1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

[Solved] Hotmail issue

Discussion in 'Malware Removal Help' started by Tony Loly, Aug 27, 2014.

  1. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    This is the log with ref to my thread " Hotmail issue " in the windows 7 forum. It was suggested I paste it here. Detected items are now quarantined.
    Thank you



    Malwarebytes Anti-Malware
    www.malwarebytes.org
    Scan Date: 27/08/2014
    Scan Time: 11:16:58
    Logfile:
    Administrator: Yes
    Version: 2.00.2.1012
    Malware Database: v2014.08.27.02
    Rootkit Database: v2014.08.21.01
    License: Free
    Malware Protection: Disabled
    Malicious Website Protection: Disabled
    Self-protection: Disabled
    OS: Windows 7 Service Pack 1
    CPU: x64
    File System: NTFS
    User: Tony
    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 327997
    Time Elapsed: 20 min, 15 sec
    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Warn
    PUM: Enabled
    Processes: 0
    (No malicious items detected)
    Modules: 0
    (No malicious items detected)
    Registry Keys: 11
    PUP.Optional.PinPhotoZoom, HKLM\SOFTWARE\CLASSES\CLSID\{4a0c8953-9d4e-4790-b732-2b9fc9ebce05}, Quarantined, [95f9f3d80c6f7bbb89f35159b1510cf4],
    PUP.Optional.PinPhotoZoom, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{4A0C8953-9D4E-4790-B732-2B9FC9EBCE05}, Quarantined, [95f9f3d80c6f7bbb89f35159b1510cf4],
    PUP.Optional.PinPhotoZoom, HKU\S-1-5-21-131991233-2839458126-3920297457-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{4A0C8953-9D4E-4790-B732-2B9FC9EBCE05}, Quarantined, [95f9f3d80c6f7bbb89f35159b1510cf4],
    PUP.Optional.GetNow.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{237FDFDB-3722-470E-8BA8-90196DABE967}, Quarantined, [1c725e6d3b4014229a85c4b623df02fe],
    PUP.Optional.GetNow.A, HKLM\SOFTWARE\CLASSES\TypeLib\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}, Quarantined, [eaa46c5f0675eb4bd847c6b443bf8a76],
    PUP.Optional.Lyrics.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\SuperLyrics-16, Quarantined, [3c52eae18cef77bf6e640207a360827e],
    PUP.Optional.WeDownLoadManager.A, HKU\S-1-5-21-131991233-2839458126-3920297457-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WeDlMngr, Quarantined, [206ef9d2e89356e06dbc0be302007a86],
    PUP.Optional.DealPly.A, HKU\S-1-5-21-131991233-2839458126-3920297457-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\gaiilaahiahdejapggenmdmafpmbipje, Quarantined, [830baf1c89f283b3abcb7a840cf66d93],
    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110411411162}, Quarantined, [f09effcc3f3ce84edc8fe106df2554ac],
    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110411411162}, Quarantined, [f09effcc3f3ce84edc8fe106df2554ac],
    PUP.Optional.CrossRider.A, HKU\S-1-5-21-131991233-2839458126-3920297457-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{11111111-1111-1111-1111-110411411162}, Quarantined, [f09effcc3f3ce84edc8fe106df2554ac],
    Registry Values: 1
    PUP.Optional.CertifiedToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), http://search.certified-toolbar.com...7363376-5E396195B007C0A662761ADF2A0188B5&q=%s, Quarantined, [cbc3b11a83f86acc95ece017d230e818]
    Registry Data: 2
    PUP.Optional.SimplyTech.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|newtab, %appdata%\SimplyTech\home\home.htm, Good: (www.google.com), Bad: (%appdata%\SimplyTech\home\home.htm),Replaced,[6b238a41dba055e1c2cb4d8950b41ee2]
    PUP.Optional.SimplyTech.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|newtab, %appdata%\SimplyTech\home\home.htm, Good: (www.google.com), Bad: (%appdata%\SimplyTech\home\home.htm),Replaced,[e1ad72595a21db5ba4e9ebeb19ebd030]
    Folders: 79
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\defaults, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\defaults\preferences, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\userCode, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\locale, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\locale\en-US, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\defaults, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\defaults\preferences, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\userCode, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\locale, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\locale\en-US, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.SuperLyrics.A, C:\Users\Tony\AppData\LocalLow\SuperLyrics-16, Quarantined, [e0ae7e4db8c33ef8e305c9ff8f73f10f],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\browser, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\browser\misc, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\data, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\newtab, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\external, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\gallery, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\icons, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\resources, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\chrome, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\favorites, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\info, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\review, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\ar, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\de, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\en, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\es, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\fr, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\he, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\it, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\ja, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\nl, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\pl, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\pt_BR, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\ru, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\tr, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.SystemSpeedup, C:\Users\Tony\AppData\Roaming\systweak\ssd, Quarantined, [e4aa4784691255e1330814c5df23a957],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\chrome, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\chrome\content, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\defaults, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\defaults\preferences, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\Adobe AIR, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\Adobe AIR\Versions, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\Adobe AIR\Versions\1.0, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\META-INF, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\META-INF\AIR, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLVM Player, Quarantined, [612d5477077484b2bb766285e61cf50b],
    Files: 389
    PUP.Optional.Spigot, C:\Users\Tony\AppData\Local\Temp\SearchProtectionSetup.exe, Quarantined, [6c22a02bd7a423136df396110df42ad6],
    PUP.Optional.AirAdInstaller, C:\Users\Tony\AppData\Local\Temp\setup.exe, Quarantined, [4b43c803344769cd79c20c2e916f14ec],
    PUP.Optional.BundleInstaller.A, C:\Users\Tony\AppData\Local\Temp\n648\s648.exe, Quarantined, [8a04d4f7cead74c2d1573b0f1ce4748c],
    PUP.Optional.Babylon, C:\Users\Tony\AppData\Local\Temp\n648\systemsspeedup_0307-cd6becd7.exe, Quarantined, [a1ed4a8148339d99745008a722dfc63a],
    PUP.Optional.Wajam.A, C:\Users\Tony\AppData\Local\Temp\n648\wajam_2207-6c14163c.exe, Quarantined, [018ddeed186372c40424e95edb257888],
    PUP.Optional.VisualBee, C:\Windows\System32\Tasks\VisualBeeRecovery, Quarantined, [305efccf87f4b482de5c8568bd45c53b],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome.manifest, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\install.rdf, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\background.html, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\baseObject.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\browser.xul, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\dialog.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\main.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\options.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\options.xul, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\platformVersion.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\search_dialog.xul, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\asyncDB.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\background.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\browserAction.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\contextMenu.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\dbManager.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\dom_bg.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\fileManager.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\firefox.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\firefoxNotifications.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\firefoxOmnibox.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\message.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\pageAction.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\request.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\tabs.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\webRequest.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\windowsMessagingHandler.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\addressBarChangeObserver.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\console.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\consts.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\delegate.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\extensionDataStore.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\folderIOWrapper.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\httpObserver.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\IDBWrapper.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\installer.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\logFile.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\prefs.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\progressListenerObserver.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\registry.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\reloadObserver.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\reports.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\requestObject.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\searchSettings.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\uninstallObserver.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\updateManager.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\utils.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\xhr.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\defaults\preferences\prefs.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\manifest.xml, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins.json, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\22_resources.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\13_CrossriderAppUtils.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\14_CrossriderUtils.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\16_FFAppAPIWrapper.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\177_crossriderDashboard.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\17_jQuery.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\182_openUrl.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\183_tabsWrapper.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\1_base.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\207_dbWrapper.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\21_debug.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\28_initializer.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\47_resources_background.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\4_jquery_1_7_1.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\64_appApiMessage.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\72_appApiValidation.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\78_CrossriderInfo.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\91_monetizationLoader.js.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\98_omniCommands.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\userCode\background.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\userCode\extension.js, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\locale\en-US\translations.dtd, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\button1.png, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\button2.png, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\button3.png, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\button4.png, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\button5.png, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\crossrider_statusbar.png, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\icon128.png, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\icon16.png, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\icon24.png, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\icon48.png, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\panelarrow-up.png, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\popup.html, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\skin.css, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\update.css, Quarantined, [a0eec308c6b544f24a980db8fc067789],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome.manifest, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\install.rdf, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\background.html, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\baseObject.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\browser.xul, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\dialog.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\main.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\options.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\options.xul, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\search_dialog.xul, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\asyncDB.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\background.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\browserAction.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\contextMenu.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\dbManager.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\dom_bg.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\fileManager.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\firefox.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\firefoxNotifications.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\firefoxOmnibox.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\message.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\pageAction.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\request.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\tabs.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\api\webRequest.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\console.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\consts.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\delegate.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\extensionDataStore.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\folderIOWrapper.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\httpObserver.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\IDBWrapper.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\installer.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\logFile.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\prefs.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\progressListenerObserver.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\registry.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\reloadObserver.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\reports.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\requestObject.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\searchSettings.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\uninstallObserver.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\updateManager.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\utils.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\chrome\content\core\xhr.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\defaults\preferences\prefs.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\manifest.xml, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins.json, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\16_FFAppAPIWrapper.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\22_resources.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\101_cortica_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\102_dealply_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\103_intext_5_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\104_jollywallet_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\105_corticas_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\108_icm_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\116_ads_only_5_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\117_coupons_intext_ads_5_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\119_similar_web_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\120_luck_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\123_intext_adv_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\124_superfish_no_search_no_coupons_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\125_arcadi2_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\126_revizer_ws_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\127_revizer_p_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\128_superfish_pricora_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\129_widdit_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\135_arcadi3_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\138_getdeal_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\13_CrossriderAppUtils.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\141_corticas_ru_m.js.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\142_intext_fa_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\14_CrossriderUtils.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\155_ibario_pops_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\158_50onred_ads_only_no_fb_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\159_cortica_rollover_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\170_icm1_5_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\171_arcadi2_sourceID_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\174_arcadi_serp_dynamic_id_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\175_coolmirage_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\178_revizer_ws_dynamic_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\179_revizer_p_dynamic_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\17_jQuery.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\1_base.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\21_debug.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\28_initializer.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\47_resources_background.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\4_jquery_1_7_1.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\64_appApiMessage.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\72_appApiValidation.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\78_CrossriderInfo.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\7_hooks.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\87_ginyas_wrapper.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\91_monetizationLoader.js.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\92_superfish_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\93_superfish_no_coupons_m.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\98_omniCommands.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\plugins\9_search_engine_hook.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\userCode\background.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\extensionData\userCode\extension.js, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\locale\en-US\translations.dtd, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\button1.png, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\button2.png, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\button3.png, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\button4.png, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\button5.png, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\crossrider_statusbar.png, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\icon128.png, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\icon16.png, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\icon24.png, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\icon48.png, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\panelarrow-up.png, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\popup.html, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\skin.css, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.CrossRider.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\extensions\58ad0086-1cfb-48bb-8ad2-33a8905572bc@5715d2be-69b9-4930-8f7e-64bdeb961cfd.com\skin\update.css, Quarantined, [f19d9a316e0d1a1c826018ad41c1bc44],
    PUP.Optional.SuperLyrics.A, C:\Users\Tony\AppData\LocalLow\SuperLyrics-16\DTFProxyToServerSect_bCrossriderApp0044162_p15816.dat, Quarantined, [e0ae7e4db8c33ef8e305c9ff8f73f10f],
    PUP.Optional.SuperLyrics.A, C:\Users\Tony\AppData\LocalLow\SuperLyrics-16\DTFProxyToServerSect_bCrossriderApp0044162_p26696.dat, Quarantined, [e0ae7e4db8c33ef8e305c9ff8f73f10f],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\manifest.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\browser\background.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\browser\background.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\browser\misc\screenshot.inject.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\data\favorites_de.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\data\favorites_en_gb.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\data\favorites_en_us.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\data\favorites_fr.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\data\favorites_he.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\data\favorites_it.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\data\favorites_pt_br.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\data\favorites_ru.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\data\favorites_tr.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external\angular.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external\crypto-js.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external\jquery-2.1.0.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external\jquery.autocomplete.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external\jquery.balloon.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external\jquery.fittext.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external\jquery.Jcrop.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external\jquery.simplecolorpicker.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external\mustache.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external\string.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\external\underscore-min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\newtab\gallery.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\newtab\gallery.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\newtab\newtab.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\newtab\newtab.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\newtab\review.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\content\newtab\review.min.js, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\external\foundation.min.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\external\indicator.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\external\Jcrop.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\external\jquery.autocomplete.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\external\jquery.Jcrop.min.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\external\jquery.simplecolorpicker.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\external\normalize.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\gallery\arrow-gallery-cat-selected.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\gallery\arrow.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\gallery\emptyArea.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\gallery\gallery.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\gallery\gallery_templates.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\gallery\icon-gallery-search.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\gallery\not_available_32.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\gallery\plus.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\gallery\X.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\icons\128.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\icons\16.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\icons\48.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\css\buttons.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\css\footer.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\css\header.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\css\list.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\css\newtab.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\css\search.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\css\themes.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-layout.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\ajax-loader-2.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\ajax-loader-bar.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\ajax-loader-medium.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\ajax-loader-small.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\ajax-loader.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\arrow-footer.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\arrow-header.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\attachment.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\close-bar2.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\close.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\edit-button.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-apps-dark.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-apps.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-chrome.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-close.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-contents-light.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-contents.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-edit.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-plus-dark.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-plus.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-right.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-search.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-settings.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\icon-theme.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\menu_v.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\menu_v_white.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\x-button.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\arab_tile.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\batthern_@2X.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\bo_play_pattern_@2X.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\dark_wood_@2X.jpg, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\diagonal_striped_brick.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\escheresque_ste_@2X.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\gold_scale.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\purty_wood_@2X.jpg, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\readme.txt, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\starring_@2X.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\tileable_wood_texture_@2X.jpg, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\weave_@2X.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\wild_oliva_@2X.jpg, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\images\patterns\woven.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\resources\groups.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\resources\list.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\newtab\resources\menu.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\css\activetabs.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\css\favorites.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\css\layout.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\css\modal-fav-add.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\css\modal-fav-edit.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\css\modal-fav-group.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\css\readitlater.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\css\recentlyclosed.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\css\theme.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\css\webapps.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\chrome\bookmarks.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\chrome\download.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\chrome\downloads.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\chrome\downloas.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\chrome\extensions.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\chrome\history.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\chrome\settings.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\chrome\trash.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\favorites\empty.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\favorites\error.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\favorites\shadow.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\info\contactus.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\info\facebook.ico, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\info\rateus.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\images\info\twitter.ico, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\activetabs.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\favorites.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\layout.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\modal-fav-add.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\modal-fav-edit.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\modal-fav-group.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\readitlater.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\readitlater_content.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\readitlater_menu.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\recentlyclosed.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\theme.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\webapps.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\plugins\resources\webapps_contextmenu.html, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\review\cat_1.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\review\cat_2.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\review\cat_3.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\review\cat_4.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\review\cat_5.gif, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\review\rating-star.png, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\skin\review\review.css, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\ar\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\de\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\en\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\es\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\fr\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\he\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\it\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\ja\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\nl\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\pl\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\pt_BR\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\ru\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.NewTab.A, C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.25_0\_locales\tr\messages.json, Quarantined, [6b237259017a0a2cf6cb627043bf34cc],
    PUP.Optional.SystemSpeedup, C:\Users\Tony\AppData\Roaming\systweak\ssd\SSDPTstub.exe, Quarantined, [e4aa4784691255e1330814c5df23a957],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\chrome.manifest, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\install.rdf, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\chrome\content\appIcon.png, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\chrome\content\browserOverlay.xul, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\chrome\content\options.js, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\chrome\content\options.xul, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\chrome\content\utils.js, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.PinPhotoZoom.A, C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}\defaults\preferences\predictad.js, Quarantined, [6925a12a7dfefa3c2fc93aab03ff17e9],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\FLVMPlayer.exe, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\FLVMPlayer.swf, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\mimetype, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\Uninstaller.exe, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\Adobe AIR\Versions\1.0\Adobe AIR.dll, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\META-INF\AIR\application.xml, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player\META-INF\AIR\signatures.xml, Quarantined, [e3abc00b91ea57df2e02aa3de022b54b],
    PUP.Optional.FLVMPlayer, C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLVM Player\FLVM Player.lnk, Quarantined, [612d5477077484b2bb766285e61cf50b],
    PUP.Optional.FLVMPlayer, C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLVM Player\Uninstall FLVM Player.lnk, Quarantined, [612d5477077484b2bb766285e61cf50b],
    Physical Sectors: 0
    (No malicious items detected)

    (end)
     
  2. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Tony,

    That's a nice collection of PuP's (Adware)
    I'd be very surprised if that's all there was.

    Let's take a look:

    Step 1
    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.



    Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator.
    • Click on the Scan button.
    • AdwCleaner will begin to scan your computer.
    • After the scan has finished...
    • Click on the Clean button.
    • Press OK when asked to close all programs and follow the onscreen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
    • Copy and paste the contents of that logfile in your next reply.
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

    Step 2
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to your Desktop.

    • Double-click the downloaded icon to run the tool. Vista/Windows 7/8 users right-click and select Run As Administrator

      a1e30894cbd1e51d77798ccaebcd6fa0.png
    • When the tool opens click Yes to disclaimer.

      6c81f32e4cfa276b33b2c5b126a03416.png
    • Make sure that Addition.txt is selected at the bottom
    • Press Scan button.

      1b8c7ec40ba5fc57455a82d8388da693.png
    • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
    • The first time the tool is run, it also makes another log (Addition.txt). Please copy and paste it to your reply also.


    In your next reply, please submit:
    JRT.txt
    AdwCleaner report
    Both reports from FRST


    Thanks
     
  3. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    Thanks I will start this tomorrow morning......just one query, you say "Shut down your protection software"..........do you mean' BT net protect plus' & when do I open it again? Sorry to be such a novice.
     
  4. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    Do you mean turn off my firewall?
    Just tried to download JRT & it was blocked?
     
  5. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Yes, BT Net Protect basically use McAfee, this will include a Virus scanner and a personal Firewall.
    so these will need to be turned off.

    Turn off your BT Net Protect, then download and run JRT.
    Once Jrt has finished, you can turn the security software back on.

    Nothing to be sorry for.
    You only learn by asking questions.... especially if you are unsure.
     
  6. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    Thanks Starbuck, here we go .......

