Jump to content

Recommended Posts

Hello,

I have a 2007 Sony Vaio VGN-FW370J laptop running 64-bit Windows Vista Home Premium Service Pack 2.

The laptop started working slower and slower, especially at start up, so I decided to try out a few things to solve the problem. After these trials my computer is now unable to work in normal mode: it boots up regularly, I can log into my (administrator) account but after a couple of minutes everything freezes up and the computer hangs forever until I hardware switch it off. The computer works well in normal mode.

 

Here is some history of the steps I took before deciding to post in this forum

 

1) I ran the free version of MBAM to check for malware. MBAM effectively detected several malicious items, which I quarantined.

After this action, the computer still worked in normal mode (though it was still slow), but a pop up window titled "RunDLL" appeared with the message "Error in: C:\Users\MarcoAdm\AppData\Local\TB\APISupport\APISupport.dll Missing entry: DLLRunAPISupport".

 

2) At a friend's suggestion I downloaded and ran a series of tools from IOBit Advanced System Care, who apparently found some more malware, eliminated some programs from the Startup, and cleaned some registers.

This was probably a bad move, since after that the computer stopped working in normal mode.

 

3) I set-up the computer to a clean-boot disabling all non-Microsoft services, but it did not solve the issue in normal mode. So I guess the problem is that the OS got potentially corrupted.

 

4) When I try to run Startup Repair at boot up, I get the message "StartRep.exe - Application error" with the text "The exception Breakpoint . A breakpoint has been reached (0x80000003) occurred in the application at location 0xfb635fa5. Click on OK to terminate the program".

The Startup Repair log says: Root cause found: Registry is corrupt. Repair action: Registry roll back. Result: Failed. Error code = 0x20".

 

5) System resore fails saying "No restore points have been created on your computer's system disk. To create a restore point open System Protection"

When I try to open System Protection, a System Properties windows pop up, with no way to create a restore point. This is possibly a result of OS corruption.

 

6) I am attaching the file sfcdetails.txt obtained by parsing the CBS.log produced by sfc /scanall with the command

findstr /c:"[sR]" %windir%\logs\cbs\cbs.log >%userprofile%\Desktop\sfcdetails.txt

and the file ntbtlog.txt generated when I enable boot logging .

 

7) My antivirus, Microsoft Security Essentials. found no viruses.

 

 

After this lengthy introduction, here are the results of the steps recommended in

https://forums.malwarebytes.org/index.php?/topic/9573-im-infected-what-do-i-do-now/

 

1) I download the latest free version of MBAM and did a Threat Scan (in Safe Mode with Networking). Some more malware was found. I attached the corresponding  log mbam_log_10102014.txt. I took no action on those items.

 

2) I downloaded the Farbar Recovery Scan Tool (again in Safe Mode with Networking). I am attaching below the requested log files. Again, I took no action on these results.

 

I would appreciate any help the forum experts can give me.

 

Regards,

Marco

 

FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-10-2014 01
Ran by MarcoAdm (administrator) on SONYLAPTOP on 10-10-2014 16:18:33
Running from C:\Users\MarcoAdm\Downloads
Loaded Profile: MarcoAdm (Available profiles: MarcoAdm & Administrator & Guest)
Platform: Windows Vista Home Premium Service Pack 2 (X64) OS Language: English (United States)
Internet Explorer Version 9
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office\WINWORD.EXE
(Microsoft Corporation) C:\Windows\MSAgent\AgentSvr.exe
(Microsoft Corporation) C:\Windows\System32\msconfig.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\VESWinlogon-x32: VESWinlogon.dll [X]
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_14_0_0_145_Plugin.exe [851632 2014-07-09] (Adobe Systems Incorporated)
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\MountPoints2: {0704b6c6-eef6-11e1-b785-8c87dfc73970} - F:\LaunchU3.exe -a
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\MountPoints2: {69fcf01f-e7d4-11e1-8e88-806e6f6e6963} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\MountPoints2: {b2d1a024-e7d0-11e1-9396-d07ffd9f2f6d} - F:\setup_vmb_lite.exe /checkApplicationPresence
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=SNYR&bmod=SNYR
StartMenuInternet: IEXPLORE.EXE - %ProgramFiles(x86)%\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Virtual Account Numbers Helper -> {17424104-1444-4810-85D7-B4DA413C5A9A} -> C:\Program Files (x86)\Virtual Account Numbers\CitiVANHelper.dll (Orbiscom Ltd. All rights reserved.)
BHO-x32: CitiUSBrowserHelper Class -> {387EDF53-1CF2-4523-BC2F-13462651BE8C} -> C:\Program Files (x86)\Virtual Account Numbers\BhoCitUS.dll (Orbiscom Ltd. All rights reserved.)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Advanced SystemCare Browser Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - I.R.I.S. Desktop Search - {577EBCA9-8ED3-45FC-A514-55B3817D4BCF} - C:\Program Files (x86)\IRIS Desktop Search\IRISDesktopSearchIntegration910.dll (Copernic Technologies Inc.)
Toolbar: HKLM-x32 - Virtual Account Numbers - {7A21A046-B886-4A62-9D69-EF2059B0A27B} - C:\Program Files (x86)\Virtual Account Numbers\CitiVANToolbar.dll (Orbiscom Ltd. All rights reserved.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU - I.R.I.S. Desktop Search - {577EBCA9-8ED3-45FC-A514-55B3817D4BCF} -  No File
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} -  No File
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} -  No File
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} -  No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{2A73429A-B03C-4F88-ABAF-48B0629EA399}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{2BF03E76-37A1-4EB0-867B-923862A5E1AA}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{83228AEC-D667-4A75-AC1E-483C1216EBA5}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{C2F38D47-8F48-4FFF-9C21-3B5EA2894EFB}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{FC077840-0E7B-4E6C-9460-0DB6F45F914E}: [NameServer] 8.8.8.8,8.8.4.4

FireFox:
========
FF ProfilePath: C:\Users\MarcoAdm\AppData\Roaming\Mozilla\Firefox\Profiles\56wx6ubw.default-1399854068777
FF Homepage: www.google.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/MycameraPlugin -> C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: tdameritrade.com/thinkorswim -> C:\Program Files (x86)\thinkTDA\npthinkorswim.dll (TD Ameritrade)
FF Plugin HKCU: tdameritrade.com/tossc -> C:\Program Files (x86)\thinkTDA\nptossc.dll (TD Ameritrade)
FF user.js: detected! => C:\Users\MarcoAdm\AppData\Roaming\Mozilla\Firefox\Profiles\56wx6ubw.default-1399854068777\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\MarcoAdm\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\MarcoAdm\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\MarcoAdm\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\MarcoAdm\AppData\Roaming\Mozilla\Firefox\Profiles\56wx6ubw.default-1399854068777\Extensions\ascsurfingprotection@iobit.com [2014-08-30]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-10-05]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-04-15]
FF HKLM-x32\...\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn
FF HKLM-x32\...\Firefox\Extensions: [citius@orbiscom] - C:\Program Files (x86)\Virtual Account Numbers
FF Extension: Virtual Account Numbers for Firefox - C:\Program Files (x86)\Virtual Account Numbers [2009-04-05]
FF Extension: No Name - C:\Program Files (x86)\IObit Apps Toolbar\FF [Not Found]

Chrome:
=======
CHR HomePage: Default -> hxxp://search.conduit.com/?ctid=CT2504091&SearchSource=48&CUI=UN52017086324385214&UM=2
CHR StartupUrls: Default -> "hxxp://search.conduit.com/?ctid=CT2504091&SearchSource=48&CUI=UN52017086324385214&UM=2"
CHR Profile: C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd [2014-09-03]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-29]
CHR Extension: (Google Wallet) - C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-14]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S4 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2012-07-04] () [File not signed]
S4 EvtEng; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [1449984 2008-08-20] (Intel® Corporation) [File not signed]
S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
S4 KodakSvc; C:\Program Files (x86)\Kodak\AiO\center\KodakSvc.exe [38296 2009-01-19] (Eastman Kodak Company)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S4 MSCSPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [53248 2008-05-20] (Sony Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S4 NgVpnMgr; C:\Windows\system32\ngvpnmgr.exe [424984 2009-06-04] (Aventail Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
S4 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [53248 2008-05-20] (Sony Corporation) [File not signed]
S4 PowerOffer Service; C:\Users\MarcoAdm\AppData\Local\PosService\Pos.exe [164352 2011-12-16] (PowerOfferService) [File not signed]
S4 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [24576 2008-09-10] (Intuit) [File not signed]
S4 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [61440 2008-08-08] (Intuit Inc.) [File not signed]
S4 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1886488 2014-07-10] (Trusteer Ltd.)
S4 RegSrvc; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [826368 2008-08-20] (Intel® Corporation) [File not signed]
S4 RtkAudioService; C:\Windows\RtkAudioService.exe [134656 2008-10-17] (Realtek Semiconductor) [File not signed]
S4 SampleCollector; C:\Program Files\Sony\VAIO Care\collsvc.exe [167424 2008-09-29] (Intel Corporation) [File not signed]
S4 ServUpdater; C:\Users\MarcoAdm\AppData\Local\ServUpdater\ServiceUpd.exe [156160 2011-12-16] (ServiceUpd) [File not signed]
S4 SOHCImp; C:\Program Files (x86)\Sony\VAIO Media plus\SOHCImp.exe [103712 2008-10-21] (Sony Corporation)
S4 SOHDms; C:\Program Files (x86)\Sony\VAIO Media plus\SOHDms.exe [353568 2008-10-21] (Sony Corporation)
S4 SOHDs; C:\Program Files (x86)\Sony\VAIO Media plus\SOHDs.exe [62752 2008-10-21] (Sony Corporation)
S4 SPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe [77824 2008-05-20] (Sony Corporation) [File not signed]
S4 TBSrv; C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe [350528 2014-03-31] () [File not signed]
S4 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S4 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [73728 2008-09-08] (Sony Corporation) [File not signed]
S4 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [446464 2008-09-03] (Sony Corporation) [File not signed]
S4 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [279848 2008-09-08] (Sony Corporation)
S4 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [8704 2010-09-08] (Vodafone) [File not signed]
S4 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2008-09-08] (Sony Corporation) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2008-04-24] (ArcSoft, Inc.)
S3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
S1 DMICall; C:\Windows\SysWOW64\DRIVERS\DMICall.sys [10216 2008-08-22] (Sony Corporation)
U3 Ehtssvcietle_; C:\Windows\SysWOW64\drivers\DMICall.sys [10216 2008-08-22] (Sony Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-10-10] (Malwarebytes Corporation)
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NgFilter; C:\Windows\System32\DRIVERS\ngfilter.sys [25624 2009-06-04] (Aventail Corporation)
S3 NgLog; C:\Windows\System32\DRIVERS\nglog.sys [31256 2009-06-04] (Aventail Corporation)
R3 NgVpn; C:\Windows\System32\DRIVERS\ngvpn.sys [102424 2009-06-04] (Aventail Corporation)
S3 NgWfp; C:\Windows\System32\DRIVERS\ngwfp.sys [28696 2009-06-04] (Aventail Corporation)
S2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 ONDAusbmdm6k; C:\Windows\System32\DRIVERS\ONDAusbmdm6k.sys [119680 2010-09-02] (Onda Communication)
S3 ONDAusbnet; C:\Windows\System32\DRIVERS\ONDAusbnet.sys [135168 2010-09-02] (ONDA Corporation)
S3 ONDAusbnmea; C:\Windows\System32\DRIVERS\ONDAusbnmea.sys [119680 2010-09-02] (Onda Communication)
S3 ONDAusbser6k; C:\Windows\System32\DRIVERS\ONDAusbser6k.sys [119680 2010-09-02] (Onda Communication)
S1 RapportCerberus_69875; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_69875.sys [631128 2014-07-30] ()
S1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [299736 2014-07-10] (Trusteer Ltd.)
S3 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [358616 2014-07-10] (Trusteer Ltd.)
S1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [414296 2014-07-10] (Trusteer Ltd.)
R2 risdptsk; C:\Windows\System32\DRIVERS\risdsn64.sys [76288 2008-10-22] (REDC)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
S3 Spyder2; C:\Windows\System32\DRIVERS\Spyder2.sys [15360 2007-01-17] ()
S3 vodafone_K3805-z_cdc_acm; C:\Windows\System32\DRIVERS\vodafone_K3805-z_cdc_acm.sys [98304 2010-09-01] (Vodafone)
S3 vodafone_K3805-z_cdc_ecm; C:\Windows\System32\DRIVERS\vodafone_K3805-z_cdc_ecm.sys [53760 2010-09-01] (Vodafone)
S3 vodafone_K3805-z_cpo; C:\Windows\System32\DRIVERS\vodafone_K3805-z_cpo.sys [13824 2010-09-01] (Vodafone)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-10 16:18 - 2014-10-10 16:19 - 00022792 _____ () C:\Users\MarcoAdm\Downloads\FRST.txt
2014-10-10 16:17 - 2014-10-10 16:18 - 00000000 ____D () C:\FRST
2014-10-10 16:16 - 2014-10-10 16:16 - 02109952 _____ (Farbar) C:\Users\MarcoAdm\Downloads\FRST64.exe
2014-10-10 16:04 - 2014-10-10 16:04 - 00116171 _____ () C:\Users\MarcoAdm\Desktop\sfcdetails.txt
2014-10-10 15:43 - 2014-10-10 15:53 - 00023040 ____H () C:\Users\MarcoAdm\Documents\~WRL2756.tmp
2014-10-10 15:43 - 2014-10-10 15:43 - 00021504 ____H () C:\Users\MarcoAdm\Documents\~WRL0742.tmp
2014-10-10 15:03 - 2014-10-10 15:03 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\MarcoAdm\Downloads\mbam-setup-2.0.2.1012(1).exe
2014-10-10 14:56 - 2014-10-10 14:56 - 00006538 _____ () C:\Windows\system32\PerfStringBackup.TMP
2014-10-07 05:39 - 2014-10-07 05:39 - 00273656 _____ () C:\Windows\Minidump\Mini100714-01.dmp
2014-10-06 01:38 - 2014-10-06 01:38 - 00984576 _____ () C:\Users\MarcoAdm\Downloads\MicrosoftFixit50906.msi
2014-10-06 00:55 - 2014-10-06 00:55 - 00009976 _____ () C:\Users\MarcoAdm\Desktop\errors3.txt
2014-10-05 14:14 - 2014-10-05 14:14 - 00000974 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-10-05 14:13 - 2014-10-05 14:13 - 00000915 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2014-10-05 13:35 - 2014-10-05 13:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-05 12:47 - 2014-10-05 12:47 - 00002601 _____ () C:\Users\MarcoAdm\Desktop\DetectedProblems.txt
2014-10-05 11:09 - 2014-10-05 11:09 - 00273656 _____ () C:\Windows\Minidump\Mini100514-01.dmp
2014-10-04 21:33 - 2014-10-07 05:39 - 574202035 _____ () C:\Windows\MEMORY.DMP
2014-10-04 21:33 - 2014-10-04 21:33 - 00273656 _____ () C:\Windows\Minidump\Mini100414-01.dmp
2014-10-04 17:08 - 2014-10-04 17:08 - 00000178 _____ () C:\Windows\setupact.log
2014-10-04 17:08 - 2014-10-04 17:08 - 00000071 _____ () C:\Windows\setuperr.log
2014-10-04 17:06 - 2014-10-04 17:06 - 00145408 _____ (Intel® Corporation) C:\Windows\system32\Drivers\IntcHdmi.sys
2014-10-04 17:05 - 2014-10-04 17:08 - 00000000 ____D () C:\Windows\LastGood
2014-10-04 17:05 - 2014-10-04 17:05 - 00000000 ____H () C:\ProgramData\DP45977C.lfl
2014-10-04 17:05 - 2014-10-04 17:05 - 00000000 ____D () C:\Program Files\Realtek
2014-10-04 17:04 - 2014-10-04 17:04 - 60636160 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2014-10-04 17:04 - 2014-10-04 17:04 - 28343384 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 14863448 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 12894808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO3064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 07164176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 06218072 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 05804772 _____ () C:\Windows\system32\Drivers\rtvienna.dat
2014-10-04 17:04 - 2014-10-04 17:04 - 05751048 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 03962840 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2014-10-04 17:04 - 2014-10-04 17:04 - 03959384 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnN64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02834648 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02800344 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02770976 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02162992 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02117424 _____ () C:\Windows\system32\SStudio.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02101848 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02041432 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01959128 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2014-10-04 17:04 - 2014-10-04 17:04 - 01939800 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01934424 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek264.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01317976 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO6064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01313904 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01286872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01168472 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO5064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01136728 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO4064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01099203 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2014-10-04 17:04 - 2014-10-04 17:04 - 01063512 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01048824 _____ (SRS Labs, Inc.) C:\Windows\system32\slcnt64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01022168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00956504 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO2064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00948952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00947760 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00942384 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOSettingsIPC.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00906800 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00900696 _____ (Waves Audio Ltd.) C:\Windows\SysWOW64\MaxxAudioAPOShell.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00889592 _____ (DTS, Inc.) C:\Windows\system32\sl3apo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00871856 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaeapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00836544 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00724728 _____ (DTS, Inc.) C:\Windows\system32\sltech64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00712296 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00663296 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00662784 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00628952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00603984 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00582056 _____ (TOSHIBA Corporation) C:\Windows\system32\tosasfapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00501184 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00487360 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00434960 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00415680 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00315736 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00291488 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00261464 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00246008 _____ (TODO: <Company name>) C:\Windows\system32\slprp64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00241768 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00221024 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00209096 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00162224 _____ (TOSHIBA Corporation) C:\Windows\system32\toseaeapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00141584 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00124176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00109848 _____ () C:\Windows\system32\AcpiServiceVnA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00078688 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00075024 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00065944 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00033592 _____ () C:\Windows\system32\audioLibVc.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2014-10-04 16:58 - 2014-10-04 16:58 - 00000254 _____ () C:\Windows\Tasks\Driver Booster SkipUAC (MarcoAdm).job
2014-10-04 16:34 - 2014-10-04 16:37 - 00000000 _____ () C:\Users\MarcoAdm\sfcdetails.txt
2014-10-04 16:29 - 2014-10-04 16:29 - 00669185 _____ () C:\Users\MarcoAdm\Desktop\CBS.log
2014-10-04 16:29 - 2014-10-04 16:29 - 00000485 _____ () C:\Users\MarcoAdm\Desktop\sfcscannowresults.txt
2014-10-04 11:45 - 2014-10-04 11:45 - 00000320 _____ () C:\Windows\PFRO.log
2014-10-04 10:42 - 2014-10-04 10:42 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Eastman Kodak Company
2014-10-04 10:28 - 2014-10-04 10:28 - 00000000 ____D () C:\Windows\Tasks\TaskDisabled
2014-10-04 10:27 - 2014-10-04 10:27 - 00116216 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-04 10:26 - 2014-10-04 10:53 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\IObit
2014-10-04 10:25 - 2014-10-05 14:13 - 00000000 ____D () C:\Users\Administrator
2014-10-04 10:25 - 2014-10-04 10:25 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-10-04 10:25 - 2013-12-05 21:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Trusteer
2014-10-04 10:25 - 2013-01-18 23:44 - 00000000 ____D () C:\Users\Administrator\AppData\LocalGoogle
2014-10-04 10:25 - 2013-01-18 23:44 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-10-04 10:25 - 2012-07-08 21:27 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia
2014-10-04 10:25 - 2009-01-06 04:00 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Help
2014-10-04 10:25 - 2008-01-20 20:20 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-10-04 10:25 - 2008-01-20 20:20 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-04 03:52 - 2014-10-04 11:31 - 00000284 _____ () C:\Windows\Tasks\Uninstaller_SkipUac_Administrator.job
2014-10-03 21:58 - 2014-10-03 21:58 - 00000000 ____D () C:\Windows\LastGood.Tmp
2014-10-03 08:40 - 2014-10-03 19:44 - 00010783 _____ () C:\Users\MarcoAdm\Desktop\errors2.txt
2014-10-03 08:27 - 2014-10-10 15:21 - 00000732 _____ () C:\Users\MarcoAdm\AppData\Local\d3d9caps64.dat
2014-10-03 01:10 - 2014-10-03 01:10 - 00001331 _____ () C:\Users\MarcoAdm\Desktop\errors.txt
2014-10-03 00:52 - 2014-10-03 00:52 - 00000165 _____ () C:\Users\MarcoAdm\Documents\errors.txt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-10 15:49 - 2008-12-03 08:44 - 01617285 _____ () C:\Windows\WindowsUpdate.log
2014-10-10 15:05 - 2014-08-29 20:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-10 15:04 - 2014-08-29 20:26 - 00000941 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-10 15:04 - 2014-08-29 20:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-10 15:04 - 2014-08-29 20:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-10 14:44 - 2006-11-02 08:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-10 14:44 - 2006-11-02 08:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-10 14:44 - 2006-11-02 08:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-07 05:39 - 2009-08-30 01:04 - 00000000 ____D () C:\Windows\Minidump
2014-10-06 21:34 - 2006-11-02 05:46 - 00781016 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-06 02:14 - 2006-11-02 06:33 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-10-06 01:08 - 2012-05-02 19:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-04 17:08 - 2009-02-01 12:46 - 00000000 ____D () C:\Users\MarcoAdm
2014-10-04 17:08 - 2006-11-02 06:33 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-04 17:06 - 2008-10-30 20:07 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2014-10-04 17:06 - 2008-10-30 19:56 - 00006144 _____ () C:\Windows\system32\HdmiCoin.dll
2014-10-04 15:57 - 2012-04-16 23:03 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-04 15:56 - 2008-10-30 19:17 - 00000012 _____ () C:\Windows\bthservsdp.dat
2014-10-04 15:56 - 2006-11-02 08:42 - 00032580 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-04 13:07 - 2009-12-23 23:13 - 00000000 ____D () C:\Windows\pss
2014-10-04 13:06 - 2013-01-06 12:30 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Roaming\Dropbox
2014-10-04 11:50 - 2010-02-09 20:38 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-04 11:42 - 2014-08-30 00:13 - 00002040 _____ () C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2014-10-04 03:48 - 2009-02-01 13:47 - 00116224 _____ () C:\Users\MarcoAdm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-10-04 03:45 - 2010-02-12 09:39 - 00001356 _____ () C:\Users\MarcoAdm\AppData\Local\d3d9caps.dat
2014-10-04 03:43 - 2012-09-26 09:52 - 00002709 _____ () C:\Users\MarcoAdm\Desktop\iBackup Extractor.lnk
2014-10-03 20:59 - 2006-11-02 08:21 - 00408024 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-03 07:59 - 2006-11-02 08:21 - 00046080 _____ () C:\Windows\system32\umstartup.etl
2014-10-02 22:20 - 2014-08-30 00:14 - 00000000 ____D () C:\ProgramData\ProductData
2014-10-02 22:19 - 2014-04-13 15:00 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Local\NativeMessaging
2014-10-02 22:18 - 2014-04-13 15:01 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Local\TB
2014-10-02 22:18 - 2014-04-13 15:00 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Local\CRE

Some content of TEMP:
====================
C:\Users\MarcoAdm\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpb635ro.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-10 15:05

==================== End Of Log ============================

 

