# AdwCleaner v4.107 - Report created 13/01/2015 at 21:41:57
# Updated 07/01/2015 by Xplode
# Database : 2015-01-13.2 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : AL - AL-PC
# Running from : C:\Users\AL\Downloads\adwcleaner_4.107.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UpdateAdmin
Folder Deleted : C:\Users\AL\AppData\LocAL\GeniusBox
Folder Deleted : C:\Users\AL\AppData\LocAL\UpdateAdmin
File Deleted : C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
File Deleted : C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKCU\Software\Search Extensions
Key Deleted : HKCU\Software\StormWatchApp
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17496
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Google Chrome v39.0.2171.95
[C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] :
hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] :
hxxp://start.facemoods.com/?a=make&s={searchTerms}&f=4
[C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] :
hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] :
hxxp://search.ividi.org/?q={searchTerms}&src=tbsp&id=18b8dd47000000000000002564eaecfb&affilt=3
[C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] :
hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=mp30102&cd=2XzuyEtN2Y1L1QzutDtDtByDyCyE0E0A0E0C0F0B0D0DyEyBtN0D0Tzu0SyByDyBtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=762133152&ir=
[C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] :
hxxp://Taplika.com/results.php?f=4&q={searchTerms}&a=tpl_tight2_15_02&cd=2XzuyEtN2Y1L1QzutDtDtByDyCyE0E0A0E0C0F0ByDzyyBzztN0D0Tzu0StCtCtDyCtN1L2XzutAtFyCtFyCtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAyDtDyC0A0D0D0BtGzytAyE0DtGtDzyyEtAtGzz0F0AtBtGtBtByD0ByCtByCzyyD0B0A0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StB0DyCzyyByD0EtCtG0F0A0E0BtGyE0F0A0EtG0AtD0A0CtGtAyDtDyDzz0CzztC0F0AtAzy2Q&cr=173989028&ir=
*************************
AdwCleaner[R0].txt - [4694 octets] - [13/01/2015 21:36:25]
AdwCleaner[S0].txt - [4069 octets] - [13/01/2015 21:41:57]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4129 octets] ##########
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-01-2015 02
Ran by [redacted] at 2015-01-13 22:23:01
Running from C:\Users\[redacted]\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Digital Editions 4.0 (HKLM-x32\...\Adobe Digital Editions 4.0) (Version: 4.0.2 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5645 - AVG Technologies)
AVG 2015 (Version: 15.0.4260 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.5645 - AVG Technologies) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom NetXtreme-I Netlink Driver and Management Installer (HKLM\...\{5569655A-9653-42CD-A599-5617DF767D2A}) (Version: 12.37.01 - Broadcom Corporation)
Dell Resource CD (HKLM-x32\...\{42929F0F-CE14-47AF-9FC7-FF297A603021}) (Version: 1.00.0000 - Dell Inc.)
GeniusBox 2.0 (HKLM-x32\...\GeniusBox) (Version: 2.0 - GeniusBox 2.0)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 72 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217072FF}) (Version: 7.0.720 - Oracle)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Modem Diagnostic Tool (HKLM\...\{0335701D-8E28-4A7F-B0EF-312974755BB2}) (Version: 1.0.24.0 - Dell)
MP3 Rocket (HKLM-x32\...\MP3 Rocket) (Version: 7.1 - MP3 Rocket Inc)
NetWaiting (HKLM-x32\...\{3F92ABBB-6BBF-11D5-B229-002078017FBF}) (Version: 2.5.54 - BVRP Software, Inc)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
UpdateAdmin (HKLM-x32\...\{07B4B423-E4DA-47D1-8327-B589EB4BEB58}) (Version: 2.0.1885 - DownloadAdmin)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
17-12-2014 23:01:17 Windows Update
20-12-2014 19:24:16 Windows Backup
21-12-2014 19:37:29 Windows Backup
21-12-2014 19:47:18 Windows Backup
28-12-2014 19:01:13 Windows Backup
04-01-2015 19:00:14 Windows Backup
11-01-2015 19:00:15 Windows Backup
12-01-2015 20:45:07 Checkpoint by HitmanPro
13-01-2015 21:56:00 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0284C3A2-9C12-407B-B369-65EE18A6DC3B} - System32\Tasks\Check Updates => C:\Users\AL\AppData\Local\GeniusBox\updater.exe
Task: {0FEA6823-66A0-4633-BD6F-D93957D95252} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {5AECD7E5-41C9-489E-895D-0D396A1DAB02} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-26] (Google Inc.)