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.1.4 (04.06.2014:1)
    OS: Windows 7 Home Premium x64
    Ran by Tony on 29/08/2014 at 8:44:10.29
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    ~~~ Services
    ~~~ Registry Values
    Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotection
    ~~~ Registry Keys
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\systweak
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211671166}
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211671166}
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A6A9E0D1-F32A-4899-8F67-D6B14EB39746}
    ~~~ Files
    Successfully deleted: [File] "C:\chromehplog.txt"
    Successfully deleted: [File] C:\Windows\syswow64\sho481D.tmp
    Successfully deleted: [File] C:\Windows\syswow64\shoD996.tmp
    ~~~ Folders
    Successfully deleted: [Folder] "C:\Users\Tony\AppData\Roaming\systweak"
    Successfully deleted: [Folder] "C:\Users\Tony\appdata\locallow\boost_interprocess"
    Successfully deleted: [Folder] "C:\Program Files (x86)\coupons"
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{070A1DFF-3F55-496B-B99D-3769AD2C6C2C}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{1DDEFF25-1C5E-4980-A803-6190F37FF998}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{3529B24A-13C1-41B6-9CD7-6B00035FF832}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{6BA924D3-DFA9-4CBE-9781-C8334CB77531}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{7A426C6E-15C3-46BD-81A6-8D4D2E9026EF}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{896E66F6-A441-49F7-ACD2-AF1EDB4E992A}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{8D21CB79-860E-4431-A89C-CACEDFD175F4}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{8DE1627D-4816-4228-B374-B830E0FC443C}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{8DF6A115-5FF7-4552-B5E6-7087ED0CFCBA}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{E08A0905-2D3A-4A17-9A47-46E25FCD2BBF}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{E0AFE739-DAA4-447D-A2DB-4418EFB329BD}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{E835950C-D8A8-4061-BEE8-AB02279140CD}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{F036FFCA-E01C-4B8F-8BD0-0DE80E5527FF}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{F08834DD-53FC-47CD-BDF3-A17B2A0B66BD}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{F3DCEAFE-90FB-4412-B685-21CC624A7D17}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{FDD5DE56-7746-4712-81E3-B5642B27BEEC}
    Successfully deleted: [Empty Folder] C:\Users\Tony\appdata\local\{FE6155B2-7B49-4C47-8B6F-3E7BEEB117F1}
    ~~~ FireFox
    Successfully deleted: [File] C:\user.js
    Successfully deleted: [Folder] "C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com"
    Successfully deleted: [Folder] "C:\Program Files (x86)\Mozilla Firefox\extensions\{650eed71-89e2-453b-8dcf-2aa1b4ae6ef3}"
    Successfully deleted the following from C:\Users\Tony\AppData\Roaming\mozilla\firefox\profiles\9u8txpth.default-1358439559668\prefs.js
    user_pref("extensions.fvd_single.surfcanyon.ramp.start_time", "1394095688050");
    user_pref("{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}.ScriptData_WSG_referrer", "hxxp://us.yhs4.search.yahoo.com/yhs/search?fr=altavista&itag=ody&q=hxxp://www.voyeurbb.com/?cat=13
    user_pref("{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}.ScriptData_WSG_temp_referer", "hxxp://us.yhs4.search.yahoo.com/yhs/search?fr=altavista&itag=ody&q=hxxp://redir.info/mf01/defa
    Emptied folder: C:\Users\Tony\AppData\Roaming\mozilla\firefox\profiles\9u8txpth.default-1358439559668\minidumps [125 files]
    ~~~ Event Viewer Logs were cleared
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 29/08/2014 at 8:51:13.51
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


    # AdwCleaner v3.308 - Report created 29/08/2014 at 08:59:42
    # Updated 20/08/2014 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : Tony - TONY-HP
    # Running from : C:\Users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PA1TWXWP\AdwCleaner.exe
    # Option : Clean
    ***** [ Services ] *****

    ***** [ Files / Folders ] *****
    Folder Deleted : C:\ProgramData\AVG Secure Search
    Folder Deleted : C:\Program Files (x86)\SendSpace
    Folder Deleted : C:\Program Files\Uninstaller
    Folder Deleted : C:\Users\Tony\AppData\Local\Temp\AirInstaller
    Folder Deleted : C:\Users\Tony\AppData\Local\Temp\mt_ffx
    File Deleted : C:\Windows\System32\roboot64.exe
    File Deleted : C:\Users\Tony\AppData\Local\Temp\Uninstall.exe
    ***** [ Scheduled Tasks ] *****
    Task Deleted : Dealply
    Task Deleted : DealPlyUpdate
    Task Deleted : Desk 365 RunAsStdUser
    Task Deleted : DSite
    Task Deleted : VisualBeeRecovery
    ***** [ Shortcuts ] *****

    ***** [ Registry ] *****
    Key Deleted : HKCU\Software\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
    Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
    Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
    Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\avg-secure-search-installer_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\avg-secure-search-installer_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Discount Buddy_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Discount Buddy_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup{2_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup{2_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Supreme Savings_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Supreme Savings_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A1CCCE0D-AE21-42A2-BE58-8E6109410995}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
    Key Deleted : HKLM\SOFTWARE\hdcode
    Key Deleted : HKLM\SOFTWARE\VBMZ
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DSite
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DMUninstaller
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Printer for Windows5.0.0.0
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EE58E3C298524145B73CBBED3CAC4D3
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0
    ***** [ Browsers ] *****
    -\\ Internet Explorer v11.0.9600.17239

    -\\ Mozilla Firefox v31.0 (x86 en-US)
    [ File : C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\prefs.js ]

    [ File : C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js ]

    [ File : C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_594348\prefs.js ]

    -\\ Google Chrome v36.0.1985.143
    [ File : C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\preferences ]
    Deleted [Search Provider] : hxxp://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=GB&userid=15a456a1-05ac-4efb-9d66-b0a1a64d91f7&searchtype=ds&q={searchTerms}&installDate=01/06/2013
    Deleted [Search Provider] : hxxp://uk.ask.com/web?q={searchTerms}
    Deleted [Search Provider] : hxxp://search.certified-toolbar.com?si=71578&st=bs&tid=8195&ver=4.9&ts=1383397363376&tguid=71578-8195-1383397363376-5E396195B007C0A662761ADF2A0188B5&q={searchTerms}
    Deleted [Extension] : bakijjialdiiboeaknfpmflphhmljfkd
    Deleted [Extension] : bopakagnckmlgajfccecajhnimjiiedh
    *************************
    AdwCleaner[R0].txt - [42574 octets] - [06/11/2013 18:45:33]
    AdwCleaner[R1].txt - [8051 octets] - [29/08/2014 08:57:53]
    AdwCleaner[S0].txt - [41288 octets] - [06/11/2013 18:46:36]
    AdwCleaner[S1].txt - [8008 octets] - [29/08/2014 08:59:42]
    ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [8068 octets] ##########



    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-08-2014
    Ran by Tony (administrator) on TONY-HP on 29-08-2014 09:14:54
    Running from C:\Users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZ2BIDZM
    Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
    Internet Explorer Version 11
    Boot Mode: Normal
    The only official download link for FRST:
    Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
    Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
    Download link from any site other than Bleeping Computer is unpermitted or outdated.
    See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
    ==================== Processes (Whitelisted) =================
    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
    (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Alcatel-Lucent) C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\MAHostService.exe
    (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    (Joyent, Inc) C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\node.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
    (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
    (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
    (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
    (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
    (Mirics Semiconductor) C:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe
    (Mirics Ltd.) C:\Program Files\MiricsFlexiTV\DVBT\DVBservice.exe
    (Mirics Semiconductor) C:\Program Files\MiricsFlexiTV\Driver\MSiBdaDemodWrapper.exe
    (Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\pcCMService.exe
    (Alcatel-Lucent) C:\Program Files\Common Files\Motive\pcCMService.exe
    (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
    (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
    (Intel Corporation) C:\Windows\System32\igfxtray.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
    (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
    (Alcatel-Lucent) C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
    (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
    (Hobbyist Software) C:\Program Files (x86)\Hobbyist Software\VLC Streamer\VLC Streamer Configuration.exe
    (Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\pcContextHookShim.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
    (Portrait Displays, Inc) C:\Program Files (x86)\Hewlett-Packard\HP My Display\OSDManager.exe
    (Sony Corporation) C:\Program Files (x86)\Sony\Bloggie Software\BGVolumeWatcher.exe
    (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
    () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    (CyberLink) C:\Program Files (x86)\Cyberlink\YouCam\YCMMirage.exe
    (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
    () C:\Program Files (x86)\Portrait Displays\Pivot Pro Plugin\wpCtrl.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Portrait Displays, Inc) C:\Program Files (x86)\Hewlett-Packard\HP My Display\dthtml.exe
    (Portrait Displays Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Shared\HookManager.exe
    (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSDKHelperx64.exe
    (Intel Corporation) C:\Windows\System32\igfxext.exe
    (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
    () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper.exe
    () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper64.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
    (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_14_0_0_176_ActiveX.exe
    (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe

    ==================== Registry (Whitelisted) ==================
    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
    HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
    HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1424896 2012-10-22] (IDT, Inc.)
    HKLM\...\Run: [btbb_McciTrayApp] => C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe [2860856 2013-11-11] (Alcatel-Lucent)
    HKLM-x32\...\Run: [HP Software Update] => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [HP Remote Solution] => C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe [656896 2009-08-25] (Hewlett-Packard)
    HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-09-27] (EasyBits Software AS)
    HKLM-x32\...\Run: [DT HPO] => C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe [120400 2012-08-16] (Portrait Displays, Inc.)
    HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-08-12] (PDF Complete Inc)
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
    HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
    HKLM-x32\...\Run: [PivotSoftware] => C:\Program Files (x86)\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe [110192 2010-05-13] ()
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-04-03] (DivX, LLC)
    HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1232896 2013-10-24] (Easybits)
    HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
    HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
    HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
    HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-07-08] (Hewlett-Packard)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
    HKLM\...\Policies\Explorer: [NoControlPanel] 0
    HKLM\...\Policies\Explorer: [NoFolderOptions] 0
    HKU\S-1-5-21-131991233-2839458126-3920297457-1001\...\Run: [MobileDocuments] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
    HKU\S-1-5-21-131991233-2839458126-3920297457-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7762712 2014-08-13] (SUPERAntiSpyware)
    HKU\S-1-5-21-131991233-2839458126-3920297457-1001\...\Run: [Hobbyist Software VLC Streamer] => C:\Program Files (x86)\Hobbyist Software\VLC Streamer\VLC Streamer Configuration.exe [1193288 2014-08-18] (Hobbyist Software)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bloggie Watcher Utility.lnk
    ShortcutTarget: Bloggie Watcher Utility.lnk -> C:\Program Files (x86)\Sony\Bloggie Software\BGVolumeWatcher.exe (Sony Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
    ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
    ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
    ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
    ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
    ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
    ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
    ==================== Internet (Whitelisted) ====================
    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.co.uk/
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchScopes: HKLM - {251B63F3-36E5-4F04-93D6-F4E9D2977C49} URL = http://www.amazon.co.uk/s/ref=azs_o...code=qs&index=aps&field-keywords={searchTerms}
    SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/710-1...//www.ebay.co.uk/sch/i.html?_nkw={searchTerms}
    SearchScopes: HKLM-x32 - Backup.Old.DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    SearchScopes: HKCU - {251B63F3-36E5-4F04-93D6-F4E9D2977C49} URL =
    SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
    BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
    BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
    BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
    BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
    BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
    Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
    Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
    Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
    Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
    Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
    Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
    ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2012-04-11] (EasyBits Software Corp.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254
    FireFox:
    ========
    FF ProfilePath: C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668
    FF NewTab: about:home
    FF DefaultSearchEngine: Bing
    FF SelectedSearchEngine: Bing
    FF Homepage: hxxp://uk.msn.com/
    FF Keyword.URL: user_pref("keyword.URL", "");
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
    FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
    FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF Plugin-x32: @ASC/FileLabPlugin;version=1.1.33 -> C:\ProgramData\FileLab\Plugin\Framework\npFlPluginS.dll (FileLab)
    FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
    FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @Motive.com/NpMotive,version=1.0 -> C:\Program Files (x86)\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
    FF Plugin-x32: @Motive.com/npMotiveRequest,version=1.0 -> C:\Program Files (x86)\Common Files\Motive\npMotiveRequest.dll (Alcatel-Lucent)
    FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin HKCU: @sony.com/Some -> C:\Program Files (x86)\Sony\Bloggie Software\npsome.dll (Sony)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
    FF Extension: Flash Video Downloader - YouTube Full HD Download - C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\Extensions\artur.dubovoy@gmail.com [2014-08-01]
    FF Extension: HomeTab - C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\Extensions\{4ca8c1be-c30f-49bf-9ac8-f3e63f49665d} [2013-11-02]
    FF Extension: DownloadHelper - C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-08-09]
    FF Extension: MEGA - C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\Extensions\firefox@mega.co.nz.xpi [2013-03-14]
    FF Extension: ImageGrabber - C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\Extensions\{546d2a00-2bbf-11dc-8314-0800200c9a66}.xpi [2013-03-20]
    FF Extension: BT DesktopHelp extension - C:\Program Files (x86)\Mozilla Firefox\extensions\mcciwbch@motive.com.xpi [2014-07-30]
    FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\mcciwbch@motive.com.xpi [2014-07-30]
    FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]
    FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
    FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2012-09-07]
    FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
    FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
    Chrome:
    =======
    CHR HomePage: Default ->
    CHR StartupUrls: Default -> "hxxp://mysearch.avg.com?cid={E7AE3A81-3542-4C93-A479-C892EF86BF35}&mid=3d758e6b1cc64be1a414b11ccceea2c4-13f7a46765dbab8bfdb2aa13e197f078ae1db1dc&lang=en&ds=gm011&coid=avgtbdisgm&cmpid=&pr=sa&d=2013-12-21 11:14:34&v=17.2.0.38&pid=safeguard&sg=&sap=hp"
    CHR DefaultSearchKeyword: Default -> mcafee
    CHR DefaultSearchProvider: Default -> McAfee
    CHR DefaultSearchURL: Default -> https://uk.search.yahoo.com/search?fr=mcafee&type=A211GB691&p={searchTerms}
    CHR Profile: C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-05]
    CHR Extension: (Google Wallet) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-03]
    CHR HKLM-x32\...\Chrome\Extension: [edmgmpmklgfbohogafcfobonnkogchec] - C:\Program Files (x86)\Common Files\Motive\extensions\MotiveRequest.crx []
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
    CHR HKLM-x32\...\Chrome\Extension: [oihiaojfckjaconbjjpanjechlighodn] - C:\Program Files (x86)\HomeTab\chrome\HomeTab.crx [2014-07-14]
    ==================== Services (Whitelisted) =================
    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-08-13] (SUPERAntiSpyware.com)
    R2 BT Help Wizard; C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\MAHostService.exe [321024 2014-04-09] (Alcatel-Lucent) [File not signed]
    R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
    R2 CalendarSynchService; C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [16384 2011-08-16] (Hewlett-Packard) [File not signed]
    R2 DTSRVC; C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe [136784 2012-08-16] (Portrait Displays, Inc.)
    R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
    R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
    R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2375168 2011-03-08] (Realsil Microelectronics Inc.) [File not signed]
    R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
    R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
    R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [603424 2014-06-12] (McAfee, Inc.)
    R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-06-18] (McAfee, Inc.)
    R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
    R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
    R2 msi2500scan; c:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe [229376 2011-12-16] (Mirics Semiconductor)
    R2 MSiDVBT; c:\Program Files\MiricsFlexiTV\DVBT\DVBService.exe [2715648 2011-12-16] (Mirics Ltd.)
    R2 pcCMService64; C:\Program Files\Common Files\Motive\pcCMService.exe [467256 2013-11-11] (Alcatel-Lucent)
    R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-08-12] (PDF Complete Inc)
    ==================== Drivers (Whitelisted) ====================
    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
    R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
    S3 CpqDfw; C:\Windows\System32\drivers\CpqDfw.sys [27456 2012-05-29] (Windows (R) Codename Longhorn DDK provider)
    S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
    R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
    R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
    R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
    R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
    R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [444720 2014-06-18] (McAfee, Inc.)
    S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96592 2014-06-18] (McAfee, Inc.)
    R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
    S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
    S3 MREMP50a64; C:\Program Files\Common Files\Motive\MREMP50a64.SYS [43008 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
    S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
    S3 MRESP50a64; C:\Program Files\Common Files\Motive\MRESP50a64.SYS [40960 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
    R3 MSi2500BDA; C:\Windows\System32\DRIVERS\AVerMsiBDA.sys [228352 2011-12-16] (AVerMedia TECHNOLOGIES, Inc.)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S3 MREMPR5; \??\C:\PROGRA~2\COMMON~1\Motive\MREMPR5.SYS [X]
    S3 MRENDIS5; \??\C:\PROGRA~2\COMMON~1\Motive\MRENDIS5.SYS [X]
    S2 NEWDRIVER; \??\C:\Windows\SysWow64\WinVDEdrv6.sys [X]
    S2 RHDISK_AMD64; \??\C:\Program Files (x86)\Rohos\RHDISK_AMD64.SYS [X]
    ==================== NetSvcs (Whitelisted) ===================
    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