Addition.txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-10-2014 01
Ran by MarcoAdm at 2014-10-10 16:19:45
Running from C:\Users\MarcoAdm\Downloads
Boot Mode: Safe Mode (with Networking)
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 Setup OpenMP (x32 Version: 1.0.0 - Eastmen Kodak Company) Hidden
7-Zip 4.65 (HKLM-x32\...\7-Zip) (Version: v9.20 - TUGUU SL) <==== ATTENTION
Acrobat.com (HKLM-x32\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2540 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.4.0.2540 - Adobe Systems Incorporated) Hidden
Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version:  - )
Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Photoshop CS (HKLM-x32\...\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}) (Version: CS - Adobe Systems, Inc.)
Adobe Reader X (10.1.11) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated)
Advanced SystemCare 7 (HKLM-x32\...\Advanced SystemCare 7_is1) (Version: 7.3.0 - IObit)
aiofw (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
aioprnt (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
aioscnnr (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
Alps Pointing-device for VAIO (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version:  - )
ALTools Update (HKLM-x32\...\ALUpdate_is1) (Version: v11.4 - ESTsoft Corp.)
ALZip 8.51 (HKLM-x32\...\ALZip_is1) (Version: v8.51 - ESTsoft Corp.)
Amazon Kindle (HKCU\...\Amazon Kindle) (Version:  - Amazon)
Apple Application Support (HKLM-x32\...\{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}) (Version: 3.0.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft Magic-i Visual Effects 2 (HKLM-x32\...\{7BB90344-0647-468E-925A-7F69F7983421}) (Version: 2.0.1.39 - ArcSoft)
ArcSoft WebCam Companion 2 (HKLM-x32\...\{9973498D-EA29-4A68-BE0B-C88D6E03E928}) (Version:  - ArcSoft)
Aventail Connect (HKLM\...\{C338ACAC-7162-42E3-8B8C-85E5746F4A2E}) (Version: 10.1.95 - SonicWALL Aventail)
Batch PDF Merger (HKLM-x32\...\com.essexreddevelopment.mergepdfmac) (Version: 2.6 - Essex Redevelopment Group)
Batch PDF Merger (x32 Version: 2.6 - Essex Redevelopment Group) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Canon DIGITAL CAMERA Solution Disk Software Guide (HKLM-x32\...\Software Guide) (Version: 1.5.0.1 - Canon Inc.)
CANON iMAGE GATEWAY MyCamera Download Plugin (HKLM-x32\...\MyCamera Download Plugin) (Version: 3.1.1.2 - Canon Inc.)
CANON iMAGE GATEWAY Task for ZoomBrowser EX (HKLM-x32\...\CANON iMAGE GATEWAY Task) (Version: 1.9.0.9 - Canon Inc.)
Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\...\MovieEditTask) (Version: 3.8.0.5 - Canon Inc.)
Canon PowerShot SX230 HS and PowerShot SX220 HS Camera User Guide (HKLM-x32\...\CameraUserGuide-PSSX230HSandPSSX220HS) (Version: 1.0.1.2 - Canon Inc.)
Canon PowerShot SX280 HS and SX270 HS Camera User Guide (HKLM-x32\...\CameraUserGuide-PSSX280HSandSX270HS) (Version: 1.0.0.1 - Canon Inc.)
Canon RAW Image Task for ZoomBrowser EX (HKLM-x32\...\RAW Image Task) (Version: 0.9.3.9 - Canon Inc.)
Canon Utilities CameraWindow DC 8 (HKLM-x32\...\CameraWindowDC) (Version: 8.10.0.16 - Canon Inc.)
Canon Utilities ImageBrowser EX (HKLM-x32\...\ImageBrowser EX) (Version: 1.4.0.5 - Canon Inc.)
Canon Utilities MyCamera (HKLM-x32\...\MyCamera) (Version: 7.4.0.2 - Canon Inc.)
Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.23.47 - Canon Inc.)
Canon Utilities RemoteCapture Task for ZoomBrowser EX (HKLM-x32\...\RemoteCaptureTask) (Version: 1.7.1.9 - Canon Inc.)
Canon Utilities ZoomBrowser EX (HKLM-x32\...\ZoomBrowser EX) (Version: 6.7.2.33 - Canon Inc.)
center (x32 Version: 3.30.0000.0000 - Eastman Kodak Company) Hidden
Chiavetta Internet MT191UP (HKLM-x32\...\{93D34EE3-99B3-4DB1-8B0A-0A657466F90D}) (Version: 1.0.0.1 - Onda Communication S.p.a.)
Click to Disc (HKLM-x32\...\{68A69CFF-130D-4CDE-AB0E-7374ECB144C8}) (Version: 1.2.52.09250 - Sony Corporation)
Click to Disc (x32 Version: 1.2.52.09250 - Sony Corporation) Hidden
Click to Disc Editor (HKLM-x32\...\InstallShield_{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}) (Version: 1.2.51 - Sony Corporation)
Click to Disc Editor (x32 Version: 1.2.51 - Sony Corporation) Hidden
Cloud System Booster (HKLM-x32\...\Cloud System Booster) (Version: 3.4 - Anvisoft)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dolby Control Center (HKLM\...\{D035FBF6-FDEF-487D-89CA-6F9DD07B783F}) (Version: 1.2.0702 - Dolby)
Driver Booster (HKLM-x32\...\Driver Booster_is1) (Version: 1.5 - IObit)
Dropbox (HKCU\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.)
EPS Viewer (HKLM-x32\...\{32E05824-A0AC-4DFE-B965-5F52C28FBE9F}_is1) (Version:  - IdeaMK)
Eye-Fi Center 3.4 (HKLM-x32\...\{7764F7B0-7225-4145-82B6-2AB4540D33A6}) (Version: 3.4.26 - Eye-Fi, Inc)
EZSniper Homelink (HKLM-x32\...\{77A1856E-57F6-4C1A-BC89-DBA4F4DF4BA3}) (Version: 1.5 - EZSniper)
FlipBuilder CHM to PDF (HKLM-x32\...\FlipBuilder CHM to PDF  freeware_is1) (Version:  - FlipBuilder Solution)
Google Drive (HKLM-x32\...\{C6640705-7479-4EE5-BC86-879F05F65E74}) (Version: 1.17.7290.4094 - Google, Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
HandBrake 0.9.9.1 (HKLM-x32\...\HandBrake) (Version: 0.9.9.1 - )
HDAUDIO SoftV92 Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200) (Version:  - )
HP Deskjet 3050A J611 series Basic Device Software (HKLM\...\{FB555BCF-9202-4886-9203-88C9A210D727}) (Version: 25.0.571.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Help (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Deskjet 3050A J611 series Product Improvement Study (HKLM\...\{710D4D91-1924-4A6B-8659-9CDE02DC7207}) (Version: 25.0.571.0 - Hewlett-Packard Co.)
I.R.I.S. Desktop Search (HKLM-x32\...\I.R.I.S. Desktop Search) (Version:  - I.R.I.S S.A)
iBackup Extractor (HKLM-x32\...\{29B35C59-53AA-4893-A233-79CEDF7D1494}) (Version: 1.4.0 - Wide Angle Software)
iCloud (HKLM\...\{CE97E4D3-9F91-4D72-8A29-ED9EA90E5A15}) (Version: 2.1.3.25 - Apple Inc.)
iExplorer 3.1.0.1 (HKLM-x32\...\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant LLC)
ImageMixer 3 SE Ver.3 (HKLM-x32\...\{3A95D49D-0076-4DB7-A91E-0E685DC6D6AD}) (Version: 3.01.012 - PIXELA)
Intel PROSet Wireless (Version:  - ) Hidden
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version:  - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{52A7C6A6-6B88-47D1-922E-9F8A7E089E6A}) (Version: 12.01.1000 - Intel® Corporation)
IObit Malware Fighter (HKLM-x32\...\IObit Malware Fighter_is1) (Version: 2.4 - IObit)
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 3.2.10.2466 - IObit)
iPhone Backup Extractor (HKLM-x32\...\iPhoneBackupExtractor) (Version: 4.0.4.0 - Reincubate Ltd)
iPhoneSMSExport (HKLM-x32\...\iPhoneSMSExport) (Version:  - )
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.27 - Irfan Skiljan)
iTunes (HKLM\...\{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}) (Version: 11.3.0.54 - Apple Inc.)
Java 7 Update 9 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417009FF}) (Version: 7.0.90 - Oracle)
Java 7 Update 9 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden
KODAK All-in-One Printer Software (HKLM-x32\...\{E0F274B7-592B-4669-8FB8-8D9825A09858}) (Version: 3.30.0.0 - Eastman Kodak Company)
KODAK Capture Pro Software - Trial Edition (x32 Version: 3.0.0 - Eastman Kodak Company) Hidden
Kodak Capture Software for iSeries scanners (HKLM-x32\...\XVCS6C) (Version:  - )
KODAK i1210/i1220 Scanner (HKLM-x32\...\KODAK i1210/i1220 Scanner) (Version: 3.33 - )
ksDIP (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Office 2000 SR-1 Professional (HKLM-x32\...\{00010409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.9327 - Microsoft Corporation)
Microsoft Office 2007 Primary Interop Assemblies (HKLM-x32\...\{50120000-1105-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50701 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.50706 - Microsoft Corporation) Hidden
Microsoft Works (HKLM-x32\...\{67E03279-F703-408F-B4BF-46B5FC8D70CD}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 32.0.3 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 32.0.3 (x86 en-US)) (Version: 32.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Music Transfer (HKLM-x32\...\{CE2121C6-C94D-4A73-8EA4-6943F33EE335}) (Version: 1.2.00.17290 - Sony Corporation)
OpenMG Secure Module 5.1.00 (HKLM-x32\...\InstallShield_{C1083DBC-C541-4E8C-91EA-D92397AB9A2C}) (Version: 5.1.00.05200 - Sony Corporation)
OpenMG Secure Module 5.1.00 (x32 Version: 5.1.00.05200 - Sony Corporation) Hidden
PamFax (HKLM-x32\...\{6432B21C-CA95-46CA-87D4-178CC2E58F84}_is1) (Version: 3.4.6.11 - Scendix Software GmbH)
PamFax Office Integration (x32 Version: 1.0.2 - Scendix Software GmbH) Hidden
PDFill PDF Editor with FREE Writer and FREE Tools (HKLM\...\{D1399216-81B2-457C-A0F7-73B9A2EF6902}) (Version: 9.0 - PlotSoft LLC)
Pegasus Mail HTML Renderer 2.4.7.2 (HKLM-x32\...\{A9F5E1E1-1281-4862-90B4-6CF8E6AF83CE}_is1) (Version:  - Micha's Midnight Manufacture)
Pinnacle Instant DVD Recorder (HKLM-x32\...\{C1212AE3-DBB9-4365-8473-F8ABC7B06BBB}) (Version: 2.6.0.118 - Pinnacle Systems)
Pinnacle Studio 12 (HKLM-x32\...\{D041EB9E-890A-4098-8F94-51DA194AC72A}) (Version: 12.1.3.6605 - Pinnacle Systems)
Pinnacle Video Driver (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.029 - Pinnacle Systems)
PIXELA AAC LC CODEC (HKLM-x32\...\PIXELA AAC LC CODEC) (Version: 1.1.0.1 - Canon Inc.)
PowerOffer 2.0 (HKLM-x32\...\{0B500125-92A7-40BF-ACF0-45A9221ADE21}_is1) (Version: 2.0 - )
PreReq (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
Primo (x32 Version: 1.00.0000 - Your Company Name) Hidden
QuickBooks Simple Start 2009 (HKLM-x32\...\{9A2F0810-3619-4E86-9072-973FBE1679C5}) (Version: 19.0.4001.703 - Intuit Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Rampant Logic Postscript Viewer 1.1 (HKLM-x32\...\{39C4C6DE-641B-483F-B875-2AEDF0FB85CA}_is1) (Version:  - Rampant Logic)
Rapport (x32 Version: 3.5.1307.109 - Trusteer) Hidden
Readiris Pro 11 Corporate Edition (HKLM-x32\...\{2B6E0003-45D0-4751-83AD-2D053A61B88E}) (Version: 11.00.4824 - I.R.I.S.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.)
Regi (Version: 1.00.0000 - InterVideo Inc.) Hidden
Roxio Central Audio (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Copy (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Core (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Data (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Tools (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Easy Media Creator 10 LJ (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.1 - Roxio)
Roxio Easy Media Creator Home (x32 Version: 10.1.296 - Roxio) Hidden
ScanWiz (HKLM-x32\...\ScanWiz) (Version: 2.50 - Softi Software)
Segoe UI (x32 Version: 15.4.2271.0615 - Microsoft Corp) Hidden
Setting Utility Series (HKLM-x32\...\{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}) (Version: 4.2.0.10150 - Sony Corporation)
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.2.10687 - Skype Technologies S.A.)
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Smart Defrag 3 (HKLM-x32\...\Smart Defrag 3_is1) (Version: 3.2 - IObit)
Sony Picture Utility (HKLM-x32\...\{D5068583-D569-468B-9755-5FBF5848F46F}) (Version: 3.3.01.09300 - Sony Corporation)
Sony Video Shared Library (HKLM-x32\...\{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}) (Version: 3.5.00 - Sony Corporation)
Spyder2express (HKLM-x32\...\Spyder2express) (Version:  - )
StreamFree version 1.0 (HKLM-x32\...\{91456E40-04E4-4B21-BA1C-8BC32646F2CA}_is1) (Version: 1.0 - Streammy.net)
SupportSoft Assisted Service (HKLM-x32\...\{5A3F6A80-7913-475E-8B96-477A952CFA43}) (Version: 15 - SupportSoft)
Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.0 - IObit)
System Requirements Lab for Intel (HKLM-x32\...\{CD41B576-4787-4D5C-95EE-24A4ABD89CD3}) (Version: 4.4.24.0 - Husdawg, LLC)
TD AMERITRADE StrategyDesk 3.1 (HKCU\...\{34E78C00-BBEE-4942-A5A2-91DCF3DCBF4C}) (Version: 3.1 - TD AMERITRADE)
TD AMERITRADE StrategyDesk 3.4_2 (C:\Users\MarcoAdm\AppData\Roaming\TD AMERITRADE\StrategyDesk) (HKCU\...\{0E791D90-FA4B-46CF-B0E6-F89C2F490843}) (Version: 3.4 - TD AMERITRADE)
The Rosetta Stone (HKLM-x32\...\The Rosetta Stone) (Version:  - )
thinkorswim from TD AMERITRADE (HKLM-x32\...\thinkorswim from TD AMERITRADE) (Version:  - TD AMERITRADE, Inc.)
Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1307.109 - Trusteer)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
VAIO Care (HKLM-x32\...\{36C5BBF0-E5BF-4DE1-B684-7E90B0C93FB5}) (Version: 3.0.0.0423 - Sony)
VAIO Content Folder Setting (HKLM-x32\...\{23825B69-36DF-4DAD-9CFD-118D11D80F16}) (Version: 2.1.0.08260 - Sony Corporation)
VAIO Content Folder Watcher (HKLM-x32\...\{327B75F0-92AF-420A-988F-FA596A218E0B}) (Version: 1.0.01.09030 - Sony Corporation)
VAIO Content Folder Watcher (x32 Version: 1.0.01.09030 - Sony Corporation) Hidden
VAIO Content Metadata Intelligent Analyzing Manager (HKLM-x32\...\{ECB5774A-A39B-4419-A7D3-92F49C0FCAB3}) (Version: 3.3.0.10012 - Sony Corporation)
VAIO Content Metadata Intelligent Analyzing Manager (x32 Version: 3.3.0.10012 - Sony Corporation) Hidden
VAIO Content Metadata Manager Setting (HKLM-x32\...\{EADE97A7-E7AA-43FD-A042-92A68E0187A6}) (Version: 3.3.0.09300 - Sony Corporation)
VAIO Content Metadata Manager Setting (x32 Version: 3.3.0.09300 - Sony Corporation) Hidden
VAIO Content Metadata XML Interface Library (HKLM-x32\...\{E3453B1B-C91B-4C48-B046-8DF635DD46F2}) (Version: 3.3.0.09182 - Sony Corporation)
VAIO Content Metadata XML Interface Library (x32 Version: 3.3.0.09182 - Sony Corporation) Hidden
VAIO Control Center (HKLM-x32\...\{72042FA6-5609-489F-A8EA-3C2DD650F667}) (Version: 3.2.0.09120 - Sony Corporation)
VAIO Data Restore Tool (HKLM-x32\...\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}) (Version: 1.0.04.01170 - Sony Corporation)
VAIO DVD Menu Data Basic (HKLM-x32\...\{596BED91-A1D8-4DF1-8CD1-1C777F7588AC}) (Version: 1.0.00.08130 - Sony Corporation)
VAIO Entertainment Platform (HKLM-x32\...\{6B1F20F2-6321-4669-A58C-33DF8E7517FF}) (Version: 3.2.3.10070 - Sony Corporation)
VAIO Entertainment Platform (x32 Version: 3.2.3.10070 - Sony Corporation) Hidden
VAIO Event Service (HKLM-x32\...\{C7477742-DDB4-43E5-AC8D-0259E1E661B1}) (Version: 4.2.0.10172 - Sony Corporation)
VAIO Help and Support (HKLM-x32\...\{D47FE987-EA3D-424B-9886-B752501D7CE7}) (Version: 7.00.1023.FW - Sony Corporation)
VAIO Launcher (HKLM-x32\...\{15D5C238-4C2E-4AEA-A66D-D6989A4C586B}) (Version: 2.2.0.09090 - Sony Corporation)
VAIO Media plus (HKLM-x32\...\{8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD}) (Version: 1.2.0.10230 - Sony Corporation)
VAIO Media plus (x32 Version: 1.2.0.10230 - Sony Corporation) Hidden
VAIO Media plus Opening Movie (HKLM-x32\...\{6BF03C88-C06A-48DC-B9A1-FE72B24E5FA9}) (Version: 1.2.0.09050 - Sony Corporation)
VAIO Movie Story (HKLM-x32\...\{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3}) (Version: 1.3.01.08060 - Sony Corporation)
VAIO Movie Story (x32 Version: 1.3.01.08060 - Sony Corporation) Hidden
VAIO Movie Story Template Data (HKLM-x32\...\{6FA8BA2C-052B-4072-B8E2-2302C268BE9E}) (Version: 1.3.00.06120 - Sony Corporation)
VAIO MusicBox (HKLM-x32\...\{4EA55D20-27FB-45D7-8726-147E8A5F6C62}) (Version: 2.1.1.09160 - Sony Corporation)
VAIO MusicBox Sample Music (HKLM-x32\...\{98FC7A64-774B-49B5-B046-4B4EBC053FA9}) (Version: 1.1.00.14140 - Sony Corporation)
VAIO My Memory Center (HKLM-x32\...\{72B5983C-80C7-4225-BA72-E92AE1D59C62}) (Version: 2.00.1029 - Sony)
VAIO OOBE and Welcome Center (HKLM-x32\...\{1B500D37-E7CF-480B-8054-8A563594EC4E}) (Version: 7.00.1022.US - Sony Corporation)
VAIO Original Function Setting (HKLM-x32\...\{A63E7492-A0BC-4BB9-89A7-352965222380}) (Version: 1.5.00.08150 - Sony Corporation)
VAIO Power Management (HKLM-x32\...\{5F5867F0-2D23-4338-A206-01A76C823924}) (Version: 3.2.0.10200 - Sony Corporation)
VAIO Presentation Support (HKLM-x32\...\{2018C019-30D9-4240-8C01-0865C10DCF5A}) (Version: 1.1.0.08250 - Sony Corporation)
VAIO Startup Assistant (HKLM-x32\...\{DFD0E9A9-F24A-492B-8975-8C938E32408F}) (Version: 4.00.1030 - Sony)
VAIO Survey (HKLM-x32\...\{34B37A74-125E-4406-87BA-E4BD3D097AE5}) (Version: 6.00.0722 - Sony Corporation)
VAIO Update 4 (HKLM-x32\...\{83CDA18E-0BF3-4ACA-872C-B4CDABF2360E}) (Version: 4.0.0.08280 - Sony Corporation)
VAIO Wallpaper Contents (HKLM-x32\...\{D60F97EC-EF06-4E1E-B0D1-C2CBABA62FA3}) (Version: 1.3.0.10310 - Sony Corporation)
VAIO Wireless Wizard (HKLM-x32\...\{BCED773C-99EE-48DD-8915-25733F69F0A8}) (Version: 2.00.1013 - Sony)
Virtual Account Numbers (HKLM-x32\...\{DE700910-58F7-4D2E-B7E6-3BA2DA1B6806}) (Version: 4.0.0.2248 - Citi)
Virtual Account Numbers (x32 Version: 1.0.6.0 - Citi) Hidden
VLC media player 2.1.1 (HKLM-x32\...\VLC media player) (Version: 2.1.1 - VideoLAN)
Vodafone Mobile Broadband Lite (HKLM-x32\...\{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}) (Version: 10.1.001.26030 - Vodafone)
Vuze (HKLM-x32\...\8461-7759-5462-8226) (Version: 5.3.0.0 - Azureus Software, Inc.)
Vuze Remote Toolbar for IE (HKLM-x32\...\IECT2504091) (Version: 6.19.0.18 - Vuze Remote) <==== ATTENTION
WebEx (HKCU\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
WIDCOMM Bluetooth Software 6.2.0.5800 (HKLM\...\{E464702F-5433-46EC-8F65-159276C0A54F}) (Version: 6.2.0.5800 - Broadcom Corporation)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4040.0 - Microsoft Corporation)
WinDVD BD for VAIO (HKLM-x32\...\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}) (Version: 8.0-B9.617 - InterVideo Inc.)
WinDVD BD for VAIO (x32 Version: 8.0-B9.617 - InterVideo Inc.) Hidden
Wisdom-soft ScreenHunter 6.0 Free (HKLM-x32\...\Wisdom-soft ScreenHunter 6.0 Free) (Version:  - Wisdom Software Inc.)
Xmarks for IE (HKLM-x32\...\{C56BBAC8-0DD2-4CE4-86E0-F2BDEABDD0CF}) (Version: 127.0.160 - Xmarks)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\MarcoAdm\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{738CD606-129D-45db-86D6-6C9739C750CA}\localserver32 -> C:\Program Files (x86)\Intuit\QuickBooks 2009\qbw32.exe (Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{8E590317-1329-11D1-B70B-00805F29CD16}\localserver32 -> C:\Program Files (x86)\Intuit\QuickBooks 2009\qbw32.exe (Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{FAC93D42-FFC2-11d1-9DEB-0008C7A08EBA}\localserver32 -> C:\Program Files (x86)\Intuit\QuickBooks 2009\qbw32.exe (Intuit Inc.)
CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MarcoAdm\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MarcoAdm\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MarcoAdm\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MarcoAdm\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MarcoAdm\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MarcoAdm\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MarcoAdm\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MarcoAdm\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 05:34 - 2012-09-30 00:57 - 00000815 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {060248CA-77FF-4763-A21B-C6045EFD30C0} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-20] (Microsoft Corporation)
Task: {09A73C34-67D3-4CBE-8B3B-0AAF4665BF5C} - \3317973412 No Task File <==== ATTENTION
Task: {0A3728E9-CA29-4C78-938F-48757519B047} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-02-09] (Google Inc.)
Task: {0A532475-EED2-4697-AC39-84B312331EA8} - \3571684936 No Task File <==== ATTENTION
Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {13223012-D97F-4A0C-9355-D2CE7CB72C79} - System32\Tasks\{0E6E1FE2-D011-4701-B643-333F59F4BE23} => Firefox.exe http://ui.skype.com/ui/0/5.0.0.156.217/en/abandoninstall?page=tsChrome&installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {13A118FD-1C23-4824-9B2C-02E9F07A97F6} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-05-06] (IObit)
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {1A4B5E64-428A-4F0E-AD22-7EEE77FCA626} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-02-09] (Google Inc.)
Task: {1E67769F-969F-4D33-B3A8-43A7FE74B1ED} - System32\Tasks\Driver Booster SkipUAC (MarcoAdm) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2014-08-06] (IObit)
Task: {24AFC1A3-2E42-4F90-BAED-2F435DE39F40} - System32\Tasks\{897DAE3D-6DA8-4F43-91F2-BC1E96A31D56} => Firefox.exe http://ui.skype.com/ui/0/5.5.0.119.217/en/abandoninstall?page=tsChrome&installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-20] (Microsoft Corporation)
Task: {2CE9EA3C-CCFA-40EB-879B-21E8AFCCE417} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2014-08-01] (IObit)
Task: {2E0780AB-0A4C-44E6-9C96-61A1471745E5} - System32\Tasks\HPCustParticipation HP Deskjet 3050A J611 series => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPCustPartic.exe [2011-06-08] (Hewlett-Packard Co.)
Task: {36B96A32-2368-4D87-8018-7BCEA8006738} - System32\Tasks\ASC7_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe [2014-05-06] (IObit)
Task: {39ED30B1-778B-47C8-BD64-F4E66483D71F} - System32\Tasks\SONY\VAIO Wallpaper Setting Tool\VAIO Wallpaper Setting Tool => C:\Program Files (x86)\Sony\VAIO Wallpaper Setting Tool\VWSet.exe [2008-06-27] (Sony Corporation)
Task: {3EF12406-33CF-49AF-90FE-F0F379DD7335} - System32\Tasks\SmartDefrag3_Startup => C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe [2014-07-02] (IObit)
Task: {440F8681-07BF-43D0-B43F-954C74802C0A} - System32\Tasks\{A2E22F8B-C51A-48C1-AA0F-429EA91D7DE3} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-02-10] (Skype Technologies S.A.)
Task: {48D572FE-81C9-405B-92DA-AD3CC5DB6F60} - System32\Tasks\Microsoft\Windows\RestartManager\{BB219F1A-5B5E-478f-9748-64B36FC902EE} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation)
Task: {525FBAB3-402C-49F8-A3BA-786D663B627A} - System32\Tasks\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2009-04-29] (Sony Electronics, Inc.)
Task: {5B4710E9-A4BF-4746-8B38-68EF93339466} - System32\Tasks\SmartDefrag3_Update => C:\Program Files (x86)\IObit\Smart Defrag 3\AutoUpdate.exe [2014-07-03] (IObit)
Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {8FE20A46-31A2-41EA-BE78-BC4E4B4DBC46} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09] (Adobe Systems Incorporated)
Task: {94C1CEED-29B2-492B-B61B-A99C89DFC581} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2014-08-01] (IObit)
Task: {BB33618C-785C-4294-9BAE-268588F20D7C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {CFCEF2EB-DA61-4153-96B6-AB83E4941E91} - System32\Tasks\thpm4895375420692929156 => \\.\globalroot\Device\HarddiskVolume2\Users\MarcoAdm\AppData\Local\Temp\thpm4895375420692929156.tmp <==== ATTENTION
Task: {E3821242-ACE8-49ED-938D-A5040EB7254B} - System32\Tasks\ASC7_SkipUac_MarcoAdm => C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe [2014-05-04] (IObit)
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-20] ()
Task: {E9FBECD8-090B-421A-9360-ED94E212EF8B} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {F1D3DAA2-D4DC-45CA-A154-3252C0D354B8} - System32\Tasks\SONY\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe [2008-08-28] (Sony Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Driver Booster SkipUAC (MarcoAdm).job => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Uninstaller_SkipUac_Administrator.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe

==================== Loaded Modules (whitelisted) =============

2013-10-31 13:47 - 2013-10-31 13:47 - 00954696 _____ () C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll
2014-10-05 13:35 - 2014-10-05 13:35 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
1999-10-20 13:50 - 1999-10-20 13:50 - 00057403 _____ () C:\Program Files (x86)\Microsoft Office\Office\BLNMGRPS.DLL
1999-02-01 17:39 - 1999-02-01 17:39 - 00073785 _____ () C:\Program Files (x86)\Microsoft Office\Office\BLNMGR.DLL

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:E1268B2C

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

HKU\S-1-5-21-1683370733-2581893643-414232939-1001\Software\Classes\.exe:  =>  <===== ATTENTION!

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Aventail VPN Connection.lnk => C:\Windows\pss\Aventail VPN Connection.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ImageMixer 3 SE Camera Monitor Ver.3.lnk => C:\Windows\pss\ImageMixer 3 SE Camera Monitor Ver.3.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Network Server.lnk => C:\Windows\pss\Network Server.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk => C:\Windows\pss\QuickBooks Update Agent.lnk.CommonStartup
MSCONFIG\startupreg: Citi Virtual Account Numbers => C:\PROGRA~2\VIRTUA~1\CitiVAN.exe /lang=en_RG /dontopenmycards
MSCONFIG\startupreg: Intuit SyncManager => C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup
MSCONFIG\startupreg: IObit Malware Fighter => "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
MSCONFIG\startupreg: PosService =>
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RtHDVCpl => RAVCpl64.exe
MSCONFIG\startupreg: Skytel => Skytel.exe
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: VAIORegistration => "C:\Program Files\Sony\First Experience\WelcomeLauncher.exe"
MSCONFIG\startupreg: VAIOSurvey => "C:\Program Files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-1683370733-2581893643-414232939-500 - Administrator - Enabled) => C:\Users\Administrator
Guest (S-1-5-21-1683370733-2581893643-414232939-501 - Limited - Disabled) => C:\Users\Guest
MarcoAdm (S-1-5-21-1683370733-2581893643-414232939-1001 - Administrator - Enabled) => C:\Users\MarcoAdm

==================== Faulty Device Manager Devices =============

Name: Realtek High Definition Audio
Description: Realtek High Definition Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: IntcAzAudAddService
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/10/2014 02:56:29 PM) (Source: LoadPerf) (EventID: 3001) (User: )
Description: 2763816

Error: (10/10/2014 02:56:26 PM) (Source: LoadPerf) (EventID: 3011) (User: )
Description: WmiApRplWmiApRpl8

Error: (10/10/2014 02:56:26 PM) (Source: LoadPerf) (EventID: 3001) (User: )
Description: 2763816

Error: (10/10/2014 02:52:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/10/2014 02:52:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/10/2014 02:52:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/10/2014 02:52:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/10/2014 02:52:24 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/10/2014 02:52:24 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/10/2014 02:52:24 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.


System errors:
=============
Error: (10/10/2014 03:49:27 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084wuauserv{E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error: (10/10/2014 03:01:02 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 0.0.0.0

    Update Source: %NT AUTHORITY51

    Update Stage: 4.5.0216.00

    Source Path: 4.5.0216.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\NETWORK SERVICE

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (10/10/2014 03:01:01 PM) (Source: Microsoft Antimalware) (EventID: 2003) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update the engine.