Task: {5BEC3C21-014F-4966-A71B-A9C7B913358A} - System32\Tasks\Validate Installation => C:\Users\AL\AppData\Local\GeniusBox\updater.exe
Task: {6F91B6F9-19C7-460B-A370-D9A6F865D390} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-26] (Google Inc.)
Task: {B26B96E2-E8B1-4BC5-8F06-AF7DAC82ABC9} - System32\Tasks\GeniusBox => cmd.exe /C start "" "C:\Users\AL\AppData\Local\GeniusBox\client.exe"
Task: {C5E947A4-9F2F-4942-B473-D68D421D34FF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {D4EF2D7B-582A-43C7-A51D-B5ED8770DBFC} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1544753468-1480976245-751527611-1000
Task: {ED51586C-6205-49DF-9991-EAC0044E025A} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2014-12-22] ()
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2012-01-10 21:12 - 2012-01-10 21:12 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-10-11 13:06 - 2014-10-11 13:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-1544753468-1480976245-751527611-500 - Administrator - Disabled)
AL (S-1-5-21-1544753468-1480976245-751527611-1000 - Administrator - Enabled) => C:\Users\AL
Guest (S-1-5-21-1544753468-1480976245-751527611-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1544753468-1480976245-751527611-1002 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/12/2015 07:11:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: ERROR: accept: 10022 (An invalid argument was supplied.)
Error: (01/11/2015 08:38:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9266
Error: (01/11/2015 08:38:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9266
Error: (01/11/2015 08:38:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/11/2015 08:38:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8268
Error: (01/11/2015 08:38:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8268
Error: (01/11/2015 08:38:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/11/2015 08:38:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7269
Error: (01/11/2015 08:38:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7269
Error: (01/11/2015 08:38:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
System errors:
=============
Error: (01/13/2015 09:56:23 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Error: (01/13/2015 09:42:00 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk6\DR6.
Error: (01/13/2015 09:41:58 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
Error: (01/13/2015 09:41:58 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
Error: (01/13/2015 09:41:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Office Software Protection Platform service terminated unexpectedly. It has done this 1 time(s).
Error: (01/13/2015 09:41:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The iPod Service service terminated unexpectedly. It has done this 1 time(s).
Error: (01/13/2015 09:41:58 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Error: (01/13/2015 09:41:58 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Error: (01/13/2015 09:41:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
Error: (01/13/2015 09:19:08 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk6\DR6.
Microsoft Office Sessions:
=========================
Error: (01/12/2015 07:11:30 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: ERROR: accept: 10022 (An invalid argument was supplied.)
