan.Zbot) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\media enhance\media enhance-bg.exe.vir (PUP.Optional.MediaEnhance.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\media enhance\media enhance-bho.dll.vir (PUP.Optional.MediaEnhance.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\media enhance\media enhance-bho64.dll.vir (PUP.Optional.MediaEnhance.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\media enhance\media enhance-chromeinstaller.exe.vir (PUP.Optional.MediaEnhance.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\media enhance\media enhance-codedownloader.exe.vir (PUP.Optional.MediaEnhance.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\media enhance\media enhance-enabler.exe.vir (PUP.Optional.MediaEnhance.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\media enhance\media enhance-firefoxinstaller.exe.vir (PUP.Optional.MediaEnhance.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\media enhance\media enhance-updater.exe.vir (PUP.Optional.MediaEnhance.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\media enhance\utils.exe.vir (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Mega Browse\MegaBrowseBHO.dll.vir (PUP.Optional.MegaBrowse.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Mega Browse\updateMegaBrowse.exe.vir (PUP.Optional.MegaBrowse.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Mega Browse\bin\utilMegaBrowse.exe.vir (PUP.Optional.MegaBrowse.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialApp.dll.vir (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialEng.dll.vir (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialsrv.exe.vir (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialTlbr.dll.vir (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Mysearchdial\1.8.29.0\bh\mysearchdial.dll.vir (PUP.Optional.MySearchDial.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProReminder.exe.vir (PUP.Optional.OptimizerPro) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProSchedule.exe.vir (PUP.Optional.OptimizerPro) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe.vir (PUP.Optional.OptimizerPro) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Program Files (x86)\Video-for-PC-1.2\utils.exe.vir (PUP.Optional.HQVideoPro.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlerts.exe.vir (PUP.Optional.SevereWeatherAlerts.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\SevereWeatherAlerts\SevereWeatherAlertsApp.exe.vir (PUP.Optional.SevereWeatherAlerts.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\SevereWeatherAlerts\uninstall.exe.vir (PUP.Optional.SevereWeatherAlerts) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Smartbar\Application\SmartbarVersionsHelper.exe.vir (PUP.Optional.SmartBar.A) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\mysearchdial\UpdateProc\UpdateTask.exe.vir (PUP.Optional.DealPly) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\VOPackage\Uninstall.exe.vir (PUP.Optional.SilenceInstall) -> Quarantined and deleted successfully.

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\VOPackage\VOPackage.exe.vir (PUP.Optional.SilenceInstall) -> Quarantined and deleted successfully.

C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\File System\000\t\00\00000000 (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.

C:\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\00\00000000 (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.

C:\Users\Royal\Downloads\Installer.exe (PUP.Optional.Outbrowse) -> Quarantined and deleted successfully.

C:\Users\Royal\Downloads\Java.exe (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.

C:\Users\Royal\Downloads\Setup.exe (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.

C:\Windows\Installer\121bdd.msi (PUP.Optional.SmartBar.A) -> Quarantined and deleted successfully.

C:\Users\Royal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SEVERE WEATHER ALERTS\SEVERE WEATHER ALERTS.LNK (PUP.Optional.SevereWeatherAlerts) -> Quarantined and deleted successfully.

(end)

eset.txt

C:\$RECYCLE.BIN\S-1-5-21-1242493167-1881160721-3933183209-1000\$R9TU2SM\Quarantine\C\ProgramData\apn\APN-Stub\W3IV6-G\APNIC.dll.vir a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application

C:\$RECYCLE.BIN\S-1-5-21-1242493167-1881160721-3933183209-1000\$R9TU2SM\Quarantine\C\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application

C:\Qoobox\Quarantine\C\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe.vir a variant of MSIL/AdvancedSystemProtector.B potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Advanced System Protector\AspManager.exe.vir a variant of MSIL/AdvancedSystemProtector.B potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Advanced System Protector\filetypehelper.exe.vir a variant of MSIL/AdvancedSystemProtector.B potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Advanced System Protector\scandll.dll.vir a variant of MSIL/AdvancedSystemProtector.B potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Mega Browse\MegaBrowseUninstall.exe.vir Win32/BrowseFox.C potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Mega Browse\bin\MegaBrowseBrowserFilter.exe.vir a variant of MSIL/BrowseFox.B potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Optimizer Pro\OptimizerPro.exe.vir a variant of Win32/SpeedingUpMyPC application