    New Engine Version:

    Previous Engine Version: 2.1.10903.0

    Engine Type: %NT AUTHORITY604

    User: NT AUTHORITY\NETWORK SERVICE

    Error Code: %NT AUTHORITY601

    Error description: %NT AUTHORITY602

Error: (10/10/2014 03:01:01 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 112.5.0.0

    Update Source: %NT AUTHORITY15

    Update Stage: 4.5.0216.00

    Source Path: 4.5.0216.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\NETWORK SERVICE

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (10/10/2014 03:00:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.185.2162.0

    Update Source: %NT AUTHORITY59

    Update Stage: 4.5.0216.00

    Source Path: 4.5.0216.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (10/10/2014 02:52:20 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: PnP-X IP Bus EnumeratorFunction Discovery Provider Host%%1068

Error: (10/10/2014 02:51:53 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (10/10/2014 02:51:29 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: DMICall
MpFilter
spldr
Wanarpv6

Error: (10/10/2014 02:51:29 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Microsoft Network Inspection SystemMicrosoft Malware Protection Driver%%31

Error: (10/10/2014 02:51:29 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Computer BrowserServer%%1068


Microsoft Office Sessions:
=========================
Error: (10/10/2014 02:56:29 PM) (Source: LoadPerf) (EventID: 3001) (User: )
Description: 2763816

Error: (10/10/2014 02:56:26 PM) (Source: LoadPerf) (EventID: 3011) (User: )
Description: WmiApRplWmiApRpl8

Error: (10/10/2014 02:56:26 PM) (Source: LoadPerf) (EventID: 3001) (User: )
Description: 2763816

Error: (10/10/2014 02:52:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe

Error: (10/10/2014 02:52:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe

Error: (10/10/2014 02:52:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe

Error: (10/10/2014 02:52:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe

Error: (10/10/2014 02:52:24 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe

Error: (10/10/2014 02:52:24 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe

Error: (10/10/2014 02:52:24 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksCal.exe


CodeIntegrity Errors:
===================================
  Date: 2014-10-10 16:19:02.748
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-10 16:19:02.545
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-10 16:19:02.342
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-10 16:19:02.124
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-10 16:19:01.859
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-10 16:19:01.609
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-10 16:19:01.406
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-10 16:19:01.203
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-10 16:19:00.767
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\RapportKE64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-10 16:19:00.517
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\RapportKE64.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel® Core2 Duo CPU P8600 @ 2.40GHz
Percentage of memory in use: 41%
Total physical RAM: 3934.11 MB
Available physical RAM: 2311.68 MB
Total Pagefile: 8091.48 MB
Available Pagefile: 6601.03 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:222.39 GB) (Free:52.51 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.9 GB) (Disk ID: 808E8887)
Partition 1: (Not Active) - (Size=10.5 GB) - (Type=27)
Partition 2: (Active) - (Size=222.4 GB) - (Type=07 NTFS)

==================== End Of Log ============================

 

 

sfcdetails.txt

ntbtlog.txt

mbam_log_10102014.txt

FRST.txt

Addition.txt

Link to post
Share on other sites

  • Root Admin

Hello and :welcome:

Please read the following and post back the logs when ready and we'll see about getting you cleaned up.

General P2P/Piracy Warning:

If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the policy on Piracy.

Before we proceed further, please read all of the following instructions carefully.

If there is anything that you do not understand kindly ask before proceeding.

If needed please print out these instructions.

  • Please do not post logs using CODE, QUOTE, or FONT tags. Just paste them as direct text.
  • If the log is too large then you can use attachments by clicking on the More Reply Options button.
  • Please enable your system to show hidden files: How to see hidden files in Windows
  • Make sure you're subscribed to this topic:
    • Click on the Follow This Topic Button (at the top right of this page), make sure that the Receive notification box is checked and that it is set to Instantly
  • Removing malware can be unpredictable...It is unlikely but things can go very wrong! Please make sure you Backup all files that cannot be replaced if something were to happen. You can copy them to a CD/DVD, external drive or a pen drive
  • Please don't run any other scans, download, install or uninstall any programs unless requested by me while I'm working with you.
  • The removal of malware is not instantaneous, please be patient. Often we are also on a different Time Zone.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of the issue.
  • You can check here if you're not sure if your computer is 32-bit or 64-bit
  • Please disable your antivirus while running any requested scanners so that they do not interfere with the scanners.
  • When we are done, I'll give you instructions on how to cleanup all the tools and logs
  • Please stick with me until I give you the "all clear" and Please don't waste my time by leaving before that.
  • Your topic will be closed if you haven't replied within 3 days
  • (If I have not responded within 24 hours, please send me a Private Message as a reminder)
STEP 0

RKill is a program that was developed at BleepingComputer.com that attempts to terminate known malware processes

so that your normal security software can then run and clean your computer of infections.

When RKill runs it will kill malware processes and then removes incorrect executable associations and fixes policies

that stop us from using certain tools. When finished it will display a log file that shows the processes that were

terminated while the program was running.

As RKill only terminates a program's running process, and does not delete any files, after running it you should not reboot

your computer as any malware processes that are configured to start automatically will just be started again.

Instead, after running RKill you should immediately scan your computer using the requested scans I've included.

Please download Rkill by Grinler from one of the links below and save it to your desktop.

Link 1

Link 2

  • On Windows XP double-click on the Rkill desktop icon to run the tool.
  • On Windows Vista/Windows 7 or 8, right-click on the Rkill desktop icon and select Run As Administrator
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • If the tool does not run from any of the links provided, please let me know.
  • Do not reboot the computer, you will need to run the application again.
STEP 01

Backup the Registry:

Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.

  • Please download ERUNT from one of the following links: Link1 | Link2 | Link3
  • ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.
  • Double click on erunt-setup.exe to Install ERUNT by following the prompts.
  • NOTE: Do not choose to allow ERUNT to add an Entry to the Startup folder. Click NO.
  • Start ERUNT either by double clicking on the desktop icon or choosing to start the program at the end of the setup process.
  • Choose a location for the backup.
    • Note: the default location is C:\Windows\ERDNT which is acceptable.
  • Make sure that at least the first two check boxes are selected.
  • Click on OK
  • Then click on YES to create the folder.
  • Note: if it is necessary to restore the registry, open the backup folder and start ERDNT.exe
STEP 02

Please run a Threat Scan with MBAM. If you're unable to run or complete the scan as shown below please see the following: MBAM Clean Removal Process 2x

When reinstalling the program please try the latest version.

Right click and choose "Run as administrator" to open Malwarebytes Anti-Malware and from the Dashboard please Check for Updates by clicking the Update Now... link

Open up Malwarebytes > Settings > Detection and Protection > Enable Scan for rootkit and Under Non Malware Protection set both PUP and PUM to Treat detections as malware.

Click on the SCAN button and run a Threat Scan with Malwarebytes Anti-Malware by clicking the Scan Now>> button.

Once completed please click on the History > Application Logs and find your scan log and open it and then click on the "copy to clipboard" button and post back the results on your next reply.

STEP 03

Please download RogueKiller and save it to your desktop.

You can check here if you're not sure if your computer is 32-bit or 64-bit

  • RogueKiller 32-bit | RogueKiller 64-bit
  • Quit all running programs.
  • For Windows XP, double-click to start.
  • For Vista,Windows 7/8, Right-click on the program and select Run as Administrator to start and when prompted allow it to run.
  • Read and accept the EULA (End User Licene Agreement)
  • Click Scan to scan the system.
  • When the scan completes Close the program > Don't Fix anything!
  • Don't run any other options, they're not all bad!!
  • Post back the report which should be located on your desktop.
Thank you
Link to post
Share on other sites

Hello sir,

Thanks for the welcome and the procedure to follow.

Unfortunately, I can't complete the whole process. When I try to run RogueKiller, the computer crashes after a couple of minutes and I get the BSOD. I tried to attach the generated dump file but the uploader did not allow me to.

 

Here are the results of the previous steps

STEP 0:

Attached is the rkill log

Rkill 2.6.8 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 10/15/2014 11:18:10 PM in x64 mode. (Safe Mode)
Windows Version: Windows Vista Home Premium Service Pack 2

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
  * HKCU\SOFTWARE\Classes\.exe "@" exists and is set to !
  * HKCU\SOFTWARE\Classes\.exe has been deleted!

Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * COM+ Event System (EventSystem) is not Running.
   Startup Type set to: Automatic

 * Security Center (wscsvc) is not Running.
   Startup Type set to: Automatic (Delayed Start)

 * Windows Update (wuauserv) is not Running.
   Startup Type set to: Automatic (Delayed Start)

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * HOSTS file entries found:

  127.0.0.1       localhost
  ::1             localhost

Program finished at: 10/15/2014 11:24:45 PM
Execution time: 0 hours(s), 6 minute(s), and 34 seconds(s)

STEP 02

Attached is the MBAM log. There are entries related to Chrome and Vuze even though these programs have been uninstalled in the past

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 10/15/2014
Scan Time: 11:34:51 PM
Logfile:
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.10.16.02
Rootkit Database: v2014.10.15.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows Vista Service Pack 2
CPU: x64
File System: NTFS
User: MarcoAdm

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 418804
Time Elapsed: 23 min, 30 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 6
PUP.Optional.VuzeRemoteTB.A, C:\Users\MarcoAdm\AppData\Local\Temp\Vuze_Remote, , [5ea1e034e8947db937849c742ad98d73],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk, , [946b8e863448f83e09b76fa1ea19ec14],
PUP.Optional.Conduit.A, C:\ProgramData\Tbccint\Multi\CT2504091, , [d22d59bb7ffd91a5923236da8a7902fe],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ojpijjmpahflnipadmlpgbjmagmjchkk_0, , [4ab5e62e55274cea6066be522ad98e72],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\tbccint\Chrome\CT2504091, , [d926977d512bb383fbce3dd306fd916f],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\tbccint\CT2504091, , [d9269c78fc80d85e4b8034dcfa098c74],

Files: 18
PUP.Optional.Babylon.A, C:\Program Files (x86)\EPSViewer\MyBabylonTB.exe, , [02fd83915b219b9b8b6e43db7c8418e8],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ojpijjmpahflnipadmlpgbjmagmjchkk_0.localstorage, , [827d779db8c41224cfa5503a5ba9867a],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ojpijjmpahflnipadmlpgbjmagmjchkk_0.localstorage-journal, , [32cd53c12755ae88e193c6c49173f50b],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\000003.log, , [946b8e863448f83e09b76fa1ea19ec14],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\CURRENT, , [946b8e863448f83e09b76fa1ea19ec14],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\LOCK, , [946b8e863448f83e09b76fa1ea19ec14],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\LOG, , [946b8e863448f83e09b76fa1ea19ec14],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\MANIFEST-000002, , [946b8e863448f83e09b76fa1ea19ec14],
PUP.Optional.Conduit.A, C:\ProgramData\Tbccint\Multi\CT2504091\configutaion.json, , [d22d59bb7ffd91a5923236da8a7902fe],
PUP.Optional.Conduit.A, C:\ProgramData\Tbccint\Multi\CT2504091\SetupIcon.ico, , [d22d59bb7ffd91a5923236da8a7902fe],
PUP.Optional.Conduit.A, C:\ProgramData\Tbccint\Multi\CT2504091\UninstallerUI.exe, , [d22d59bb7ffd91a5923236da8a7902fe],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ojpijjmpahflnipadmlpgbjmagmjchkk_0\7, , [4ab5e62e55274cea6066be522ad98e72],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\tbccint\Chrome\CT2504091\CHUninstaller.exe, , [d926977d512bb383fbce3dd306fd916f],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\tbccint\Chrome\CT2504091\configutaion.json, , [d926977d512bb383fbce3dd306fd916f],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\tbccint\Chrome\CT2504091\Uninstaller.ico, , [d926977d512bb383fbce3dd306fd916f],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\tbccint\Chrome\CT2504091\UninstallerUI.exe, , [d926977d512bb383fbce3dd306fd916f],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\tbccint\CT2504091\Vuze_RemoteAutoUpdateHelper.exe, , [d9269c78fc80d85e4b8034dcfa098c74],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\tbccint\CT2504091\Vuze_RemoteToolbarHelper.exe, , [d9269c78fc80d85e4b8034dcfa098c74],

Physical Sectors: 0
(No malicious items detected)


(end)

 

Reagards,

Marco

Link to post
Share on other sites

  • Root Admin

No problem. These infections dig in like a tick on a dog sometimes and rarely uninstall well when you uninstall them.

Please go ahead and run through the following steps and post back the logs when ready.

STEP 04

Please download Junkware Removal Tool to your desktop.

  • Shutdown your antivirus to avoid any conflicts.
  • Right click over JRT.exe and select Run as administrator on Windows Vista or Windows 7, double-click on XP.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next reply message
  • When completed make sure to re-enable your antivirus
STEP 05

Lets clean out any adware now: (this will require a reboot so save all your work)

Please download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.

    Vista/Windows 7/8 users right-click and select Run As Administrator

  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you may want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review. (all items found are adware/spyware/foistware)
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted:
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.
STEP 06

Please open Malwarebytes Anti-Malware and from the Dashboard please Check for Updates by clicking the Update Now... link

Open up Malwarebytes > Settings > Detection and Protection > Enable Scan for rootkits, Under Non Malware Protection set both PUP and PUM to Treat detections as malware.

Click on the SCAN button and run a Threat Scan with Malwarebytes Anti-Malware by clicking the Scan Now>> button. Remove any threats found

Once completed please click on the History > Application Logs and find your scan log and open it and then click on the "copy to clipboard" button and post back the results on your next reply.

STEP 07

button_eos.gif

Please go here to run the online antivirus scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file....
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
STEP 08

Please download the Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. You can check here if you're not sure if your computer is 32-bit or 64-bit

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press the Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it also makes another log (Addition.txt). Please attach it to your reply as well.
Link to post
Share on other sites

Thanks for providing these new steps.

Before reporting the results, I have a question. In step 02 you did not ask me to fix (quarantine) the malware found by

MBAM. Why is that, is it normally not a safe thing to do? When I used MBAM in the PAST, I always quarantined the results,

was it a wrong thing to do?

Here are the results of the new steps. I divided them in two posts because a single post was too long to be uploaded:

STEP 04

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.14.2014:1)
OS: Windows Vista Home Premium x64
Ran by MarcoAdm on Thu 10/16/2014 at 20:43:11.94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{11111111-1111-1111-1111-110011441193}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111

-1111-1111-1111-110011441193}



~~~ Files

Successfully deleted: [File] C:\Windows\Tasks\Driver Booster SkipUAC (MarcoAdm).job