Error: (01/11/2015 08:38:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9266
Error: (01/11/2015 08:38:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9266
Error: (01/11/2015 08:38:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/11/2015 08:38:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8268
Error: (01/11/2015 08:38:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8268
Error: (01/11/2015 08:38:46 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/11/2015 08:38:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7269
Error: (01/11/2015 08:38:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7269
Error: (01/11/2015 08:38:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) CPU G6950 @ 2.80GHz
Percentage of memory in use: 33%
Total physical RAM: 3895.12 MB
Available physical RAM: 2606.4 MB
Total Pagefile: 7788.42 MB
Available Pagefile: 6406.29 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:232.73 GB) (Free:189.8 GB) NTFS
Drive j: (FreeAgent Drive) (Fixed) (Total:465.76 GB) (Free:206.82 GB) NTFS
Drive k: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or

(Size: 232.8 GB) (Disk ID: 90000000)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.7 GB) - (Type=07 NTFS)
========================================================
Disk: 6 (Size: 465.8 GB) (Disk ID: A4B57300)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2015 02
Ran by [redacted] (administrator) on AL-PC on 13-01-2015 22:22:03
Running from C:\Users\[redacted]\Downloads
[redacted]
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-11-27] (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-1544753468-1480976245-751527611-1000] => http=127.0.0.1:49172;https=127.0.0.1:49172
HKU\S-1-5-21-1544753468-1480976245-751527611-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.72.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.72.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
Chrome:
=======
CHR HomePage: Default ->
hxxp://search.conduit.com/?gd=&ctid=CT3 ... E5A8&SSPV=
CHR StartupUrls: Default -> "hxxp://Taplika.com/?f=7&a=tpl_tight2_15_02&cd=2XzuyEtN2Y1L1QzutDtDtByDyCyE0E0A0E0C0F0ByDzyyBzztN0D0Tzu0StCtCtDyCtN1L2XzutAtFyCtFyCtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAyDtDyC0A0D0D0BtGzytAyE0DtGtDzyyEtAtGzz0F0AtBtGtBtByD0ByCtByCzyyD0B0A0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StB0DyCzyyByD0EtCtG0F0A0E0BtGyE0F0A0EtG0AtD0A0CtGtAyDtDyDzz0CzztC0F0AtAzy2Q&cr=173989028&ir="
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-26]
CHR Extension: (Google Docs) - C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-26]
CHR Extension: (Google Drive) - C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-26]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-26]
CHR Extension: (YouTube) - C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-26]
CHR Extension: (Google Search) - C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-26]
CHR Extension: (Google Sheets) - C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-26]
CHR Extension: (Google Wallet) - C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-26]
CHR Extension: (Gmail) - C:\Users\AL\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-26]
CHR HKLM\...\Chrome\Extension: [lfkjojacgdjkninepeghaamnapdjmlfn] - No Path
CHR HKU\S-1-5-21-1544753468-1480976245-751527611-1000\...\Chrome\Extension: [lfkjojacgdjkninepeghaamnapdjmlfn] - No Path
CHR HKLM-x32\...\Chrome\Extension: [lfkjojacgdjkninepeghaamnapdjmlfn] - No Path
CHR StartMenuInternet: Google Chrome - chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3432976 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-12-18] (AVG Technologies CZ, s.r.o.)
S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [260888 2014-12-08] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [203544 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [274200 2014-10-10] (AVG Technologies CZ, s.r.o.)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-13 22:22 - 2015-01-13 22:22 - 00010548 _____ () C:\Users\AL\Downloads\FRST.txt