    ==================== One Month Created Files and Folders ========
    (If an entry is included in the fixlist, the file\folder will be moved.)
    2014-08-29 09:14 - 2014-08-29 09:15 - 00000000 ____D () C:\FRST
    2014-08-29 09:05 - 2014-08-29 09:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
    2014-08-29 08:58 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
    2014-08-29 08:51 - 2014-08-29 08:51 - 00004952 _____ () C:\Users\Tony\Desktop\JRT.txt
    2014-08-29 08:44 - 2014-08-29 08:44 - 00000000 ____D () C:\Windows\ERUNT
    2014-08-28 09:02 - 2014-08-23 03:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
    2014-08-28 09:02 - 2014-08-23 02:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
    2014-08-28 09:02 - 2014-08-23 01:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2014-08-27 11:16 - 2014-08-27 11:48 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-08-27 11:16 - 2014-08-27 11:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2014-08-27 11:15 - 2014-08-27 11:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-08-27 11:15 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-08-27 11:15 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2014-08-24 14:27 - 2014-08-24 14:27 - 00000000 ____D () C:\Users\Tony\AppData\Local\Adobe
    2014-08-19 09:52 - 2014-08-19 09:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VLC Streamer
    2014-08-16 01:59 - 2014-08-29 08:41 - 00003180 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForTony
    2014-08-14 10:27 - 2014-08-14 10:27 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
    2014-08-14 10:27 - 2014-08-14 10:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files\iTunes
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files\iPod
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files (x86)\iTunes
    2014-08-13 22:36 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
    2014-08-13 22:36 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
    2014-08-13 22:36 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
    2014-08-13 22:36 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
    2014-08-13 22:36 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
    2014-08-13 22:36 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
    2014-08-13 22:36 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
    2014-08-13 22:36 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
    2014-08-13 08:28 - 2014-08-01 00:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2014-08-13 08:28 - 2014-07-25 15:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2014-08-13 08:28 - 2014-07-25 15:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2014-08-13 08:28 - 2014-07-25 14:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2014-08-13 08:28 - 2014-07-25 14:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2014-08-13 08:28 - 2014-07-25 14:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2014-08-13 08:28 - 2014-07-25 14:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2014-08-13 08:28 - 2014-07-25 13:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2014-08-13 08:28 - 2014-07-25 13:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2014-08-13 08:28 - 2014-07-25 13:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2014-08-13 08:28 - 2014-07-25 13:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2014-08-13 08:28 - 2014-07-25 13:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2014-08-13 08:28 - 2014-07-25 13:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2014-08-13 08:28 - 2014-07-25 13:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2014-08-13 08:28 - 2014-07-25 13:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2014-08-13 08:28 - 2014-07-25 13:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2014-08-13 08:28 - 2014-07-25 12:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2014-08-13 08:28 - 2014-07-25 12:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2014-08-13 08:28 - 2014-07-25 12:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2014-08-13 08:28 - 2014-07-25 12:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2014-08-13 08:28 - 2014-07-25 12:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2014-08-13 08:28 - 2014-07-25 12:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2014-08-13 08:28 - 2014-07-25 12:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2014-08-13 08:28 - 2014-07-25 12:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2014-08-13 08:28 - 2014-07-25 11:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2014-08-13 08:28 - 2014-07-25 11:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2014-08-13 08:28 - 2014-07-16 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
    2014-08-13 08:28 - 2014-07-16 03:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2014-08-13 08:28 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
    2014-08-13 08:28 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
    2014-08-13 08:28 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
    2014-08-13 08:28 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
    2014-08-13 08:28 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
    2014-08-13 08:28 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
    2014-08-13 08:28 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
    2014-08-13 08:28 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
    2014-08-13 08:28 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
    2014-08-13 08:28 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
    2014-08-13 08:28 - 2014-07-08 23:38 - 00419992 _____ () C:\Windows\system32\locale.nls
    2014-08-13 08:28 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
    2014-08-13 08:28 - 2014-06-25 03:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
    2014-08-13 08:28 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2014-08-13 08:28 - 2014-06-16 03:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
    2014-08-13 08:28 - 2014-06-03 11:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
    2014-08-13 08:28 - 2014-06-03 11:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
    2014-08-13 08:28 - 2014-06-03 11:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
    2014-08-13 08:28 - 2014-06-03 11:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
    2014-08-13 08:28 - 2014-06-03 10:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2014-08-13 08:28 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2014-08-13 08:28 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
    2014-08-13 08:27 - 2014-08-01 00:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2014-08-13 08:27 - 2014-07-25 15:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2014-08-13 08:27 - 2014-07-25 14:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2014-08-13 08:27 - 2014-07-25 14:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2014-08-13 08:27 - 2014-07-25 14:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2014-08-13 08:27 - 2014-07-25 14:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2014-08-13 08:27 - 2014-07-25 14:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2014-08-13 08:27 - 2014-07-25 14:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2014-08-13 08:27 - 2014-07-25 14:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2014-08-13 08:27 - 2014-07-25 14:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2014-08-13 08:27 - 2014-07-25 13:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2014-08-13 08:27 - 2014-07-25 13:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2014-08-13 08:27 - 2014-07-25 13:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2014-08-13 08:27 - 2014-07-25 13:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2014-08-13 08:27 - 2014-07-25 13:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2014-08-13 08:27 - 2014-07-25 13:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2014-08-13 08:27 - 2014-07-25 13:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2014-08-13 08:27 - 2014-07-25 13:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2014-08-13 08:27 - 2014-07-25 13:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2014-08-13 08:27 - 2014-07-25 13:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2014-08-13 08:27 - 2014-07-25 12:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2014-08-13 08:27 - 2014-07-25 12:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2014-08-13 08:27 - 2014-07-25 12:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2014-08-13 08:27 - 2014-07-25 12:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2014-08-13 08:27 - 2014-07-25 12:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2014-08-13 08:27 - 2014-07-25 12:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2014-08-13 08:27 - 2014-07-25 11:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2014-08-13 08:27 - 2014-07-25 11:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2014-08-13 08:27 - 2014-07-25 11:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2014-08-13 08:27 - 2014-07-25 11:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2014-08-13 08:25 - 2014-08-07 03:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2014-08-13 08:25 - 2014-08-07 03:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2014-08-13 08:25 - 2014-07-14 03:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2014-08-13 08:25 - 2014-07-14 02:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2014-08-02 15:49 - 2014-08-02 15:49 - 00000124 _____ () C:\Windows\wininit.ini
    2014-08-02 15:49 - 2014-08-02 15:49 - 00000000 ____D () C:\ProgramData\GRETECH
    2014-08-01 08:56 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2014-08-01 08:56 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2014-08-01 08:56 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2014-08-01 08:56 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2014-08-01 08:55 - 2014-05-14 17:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2014-08-01 08:55 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2014-08-01 08:55 - 2014-05-14 17:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2014-08-01 08:55 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2014-08-01 08:55 - 2014-05-14 17:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2014-08-01 08:55 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2014-08-01 08:55 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2014-08-01 08:55 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2014-08-01 08:55 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2014-08-01 08:55 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2014-07-30 10:54 - 2014-07-30 10:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    ==================== One Month Modified Files and Folders =======
    (If an entry is included in the fixlist, the file\folder will be moved.)
    2014-08-29 09:15 - 2014-08-29 09:14 - 00000000 ____D () C:\FRST
    2014-08-29 09:08 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2014-08-29 09:08 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2014-08-29 09:05 - 2014-08-29 09:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
    2014-08-29 09:05 - 2012-09-07 11:31 - 00001846 _____ () C:\Users\Public\Desktop\BT NetProtect Plus.lnk
    2014-08-29 09:05 - 2012-07-17 15:43 - 02025696 _____ () C:\Windows\WindowsUpdate.log
    2014-08-29 09:05 - 2009-07-14 06:13 - 00783360 _____ () C:\Windows\system32\PerfStringBackup.INI
    2014-08-29 09:01 - 2012-10-03 15:54 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
    2014-08-29 09:01 - 2012-07-18 16:26 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-08-29 09:01 - 2012-04-11 15:56 - 00000000 ____D () C:\ProgramData\PDFC
    2014-08-29 09:00 - 2014-07-01 09:52 - 00000328 _____ () C:\Windows\Tasks\HPCeeScheduleForTony.job
    2014-08-29 09:00 - 2010-11-21 04:47 - 01131722 _____ () C:\Windows\PFRO.log
    2014-08-29 09:00 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2014-08-29 09:00 - 2009-07-14 05:51 - 00080337 _____ () C:\Windows\setupact.log
    2014-08-29 08:59 - 2013-11-06 18:45 - 00000000 ____D () C:\AdwCleaner
    2014-08-29 08:51 - 2014-08-29 08:51 - 00004952 _____ () C:\Users\Tony\Desktop\JRT.txt
    2014-08-29 08:44 - 2014-08-29 08:44 - 00000000 ____D () C:\Windows\ERUNT
    2014-08-29 08:43 - 2012-07-18 16:26 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-08-29 08:41 - 2014-08-16 01:59 - 00003180 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForTony
    2014-08-29 08:41 - 2012-07-18 10:06 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2014-08-29 08:35 - 2009-07-14 05:45 - 00280872 _____ () C:\Windows\system32\FNTCACHE.DAT
    2014-08-28 20:27 - 2012-07-17 15:51 - 00003918 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{654B34D5-AE44-4A92-AD8E-01A23DF2D396}
    2014-08-28 17:47 - 2012-07-17 23:45 - 00000000 ____D () C:\ProgramData\Zoom Player
    2014-08-28 16:28 - 2012-07-21 13:38 - 00000000 ____D () C:\Users\Tony\AppData\Local\CrashDumps
    2014-08-28 11:02 - 2012-07-18 17:43 - 00000000 ____D () C:\ProgramData\ACD Systems
    2014-08-27 18:57 - 2012-07-26 01:10 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
    2014-08-27 18:57 - 2012-07-18 18:12 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
    2014-08-27 11:48 - 2014-08-27 11:16 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-08-27 11:39 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Speech
    2014-08-27 11:16 - 2014-08-27 11:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2014-08-27 11:16 - 2013-07-02 16:53 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2014-08-27 11:16 - 2013-03-04 11:38 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Malwarebytes
    2014-08-27 11:15 - 2014-08-27 11:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-08-27 11:15 - 2013-07-02 16:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2014-08-27 11:15 - 2013-03-04 11:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2014-08-24 15:44 - 2013-05-03 14:01 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Skype
    2014-08-24 14:27 - 2014-08-24 14:27 - 00000000 ____D () C:\Users\Tony\AppData\Local\Adobe
    2014-08-23 03:07 - 2014-08-28 09:02 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
    2014-08-23 02:45 - 2014-08-28 09:02 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
    2014-08-23 01:59 - 2014-08-28 09:02 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2014-08-22 17:16 - 2013-12-20 12:14 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\avidemux
    2014-08-21 11:41 - 2012-07-18 10:06 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2014-08-21 11:30 - 2012-07-18 10:06 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2014-08-21 11:30 - 2012-04-11 15:46 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2014-08-19 09:52 - 2014-08-19 09:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VLC Streamer
    2014-08-19 09:52 - 2013-03-21 12:03 - 00000000 ____D () C:\Program Files (x86)\Hobbyist Software
    2014-08-14 13:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
    2014-08-14 10:27 - 2014-08-14 10:27 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
    2014-08-14 10:27 - 2014-08-14 10:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files\iTunes
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files\iPod
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files (x86)\iTunes
    2014-08-14 09:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
    2014-08-13 22:44 - 2013-08-14 22:48 - 00000000 ____D () C:\Windows\system32\MRT
    2014-08-13 22:40 - 2012-07-23 09:28 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2014-08-13 22:35 - 2014-05-06 22:07 - 00000000 ___SD () C:\Windows\system32\CompatTel
    2014-08-13 12:09 - 2013-06-15 12:26 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\vlc
    2014-08-12 20:52 - 2012-08-28 08:54 - 00002185 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2014-08-08 10:06 - 2013-06-27 14:48 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\uTorrent
    2014-08-07 03:06 - 2014-08-13 08:25 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2014-08-07 03:01 - 2014-08-13 08:25 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2014-08-05 09:20 - 2010-11-21 04:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
    2014-08-05 08:57 - 2014-03-13 14:53 - 00000000 ___RD () C:\Program Files (x86)\Skype
    2014-08-05 08:57 - 2012-04-11 15:45 - 00000000 ____D () C:\ProgramData\Skype
    2014-08-03 11:03 - 2012-09-07 11:30 - 00000000 ____D () C:\Program Files (x86)\McAfee
    2014-08-02 15:49 - 2014-08-02 15:49 - 00000124 _____ () C:\Windows\wininit.ini
    2014-08-02 15:49 - 2014-08-02 15:49 - 00000000 ____D () C:\ProgramData\GRETECH
    2014-08-02 15:49 - 2013-02-11 23:12 - 00001211 _____ () C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
    2014-08-02 15:49 - 2012-08-23 18:43 - 00001187 _____ () C:\Users\Public\Desktop\GOM Player.lnk
    2014-08-01 00:41 - 2014-08-13 08:27 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2014-08-01 00:16 - 2014-08-13 08:28 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2014-07-31 14:37 - 2012-07-19 22:00 - 00009216 _____ () C:\Users\Tony\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2014-07-31 09:55 - 2012-07-17 16:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
    2014-07-30 10:55 - 2014-07-30 10:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    Some content of TEMP:
    ====================
    C:\Users\Tony\AppData\Local\Temp\airD8B3.exe
    C:\Users\Tony\AppData\Local\Temp\apptorun.exe
    C:\Users\Tony\AppData\Local\Temp\avguidx.dll
    C:\Users\Tony\AppData\Local\Temp\BackupSetup.exe
    C:\Users\Tony\AppData\Local\Temp\cg_qcnqv.dll
    C:\Users\Tony\AppData\Local\Temp\CommonInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\eSafeSvc.exe
    C:\Users\Tony\AppData\Local\Temp\ExPromo.exe
    C:\Users\Tony\AppData\Local\Temp\Extract.exe
    C:\Users\Tony\AppData\Local\Temp\free-hide-folder.exe
    C:\Users\Tony\AppData\Local\Temp\GomAudDnInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\GomEncDnInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\HPHelpUpdater.exe
    C:\Users\Tony\AppData\Local\Temp\HPPSdr.exe
    C:\Users\Tony\AppData\Local\Temp\instruct.exe
    C:\Users\Tony\AppData\Local\Temp\launcher.exe
    C:\Users\Tony\AppData\Local\Temp\MachineIdCreator.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{0B3A180C-0270-4BAD-BE2D-51C23267FA5C}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{376AD83B-18D4-4178-B382-BA08C08C4B44}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{6C4DC06A-72B3-4FB2-87D5-34DA62BE4F18}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{EAA3C375-2E1F-4A76-B2C8-4050037AA001}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{EAACB772-C4BF-4AB1-B433-2F2E92C1D030}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{F2D8CEDF-EF03-4769-95E6-64C765645308}.exe
    C:\Users\Tony\AppData\Local\Temp\pcDesktopAlertNotifierX.dll
    C:\Users\Tony\AppData\Local\Temp\pmllflwn.dll
    C:\Users\Tony\AppData\Local\Temp\Quarantine.exe
    C:\Users\Tony\AppData\Local\Temp\Resource.exe
    C:\Users\Tony\AppData\Local\Temp\RSPUpgradeInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\Runner.exe
    C:\Users\Tony\AppData\Local\Temp\safeguard.exe
    C:\Users\Tony\AppData\Local\Temp\SAS6_Update.exe
    C:\Users\Tony\AppData\Local\Temp\SendMsg.dll
    C:\Users\Tony\AppData\Local\Temp\SIMEEIInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\SkypeSetup.exe
    C:\Users\Tony\AppData\Local\Temp\SP57550.exe
    C:\Users\Tony\AppData\Local\Temp\sp58915.exe
    C:\Users\Tony\AppData\Local\Temp\SP59509.exe
    C:\Users\Tony\AppData\Local\Temp\sp64126.exe
    C:\Users\Tony\AppData\Local\Temp\SP65786.exe
    C:\Users\Tony\AppData\Local\Temp\SSUPDATE64.EXE
    C:\Users\Tony\AppData\Local\Temp\ToolbarInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\uninst1.exe
    C:\Users\Tony\AppData\Local\Temp\UninstallHPSA.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.0.2-win32.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.0.4-win32.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.0.5-win32.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.1.4-win64.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.1.5-win64.exe
    C:\Users\Tony\AppData\Local\Temp\VLCStreamerSetup.exe

    ==================== Bamital & volsnap Check =================
    (There is no automatic fix for files that do not pass verification.)
    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2014-08-27 10:12
    ==================== End Of Log ============================


    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-08-2014
    Ran by Tony at 2014-08-29 09:16:13
    Running from C:\Users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZ2BIDZM
    Boot Mode: Normal
    ==========================================================