~~~ Folders

Successfully deleted: [Folder] "C:\Users\MarcoAdm\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\MarcoAdm\appdata\local\cre"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{00029C5B-8A15-4D40-8099-B0DFCEAEE296}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{002F81E2-18E6-4D24-8D03-11E5B86BC35B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{013F8FC5-0E82-461A-B003-D53B2E99C995}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{01B11FDA-4005-4E40-8641-4B7CC8D6CF7D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0282E7DF-6A32-4325-A421-5B2F003A5416}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0304B691-E029-43AB-AD62-ED96AA3D490F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{04CC4009-BDC7-4317-896C-A04A6A318E26}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0518D901-7F19-40D1-95CE-53E9A4043607}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{056EB017-09D6-4CC8-84EA-67C278D647FA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{059FC61C-7B1D-4502-B7A3-F8BD0FDB81FE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{05C202B2-F929-40C1-9B2F-B026ED5F745C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{05D0E3CE-E1F7-4350-8626-A11DD7AA2C10}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{07069737-D03E-49A8-B736-AB376ED2F7F8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{07844E5D-48C1-42BC-B544-E9FDEF30A7B0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{078C48A5-1FCC-4F37-9FBB-28AEC79EBDF9}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{078FE104-4424-49EA-8BEB-05B19385E505}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{088CEF51-F7C0-4128-BEE7-CDA736DFF083}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{08E25375-61F5-45A4-95FF-AB6C3BBE3A35}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{09E718A5-19C9-46F3-8005-750D9B4ACE2E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0BBFCCF7-D376-4838-B983-2534C35C226E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0BE8A5FB-7311-4479-A8F4-2B10B2F11344}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0C045863-819C-48DA-8168-183493DCCCF8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0D067B0D-F326-4A3D-864C-82618E54444E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0D72F882-D4AD-40FE-844A-79C60F78C915}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0DA71E2D-1DBA-4708-B71F-8C2388F2AA3B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0DD3C0AC-85F9-482B-9CE2-08D8E9D2C071}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0DD79B87-DE33-49EA-AEE9-87487370046F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0E69D7D6-B4FA-4995-93B6-E769F0D761EC}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0EB5C806-81C6-490B-AC7B-2FD57443A434}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{0F7FBFE0-28CD-430F-9CA7-234E5F94A1BE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{103A118B-0863-4BB6-ABF7-91B9FC983B64}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{113E379F-A73A-42C7-8128-B94887D7579C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{114E858C-B572-44EA-AE17-4561C9F5E495}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{12025C2B-1D94-405E-8409-5F9FAA782C04}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{12774116-4EAF-4CAE-96C5-B6015EE75171}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{12E8F2AF-C572-4C4C-85E4-98D635665C9D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{13E7FB4C-97B7-4760-98DD-6E6E47D421CD}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{146C6112-7D19-442B-83FB-C5F6ECD7B124}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1489B27F-398A-481E-B047-9E2116DF07A3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{151727B4-C80A-4BCF-8A86-B08AE88B11F4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{157EAC71-9975-44E7-A1CF-A1D4EB9E3773}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{15C92912-5EFB-4D30-A85C-76EB52058433}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{15D91E14-B634-448E-893B-D5E9F1D5A57D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1923B08A-846F-4CB6-A6C0-1E45E8540A07}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{194AFCDE-76F8-45C6-AA30-B06A40CCD3E5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1A71C385-3ACC-4778-A824-D20E71FAF1D6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1B02E0CE-7126-4390-8EF7-9CEC08B31508}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1C2A4A68-6530-4A4F-AD4E-9AA86F30E9C5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1C4A71DB-47C7-486E-8FD3-1DCE77830190}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1D15B844-9224-43B1-84D9-6D6E02649BF9}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1D8B1F3B-C939-4C2F-9082-F5F6A557499A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1DAC2F28-168A-48F2-BE8B-B06380943B3F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1DCC7F44-E88B-4F41-89C2-89774F54786F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1DD3AEDD-4128-465C-A9AB-0839F0406FF8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1E1041B9-B733-440E-84DF-E428362F42C0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1E4C779A-4F00-43CA-AFA1-FCBD812B82F4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1E8516E4-8167-443C-BE60-59E12A82CA29}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1E968D83-5200-40B3-9789-81B0BE753D7C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1F6C09DC-38AA-4127-AD1D-C25C48C67B00}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{1F97B540-8D1B-469B-8594-F3D6387F420A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2120605F-9637-4230-9712-DC1F431747CD}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{21579977-2442-427A-9467-C83B0944F831}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{21C36505-DF22-412F-8941-A3E440C3AE37}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{21CEC2D3-37BE-4056-93D0-770D9224EB8B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{21EAB0C0-0CC2-4E57-B45C-DFD1BC1DE821}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{229A4653-800C-4325-BA96-CA249D7EB873}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{22FD7D55-822D-485F-A8A8-94237AA4B74F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{231F67B5-24E6-415F-87DE-1161A8E8D611}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{232B244A-3BC5-49EB-86DE-47CD98B13079}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2373AB79-3CF7-44B0-8579-C4A8A7A195B4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{249EB633-BAD1-4108-84E9-47EC19FE4481}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{253C0F79-83F0-4E05-B099-9AC1E0947EDE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{25DEDE04-1D20-4E64-9208-1E90296557A8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{261D2065-1302-4CF3-9EE0-715BE16A8DD4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2646F619-A963-436F-B4B0-F3B494BE6EFF}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{266ED8AD-9FF0-4432-89FF-E2B9EE453769}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{26D2654A-A7F3-46D3-8FD7-ABCB2F70DB96}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{270467AB-5D05-42F4-AEE0-D3DCEA2BA788}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{27F59217-8D40-48F1-B984-CB712465CCCF}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{281589DD-A32A-4F01-B4B6-7F8C2A8FA303}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2844A872-E1BA-46E2-939C-ADA85A0AB8C6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{29989F8B-7D78-4AB3-A328-892A16F46D23}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{29C9F9C3-7FB6-463A-85FF-ECB2DB7DCA2E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2AD479D6-343F-47BF-9CC2-69B59054A3C7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2B6204E3-40A4-4D99-94D4-F85E869EF057}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2C03590F-1440-4F47-80E6-5BB9140E4C80}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2C66C436-11AF-4702-B20E-29406205C13B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2CFACCD1-F160-4860-B830-E01BAF38314F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2E41A55C-EE2A-47FB-922D-DCF8B3BABC70}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2E8CD2C7-7A17-4B6C-BB1C-2139AD6FCE79}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2EA63870-2680-4906-B556-C2A3794F0623}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{2EF83168-EB36-483E-AC75-90D0F186F87B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{30507CFF-21A4-46E8-8E6E-474932D7800F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{30D672C7-FFD1-4DC8-B74A-C3F1BEF14A06}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{313C4869-C39C-4B21-9ED9-C2D532CF48E5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{31615712-0A41-45C5-8F68-21256FD302D3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3262AFA9-D498-4B6B-A5A3-A3A9E9B080D3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{327925AC-D7D0-4322-AFF3-06E84B40181E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{32DD1236-2970-4061-A403-608D0930D6A5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3373F6EE-4EC3-4C81-BE2A-5484167376AF}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{33ACA570-4B9E-41E8-BE69-41606B06867A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{33CD1314-6473-446B-A45C-E88C9C7DD560}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{34D5F21E-919E-4D2D-B3C3-B2EA71A986BC}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{37FC630C-EE42-4CC8-82FF-B25746FC0BD9}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{380B70D3-7B14-4667-BEFB-5C32F8E74489}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{38E76167-9AF4-4336-8B41-FEFFF6738270}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{391CBDC2-A743-408A-8D04-822E675C35E2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{394FB8FB-F40C-45BB-A6F2-2B826B429EB8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3A4D42DD-526E-4CC7-8063-147E73DE978B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3A665C32-18D3-4AB7-8767-B5E927F92C38}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3A92FCF7-210F-46F4-B2A6-E95429162F6E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3A986438-6512-4173-9A85-3ACA9E26FC01}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3BC68678-BC05-4BA3-B604-C25FA931F04A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3BD068F9-D400-4E0F-A305-BB3730E391C1}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3C67DE74-FBCD-4CCC-A862-7C87A54EB7DD}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3D94A394-15A1-4A3F-92E2-0ECD5C6DFE57}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3DAF6CBE-C082-40CA-9550-788433226015}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3DB3F8DF-2C22-4BAB-B9E7-7748587C7A8A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3DEE7443-61BF-460F-A41B-305A72FCA1E3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3E813E0D-FE3E-4E8D-9FED-9BDDB40A37D2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3EAB4AF7-1E41-4635-8A3C-0C827E4B4F30}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3F164169-CB5D-4ED8-88EB-108969EBA73F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{3FAE233B-4AFB-4738-872F-7711CE9EC7AA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4046C053-1793-4289-83F0-9FA7074F084F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{405B03FC-FD24-424D-AFA6-F7809AD31B88}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{40E1EC7D-7186-4D27-ACC3-FF2412834306}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{411AFB51-673C-4E84-9916-335340367BEE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{41B0020C-AB97-4AEE-BEC8-AC00FDE3AFB7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{41E481B3-D02A-4E34-B2D5-76B43A151DC5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{425620F8-907C-4E2C-8545-AD94843EAFBA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4341341C-9D84-4BC5-B42C-AB7AAD6467C7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{434C9756-0D48-4567-AAF9-CDD44944BF74}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{43544A29-9288-4EEB-8A68-3CF278C49C09}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4395590F-97CD-4909-924F-6B51A92DA526}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{43B8992C-245D-47AA-BACE-E14058EC3351}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{43BA3C7D-2853-48D5-9CB1-74E9AAE09B95}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{43FB3E78-8682-41D2-883A-831E3AFB5C9F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4471FE71-68C6-4EA0-A85B-BCDC0D14A02D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{44A21628-A339-4420-9561-5A53240A522A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{44A96773-A0AA-4C5C-ACB2-9F1EDCB7836B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{44AB71A8-5402-4418-9DF5-B0E556FE8820}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{44C8F152-1D69-41F2-84F5-1154518AB0AE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{44F4BCF9-B34C-4F2D-9EC5-C7F267A21F8A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{45516CB4-73A8-4DF5-86A4-04B52829636B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{45B9C69E-D2DA-4889-A02F-928BE2004A39}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{45C95DF9-CA1A-480E-9200-33F35C999F5B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{45DE75B5-4BBE-48D4-BD0B-321655F3DACB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{460F4FFE-31F0-41E2-9A23-653DE442E9D5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4655608F-703E-4EC5-8D2B-DDB96BC74EFD}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{46D65EEA-29E7-4606-9791-E815CBF3CE81}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{47918725-5657-47EB-95AB-0A248A9E1BD2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{47FBA746-2C6C-4828-96F4-98652F8E62D0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4889025B-7BEA-4BC5-A330-47E66A54BC29}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{48A3EE4C-A5E5-455C-A92C-B6C0A47B542F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{48C49E00-D607-4B0A-ACBF-4CDD5AFE0E9B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{491746A4-DE38-4741-B11B-096C909E5E30}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{492F8AEC-FDA7-4A73-8BC4-6EB94E3E147D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{49485ED2-B10C-41D5-A21D-25213C1679C5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4A36B0B2-6FAB-429E-937C-DBF9A4F5D46C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4B144E63-0140-4862-9E55-C7CA8F69574D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4B41E7EB-8508-4D41-851C-99DB65D0A009}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4BF3B363-4826-45E6-911B-57ECFE5986D8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4CB376D2-19FA-4391-92AC-458F9DE94811}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4CC22E07-F79E-4270-BE32-0669BD396B43}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4D3E0607-7445-4F0A-92EC-9379A592270F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4D6C5500-EBBD-4C9C-A777-B6F0E71E9937}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{4F1F1691-920F-45A1-B4AB-ED84FE887AF0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{517158E7-03F9-4E6F-9D8D-B12D5AB4216A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5187E71F-668C-40EB-B117-12F6513A7632}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{525073DA-E9C7-4839-84BD-812C0521BA16}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{52705135-5584-452C-A721-47DD9CBA6F35}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5363DB94-8B3E-4783-ACD5-B625B0F573CF}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{53DECC93-52E2-453A-ACBA-C69DF48551B2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{53F0C4AD-67E5-49B5-9517-971FAA68E7AD}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{55891E25-06EE-4CD0-9AA3-AD50E919EB57}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{55A5E96D-F6FE-433B-96E2-6FFE85A1F2DF}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{55DD2FC5-0DE7-421B-B76C-E82D8FA99EB5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{58A7BBE5-CEE1-48A4-A98A-2CA1716204FB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{58C4129E-A471-4A2A-B6AC-D504AAE98BE3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{58F71789-8823-4312-98C4-9E9D1725BD15}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{59881244-B217-4D28-8698-2806D8F81C99}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{59C1C399-DA5C-43FC-94C3-B04265C84726}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5A6D116D-BF5A-4B8C-A442-26644767C3C7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5A6E3F97-1AA2-408A-82BD-C187A2481205}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5B7B470E-3E66-4174-8FB0-ED2BF283FA7C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5B7CAA49-F4B4-411D-B769-788FF51FA7D4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5B930685-B46C-41D4-8062-0D4DF03EDED8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5CD9A114-56CF-4898-BE21-0A87EE921293}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5DBED689-CC99-438F-B2A6-B1039FF1669A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5E35EC8A-CA3D-48BE-A1FB-0731907E03B8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5F3C13DE-F6A7-4FA8-B27A-DE65E7BE1B5E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{5F84A751-DB07-487C-AB77-FC5E79EA5A82}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{60126F95-42E8-459C-8080-0E6215D219B6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{60156B1C-79CB-417D-89D8-55F4F229FA51}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6021A070-F346-4095-923B-C9C500A57564}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6033FBE5-7015-46BA-81CA-6AA4C12D19AA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{627A1592-3F53-48BA-92B3-7BDB14E7D612}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{62ABBE70-FC86-456E-B1ED-B56A9CBEBC60}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{62E31C60-FB99-43F6-895E-842DC95B2463}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{638945D8-268D-4D94-983B-4BDC84E69AFD}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{63CA847B-3354-4782-9FD9-00A3B384A4CA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{653EE2FE-D6B5-4A0A-8B8F-62E647793735}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{657FBEC7-83D6-497E-AA58-423C19977163}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{666728D9-EB27-4BCA-970B-E4D74AAE1E92}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{66F86EF9-E1D3-4407-A6EE-8AE5708BCBB2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6757677A-542F-4F1F-993F-05F122AB99AC}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{676165A8-1E05-4C11-B440-2C5AAE269E63}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{67A3205B-F43A-4975-AAB8-294E37CD9B70}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{67B994AB-C54F-4918-9586-EDB23F6A3519}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{68470603-CF94-420A-BCBE-1FE511A62884}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{687E17A9-A8E8-47AA-A54B-08622B72BED1}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{68BE2241-270C-4E41-BF0D-C964BCEF39FB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{69B0B66F-1B4E-4BA3-B9E9-8FA553AD88EB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6B212F00-EDAC-4361-A0E7-8D61A14D1178}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6B352015-6A92-4BCF-9F17-E195D0B7F8DB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6BDAB467-95D1-4AC6-89AD-408A5DC8656C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6C2C6D1F-E434-461F-9214-050CE0482144}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6CA28EA9-1FAB-4557-862C-452CB48C52A9}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6D59A8DC-AC2D-499C-A578-AE2ED9D63CA2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6D89F8B2-AAEA-4AC5-B124-823B1DE5B340}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6DB3C5ED-98FA-468A-9391-3AADFE569312}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6E388670-E3E0-447F-8B64-D61D52887179}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6EB81265-5637-45BA-93DE-C87AA2927FF3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6EE2691F-3645-4EFD-928C-D31AED1C9577}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6F02160C-AB64-47A7-84B9-EFBEBAC9504A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6F22EE84-AD7F-47A9-9E2B-FA49564DD280}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6F40F26A-6C6E-4A8F-B073-B62484763FA7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{6F7AD07A-A356-40A1-9B1C-E4A8C86AD617}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{70FC7E3F-468A-4721-B9A0-18F8ABEF3D2E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7165A73D-DADB-4EFB-87E0-5B23727E568A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{719EB92A-9FEE-49E8-92DE-9174F3C252FA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{71FB2802-2FA2-4CF3-B92D-AE5AA216CE0F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{71FD7637-C492-4B53-81DC-6ADE2178560E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{724B99DD-0A55-4812-8619-9C829E77E8BE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{72674D1C-874F-463A-B4B9-24FB1F7B1C95}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{726F06BF-2189-4B10-A618-B8D9C2FE2271}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{72B17197-4C06-41EB-AABC-AB294ABF700E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{734D7F46-E1FC-4874-95DB-1921B809DB2F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{746609FB-13DD-4417-A0F9-7D7A938CE27A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{74AC305E-5360-4F83-AC0C-77D4E3F5CFBC}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7542FEFF-5D47-458B-88E1-0C4739B2B03E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{754D73D6-4AEE-4BC4-B908-EE01A33D8FE8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{75F9F90E-FD1B-441A-8C7F-C22835D03AEC}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{764BD54B-158F-4E2E-99F7-3398A075466E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{76C51EB5-E823-4E1C-AF0F-827BD6C895B7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{76EEC78B-BC57-4F64-BA52-E3608397147F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{77B4E96B-0300-46F4-9B68-68F0C1B6DB08}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{784F49A6-E414-4FE4-AB7A-A49F75417810}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{78E241F3-DC32-47B9-B061-AC7A9DEBE1C1}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{79FBFD40-6429-4C8D-BD7D-376241B7363A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7A4D1E67-98D0-49BB-8D86-32175D409396}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7AD735EE-8088-47AC-AE9E-28FB6BB9DE8C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7B1B4D27-FC39-472E-B8AE-797C5F0C8487}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7B47300C-0191-4A1B-B15A-8B750812FDA2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7BD17B04-C1BB-4D41-AFC9-0867C3AB347F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7BEF7E04-FC1C-424A-8F15-A869E7855605}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7C1FA9E7-0DB9-4D2A-A432-1BE550BBE301}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7D9AA55B-F4D2-4A98-AE01-E905D14A2ADA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7DE703D8-BF62-468D-A540-4D06F0C676BB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7DEB9E9F-C5E8-41DF-BEF6-AA8D22ED1311}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7E1E7471-CEE6-42C3-AC50-4E406AE6EAF2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7E7CC352-FD09-4D1E-81B0-C35A3DEEBF6E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7E9B6D96-250A-40E2-8CF2-58184785D29F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7F3886A5-F606-44C5-B68D-D9832813C893}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{7F93E2A9-613F-4979-8803-9456B482F4CA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{81F5D1C2-DD3B-4161-9BAA-2CD9102A1B96}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8226A7F7-B9AF-47BD-9CD2-EB863F0BE922}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8307C4C4-D1F3-4E00-8865-3BDCF9FFBB26}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{83161A74-C02B-4C89-B4D1-D52D0EEB74B1}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8542C08E-B61B-4390-B94A-C1782F85ABE4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{85F570BB-6103-47BE-99FD-F51FB0F99738}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{861F3BED-9ED6-4F85-9707-6962FBDBA832}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{86668D43-98E7-4F42-898C-5A32854BDA12}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{86756A24-E2A1-4807-B141-CFFE68674E63}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{86ACFABE-B1CF-4B2A-9E94-248CA9CE1841}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{86B9444E-4F4A-4495-9631-C2EA24929DC6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8791B45A-9A49-4ACD-946B-6AABA65B4EA9}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{87AEA347-1B49-4B39-8C6F-5E343E4381CA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{87DD2C07-0C7D-4315-9BB0-1B4900A33C4F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8A8A8640-1538-42B3-AA43-E8B4E4E95C03}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8B5F0939-89DD-4172-BDB9-287ADD7A110A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8C1E674D-D2EC-492D-8080-8851681B3116}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8CFC4F53-471F-402A-8843-D8CECBD9A3B2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8EAF99B7-D02F-41CA-8505-334EDDD0EAA5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8FC14BD7-6D8E-4321-A6C8-E1FD5BAE2FAA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8FCFBD0A-28C2-4A31-8B7F-9158A17CBBFB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8FD09ED2-B4E9-463F-BAA5-49D76CA9B69B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8FD63629-8A55-4821-8B67-C1DE1243936B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8FF6C62A-3725-401C-9228-BC155F70D9E4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{8FFFAA9F-4619-4937-B101-2A06E9883B67}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{900BF31A-FA94-446F-9E84-D6ADE3C684CE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9022EABE-33EE-46CA-B1D3-DE123B1279B7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{907E02F2-314A-4329-8EBA-2C084EA33296}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9149FE9D-4DCD-4CB6-8141-0C843C2FC19F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{91813869-1076-435D-9422-1F410614A232}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9183F707-0B1D-4D81-B2A2-C6E966A61B36}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{91B09A2E-375E-4176-A723-305345A57355}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{92A643AA-110A-4035-B909-C58A8DAEF267}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{937DC512-95C6-4D82-A7B1-FA5FF05D527E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{94634577-B62F-40D8-8BEA-9EA6820C495C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{95215660-6566-47CE-9034-2892F954A2BA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{95B673A9-3B58-4B37-9181-BE69FDB3C6C6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9607A606-4FA6-4F5B-8DFC-8A83527FB46B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{96510D32-BF40-41FB-80FB-044F0749ADB7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9700DC67-A8C0-42E4-BB1C-3576AA4B487D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9704F45A-DEA2-42ED-8BAE-FCDDCDF34AD6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9774C49B-F410-41D6-AD33-552D1C3E3AD0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{977E0C0D-F774-4553-94E0-8E5ED65D3A2B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{978D605B-F99C-4C7A-991C-A37D79D3356B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{979D9AB9-65E1-4354-8458-B0A85584D910}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{97A84916-5D43-4E77-A186-F7317C109F05}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{97F3581F-C879-44BA-83EF-251AA214F1CE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{98EF3429-F6F2-42AC-9B31-F234F9163C60}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{98F43ED9-8C39-42CA-BE66-BE138B0FA4F2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{993B2B6C-BFCD-42F1-B63B-F122DAB776AC}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9961AFEA-D636-4CF4-B02A-1BF9FC7BC32C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9991041D-B481-4158-BBC0-D6DEE00347C7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{99E5BFEE-B13C-4813-B187-B521CD6BBC1C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9AA140C6-F76F-4650-9DF2-D6DEEB6808C0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9AE3927E-DD4D-4C1A-8F09-91300F9E0214}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9BB04045-41D9-4841-AD23-D371CFEF3D71}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9BDF7A01-8B68-4F42-B7A9-9069F2FA0C6B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9BDFD6F8-2F39-48EC-9449-254348E698D2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9BEE8AB7-9C98-4898-A979-61AAA5715CBA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9C049979-ECB6-48BA-8266-D17FE70E61EB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9C383F90-E7AF-4407-9707-E59CD07C9356}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9CB73FAA-E512-4A34-B331-9EAE5435DFA0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9CE13003-BC3E-4610-9A35-4A169DCE51A8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9D20E292-3BD0-45EC-87A7-ED8C9C383734}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9D962A25-190C-4B66-8B5A-96ED843F462E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9DAF548B-14BD-4503-8690-2BB153E0804F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9E73CA46-2ABC-40E0-BFA9-0B5BB2AB3A84}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9E78D70E-D133-4143-AF23-6324117424E3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9F3E16A4-5C0B-4313-BE94-60AAC39A79D6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9F850748-9567-4726-B7E1-BBAEC8E98F5C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9FAD73CD-08B2-42F2-800C-57DD49246917}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9FD5A9EB-2C7A-4346-B93A-3B2235D49B7C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{9FDA0480-0238-4047-83A5-E533781A5D11}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A054DF08-9061-46A2-939B-BD76C723A072}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A0687971-38BE-41F3-A625-598D68C27476}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A0D9ADFD-8E04-4F64-A687-064BD5691F9C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A18534D7-C309-4FA1-A781-1C8B5B0335F3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A1876DF2-5890-4379-9EF9-CD88587D109E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A1E27D91-12AD-4E5C-A91C-C8AAEFA5C4D9}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A21EEA36-0EFF-4E01-8753-46C93A9553F0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A236D4B1-9A24-4950-ABB2-9FA06D2B3B71}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A29B5DC7-E246-4A7C-8A4B-E18DFBBC172A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A2E1E3FC-7142-4F30-B400-58C662A1AC4C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A2F43985-DDD0-4CBB-BDD1-CCBD3788B06A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A385170E-7267-442A-84EB-BACC6B358B72}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A387B0A6-F2D0-4BE6-BECC-071E3AC12F44}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A3C7F08C-38C0-457D-9F47-4888CD3727E2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A4CDECB1-F51B-41FE-AD9A-4983C6358B0C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A4F086F0-F209-4853-959E-0BB0AD9DD656}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A545E004-1A52-451E-9946-81EA53E23F26}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A59012DA-CB4B-4591-B505-56858C6A1B7C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A714D1BF-2615-49BB-BEB4-F46C5B2AA75C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A7411629-422C-40E9-BA63-F1FC53D6A584}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A7E3B3B2-4206-4AC0-9AD7-51D173B4D430}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A87007AB-B23F-403B-9DB9-BF15A8E17217}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A879E30A-1D14-4AF3-A7E2-4FA92FED5A07}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A8BD1196-8C05-4BF9-8DFA-1860846D410E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A90865D0-4058-47D9-B320-7C8BCA6123E8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{A9DD5000-4DB9-4DEA-8D52-413A372F59EC}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{AA65EE2E-BE20-4A56-97DE-73D1034530DE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{AAC45671-8511-498D-BF38-169C7F28C3FA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{AC1C8903-E529-45AC-AB17-86BD015672B6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{ACAC0347-D6E2-473F-ADAB-3AE3083B1D00}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{ACCB070D-69FB-445A-BB8D-3A10173F3327}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{AD847824-C5D0-45E3-99D8-D529333E8FE3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{AF2253AE-0818-42C6-AA39-480B9566E5A3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{AF7F32D9-7D16-46F9-AD7B-16AF66BE65E2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B04A6C0A-4576-4B29-BF69-813207256C4E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B080BF04-F566-4126-9523-47B7D5410391}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B0AE2F02-AC08-4A90-9EAB-F2086F6387C7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B35314C4-F820-4576-B604-5007E121A1F5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B391A77B-601D-4711-8795-A9A99A077314}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B45048EA-EEFA-4871-810E-412618F702DC}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B5373488-0493-4DD7-BC12-DFE6FE9D9D97}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B566E798-D5B9-4EEF-B960-56F62F31BCDA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B59F9F5B-CAD2-4A8A-A174-0D033DC13F84}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B5ABE509-662D-49CB-B14A-F0BC11FD012B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B6CF09DC-EFDA-42E7-9950-41DBAD66D5FD}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B6D11181-8118-48AF-9051-0404063DF642}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B7183278-5CD0-494F-807F-92197DA819D2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B71ED08D-EDEB-4C1B-A2A1-2E3B65DAE51B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B7218B7A-3302-4F96-B2E2-9F68D5002AD3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B75AD1C9-F7C3-47D5-ACAF-D97020E0981A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B79BD3EC-2D30-4857-89E8-8FCDCB98CBE4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B84C01D7-8387-4377-A69B-B61228682E94}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B8C2F72F-70E1-4863-B9C8-76EE963F7A53}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{B8F41D55-4A7E-480E-998B-8220BEFA2D11}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BA2723A0-9D67-4CFB-9DC9-98CEFD91DAC8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BAD89026-50F5-4701-B9AB-8AD6A869E30D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BB202F40-FD60-4E4F-BE6C-3E44093678C8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BB9E21B8-BABC-41BB-A64E-AD324D7D9334}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BCB88012-563E-4D30-A3A2-AA9ED33981B3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BCB9894D-4379-4909-B20B-E960E2C0F570}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BCC1B431-03F9-4270-A1E1-B9969E821ECE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BD47477E-D9B5-4F64-9DB8-AE1BAC88A5A2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BD524703-FC73-44F8-8519-B51235C16FA5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BD6E5E6C-7DCB-418A-961B-52DC34483FE2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BE3EFAD3-7692-4642-8729-5869042CD9AF}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BE5EF409-D40D-4F54-A60E-19EDB1EA648E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{BFD56D66-ACCA-48CB-8767-496BF86264AD}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C0197F1C-E959-47CA-8803-265B93FC556D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C1962E51-367D-47E5-834E-645C1C421D6D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C1B80AEC-0AD6-4848-A6E3-AC7559A992FC}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C1DF0727-2735-4214-9524-E57232426E87}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C2606C16-E6AA-42F2-8CED-271CC0ECC19D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C303C5B2-7E97-4656-BF39-0C5315FE04A3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C375390A-C0C2-47BF-BBBF-0A32C76F14A4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C3DFF2AC-ABD3-4482-936C-E3E0BEB4E0CE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C405AFE7-61E6-4036-B977-3BDBB084FAD1}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C42572AD-217D-4590-83DE-7B7A16F0FE29}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C42CAF6A-3183-4270-8EC3-128E52AF8226}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C52A15DD-3F68-4808-B928-5B1E24BD926C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C56630BC-7E8B-4397-997A-7E22D691E964}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C6D024FA-2AE4-4D07-8EF2-376638BB88BF}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C6D2B91A-4A2D-4023-9BDE-EA76A6A8FF5F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C6E14497-1ABD-4B50-B400-27A2C1447C2D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C7649FEE-3854-483A-8247-B84817C75667}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C7712535-7E9A-4BD7-BD5A-2E0F03FF05E9}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C7A16F80-4805-4D8C-A499-7247E9BDE6FD}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C7ADD30D-A14C-411F-9774-CDF0B8B46CB6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C87A5F6C-90BE-45D2-B714-3715DA583B1B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C8801480-C98F-4B0D-8547-9BB08E5270E2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C96AC388-262C-4E53-82F1-BB4FE0883685}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{C98EE1E8-9D2C-48EF-815F-CAC7D28A52FB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CA1CC08C-0CE2-4B8D-BA80-9AA837FE4D0A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CA33736B-E314-4832-91F3-A2CE49E7F3AB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CA4F7BFA-F66E-4592-A0B5-A27D7ADFBF48}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CAEDDEC1-45B9-4C6F-B319-5BE50F211AC2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CCEAB979-7504-4301-94E0-0C55C1F89E6B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CD264D2A-D06F-4F1B-89A9-A137CF0C6B32}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CD7B65EC-3D40-4BEE-9DAA-C344BB5A1984}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CD8B708B-994A-43C6-B5C3-0C78DBF1B6F8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CDA7B00C-553D-4071-9FC2-98529E3EC43B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CDBB4FE7-AA79-45D7-97C3-321613125785}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CDDE9F63-BBDF-4500-9F52-E129237BD99F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CE148FD1-BE3B-44CC-8E23-4CD81699D2B4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CEA6BCC8-3F1C-49A1-81B8-7F4DB43F60E0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{CFE66992-3447-4010-A275-498D8631B16F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D028D43C-4B2F-4EC2-B689-12F09D1809E0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D03AE56E-CFDF-4087-A221-1C4C0DB0D8DD}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D061EAF2-5D4E-4198-82AC-DCAE92D05B32}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D14112E3-DB0A-4390-8671-EAB8D1B2582E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D28C78CF-19FD-40FA-BB1E-0804FCFFF68D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D2DA9F42-3E3C-4FC5-88D7-D3E61399D671}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D2DE2F54-4462-454E-8560-AF60138A9710}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D2F15443-A368-4298-AEA0-61A59C103A33}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D3591D1B-8A9A-4E65-85BC-20DED0B84420}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D3F68AC2-157B-45D3-8206-EA14CDA0DF76}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D419AF2D-BFE0-4BBE-83E8-DBDAA033CCA5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D4602A80-39DE-48AC-82C4-55317FEB3DC6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D5D0AC85-F440-4F20-B418-2CFD6083C38E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D683C5F7-8767-4FA6-8385-B142D54EACE6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D6A6333B-9FA1-4912-BB58-CC336F39F514}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D7335A5A-E61B-4426-BE6A-16475DE6B745}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D79AAA6A-FD00-4998-B239-24B9443201A0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D8169A1A-99D8-4874-9A0C-C7FEF2A73923}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D8444047-82CC-47FD-950A-A66E5AF2AEDA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D84F972B-0237-4E31-98D7-60FF7B584471}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D893C53B-DA51-40D7-9C45-DF9DE41E727A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{D93B8C1B-59FF-42AC-866B-09450F076721}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DA5DA9EB-F1C1-4DBD-9660-B8448B2DAA40}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DA67D3E2-5E6A-4A92-A744-6E9B341C8AAB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DA950580-EED8-4D73-9ACD-EA0A04F23860}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DA951892-1E82-4656-9239-BCAD668F6BF0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DAB54C3F-43DB-4280-8BCB-74B6F92C4457}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DAB8B43A-58C3-4896-9691-9992668C81F2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DD15C4F6-B92C-45BB-91A3-620ADA04F65B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DD69D215-C43D-4155-BCB9-22D19DDBA30A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DD77B5E4-AAAC-49EB-B900-BE7A778547EB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DE0399FA-FBDD-4723-8338-242DABE53A97}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DE0FC13D-97A8-4DBB-ABD0-B3A48C75A6D2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DEB2090F-5AC9-4076-A071-5576BDF7A907}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DF260341-C245-4601-81DA-D55421917B66}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DF30E6E7-E22B-460F-9DA7-48CB18DF15F3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DF457DCC-8BD3-4538-A4DC-BDE1A698EA39}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DF69BF83-3F35-448B-B899-1E55566C8601}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DFDBEFD6-4373-4824-9E20-89CCE1B70D77}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DFE1202E-7C4E-442C-819E-4178A37C0975}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{DFF64678-F568-4B0F-9D94-299B6B79707A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E03D51D2-792E-40AC-9C0E-267B71559BA2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E092B140-20E1-461D-86FD-999157A76958}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E26F13BF-3525-4FCE-9D8C-788AF0E9B7C0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E2C6D07E-7A31-4993-BA81-7AFE8B6043CA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E452A70D-7064-45DD-9889-AF0F6552A332}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E51B7BA5-BA1C-4D92-94A3-023871AD93A3}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E547FC4E-706D-44B3-A0D7-6227811BC3DA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E55534FF-70C0-419A-8ABA-78F387B8DE5A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E560F149-B0E8-45BB-ACDF-0BCB06D01C4B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E619F7AA-4417-413A-83BE-9F689C6CADB4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E63E2784-D6D2-4881-A889-EBDE58282922}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E6631519-58D2-4666-A946-09F276CE6516}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E6F3FF46-4955-48FF-80B6-2DF7C497489F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E7DA0CA3-080B-43D8-AD70-874A44806280}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E7F0D992-27EC-4131-AA28-93E77CA585D2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E95F374F-9BF0-4458-BD47-AFCB84A4217D}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E97E5C22-A831-437D-9A40-D4ACC613608C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E981E0BF-AE3C-4E7E-AC03-1E09173E9212}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E985D042-4DE5-4814-844F-2A1D6A8A055A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E9C466C8-E6D2-4305-956B-C9561234DA16}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{E9E86DAE-2AE0-4F99-9328-E3715F007FA0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{EADA07AD-B45C-48A1-80EF-26778963D8F2}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{EB0F1FC7-BC76-40CC-92C8-D3EC5972D9EE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{EBB6F244-E171-4E23-9F4F-CD60B585D2C9}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{EBD4556C-6B23-49AD-82DB-637E18D3FDF7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{EC3E7E03-BE3C-4273-AD8C-79BEED0E636A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{ECCF30C6-9F7F-4EF2-A710-EE86A79D3E73}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{ED4E97AA-38A9-4EC4-8019-2A9B02D6E9FA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{ED6EF561-3D1D-44F1-BCEF-1388BA124F4F}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{EE3AFC9F-C653-4D9C-8387-CF2613CD6490}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{EE68AE72-C23D-48D7-A86B-4234E681A4EB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{EE95B038-AB58-452A-A27D-7448FC7ABBF1}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{EFC9D06B-DA81-433F-ADCC-6BCF40CC8E20}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{EFDDA8F0-C6CF-40C5-9711-B91B31A270DE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{EFF6FF28-69CE-4192-815E-52DEBB6A7A14}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F006E018-4202-4931-8E87-888EC15BDDD7}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F02AC065-57CF-4A94-B3E9-C60785BA98E8}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F03D9D4D-B6B7-492F-A7C6-FC6A160F7D03}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F0775642-3DD8-4D3E-BC39-10C12B32199C}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F09957DA-0C8C-4FF1-A472-3C9B0C74D08B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F130CF7C-7776-4BB7-918B-18A546A8098E}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F16668F2-0B71-44A1-944C-EAA19577BD25}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F187B0CA-B56A-4F02-A49E-CBFD91577D60}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F20D5D36-B3A3-4073-8A99-5B442171AE90}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F2447D7C-F0B3-400A-9D66-9F1BAE8F42C6}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F2879740-418B-4579-BD6D-E0AE71A769AC}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F2B2C51D-8151-44E9-941F-69E6013CE270}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F2BBA34B-E087-4639-B826-F0BF86B803B5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F2DCA717-0423-40A7-A6E6-C31686B57AD9}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F31F7C97-2113-48B0-8B0C-282A9B970EBD}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F422DF4B-464A-4DB2-AF61-AB8F8D912CBE}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F432FB9A-A06F-4419-953C-8B6B824B4B2B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F4F5B4C5-0C7B-4F85-895E-EC4C0F25732A}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F527768A-F391-461F-91AC-0548937AF683}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F52F976A-7214-417A-9C3A-BEF059E423AF}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F5D0B3D7-1B02-43E7-BD51-A8FB4DCBCDC1}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F6555068-22E4-4EE4-A5BA-1FC5D58771C0}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F81AF874-5D15-48B1-AEBC-0610956BA793}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F9001457-352D-421E-ADA6-6171B0CFC390}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{F9FF0BBD-7949-4D36-AEA2-0C6B2695772B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{FAD4538D-7796-4C99-83FF-93BB9ADFBDC4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{FB4A179E-D1BB-409D-9DB5-771ABE7F36F4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{FB718365-2EB3-4AA4-95E9-77FF93B0F2DA}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{FBACE547-D2E3-4544-B10B-2B3E67EBF9A4}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{FBFD91AE-0A28-42DF-BA83-CD54952676BB}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{FC813CD1-1E0E-4867-9276-91A831F8C1D9}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{FDC36C30-43FB-4DD0-8D96-B6955C0A286B}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{FECFE02F-B89D-4E77-8F96-ADE06FB30DA5}
Successfully deleted: [Empty Folder] C:\Users\MarcoAdm\appdata\local\{FF228D60-BD2B-468D-AD0A-368A61180005}



~~~ FireFox

Successfully deleted: [File] C:\Users\MarcoAdm\AppData\Roaming\mozilla\firefox\profiles\56wx6ubw.default-1399854068777

\user.js
Emptied folder: C:\Users\MarcoAdm\AppData\Roaming\mozilla\firefox\profiles\56wx6ubw.default-1399854068777\minidumps [9

files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 10/16/2014 at 20:45:17.37
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



STEP 05


# AdwCleaner v4.000 - Report created 16/10/2014 at 21:12:58
# DB v2014-10-16.8
# Updated 12/10/2014 by Xplode
# Operating System : Windows Vista Home Premium Service Pack 2 (64 bits)
# Username : MarcoAdm - SONYLAPTOP
# Running from : C:\Users\MarcoAdm\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : ServUpdater
[#] Service Deleted : TBSrv

***** [ Files / Folders ] *****

[!] Folder Deleted : C:\Users\MarcoAdm\AppData\Local\Temp\AirInstaller
[!] Folder Deleted : C:\Users\MarcoAdm\AppData\Local\NativeMessaging
[!] Folder Deleted : C:\Users\MarcoAdm\AppData\Local\Temp\NativeMessaging
[!] Folder Deleted : C:\Users\MarcoAdm\AppData\Local\ServUpdater
[!] Folder Deleted : C:\ProgramData\Tbccint
[!] Folder Deleted : C:\Program Files (x86)\Tbccint
[!] Folder Deleted : C:\Users\MarcoAdm\AppData\Local\Tbccint
[!] Folder Deleted : C:\Users\MarcoAdm\AppData\LocalLow\Tbccint
[!] Folder Deleted : C:\Users\MarcoAdm\AppData\Local\Temp\Vuze_Remote
File Deleted : C:\END

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Tbccint
Key Deleted : HKCU\Software\Tbccint_HKLM
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Tbccint
Key Deleted : HKCU\Software\AppDataLow\Software\TbccintSearchScopes
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Freeze.com
Key Deleted : HKLM\SOFTWARE\WinWSD ToolBar

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16563


-\\ Mozilla Firefox v32.0.3 (x86 en-US)


-\\ Google Chrome v


*************************

AdwCleaner[R0].txt - [2355 octets] - [16/10/2014 20:56:42]
AdwCleaner[s0].txt - [2036 octets] - [16/10/2014 21:12:58]

########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [2096 octets] ##########


STEP 06

MBAM did not offer me the option to remove (delete) the threats found, but only to quarantine them, so I did that.
Here is the log:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 10/16/2014
Scan Time: 9:24:14 PM
Logfile: mbam_log_10162014_3.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.10.17.02
Rootkit Database: v2014.10.15.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows Vista Service Pack 2
CPU: x64
File System: NTFS
User: MarcoAdm

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 419207
Time Elapsed: 22 min, 20 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 2
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension

Settings\ojpijjmpahflnipadmlpgbjmagmjchkk, Quarantined, [47b8c94b770583b30aa2d9385fa4df21],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-

extension_ojpijjmpahflnipadmlpgbjmagmjchkk_0, Quarantined, [07f85aba3e3ebf77ded43dd425de4eb2],

Files: 9
PUP.Optional.Babylon.A, C:\Program Files (x86)\EPSViewer\MyBabylonTB.exe, Quarantined, [db24779d6616f54127d3839bc838639d],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-

extension_ojpijjmpahflnipadmlpgbjmagmjchkk_0.localstorage, Quarantined, [847bd73d95e7a3935a4bd8b3db29c43c],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-

extension_ojpijjmpahflnipadmlpgbjmagmjchkk_0.localstorage-journal, Quarantined, [f60936deb1cbfc3ab5f0fb90788cbb45],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension

Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\000003.log, Quarantined, [47b8c94b770583b30aa2d9385fa4df21],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension

Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\CURRENT, Quarantined, [47b8c94b770583b30aa2d9385fa4df21],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension

Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\LOCK, Quarantined, [47b8c94b770583b30aa2d9385fa4df21],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension

Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\LOG, Quarantined, [47b8c94b770583b30aa2d9385fa4df21],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Local Extension

Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\MANIFEST-000002, Quarantined, [47b8c94b770583b30aa2d9385fa4df21],
PUP.Optional.Conduit.A, C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-

extension_ojpijjmpahflnipadmlpgbjmagmjchkk_0\7, Quarantined, [07f85aba3e3ebf77ded43dd425de4eb2],

Physical Sectors: 0
(No malicious items detected)


(end)


STEP 07

ESET log:

C:\AdwCleaner\Quarantine\C\ProgramData\Tbccint\Multi\CT2504091\UninstallerUI.exe.vir    a variant of Win32/ClientConnect.A

potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\MarcoAdm\AppData\Local\Tbccint\Chrome\CT2504091\CHUninstaller.exe.vir    a variant of

Win32/ClientConnect.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\MarcoAdm\AppData\Local\Tbccint\Chrome\CT2504091\UninstallerUI.exe.vir    a variant of

Win32/ClientConnect.A potentially unwanted application
C:\Program Files (x86)\Wisdom-soft ScreenHunter 6.0 Free\Toolbar.exe    Win32/Toolbar.Conduit potentially unwanted

application
C:\Users\MarcoAdm\Desktop\Old Firefox Data\i7e04y4r.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}

\ctypes\FirefoxCtype.dll    a variant of Win32/Conduit.SearchProtect.N potentially unwanted application
C:\Users\MarcoAdm\Desktop\Old Firefox Data\i7e04y4r.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}

\Plugins\npFirefoxPlugin.dll    a variant of Win32/Conduit.SearchProtect.N potentially unwanted application
C:\Users\MarcoAdm\Downloads\7zip-setup.exe    Win32/DownloadAdmin.A.Gen potentially unwanted application
C:\Users\MarcoAdm\Downloads\asc7-setup-aff.exe    a variant of Win32/Toolbar.Widgi.B potentially unwanted application
C:\Users\MarcoAdm\Downloads\cbsidlm-tr1_7-Postscript_Viewer-SEO2-10845650.exe    Win32/DownloadAdmin.D potentially unwanted

application
C:\Users\MarcoAdm\Downloads\cbsidlm-tra1-WinWSD_WebSite_Downloader-SEO2-10562531.exe    Win32/DownloadAdmin.G potentially

unwanted application
C:\Users\MarcoAdm\Downloads\EPSViewerSetup.exe    a variant of Win32/Toolbar.Babylon.A potentially unwanted application
C:\Users\MarcoAdm\Downloads\setupscreenhunterfree.exe    Win32/Toolbar.Conduit potentially unwanted application

 

Link to post
Share on other sites

STEP 08

Pasted below are both the FRST and the Addition logs:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-10-2014
Ran by MarcoAdm (administrator) on SONYLAPTOP on 17-10-2014 00:24:49
Running from C:\Users\MarcoAdm\Desktop
Loaded Profile: MarcoAdm (Available profiles: MarcoAdm & Administrator & Guest)
Platform: Windows Vista Home Premium Service Pack 2 (X64) OS Language: English (United States)
Internet Explorer Version 9
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-

recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be

moved.)

HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-

Malware\mbamdor.exe [54072 2014-05-12] (Malwarebytes Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\VESWinlogon-x32: VESWinlogon.dll [X]
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64

\Macromed\Flash\FlashUtil32_14_0_0_145_Plugin.exe [851632 2014-07-09] (Adobe Systems Incorporated)
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\RunOnce: [Report] => C:\AdwCleaner\AdwCleaner[s0].txt [2176 2014-10-

16] ()
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\MountPoints2: {0704b6c6-eef6-11e1-b785-8c87dfc73970} - F:\LaunchU3.exe

-a
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\MountPoints2: {69fcf01f-e7d4-11e1-8e88-806e6f6e6963} -

F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\MountPoints2: {b2d1a024-e7d0-11e1-9396-d07ffd9f2f6d} -

F:\setup_vmb_lite.exe /checkApplicationPresence
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS

Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS

Corporation)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32

\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64

\CbFsMntNtf3.dll (EldoS Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?

brand=SNYR&bmod=SNYR
StartMenuInternet: IEXPLORE.EXE - %ProgramFiles(x86)%\Internet Explorer\iexplore.exe
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit

Uninstaller\UninstallExplorer64.dll (IObit)
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle

Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft

Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google

Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)

\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll

(Oracle Corporation)
BHO-x32: Virtual Account Numbers Helper -> {17424104-1444-4810-85D7-B4DA413C5A9A} -> C:\Program Files (x86)\Virtual Account

Numbers\CitiVANHelper.dll (Orbiscom Ltd. All rights reserved.)
BHO-x32: CitiUSBrowserHelper Class -> {387EDF53-1CF2-4523-BC2F-13462651BE8C} -> C:\Program Files (x86)\Virtual Account

Numbers\BhoCitUS.dll (Orbiscom Ltd. All rights reserved.)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7

\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common

Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows

Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google

Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet

Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Advanced SystemCare Browser Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)

\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7

\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google

Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - I.R.I.S. Desktop Search - {577EBCA9-8ED3-45FC-A514-55B3817D4BCF} - C:\Program Files (x86)\IRIS Desktop

Search\IRISDesktopSearchIntegration910.dll (Copernic Technologies Inc.)
Toolbar: HKLM-x32 - Virtual Account Numbers - {7A21A046-B886-4A62-9D69-EF2059B0A27B} - C:\Program Files (x86)\Virtual

Account Numbers\CitiVANToolbar.dll (Orbiscom Ltd. All rights reserved.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google

Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google

Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU - I.R.I.S. Desktop Search - {577EBCA9-8ED3-45FC-A514-55B3817D4BCF} -  No File
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} -  No File
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} -  No File
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} -  No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet

Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole

DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole

DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole

DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole

DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2009

\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole

DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole

DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole

DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet

Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

(Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{2A73429A-B03C-4F88-ABAF-48B0629EA399}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{2BF03E76-37A1-4EB0-867B-923862A5E1AA}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{83228AEC-D667-4A75-AC1E-483C1216EBA5}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{C2F38D47-8F48-4FFF-9C21-3B5EA2894EFB}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{FC077840-0E7B-4E6C-9460-0DB6F45F914E}: [NameServer] 8.8.8.8,8.8.4.4

FireFox:
========
FF ProfilePath: C:\Users\MarcoAdm\AppData\Roaming\Mozilla\Firefox\Profiles\56wx6ubw.default-1399854068777
FF Homepage: www.google.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/MycameraPlugin -> C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle

Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll (

Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation

Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15

\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15

\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: tdameritrade.com/thinkorswim -> C:\Program Files (x86)\thinkTDA\npthinkorswim.dll (TD Ameritrade)
FF Plugin HKCU: tdameritrade.com/tossc -> C:\Program Files (x86)\thinkTDA\nptossc.dll (TD Ameritrade)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\MarcoAdm\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\MarcoAdm\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\MarcoAdm\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Extension: Advanced SystemCare Surfing Protection -

C:\Users\MarcoAdm\AppData\Roaming\Mozilla\Firefox\Profiles\56wx6ubw.default-1399854068777

\Extensions\ascsurfingprotection@iobit.com [2014-08-30]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

[2014-10-05]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5

\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation

Foundation\DotNetAssistantExtension [2009-04-15]
FF HKLM-x32\...\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-

AAA2-85EF591126E7}\Norton\coFFPlgn
FF HKLM-x32\...\Firefox\Extensions: [citius@orbiscom] - C:\Program Files (x86)\Virtual Account Numbers
FF Extension: Virtual Account Numbers for Firefox - C:\Program Files (x86)\Virtual Account Numbers [2009-04-05]
FF Extension: No Name - C:\Program Files (x86)\IObit Apps Toolbar\FF [Not Found]

Chrome:
=======
CHR HomePage: Default -> hxxp://search.conduit.com/?ctid=CT2504091&SearchSource=48&CUI=UN52017086324385214&UM=2
CHR StartupUrls: Default -> "hxxp://search.conduit.com/?ctid=CT2504091&SearchSource=48&CUI=UN52017086324385214&UM=2"
CHR Profile: C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User

Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd [2014-09-03]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User

Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-29]
CHR Extension: (Google Wallet) - C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User

Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-14]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless

listed separately.)

S4 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft

Inc.)
S4 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2012-07-04] ()

[File not signed]
S4 EvtEng; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [1449984 2008-08-20] (Intel® Corporation) [File not signed]
S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14]

(Macrovision Corporation) [File not signed]
S4 KodakSvc; C:\Program Files (x86)\Kodak\AiO\center\KodakSvc.exe [38296 2009-01-19] (Eastman Kodak Company)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes

Corporation)
S4 MSCSPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [53248 2008-05-20] (Sony Corporation)

[File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S4 NgVpnMgr; C:\Windows\system32\ngvpnmgr.exe [424984 2009-06-04] (Aventail Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
S4 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [53248 2008-05-20] (Sony Corporation)

[File not signed]
S4 PowerOffer Service; C:\Users\MarcoAdm\AppData\Local\PosService\Pos.exe [164352 2011-12-16] (PowerOfferService) [File not

signed]
S4 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [24576 2008-09-10]

(Intuit) [File not signed]
S4 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [61440 2008-08-08]

(Intuit Inc.) [File not signed]
S4 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1886488 2014-07-10] (Trusteer

Ltd.)
S4 RegSrvc; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [826368 2008-08-20] (Intel® Corporation) [File

not signed]
S4 RtkAudioService; C:\Windows\RtkAudioService.exe [134656 2008-10-17] (Realtek Semiconductor) [File not signed]