2015-01-13 22:20 - 2015-01-13 22:22 - 00000000 ____D () C:\FRST
2015-01-13 22:20 - 2015-01-13 22:20 - 02124288 _____ (Farbar) C:\Users\AL\Downloads\FRST64.exe
2015-01-13 21:46 - 2015-01-13 21:46 - 00004245 _____ () C:\Users\AL\Desktop\AdwCleaner[S0].txt
2015-01-13 21:35 - 2015-01-13 21:41 - 00000000 ____D () C:\AdwCleaner
2015-01-13 21:34 - 2015-01-13 21:34 - 02191360 _____ () C:\Users\AL\Downloads\adwcleaner_4.107.exe
2015-01-13 19:48 - 2014-12-18 22:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-13 19:48 - 2014-12-18 20:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-13 19:48 - 2014-12-12 00:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-13 19:48 - 2014-12-12 00:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-13 19:48 - 2014-12-12 00:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-13 19:48 - 2014-12-12 00:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-13 19:48 - 2014-12-12 00:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-13 19:48 - 2014-12-12 00:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-13 19:48 - 2014-12-12 00:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-13 19:48 - 2014-12-11 12:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-13 19:48 - 2014-12-05 23:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-13 19:48 - 2014-12-05 22:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-13 19:48 - 2014-12-05 22:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-12 22:51 - 2015-01-12 22:51 - 00014375 _____ () C:\Users\AL\Desktop\dds.txt
2015-01-12 22:51 - 2015-01-12 22:51 - 00005968 _____ () C:\Users\AL\Desktop\attach.txt
2015-01-12 22:50 - 2015-01-12 22:50 - 00688992 ____R (Swearware) C:\Users\AL\Downloads\dds.scr
2015-01-12 19:15 - 2015-01-12 19:15 - 00000000 ____D () C:\Windows\system32\appmgmt
2015-01-11 19:42 - 2015-01-11 19:42 - 00004428 _____ () C:\Windows\System32\Tasks\Validate Installation
2015-01-11 19:42 - 2015-01-11 19:42 - 00004220 _____ () C:\Windows\System32\Tasks\Check Updates
2015-01-11 19:42 - 2015-01-11 19:42 - 00003836 _____ () C:\Windows\System32\Tasks\GeniusBox
2015-01-11 19:42 - 2015-01-11 19:42 - 00000064 _____ () C:\Users\AL\AppData\Local\543103c6c673b3f823f1c9d2b31c229b
2015-01-11 19:40 - 2015-01-11 19:40 - 79497296 _____ () C:\Users\AL\Downloads\7zip-setup.exe
2015-01-10 21:46 - 2015-01-10 21:46 - 00882504 _____ ( ) C:\Users\AL\Downloads\mp3rocket (2).exe
2015-01-10 21:12 - 2015-01-10 21:12 - 00882504 _____ ( ) C:\Users\AL\Downloads\mp3rocket (1).exe
2015-01-10 20:17 - 2015-01-10 20:18 - 00000133 _____ () C:\Users\AL\Desktop\Craiglist.url
2015-01-08 21:02 - 2015-01-08 21:02 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software
2015-01-08 21:02 - 2015-01-08 21:02 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software
2015-01-07 22:38 - 2015-01-13 21:30 - 00008900 _____ () C:\Users\AL\Desktop\Weight Chart.xlsx
2015-01-01 21:46 - 2015-01-01 21:46 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2015-01-01 19:37 - 2015-01-01 19:37 - 00001787 _____ () C:\Users\AL\Downloads\RunningDream9780375896798 (11).acsm
2015-01-01 14:37 - 2015-01-10 15:15 - 00000125 _____ () C:\Users\AL\Desktop\Pandora Internet Radio - Listen to Free Music You'll Love.url
2014-12-30 16:29 - 2014-12-30 16:29 - 03668905 _____ () C:\Users\AL\Downloads\IMG_2158.MOV
2014-12-27 16:09 - 2014-12-27 16:09 - 00001791 _____ () C:\Users\AL\Downloads\RunningDream9780375896798 (10).acsm
2014-12-27 16:06 - 2014-12-27 16:06 - 00001791 _____ () C:\Users\AL\Downloads\RunningDream9780375896798 (9).acsm
2014-12-27 16:05 - 2014-12-27 16:05 - 00001791 _____ () C:\Users\AL\Downloads\RunningDream9780375896798 (8).acsm
2014-12-24 22:49 - 2014-12-24 22:49 - 00001791 _____ () C:\Users\AL\Downloads\RunningDream9780375896798 (7).acsm