    ==================== Security Center ========================
    (If an entry is included in the fixlist, it will be removed.)
    AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
    AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}
    ==================== Installed Programs ======================
    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
    7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
    AC3Filter 2.6.0b (HKLM-x32\...\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
    Adobe AIR (x32 Version: 4.0.0.1390 - Adobe Systems Incorporated) Hidden
    Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.176 - Adobe Systems Incorporated)
    Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.179 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.08) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
    Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Avidemux 2.6 (32-bit) (HKLM-x32\...\Avidemux 2.6) (Version: 2.6.7.8981 - )
    AVS Screen Capture version 2.0.1 (HKLM-x32\...\AVS Screen Capture_is1) (Version: - Online Media Technologies Ltd.)
    AVS Update Manager 1.0 (HKLM-x32\...\AVS Update Manager_is1) (Version: - Online Media Technologies Ltd.)
    AVS Video Editor 6 (HKLM-x32\...\AVS Video Editor_is1) (Version: - Online Media Technologies Ltd.)
    AVS Video Recorder 2.5 (HKLM-x32\...\AVS Video Recorder_is1) (Version: - Online Media Technologies Ltd.)
    AVS4YOU Software Navigator 1.4 (HKLM-x32\...\AVS4YOU Software Navigator_is1) (Version: - Online Media Technologies Ltd.)
    Bass Audio Decoder (remove only) (HKLM-x32\...\Bass Audio Decoder) (Version: - )
    BBC iPlayer Desktop (HKLM-x32\...\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1) (Version: 3.2.15 - British Broadcasting Corp.)
    BBC iPlayer Desktop (x32 Version: 3.2.15 - British Broadcasting Corp.) Hidden
    Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Bing Bar (HKLM-x32\...\{9FA13759-5C2B-4177-9DDC-0038F8B5BEFD}) (Version: 7.0.826.0 - Microsoft Corporation)
    Blio (HKLM-x32\...\{741006D1-7B2B-4E33-B2B0-831F282EEF64}) (Version: 2.2.8188 - K-NFB Reading Technology, Inc.)
    Bloggie Software (HKLM-x32\...\BloggieSoftware) (Version: 3.3.1.73 - Sony)
    Bloggie Software (x32 Version: 3.3.1.73 - Sony Corporation) Hidden
    Bluetooth by hp (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.8200 - Broadcom Corporation)
    Boilsoft Video Joiner 6.57 (HKLM-x32\...\{FD39EF4B-0B5C-4B33-8D57-2EE865A80EB1}_is1) (Version: - Boilsoft, Inc.)
    Boilsoft Video Splitter 6.34 (HKLM-x32\...\{24549038-9956-4EE5-976D-4419AAEA7DD5}_is1) (Version: - Boilsoft, Inc.)
    Boilsoft WMV Converter 1.51 (HKLM-x32\...\{4F556FDB-C47D-4897-A2F2-EC53AC7F8DA6}_is1) (Version: - Boilsoft.Inc.)
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    BT Desktop Help (HKLM-x32\...\BT Desktop Help) (Version: - )
    BT NetProtect Plus (HKLM-x32\...\MSC) (Version: 12.8.958 - McAfee, Inc.)
    Cake Mania (x32 Version: 2.2.0.98 - WildTangent) Hidden
    CD Audio Reader Filter (remove only) (HKLM-x32\...\CD Audio Reader Filter) (Version: - )
    Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
    ConvertHelper 2.2 (HKLM-x32\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1) (Version: - DownloadHelper)
    Cradle of Rome 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
    CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.0.4417 - CyberLink Corp.)
    CyberLink YouCam (x32 Version: 3.5.0.4417 - CyberLink Corp.) Hidden
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    DC-Bass Source 1.3.0 (HKLM-x32\...\DC-Bass Source) (Version: - )
    DCoder Image Source (remove only) (HKLM-x32\...\DCoder Image Source) (Version: - )
    DirectVobSub (remove only) (HKLM-x32\...\DirectVobSub) (Version: - )
    DirectVobSub 2.40.4209 (HKLM-x32\...\vsfilter_is1) (Version: 2.40.4209 - MPC-HC Team)
    DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
    DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.3.22 - DivX, LLC)
    DScaler 5 Mpeg Decoders (HKLM-x32\...\DScaler 5 Mpeg Decoders_is1) (Version: - )
    Facebook (HKLM-x32\...\{8AE50893-3A87-4439-9A57-942ED43F7189}) (Version: 1.1.0004 - Hewlett-Packard)
    Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Farmscapes (x32 Version: 2.2.0.98 - WildTangent) Hidden
    FastStone Image Viewer 4.6 (HKLM-x32\...\FastStone Image Viewer) (Version: 4.6 - FastStone Soft)
    FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
    ffdshow v1.2.4453 [2012-05-21] (HKLM-x32\...\ffdshow_is1) (Version: 1.2.4453.0 - )
    FFMPEG Core Files (remove only) (HKLM-x32\...\FFMPEG Core Files) (Version: - )
    FileLab Plugin 1.1.33 (HKLM-x32\...\{6AC5F630-9453-433D-90FF-BB3A8E4F8960}) (Version: 1.1.33 - FileLab)
    Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Fishdom (TM) 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Freemake Video Converter version 4.1.2 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.2 - Ellora Assets Corporation)
    Gabest MPEG Splitter (remove only) (HKLM-x32\...\Gabest MPEG Splitter) (Version: - )
    GOM Player (HKLM-x32\...\GOM Player) (Version: 2.2.62.5207 - Gretech Corporation)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.143 - Google Inc.)
    Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
    Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
    Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version: - )
    Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
    HP Auto (Version: 1.0.12935.3667 - Hewlett-Packard Company) Hidden
    HP Calendar (HKLM-x32\...\{2B38E0FA-D8A5-4EBF-A018-E3C1C8E7A2E2}) (Version: 5.1.4245.23508 - Hewlett-Packard)
    HP Client Services (Version: 1.1.12938.3539 - Hewlett-Packard) Hidden
    HP Clock (HKLM-x32\...\{0EEC4E49-D4C2-4E23-87F2-B5641F1A09E4}) (Version: 5.1.4244.16367 - Hewlett-Packard)
    HP Customer Experience Enhancements (x32 Version: 6.0.1.8 - Hewlett-Packard) Hidden
    HP Deskjet 3050 J610 series Basic Device Software (HKLM\...\{650AF771-456D-418F-BFC7-F6FFC9D0235C}) (Version: 22.0.334.0 - Hewlett-Packard Co.)
    HP Deskjet 3050 J610 series Help (HKLM-x32\...\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}) (Version: 140.0.63.63 - Hewlett Packard)
    HP Deskjet 3050 J610 series Product Improvement Study (HKLM\...\{FEB2C4AA-661E-483F-9626-21A8ACFD10F2}) (Version: 22.0.334.0 - Hewlett-Packard Co.)
    HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent)
    HP LinkUp (HKLM-x32\...\{7E750542-55BC-4300-8B7B-AC2A762FB435}) (Version: 2.01.029 - Hewlett-Packard)
    HP Magic Canvas (HKLM-x32\...\{DDFDC9D6-4220-41F8-BF9A-8E7512C4EF52}) (Version: 5.1.15.0 - Hewlett-Packard)
    HP Magic Canvas Tutorials (HKLM-x32\...\{858FCB65-7C6D-4BA4-AD80-A3CB3744CE09}_is1) (Version: 5.0.0.3 - Hewlett-Packard)
    HP My Display (HKLM-x32\...\{1F4DDC90-5923-4E49-A4C7-F3CCC954DCA0}) (Version: 1.12.004 - Portrait Displays, Inc.)
    HP Notes (HKLM-x32\...\{86BAB08A-5E66-4C53-82E3-C1E91673C7CA}) (Version: 5.1.4274.30382 - Hewlett-Packard)
    HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
    HP Remote Solution (HKLM-x32\...\HP Remote Solution) (Version: 1.1.14.0 - Hewlett-Packard)
    HP Remote Solution (x32 Version: 1.1.14.0 - Hewlett-Packard) Hidden
    HP RSS (HKLM-x32\...\{A35E58D6-2A0F-4051-983B-79342081338E}) (Version: 5.1.4301.21494 - Hewlett-Packard)
    HP Setup (HKLM-x32\...\{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}) (Version: 9.0.15130.3904 - Hewlett-Packard Company)
    HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.2.15145.3905 - Hewlett-Packard Company)
    HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
    HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 11.00.0001 - Hewlett-Packard)
    HP TouchSmart Background - Beats (HKLM-x32\...\{6A6F8D36-04BA-41E9-9004-1789BD545874}) (Version: 1.0.1.0 - Hewlett-Packard)
    HP TouchSmart RecipeBox (HKLM-x32\...\{20714B53-FC73-4F9C-9687-49EB237D6FD7}) (Version: 3.0.3830.27730 - Hewlett-Packard)
    HP Update (HKLM-x32\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
    HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.12.1.0 - Hewlett-Packard)
    iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
    IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6370.0 - IDT)
    Insaniquarium Deluxe (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2462 - Intel Corporation)
    iTunes (HKLM\...\{77DE5105-D05E-448C-96CB-7FA381903753}) (Version: 11.3.1.2 - Apple Inc.)
    Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Jewel Quest II (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Jewel Quest Solitaire 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Kobo (HKLM-x32\...\Kobo) (Version: 2.0.3 - Kobo Inc.)
    L&H TTS3000 British English (HKLM-x32\...\LHTTSENG) (Version: - )
    LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4507 - CyberLink Corp.)
    LabelPrint (x32 Version: 2.5.4507 - CyberLink Corp.) Hidden
    Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - )
    LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
    LAV Filters 0.61.1 (HKLM-x32\...\lavfilters_is1) (Version: 0.61.1 - Hendrik Leppkes)
    MadVR (remove only) (HKLM-x32\...\MadVR) (Version: - )
    Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: 3.0 - EasyBits Software AS)
    Mahjongg Artifacts (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
    McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
    Media Preview (HKLM\...\{9EE88DE0-9E1C-43E5-9827-4C3EEB0DDE5E}) (Version: 1.3.1.343 - BabelSoft)
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Metric Converter (HKLM-x32\...\{D0661463-50F7-4A1E-83CB-37CC590589AE}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
    Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
    Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
    Microsoft Mathematics (HKLM-x32\...\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Microsoft Corporation)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Click-to-Run 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
    Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5139.5005 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
    Mozilla Firefox 31.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
    MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
    MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
    Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
    opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
    OpenSource AVI Splitter (remove only) (HKLM-x32\...\OpenSource AVI Splitter) (Version: - )
    OpenSource DTS/AC3/DD+ Source Filter (remove only) (HKLM-x32\...\OpenSource DTS/AC3/DD+ Source Filter) (Version: - )
    OpenSource Flash Video Splitter 1.0.0.5 (HKLM-x32\...\OpenSource Flash Video Splitter) (Version: 1.0.0.5 - )
    Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA)
    Opera Next 19.0.1326.9 (HKLM-x32\...\Opera 19.0.1326.9) (Version: 19.0.1326.9 - Opera Software ASA)
    Opera Next 23.0.1522.43 (HKLM-x32\...\Opera 23.0.1522.43) (Version: 23.0.1522.43 - Opera Software ASA)
    Opera Stable 20.0.1387.82 (HKLM-x32\...\Opera 20.0.1387.82) (Version: 20.0.1387.82 - Opera Software ASA)
    Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
    PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.65 - PDF Complete, Inc)
    Pivot Pro Plugin (x32 Version: 9.50.110 - Portrait Displays, Inc.) Hidden
    Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
    PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
    PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
    Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.5705 - CyberLink Corp.)
    Power2Go (x32 Version: 6.1.5705 - CyberLink Corp.) Hidden
    PressReader (HKLM-x32\...\{912CED74-88D3-4C5B-ACB0-132318649765}) (Version: 5.11.0721.0 - NewspaperDirect Inc.)
    QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
    Ranch Rush 2 - Premium Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.77.1126.2013 - Realtek)
    Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.82 - Realtek Semiconductor Corp.)
    Recovery Manager (x32 Version: 5.5.0.4424 - CyberLink Corp.) Hidden
    Remote Graphics Receiver (HKLM-x32\...\{16FC3056-90C0-4757-8A68-64D8DA846ADA}) (Version: 5.4.5 - Hewlett-Packard)
    SDK (x32 Version: 2.28.007 - Portrait Displays, Inc.) Hidden
    SendSpace Wizard (HKLM-x32\...\SendSpaceWizard) (Version: 1.4.1 - SendSpace)
    Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
    Sky Go Desktop (HKCU\...\2961178377.go.sky.com) (Version: - go.sky.com)
    Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
    Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
    StreamTransport version: 1.0.2.2171 (HKLM-x32\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - )
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.5.1022 - SUPERAntiSpyware.com)
    Torchlight (x32 Version: 2.2.0.98 - WildTangent) Hidden
    TSHostedAppLauncher (x32 Version: 5.1.15.0 - Hewlett-Packard) Hidden
    Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
    VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
    Virtual Families (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden
    VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN)
    VLC Streamer 4.77 (HKLM-x32\...\VLC Streamer_is1) (Version: - )
    Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden
    WildTangent Games App (x32 Version: 4.0.10.2 - WildTangent) Hidden
    Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
    Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
    Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
    Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
    Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
    Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
    Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
    WinRAR 4.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
    Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team)
    Zinio Reader 4 (HKLM-x32\...\ZinioReader4) (Version: 4.2.4164 - Zinio LLC)
    Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden
    Zoom Player (remove only) (HKLM-x32\...\ZoomPlayer) (Version: - )
    Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden
    ==================== Custom CLSID (selected items): ==========================
    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
    CustomCLSID: HKU\S-1-5-21-131991233-2839458126-3920297457-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Tony\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
    ==================== Restore Points =========================
    19-08-2014 07:54:20 Windows Update
    22-08-2014 08:01:52 Windows Update
    26-08-2014 08:22:09 Windows Update
    28-08-2014 10:00:27 Removed ACDSee 14.
    28-08-2014 20:58:59 Windows Update
    ==================== Hosts content: ==========================
    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
    2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
    ==================== Scheduled Tasks (whitelisted) =============
    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
    Task: {0AD59C22-ACEB-4FD8-9BE5-8D70B2BA1646} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-08-04] (Hewlett-Packard)
    Task: {1905BF32-7AD5-458A-8453-FBB6A2D69CE7} - System32\Tasks\{B46A186C-87CD-426D-BD70-BEC65E9A8C2F} => Firefox.exe
    Task: {1997A933-3C32-48D7-A569-8B6D7F3744CE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
    Task: {1A2E6077-000D-4124-B86C-035D5E2F2C2C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-18] (Google Inc.)
    Task: {1BD947A1-6CB6-4645-AF4B-F60D79E2454E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-18] (Google Inc.)
    Task: {246F16D0-284A-42F6-B94E-1C579477CA9D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-08-04] (Hewlett-Packard)
    Task: {29B4D27D-12D9-42FD-9517-C5E74F885551} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-21] (Adobe Systems Incorporated)
    Task: {2FE39EC7-6240-456F-814A-F5202153EF9A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {30BDA2F7-CD7B-4E65-A51A-24062474B954} - System32\Tasks\{4058A5F4-2D1A-4176-8096-0E64D337D43B} => Firefox.exe
    Task: {3E15E595-7DDF-4B7C-B3E3-1F9579344056} - \ProtectedSearch\Protected Search No Task File <==== ATTENTION
    Task: {40BF79AA-53CB-448E-B858-02E16049CA95} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-08-18] (CyberLink)
    Task: {4A98E2F0-72DA-4B02-AAC8-787E639DE906} - System32\Tasks\Opera scheduled Autoupdate 1372595359 => C:\Program Files (x86)\Opera Next\launcher.exe [2014-07-02] (Opera Software)
    Task: {759C1702-005B-439A-BCD8-289ACDCDE3E5} - \Browser Updater\Browser Updater No Task File <==== ATTENTION
    Task: {760188A6-A3DE-4CC1-8580-5D0ED0C924E8} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Warranty Opt-In(Yes) => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\Detection_PostWarrantyAlert.exe
    Task: {7CC1E495-3340-4CF3-93F8-264A5AA07F55} - System32\Tasks\HPCeeScheduleForTony => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
    Task: {92BCF4D0-DB3B-4A94-BEE5-238ACF769A66} - System32\Tasks\Test TimeTrigger => C:\Users\Tony\AppData\Local\Temp\Runner.exe [2012-11-02] () <==== ATTENTION
    Task: {9CDDC8E6-1CD6-4035-9616-3BE0593288FE} - System32\Tasks\RMCreator => C:\Program Files (x86)\Hewlett-Packard\Recovery\Reminder.exe [2011-08-23] (CyberLink)
    Task: {9D91621F-C81B-4C7F-A575-732136AE3EC1} - System32\Tasks\HPCustParticipation HP Deskjet 3050 J610 series => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-14] (Hewlett-Packard Co.)
    Task: {B43A93D8-E3E6-4189-AA1E-96832A6D26A0} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
    Task: {C993964C-2AE8-4AC2-988B-356D88DA0C38} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {F2076657-57E4-405C-A09C-56BEA355A55E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Warranty Opt-In(No) => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\Detection_PostWarrantyAlert.exe
    Task: {FD484260-C99F-4268-A037-FB1D5D9F09B0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\HPCeeScheduleForTony.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
    ==================== Loaded Modules (whitelisted) =============
    2012-12-27 11:06 - 2012-08-16 18:12 - 00268880 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dthook.dll
    2012-04-11 15:32 - 2011-07-27 00:37 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
    2014-01-10 06:26 - 2014-01-10 06:26 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    2012-12-27 11:06 - 2010-05-13 17:34 - 00674928 _____ () C:\Program Files (x86)\Portrait Displays\Pivot Pro Plugin\wpctrl.exe
    2012-04-11 15:50 - 2012-08-16 18:12 - 00161360 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper.exe
    2012-04-11 15:50 - 2012-08-16 18:12 - 00194640 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper64.exe
    2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2013-11-07 18:58 - 2013-11-07 18:58 - 00244736 _____ () C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\node_modules\motive-activex-wrapper\build\Release\NodeActiveXWrapper.node
    2013-11-07 18:58 - 2013-11-07 18:58 - 00271360 _____ () C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\node_modules\motive-osbridge\build\Release\MotiveOSBridgeNodeModule.node
    2013-11-07 18:57 - 2013-11-07 18:57 - 00237056 _____ () C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\node_modules\motive-xmpps\build\Release\MotiveXMPPSNode.node
    2013-04-24 08:55 - 2013-04-24 08:55 - 01581056 _____ () C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\node_modules\libxmljs\build\Release\xmljs.node
    2013-04-18 17:55 - 2013-04-18 17:55 - 00068608 _____ () C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\node_modules\dnode\node_modules\weak\build\Release\weakref.node
    2012-04-11 15:50 - 2012-01-17 17:21 - 00068104 _____ () C:\Program Files (x86)\Hewlett-Packard\HP My Display\PEGAACPIDLL.dll
    2012-04-11 15:50 - 2011-02-15 19:59 - 00015624 _____ () C:\Program Files (x86)\Hewlett-Packard\HP My Display\ACPIDll.dll
    2014-01-10 06:28 - 2014-01-10 06:28 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
    2012-04-11 15:50 - 2012-08-16 17:53 - 00180224 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Shared\PresetsCOM.dll
    ==================== Alternate Data Streams (whitelisted) =========
    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

    ==================== Safe Mode (whitelisted) ===================
    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
    ==================== EXE Association (whitelisted) =============
    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

    ==================== MSCONFIG/TASK MANAGER disabled items =========
    (Currently there is no automatic fix for this section.)
    MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup
    MSCONFIG\startupfolder: C:^Users^Tony^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^BBC iPlayer Desktop.lnk => C:\Windows\pss\BBC iPlayer Desktop.lnk.Startup
    MSCONFIG\startupreg: ACSW14EN => "C:\Program Files (x86)\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe" /pid ACSW14EN
    MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
    MSCONFIG\startupreg: BeatsOSDApp => C:\Program Files\IDT\WDM\beats64.exe
    MSCONFIG\startupreg: com.apple.dav.bookmarks.daemon => C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
    MSCONFIG\startupreg: iCloudServices => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
    MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    ==================== Faulty Device Manager Devices =============
    Name: RHDISK_AMD64
    Description: RHDISK_AMD64
    Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Manufacturer:
    Service: RHDISK_AMD64
    Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
    Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
    Devices stay in this state if they have been prepared for removal.
    After you remove the device, this error disappears.Remove the device, and this error should be resolved.

    ==================== Event log errors: =========================
    Application errors:
    ==================
    Error: (08/29/2014 09:02:14 AM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Information only.
    Click-2-Run package registration failure.
    Error: (08/29/2014 09:02:14 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: )
    Description: {tid=E88}
    The Application Virtualization Client could not connect to stream URL 'http://c2r.microsoft.com/ConsumerC2R/en-us/14.0.4763.1000/ConsumerC2R.en-us_14.0.7130.5000.sft' (rc 2460420A-40002EFD, original rc 2460420A-40002EFD).

    System errors:
    =============
    Error: (08/29/2014 09:01:53 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
    Error: (08/29/2014 09:01:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The RHDISK_AMD64 service failed to start due to the following error:
    %%3
    Error: (08/29/2014 09:00:59 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The NEWDRIVER service failed to start due to the following error:
    %%2

    Microsoft Office Sessions:
    =========================
    Error: (08/29/2014 09:02:14 AM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Click-2-Run package registration failure.
    Error: (08/29/2014 09:02:14 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: )
    Description: {tid=E88}
    http://c2r.microsoft.com/ConsumerC2...30.5000.sft2460420A-40002EFD2460420A-40002EFD

    ==================== Memory info ===========================
    Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
    Percentage of memory in use: 69%
    Total physical RAM: 4000.31 MB
    Available physical RAM: 1208.02 MB
    Total Pagefile: 7998.8 MB
    Available Pagefile: 4602.76 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.83 MB
    ==================== Drives ================================
    Drive c: (OS) (Fixed) (Total:915.04 GB) (Free:639.2 GB) NTFS
    Drive d: (HP_RECOVERY) (Fixed) (Total:16.37 GB) (Free:2.04 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive f: (Quarantine- DO NOT OPEN) (Fixed) (Total:931.48 GB) (Free:700.56 GB) NTFS
    ==================== MBR & Partition Table ==================
    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: F375266E)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=915 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=16.4 GB) - (Type=07 NTFS)
    ========================================================
    Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: A7675D2A)
    Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
    ==================== End Of Log ============================
     
  7. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Tony.

    Unfortunately FRST isn't located in one of the default folders.
    It is running from the temp internet folder:
    This will cause us a lot of problems when it comes to running a fix.
    It must be run from either the Desktop or the Download folder.
    Please use the previous instructions to download FRST.
    Do not click on Run ( when first downloading it) ...... make sure that you click on Save.
    The default folder for saved items should be either the Desktop or the Downloads folder.
    Please let me have a new scan report once it's been downloaded again.