S4 SampleCollector; C:\Program Files\Sony\VAIO Care\collsvc.exe [167424 2008-09-29] (Intel Corporation) [File not signed]
S4 SOHCImp; C:\Program Files (x86)\Sony\VAIO Media plus\SOHCImp.exe [103712 2008-10-21] (Sony Corporation)
S4 SOHDms; C:\Program Files (x86)\Sony\VAIO Media plus\SOHDms.exe [353568 2008-10-21] (Sony Corporation)
S4 SOHDs; C:\Program Files (x86)\Sony\VAIO Media plus\SOHDs.exe [62752 2008-10-21] (Sony Corporation)
S4 SPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe [77824 2008-05-20] (Sony Corporation) [File

not signed]
S4 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S4 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment

Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [73728 2008-09-08] (Sony

Corporation) [File not signed]
S4 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [446464 2008-09-03] (Sony

Corporation) [File not signed]
S4 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [279848 2008-09-08] (Sony

Corporation)
S4 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [8704 2010-09-08] (Vodafone)

[File not signed]
S4 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2008-09

-08] (Sony Corporation) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless

listed separately.)

S3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2008-04-24] (ArcSoft, Inc.)
S3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
S1 DMICall; C:\Windows\SysWOW64\DRIVERS\DMICall.sys [10216 2008-08-22] (Sony Corporation)
U3 Ehtssvcietle_; C:\Windows\SysWOW64\drivers\DMICall.sys [10216 2008-08-22] (Sony Corporation)
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NgFilter; C:\Windows\System32\DRIVERS\ngfilter.sys [25624 2009-06-04] (Aventail Corporation)
S3 NgLog; C:\Windows\System32\DRIVERS\nglog.sys [31256 2009-06-04] (Aventail Corporation)
R3 NgVpn; C:\Windows\System32\DRIVERS\ngvpn.sys [102424 2009-06-04] (Aventail Corporation)
S3 NgWfp; C:\Windows\System32\DRIVERS\ngwfp.sys [28696 2009-06-04] (Aventail Corporation)
S2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 ONDAusbmdm6k; C:\Windows\System32\DRIVERS\ONDAusbmdm6k.sys [119680 2010-09-02] (Onda Communication)
S3 ONDAusbnet; C:\Windows\System32\DRIVERS\ONDAusbnet.sys [135168 2010-09-02] (ONDA Corporation)
S3 ONDAusbnmea; C:\Windows\System32\DRIVERS\ONDAusbnmea.sys [119680 2010-09-02] (Onda Communication)
S3 ONDAusbser6k; C:\Windows\System32\DRIVERS\ONDAusbser6k.sys [119680 2010-09-02] (Onda Communication)
S1 RapportCerberus_69875; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_69875.sys

[631128 2014-07-30] ()
S1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [299736 2014-07-10] (Trusteer Ltd.)
S3 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [358616 2014-07-10] (Trusteer Ltd.)
S1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [414296 2014-07-10] (Trusteer Ltd.)
R2 risdptsk; C:\Windows\System32\DRIVERS\risdsn64.sys [76288 2008-10-22] (REDC)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
S3 Spyder2; C:\Windows\System32\DRIVERS\Spyder2.sys [15360 2007-01-17] ()
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [37624 2014-10-16] ()
S3 vodafone_K3805-z_cdc_acm; C:\Windows\System32\DRIVERS\vodafone_K3805-z_cdc_acm.sys [98304 2010-09-01] (Vodafone)
S3 vodafone_K3805-z_cdc_ecm; C:\Windows\System32\DRIVERS\vodafone_K3805-z_cdc_ecm.sys [53760 2010-09-01] (Vodafone)
S3 vodafone_K3805-z_cpo; C:\Windows\System32\DRIVERS\vodafone_K3805-z_cpo.sys [13824 2010-09-01] (Vodafone)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately

to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-17 00:24 - 2014-10-17 00:26 - 00022360 _____ () C:\Users\MarcoAdm\Desktop\FRST.txt
2014-10-17 00:24 - 2014-10-17 00:24 - 00000000 ____D () C:\Users\MarcoAdm\Desktop\FRST-OlderVersion
2014-10-16 22:02 - 2014-10-16 22:02 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-10-16 22:01 - 2014-10-16 22:01 - 02347384 _____ (ESET) C:\Users\MarcoAdm\Desktop\esetsmartinstaller_enu.exe
2014-10-16 21:04 - 2014-10-16 21:04 - 00084917 _____ () C:\Users\MarcoAdm\Downloads\bluescreenview-x64.zip
2014-10-16 20:56 - 2014-10-16 21:13 - 00000000 ____D () C:\AdwCleaner
2014-10-16 20:54 - 2014-10-16 20:55 - 01976320 _____ () C:\Users\MarcoAdm\Desktop\AdwCleaner.exe
2014-10-16 20:51 - 2014-10-17 00:23 - 00069572 _____ () C:\Users\MarcoAdm\Desktop\reply2.txt
2014-10-16 20:45 - 2014-10-16 20:45 - 00061812 _____ () C:\Users\MarcoAdm\Desktop\JRT.txt
2014-10-16 20:43 - 2014-10-16 20:43 - 00000000 ____D () C:\Windows\ERUNT
2014-10-16 20:41 - 2014-10-16 20:41 - 01705698 _____ (Thisisu) C:\Users\MarcoAdm\Desktop\JRT.exe
2014-10-16 09:20 - 2014-10-16 09:20 - 00269416 _____ () C:\Windows\Minidump\Mini101614-02.dmp
2014-10-16 08:36 - 2014-10-16 08:36 - 00269416 _____ () C:\Windows\Minidump\Mini101614-01.dmp
2014-10-16 08:33 - 2014-10-16 09:18 - 00037624 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-10-16 08:33 - 2014-10-16 08:33 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-10-16 08:31 - 2014-10-16 08:31 - 00006507 _____ () C:\Users\MarcoAdm\Desktop\Reply.txt
2014-10-16 08:30 - 2014-10-16 08:30 - 18550872 _____ () C:\Users\MarcoAdm\Desktop\RogueKillerX64.exe
2014-10-15 23:30 - 2014-10-16 08:47 - 00000000 ____D () C:\Windows\ERDNT
2014-10-15 23:29 - 2014-10-15 23:29 - 00000744 _____ () C:\Users\MarcoAdm\Desktop\ERUNT.lnk
2014-10-15 23:29 - 2014-10-15 23:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
2014-10-15 23:29 - 2014-10-15 23:29 - 00000000 ____D () C:\Program Files (x86)\ERUNT
2014-10-15 23:18 - 2014-10-16 20:37 - 00002748 _____ () C:\Users\MarcoAdm\Desktop\Rkill.txt
2014-10-15 23:15 - 2014-10-15 23:15 - 00791393 _____ (Lars Hederer ) C:\Users\MarcoAdm\Desktop\erunt-setup.exe
2014-10-15 23:14 - 2014-10-15 23:14 - 01944824 _____ (Bleeping Computer, LLC) C:\Users\MarcoAdm\Desktop\rkill.exe
2014-10-10 19:50 - 2014-10-11 13:09 - 00033462 _____ () C:\Users\MarcoAdm\Desktop\FRST_.txt
2014-10-10 19:27 - 2014-10-10 19:28 - 00015616 _____ () C:\Users\MarcoAdm\Desktop\FRST_part1.txt
2014-10-10 19:11 - 2014-10-10 19:12 - 00015561 _____ () C:\Users\MarcoAdm\Downloads\FRST_1.txt
2014-10-10 16:19 - 2014-10-10 16:19 - 00050515 _____ () C:\Users\MarcoAdm\Downloads\Addition_old.txt
2014-10-10 16:18 - 2014-10-10 16:19 - 00042684 _____ () C:\Users\MarcoAdm\Downloads\FRST_old.txt
2014-10-10 16:17 - 2014-10-17 00:24 - 00000000 ____D () C:\FRST
2014-10-10 16:16 - 2014-10-17 00:24 - 02112000 _____ (Farbar) C:\Users\MarcoAdm\Desktop\FRST64.exe
2014-10-10 16:04 - 2014-10-10 16:04 - 00116171 _____ () C:\Users\MarcoAdm\Desktop\sfcdetails.txt
2014-10-10 15:03 - 2014-10-10 15:03 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\MarcoAdm\Downloads\mbam-setup-

2.0.2.1012(1).exe
2014-10-07 05:39 - 2014-10-07 05:39 - 00273656 _____ () C:\Windows\Minidump\Mini100714-01.dmp
2014-10-06 01:38 - 2014-10-06 01:38 - 00984576 _____ () C:\Users\MarcoAdm\Downloads\MicrosoftFixit50906.msi
2014-10-06 00:55 - 2014-10-06 00:55 - 00009976 _____ () C:\Users\MarcoAdm\Desktop\errors3.txt
2014-10-05 14:14 - 2014-10-05 14:14 - 00000974 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start

Menu\Programs\Windows Media Player.lnk
2014-10-05 14:13 - 2014-10-05 14:13 - 00000915 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start

Menu\Programs\Windows Mail.lnk
2014-10-05 13:35 - 2014-10-05 13:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-05 12:47 - 2014-10-05 12:47 - 00002601 _____ () C:\Users\MarcoAdm\Desktop\DetectedProblems.txt
2014-10-05 11:09 - 2014-10-05 11:09 - 00273656 _____ () C:\Windows\Minidump\Mini100514-01.dmp
2014-10-04 21:33 - 2014-10-16 09:20 - 535829603 _____ () C:\Windows\MEMORY.DMP
2014-10-04 21:33 - 2014-10-04 21:33 - 00273656 _____ () C:\Windows\Minidump\Mini100414-01.dmp
2014-10-04 17:08 - 2014-10-04 17:08 - 00000178 _____ () C:\Windows\setupact.log
2014-10-04 17:08 - 2014-10-04 17:08 - 00000071 _____ () C:\Windows\setuperr.log
2014-10-04 17:06 - 2014-10-04 17:06 - 00145408 _____ (Intel® Corporation) C:\Windows\system32\Drivers\IntcHdmi.sys
2014-10-04 17:05 - 2014-10-04 17:08 - 00000000 ____D () C:\Windows\LastGood
2014-10-04 17:05 - 2014-10-04 17:05 - 00000000 ____H () C:\ProgramData\DP45977C.lfl
2014-10-04 17:05 - 2014-10-04 17:05 - 00000000 ____D () C:\Program Files\Realtek
2014-10-04 17:04 - 2014-10-04 17:04 - 60636160 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2014-10-04 17:04 - 2014-10-04 17:04 - 28343384 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 14863448 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 12894808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO3064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 07164176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 06218072 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 05804772 _____ () C:\Windows\system32\Drivers\rtvienna.dat
2014-10-04 17:04 - 2014-10-04 17:04 - 05751048 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 03962840 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2014-10-04 17:04 - 2014-10-04 17:04 - 03959384 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnN64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02834648 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02800344 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02770976 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02162992 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02117424 _____ () C:\Windows\system32\SStudio.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02101848 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02041432 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01959128 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2014-10-04 17:04 - 2014-10-04 17:04 - 01939800 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01934424 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek264.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01317976 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO6064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01313904 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01286872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01168472 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO5064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01136728 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO4064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01099203 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2014-10-04 17:04 - 2014-10-04 17:04 - 01063512 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01048824 _____ (SRS Labs, Inc.) C:\Windows\system32\slcnt64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01022168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00956504 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO2064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00948952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00947760 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00942384 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOSettingsIPC.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00906800 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00900696 _____ (Waves Audio Ltd.) C:\Windows\SysWOW64\MaxxAudioAPOShell.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00889592 _____ (DTS, Inc.) C:\Windows\system32\sl3apo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00871856 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaeapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00836544 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00724728 _____ (DTS, Inc.) C:\Windows\system32\sltech64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00712296 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00663296 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00662784 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00628952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00603984 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00582056 _____ (TOSHIBA Corporation) C:\Windows\system32\tosasfapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00501184 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00487360 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00434960 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00415680 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00315736 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00291488 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00261464 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00246008 _____ (TODO: <Company name>) C:\Windows\system32\slprp64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00241768 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00221024 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00209096 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00162224 _____ (TOSHIBA Corporation) C:\Windows\system32\toseaeapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00141584 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00124176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00109848 _____ () C:\Windows\system32\AcpiServiceVnA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00078688 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00075024 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00065944 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00033592 _____ () C:\Windows\system32\audioLibVc.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2014-10-04 16:34 - 2014-10-04 16:37 - 00000000 _____ () C:\Users\MarcoAdm\sfcdetails.txt
2014-10-04 16:29 - 2014-10-04 16:29 - 00669185 _____ () C:\Users\MarcoAdm\Desktop\CBS.log
2014-10-04 16:29 - 2014-10-04 16:29 - 00000485 _____ () C:\Users\MarcoAdm\Desktop\sfcscannowresults.txt
2014-10-04 11:45 - 2014-10-16 21:57 - 00006170 _____ () C:\Windows\PFRO.log
2014-10-04 10:42 - 2014-10-04 10:42 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Eastman Kodak Company
2014-10-04 10:28 - 2014-10-04 10:28 - 00000000 ____D () C:\Windows\Tasks\TaskDisabled
2014-10-04 10:27 - 2014-10-04 10:27 - 00116216 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-04 10:26 - 2014-10-04 10:53 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\IObit
2014-10-04 10:25 - 2014-10-05 14:13 - 00000000 ____D () C:\Users\Administrator
2014-10-04 10:25 - 2014-10-04 10:25 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-10-04 10:25 - 2013-12-05 21:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Trusteer
2014-10-04 10:25 - 2013-01-18 23:44 - 00000000 ____D () C:\Users\Administrator\AppData\LocalGoogle
2014-10-04 10:25 - 2013-01-18 23:44 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-10-04 10:25 - 2012-07-08 21:27 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia
2014-10-04 10:25 - 2009-01-06 04:00 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Help
2014-10-04 10:25 - 2008-01-20 20:20 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start

Menu\Programs\Maintenance
2014-10-04 10:25 - 2008-01-20 20:20 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start

Menu\Programs\Accessories
2014-10-04 03:52 - 2014-10-15 23:04 - 00000284 _____ () C:\Windows\Tasks\Uninstaller_SkipUac_Administrator.job
2014-10-03 21:58 - 2014-10-03 21:58 - 00000000 ____D () C:\Windows\LastGood.Tmp
2014-10-03 08:40 - 2014-10-03 19:44 - 00010783 _____ () C:\Users\MarcoAdm\Desktop\errors2.txt
2014-10-03 08:27 - 2014-10-10 15:21 - 00000732 _____ () C:\Users\MarcoAdm\AppData\Local\d3d9caps64.dat
2014-10-03 01:10 - 2014-10-03 01:10 - 00001331 _____ () C:\Users\MarcoAdm\Desktop\errors.txt
2014-10-03 00:52 - 2014-10-03 00:52 - 00000165 _____ () C:\Users\MarcoAdm\Documents\errors.txt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-16 22:02 - 2006-11-02 05:46 - 00799602 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-16 21:57 - 2006-11-02 06:33 - 00000000 ____D () C:\Windows\PLA
2014-10-16 21:22 - 2014-08-29 20:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32

\Drivers\MBAMSwissArmy.sys
2014-10-16 09:20 - 2009-08-30 01:04 - 00000000 ____D () C:\Windows\Minidump
2014-10-16 08:46 - 2008-12-03 08:44 - 01622298 _____ () C:\Windows\WindowsUpdate.log
2014-10-15 23:06 - 2010-02-12 09:39 - 00001356 _____ () C:\Users\MarcoAdm\AppData\Local\d3d9caps.dat
2014-10-15 23:04 - 2012-08-16 14:42 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Roaming\Azureus
2014-10-15 23:04 - 2009-02-01 13:47 - 00118784 _____ () C:\Users\MarcoAdm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-

E0D61DEA3FDF.ini
2014-10-11 13:10 - 2006-11-02 06:33 - 00000000 __RHD () C:\Users\Default
2014-10-11 13:06 - 2006-11-02 08:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-11 13:06 - 2006-11-02 08:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-

1.C7483456-A289-439d-8115-601632D005A0
2014-10-11 13:06 - 2006-11-02 08:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-

0.C7483456-A289-439d-8115-601632D005A0
2014-10-10 15:04 - 2014-08-29 20:26 - 00000941 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-10 15:04 - 2014-08-29 20:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes

Anti-Malware
2014-10-10 15:04 - 2014-08-29 20:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-06 02:14 - 2006-11-02 06:33 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-10-06 01:08 - 2012-05-02 19:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-04 17:08 - 2009-02-01 12:46 - 00000000 ____D () C:\Users\MarcoAdm
2014-10-04 17:08 - 2006-11-02 06:33 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-04 17:06 - 2008-10-30 20:07 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2014-10-04 17:06 - 2008-10-30 19:56 - 00006144 _____ () C:\Windows\system32\HdmiCoin.dll
2014-10-04 15:57 - 2012-04-16 23:03 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-04 15:56 - 2008-10-30 19:17 - 00000012 _____ () C:\Windows\bthservsdp.dat
2014-10-04 15:56 - 2006-11-02 08:42 - 00032580 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-04 13:07 - 2009-12-23 23:13 - 00000000 ____D () C:\Windows\pss
2014-10-04 13:06 - 2013-01-06 12:30 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Roaming\Dropbox
2014-10-04 11:50 - 2010-02-09 20:38 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-04 11:42 - 2014-08-30 00:13 - 00002040 _____ () C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2014-10-04 03:43 - 2012-09-26 09:52 - 00002709 _____ () C:\Users\MarcoAdm\Desktop\iBackup Extractor.lnk
2014-10-03 20:59 - 2006-11-02 08:21 - 00408024 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-03 07:59 - 2006-11-02 08:21 - 00046080 _____ () C:\Windows\system32\umstartup.etl
2014-10-02 22:20 - 2014-08-30 00:14 - 00000000 ____D () C:\ProgramData\ProductData
2014-10-02 22:18 - 2014-04-13 15:01 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Local\TB

Some content of TEMP:
====================
C:\Users\MarcoAdm\AppData\Local\Temp\dllnt_dump.dll
C:\Users\MarcoAdm\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpb635ro.dll
C:\Users\MarcoAdm\AppData\Local\Temp\Quarantine.exe
C:\Users\MarcoAdm\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-16 22:15

==================== End Of Log ============================



Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-10-2014
Ran by MarcoAdm at 2014-10-17 00:26:55
Running from C:\Users\MarcoAdm\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be

uninstalled manually.)

 Setup OpenMP (x32 Version: 1.0.0 - Eastmen Kodak Company) Hidden
7-Zip 4.65 (HKLM-x32\...\7-Zip) (Version: v9.20 - TUGUU SL) <==== ATTENTION
Acrobat.com (HKLM-x32\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems

Incorporated)
Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2540 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.4.0.2540 - Adobe Systems Incorporated) Hidden
Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version:  - )
Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Photoshop CS (HKLM-x32\...\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}) (Version: CS - Adobe Systems, Inc.)
Adobe Reader X (10.1.11) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems

Incorporated)
Advanced SystemCare 7 (HKLM-x32\...\Advanced SystemCare 7_is1) (Version: 7.3.0 - IObit)
aiofw (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
aioprnt (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
aioscnnr (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
Alps Pointing-device for VAIO (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version:  - )
ALTools Update (HKLM-x32\...\ALUpdate_is1) (Version: v11.4 - ESTsoft Corp.)
ALZip 8.51 (HKLM-x32\...\ALZip_is1) (Version: v8.51 - ESTsoft Corp.)
Amazon Kindle (HKCU\...\Amazon Kindle) (Version:  - Amazon)
Apple Application Support (HKLM-x32\...\{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}) (Version: 3.0.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft Magic-i Visual Effects 2 (HKLM-x32\...\{7BB90344-0647-468E-925A-7F69F7983421}) (Version: 2.0.1.39 - ArcSoft)
ArcSoft WebCam Companion 2 (HKLM-x32\...\{9973498D-EA29-4A68-BE0B-C88D6E03E928}) (Version:  - ArcSoft)
Aventail Connect (HKLM\...\{C338ACAC-7162-42E3-8B8C-85E5746F4A2E}) (Version: 10.1.95 - SonicWALL Aventail)
Batch PDF Merger (HKLM-x32\...\com.essexreddevelopment.mergepdfmac) (Version: 2.6 - Essex Redevelopment Group)
Batch PDF Merger (x32 Version: 2.6 - Essex Redevelopment Group) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Canon DIGITAL CAMERA Solution Disk Software Guide (HKLM-x32\...\Software Guide) (Version: 1.5.0.1 - Canon Inc.)
CANON iMAGE GATEWAY MyCamera Download Plugin (HKLM-x32\...\MyCamera Download Plugin) (Version: 3.1.1.2 - Canon Inc.)
CANON iMAGE GATEWAY Task for ZoomBrowser EX (HKLM-x32\...\CANON iMAGE GATEWAY Task) (Version: 1.9.0.9 - Canon Inc.)
Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\...\MovieEditTask) (Version: 3.8.0.5 - Canon Inc.)
Canon PowerShot SX230 HS and PowerShot SX220 HS Camera User Guide (HKLM-x32\...\CameraUserGuide-PSSX230HSandPSSX220HS)

(Version: 1.0.1.2 - Canon Inc.)
Canon PowerShot SX280 HS and SX270 HS Camera User Guide (HKLM-x32\...\CameraUserGuide-PSSX280HSandSX270HS) (Version: 1.0.0.1

- Canon Inc.)
Canon RAW Image Task for ZoomBrowser EX (HKLM-x32\...\RAW Image Task) (Version: 0.9.3.9 - Canon Inc.)
Canon Utilities CameraWindow DC 8 (HKLM-x32\...\CameraWindowDC) (Version: 8.10.0.16 - Canon Inc.)
Canon Utilities ImageBrowser EX (HKLM-x32\...\ImageBrowser EX) (Version: 1.4.0.5 - Canon Inc.)
Canon Utilities MyCamera (HKLM-x32\...\MyCamera) (Version: 7.4.0.2 - Canon Inc.)
Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.23.47 - Canon Inc.)
Canon Utilities RemoteCapture Task for ZoomBrowser EX (HKLM-x32\...\RemoteCaptureTask) (Version: 1.7.1.9 - Canon Inc.)
Canon Utilities ZoomBrowser EX (HKLM-x32\...\ZoomBrowser EX) (Version: 6.7.2.33 - Canon Inc.)
center (x32 Version: 3.30.0000.0000 - Eastman Kodak Company) Hidden
Chiavetta Internet MT191UP (HKLM-x32\...\{93D34EE3-99B3-4DB1-8B0A-0A657466F90D}) (Version: 1.0.0.1 - Onda Communication

S.p.a.)
Click to Disc (HKLM-x32\...\{68A69CFF-130D-4CDE-AB0E-7374ECB144C8}) (Version: 1.2.52.09250 - Sony Corporation)
Click to Disc (x32 Version: 1.2.52.09250 - Sony Corporation) Hidden
Click to Disc Editor (HKLM-x32\...\InstallShield_{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}) (Version: 1.2.51 - Sony

Corporation)
Click to Disc Editor (x32 Version: 1.2.51 - Sony Corporation) Hidden
Cloud System Booster (HKLM-x32\...\Cloud System Booster) (Version: 3.4 - Anvisoft)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000

- Microsoft Corporation)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dolby Control Center (HKLM\...\{D035FBF6-FDEF-487D-89CA-6F9DD07B783F}) (Version: 1.2.0702 - Dolby)
Driver Booster (HKLM-x32\...\Driver Booster_is1) (Version: 1.5 - IObit)
Dropbox (HKCU\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.)
EPS Viewer (HKLM-x32\...\{32E05824-A0AC-4DFE-B965-5F52C28FBE9F}_is1) (Version:  - IdeaMK)
ERUNT 1.1j (HKLM-x32\...\ERUNT_is1) (Version:  - Lars Hederer)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Eye-Fi Center 3.4 (HKLM-x32\...\{7764F7B0-7225-4145-82B6-2AB4540D33A6}) (Version: 3.4.26 - Eye-Fi, Inc)
EZSniper Homelink (HKLM-x32\...\{77A1856E-57F6-4C1A-BC89-DBA4F4DF4BA3}) (Version: 1.5 - EZSniper)
FlipBuilder CHM to PDF (HKLM-x32\...\FlipBuilder CHM to PDF  freeware_is1) (Version:  - FlipBuilder Solution)
Google Drive (HKLM-x32\...\{C6640705-7479-4EE5-BC86-879F05F65E74}) (Version: 1.17.7290.4094 - Google, Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google

Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
HandBrake 0.9.9.1 (HKLM-x32\...\HandBrake) (Version: 0.9.9.1 - )
HDAUDIO SoftV92 Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200) (Version:  - )
HP Deskjet 3050A J611 series Basic Device Software (HKLM\...\{FB555BCF-9202-4886-9203-88C9A210D727}) (Version: 25.0.571.0 -

Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Help (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett

Packard)
HP Deskjet 3050A J611 series Product Improvement Study (HKLM\...\{710D4D91-1924-4A6B-8659-9CDE02DC7207}) (Version:

25.0.571.0 - Hewlett-Packard Co.)
I.R.I.S. Desktop Search (HKLM-x32\...\I.R.I.S. Desktop Search) (Version:  - I.R.I.S S.A)
iBackup Extractor (HKLM-x32\...\{29B35C59-53AA-4893-A233-79CEDF7D1494}) (Version: 1.4.0 - Wide Angle Software)
iCloud (HKLM\...\{CE97E4D3-9F91-4D72-8A29-ED9EA90E5A15}) (Version: 2.1.3.25 - Apple Inc.)
iExplorer 3.1.0.1 (HKLM-x32\...\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant LLC)
ImageMixer 3 SE Ver.3 (HKLM-x32\...\{3A95D49D-0076-4DB7-A91E-0E685DC6D6AD}) (Version: 3.01.012 - PIXELA)
Intel PROSet Wireless (Version:  - ) Hidden
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version:  - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{52A7C6A6-6B88-47D1-922E-9F8A7E089E6A}) (Version: 12.01.1000 - Intel®

Corporation)
IObit Malware Fighter (HKLM-x32\...\IObit Malware Fighter_is1) (Version: 2.4 - IObit)
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 3.2.10.2466 - IObit)
iPhone Backup Extractor (HKLM-x32\...\iPhoneBackupExtractor) (Version: 4.0.4.0 - Reincubate Ltd)
iPhoneSMSExport (HKLM-x32\...\iPhoneSMSExport) (Version:  - )
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.27 - Irfan Skiljan)
iTunes (HKLM\...\{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}) (Version: 11.3.0.54 - Apple Inc.)
Java 7 Update 9 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417009FF}) (Version: 7.0.90 - Oracle)
Java 7 Update 9 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden
KODAK All-in-One Printer Software (HKLM-x32\...\{E0F274B7-592B-4669-8FB8-8D9825A09858}) (Version: 3.30.0.0 - Eastman Kodak

Company)
KODAK Capture Pro Software - Trial Edition (x32 Version: 3.0.0 - Eastman Kodak Company) Hidden
Kodak Capture Software for iSeries scanners (HKLM-x32\...\XVCS6C) (Version:  - )
KODAK i1210/i1220 Scanner (HKLM-x32\...\KODAK i1210/i1220 Scanner) (Version: 3.33 - )
ksDIP (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 -

Malwarebytes Corporation)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft

Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Office 2000 SR-1 Professional (HKLM-x32\...\{00010409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.9327 -

Microsoft Corporation)
Microsoft Office 2007 Primary Interop Assemblies (HKLM-x32\...\{50120000-1105-0000-0000-0000000FF1CE}) (Version:

12.0.4518.1014 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version:

12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118})

(Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 -

Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 -

Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-

E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989})

(Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F})

(Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version:

10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version:

10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime

(x64)) (Version: 10.0.50701 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.50706 - Microsoft Corporation) Hidden
Microsoft Works (HKLM-x32\...\{67E03279-F703-408F-B4BF-46B5FC8D70CD}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 32.0.3 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 32.0.3 (x86 en-US)) (Version: 32.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft

Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft

Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft

Corporation)
Music Transfer (HKLM-x32\...\{CE2121C6-C94D-4A73-8EA4-6943F33EE335}) (Version: 1.2.00.17290 - Sony Corporation)
OpenMG Secure Module 5.1.00 (HKLM-x32\...\InstallShield_{C1083DBC-C541-4E8C-91EA-D92397AB9A2C}) (Version: 5.1.00.05200 -

Sony Corporation)
OpenMG Secure Module 5.1.00 (x32 Version: 5.1.00.05200 - Sony Corporation) Hidden
PamFax (HKLM-x32\...\{6432B21C-CA95-46CA-87D4-178CC2E58F84}_is1) (Version: 3.4.6.11 - Scendix Software GmbH)
PamFax Office Integration (x32 Version: 1.0.2 - Scendix Software GmbH) Hidden
PDFill PDF Editor with FREE Writer and FREE Tools (HKLM\...\{D1399216-81B2-457C-A0F7-73B9A2EF6902}) (Version: 9.0 - PlotSoft

LLC)
Pegasus Mail HTML Renderer 2.4.7.2 (HKLM-x32\...\{A9F5E1E1-1281-4862-90B4-6CF8E6AF83CE}_is1) (Version:  - Micha's Midnight

Manufacture)
Pinnacle Instant DVD Recorder (HKLM-x32\...\{C1212AE3-DBB9-4365-8473-F8ABC7B06BBB}) (Version: 2.6.0.118 - Pinnacle Systems)
Pinnacle Studio 12 (HKLM-x32\...\{D041EB9E-890A-4098-8F94-51DA194AC72A}) (Version: 12.1.3.6605 - Pinnacle Systems)
Pinnacle Video Driver (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.029 - Pinnacle Systems)
PIXELA AAC LC CODEC (HKLM-x32\...\PIXELA AAC LC CODEC) (Version: 1.1.0.1 - Canon Inc.)
PowerOffer 2.0 (HKLM-x32\...\{0B500125-92A7-40BF-ACF0-45A9221ADE21}_is1) (Version: 2.0 - )
PreReq (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
Primo (x32 Version: 1.00.0000 - Your Company Name) Hidden
QuickBooks Simple Start 2009 (HKLM-x32\...\{9A2F0810-3619-4E86-9072-973FBE1679C5}) (Version: 19.0.4001.703 - Intuit Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Rampant Logic Postscript Viewer 1.1 (HKLM-x32\...\{39C4C6DE-641B-483F-B875-2AEDF0FB85CA}_is1) (Version:  - Rampant Logic)
Rapport (x32 Version: 3.5.1307.109 - Trusteer) Hidden
Readiris Pro 11 Corporate Edition (HKLM-x32\...\{2B6E0003-45D0-4751-83AD-2D053A61B88E}) (Version: 11.00.4824 - I.R.I.S.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek

Semiconductor Corp.)
Regi (Version: 1.00.0000 - InterVideo Inc.) Hidden
Roxio Central Audio (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Copy (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Core (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Data (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Central Tools (x32 Version: 3.7.0 - Roxio) Hidden
Roxio Easy Media Creator 10 LJ (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.1 - Roxio)
Roxio Easy Media Creator Home (x32 Version: 10.1.296 - Roxio) Hidden
ScanWiz (HKLM-x32\...\ScanWiz) (Version: 2.50 - Softi Software)
Segoe UI (x32 Version: 15.4.2271.0615 - Microsoft Corp) Hidden
Setting Utility Series (HKLM-x32\...\{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}) (Version: 4.2.0.10150 - Sony Corporation)
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.2.10687 - Skype Technologies S.A.)
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Smart Defrag 3 (HKLM-x32\...\Smart Defrag 3_is1) (Version: 3.2 - IObit)
Sony Picture Utility (HKLM-x32\...\{D5068583-D569-468B-9755-5FBF5848F46F}) (Version: 3.3.01.09300 - Sony Corporation)
Sony Video Shared Library (HKLM-x32\...\{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}) (Version: 3.5.00 - Sony Corporation)
Spyder2express (HKLM-x32\...\Spyder2express) (Version:  - )
StreamFree version 1.0 (HKLM-x32\...\{91456E40-04E4-4B21-BA1C-8BC32646F2CA}_is1) (Version: 1.0 - Streammy.net)
SupportSoft Assisted Service (HKLM-x32\...\{5A3F6A80-7913-475E-8B96-477A952CFA43}) (Version: 15 - SupportSoft)
Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.0 - IObit)
System Requirements Lab for Intel (HKLM-x32\...\{CD41B576-4787-4D5C-95EE-24A4ABD89CD3}) (Version: 4.4.24.0 - Husdawg, LLC)
TD AMERITRADE StrategyDesk 3.1 (HKCU\...\{34E78C00-BBEE-4942-A5A2-91DCF3DCBF4C}) (Version: 3.1 - TD AMERITRADE)
TD AMERITRADE StrategyDesk 3.4_2 (C:\Users\MarcoAdm\AppData\Roaming\TD AMERITRADE\StrategyDesk) (HKCU\...\{0E791D90-FA4B-

46CF-B0E6-F89C2F490843}) (Version: 3.4 - TD AMERITRADE)
The Rosetta Stone (HKLM-x32\...\The Rosetta Stone) (Version:  - )
thinkorswim from TD AMERITRADE (HKLM-x32\...\thinkorswim from TD AMERITRADE) (Version:  - TD AMERITRADE, Inc.)
Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1307.109 - Trusteer)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707)

(Version: 1 - Microsoft Corporation)
VAIO Care (HKLM-x32\...\{36C5BBF0-E5BF-4DE1-B684-7E90B0C93FB5}) (Version: 3.0.0.0423 - Sony)