C:\Qoobox\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProCrash.dll.vir a variant of Win32/SProtector.E potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Optimizer Pro\optprocrashSvc.dll.vir a variant of Win32/SProtector.F potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll.vir a variant of Win64/SProtector.A potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Optimizer Pro\OptProLauncher.exe.vir a variant of Win32/AdWare.SpeedingUpMyPC.D application

C:\Qoobox\Quarantine\C\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-bg.exe.vir a variant of Win32/Toolbar.CrossRider.AA potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-bho64.dll.vir a variant of Win64/Toolbar.Crossrider.D potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-chromeinstaller.exe.vir a variant of Win32/Toolbar.CrossRider.Y potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-codedownloader.exe.vir a variant of Win32/Toolbar.CrossRider.X potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-enabler.exe.vir a variant of Win32/Toolbar.CrossRider.X potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-firefoxinstaller.exe.vir a variant of Win32/Toolbar.CrossRider.Y potentially unwanted application

C:\Qoobox\Quarantine\C\Program Files (x86)\Video-for-PC-1.2\Video-for-PC-1.2-updater.exe.vir a variant of Win32/Toolbar.CrossRider.X potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\102_dealply_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\103_intext_5_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\104_jollywallet_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\155_ibario_pops_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\184_noproblemppc_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\190_pops_5_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\191_ciuvo_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\195_icm_convertmedia_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\230_revizer_ws_dynamic_b2b_2_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\91_monetizationLoader.js.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.71_0\extensionData\plugins\93_superfish_no_coupons_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\102_dealply_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\103_intext_5_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\104_jollywallet_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\178_revizer_ws_dynamic_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\179_revizer_p_dynamic_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\180_bpo_serp_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\184_noproblemppc_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\190_pops_5_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\191_ciuvo_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\195_icm_convertmedia_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\221_icm_downloads_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\223_imonomy_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\91_monetizationLoader.js.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lndipknmjijnalnkamonmljeaojdbpna\1.26.19_0\extensionData\plugins\93_superfish_no_coupons_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll.vir a variant of MSIL/Toolbar.Linkury.D potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll.vir a variant of MSIL/Toolbar.Linkury.D potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll.vir Win32/Toolbar.Linkury.D potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_22.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_23.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_24.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_25.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_26.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_27.dll.vir a variant of Win32/Toolbar.Linkury.D potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\102_dealply_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\103_intext_5_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\104_jollywallet_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\155_ibario_pops_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\190_pops_5_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\191_ciuvo_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\195_icm_convertmedia_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\230_revizer_ws_dynamic_b2b_2_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\91_monetizationLoader.js.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\93_superfish_no_coupons_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\102_dealply_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\103_intext_5_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\104_jollywallet_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\178_revizer_ws_dynamic_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\179_revizer_p_dynamic_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\180_bpo_serp_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\184_noproblemppc_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\190_pops_5_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\191_ciuvo_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\195_icm_convertmedia_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\221_icm_downloads_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\223_imonomy_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\91_monetizationLoader.js.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Qoobox\Quarantine\C\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\93_superfish_no_coupons_m.js.vir JS/Toolbar.Crossrider.B potentially unwanted application

C:\Users\Royal\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OT7W588T\monetizationLoader[1].js JS/Toolbar.Crossrider.B potentially unwanted application

C:\Users\Royal\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VPOWVP80\price_gong_m[1].js JS/Toolbar.Crossrider.B potentially unwanted application

C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_22.dll a variant of Win32/Toolbar.Linkury.D potentially unwanted application

C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_23.dll a variant of Win32/Toolbar.Linkury.D potentially unwanted application

C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_24.dll a variant of Win32/Toolbar.Linkury.D potentially unwanted application

C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_25.dll a variant of Win32/Toolbar.Linkury.D potentially unwanted application

C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_26.dll a variant of Win32/Toolbar.Linkury.D potentially unwanted application

C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_27.dll a variant of Win32/Toolbar.Linkury.D potentially unwanted application

Link to post
Share on other sites

Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe
  • Hit Scan and wait for the scan to finish.
  • Confirm the message but don´t uncheck anything.
  • Hit Clean
  • When the run is finished, it will open up a text file
  • Please post its contents within your next reply
  • You´ll find the log file at C:\AdwCleaner[s1].txt also

 
 
Delete junk with JRT

thisisujrt.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

 

SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.