    Thanks
     
  8. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    Ok have run it again from ' downloads '.....
    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-08-2014
    Ran by Tony (administrator) on TONY-HP on 29-08-2014 15:54:43
    Running from C:\Users\Tony\Downloads
    Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
    Internet Explorer Version 11
    Boot Mode: Normal
    The only official download link for FRST:
    Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
    Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
    Download link from any site other than Bleeping Computer is unpermitted or outdated.
    See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
    ==================== Processes (Whitelisted) =================
    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
    (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Alcatel-Lucent) C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\MAHostService.exe
    (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    (Joyent, Inc) C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\node.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
    (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
    (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
    (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
    (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
    (Mirics Semiconductor) C:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe
    (Mirics Ltd.) C:\Program Files\MiricsFlexiTV\DVBT\DVBservice.exe
    (Mirics Semiconductor) C:\Program Files\MiricsFlexiTV\Driver\MSiBdaDemodWrapper.exe
    (Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\pcCMService.exe
    (Alcatel-Lucent) C:\Program Files\Common Files\Motive\pcCMService.exe
    (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
    (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
    (Intel Corporation) C:\Windows\System32\igfxtray.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
    (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
    (Alcatel-Lucent) C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
    (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
    (Hobbyist Software) C:\Program Files (x86)\Hobbyist Software\VLC Streamer\VLC Streamer Configuration.exe
    (Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\pcContextHookShim.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
    (Portrait Displays, Inc) C:\Program Files (x86)\Hewlett-Packard\HP My Display\OSDManager.exe
    (Sony Corporation) C:\Program Files (x86)\Sony\Bloggie Software\BGVolumeWatcher.exe
    (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
    () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    (CyberLink) C:\Program Files (x86)\Cyberlink\YouCam\YCMMirage.exe
    (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
    () C:\Program Files (x86)\Portrait Displays\Pivot Pro Plugin\wpCtrl.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Portrait Displays, Inc) C:\Program Files (x86)\Hewlett-Packard\HP My Display\dthtml.exe
    (Portrait Displays Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Shared\HookManager.exe
    (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSDKHelperx64.exe
    (Intel Corporation) C:\Windows\System32\igfxext.exe
    (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
    () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper.exe
    () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper64.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
    (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
    (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_14_0_0_176_ActiveX.exe
    (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
    (McAfee, Inc.) C:\Program Files\McAfee\MSM\McSmtFwk.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe
    (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe
    (Opera Software) C:\Program Files (x86)\Opera Next\23.0.1522.43\opera.exe
    () C:\Program Files (x86)\Opera Next\23.0.1522.43\opera_crashreporter.exe
    (Opera Software) C:\Program Files (x86)\Opera Next\23.0.1522.43\opera.exe
    (Opera Software) C:\Program Files (x86)\Opera Next\23.0.1522.43\opera.exe
    (Opera Software) C:\Program Files (x86)\Opera Next\23.0.1522.43\opera.exe
    (Opera Software) C:\Program Files (x86)\Opera Next\23.0.1522.43\opera.exe
    (Opera Software) C:\Program Files (x86)\Opera Next\23.0.1522.43\opera.exe

    ==================== Registry (Whitelisted) ==================
    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
    HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
    HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1424896 2012-10-22] (IDT, Inc.)
    HKLM\...\Run: [btbb_McciTrayApp] => C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe [2860856 2013-11-11] (Alcatel-Lucent)
    HKLM-x32\...\Run: [HP Software Update] => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [HP Remote Solution] => C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe [656896 2009-08-25] (Hewlett-Packard)
    HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-09-27] (EasyBits Software AS)
    HKLM-x32\...\Run: [DT HPO] => C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe [120400 2012-08-16] (Portrait Displays, Inc.)
    HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-08-12] (PDF Complete Inc)
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
    HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
    HKLM-x32\...\Run: [PivotSoftware] => C:\Program Files (x86)\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe [110192 2010-05-13] ()
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-04-03] (DivX, LLC)
    HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1232896 2013-10-24] (Easybits)
    HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
    HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
    HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
    HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-07-08] (Hewlett-Packard)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
    HKLM\...\Policies\Explorer: [NoControlPanel] 0
    HKLM\...\Policies\Explorer: [NoFolderOptions] 0
    HKU\S-1-5-21-131991233-2839458126-3920297457-1001\...\Run: [MobileDocuments] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
    HKU\S-1-5-21-131991233-2839458126-3920297457-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7762712 2014-08-13] (SUPERAntiSpyware)
    HKU\S-1-5-21-131991233-2839458126-3920297457-1001\...\Run: [Hobbyist Software VLC Streamer] => C:\Program Files (x86)\Hobbyist Software\VLC Streamer\VLC Streamer Configuration.exe [1193288 2014-08-18] (Hobbyist Software)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bloggie Watcher Utility.lnk
    ShortcutTarget: Bloggie Watcher Utility.lnk -> C:\Program Files (x86)\Sony\Bloggie Software\BGVolumeWatcher.exe (Sony Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
    ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
    ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
    ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
    ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
    ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
    ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
    ==================== Internet (Whitelisted) ====================
    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.co.uk/
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchScopes: HKLM - {251B63F3-36E5-4F04-93D6-F4E9D2977C49} URL = http://www.amazon.co.uk/s/ref=azs_o...code=qs&index=aps&field-keywords={searchTerms}
    SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/710-1...//www.ebay.co.uk/sch/i.html?_nkw={searchTerms}
    SearchScopes: HKLM-x32 - Backup.Old.DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    SearchScopes: HKCU - {251B63F3-36E5-4F04-93D6-F4E9D2977C49} URL =
    SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
    BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
    BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
    BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
    BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
    BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
    Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
    Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
    Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
    Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
    Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
    Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
    ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2012-04-11] (EasyBits Software Corp.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254
    FireFox:
    ========
    FF ProfilePath: C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668
    FF NewTab: about:home
    FF DefaultSearchEngine: Bing
    FF SelectedSearchEngine: Bing
    FF Homepage: hxxp://uk.msn.com/
    FF Keyword.URL: user_pref("keyword.URL", "");
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
    FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
    FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF Plugin-x32: @ASC/FileLabPlugin;version=1.1.33 -> C:\ProgramData\FileLab\Plugin\Framework\npFlPluginS.dll (FileLab)
    FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
    FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @Motive.com/NpMotive,version=1.0 -> C:\Program Files (x86)\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
    FF Plugin-x32: @Motive.com/npMotiveRequest,version=1.0 -> C:\Program Files (x86)\Common Files\Motive\npMotiveRequest.dll (Alcatel-Lucent)
    FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin HKCU: @sony.com/Some -> C:\Program Files (x86)\Sony\Bloggie Software\npsome.dll (Sony)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
    FF Extension: Flash Video Downloader - YouTube Full HD Download - C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\Extensions\artur.dubovoy@gmail.com [2014-08-01]
    FF Extension: HomeTab - C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\Extensions\{4ca8c1be-c30f-49bf-9ac8-f3e63f49665d} [2013-11-02]
    FF Extension: DownloadHelper - C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-08-09]
    FF Extension: MEGA - C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\Extensions\firefox@mega.co.nz.xpi [2013-03-14]
    FF Extension: ImageGrabber - C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\9u8txpth.default-1358439559668\Extensions\{546d2a00-2bbf-11dc-8314-0800200c9a66}.xpi [2013-03-20]
    FF Extension: BT DesktopHelp extension - C:\Program Files (x86)\Mozilla Firefox\extensions\mcciwbch@motive.com.xpi [2014-07-30]
    FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\mcciwbch@motive.com.xpi [2014-07-30]
    FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]
    FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
    FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2012-09-07]
    FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
    FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
    Chrome:
    =======
    CHR HomePage: Default ->
    CHR StartupUrls: Default -> "hxxp://mysearch.avg.com?cid={E7AE3A81-3542-4C93-A479-C892EF86BF35}&mid=3d758e6b1cc64be1a414b11ccceea2c4-13f7a46765dbab8bfdb2aa13e197f078ae1db1dc&lang=en&ds=gm011&coid=avgtbdisgm&cmpid=&pr=sa&d=2013-12-21 11:14:34&v=17.2.0.38&pid=safeguard&sg=&sap=hp"
    CHR DefaultSearchKeyword: Default -> mcafee
    CHR DefaultSearchProvider: Default -> McAfee
    CHR DefaultSearchURL: Default -> https://uk.search.yahoo.com/search?fr=mcafee&type=A211GB691&p={searchTerms}
    CHR Profile: C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-05]
    CHR Extension: (Google Wallet) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-03]
    CHR HKLM-x32\...\Chrome\Extension: [edmgmpmklgfbohogafcfobonnkogchec] - C:\Program Files (x86)\Common Files\Motive\extensions\MotiveRequest.crx []
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
    CHR HKLM-x32\...\Chrome\Extension: [oihiaojfckjaconbjjpanjechlighodn] - C:\Program Files (x86)\HomeTab\chrome\HomeTab.crx [2014-07-14]
    ==================== Services (Whitelisted) =================
    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-08-13] (SUPERAntiSpyware.com)
    R2 BT Help Wizard; C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\MAHostService.exe [321024 2014-04-09] (Alcatel-Lucent) [File not signed]
    R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
    R2 CalendarSynchService; C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [16384 2011-08-16] (Hewlett-Packard) [File not signed]
    R2 DTSRVC; C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe [136784 2012-08-16] (Portrait Displays, Inc.)
    R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
    R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
    R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2375168 2011-03-08] (Realsil Microelectronics Inc.) [File not signed]
    R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
    R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
    R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [603424 2014-06-12] (McAfee, Inc.)
    R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-06-18] (McAfee, Inc.)
    R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
    R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
    R2 msi2500scan; c:\Program Files\MiricsFlexiTV\Driver\msi2500scan.exe [229376 2011-12-16] (Mirics Semiconductor)
    R2 MSiDVBT; c:\Program Files\MiricsFlexiTV\DVBT\DVBService.exe [2715648 2011-12-16] (Mirics Ltd.)
    R2 pcCMService64; C:\Program Files\Common Files\Motive\pcCMService.exe [467256 2013-11-11] (Alcatel-Lucent)
    R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-08-12] (PDF Complete Inc)
    ==================== Drivers (Whitelisted) ====================
    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
    R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
    S3 CpqDfw; C:\Windows\System32\drivers\CpqDfw.sys [27456 2012-05-29] (Windows (R) Codename Longhorn DDK provider)
    S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
    R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
    R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
    R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
    R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
    R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [444720 2014-06-18] (McAfee, Inc.)
    S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96592 2014-06-18] (McAfee, Inc.)
    R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
    S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
    S3 MREMP50a64; C:\Program Files\Common Files\Motive\MREMP50a64.SYS [43008 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
    S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
    R3 MRESP50a64; C:\Program Files\Common Files\Motive\MRESP50a64.SYS [40960 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
    R3 MSi2500BDA; C:\Windows\System32\DRIVERS\AVerMsiBDA.sys [228352 2011-12-16] (AVerMedia TECHNOLOGIES, Inc.)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S3 MREMPR5; \??\C:\PROGRA~2\COMMON~1\Motive\MREMPR5.SYS [X]
    S3 MRENDIS5; \??\C:\PROGRA~2\COMMON~1\Motive\MRENDIS5.SYS [X]
    S2 NEWDRIVER; \??\C:\Windows\SysWow64\WinVDEdrv6.sys [X]
    S2 RHDISK_AMD64; \??\C:\Program Files (x86)\Rohos\RHDISK_AMD64.SYS [X]
    ==================== NetSvcs (Whitelisted) ===================
    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

    ==================== One Month Created Files and Folders ========
    (If an entry is included in the fixlist, the file\folder will be moved.)
    2014-08-29 15:52 - 2014-08-29 15:54 - 02103296 _____ (Farbar) C:\Users\Tony\Downloads\FRST64.exe
    2014-08-29 15:52 - 2014-08-29 15:54 - 00030801 _____ () C:\Users\Tony\Downloads\FRST.txt
    2014-08-29 15:48 - 2014-08-29 15:48 - 01016261 _____ (Thisisu) C:\Users\Tony\Downloads\JRT.exe
    2014-08-29 13:34 - 2014-08-29 13:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
    2014-08-29 09:14 - 2014-08-29 15:54 - 00000000 ____D () C:\FRST
    2014-08-29 08:58 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
    2014-08-29 08:51 - 2014-08-29 08:51 - 00004952 _____ () C:\Users\Tony\Desktop\JRT.txt
    2014-08-29 08:44 - 2014-08-29 08:44 - 00000000 ____D () C:\Windows\ERUNT
    2014-08-28 09:02 - 2014-08-23 03:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
    2014-08-28 09:02 - 2014-08-23 02:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
    2014-08-28 09:02 - 2014-08-23 01:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2014-08-27 11:16 - 2014-08-27 11:48 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-08-27 11:16 - 2014-08-27 11:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2014-08-27 11:15 - 2014-08-27 11:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-08-27 11:15 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-08-27 11:15 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2014-08-24 14:27 - 2014-08-24 14:27 - 00000000 ____D () C:\Users\Tony\AppData\Local\Adobe
    2014-08-19 09:52 - 2014-08-19 09:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VLC Streamer
    2014-08-16 01:59 - 2014-08-29 08:41 - 00003180 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForTony
    2014-08-14 10:27 - 2014-08-14 10:27 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
    2014-08-14 10:27 - 2014-08-14 10:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files\iTunes
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files\iPod
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files (x86)\iTunes
    2014-08-13 22:36 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
    2014-08-13 22:36 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
    2014-08-13 22:36 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
    2014-08-13 22:36 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
    2014-08-13 22:36 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
    2014-08-13 22:36 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
    2014-08-13 22:36 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
    2014-08-13 22:36 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
    2014-08-13 08:28 - 2014-08-01 00:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2014-08-13 08:28 - 2014-07-25 15:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2014-08-13 08:28 - 2014-07-25 15:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2014-08-13 08:28 - 2014-07-25 14:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2014-08-13 08:28 - 2014-07-25 14:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2014-08-13 08:28 - 2014-07-25 14:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2014-08-13 08:28 - 2014-07-25 14:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2014-08-13 08:28 - 2014-07-25 13:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2014-08-13 08:28 - 2014-07-25 13:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2014-08-13 08:28 - 2014-07-25 13:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2014-08-13 08:28 - 2014-07-25 13:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2014-08-13 08:28 - 2014-07-25 13:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2014-08-13 08:28 - 2014-07-25 13:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2014-08-13 08:28 - 2014-07-25 13:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2014-08-13 08:28 - 2014-07-25 13:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2014-08-13 08:28 - 2014-07-25 13:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2014-08-13 08:28 - 2014-07-25 12:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2014-08-13 08:28 - 2014-07-25 12:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2014-08-13 08:28 - 2014-07-25 12:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2014-08-13 08:28 - 2014-07-25 12:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2014-08-13 08:28 - 2014-07-25 12:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2014-08-13 08:28 - 2014-07-25 12:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2014-08-13 08:28 - 2014-07-25 12:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2014-08-13 08:28 - 2014-07-25 12:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2014-08-13 08:28 - 2014-07-25 11:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2014-08-13 08:28 - 2014-07-25 11:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2014-08-13 08:28 - 2014-07-16 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
    2014-08-13 08:28 - 2014-07-16 03:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2014-08-13 08:28 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
    2014-08-13 08:28 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
    2014-08-13 08:28 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
    2014-08-13 08:28 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
    2014-08-13 08:28 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
    2014-08-13 08:28 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
    2014-08-13 08:28 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
    2014-08-13 08:28 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
    2014-08-13 08:28 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
    2014-08-13 08:28 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
    2014-08-13 08:28 - 2014-07-08 23:38 - 00419992 _____ () C:\Windows\system32\locale.nls
    2014-08-13 08:28 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
    2014-08-13 08:28 - 2014-06-25 03:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
    2014-08-13 08:28 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2014-08-13 08:28 - 2014-06-16 03:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
    2014-08-13 08:28 - 2014-06-03 11:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
    2014-08-13 08:28 - 2014-06-03 11:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
    2014-08-13 08:28 - 2014-06-03 11:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
    2014-08-13 08:28 - 2014-06-03 11:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
    2014-08-13 08:28 - 2014-06-03 10:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2014-08-13 08:28 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2014-08-13 08:28 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
    2014-08-13 08:27 - 2014-08-01 00:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2014-08-13 08:27 - 2014-07-25 15:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2014-08-13 08:27 - 2014-07-25 14:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2014-08-13 08:27 - 2014-07-25 14:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2014-08-13 08:27 - 2014-07-25 14:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2014-08-13 08:27 - 2014-07-25 14:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2014-08-13 08:27 - 2014-07-25 14:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2014-08-13 08:27 - 2014-07-25 14:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2014-08-13 08:27 - 2014-07-25 14:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2014-08-13 08:27 - 2014-07-25 14:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2014-08-13 08:27 - 2014-07-25 13:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2014-08-13 08:27 - 2014-07-25 13:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2014-08-13 08:27 - 2014-07-25 13:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2014-08-13 08:27 - 2014-07-25 13:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2014-08-13 08:27 - 2014-07-25 13:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2014-08-13 08:27 - 2014-07-25 13:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2014-08-13 08:27 - 2014-07-25 13:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2014-08-13 08:27 - 2014-07-25 13:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2014-08-13 08:27 - 2014-07-25 13:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2014-08-13 08:27 - 2014-07-25 13:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2014-08-13 08:27 - 2014-07-25 12:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2014-08-13 08:27 - 2014-07-25 12:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2014-08-13 08:27 - 2014-07-25 12:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2014-08-13 08:27 - 2014-07-25 12:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2014-08-13 08:27 - 2014-07-25 12:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2014-08-13 08:27 - 2014-07-25 12:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2014-08-13 08:27 - 2014-07-25 11:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2014-08-13 08:27 - 2014-07-25 11:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2014-08-13 08:27 - 2014-07-25 11:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2014-08-13 08:27 - 2014-07-25 11:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2014-08-13 08:25 - 2014-08-07 03:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2014-08-13 08:25 - 2014-08-07 03:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2014-08-13 08:25 - 2014-07-14 03:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2014-08-13 08:25 - 2014-07-14 02:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2014-08-02 15:49 - 2014-08-02 15:49 - 00000124 _____ () C:\Windows\wininit.ini
    2014-08-02 15:49 - 2014-08-02 15:49 - 00000000 ____D () C:\ProgramData\GRETECH
    2014-08-01 08:56 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2014-08-01 08:56 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2014-08-01 08:56 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2014-08-01 08:56 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2014-08-01 08:55 - 2014-05-14 17:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2014-08-01 08:55 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2014-08-01 08:55 - 2014-05-14 17:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2014-08-01 08:55 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2014-08-01 08:55 - 2014-05-14 17:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2014-08-01 08:55 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2014-08-01 08:55 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2014-08-01 08:55 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2014-08-01 08:55 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2014-08-01 08:55 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2014-07-30 10:54 - 2014-07-30 10:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    ==================== One Month Modified Files and Folders =======
    (If an entry is included in the fixlist, the file\folder will be moved.)
    2014-08-29 15:54 - 2014-08-29 15:52 - 02103296 _____ (Farbar) C:\Users\Tony\Downloads\FRST64.exe
    2014-08-29 15:54 - 2014-08-29 15:52 - 00030801 _____ () C:\Users\Tony\Downloads\FRST.txt
    2014-08-29 15:54 - 2014-08-29 09:14 - 00000000 ____D () C:\FRST
    2014-08-29 15:48 - 2014-08-29 15:48 - 01016261 _____ (Thisisu) C:\Users\Tony\Downloads\JRT.exe
    2014-08-29 15:43 - 2012-07-18 16:26 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-08-29 15:41 - 2012-07-18 10:06 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2014-08-29 15:39 - 2012-07-17 23:45 - 00000000 ____D () C:\ProgramData\Zoom Player
    2014-08-29 14:38 - 2012-07-17 15:43 - 02025976 _____ () C:\Windows\WindowsUpdate.log
    2014-08-29 13:34 - 2014-08-29 13:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
    2014-08-29 13:34 - 2012-09-07 11:31 - 00001846 _____ () C:\Users\Public\Desktop\BT NetProtect Plus.lnk
    2014-08-29 09:43 - 2012-07-18 16:26 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-08-29 09:08 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2014-08-29 09:08 - 2009-07-14 05:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2014-08-29 09:05 - 2009-07-14 06:13 - 00783360 _____ () C:\Windows\system32\PerfStringBackup.INI
    2014-08-29 09:01 - 2012-10-03 15:54 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
    2014-08-29 09:01 - 2012-04-11 15:56 - 00000000 ____D () C:\ProgramData\PDFC
    2014-08-29 09:00 - 2014-07-01 09:52 - 00000328 _____ () C:\Windows\Tasks\HPCeeScheduleForTony.job
    2014-08-29 09:00 - 2010-11-21 04:47 - 01131722 _____ () C:\Windows\PFRO.log
    2014-08-29 09:00 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2014-08-29 09:00 - 2009-07-14 05:51 - 00080337 _____ () C:\Windows\setupact.log
    2014-08-29 08:59 - 2013-11-06 18:45 - 00000000 ____D () C:\AdwCleaner
    2014-08-29 08:51 - 2014-08-29 08:51 - 00004952 _____ () C:\Users\Tony\Desktop\JRT.txt
    2014-08-29 08:44 - 2014-08-29 08:44 - 00000000 ____D () C:\Windows\ERUNT
    2014-08-29 08:41 - 2014-08-16 01:59 - 00003180 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForTony
    2014-08-29 08:35 - 2009-07-14 05:45 - 00280872 _____ () C:\Windows\system32\FNTCACHE.DAT
    2014-08-28 20:27 - 2012-07-17 15:51 - 00003918 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{654B34D5-AE44-4A92-AD8E-01A23DF2D396}
    2014-08-28 16:28 - 2012-07-21 13:38 - 00000000 ____D () C:\Users\Tony\AppData\Local\CrashDumps
    2014-08-28 11:02 - 2012-07-18 17:43 - 00000000 ____D () C:\ProgramData\ACD Systems
    2014-08-27 18:57 - 2012-07-26 01:10 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
    2014-08-27 18:57 - 2012-07-18 18:12 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
    2014-08-27 11:48 - 2014-08-27 11:16 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-08-27 11:39 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Speech
    2014-08-27 11:16 - 2014-08-27 11:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2014-08-27 11:16 - 2013-07-02 16:53 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2014-08-27 11:16 - 2013-03-04 11:38 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Malwarebytes
    2014-08-27 11:15 - 2014-08-27 11:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-08-27 11:15 - 2013-07-02 16:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2014-08-27 11:15 - 2013-03-04 11:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2014-08-24 15:44 - 2013-05-03 14:01 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Skype
    2014-08-24 14:27 - 2014-08-24 14:27 - 00000000 ____D () C:\Users\Tony\AppData\Local\Adobe
    2014-08-23 03:07 - 2014-08-28 09:02 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
    2014-08-23 02:45 - 2014-08-28 09:02 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
    2014-08-23 01:59 - 2014-08-28 09:02 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2014-08-22 17:16 - 2013-12-20 12:14 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\avidemux
    2014-08-21 11:41 - 2012-07-18 10:06 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2014-08-21 11:30 - 2012-07-18 10:06 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2014-08-21 11:30 - 2012-04-11 15:46 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2014-08-19 09:52 - 2014-08-19 09:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VLC Streamer
    2014-08-19 09:52 - 2013-03-21 12:03 - 00000000 ____D () C:\Program Files (x86)\Hobbyist Software
    2014-08-14 13:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
    2014-08-14 10:27 - 2014-08-14 10:27 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
    2014-08-14 10:27 - 2014-08-14 10:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files\iTunes
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files\iPod
    2014-08-14 10:26 - 2014-08-14 10:26 - 00000000 ____D () C:\Program Files (x86)\iTunes
    2014-08-14 09:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
    2014-08-13 22:44 - 2013-08-14 22:48 - 00000000 ____D () C:\Windows\system32\MRT
    2014-08-13 22:40 - 2012-07-23 09:28 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2014-08-13 22:35 - 2014-05-06 22:07 - 00000000 ___SD () C:\Windows\system32\CompatTel
    2014-08-13 12:09 - 2013-06-15 12:26 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\vlc
    2014-08-12 20:52 - 2012-08-28 08:54 - 00002185 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2014-08-08 10:06 - 2013-06-27 14:48 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\uTorrent
    2014-08-07 03:06 - 2014-08-13 08:25 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2014-08-07 03:01 - 2014-08-13 08:25 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2014-08-05 09:20 - 2010-11-21 04:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
    2014-08-05 08:57 - 2014-03-13 14:53 - 00000000 ___RD () C:\Program Files (x86)\Skype
    2014-08-05 08:57 - 2012-04-11 15:45 - 00000000 ____D () C:\ProgramData\Skype
    2014-08-03 11:03 - 2012-09-07 11:30 - 00000000 ____D () C:\Program Files (x86)\McAfee
    2014-08-02 15:49 - 2014-08-02 15:49 - 00000124 _____ () C:\Windows\wininit.ini
    2014-08-02 15:49 - 2014-08-02 15:49 - 00000000 ____D () C:\ProgramData\GRETECH
    2014-08-02 15:49 - 2013-02-11 23:12 - 00001211 _____ () C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
    2014-08-02 15:49 - 2012-08-23 18:43 - 00001187 _____ () C:\Users\Public\Desktop\GOM Player.lnk
    2014-08-01 00:41 - 2014-08-13 08:27 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2014-08-01 00:16 - 2014-08-13 08:28 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2014-07-31 14:37 - 2012-07-19 22:00 - 00009216 _____ () C:\Users\Tony\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2014-07-31 09:55 - 2012-07-17 16:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
    2014-07-30 10:55 - 2014-07-30 10:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    Some content of TEMP:
    ====================
    C:\Users\Tony\AppData\Local\Temp\airD8B3.exe
    C:\Users\Tony\AppData\Local\Temp\apptorun.exe
    C:\Users\Tony\AppData\Local\Temp\avguidx.dll
    C:\Users\Tony\AppData\Local\Temp\BackupSetup.exe
    C:\Users\Tony\AppData\Local\Temp\cg_qcnqv.dll
    C:\Users\Tony\AppData\Local\Temp\CommonInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\eSafeSvc.exe
    C:\Users\Tony\AppData\Local\Temp\ExPromo.exe
    C:\Users\Tony\AppData\Local\Temp\Extract.exe
    C:\Users\Tony\AppData\Local\Temp\free-hide-folder.exe
    C:\Users\Tony\AppData\Local\Temp\GomAudDnInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\GomEncDnInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\HPHelpUpdater.exe
    C:\Users\Tony\AppData\Local\Temp\HPPSdr.exe
    C:\Users\Tony\AppData\Local\Temp\instruct.exe
    C:\Users\Tony\AppData\Local\Temp\launcher.exe
    C:\Users\Tony\AppData\Local\Temp\MachineIdCreator.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{0B3A180C-0270-4BAD-BE2D-51C23267FA5C}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{376AD83B-18D4-4178-B382-BA08C08C4B44}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{6C4DC06A-72B3-4FB2-87D5-34DA62BE4F18}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{EAA3C375-2E1F-4A76-B2C8-4050037AA001}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{EAACB772-C4BF-4AB1-B433-2F2E92C1D030}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{F2D8CEDF-EF03-4769-95E6-64C765645308}.exe
    C:\Users\Tony\AppData\Local\Temp\pcDesktopAlertNotifierX.dll
    C:\Users\Tony\AppData\Local\Temp\pmllflwn.dll
    C:\Users\Tony\AppData\Local\Temp\Quarantine.exe
    C:\Users\Tony\AppData\Local\Temp\Resource.exe
    C:\Users\Tony\AppData\Local\Temp\RSPUpgradeInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\Runner.exe
    C:\Users\Tony\AppData\Local\Temp\safeguard.exe
    C:\Users\Tony\AppData\Local\Temp\SAS6_Update.exe
    C:\Users\Tony\AppData\Local\Temp\SendMsg.dll
    C:\Users\Tony\AppData\Local\Temp\SIMEEIInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\SkypeSetup.exe
    C:\Users\Tony\AppData\Local\Temp\SP57550.exe
    C:\Users\Tony\AppData\Local\Temp\sp58915.exe
    C:\Users\Tony\AppData\Local\Temp\SP59509.exe
    C:\Users\Tony\AppData\Local\Temp\sp64126.exe
    C:\Users\Tony\AppData\Local\Temp\SP65786.exe
    C:\Users\Tony\AppData\Local\Temp\SSUPDATE64.EXE
    C:\Users\Tony\AppData\Local\Temp\ToolbarInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\uninst1.exe
    C:\Users\Tony\AppData\Local\Temp\UninstallHPSA.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.0.2-win32.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.0.4-win32.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.0.5-win32.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.1.4-win64.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.1.5-win64.exe
    C:\Users\Tony\AppData\Local\Temp\VLCStreamerSetup.exe