VAIO Content Folder Setting (HKLM-x32\...\{23825B69-36DF-4DAD-9CFD-118D11D80F16}) (Version: 2.1.0.08260 - Sony Corporation)
VAIO Content Folder Watcher (HKLM-x32\...\{327B75F0-92AF-420A-988F-FA596A218E0B}) (Version: 1.0.01.09030 - Sony Corporation)
VAIO Content Folder Watcher (x32 Version: 1.0.01.09030 - Sony Corporation) Hidden
VAIO Content Metadata Intelligent Analyzing Manager (HKLM-x32\...\{ECB5774A-A39B-4419-A7D3-92F49C0FCAB3}) (Version:

3.3.0.10012 - Sony Corporation)
VAIO Content Metadata Intelligent Analyzing Manager (x32 Version: 3.3.0.10012 - Sony Corporation) Hidden
VAIO Content Metadata Manager Setting (HKLM-x32\...\{EADE97A7-E7AA-43FD-A042-92A68E0187A6}) (Version: 3.3.0.09300 - Sony

Corporation)
VAIO Content Metadata Manager Setting (x32 Version: 3.3.0.09300 - Sony Corporation) Hidden
VAIO Content Metadata XML Interface Library (HKLM-x32\...\{E3453B1B-C91B-4C48-B046-8DF635DD46F2}) (Version: 3.3.0.09182 -

Sony Corporation)
VAIO Content Metadata XML Interface Library (x32 Version: 3.3.0.09182 - Sony Corporation) Hidden
VAIO Control Center (HKLM-x32\...\{72042FA6-5609-489F-A8EA-3C2DD650F667}) (Version: 3.2.0.09120 - Sony Corporation)
VAIO Data Restore Tool (HKLM-x32\...\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}) (Version: 1.0.04.01170 - Sony Corporation)
VAIO DVD Menu Data Basic (HKLM-x32\...\{596BED91-A1D8-4DF1-8CD1-1C777F7588AC}) (Version: 1.0.00.08130 - Sony Corporation)
VAIO Entertainment Platform (HKLM-x32\...\{6B1F20F2-6321-4669-A58C-33DF8E7517FF}) (Version: 3.2.3.10070 - Sony Corporation)
VAIO Entertainment Platform (x32 Version: 3.2.3.10070 - Sony Corporation) Hidden
VAIO Event Service (HKLM-x32\...\{C7477742-DDB4-43E5-AC8D-0259E1E661B1}) (Version: 4.2.0.10172 - Sony Corporation)
VAIO Help and Support (HKLM-x32\...\{D47FE987-EA3D-424B-9886-B752501D7CE7}) (Version: 7.00.1023.FW - Sony Corporation)
VAIO Launcher (HKLM-x32\...\{15D5C238-4C2E-4AEA-A66D-D6989A4C586B}) (Version: 2.2.0.09090 - Sony Corporation)
VAIO Media plus (HKLM-x32\...\{8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD}) (Version: 1.2.0.10230 - Sony Corporation)
VAIO Media plus (x32 Version: 1.2.0.10230 - Sony Corporation) Hidden
VAIO Media plus Opening Movie (HKLM-x32\...\{6BF03C88-C06A-48DC-B9A1-FE72B24E5FA9}) (Version: 1.2.0.09050 - Sony

Corporation)
VAIO Movie Story (HKLM-x32\...\{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3}) (Version: 1.3.01.08060 - Sony Corporation)
VAIO Movie Story (x32 Version: 1.3.01.08060 - Sony Corporation) Hidden
VAIO Movie Story Template Data (HKLM-x32\...\{6FA8BA2C-052B-4072-B8E2-2302C268BE9E}) (Version: 1.3.00.06120 - Sony

Corporation)
VAIO MusicBox (HKLM-x32\...\{4EA55D20-27FB-45D7-8726-147E8A5F6C62}) (Version: 2.1.1.09160 - Sony Corporation)
VAIO MusicBox Sample Music (HKLM-x32\...\{98FC7A64-774B-49B5-B046-4B4EBC053FA9}) (Version: 1.1.00.14140 - Sony Corporation)
VAIO My Memory Center (HKLM-x32\...\{72B5983C-80C7-4225-BA72-E92AE1D59C62}) (Version: 2.00.1029 - Sony)
VAIO OOBE and Welcome Center (HKLM-x32\...\{1B500D37-E7CF-480B-8054-8A563594EC4E}) (Version: 7.00.1022.US - Sony

Corporation)
VAIO Original Function Setting (HKLM-x32\...\{A63E7492-A0BC-4BB9-89A7-352965222380}) (Version: 1.5.00.08150 - Sony

Corporation)
VAIO Power Management (HKLM-x32\...\{5F5867F0-2D23-4338-A206-01A76C823924}) (Version: 3.2.0.10200 - Sony Corporation)
VAIO Presentation Support (HKLM-x32\...\{2018C019-30D9-4240-8C01-0865C10DCF5A}) (Version: 1.1.0.08250 - Sony Corporation)
VAIO Startup Assistant (HKLM-x32\...\{DFD0E9A9-F24A-492B-8975-8C938E32408F}) (Version: 4.00.1030 - Sony)
VAIO Survey (HKLM-x32\...\{34B37A74-125E-4406-87BA-E4BD3D097AE5}) (Version: 6.00.0722 - Sony Corporation)
VAIO Update 4 (HKLM-x32\...\{83CDA18E-0BF3-4ACA-872C-B4CDABF2360E}) (Version: 4.0.0.08280 - Sony Corporation)
VAIO Wallpaper Contents (HKLM-x32\...\{D60F97EC-EF06-4E1E-B0D1-C2CBABA62FA3}) (Version: 1.3.0.10310 - Sony Corporation)
VAIO Wireless Wizard (HKLM-x32\...\{BCED773C-99EE-48DD-8915-25733F69F0A8}) (Version: 2.00.1013 - Sony)
Virtual Account Numbers (HKLM-x32\...\{DE700910-58F7-4D2E-B7E6-3BA2DA1B6806}) (Version: 4.0.0.2248 - Citi)
Virtual Account Numbers (x32 Version: 1.0.6.0 - Citi) Hidden
VLC media player 2.1.1 (HKLM-x32\...\VLC media player) (Version: 2.1.1 - VideoLAN)
Vodafone Mobile Broadband Lite (HKLM-x32\...\{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}) (Version: 10.1.001.26030 - Vodafone)
WebEx (HKCU\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
WIDCOMM Bluetooth Software 6.2.0.5800 (HKLM\...\{E464702F-5433-46EC-8F65-159276C0A54F}) (Version: 6.2.0.5800 - Broadcom

Corporation)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4040.0 - Microsoft Corporation)
WinDVD BD for VAIO (HKLM-x32\...\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}) (Version: 8.0-B9.617 - InterVideo

Inc.)
WinDVD BD for VAIO (x32 Version: 8.0-B9.617 - InterVideo Inc.) Hidden
Wisdom-soft ScreenHunter 6.0 Free (HKLM-x32\...\Wisdom-soft ScreenHunter 6.0 Free) (Version:  - Wisdom Software Inc.)
Xmarks for IE (HKLM-x32\...\{C56BBAC8-0DD2-4CE4-86E0-F2BDEABDD0CF}) (Version: 127.0.160 - Xmarks)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 05:34 - 2012-09-30 00:57 - 00000815 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to

be moved.)

Task: {060248CA-77FF-4763-A21B-C6045EFD30C0} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update =>

c:\program files\windows defender\MpCmdRun.exe [2008-01-20] (Microsoft Corporation)
Task: {09A73C34-67D3-4CBE-8B3B-0AAF4665BF5C} - \3317973412 No Task File <==== ATTENTION
Task: {0A3728E9-CA29-4C78-938F-48757519B047} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)

\Google\Update\GoogleUpdate.exe [2010-02-09] (Google Inc.)
Task: {0A532475-EED2-4697-AC39-84B312331EA8} - \3571684936 No Task File <==== ATTENTION
Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {13223012-D97F-4A0C-9355-D2CE7CB72C79} - System32\Tasks\{0E6E1FE2-D011-4701-B643-333F59F4BE23} => Firefox.exe

http://ui.skype.com/ui/0/5.0.0.156.217/en/abandoninstall?page=tsChrome&installinfo=google-

toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {13A118FD-1C23-4824-9B2C-02E9F07A97F6} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)

\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-05-06] (IObit)
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {1A4B5E64-428A-4F0E-AD22-7EEE77FCA626} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)

\Google\Update\GoogleUpdate.exe [2010-02-09] (Google Inc.)
Task: {1E67769F-969F-4D33-B3A8-43A7FE74B1ED} - System32\Tasks\Driver Booster SkipUAC (MarcoAdm) => C:\Program Files (x86)

\IObit\Driver Booster\DriverBooster.exe [2014-08-06] (IObit)
Task: {24AFC1A3-2E42-4F90-BAED-2F435DE39F40} - System32\Tasks\{897DAE3D-6DA8-4F43-91F2-BC1E96A31D56} => Firefox.exe

http://ui.skype.com/ui/0/5.5.0.119.217/en/abandoninstall?page=tsChrome&installinfo=google-

toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32

\RacAgent.exe [2008-01-20] (Microsoft Corporation)
Task: {2CE9EA3C-CCFA-40EB-879B-21E8AFCCE417} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver

Booster\Scheduler.exe [2014-08-01] (IObit)
Task: {2E0780AB-0A4C-44E6-9C96-61A1471745E5} - System32\Tasks\HPCustParticipation HP Deskjet 3050A J611 series => C:\Program

Files\HP\HP Deskjet 3050A J611 series\Bin\HPCustPartic.exe [2011-06-08] (Hewlett-Packard Co.)
Task: {36B96A32-2368-4D87-8018-7BCEA8006738} - System32\Tasks\ASC7_PerformanceMonitor => C:\Program Files (x86)

\IObit\Advanced SystemCare 7\Monitor.exe [2014-05-06] (IObit)
Task: {39ED30B1-778B-47C8-BD64-F4E66483D71F} - System32\Tasks\SONY\VAIO Wallpaper Setting Tool\VAIO Wallpaper Setting Tool

=> C:\Program Files (x86)\Sony\VAIO Wallpaper Setting Tool\VWSet.exe [2008-06-27] (Sony Corporation)
Task: {3EF12406-33CF-49AF-90FE-F0F379DD7335} - System32\Tasks\SmartDefrag3_Startup => C:\Program Files (x86)\IObit\Smart

Defrag 3\SmartDefrag.exe [2014-07-02] (IObit)
Task: {440F8681-07BF-43D0-B43F-954C74802C0A} - System32\Tasks\{A2E22F8B-C51A-48C1-AA0F-429EA91D7DE3} => C:\Program Files

(x86)\Skype\Phone\Skype.exe [2014-02-10] (Skype Technologies S.A.)
Task: {48D572FE-81C9-405B-92DA-AD3CC5DB6F60} - System32\Tasks\Microsoft\Windows\RestartManager\{BB219F1A-5B5E-478f-9748-

64B36FC902EE} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation)
Task: {525FBAB3-402C-49F8-A3BA-786D663B627A} - System32\Tasks\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe

[2009-04-29] (Sony Electronics, Inc.)
Task: {5B4710E9-A4BF-4746-8B38-68EF93339466} - System32\Tasks\SmartDefrag3_Update => C:\Program Files (x86)\IObit\Smart

Defrag 3\AutoUpdate.exe [2014-07-03] (IObit)
Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {8FE20A46-31A2-41EA-BE78-BC4E4B4DBC46} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64

\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09] (Adobe Systems Incorporated)
Task: {94C1CEED-29B2-492B-B61B-A99C89DFC581} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver

Booster\AutoUpdate.exe [2014-08-01] (IObit)
Task: {BB33618C-785C-4294-9BAE-268588F20D7C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple

Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {CFCEF2EB-DA61-4153-96B6-AB83E4941E91} - System32\Tasks\thpm4895375420692929156 =>

\\.\globalroot\Device\HarddiskVolume2\Users\MarcoAdm\AppData\Local\Temp\thpm4895375420692929156.tmp <==== ATTENTION
Task: {E3821242-ACE8-49ED-938D-A5040EB7254B} - System32\Tasks\ASC7_SkipUac_MarcoAdm => C:\Program Files (x86)\IObit\Advanced

SystemCare 7\ASC.exe [2014-05-04] (IObit)
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo =>

C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-20] ()
Task: {E9FBECD8-090B-421A-9360-ED94E212EF8B} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32

\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {F1D3DAA2-D4DC-45CA-A154-3252C0D354B8} - System32\Tasks\SONY\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO

Update 4\VAIOUpdt.exe [2008-08-28] (Sony Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Uninstaller_SkipUac_Administrator.job => C:\Program Files (x86)\IObit\IObit

Uninstaller\IObitUninstaler.exe

==================== Loaded Modules (whitelisted) =============

2013-10-31 13:47 - 2013-10-31 13:47 - 00954696 _____ () C:\Program Files\Common Files\Apple\Internet

Services\ShellStreams64.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:E1268B2C

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Aventail VPN Connection.lnk =>

C:\Windows\pss\Aventail VPN Connection.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ImageMixer 3 SE Camera Monitor

Ver.3.lnk => C:\Windows\pss\ImageMixer 3 SE Camera Monitor Ver.3.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk =>

C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Network Server.lnk =>

C:\Windows\pss\Network Server.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk =>

C:\Windows\pss\QuickBooks Update Agent.lnk.CommonStartup
MSCONFIG\startupreg: Citi Virtual Account Numbers => C:\PROGRA~2\VIRTUA~1\CitiVAN.exe /lang=en_RG /dontopenmycards
MSCONFIG\startupreg: Intuit SyncManager => C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup
MSCONFIG\startupreg: IObit Malware Fighter => "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
MSCONFIG\startupreg: PosService =>
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RtHDVCpl => RAVCpl64.exe
MSCONFIG\startupreg: Skytel => Skytel.exe
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: VAIORegistration => "C:\Program Files\Sony\First Experience\WelcomeLauncher.exe"
MSCONFIG\startupreg: VAIOSurvey => "C:\Program Files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-1683370733-2581893643-414232939-500 - Administrator - Enabled) => C:\Users\Administrator
Guest (S-1-5-21-1683370733-2581893643-414232939-501 - Limited - Disabled) => C:\Users\Guest
MarcoAdm (S-1-5-21-1683370733-2581893643-414232939-1001 - Administrator - Enabled) => C:\Users\MarcoAdm

==================== Faulty Device Manager Devices =============

Name: Realtek High Definition Audio
Description: Realtek High Definition Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: IntcAzAudAddService
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow

the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/16/2014 10:02:09 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1".Error in manifest or policy file

"C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" on line

C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error: (10/16/2014 10:02:02 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1".Error in manifest or policy file

"C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" on line

C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error: (10/16/2014 10:01:57 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest1".Error in manifest or policy file

"C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest2" on line

C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error: (10/16/2014 09:59:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for

"msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/16/2014 09:59:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for

"msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/16/2014 09:59:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for

"msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/16/2014 09:59:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for

"msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/16/2014 09:59:16 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for

"msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/16/2014 09:59:16 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for

"msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/16/2014 09:59:16 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for

"msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.


System errors:
=============
Error: (10/16/2014 09:59:55 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: PnP-X IP Bus EnumeratorFunction Discovery Provider Host%%1068

Error: (10/16/2014 09:58:54 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: DMICall
MpFilter
spldr
Wanarpv6

Error: (10/16/2014 09:58:54 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Microsoft Network Inspection SystemMicrosoft Malware Protection Driver%%31

Error: (10/16/2014 09:58:54 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Computer BrowserServer%%1068

Error: (10/16/2014 09:58:46 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (10/16/2014 09:58:25 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084EventSystem{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (10/16/2014 09:58:13 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: C:\Windows\System32\IWMSSvc.dll21

Error: (10/16/2014 09:58:13 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084ShellHWDetection{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (10/16/2014 09:52:35 PM) (Source: Dhcpv6) (EventID: 1000) (User: )
Description: Your computer has lost the lease to its IP address &Ç░ó` on the Network Card with network address

00215DD34934.

Error: (10/16/2014 09:17:08 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: PnP-X IP Bus EnumeratorFunction Discovery Provider Host%%1068


Microsoft Office Sessions:
=========================
Error: (10/16/2014 10:02:09 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.com

mon-

controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifestC:\Users\MarcoAdm\Desktop\esetsmartinstaller_enu.exe

Error: (10/16/2014 10:02:02 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.com

mon-

controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifestC:\Users\MarcoAdm\Desktop\esetsmartinstaller_enu.exe

Error: (10/16/2014 10:01:57 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-

controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.com

mon-

controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifestC:\Users\MarcoAdm\Downloads\esetsmartinstaller_enu.ex

e

Error: (10/16/2014 09:59:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F

-B4BF-46B5FC8D70CD}\WksWP.exe

Error: (10/16/2014 09:59:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F

-B4BF-46B5FC8D70CD}\WksWP.exe

Error: (10/16/2014 09:59:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F

-B4BF-46B5FC8D70CD}\wksss.exe

Error: (10/16/2014 09:59:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F

-B4BF-46B5FC8D70CD}\wksss.exe

Error: (10/16/2014 09:59:16 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F

-B4BF-46B5FC8D70CD}\wksdb.exe

Error: (10/16/2014 09:59:16 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F

-B4BF-46B5FC8D70CD}\wksdb.exe

Error: (10/16/2014 09:59:16 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{67E03279-F703-408F

-B4BF-46B5FC8D70CD}\WksCal.exe


CodeIntegrity Errors:
===================================
  Date: 2014-10-17 00:26:08.430
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files

(x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-17 00:26:08.196
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files

(x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-17 00:26:07.962
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files

(x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-17 00:26:07.728
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files

(x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-17 00:26:07.447
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files

(x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-17 00:26:07.213
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files

(x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-17 00:26:06.979
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files

(x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-17 00:26:06.745
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files

(x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-17 00:26:06.246
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32

\drivers\RapportKE64.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-17 00:26:06.012
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32

\drivers\RapportKE64.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel® Core2 Duo CPU P8600 @ 2.40GHz
Percentage of memory in use: 30%
Total physical RAM: 3934.11 MB
Available physical RAM: 2753.36 MB
Total Pagefile: 8073.48 MB
Available Pagefile: 7140.54 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:222.39 GB) (Free:59.16 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.9 GB) (Disk ID: 808E8887)
Partition 1: (Not Active) - (Size=10.5 GB) - (Type=27)
Partition 2: (Active) - (Size=222.4 GB) - (Type=07 NTFS)

==================== End Of Log ============================




Regards,
Marco

Link to post
Share on other sites

No signs of infection were detected by running again MBAM, Jrt and AdwCleaner.

However the computer still shows the same problem: when I boot in normal mode, it freezes completely after a couple of minutes.

I guess the problem is more serious than I expected. Can it be that the malware corrupted the OS?

 

One detail: the event viewer shows many errors, but the first one seems to be "\SystemRoot\SysWow64\DRIVERS\DMICall.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver."

Link to post
Share on other sites

  • Root Admin

That is normal. The file is probably very old not supported on newer Windows.

SystemRoot\SysWow64\DRIVERS\DMICall.sys

We can try to run some other scans and fixes but it might be best to backup your data and do a Factory Restore or reinstall Windows.

Please read the following and let me know what you'd like to do

The complexity of finding, preventing, and cleanup from malware

Link to post
Share on other sites

Definitely reinstalling Windows is an option at this point, but I would still like to try a few things before that.

 

A question: I backed up my data by copying C:\Users\Marco into an external hard drive before we started the whole cleaning procedure. If I use these data after reinstalling Windows, do I run the risk of reinfecting the system again? Do I need to perform the same sequence of steps that you told me on that external hard drive before using the data?

 

There are some new things to report:

 

1) I found a blog entry from July 2009 in which a user was reporting exactly my same issue: same computer (Sony Vaio), same OS (Vista Home Premium 64bit), same exact freezing issue after a few minutes in normal mode with no problems in safe mode, and same error message concerning C:\Windows\SysWOW64\drivers\DMICall.sys. It doesn't seem that back then a resolution was found, but maybe it's a documented issue somewhere. The blog entry is http://www.bleepingcomputer.com/forums/t/245832/windows-vista-64-freezes/

 

2) I was finally able to run a couple of the tools you suggested (FarBar and Rkill) with the computer in normal mode before it froze. The logs appear different from those I got in safe mode. I am copying them below, maybe they give us some more clues.

 

Rkill 2.6.8 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 10/22/2014 05:27:53 PM in x64 mode.
Windows Version: Windows Vista Home Premium Service Pack 2

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * Security Center (wscsvc) is not Running.
   Startup Type set to: Automatic (Delayed Start)

 * Windows Update (wuauserv) is not Running.
   Startup Type set to: Automatic (Delayed Start)

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * HOSTS file entries found:

  127.0.0.1       localhost
  ::1             localhost

Program finished at: 10/22/2014 05:36:21 PM
Execution time: 0 hours(s), 8 minute(s), and 28 seconds(s)
 

 

########################################

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-10-2014
Ran by MarcoAdm (administrator) on SONYLAPTOP on 22-10-2014 17:17:25
Running from C:\Users\MarcoAdm\Desktop
Loaded Profile: MarcoAdm (Available profiles: MarcoAdm & Administrator & Guest)
Platform: Windows Vista Home Premium Service Pack 2 (X64) OS Language: English (United States)
Internet Explorer Version 9
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag 3\AutoUpdate.exe
(IObit) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Wallpaper Setting Tool\VWSet.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\VESWinlogon-x32: VESWinlogon.dll [X]
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\MountPoints2: {0704b6c6-eef6-11e1-b785-8c87dfc73970} - F:\LaunchU3.exe -a
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\MountPoints2: {69fcf01f-e7d4-11e1-8e88-806e6f6e6963} - F:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1683370733-2581893643-414232939-1001\...\MountPoints2: {b2d1a024-e7d0-11e1-9396-d07ffd9f2f6d} - F:\setup_vmb_lite.exe /checkApplicationPresence
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=SNYR&bmod=SNYR
StartMenuInternet: IEXPLORE.EXE - %ProgramFiles(x86)%\Internet Explorer\iexplore.exe
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Virtual Account Numbers Helper -> {17424104-1444-4810-85D7-B4DA413C5A9A} -> C:\Program Files (x86)\Virtual Account Numbers\CitiVANHelper.dll (Orbiscom Ltd. All rights reserved.)
BHO-x32: CitiUSBrowserHelper Class -> {387EDF53-1CF2-4523-BC2F-13462651BE8C} -> C:\Program Files (x86)\Virtual Account Numbers\BhoCitUS.dll (Orbiscom Ltd. All rights reserved.)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Advanced SystemCare Browser Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - I.R.I.S. Desktop Search - {577EBCA9-8ED3-45FC-A514-55B3817D4BCF} - C:\Program Files (x86)\IRIS Desktop Search\IRISDesktopSearchIntegration910.dll (Copernic Technologies Inc.)
Toolbar: HKLM-x32 - Virtual Account Numbers - {7A21A046-B886-4A62-9D69-EF2059B0A27B} - C:\Program Files (x86)\Virtual Account Numbers\CitiVANToolbar.dll (Orbiscom Ltd. All rights reserved.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU - I.R.I.S. Desktop Search - {577EBCA9-8ED3-45FC-A514-55B3817D4BCF} -  No File
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} -  No File
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} -  No File
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} -  No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{2A73429A-B03C-4F88-ABAF-48B0629EA399}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{2BF03E76-37A1-4EB0-867B-923862A5E1AA}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{83228AEC-D667-4A75-AC1E-483C1216EBA5}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{C2F38D47-8F48-4FFF-9C21-3B5EA2894EFB}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{FC077840-0E7B-4E6C-9460-0DB6F45F914E}: [NameServer] 8.8.8.8,8.8.4.4

FireFox:
========
FF ProfilePath: C:\Users\MarcoAdm\AppData\Roaming\Mozilla\Firefox\Profiles\56wx6ubw.default-1399854068777
FF Homepage: www.google.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/MycameraPlugin -> C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: tdameritrade.com/thinkorswim -> C:\Program Files (x86)\thinkTDA\npthinkorswim.dll (TD Ameritrade)
FF Plugin HKCU: tdameritrade.com/tossc -> C:\Program Files (x86)\thinkTDA\nptossc.dll (TD Ameritrade)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\MarcoAdm\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\MarcoAdm\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\MarcoAdm\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\MarcoAdm\AppData\Roaming\Mozilla\Firefox\Profiles\56wx6ubw.default-1399854068777\Extensions\ascsurfingprotection@iobit.com [2014-08-30]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-10-05]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-04-15]
FF HKLM-x32\...\Firefox\Extensions: [citius@orbiscom] - C:\Program Files (x86)\Virtual Account Numbers
FF Extension: Virtual Account Numbers for Firefox - C:\Program Files (x86)\Virtual Account Numbers [2009-04-05]
FF Extension: No Name - C:\Program Files (x86)\IObit Apps Toolbar\FF [Not Found]

Chrome:
=======
CHR HomePage: Default -> hxxp://search.conduit.com/?ctid=CT2504091&SearchSource=48&CUI=UN52017086324385214&UM=2
CHR StartupUrls: Default -> "hxxp://search.conduit.com/?ctid=CT2504091&SearchSource=48&CUI=UN52017086324385214&UM=2"
CHR Profile: C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd [2014-09-03]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-29]
CHR Extension: (Google Wallet) - C:\Users\MarcoAdm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-14]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S4 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2012-07-04] () [File not signed]
S4 EvtEng; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [1449984 2008-08-20] (Intel® Corporation) [File not signed]
S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
S4 KodakSvc; C:\Program Files (x86)\Kodak\AiO\center\KodakSvc.exe [38296 2009-01-19] (Eastman Kodak Company)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S4 MSCSPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [53248 2008-05-20] (Sony Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S4 NgVpnMgr; C:\Windows\system32\ngvpnmgr.exe [424984 2009-06-04] (Aventail Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
S4 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [53248 2008-05-20] (Sony Corporation) [File not signed]
S4 PowerOffer Service; C:\Users\MarcoAdm\AppData\Local\PosService\Pos.exe [164352 2011-12-16] (PowerOfferService) [File not signed]
S4 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [24576 2008-09-10] (Intuit) [File not signed]
S4 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [61440 2008-08-08] (Intuit Inc.) [File not signed]
S4 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1886488 2014-07-10] (Trusteer Ltd.)
S4 RegSrvc; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [826368 2008-08-20] (Intel® Corporation) [File not signed]
S4 RtkAudioService; C:\Windows\RtkAudioService.exe [134656 2008-10-17] (Realtek Semiconductor) [File not signed]
S4 SOHCImp; C:\Program Files (x86)\Sony\VAIO Media plus\SOHCImp.exe [103712 2008-10-21] (Sony Corporation)
S4 SOHDms; C:\Program Files (x86)\Sony\VAIO Media plus\SOHDms.exe [353568 2008-10-21] (Sony Corporation)
S4 SOHDs; C:\Program Files (x86)\Sony\VAIO Media plus\SOHDs.exe [62752 2008-10-21] (Sony Corporation)
S4 SPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe [77824 2008-05-20] (Sony Corporation) [File not signed]
S4 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S4 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [73728 2008-09-08] (Sony Corporation) [File not signed]
S4 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [446464 2008-09-03] (Sony Corporation) [File not signed]
S4 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [279848 2008-09-08] (Sony Corporation)
S4 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [8704 2010-09-08] (Vodafone) [File not signed]
S4 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2008-09-08] (Sony Corporation) [File not signed]
S2 SampleCollector; No ImagePath

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2008-04-24] (ArcSoft, Inc.)
R3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
S1 DMICall; C:\Windows\SysWow64\Drivers\DMICall.sys [10216 2008-08-22] (Sony Corporation)
U3 Ehtssvcietle_; No ImagePath
S3 IpInIp; No ImagePath
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-10-20] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NgFilter; C:\Windows\System32\DRIVERS\ngfilter.sys [25624 2009-06-04] (Aventail Corporation)
S3 NgLog; C:\Windows\System32\DRIVERS\nglog.sys [31256 2009-06-04] (Aventail Corporation)
R3 NgVpn; C:\Windows\System32\DRIVERS\ngvpn.sys [102424 2009-06-04] (Aventail Corporation)
S3 NgWfp; C:\Windows\System32\DRIVERS\ngwfp.sys [28696 2009-06-04] (Aventail Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 NwlnkFlt; No ImagePath
S3 NwlnkFwd; No ImagePath
S3 ONDAusbmdm6k; C:\Windows\System32\DRIVERS\ONDAusbmdm6k.sys [119680 2010-09-02] (Onda Communication)
S3 ONDAusbnet; C:\Windows\System32\DRIVERS\ONDAusbnet.sys [135168 2010-09-02] (ONDA Corporation)
S3 ONDAusbnmea; C:\Windows\System32\DRIVERS\ONDAusbnmea.sys [119680 2010-09-02] (Onda Communication)
S3 ONDAusbser6k; C:\Windows\System32\DRIVERS\ONDAusbser6k.sys [119680 2010-09-02] (Onda Communication)
R1 RapportCerberus_69875; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_69875.sys [631128 2014-07-30] ()
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [299736 2014-07-10] (Trusteer Ltd.)
S3 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [358616 2014-07-10] (Trusteer Ltd.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [414296 2014-07-10] (Trusteer Ltd.)
R2 risdptsk; C:\Windows\System32\DRIVERS\risdsn64.sys [76288 2008-10-22] (REDC)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
S3 Spyder2; C:\Windows\System32\DRIVERS\Spyder2.sys [15360 2007-01-17] ()
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [37624 2014-10-16] ()
S3 vodafone_K3805-z_cdc_acm; C:\Windows\System32\DRIVERS\vodafone_K3805-z_cdc_acm.sys [98304 2010-09-01] (Vodafone)
S3 vodafone_K3805-z_cdc_ecm; C:\Windows\System32\DRIVERS\vodafone_K3805-z_cdc_ecm.sys [53760 2010-09-01] (Vodafone)
S3 vodafone_K3805-z_cpo; C:\Windows\System32\DRIVERS\vodafone_K3805-z_cpo.sys [13824 2010-09-01] (Vodafone)
S3 GENERICDRV; \??\C:\Users\MarcoAdm\AppData\Local\Temp\{56099731-8D64-4A8F-87F8-A08130C3AA4F}\amifldrv64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-22 09:03 - 2008-10-03 11:24 - 00030208 _____ (Auslogics) C:\Windows\system32\rdboot64.exe
2014-10-22 08:30 - 2014-10-22 08:30 - 00075771 _____ () C:\test.xml
2014-10-22 08:07 - 2014-10-22 17:03 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Local\CrashDumps
2014-10-22 07:52 - 2014-10-22 07:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Utilities
2014-10-22 07:52 - 2008-08-22 16:22 - 00010216 _____ (Sony Corporation) C:\Windows\SysWOW64\Drivers\DMICall.sys
2014-10-22 07:51 - 2014-10-22 07:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care
2014-10-21 08:59 - 2014-10-21 08:59 - 02545968 _____ () C:\Users\MarcoAdm\Downloads\OPFOPD-00211176-1060.EXE
2014-10-21 08:59 - 2014-10-21 08:59 - 01256752 _____ () C:\Users\MarcoAdm\Downloads\INDOTH-00165424-64.EXE
2014-10-21 08:57 - 2014-10-21 08:57 - 01825584 _____ () C:\Users\MarcoAdm\Downloads\AIBSYS-00208408-US.EXE
2014-10-21 08:56 - 2014-10-21 08:56 - 05851952 _____ () C:\Users\MarcoAdm\Downloads\SOAVPM-00172192-US.EXE
2014-10-21 08:56 - 2014-10-21 08:56 - 04014384 _____ () C:\Users\MarcoAdm\Downloads\SOASUS-00209813-1020.EXE
2014-10-21 08:55 - 2014-10-21 08:55 - 02542384 _____ () C:\Users\MarcoAdm\Downloads\SOASSL-00162594-64.EXE
2014-10-21 08:54 - 2014-10-21 08:54 - 20736304 _____ () C:\Users\MarcoAdm\Downloads\SOAOTH-00000088-US.EXE
2014-10-21 08:54 - 2014-10-21 08:54 - 02333560 _____ () C:\Users\MarcoAdm\Downloads\SOAOTH-00226146-1020.EXE