Link to post
Share on other sites

adwcleaner.txt

# AdwCleaner v3.022 - Report created 15/03/2014 at 11:28:56

# Updated 13/03/2014 by Xplode

# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)

# Username : Royal - ROYAL-PC

# Running from : C:\Users\Royal\Desktop\adwcleaner.exe

# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521

-\\ Mozilla Firefox v27.0.1 (en-US)

[ File : C:\Users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\prefs.js ]

*************************

AdwCleaner[R1].txt - [769 octets] - [15/03/2014 11:22:33]

AdwCleaner[s1].txt - [691 octets] - [15/03/2014 11:28:56]

########## EOF - C:\AdwCleaner\AdwCleaner[s1].txt - [750 octets] ##########

JRT.txt

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 6.1.2 (02.20.2014:1)

OS: Windows 7 Ultimate x64

Ran by Royal on Sun 03/16/2014 at 8:49:28.31

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

~~~ Event Viewer Logs were cleared

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Sun 03/16/2014 at 8:58:55.12

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checkup.txt

UNSUPPORTED OPERATING SYSTEM! ABORTED!

Link to post
Share on other sites

Scanning is only disabled because most of these programs have asked me to turn it off before starting scans plus I dont want it to run and quarantine anything without you knowing.

checkup.txt

Results of screen317's Security Check version 0.99.80

Windows 7 Service Pack 1 x64 (UAC is disabled!)

Internet Explorer 11

``````````````Antivirus/Firewall Check:``````````````

Windows Firewall Enabled!

Microsoft Security Essentials

(On Access scanning disabled!)

Error obtaining update status for antivirus!

`````````Anti-malware/Other Utilities Check:`````````

Malwarebytes Anti-Malware version 1.75.0.1300

Java 7 Update 51

Adobe Flash Player 12.0.0.77

Adobe Reader XI

Mozilla Firefox (27.0.1)

Google Chrome 33.0.1750.146

Google Chrome 33.0.1750.154

````````Process Check: objlist.exe by Laurent````````

Microsoft Security Essentials MSMpEng.exe

Microsoft Security Essentials msseces.exe

Malwarebytes Anti-Malware mbamservice.exe

Malwarebytes Anti-Malware mbamgui.exe

Malwarebytes' Anti-Malware mbamscheduler.exe

`````````````````System Health check`````````````````

Total Fragmentation on Drive C:

````````````````````End of Log``````````````````````

Link to post
Share on other sites

Combofix scripting

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Download the attached CFScript.txt and save it to the location where Combofix is.


CFScriptB-4.gif


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

CFScript.txt

Link to post
Share on other sites

combofix.txt

ComboFix 14-03-10.01 - Royal 03/21/2014 18:43:44.3.2 - x64

State of Independence Windows 7 xDark™ v4.3 RG Deluxe 6.1.7601.1.1252.1.1033.18.3561.2297 [GMT -5:00]

Running from: c:\users\Royal\Desktop\ComboFix.exe

Command switches used :: c:\users\Royal\Desktop\CFScript.txt

AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}

SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

FILE ::

"c:\users\Royal\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OT7W588T\monetizationLoader[1].js"

"c:\users\Royal\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VPOWVP80\price_gong_m[1].js"

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\Royal\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OT7W588T\monetizationLoader[1].js

c:\users\Royal\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VPOWVP80\price_gong_m[1].js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome.manifest

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\BackPageRemove.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\externalJS.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\FBImagePreview.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\FirefoxExtensionMain.css

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\FirefoxExtensionMain.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\FirefoxExtensionMain.xul

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\down-1.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\down-2.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\down-3.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\down.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\fb.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\fblike.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\gmail.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\googleplus.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\hide-1.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\hide-2.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\hide-3.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\left.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\maximize-1.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\maximize-2.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\maximize-3.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\mgsplusvideo.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\minimize-1.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\minimize-2.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\minimize-3.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\pinit.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\right.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\searchBox.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\show-1.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\show-2.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\show-3.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\twitter.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\up-1.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\up-2.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\up-3.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\images\up.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\InternalJS.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\jquery-1.5.1.min.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\publisherDefinitions.js

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\PublisherImages\Muvic.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\PublisherImages\Muvic_small.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\PublisherImages\Muvic128.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\chrome\PublisherImages\Muvic16.png

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\ISmartbarFireFoxRemotePlugin.xpt

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_22.dll

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_23.dll

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_24.dll

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_25.dll

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_26.dll

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\components\SmartbarFireFoxRemotePlugin_27.dll

c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\extensions\{3d45363c-d41c-7232-0a7b-86846627c592}\install.rdf

.