    ==================== Bamital & volsnap Check =================
    (There is no automatic fix for files that do not pass verification.)
    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2014-08-27 10:12
    ==================== End Of Log ============================

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-08-2014
    Ran by Tony at 2014-08-29 15:55:12
    Running from C:\Users\Tony\Downloads
    Boot Mode: Normal
    ==========================================================

    ==================== Security Center ========================
    (If an entry is included in the fixlist, it will be removed.)
    AV: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
    AS: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: McAfee Firewall (Disabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}
    ==================== Installed Programs ======================
    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
    7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
    AC3Filter 2.6.0b (HKLM-x32\...\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
    Adobe AIR (x32 Version: 4.0.0.1390 - Adobe Systems Incorporated) Hidden
    Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.176 - Adobe Systems Incorporated)
    Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.179 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.08) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
    Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Avidemux 2.6 (32-bit) (HKLM-x32\...\Avidemux 2.6) (Version: 2.6.7.8981 - )
    AVS Screen Capture version 2.0.1 (HKLM-x32\...\AVS Screen Capture_is1) (Version: - Online Media Technologies Ltd.)
    AVS Update Manager 1.0 (HKLM-x32\...\AVS Update Manager_is1) (Version: - Online Media Technologies Ltd.)
    AVS Video Editor 6 (HKLM-x32\...\AVS Video Editor_is1) (Version: - Online Media Technologies Ltd.)
    AVS Video Recorder 2.5 (HKLM-x32\...\AVS Video Recorder_is1) (Version: - Online Media Technologies Ltd.)
    AVS4YOU Software Navigator 1.4 (HKLM-x32\...\AVS4YOU Software Navigator_is1) (Version: - Online Media Technologies Ltd.)
    Bass Audio Decoder (remove only) (HKLM-x32\...\Bass Audio Decoder) (Version: - )
    BBC iPlayer Desktop (HKLM-x32\...\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1) (Version: 3.2.15 - British Broadcasting Corp.)
    BBC iPlayer Desktop (x32 Version: 3.2.15 - British Broadcasting Corp.) Hidden
    Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Bing Bar (HKLM-x32\...\{9FA13759-5C2B-4177-9DDC-0038F8B5BEFD}) (Version: 7.0.826.0 - Microsoft Corporation)
    Blio (HKLM-x32\...\{741006D1-7B2B-4E33-B2B0-831F282EEF64}) (Version: 2.2.8188 - K-NFB Reading Technology, Inc.)
    Bloggie Software (HKLM-x32\...\BloggieSoftware) (Version: 3.3.1.73 - Sony)
    Bloggie Software (x32 Version: 3.3.1.73 - Sony Corporation) Hidden
    Bluetooth by hp (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.8200 - Broadcom Corporation)
    Boilsoft Video Joiner 6.57 (HKLM-x32\...\{FD39EF4B-0B5C-4B33-8D57-2EE865A80EB1}_is1) (Version: - Boilsoft, Inc.)
    Boilsoft Video Splitter 6.34 (HKLM-x32\...\{24549038-9956-4EE5-976D-4419AAEA7DD5}_is1) (Version: - Boilsoft, Inc.)
    Boilsoft WMV Converter 1.51 (HKLM-x32\...\{4F556FDB-C47D-4897-A2F2-EC53AC7F8DA6}_is1) (Version: - Boilsoft.Inc.)
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    BT Desktop Help (HKLM-x32\...\BT Desktop Help) (Version: - )
    BT NetProtect Plus (HKLM-x32\...\MSC) (Version: 12.8.958 - McAfee, Inc.)
    Cake Mania (x32 Version: 2.2.0.98 - WildTangent) Hidden
    CD Audio Reader Filter (remove only) (HKLM-x32\...\CD Audio Reader Filter) (Version: - )
    Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
    ConvertHelper 2.2 (HKLM-x32\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1) (Version: - DownloadHelper)
    Cradle of Rome 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
    CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.0.4417 - CyberLink Corp.)
    CyberLink YouCam (x32 Version: 3.5.0.4417 - CyberLink Corp.) Hidden
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    DC-Bass Source 1.3.0 (HKLM-x32\...\DC-Bass Source) (Version: - )
    DCoder Image Source (remove only) (HKLM-x32\...\DCoder Image Source) (Version: - )
    DirectVobSub (remove only) (HKLM-x32\...\DirectVobSub) (Version: - )
    DirectVobSub 2.40.4209 (HKLM-x32\...\vsfilter_is1) (Version: 2.40.4209 - MPC-HC Team)
    DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
    DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.3.22 - DivX, LLC)
    DScaler 5 Mpeg Decoders (HKLM-x32\...\DScaler 5 Mpeg Decoders_is1) (Version: - )
    Facebook (HKLM-x32\...\{8AE50893-3A87-4439-9A57-942ED43F7189}) (Version: 1.1.0004 - Hewlett-Packard)
    Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Farmscapes (x32 Version: 2.2.0.98 - WildTangent) Hidden
    FastStone Image Viewer 4.6 (HKLM-x32\...\FastStone Image Viewer) (Version: 4.6 - FastStone Soft)
    FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
    ffdshow v1.2.4453 [2012-05-21] (HKLM-x32\...\ffdshow_is1) (Version: 1.2.4453.0 - )
    FFMPEG Core Files (remove only) (HKLM-x32\...\FFMPEG Core Files) (Version: - )
    FileLab Plugin 1.1.33 (HKLM-x32\...\{6AC5F630-9453-433D-90FF-BB3A8E4F8960}) (Version: 1.1.33 - FileLab)
    Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Fishdom (TM) 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Freemake Video Converter version 4.1.2 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.2 - Ellora Assets Corporation)
    Gabest MPEG Splitter (remove only) (HKLM-x32\...\Gabest MPEG Splitter) (Version: - )
    GOM Player (HKLM-x32\...\GOM Player) (Version: 2.2.62.5207 - Gretech Corporation)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.143 - Google Inc.)
    Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
    Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
    Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version: - )
    Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
    HP Auto (Version: 1.0.12935.3667 - Hewlett-Packard Company) Hidden
    HP Calendar (HKLM-x32\...\{2B38E0FA-D8A5-4EBF-A018-E3C1C8E7A2E2}) (Version: 5.1.4245.23508 - Hewlett-Packard)
    HP Client Services (Version: 1.1.12938.3539 - Hewlett-Packard) Hidden
    HP Clock (HKLM-x32\...\{0EEC4E49-D4C2-4E23-87F2-B5641F1A09E4}) (Version: 5.1.4244.16367 - Hewlett-Packard)
    HP Customer Experience Enhancements (x32 Version: 6.0.1.8 - Hewlett-Packard) Hidden
    HP Deskjet 3050 J610 series Basic Device Software (HKLM\...\{650AF771-456D-418F-BFC7-F6FFC9D0235C}) (Version: 22.0.334.0 - Hewlett-Packard Co.)
    HP Deskjet 3050 J610 series Help (HKLM-x32\...\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}) (Version: 140.0.63.63 - Hewlett Packard)
    HP Deskjet 3050 J610 series Product Improvement Study (HKLM\...\{FEB2C4AA-661E-483F-9626-21A8ACFD10F2}) (Version: 22.0.334.0 - Hewlett-Packard Co.)
    HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent)
    HP LinkUp (HKLM-x32\...\{7E750542-55BC-4300-8B7B-AC2A762FB435}) (Version: 2.01.029 - Hewlett-Packard)
    HP Magic Canvas (HKLM-x32\...\{DDFDC9D6-4220-41F8-BF9A-8E7512C4EF52}) (Version: 5.1.15.0 - Hewlett-Packard)
    HP Magic Canvas Tutorials (HKLM-x32\...\{858FCB65-7C6D-4BA4-AD80-A3CB3744CE09}_is1) (Version: 5.0.0.3 - Hewlett-Packard)
    HP My Display (HKLM-x32\...\{1F4DDC90-5923-4E49-A4C7-F3CCC954DCA0}) (Version: 1.12.004 - Portrait Displays, Inc.)
    HP Notes (HKLM-x32\...\{86BAB08A-5E66-4C53-82E3-C1E91673C7CA}) (Version: 5.1.4274.30382 - Hewlett-Packard)
    HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
    HP Remote Solution (HKLM-x32\...\HP Remote Solution) (Version: 1.1.14.0 - Hewlett-Packard)
    HP Remote Solution (x32 Version: 1.1.14.0 - Hewlett-Packard) Hidden
    HP RSS (HKLM-x32\...\{A35E58D6-2A0F-4051-983B-79342081338E}) (Version: 5.1.4301.21494 - Hewlett-Packard)
    HP Setup (HKLM-x32\...\{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}) (Version: 9.0.15130.3904 - Hewlett-Packard Company)
    HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.2.15145.3905 - Hewlett-Packard Company)
    HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
    HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 11.00.0001 - Hewlett-Packard)
    HP TouchSmart Background - Beats (HKLM-x32\...\{6A6F8D36-04BA-41E9-9004-1789BD545874}) (Version: 1.0.1.0 - Hewlett-Packard)
    HP TouchSmart RecipeBox (HKLM-x32\...\{20714B53-FC73-4F9C-9687-49EB237D6FD7}) (Version: 3.0.3830.27730 - Hewlett-Packard)
    HP Update (HKLM-x32\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
    HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.12.1.0 - Hewlett-Packard)
    iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
    IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6370.0 - IDT)
    Insaniquarium Deluxe (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2462 - Intel Corporation)
    iTunes (HKLM\...\{77DE5105-D05E-448C-96CB-7FA381903753}) (Version: 11.3.1.2 - Apple Inc.)
    Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Jewel Quest II (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Jewel Quest Solitaire 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Kobo (HKLM-x32\...\Kobo) (Version: 2.0.3 - Kobo Inc.)
    L&H TTS3000 British English (HKLM-x32\...\LHTTSENG) (Version: - )
    LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4507 - CyberLink Corp.)
    LabelPrint (x32 Version: 2.5.4507 - CyberLink Corp.) Hidden
    Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - )
    LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
    LAV Filters 0.61.1 (HKLM-x32\...\lavfilters_is1) (Version: 0.61.1 - Hendrik Leppkes)
    MadVR (remove only) (HKLM-x32\...\MadVR) (Version: - )
    Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: 3.0 - EasyBits Software AS)
    Mahjongg Artifacts (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
    McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
    Media Preview (HKLM\...\{9EE88DE0-9E1C-43E5-9827-4C3EEB0DDE5E}) (Version: 1.3.1.343 - BabelSoft)
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Metric Converter (HKLM-x32\...\{D0661463-50F7-4A1E-83CB-37CC590589AE}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
    Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
    Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
    Microsoft Mathematics (HKLM-x32\...\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Microsoft Corporation)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Click-to-Run 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
    Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5139.5005 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
    Mozilla Firefox 31.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
    MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
    MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
    Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
    opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
    OpenSource AVI Splitter (remove only) (HKLM-x32\...\OpenSource AVI Splitter) (Version: - )
    OpenSource DTS/AC3/DD+ Source Filter (remove only) (HKLM-x32\...\OpenSource DTS/AC3/DD+ Source Filter) (Version: - )
    OpenSource Flash Video Splitter 1.0.0.5 (HKLM-x32\...\OpenSource Flash Video Splitter) (Version: 1.0.0.5 - )
    Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA)
    Opera Next 19.0.1326.9 (HKLM-x32\...\Opera 19.0.1326.9) (Version: 19.0.1326.9 - Opera Software ASA)
    Opera Next 23.0.1522.43 (HKLM-x32\...\Opera 23.0.1522.43) (Version: 23.0.1522.43 - Opera Software ASA)
    Opera Stable 20.0.1387.82 (HKLM-x32\...\Opera 20.0.1387.82) (Version: 20.0.1387.82 - Opera Software ASA)
    Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
    PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.65 - PDF Complete, Inc)
    Pivot Pro Plugin (x32 Version: 9.50.110 - Portrait Displays, Inc.) Hidden
    Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
    PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
    PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
    Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.5705 - CyberLink Corp.)
    Power2Go (x32 Version: 6.1.5705 - CyberLink Corp.) Hidden
    PressReader (HKLM-x32\...\{912CED74-88D3-4C5B-ACB0-132318649765}) (Version: 5.11.0721.0 - NewspaperDirect Inc.)
    QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
    Ranch Rush 2 - Premium Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.77.1126.2013 - Realtek)
    Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.82 - Realtek Semiconductor Corp.)
    Recovery Manager (x32 Version: 5.5.0.4424 - CyberLink Corp.) Hidden
    Remote Graphics Receiver (HKLM-x32\...\{16FC3056-90C0-4757-8A68-64D8DA846ADA}) (Version: 5.4.5 - Hewlett-Packard)
    SDK (x32 Version: 2.28.007 - Portrait Displays, Inc.) Hidden
    SendSpace Wizard (HKLM-x32\...\SendSpaceWizard) (Version: 1.4.1 - SendSpace)
    Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
    Sky Go Desktop (HKCU\...\2961178377.go.sky.com) (Version: - go.sky.com)
    Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
    Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
    StreamTransport version: 1.0.2.2171 (HKLM-x32\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - )
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.5.1022 - SUPERAntiSpyware.com)
    Torchlight (x32 Version: 2.2.0.98 - WildTangent) Hidden
    TSHostedAppLauncher (x32 Version: 5.1.15.0 - Hewlett-Packard) Hidden
    Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
    VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
    Virtual Families (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden
    VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN)
    VLC Streamer 4.77 (HKLM-x32\...\VLC Streamer_is1) (Version: - )
    Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden
    WildTangent Games App (x32 Version: 4.0.10.2 - WildTangent) Hidden
    Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
    Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
    Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
    Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
    Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
    Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
    Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
    WinRAR 4.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
    Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team)
    Zinio Reader 4 (HKLM-x32\...\ZinioReader4) (Version: 4.2.4164 - Zinio LLC)
    Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden
    Zoom Player (remove only) (HKLM-x32\...\ZoomPlayer) (Version: - )
    Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden
    ==================== Custom CLSID (selected items): ==========================
    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
    CustomCLSID: HKU\S-1-5-21-131991233-2839458126-3920297457-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Tony\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
    ==================== Restore Points =========================
    19-08-2014 07:54:20 Windows Update
    22-08-2014 08:01:52 Windows Update
    26-08-2014 08:22:09 Windows Update
    28-08-2014 10:00:27 Removed ACDSee 14.
    28-08-2014 20:58:59 Windows Update
    ==================== Hosts content: ==========================
    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
    2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
    ==================== Scheduled Tasks (whitelisted) =============
    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
    Task: {0AD59C22-ACEB-4FD8-9BE5-8D70B2BA1646} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-08-04] (Hewlett-Packard)
    Task: {1905BF32-7AD5-458A-8453-FBB6A2D69CE7} - System32\Tasks\{B46A186C-87CD-426D-BD70-BEC65E9A8C2F} => Firefox.exe
    Task: {1997A933-3C32-48D7-A569-8B6D7F3744CE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
    Task: {1A2E6077-000D-4124-B86C-035D5E2F2C2C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-18] (Google Inc.)
    Task: {1BD947A1-6CB6-4645-AF4B-F60D79E2454E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-18] (Google Inc.)
    Task: {246F16D0-284A-42F6-B94E-1C579477CA9D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-08-04] (Hewlett-Packard)
    Task: {29B4D27D-12D9-42FD-9517-C5E74F885551} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-21] (Adobe Systems Incorporated)
    Task: {2FE39EC7-6240-456F-814A-F5202153EF9A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {30BDA2F7-CD7B-4E65-A51A-24062474B954} - System32\Tasks\{4058A5F4-2D1A-4176-8096-0E64D337D43B} => Firefox.exe
    Task: {3E15E595-7DDF-4B7C-B3E3-1F9579344056} - \ProtectedSearch\Protected Search No Task File <==== ATTENTION
    Task: {40BF79AA-53CB-448E-B858-02E16049CA95} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-08-18] (CyberLink)
    Task: {4A98E2F0-72DA-4B02-AAC8-787E639DE906} - System32\Tasks\Opera scheduled Autoupdate 1372595359 => C:\Program Files (x86)\Opera Next\launcher.exe [2014-07-02] (Opera Software)
    Task: {759C1702-005B-439A-BCD8-289ACDCDE3E5} - \Browser Updater\Browser Updater No Task File <==== ATTENTION
    Task: {760188A6-A3DE-4CC1-8580-5D0ED0C924E8} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Warranty Opt-In(Yes) => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\Detection_PostWarrantyAlert.exe
    Task: {7CC1E495-3340-4CF3-93F8-264A5AA07F55} - System32\Tasks\HPCeeScheduleForTony => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
    Task: {92BCF4D0-DB3B-4A94-BEE5-238ACF769A66} - System32\Tasks\Test TimeTrigger => C:\Users\Tony\AppData\Local\Temp\Runner.exe [2012-11-02] () <==== ATTENTION
    Task: {9CDDC8E6-1CD6-4035-9616-3BE0593288FE} - System32\Tasks\RMCreator => C:\Program Files (x86)\Hewlett-Packard\Recovery\Reminder.exe [2011-08-23] (CyberLink)
    Task: {9D91621F-C81B-4C7F-A575-732136AE3EC1} - System32\Tasks\HPCustParticipation HP Deskjet 3050 J610 series => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-06-14] (Hewlett-Packard Co.)
    Task: {B43A93D8-E3E6-4189-AA1E-96832A6D26A0} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
    Task: {C993964C-2AE8-4AC2-988B-356D88DA0C38} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {F2076657-57E4-405C-A09C-56BEA355A55E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Warranty Opt-In(No) => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\Detection_PostWarrantyAlert.exe
    Task: {FD484260-C99F-4268-A037-FB1D5D9F09B0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\HPCeeScheduleForTony.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
    ==================== Loaded Modules (whitelisted) =============
    2012-12-27 11:06 - 2012-08-16 18:12 - 00268880 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dthook.dll
    2008-08-05 19:01 - 2008-08-05 19:01 - 00092160 _____ () C:\Program Files\Zoom Player\zpshlext64.dll
    2014-04-18 03:13 - 2014-04-18 03:13 - 00086872 _____ () C:\Program Files (x86)\DivX\DivX Player\DPXIconHandler.dll
    2012-04-11 15:32 - 2011-07-27 00:37 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
    2014-01-10 06:26 - 2014-01-10 06:26 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    2012-12-27 11:06 - 2010-05-13 17:34 - 00674928 _____ () C:\Program Files (x86)\Portrait Displays\Pivot Pro Plugin\wpctrl.exe
    2012-04-11 15:50 - 2012-08-16 18:12 - 00161360 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper.exe
    2012-04-11 15:50 - 2012-08-16 18:12 - 00194640 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper64.exe
    2014-07-03 09:53 - 2014-07-03 09:53 - 01401464 _____ () C:\Program Files (x86)\Opera Next\23.0.1522.43\opera_crashreporter.exe
    2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2013-11-07 18:58 - 2013-11-07 18:58 - 00244736 _____ () C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\node_modules\motive-activex-wrapper\build\Release\NodeActiveXWrapper.node
    2013-11-07 18:58 - 2013-11-07 18:58 - 00271360 _____ () C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\node_modules\motive-osbridge\build\Release\MotiveOSBridgeNodeModule.node
    2013-11-07 18:57 - 2013-11-07 18:57 - 00237056 _____ () C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\node_modules\motive-xmpps\build\Release\MotiveXMPPSNode.node
    2013-04-24 08:55 - 2013-04-24 08:55 - 01581056 _____ () C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\node_modules\libxmljs\build\Release\xmljs.node
    2013-04-18 17:55 - 2013-04-18 17:55 - 00068608 _____ () C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\node_modules\dnode\node_modules\weak\build\Release\weakref.node
    2012-04-11 15:50 - 2012-01-17 17:21 - 00068104 _____ () C:\Program Files (x86)\Hewlett-Packard\HP My Display\PEGAACPIDLL.dll
    2012-04-11 15:50 - 2011-02-15 19:59 - 00015624 _____ () C:\Program Files (x86)\Hewlett-Packard\HP My Display\ACPIDll.dll
    2014-01-10 06:28 - 2014-01-10 06:28 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
    2012-04-11 15:50 - 2012-08-16 17:53 - 00180224 _____ () C:\Program Files (x86)\Common Files\Portrait Displays\Shared\PresetsCOM.dll
    2014-07-30 10:54 - 2014-07-30 10:55 - 03800688 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
    2014-08-14 09:17 - 2014-08-14 09:17 - 17048240 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll
    2014-07-03 09:53 - 2014-07-03 09:53 - 00880248 _____ () C:\Program Files (x86)\Opera Next\23.0.1522.43\libglesv2.dll
    2014-07-03 09:53 - 2014-07-03 09:53 - 00135800 _____ () C:\Program Files (x86)\Opera Next\23.0.1522.43\libegl.dll
    2014-07-03 09:53 - 2014-07-03 09:53 - 00957048 _____ () C:\Program Files (x86)\Opera Next\23.0.1522.43\ffmpegsumo.dll
    ==================== Alternate Data Streams (whitelisted) =========
    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