2014-10-21 08:54 - 2014-10-21 08:54 - 02291072 _____ () C:\Users\MarcoAdm\Downloads\SOAOTH-12222223-US.EXE
2014-10-21 08:53 - 2014-10-21 08:53 - 06503288 _____ () C:\Users\MarcoAdm\Downloads\SOAOTH-88888887-1060.EXE
2014-10-21 08:52 - 2014-10-21 08:52 - 00001888 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care.lnk
2014-10-21 08:50 - 2014-10-21 08:51 - 49184376 _____ () C:\Users\MarcoAdm\Downloads\SOAVCA-00229335-1060.EXE
2014-10-21 08:49 - 2014-10-21 08:49 - 00474416 _____ () C:\Users\MarcoAdm\Downloads\SOAOTH-00000055-US.EXE
2014-10-21 08:47 - 2014-10-21 08:47 - 04522088 _____ () C:\Users\MarcoAdm\Downloads\SOAVUD-00176056-64.EXE
2014-10-21 08:45 - 2014-10-21 08:45 - 01072944 _____ () C:\Users\MarcoAdm\Downloads\SODOTH-00162380-64.EXE
2014-10-21 08:35 - 2014-10-22 08:18 - 00016776 _____ () C:\Windows\DPINST.LOG
2014-10-21 08:35 - 2009-03-04 12:00 - 05430272 _____ (Intel Corporation) C:\Windows\system32\Drivers\NETw5v64.sys
2014-10-21 08:34 - 2014-10-22 08:23 - 00000000 _____ () C:\Windows\Model.log
2014-10-21 08:33 - 2014-10-21 08:33 - 04173104 _____ () C:\Users\MarcoAdm\Downloads\INDWLL-76697669-64.EXE
2014-10-21 08:16 - 2014-10-21 08:16 - 00000858 _____ () C:\Users\Public\Desktop\RadarSync PC Updater.lnk
2014-10-21 08:16 - 2014-10-21 08:16 - 00000266 _____ () C:\Windows\Tasks\pcupdaterRunAtStartup.job
2014-10-21 08:16 - 2014-10-21 08:16 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Roaming\RadarSync
2014-10-21 08:16 - 2014-10-21 08:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RadarSync
2014-10-21 08:16 - 2014-10-21 08:16 - 00000000 ____D () C:\Program Files (x86)\RadarSync
2014-10-21 08:15 - 2014-10-21 08:15 - 03874480 _____ (RadarSync Ltd ) C:\Users\MarcoAdm\Downloads\radarsync.exe
2014-10-21 08:00 - 2014-10-21 08:01 - 00000000 ____D () C:\ProgramData\BSD
2014-10-21 08:00 - 2014-10-21 08:00 - 00001040 _____ () C:\Users\MarcoAdm\Desktop\TweakBit Driver Updater.lnk
2014-10-21 08:00 - 2014-10-21 08:00 - 00000000 ____D () C:\ProgramData\TweakBit
2014-10-21 08:00 - 2014-10-21 08:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweakBit
2014-10-21 08:00 - 2014-10-21 08:00 - 00000000 ____D () C:\Program Files (x86)\TweakBit
2014-10-21 07:59 - 2014-10-21 07:59 - 07973000 _____ (Auslogics Labs Pty Ltd ) C:\Users\MarcoAdm\Downloads\driver-updater-setup.exe
2014-10-20 19:53 - 2014-10-20 19:53 - 00000645 _____ () C:\Users\MarcoAdm\Desktop\JRT.txt
2014-10-17 00:26 - 2014-10-17 00:27 - 00049238 _____ () C:\Users\MarcoAdm\Desktop\Addition.txt
2014-10-17 00:24 - 2014-10-22 17:17 - 00022489 _____ () C:\Users\MarcoAdm\Desktop\FRST.txt
2014-10-17 00:24 - 2014-10-17 00:24 - 00000000 ____D () C:\Users\MarcoAdm\Desktop\FRST-OlderVersion
2014-10-16 22:02 - 2014-10-16 22:02 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-10-16 22:01 - 2014-10-16 22:01 - 02347384 _____ (ESET) C:\Users\MarcoAdm\Desktop\esetsmartinstaller_enu.exe
2014-10-16 21:04 - 2014-10-16 21:04 - 00084917 _____ () C:\Users\MarcoAdm\Downloads\bluescreenview-x64.zip
2014-10-16 20:56 - 2014-10-21 08:16 - 00000000 ____D () C:\AdwCleaner
2014-10-16 20:54 - 2014-10-16 20:55 - 01976320 _____ () C:\Users\MarcoAdm\Desktop\AdwCleaner.exe
2014-10-16 20:51 - 2014-10-17 00:42 - 00327226 _____ () C:\Users\MarcoAdm\Desktop\reply2.txt
2014-10-16 20:43 - 2014-10-16 20:43 - 00000000 ____D () C:\Windows\ERUNT
2014-10-16 20:41 - 2014-10-16 20:41 - 01705698 _____ (Thisisu) C:\Users\MarcoAdm\Desktop\JRT.exe
2014-10-16 09:20 - 2014-10-16 09:20 - 00269416 _____ () C:\Windows\Minidump\Mini101614-02.dmp
2014-10-16 08:36 - 2014-10-16 08:36 - 00269416 _____ () C:\Windows\Minidump\Mini101614-01.dmp
2014-10-16 08:33 - 2014-10-16 09:18 - 00037624 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-10-16 08:33 - 2014-10-16 08:33 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-10-16 08:31 - 2014-10-16 08:31 - 00006507 _____ () C:\Users\MarcoAdm\Desktop\Reply.txt
2014-10-16 08:30 - 2014-10-16 08:30 - 18550872 _____ () C:\Users\MarcoAdm\Desktop\RogueKillerX64.exe
2014-10-15 23:30 - 2014-10-16 08:47 - 00000000 ____D () C:\Windows\ERDNT
2014-10-15 23:29 - 2014-10-15 23:29 - 00000744 _____ () C:\Users\MarcoAdm\Desktop\ERUNT.lnk
2014-10-15 23:29 - 2014-10-15 23:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
2014-10-15 23:29 - 2014-10-15 23:29 - 00000000 ____D () C:\Program Files (x86)\ERUNT
2014-10-15 23:18 - 2014-10-16 20:37 - 00002748 _____ () C:\Users\MarcoAdm\Desktop\Rkill.txt
2014-10-15 23:15 - 2014-10-15 23:15 - 00791393 _____ (Lars Hederer ) C:\Users\MarcoAdm\Desktop\erunt-setup.exe
2014-10-15 23:14 - 2014-10-15 23:14 - 01944824 _____ (Bleeping Computer, LLC) C:\Users\MarcoAdm\Desktop\rkill.exe
2014-10-10 19:50 - 2014-10-11 13:09 - 00033462 _____ () C:\Users\MarcoAdm\Desktop\FRST_.txt
2014-10-10 19:27 - 2014-10-10 19:28 - 00015616 _____ () C:\Users\MarcoAdm\Desktop\FRST_part1.txt
2014-10-10 19:11 - 2014-10-10 19:12 - 00015561 _____ () C:\Users\MarcoAdm\Downloads\FRST_1.txt
2014-10-10 16:19 - 2014-10-10 16:19 - 00050515 _____ () C:\Users\MarcoAdm\Downloads\Addition_old.txt
2014-10-10 16:18 - 2014-10-10 16:19 - 00042684 _____ () C:\Users\MarcoAdm\Downloads\FRST_old.txt
2014-10-10 16:17 - 2014-10-22 17:17 - 00000000 ____D () C:\FRST
2014-10-10 16:16 - 2014-10-17 00:24 - 02112000 _____ (Farbar) C:\Users\MarcoAdm\Desktop\FRST64.exe
2014-10-10 16:04 - 2014-10-10 16:04 - 00116171 _____ () C:\Users\MarcoAdm\Desktop\sfcdetails.txt
2014-10-10 15:03 - 2014-10-10 15:03 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\MarcoAdm\Downloads\mbam-setup-2.0.2.1012(1).exe
2014-10-07 05:39 - 2014-10-07 05:39 - 00273656 _____ () C:\Windows\Minidump\Mini100714-01.dmp
2014-10-06 01:38 - 2014-10-06 01:38 - 00984576 _____ () C:\Users\MarcoAdm\Downloads\MicrosoftFixit50906.msi
2014-10-06 00:55 - 2014-10-06 00:55 - 00009976 _____ () C:\Users\MarcoAdm\Desktop\errors3.txt
2014-10-05 14:14 - 2014-10-05 14:14 - 00000974 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-10-05 14:13 - 2014-10-05 14:13 - 00000915 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2014-10-05 13:35 - 2014-10-05 13:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-05 12:47 - 2014-10-05 12:47 - 00002601 _____ () C:\Users\MarcoAdm\Desktop\DetectedProblems.txt
2014-10-05 11:09 - 2014-10-05 11:09 - 00273656 _____ () C:\Windows\Minidump\Mini100514-01.dmp
2014-10-04 21:33 - 2014-10-16 09:20 - 535829603 _____ () C:\Windows\MEMORY.DMP
2014-10-04 21:33 - 2014-10-04 21:33 - 00273656 _____ () C:\Windows\Minidump\Mini100414-01.dmp
2014-10-04 17:08 - 2014-10-04 17:08 - 00000178 _____ () C:\Windows\setupact.log
2014-10-04 17:08 - 2014-10-04 17:08 - 00000071 _____ () C:\Windows\setuperr.log
2014-10-04 17:06 - 2014-10-04 17:06 - 00145408 _____ (Intel® Corporation) C:\Windows\system32\Drivers\IntcHdmi.sys
2014-10-04 17:05 - 2014-10-21 08:35 - 00000000 ____D () C:\Windows\LastGood
2014-10-04 17:05 - 2014-10-04 17:05 - 00000000 ____H () C:\ProgramData\DP45977C.lfl
2014-10-04 17:05 - 2014-10-04 17:05 - 00000000 ____D () C:\Program Files\Realtek
2014-10-04 17:04 - 2014-10-04 17:04 - 60636160 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2014-10-04 17:04 - 2014-10-04 17:04 - 28343384 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 14863448 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 12894808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO3064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 07164176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 06218072 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 05804772 _____ () C:\Windows\system32\Drivers\rtvienna.dat
2014-10-04 17:04 - 2014-10-04 17:04 - 05751048 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 03962840 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2014-10-04 17:04 - 2014-10-04 17:04 - 03959384 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnN64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02834648 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02800344 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02770976 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02162992 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02117424 _____ () C:\Windows\system32\SStudio.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02101848 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 02041432 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01959128 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2014-10-04 17:04 - 2014-10-04 17:04 - 01939800 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01934424 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek264.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01317976 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO6064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01313904 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01286872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01168472 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO5064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01136728 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO4064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01099203 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2014-10-04 17:04 - 2014-10-04 17:04 - 01063512 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01048824 _____ (SRS Labs, Inc.) C:\Windows\system32\slcnt64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 01022168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00956504 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO2064.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00948952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00947760 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00942384 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOSettingsIPC.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00906800 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00900696 _____ (Waves Audio Ltd.) C:\Windows\SysWOW64\MaxxAudioAPOShell.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00889592 _____ (DTS, Inc.) C:\Windows\system32\sl3apo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00871856 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaeapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00836544 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00724728 _____ (DTS, Inc.) C:\Windows\system32\sltech64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00712296 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00663296 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00662784 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00628952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00603984 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00582056 _____ (TOSHIBA Corporation) C:\Windows\system32\tosasfapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00501184 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00487360 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00434960 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00415680 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00315736 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00291488 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00261464 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00246008 _____ (TODO: <Company name>) C:\Windows\system32\slprp64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00241768 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00221024 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00209096 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00162224 _____ (TOSHIBA Corporation) C:\Windows\system32\toseaeapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00141584 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00124176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00109848 _____ () C:\Windows\system32\AcpiServiceVnA64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00078688 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00075024 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00065944 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00033592 _____ () C:\Windows\system32\audioLibVc.dll
2014-10-04 17:04 - 2014-10-04 17:04 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2014-10-04 16:34 - 2014-10-04 16:37 - 00000000 _____ () C:\Users\MarcoAdm\sfcdetails.txt
2014-10-04 16:29 - 2014-10-04 16:29 - 00669185 _____ () C:\Users\MarcoAdm\Desktop\CBS.log
2014-10-04 16:29 - 2014-10-04 16:29 - 00000485 _____ () C:\Users\MarcoAdm\Desktop\sfcscannowresults.txt
2014-10-04 11:45 - 2014-10-22 07:55 - 00007264 _____ () C:\Windows\PFRO.log
2014-10-04 10:42 - 2014-10-04 10:42 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Eastman Kodak Company
2014-10-04 10:28 - 2014-10-04 10:28 - 00000000 ____D () C:\Windows\Tasks\TaskDisabled
2014-10-04 10:27 - 2014-10-04 10:27 - 00116216 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-04 10:26 - 2014-10-04 10:53 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\IObit
2014-10-04 10:25 - 2014-10-05 14:13 - 00000000 ____D () C:\Users\Administrator
2014-10-04 10:25 - 2014-10-04 10:25 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-10-04 10:25 - 2013-12-05 21:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Trusteer
2014-10-04 10:25 - 2013-01-18 23:44 - 00000000 ____D () C:\Users\Administrator\AppData\LocalGoogle
2014-10-04 10:25 - 2013-01-18 23:44 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-10-04 10:25 - 2012-07-08 21:27 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia
2014-10-04 10:25 - 2009-01-06 04:00 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Help
2014-10-04 10:25 - 2008-01-20 20:20 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-10-04 10:25 - 2008-01-20 20:20 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-04 03:52 - 2014-10-15 23:04 - 00000284 _____ () C:\Windows\Tasks\Uninstaller_SkipUac_Administrator.job
2014-10-03 21:58 - 2014-10-03 21:58 - 00000000 ____D () C:\Windows\LastGood.Tmp
2014-10-03 08:40 - 2014-10-03 19:44 - 00010783 _____ () C:\Users\MarcoAdm\Desktop\errors2.txt
2014-10-03 08:27 - 2014-10-22 08:26 - 00000732 _____ () C:\Users\MarcoAdm\AppData\Local\d3d9caps64.dat
2014-10-03 01:10 - 2014-10-03 01:10 - 00001331 _____ () C:\Users\MarcoAdm\Desktop\errors.txt
2014-10-03 00:52 - 2014-10-03 00:52 - 00000165 _____ () C:\Users\MarcoAdm\Documents\errors.txt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-22 17:18 - 2008-10-30 21:38 - 00000000 ____D () C:\ProgramData\Sony Corporation
2014-10-22 17:15 - 2006-11-02 08:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-22 17:15 - 2006-11-02 08:22 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-22 17:14 - 2006-11-02 08:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-22 17:04 - 2008-12-03 08:44 - 01630797 _____ () C:\Windows\WindowsUpdate.log
2014-10-22 17:01 - 2009-02-01 12:46 - 00000000 ____D () C:\Users\MarcoAdm
2014-10-22 17:00 - 2006-11-02 05:33 - 93323264 _____ () C:\Windows\system32\config\software.aus.bak
2014-10-22 17:00 - 2006-11-02 05:33 - 62390272 _____ () C:\Windows\system32\config\components.aus.bak
2014-10-22 17:00 - 2006-11-02 05:33 - 36962304 _____ () C:\Windows\system32\config\system.aus.bak
2014-10-22 17:00 - 2006-11-02 05:33 - 00524288 _____ () C:\Windows\system32\config\default.aus.bak
2014-10-22 17:00 - 2006-11-02 05:33 - 00262144 _____ () C:\Windows\system32\config\security.aus.bak
2014-10-22 16:58 - 2006-11-02 05:33 - 00262144 _____ () C:\Windows\system32\config\sam.aus.bak
2014-10-22 09:03 - 2009-04-03 09:14 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Roaming\Auslogics
2014-10-22 08:26 - 2006-11-02 05:46 - 00799602 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-22 08:23 - 2009-07-26 19:37 - 00000022 _____ () C:\Windows\Model.txt
2014-10-22 08:03 - 2008-10-30 19:17 - 00000012 _____ () C:\Windows\bthservsdp.dat
2014-10-22 08:03 - 2006-11-02 08:42 - 00032580 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-22 07:59 - 2008-10-30 20:06 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-10-22 07:53 - 2008-10-30 21:38 - 00000000 ____D () C:\Program Files\Sony
2014-10-22 07:52 - 2008-11-24 00:25 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-10-21 08:11 - 2011-01-15 18:04 - 00002621 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Word.lnk
2014-10-21 08:00 - 2010-02-12 09:39 - 00001356 _____ () C:\Users\MarcoAdm\AppData\Local\d3d9caps.dat
2014-10-21 08:00 - 2006-11-02 05:34 - 00000328 _____ () C:\Windows\win.ini
2014-10-20 18:54 - 2014-08-29 20:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-16 21:57 - 2006-11-02 06:33 - 00000000 ____D () C:\Windows\PLA
2014-10-16 09:20 - 2009-08-30 01:04 - 00000000 ____D () C:\Windows\Minidump
2014-10-15 23:04 - 2012-08-16 14:42 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Roaming\Azureus
2014-10-15 23:04 - 2009-02-01 13:47 - 00118784 _____ () C:\Users\MarcoAdm\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-10-11 13:10 - 2006-11-02 06:33 - 00000000 __RHD () C:\Users\Default
2014-10-10 15:04 - 2014-08-29 20:26 - 00000941 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-10 15:04 - 2014-08-29 20:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-10 15:04 - 2014-08-29 20:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-06 02:14 - 2006-11-02 06:33 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-10-06 01:08 - 2012-05-02 19:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-04 17:08 - 2006-11-02 06:33 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-04 17:06 - 2008-10-30 20:07 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2014-10-04 17:06 - 2008-10-30 19:56 - 00006144 _____ () C:\Windows\system32\HdmiCoin.dll
2014-10-04 15:57 - 2012-04-16 23:03 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-04 13:07 - 2009-12-23 23:13 - 00000000 ____D () C:\Windows\pss
2014-10-04 13:06 - 2013-01-06 12:30 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Roaming\Dropbox
2014-10-04 11:50 - 2010-02-09 20:38 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-04 11:42 - 2014-08-30 00:13 - 00002040 _____ () C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2014-10-04 03:43 - 2012-09-26 09:52 - 00002709 _____ () C:\Users\MarcoAdm\Desktop\iBackup Extractor.lnk
2014-10-03 20:59 - 2006-11-02 08:21 - 00408024 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-03 07:59 - 2006-11-02 08:21 - 00046080 _____ () C:\Windows\system32\umstartup.etl
2014-10-02 22:20 - 2014-08-30 00:14 - 00000000 ____D () C:\ProgramData\ProductData
2014-10-02 22:18 - 2014-04-13 15:01 - 00000000 ____D () C:\Users\MarcoAdm\AppData\Local\TB

Some content of TEMP:
====================
C:\Users\MarcoAdm\AppData\Local\Temp\dllnt_dump.dll
C:\Users\MarcoAdm\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpb635ro.dll
C:\Users\MarcoAdm\AppData\Local\Temp\GLF1162.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF125C.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF1A95.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF2639.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF2723.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF407A.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF4666.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF50D2.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF512.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF58ED.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF7938.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF7D7C.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF874D.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF8C2E.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLF9A6E.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLFB011.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLFB474.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLFB722.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLFCA1.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLFE5D0.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\GLFF7D9.EXE
C:\Users\MarcoAdm\AppData\Local\Temp\Quarantine.exe
C:\Users\MarcoAdm\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-22 08:45

==================== End Of Log ============================

Link to post
Share on other sites

  • Root Admin

Please visit this webpage and read the ComboFix User's Guide:

  • Once you've read the article and are ready to use the program you can download it directly from the link below.
  • Important! - Please make sure you save combofix to your desktop and do not run it from your browser
  • Direct download link for: ComboFix.exe
  • Please make sure you disable your security applications before running ComboFix.
  • Once Combofix has completed it will produce and open a log file.  Please be patient as it can take some time to load.
  • Please attach that log file to your next reply.
  • If needed the file can be located here:  C:\combofix.txt
  • NOTE: If you receive the message "illegal operation has been attempted on a registry key that has been marked for deletion", just reboot the computer.


 

Link to post
Share on other sites

I ran ComboFix. Below is the log file. While I was running, it said that certain operations could not be performed even though I ran it from an account with Administrator privileges.

 

ComboFix 14-10-29.01 - MarcoAdm 11/01/2014  13:25:38.1.2 - x64 NETWORK
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3934.3051 [GMT -7:00]
Running from: c:\users\MarcoAdm\Desktop\ComboFix.exe
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\users\MarcoAdm\Documents\Readiris.DUS
.
.
(((((((((((((((((((((((((   Files Created from 2014-10-01 to 2014-11-01  )))))))))))))))))))))))))))))))
.
.
2014-11-01 19:10 . 2014-10-14 19:59    11627712    ----a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E62D62F8-EAB2-4DA7-B558-E7205E9D96AD}\mpengine.dll
2014-10-25 00:12 . 2014-10-25 00:55    --------    d-----w-    c:\program files (x86)\Advanced Fix
2014-10-24 20:28 . 2014-10-24 23:56    129752    ----a-w-    c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-10-24 20:28 . 2014-10-01 18:11    64216    ----a-w-    c:\windows\system32\drivers\mwac.sys
2014-10-24 20:28 . 2014-10-01 18:11    93400    ----a-w-    c:\windows\system32\drivers\mbamchameleon.sys
2014-10-24 20:28 . 2014-10-01 18:11    25816    ----a-w-    c:\windows\system32\drivers\mbam.sys
2014-10-24 20:28 . 2014-10-24 20:28    --------    d-----w-    c:\program files (x86)\Malwarebytes Anti-Malware
2014-10-22 16:03 . 2008-10-03 18:24    30208    ----a-w-    c:\windows\system32\rdboot64.exe
2014-10-22 15:33 . 2014-10-14 19:59    11627712    ----a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-10-22 15:07 . 2014-10-25 00:55    --------    d-----w-    c:\users\MarcoAdm\AppData\Local\CrashDumps
2014-10-22 14:52 . 2008-08-22 23:22    10216    ----a-w-    c:\windows\SysWow64\drivers\DMICall.sys
2014-10-22 14:52 . 2014-10-22 14:52    --------    d-----w-    c:\windows\Vaio Application Uninstaller
2014-10-21 15:35 . 2009-03-04 19:00    5430272    ----a-w-    c:\windows\system32\drivers\NETw5v64.sys
2014-10-21 15:16 . 2014-10-21 15:16    --------    d-----w-    c:\users\MarcoAdm\AppData\Roaming\RadarSync
2014-10-21 15:16 . 2014-10-21 15:16    --------    d-----w-    c:\program files (x86)\RadarSync
2014-10-21 15:00 . 2014-10-21 15:01    --------    d-----w-    c:\programdata\BSD
2014-10-21 15:00 . 2014-10-21 15:00    --------    d-----w-    c:\programdata\TweakBit
2014-10-21 15:00 . 2014-10-21 15:00    --------    d-----w-    c:\program files (x86)\TweakBit
2014-10-17 05:02 . 2014-10-17 05:02    --------    d-----w-    c:\program files (x86)\ESET
2014-10-17 03:56 . 2014-10-24 21:12    --------    d-----w-    C:\AdwCleaner
2014-10-17 03:43 . 2014-10-17 03:43    --------    d-----w-    c:\windows\ERUNT
2014-10-16 15:33 . 2014-10-23 15:08    37624    ----a-w-    c:\windows\system32\drivers\TrueSight.sys
2014-10-16 15:33 . 2014-10-16 15:33    --------    d-----w-    c:\programdata\RogueKiller
2014-10-16 06:29 . 2014-10-16 06:29    --------    d-----w-    c:\program files (x86)\ERUNT
2014-10-10 23:17 . 2014-10-23 00:19    --------    d-----w-    C:\FRST
2014-10-05 00:06 . 2014-10-05 00:06    145408    ----a-w-    c:\windows\system32\drivers\IntcHdmi.sys
2014-10-05 00:05 . 2014-10-05 00:05    --------    d-----w-    c:\program files\Realtek
2014-10-05 00:05 . 2014-10-21 15:35    --------    d-----w-    c:\windows\LastGood
2014-10-04 17:25 . 2014-10-05 21:13    --------    d-----w-    c:\users\Administrator
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-10-05 00:06 . 2008-10-31 02:56    6144    ----a-w-    c:\windows\system32\HdmiCoin.dll
2014-08-30 02:21 . 2011-03-29 01:36    23256    ----a-w-    c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-23 01:05 . 2014-08-28 10:02    304128    ----a-w-    c:\windows\SysWow64\gdi32.dll
2014-08-23 00:42 . 2014-08-28 10:02    390144    ----a-w-    c:\windows\system32\gdi32.dll
2014-08-22 23:38 . 2014-08-28 10:02    2782208    ----a-w-    c:\windows\system32\win32k.sys
2014-08-20 14:29 . 2014-08-29 10:35    1169712    ------w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{490F0D9A-7CED-4592-8907-D5163C25096A}\gapaengine.dll
2014-08-20 14:29 . 2012-10-05 17:59    1169712    ------w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-08-16 13:23 . 2006-11-02 12:35    99218768    ----a-w-    c:\windows\system32\mrt.exe
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04    131480    ----a-w-    c:\users\MarcoAdm\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04    131480    ----a-w-    c:\users\MarcoAdm\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04    131480    ----a-w-    c:\users\MarcoAdm\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay]
@="{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}"
[HKEY_CLASSES_ROOT\CLSID\{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}]
2012-04-09 23:27    158224    ----a-w-    c:\windows\SysWOW64\CbFsMntNtf3.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Conime"="c:\windows\system32\conime.exe" [2009-04-11 69120]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2008-10-18 02:19    98304    ----a-w-    c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ECACHE
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Themes
.
Contents of the 'Scheduled Tasks' folder
.
2014-10-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 12:57]
.
2014-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-10 16:51]
.
2014-10-21 c:\windows\Tasks\pcupdaterRunAtStartup.job
- c:\program files (x86)\RadarSync\pcupdater.exe [2014-10-21 20:06]
.
2014-10-16 c:\windows\Tasks\Uninstaller_SkipUac_Administrator.job
- c:\program files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-08-30 00:52]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
2014-08-30 07:14    2471744    ----a-w-    c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay]
@="{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}"
[HKEY_CLASSES_ROOT\CLSID\{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}]
2012-04-09 23:27    190480    ----a-w-    c:\windows\System32\CbFsMntNtf3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-08-08 17:34    777032    ----a-w-    c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 17:34    777032    ----a-w-    c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 17:34    777032    ----a-w-    c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-08-08 17:34    777032    ----a-w-    c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-08-08 17:34    777032    ----a-w-    c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-08-08 17:34    777032    ----a-w-    c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = www.google.com
mLocal Page = c:\windows\system32\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{2A73429A-B03C-4F88-ABAF-48B0629EA399}: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{2BF03E76-37A1-4EB0-867B-923862A5E1AA}: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{83228AEC-D667-4A75-AC1E-483C1216EBA5}: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{C2F38D47-8F48-4FFF-9C21-3B5EA2894EFB}: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{FC077840-0E7B-4E6C-9460-0DB6F45F914E}: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\MarcoAdm\AppData\Roaming\Mozilla\Firefox\Profiles\56wx6ubw.default-1399854068777\
FF - prefs.js: browser.startup.homepage - www.google.com
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
SafeBoot-MBAMSwissArmy
SafeBoot-WudfPf
SafeBoot-WudfRd
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):79,fd,59,4a,1a,7c,da,12,9d,81,b5,48,9d,9a,e4,2a,a0,54,09,1e,09,
   f8,9b,08,68,76,40,a5,e3,84,dc,82,d9,7e,af,b9,53,c3,ae,cc,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-1683370733-2581893643-414232939-1001_Classes\Wow6432Node\CLSID\{c9c9e9dc-90ac-430f-84a0-e972809816ef}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000159
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
   38,95,44,7d,3f,f3,08,7a,08,bf,c7,68,b3,bb,67,09,b7,04,f0,e4,22,fe,98,31,bd,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.14"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet017\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
.
[HKEY_LOCAL_MACHINE\system\ControlSet017\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet017\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2014-11-01  13:39:28
ComboFix-quarantined-files.txt  2014-11-01 20:39
.
Pre-Run: 62,508,191,744 bytes free
Post-Run: 62,253,305,856 bytes free
.
- - End Of File - - 3D5D2A83A6BBA2418FB32811AC1C3A58
5C616939100B85E558DA92B899A0FC36
 

Link to post
Share on other sites

  • Root Admin

How is the computer running now?

 

Please run the following for me.

 

Please download Security Check by screen317 from HERE or HERE.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • If you get Unsupported operating system. Aborting now, just reboot and try again.
  • A Notepad document should open automatically called checkup.txt.
  • Please Post the contents of that document.
  • Do Not Attach It!!!


 

Link to post
Share on other sites

The computer still exhibits the same problem: in normal mode it freezes up only a few minutes after booting. Only the mouse tracker seems to work. Only possibility is a hardware shutdown.

 

All the tools that you suggested me have been run in "safe mode with networking", where the computer works well without any problem.

 

Question: can running all these tools in safe mode detect problems that appear only in normal mode?

 

 

Requested log from Security Check follows:

 

 Results of screen317's Security Check version 0.99.89  
 Windows Vista Service Pack 2 x64 (UAC is enabled)  
 Internet Explorer 9  
 Internet Explorer 8  
``````````````Antivirus/Firewall Check:``````````````
 Windows Security Center service is not running! This report may not be accurate!
 Windows Firewall Enabled!  
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 Spyder2express     
 Java 7 Update 9  
 Java version out of Date!
  Adobe Flash Player     14.0.0.145 Flash Player out of Date!  
 Adobe Reader 10.1.11 Adobe Reader out of Date!  
 Mozilla Firefox 32.0.3 Firefox out of Date!  
````````Process Check: objlist.exe by Laurent````````  
 Microsoft Security Essentials MSMpEng.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 1 %
````````````````````End of Log``````````````````````
 

Link to post
Share on other sites

  • Root Admin

In general the tools can repair specific threats that might be stopping it from running in Normal Mode but if the Registry is damaged or data corrupt that could prevent it from ever working properly in Normal Mode.

 

Please try creating a new user profile with admin rights from Safe Mode and then try to run in Normal Mode but try to logon as that new account and let me know your results.

Link to post
Share on other sites

  • 2 weeks later...

I did as you asked, but nothing changed. After a couple of minutes in normal mode the pc becomes unresponsive to anything but the mouse pointer, as with my regular account.

I guess it's time to wipe out the PC and reinstall the OS. Before we started this whole process I copied everything under C:\Users\MarcoAdm to an external hard drive. After reinstalling the OS, how can I copy my data back and make sure that I am not bringing back any infection that might be among them?

Link to post
Share on other sites

  • Root Admin

If the new system is fully protected then there is minimal risk in copying back infected data. Typically use Robocopy after the fact would probably be the best solution but once you've rebuilt the computer and feel you're ready send me a private message and let me know and I'll give you some pointers.

 

I'll go ahead and close your topic now and good luck with the rebuild process.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.