.

((((((((((((((((((((((((( Files Created from 2014-02-21 to 2014-03-21 )))))))))))))))))))))))))))))))

.

.

2014-03-21 23:48 . 2014-03-21 23:48 -------- d-----w- c:\users\Default\AppData\Local\temp

2014-03-16 06:49 . 2014-02-06 09:01 10536864 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B5B765A3-8CE6-458C-83BC-20E0F8F497DF}\mpengine.dll

2014-03-15 16:40 . 2014-02-06 09:01 10536864 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2014-03-15 16:22 . 2014-03-16 13:49 -------- d-----w- C:\AdwCleaner

2014-03-14 22:53 . 2014-03-14 22:53 -------- d-----w- c:\users\Royal\AppData\Roaming\Malwarebytes

2014-03-14 22:53 . 2014-03-14 22:53 -------- d-----w- c:\programdata\Malwarebytes

2014-03-14 22:53 . 2014-03-14 22:53 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2014-03-14 22:53 . 2013-04-04 19:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys

2014-03-14 22:52 . 2014-03-14 22:52 5777288 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe

2014-03-14 00:58 . 2014-03-14 00:58 -------- d-----w- c:\windows\ERUNT

2014-03-14 00:42 . 2014-03-01 22:02 235224 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll

2014-03-08 02:05 . 2014-02-17 19:30 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3812B880-443E-469F-9BA3-0CAE17528064}\gapaengine.dll

2014-03-08 01:16 . 2012-07-25 18:03 16896 ----a-w- c:\windows\system32\sasnative64.exe

2014-03-07 01:26 . 2014-03-07 01:26 -------- d-----w- c:\program files (x86)\Common Files\Java

2014-03-07 01:26 . 2014-03-07 01:26 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2014-02-23 13:16 . 2013-12-21 09:53 548864 ----a-w- c:\windows\system32\vbscript.dll

2014-02-23 13:16 . 2013-12-21 08:56 454656 ----a-w- c:\windows\SysWow64\vbscript.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2014-03-20 00:09 . 2012-10-24 10:12 90015360 ----a-w- c:\windows\system32\MRT.exe

2014-03-14 22:52 . 2012-10-26 03:53 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2014-03-14 22:52 . 2012-10-26 03:53 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2014-02-17 19:30 . 2012-11-29 00:12 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll

2014-01-19 07:33 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe

2013-12-29 21:24 . 2013-12-29 21:24 194048 ----a-w- c:\windows\SysWow64\elshyph.dll

2013-12-29 21:24 . 2013-12-29 21:24 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe

2013-12-29 21:24 . 2013-12-29 21:24 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll

2013-12-29 21:24 . 2013-12-29 21:24 235008 ----a-w- c:\windows\system32\elshyph.dll

2013-12-29 21:24 . 2013-12-29 21:24 182272 ----a-w- c:\windows\SysWow64\msls31.dll

2013-12-29 21:24 . 2013-12-29 21:24 62464 ----a-w- c:\windows\SysWow64\tdc.ocx

2013-12-29 21:24 . 2013-12-29 21:24 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll

2013-12-29 21:24 . 2013-12-29 21:24 337408 ----a-w- c:\windows\SysWow64\html.iec

2013-12-29 21:24 . 2013-12-29 21:24 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll

2013-12-29 21:24 . 2013-12-29 21:24 151552 ----a-w- c:\windows\SysWow64\iexpress.exe

2013-12-29 21:24 . 2013-12-29 21:24 139264 ----a-w- c:\windows\SysWow64\wextract.exe

2013-12-29 21:24 . 2013-12-29 21:24 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll

2013-12-29 21:24 . 2013-12-29 21:24 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll

2013-12-29 21:24 . 2013-12-29 21:24 36352 ----a-w- c:\windows\SysWow64\imgutil.dll

2013-12-29 21:24 . 2013-12-29 21:24 13312 ----a-w- c:\windows\SysWow64\mshta.exe

2013-12-29 21:24 . 2013-12-29 21:24 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll

2013-12-29 21:24 . 2013-12-29 21:24 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll

2013-12-29 21:24 . 2013-12-29 21:24 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe

2013-12-29 21:24 . 2013-12-29 21:24 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll

2013-12-29 21:24 . 2013-12-29 21:24 942592 ----a-w- c:\windows\system32\jsIntl.dll

2013-12-29 21:24 . 2013-12-29 21:24 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe

2013-12-29 21:24 . 2013-12-29 21:24 247808 ----a-w- c:\windows\system32\msls31.dll

2013-12-29 21:24 . 2013-12-29 21:24 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe

2013-12-29 21:24 . 2013-12-29 21:24 52224 ----a-w- c:\windows\system32\msfeedsbs.dll

2013-12-29 21:24 . 2013-12-29 21:24 48640 ----a-w- c:\windows\system32\mshtmler.dll

2013-12-29 21:24 . 2013-12-29 21:24 13312 ----a-w- c:\windows\system32\msfeedssync.exe

2013-12-29 21:24 . 2013-12-29 21:24 131072 ----a-w- c:\windows\system32\IEAdvpack.dll

2013-12-29 21:24 . 2013-12-29 21:24 105984 ----a-w- c:\windows\system32\iesysprep.dll

2013-12-29 21:24 . 2013-12-29 21:24 81408 ----a-w- c:\windows\system32\icardie.dll

2013-12-29 21:24 . 2013-12-29 21:24 77312 ----a-w- c:\windows\system32\tdc.ocx

2013-12-29 21:24 . 2013-12-29 21:24 616104 ----a-w- c:\windows\system32\ieapfltr.dat

2013-12-29 21:24 . 2013-12-29 21:24 453120 ----a-w- c:\windows\system32\dxtmsft.dll

2013-12-29 21:24 . 2013-12-29 21:24 413696 ----a-w- c:\windows\system32\html.iec

2013-12-29 21:24 . 2013-12-29 21:24 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll

2013-12-29 21:24 . 2013-12-29 21:24 296960 ----a-w- c:\windows\system32\dxtrans.dll

2013-12-29 21:24 . 2013-12-29 21:24 84992 ----a-w- c:\windows\system32\mshtmled.dll

2013-12-29 21:24 . 2013-12-29 21:24 30208 ----a-w- c:\windows\system32\licmgr10.dll

2013-12-29 21:24 . 2013-12-29 21:24 263376 ----a-w- c:\windows\system32\iedkcs32.dll

2013-12-29 21:24 . 2013-12-29 21:24 243200 ----a-w- c:\windows\system32\webcheck.dll

2013-12-29 21:24 . 2013-12-29 21:24 235520 ----a-w- c:\windows\system32\url.dll

2013-12-29 21:24 . 2013-12-29 21:24 167424 ----a-w- c:\windows\system32\iexpress.exe

2013-12-29 21:24 . 2013-12-29 21:24 143872 ----a-w- c:\windows\system32\wextract.exe

2013-12-29 21:24 . 2013-12-29 21:24 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll

2013-12-29 21:24 . 2013-12-29 21:24 101376 ----a-w- c:\windows\system32\inseng.dll

2013-12-29 21:24 . 2013-12-29 21:24 83968 ----a-w- c:\windows\system32\MshtmlDac.dll

2013-12-29 21:24 . 2013-12-29 21:24 774144 ----a-w- c:\windows\system32\jscript.dll

2013-12-29 21:24 . 2013-12-29 21:24 62464 ----a-w- c:\windows\system32\pngfilt.dll

2013-12-29 21:24 . 2013-12-29 21:24 48128 ----a-w- c:\windows\system32\imgutil.dll

2013-12-29 21:24 . 2013-12-29 21:24 147968 ----a-w- c:\windows\system32\occache.dll

2013-12-29 21:24 . 2013-12-29 21:24 13824 ----a-w- c:\windows\system32\mshta.exe

2013-12-29 21:24 . 2013-12-29 21:24 135680 ----a-w- c:\windows\system32\iepeers.dll

2013-12-24 23:09 . 2014-02-16 16:38 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll

2013-12-24 22:48 . 2014-02-16 16:38 2565120 ----a-w- c:\windows\system32\d3d10warp.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"EnableLUA"= 0 (0x0)

"EnableSecureUIAPaths"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"EnableVirtualization"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"SynchronousMachineGroupPolicy"= 1 (0x1)

"SynchronousUserGroupPolicy"= 1 (0x1)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoResolveTrack"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]

R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]

R3 MAUSBPRODUCER;Service for M-Audio Producer;c:\windows\system32\DRIVERS\MAudioProducer.sys;c:\windows\SYSNATIVE\DRIVERS\MAudioProducer.sys [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]

R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\drivers\Synth3dVsc.sys;c:\windows\SYSNATIVE\drivers\Synth3dVsc.sys [x]

R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]

R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]

R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]

R4 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]

R4 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]

S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]

S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]

S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmpfd.sys [x]

S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]

S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x]

S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]

S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]

S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2014-03-15 16:39 1150280 ----a-w- c:\program files (x86)\Google\Chrome\Application\33.0.1750.154\Installer\chrmstp.exe

.