    ==================== Safe Mode (whitelisted) ===================
    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
    ==================== EXE Association (whitelisted) =============
    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

    ==================== MSCONFIG/TASK MANAGER disabled items =========
    (Currently there is no automatic fix for this section.)
    MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup
    MSCONFIG\startupfolder: C:^Users^Tony^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^BBC iPlayer Desktop.lnk => C:\Windows\pss\BBC iPlayer Desktop.lnk.Startup
    MSCONFIG\startupreg: ACSW14EN => "C:\Program Files (x86)\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe" /pid ACSW14EN
    MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
    MSCONFIG\startupreg: BeatsOSDApp => C:\Program Files\IDT\WDM\beats64.exe
    MSCONFIG\startupreg: com.apple.dav.bookmarks.daemon => C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
    MSCONFIG\startupreg: iCloudServices => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
    MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    ==================== Faulty Device Manager Devices =============
    Name: RHDISK_AMD64
    Description: RHDISK_AMD64
    Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Manufacturer:
    Service: RHDISK_AMD64
    Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
    Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
    Devices stay in this state if they have been prepared for removal.
    After you remove the device, this error disappears.Remove the device, and this error should be resolved.

    ==================== Event log errors: =========================
    Application errors:
    ==================
    Error: (08/29/2014 09:02:14 AM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Information only.
    Click-2-Run package registration failure.
    Error: (08/29/2014 09:02:14 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: )
    Description: {tid=E88}
    The Application Virtualization Client could not connect to stream URL 'http://c2r.microsoft.com/ConsumerC2R/en-us/14.0.4763.1000/ConsumerC2R.en-us_14.0.7130.5000.sft' (rc 2460420A-40002EFD, original rc 2460420A-40002EFD).

    System errors:
    =============
    Error: (08/29/2014 09:01:53 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
    Error: (08/29/2014 09:01:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The RHDISK_AMD64 service failed to start due to the following error:
    %%3
    Error: (08/29/2014 09:00:59 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The NEWDRIVER service failed to start due to the following error:
    %%2

    Microsoft Office Sessions:
    =========================
    Error: (08/29/2014 09:02:14 AM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Click-2-Run package registration failure.
    Error: (08/29/2014 09:02:14 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: )
    Description: {tid=E88}
    http://c2r.microsoft.com/ConsumerC2...30.5000.sft2460420A-40002EFD2460420A-40002EFD

    ==================== Memory info ===========================
    Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
    Percentage of memory in use: 69%
    Total physical RAM: 4000.31 MB
    Available physical RAM: 1214.07 MB
    Total Pagefile: 7998.8 MB
    Available Pagefile: 3950.06 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.84 MB
    ==================== Drives ================================
    Drive c: (OS) (Fixed) (Total:915.04 GB) (Free:639.15 GB) NTFS
    Drive d: (HP_RECOVERY) (Fixed) (Total:16.37 GB) (Free:2.04 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive f: (Quarantine- DO NOT OPEN) (Fixed) (Total:931.48 GB) (Free:691.94 GB) NTFS
    ==================== MBR & Partition Table ==================
    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: F375266E)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=915 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=16.4 GB) - (Type=07 NTFS)
    ========================================================
    Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: A7675D2A)
    Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
    ==================== End Of Log ============================
     
  9. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Tony,

    Nice one... thanks.

    Please download the attached fixlist.txt file (bottom of this post) and save it to C:\Users\Tony\Downloads.
    NOTE.
    It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine.
    Running this on another machine may cause damage to your operating system


    Re-run FRST/FRST64 (which ever is installed ) and press the Fix button just once and wait.

    2cf1672fdd2151dad6f349c704143429.png

    The tool will make a log in the Download folder (Fixlog.txt). Please post this in your next reply.

    Thanks
     

    Attached Files:

  10. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    Have tried this twice & both times it starts fixing then after a couple of mins I get a message...
    Farbar recovery scan tool has stopped working ??
     
  11. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Tony,

    Try running the fix in Safe Mode.

    Please reboot your computer in Safe Mode by doing the following :
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, a menu with options should appear;
      You will need to use the 'keyboard arrow keys' to navigate on this menu.
    • Select the first option, to run Windows in Safe Mode, then press the "Enter" key on your keyboard.
    • Then choose your usual account.

    Once the fix has run you can boot back into normal mode.
     
  12. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    Yes that worked, here goes...
    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-08-2014
    Ran by Tony at 2014-08-29 19:30:16 Run:5
    Running from C:\Users\Tony\Downloads
    Boot Mode: Safe Mode (minimal)
    ==============================================
    Content of fixlist:
    *****************
    HKLM-x32\...\Run: [] => [X]
    ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
    ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
    ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
    ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
    ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
    ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
    ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
    SearchScopes: HKLM-x32 - Backup.Old.DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    SearchScopes: HKCU - {251B63F3-36E5-4F04-93D6-F4E9D2977C49} URL =
    SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
    Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    CHR HomePage: Default ->
    CHR StartupUrls: Default -> "hxxp://mysearch.avg.com?cid={E7AE3A81-3542-4C93-A479-C892EF86BF35}&mid=3d758e6b1cc64be1a414b11ccceea2c4-13f7a46765dbab8bfdb2aa13e197f078ae1db1dc&lang=en&ds=gm011&coid=avgtbdisgm&cmpid=&pr=sa&d=2013-12-21 11:14:34&v=17.2.0.38&pid=safeguard&sg=&sap=hp"
    S3 MREMPR5; \??\C:\PROGRA~2\COMMON~1\Motive\MREMPR5.SYS [X]
    S3 MRENDIS5; \??\C:\PROGRA~2\COMMON~1\Motive\MRENDIS5.SYS [X]
    S2 NEWDRIVER; \??\C:\Windows\SysWow64\WinVDEdrv6.sys [X]
    S2 RHDISK_AMD64; \??\C:\Program Files (x86)\Rohos\RHDISK_AMD64.SYS [X]
    C:\Users\Tony\AppData\Local\Temp\airD8B3.exe
    C:\Users\Tony\AppData\Local\Temp\apptorun.exe
    C:\Users\Tony\AppData\Local\Temp\avguidx.dll
    C:\Users\Tony\AppData\Local\Temp\BackupSetup.exe
    C:\Users\Tony\AppData\Local\Temp\cg_qcnqv.dll
    C:\Users\Tony\AppData\Local\Temp\CommonInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\eSafeSvc.exe
    C:\Users\Tony\AppData\Local\Temp\ExPromo.exe
    C:\Users\Tony\AppData\Local\Temp\Extract.exe
    C:\Users\Tony\AppData\Local\Temp\free-hide-folder.exe
    C:\Users\Tony\AppData\Local\Temp\GomAudDnInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\GomEncDnInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\HPHelpUpdater.exe
    C:\Users\Tony\AppData\Local\Temp\HPPSdr.exe
    C:\Users\Tony\AppData\Local\Temp\instruct.exe
    C:\Users\Tony\AppData\Local\Temp\launcher.exe
    C:\Users\Tony\AppData\Local\Temp\MachineIdCreator.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{0B3A180C-0270-4BAD-BE2D-51C23267FA5C}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{376AD83B-18D4-4178-B382-BA08C08C4B44}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{6C4DC06A-72B3-4FB2-87D5-34DA62BE4F18}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{EAA3C375-2E1F-4A76-B2C8-4050037AA001}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{EAACB772-C4BF-4AB1-B433-2F2E92C1D030}.exe
    C:\Users\Tony\AppData\Local\Temp\oi_{F2D8CEDF-EF03-4769-95E6-64C765645308}.exe
    C:\Users\Tony\AppData\Local\Temp\pcDesktopAlertNotifierX.dll
    C:\Users\Tony\AppData\Local\Temp\pmllflwn.dll
    C:\Users\Tony\AppData\Local\Temp\Quarantine.exe
    C:\Users\Tony\AppData\Local\Temp\Resource.exe
    C:\Users\Tony\AppData\Local\Temp\RSPUpgradeInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\Runner.exe
    C:\Users\Tony\AppData\Local\Temp\safeguard.exe
    C:\Users\Tony\AppData\Local\Temp\SAS6_Update.exe
    C:\Users\Tony\AppData\Local\Temp\SendMsg.dll
    C:\Users\Tony\AppData\Local\Temp\SIMEEIInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\SkypeSetup.exe
    C:\Users\Tony\AppData\Local\Temp\SP57550.exe
    C:\Users\Tony\AppData\Local\Temp\sp58915.exe
    C:\Users\Tony\AppData\Local\Temp\SP59509.exe
    C:\Users\Tony\AppData\Local\Temp\sp64126.exe
    C:\Users\Tony\AppData\Local\Temp\SP65786.exe
    C:\Users\Tony\AppData\Local\Temp\SSUPDATE64.EXE
    C:\Users\Tony\AppData\Local\Temp\ToolbarInstaller.exe
    C:\Users\Tony\AppData\Local\Temp\uninst1.exe
    C:\Users\Tony\AppData\Local\Temp\UninstallHPSA.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.0.2-win32.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.0.4-win32.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.0.5-win32.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.1.4-win64.exe
    C:\Users\Tony\AppData\Local\Temp\vlc-2.1.5-win64.exe
    C:\Users\Tony\AppData\Local\Temp\VLCStreamerSetup.exe
    CustomCLSID: HKU\S-1-5-21-131991233-2839458126-3920297457-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Tony\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
    Task: {3E15E595-7DDF-4B7C-B3E3-1F9579344056} - \ProtectedSearch\Protected Search No Task File <==== ATTENTION
    Task: {759C1702-005B-439A-BCD8-289ACDCDE3E5} - \Browser Updater\Browser Updater No Task File <==== ATTENTION
    Task: {92BCF4D0-DB3B-4A94-BEE5-238ACF769A66} - System32\Tasks\Test TimeTrigger => C:\Users\Tony\AppData\Local\Temp\Runner.exe [2012-11-02] () <==== ATTENTION
    Hosts:
    CMD: ipconfig /flushdns
    EmptyTemp:
    *****************
    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value not found.
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive1" => Key not found.
    "HKCR\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => Key not found.
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive2" => Key not found.
    "HKCR\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => Key not found.
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive3" => Key not found.
    "HKCR\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => Key not found.
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt1" => Key not found.
    "HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt2" => Key not found.
    "HKCR\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt3" => Key not found.
    "HKCR\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt4" => Key not found.
    "HKCR\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
    "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive1" => Key not found.
    "HKCR\Wow6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => Key not found.
    "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive2" => Key not found.
    "HKCR\Wow6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => Key not found.
    "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive3" => Key not found.
    "HKCR\Wow6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => Key not found.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\Backup.Old.DefaultScope => Value not found.
    "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{251B63F3-36E5-4F04-93D6-F4E9D2977C49}" => Key not found.
    "HKCR\CLSID\{251B63F3-36E5-4F04-93D6-F4E9D2977C49}" => Key not found.
    "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => Key not found.
    "HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => Key not found.
    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value not found.
    "HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => Key not found.
    Chrome HomePage deleted successfully.
    Chrome StartupUrls deleted successfully.
    MREMPR5 => Service not found.
    MRENDIS5 => Service not found.
    NEWDRIVER => Service not found.
    RHDISK_AMD64 => Service not found.
    "C:\Users\Tony\AppData\Local\Temp\airD8B3.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\apptorun.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\avguidx.dll" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\BackupSetup.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\cg_qcnqv.dll" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\CommonInstaller.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\eSafeSvc.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\ExPromo.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\Extract.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\free-hide-folder.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\GomAudDnInstaller.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\GomEncDnInstaller.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\HPHelpUpdater.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\HPPSdr.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\instruct.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\launcher.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\MachineIdCreator.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\oi_{0B3A180C-0270-4BAD-BE2D-51C23267FA5C}.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\oi_{376AD83B-18D4-4178-B382-BA08C08C4B44}.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\oi_{6C4DC06A-72B3-4FB2-87D5-34DA62BE4F18}.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\oi_{EAA3C375-2E1F-4A76-B2C8-4050037AA001}.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\oi_{EAACB772-C4BF-4AB1-B433-2F2E92C1D030}.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\oi_{F2D8CEDF-EF03-4769-95E6-64C765645308}.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\pcDesktopAlertNotifierX.dll" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\pmllflwn.dll" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\Quarantine.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\Resource.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\RSPUpgradeInstaller.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\Runner.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\safeguard.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\SAS6_Update.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\SendMsg.dll" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\SIMEEIInstaller.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\SkypeSetup.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\SP57550.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\sp58915.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\SP59509.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\sp64126.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\SP65786.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\SSUPDATE64.EXE" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\ToolbarInstaller.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\uninst1.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\UninstallHPSA.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\vlc-2.0.2-win32.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\vlc-2.0.4-win32.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\vlc-2.0.5-win32.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\vlc-2.1.4-win64.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\vlc-2.1.5-win64.exe" => File/Directory not found.
    "C:\Users\Tony\AppData\Local\Temp\VLCStreamerSetup.exe" => File/Directory not found.
    "HKU\S-1-5-21-131991233-2839458126-3920297457-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => Key not found.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E15E595-7DDF-4B7C-B3E3-1F9579344056}" => Key not found.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProtectedSearch\Protected Search" => Key not found.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{759C1702-005B-439A-BCD8-289ACDCDE3E5}" => Key not found.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Updater\Browser Updater" => Error deleting key. The key could be protected.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{92BCF4D0-DB3B-4A94-BEE5-238ACF769A66}" => Key not found.
    C:\Windows\System32\Tasks\Test TimeTrigger not found.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Test TimeTrigger" => Key not found.
    "C:\Windows\System32\Drivers\etc\hosts" => Could not move.
    Could not reset Hosts.
    ========= ipconfig /flushdns =========