Contents of the 'Scheduled Tasks' folder

.

2014-03-16 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-26 22:52]

.

2014-03-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-22 03:19]

.

2014-03-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-22 03:19]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912]

"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [bU]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

TCP: DhcpNameServer = 24.220.0.10 24.220.0.11 192.168.1.1

FF - ProfilePath - c:\users\Royal\AppData\Roaming\Mozilla\Firefox\Profiles\5psf8u1v.default\

.

- - - - ORPHANS REMOVED - - - -

.

AddRemove-AnyProtect - c:\program files (x86)\AnyProtectEx\uninstall.exe

AddRemove-f39ced07-2290-4c5b-8b63-8530de4bfc17 - c:\program files (x86)\Re-markit-soft\Uninstall.exe

AddRemove-media enhance - c:\program files (x86)\media enhance\Uninstall.exe

AddRemove-Video-for-PC-1.2 - c:\program files (x86)\Video-for-PC-1.2\Uninstall.exe

AddRemove-VOPackage - c:\users\Royal\AppData\Roaming\VOPackage\uninstall.exe

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.12"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2014-03-21 18:49:49

ComboFix-quarantined-files.txt 2014-03-21 23:49

.

Pre-Run: 470,890,881,024 bytes free

Post-Run: 470,873,583,616 bytes free

.

- - End Of File - - 073659C9B155EA53DC6FB43DDE4E7DFA

A36C5E4F47E84449FF07ED3517B43A31

Link to post
Share on other sites

Your system is clean now! :)

 

 

Uninstall our tools using delfix

Please follow these steps in order:

  1. In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  2. In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  3. In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process

[*] If there is still something left please delete it manualy.

 

 

 

Recommendations: How to protect yourself

  • System Updates
    Please ensure to have automatic updates activated in your control panel.
    For further information and a tutorial, see this Microsoft Support article.
  • Protection
    What you need is one (not more) virus scanner with background protection. Additionally I recommend a special malware scanner to run on demand weekly.
    Personally I am using avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer good protection for free.
    • To keep your browser free of advertising, you may install the Adblock Plus browser extension.
      It will filter unwanted advertising out of the website´s content.
    • To protect yourself from accidentally visiting malicious web sites, install the Web of Trust (WOT) browser extension.
      It will display a green (safe), yellow (unknown) or red (potentially dangerous) icon for a visited website within your browser.
      In addition, before accessing a dangerous classified web site, a warning screen is displayed.


    [*]Up to date Software
    Keep your Windows and your third party software up to date. The easiest way to get infected is an outdated windows, followed by: browser(s) (including add-ons and plug-ins), Adobe Flash Player and Adobe Reader, Java Runtime Environment, your antivirus program and so on. These links may help you to check:

    [*]Backup
    Hardware issues, malware, fire, lightning strike: There is a long list of different ways to loose all your data. Back up your files regularly. Use the windows internal backup function or a third party tool and save your data onto an external hard drive, cloud storage, optical media like CDs or DVDs or (if available) a professional network backup system. [*]Behaviour
    The commonest error when using a computer is "error 80" - what means that the error is located about 80cm in front of the monitor. This is a common joke between IT support technicians but it shows that all the safety mechanisms won´t help if you aren´t careful enough.

    • While surfing the internet, don´t click on anything you don´t know. In the worst case, it infects your system with malware.
    • Watch your step in social networks! Many cyber criminals use them to spread malware, mine personal pata (to be sold to advertising companies, for example) or simply do damage to other users. Even if a received hyperlink within a message seems to be coming from one of your friends, have a closer look. In addition, don´t click everything.
    • When installing software, have a look to each of the setup windows and uncheck any additional toolbars or free programs that may be offered additionally. Most of today´s setup procedures contain potentially unwanted programs so keep them off your system.
    • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
      They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.



Link to post
Share on other sites