    Windows IP Configuration
    Could not flush the DNS Resolver Cache: Function failed during execution.

    ========= End of CMD: =========
    EmptyTemp: => Removed 830.1 MB temporary data.

    The system needed a reboot.
    ==== End of Fixlog ====
     
  13. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Tony,

    I think that the problem you experienced was due to McAfee.
    It would seem that the problem with the fix stalling happened when the fix tried to run the commands:
    Hosts:
    CMD: ipconfig /flushdns
    EmptyTemp:
    Everything up to then had already been removed.... meaning that McAfee had allowed the removal of the standard entries but blocked the resetting of the Hosts and the DNS flush.
    But suddenly decided on allowing the temp folders to be emptied.
    McAfee doesn't play nice with other security tools.... it's a little too controlling. ( but not always in the right parts)
    Plus, as you will have noticed.... it adds loads of entries in the report.
    More entries than we see with other security software.

    How is Hotmail responding now?
    Still having problems?
     
  14. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    Thanks for all your patient help Starbuck. Much of what you say above is way over my head but are you saying I should not use Mcafee? It comes as part of my BT broadband deal. What do I replace it with? I thought I needed a firewall?
    The original Hotmail issue that kicked this all off....
    http://computerhelpforums.net/threads/hotmail-issue.41866/
    persists. It is strange that the box in the taskbar & the minimised box in the toolbar both indicate I have unread new messages & yet they don't show in my inbox until I refresh?
    Also since resetting IE when I enter my name to log in it no longer fills it in for me, I have to type the whole name?
     
  15. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    What i'm saying is that i would never use McAfee.
    It tries to control your system too much and adds loads of entries (services, Processes etc).

    Let me show you in practical terms what i mean.
    This system runs Win7 SP1 ( the same as yours) but i run Emsisoft AntiMalware as my security.
    3 layers of protection... (Surf Protection, Real-time File Guard and Behavior Blocker)

    I've just run FRST and these are the Emsisoft entries:
    These are the McAfee entries from your FRST report:
    Do you see what i mean?
    Obviously the more your system has to run... the harder it has to work.

    Yes that's true.
    In the days of XP we used to recommend a third party firewall as the XP firewall was next to useless.
    That has changed a lot with Win7 and Win8.
    Take a look here and decide for yourself:
    5 Reasons Why the Windows Firewall is One of the Best Firewalls

    So when did this actually start?
    Had you installed any new software around that time?

    This may be nothing, but i have noticed that McAfee adds entries to your IE and Firefox browsers...... but doesn't add any to Opera.
    Try running Internet Explorer and Firefox without any addons...... see if this makes any difference.

    Internet Explorer:
    Click Start >>All Programs >> Accessories >> System Tools >> Internet Explorer (No Addons)

    Firefox:
    Open Firefox, then click on the Help tab and select: Restart with Addons disabled
     
  16. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    Have done as you suggest regarding add ons & it seems to have resolved the main issue of emails not appearing so thanks very much. Only snag is I keep getting a box telling me that add-ons are not enabled, I close it but it comes back?
    Also I still have this minor issue as stated in my previous message..........
    "Also since resetting IE when I enter my name to log in it no longer fills it in for me, I have to type the whole name?"

    Just to be clear is your advice as follows.......
    Turn-off my netprotect ( Mcafee ) firewall ( the settings also tell me it runs ' real time scanning' do I turn that off as well? )
    Install Emisisoft ( is this expensive ? )
    Enable Windows firewall ( how ? )

    Thanks
     
  17. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Tony,

    Ok, let's go through these one at a time:

    Yes that is quite possible.
    Running IE like this is basically a temporary thing.
    Because we have established that one of the addons is is the cause of the problem...... we now need to find out which addon it is.
    This link will explain how to see the addons and turn them off.
    http://windows.microsoft.com/en-gb/internet-explorer/manage-add-ons#ie=ie-11

    It's basically trial and error to find out which one ( or more) is the cause.
    Start off with them all disabled then turn them on one at a time until you find the one that is the culprit.
    That's the one you leave disabled then.

    That said.... the cause may be McAfee, so if you are going to remove it, it's best to wait and see if the problem goes away after the removal.

    It could be a setting got changed or the cookies for the sites got removed.
    M$ explain here how to address this issue:
    http://blogs.msdn.com/b/ieinternals...ubleshooting-stored-login-problems-in-ie.aspx

    If you are going to move away from McAfee, you will need to stop the program from running and then uninstall it from the system.
    Once it's been uninstalled, you need to download and run the McAfee removal tool.
    McAfee doesn't always remove all of the registry entries.... that's what the removal tool will do for you.
    McAfee Removal Tool

    Here's a link to Emsisoft Anti-Malware
    currently it's about £25.00 for a year license.

    Obviously you don't have to go with Emsisoft.
    On my Win8 systems i run ESET NOD32
    It's hard to choose between the 2 as to which is better.
    They are both very good...... and not at all heavy on resources
    Nod32 is on offer at the moment for about £22.00 which is for a 2 year license.

    Both of these programs will let you have a 30 day free trial .... so you could install one and see how it goes.
    If your not happy with it, you can uninstall it and download the other and try that for 30 days.

    There are obviously other AV's out there, but these 2 are what i recommend as the best that i have tried.

    As for turning on the Windows Firewall.
    When you uninstall or turn off the McAfee firewall, you should get a message asking if you want the Windows firewall turned on.
    If you don't get a message:
    Click Start... Control Panel
    Then click on the Security button.
    Under Windows Firewall... click on Turn Windows Firewall on or off.
    Make sure the ON (recommended) is selected.... then click Apply and Ok.

    Let me know how these things go.
    We still need to finish off the cleaning procedure, but we'll put that on hold until you decide on the AV and when you have sorted the login issue.
     
  18. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    Thanks Starbuck. I seem to have somehow muddled my way into solving the add-ons issue but as for the auto-fill problem the link you kindly gave me is a bit beyond my understanding ( I'm a VERY silver surfer of 75 ) so that's still an annoying problem.
    I am reluctant to get rid of Mcafee as its part of my BT internet package & I don't want to have to buy another. I understand Mcafee is a respected name & has generally good products. Until recently it never gave me any problems. Please let me know if you think this is a bad decision.
    How do we proceed to the cleaning?
    Thanks you.
     
  19. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    Hi Pete
    Your message from yesterday seems to have disappeared ??? But here is my reply all the same....
    As regards autofill, all boxes are ticked as you recommended but the problem persists. This only happens with Hotmail. For other log-ins on IE I get a box at the bottom " do you want to save " so I say yes & it does. This option ( box ) does not appear with the Hotmail log-in page?

    Have run ESET & here are the files. Not sure which you require .txt or logtxt so have attached both, probably both give same info. Thanks.
    C:\AdwCleaner\Quarantine\C\Program Files\DomaIQ Uninstaller\DomaIQUninstall.exe.vir probably a variant of MSIL/DomaIQ.A potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\Extension32.dll.vir a variant of Win32/Toolbar.Perion.A potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\Extension64.dll.vir a variant of Win64/Toolbar.Perion.A potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\InstallerHelper.dll.vir a variant of Win32/Toolbar.BitCocktail.A potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\Firefox\chrome\content\main.js.vir Win32/Toolbar.Perion.D potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\Firefox\chrome\content\resources\localscript.js.vir Win32/Toolbar.Perion.E potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\resources\localscript.js.vir Win32/Toolbar.Perion.E potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Program Files\Uninstaller\Uninstall.exe.vir a variant of MSIL/DomaIQ.A potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\LocalLow\Toolbar4\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}\TbHelper2.exe.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\LocalLow\Toolbar4\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}\uninstall.exe.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\LocalLow\Toolbar4\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}\update.exe.vir a variant of Win32/Toolbar.Iminent.E potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe.vir Win32/DownWare.E potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\Extensions\plugin@yontoo.com\content\overlay.js.vir Win32/Adware.Yontoo application cleaned by deleting - quarantined
    C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\PinPhotoZoom\KeepMeUpdated.exe.vir a variant of Win32/PredictAd.A potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\PinPhotoZoom\64\AutocompletePro64.dll.vir probably a variant of Win64/Complitly.A potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\PinPhotoZoom\64\KeepMeUpdated.exe.vir a variant of Win32/PredictAd.A potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\Search Protection\SearchProtection.exe.vir a variant of Win32/Toolbar.Widgi potentially unwanted application deleted - quarantined
    C:\AdwCleaner\Quarantine\C\Windows\System32\roboot64.exe.vir a variant of Win64/Systweak.A potentially unwanted application deleted - quarantined
    C:\FRST\Quarantine\C\Users\Tony\AppData\Local\Temp\instruct.exe.xBAD a variant of Win32/OutBrowse.D potentially unwanted application deleted - quarantined
    C:\FRST\Quarantine\C\Users\Tony\AppData\Local\Temp\free-hide-folder.exe\4b337c66319340abb1da7ada36abef5d\software\Cloud_Backup_Setup.exe Win32/MyPCBackup.A potentially unwanted application deleted - quarantined
    C:\Users\Tony\Downloads\vlcmediaplayer-setup.exe Win32/DownloadAdmin.Gen potentially unwanted application deleted - quarantined




    ESETSmartInstaller@High as CAB hook log:
    OnlineScanner64.ocx - registred OK
    OnlineScanner.ocx - registred OK
    # product=EOS
    # version=8
    # IEXPLORE.EXE=11.00.9600.16428 (winblue_gdr.131013-1700)
    # OnlineScanner.ocx=1.0.0.7623
    # api_version=3.0.2
    # EOSSerial=1077b32a12f4f54fbeac1bf262d228be
    # engine=19957
    # end=finished
    # remove_checked=true
    # archives_checked=false
    # unwanted_checked=true
    # unsafe_checked=false
    # antistealth_checked=true
    # utc_time=2014-09-02 12:40:29
    # local_time=2014-09-02 01:40:29 (+0000, GMT Daylight Time)
    # country="United Kingdom"
    # lang=1033
    # osver=6.1.7601 NT Service Pack 1
    # compatibility_mode_1=''
    # compatibility_mode=5893 16776573 100 94 17895 162126679 0 0
    # scanned=297688
    # found=21
    # cleaned=21
    # scan_time=7031
    sh=1F2C0A5D4CB1B47D1DDC86E3516F06B3ECA63A56 ft=1 fh=94049be6457143fb vn="probably a variant of MSIL/DomaIQ.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\DomaIQ Uninstaller\DomaIQUninstall.exe.vir"
    sh=DCD4360B500FEC023D69701789A4D27CCDDBDD36 ft=1 fh=376b562bd6f4cdbc vn="a variant of Win32/Toolbar.Perion.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\Extension32.dll.vir"
    sh=09231BCABACCFD12D7EF933C3DE4E3B24650BC20 ft=1 fh=b6be9342ffc60f8b vn="a variant of Win64/Toolbar.Perion.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\Extension64.dll.vir"
    sh=730C3C60BF729832E4D08E8B4A2179245A488405 ft=1 fh=44f31356adc46a18 vn="a variant of Win32/Toolbar.BitCocktail.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\InstallerHelper.dll.vir"
    sh=05F172E15709DB6378CA6C23C9EF970A58C6B0E4 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Perion.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\Firefox\chrome\content\main.js.vir"
    sh=8C4EBEFA00C5146974AFA68BE39D3923D8453C20 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Perion.E potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\Firefox\chrome\content\resources\localscript.js.vir"
    sh=8C4EBEFA00C5146974AFA68BE39D3923D8453C20 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Perion.E potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\IB Updater\resources\localscript.js.vir"
    sh=741518CA17409E0C108EA202464829E6C664ED1E ft=1 fh=52477f93f91d8732 vn="a variant of MSIL/DomaIQ.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\Uninstaller\Uninstall.exe.vir"
    sh=609F2D4B1AE5C7177C44CCAF9309EFD16FC9E42D ft=1 fh=8551c46845849e5f vn="a variant of Win32/Toolbar.Iminent.E potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\LocalLow\Toolbar4\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}\TbHelper2.exe.vir"
    sh=22B1B0EAFDBB1229336F9D8187F9905A5DDEDF89 ft=1 fh=406c1e66a46fc082 vn="a variant of Win32/Toolbar.Iminent.E potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\LocalLow\Toolbar4\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}\uninstall.exe.vir"
    sh=88CA2B9C5E587306B08CF6EA239CA72775495695 ft=1 fh=b15f3040528a74fd vn="a variant of Win32/Toolbar.Iminent.E potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\LocalLow\Toolbar4\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}\update.exe.vir"
    sh=2A19E8791533376D8F930704C7487B990BE5B7CD ft=1 fh=a0530847b5c3752d vn="Win32/DownWare.E potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe.vir"
    sh=D84249CE051B0513391DECC5419C0F27AEC7F645 ft=0 fh=0000000000000000 vn="Win32/Adware.Yontoo application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\Extensions\plugin@yontoo.com\content\overlay.js.vir"
    sh=96920E5245E2873506C558EEF43E2D33414A290A ft=1 fh=c3808b7e31f5c398 vn="a variant of Win32/PredictAd.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\PinPhotoZoom\KeepMeUpdated.exe.vir"
    sh=852967EA906FD4C43A28B76B7E271F7C6E338395 ft=1 fh=5cc3f6043e3ac452 vn="probably a variant of Win64/Complitly.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\PinPhotoZoom\64\AutocompletePro64.dll.vir"
    sh=96920E5245E2873506C558EEF43E2D33414A290A ft=1 fh=c3808b7e31f5c398 vn="a variant of Win32/PredictAd.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\PinPhotoZoom\64\KeepMeUpdated.exe.vir"
    sh=2C7C651D15D2771EE89E1FCF9148B071F5980B0E ft=1 fh=8a43b250fe7eb64f vn="a variant of Win32/Toolbar.Widgi potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Tony\AppData\Roaming\Search Protection\SearchProtection.exe.vir"
    sh=51062F03695661A139E4AB7494B22329107B9771 ft=1 fh=c7823bc4c632c674 vn="a variant of Win64/Systweak.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Windows\System32\roboot64.exe.vir"
    sh=39DFD4013F1A43B5A506655DFC703B86346582E9 ft=1 fh=19c493aee16ccccf vn="a variant of Win32/OutBrowse.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\FRST\Quarantine\C\Users\Tony\AppData\Local\Temp\instruct.exe.xBAD"
    sh=D2EAFFAD45CC86DE6E07E9D8E42440CD25DA5754 ft=1 fh=855d8e396d7ffddb vn="Win32/MyPCBackup.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\FRST\Quarantine\C\Users\Tony\AppData\Local\Temp\free-hide-folder.exe\4b337c66319340abb1da7ada36abef5d\software\Cloud_Backup_Setup.exe"
    sh=CDC32905A183E96091244173F25EBEDD28C8B9C6 ft=1 fh=24cb1816127baaf2 vn="Win32/DownloadAdmin.Gen potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Tony\Downloads\vlcmediaplayer-setup.exe"
     
  20. Tony Loly

    Tony Loly Registered Members

    Joined:
    Aug 25, 2014
    Messages:
    369
    Location:
    Solihull, West Midlands
    Operating System:
    Windows 7
    Don't know if you will receive this as your last post isn't appearing here but anyway a big, big, thankyou for all your help.
    Tony
     

Share This Page