2014-12-24 10:30 - 2014-12-24 10:30 - 00001791 _____ () C:\Users\AL\Downloads\RunningDream9780375896798 (6).acsm
2014-12-24 10:21 - 2014-12-24 10:21 - 00001791 _____ () C:\Users\AL\Downloads\RunningDream9780375896798 (5).acsm
2014-12-24 10:20 - 2014-12-24 10:20 - 00001791 _____ () C:\Users\AL\Downloads\RunningDream9780375896798 (4).acsm
2014-12-24 10:19 - 2014-12-24 10:19 - 00001791 _____ () C:\Users\AL\Downloads\RunningDream9780375896798 (3).acsm
2014-12-23 23:31 - 2014-12-23 23:31 - 00000000 ____D () C:\Users\AL\Documents\Fax
2014-12-23 21:48 - 2014-12-23 21:52 - 00000000 ____D () C:\Program Files (x86)\DriverToolkit
2014-12-23 21:48 - 2014-12-23 21:48 - 00000000 ____D () C:\Users\AL\AppData\Local\DriverToolkit
2014-12-23 21:47 - 2014-12-23 21:47 - 02448688 _____ (Megaify Software ) C:\Users\AL\Downloads\driver_setup.exe
2014-12-22 16:29 - 2015-01-13 22:02 - 00003758 _____ () C:\Windows\System32\Tasks\AutoKMS
2014-12-22 16:29 - 2014-12-23 08:17 - 00000000 ____D () C:\Windows\AutoKMS
2014-12-22 16:28 - 2014-12-22 16:28 - 00000000 ____D () C:\ProgramData\Microsoft Toolkit
2014-12-20 17:16 - 2014-12-20 17:18 - 00000000 ____D () C:\Users\AL\Documents\My Digital Editions
2014-12-20 17:16 - 2014-12-20 17:16 - 00002178 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Digital Editions 4.0.lnk
2014-12-20 17:16 - 2014-12-20 17:16 - 00002166 _____ () C:\Users\Public\Desktop\Adobe Digital Editions 4.0.lnk
2014-12-20 17:16 - 2014-12-20 17:16 - 00001791 _____ () C:\Users\AL\Downloads\RunningDream9780375896798 (2).acsm
2014-12-20 17:16 - 2014-12-20 17:16 - 00000000 ____D () C:\Users\AL\AppData\Local\Adobe_Systems_Incorporate
2014-12-20 17:16 - 2014-12-20 17:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2014-12-20 17:16 - 2014-12-20 17:16 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-12-20 17:14 - 2014-12-20 17:14 - 07680016 _____ (Adobe Systems Incorporated) C:\Users\AL\Downloads\ADE_4.0_Installer.exe
2014-12-20 17:14 - 2014-12-20 17:14 - 00001791 _____ () C:\Users\AL\Downloads\RunningDream9780375896798 (1).acsm
2014-12-20 17:09 - 2014-12-20 17:09 - 00001791 _____ () C:\Users\AL\Downloads\RunningDream9780375896798.acsm
2014-12-17 18:20 - 2014-12-13 00:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-17 18:20 - 2014-12-12 22:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-17 09:04 - 2014-12-17 09:04 - 00262144 _____ () C:\Windows\Minidump\121714-23056-01.dmp
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-13 22:12 - 2014-11-25 18:27 - 02011714 _____ () C:\Windows\WindowsUpdate.log
2015-01-13 22:09 - 2014-11-25 18:58 - 00000000 ____D () C:\Users\AL\Documents\Outlook Files
2015-01-13 22:07 - 2009-07-13 23:45 - 00020720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-13 22:07 - 2009-07-13 23:45 - 00020720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-13 22:02 - 2014-11-26 19:37 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-13 22:02 - 2014-11-25 18:46 - 00003902 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{32C26912-984F-40C4-8FC2-167F68B6534C}
2015-01-13 22:01 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-13 22:01 - 2009-07-13 23:51 - 00030817 _____ () C:\Windows\setupact.log
2015-01-13 21:59 - 2014-11-25 19:09 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-13 21:56 - 2014-11-25 19:09 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-13 21:54 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-13 21:43 - 2014-11-25 19:01 - 00075914 _____ () C:\Windows\PFRO.log
2015-01-13 21:42 - 2014-11-26 19:37 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-13 19:40 - 2014-11-25 19:13 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-12 20:51 - 2014-11-28 18:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2015-01-11 19:41 - 2014-11-26 19:37 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-11 19:40 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\Resources
2015-01-10 22:40 - 2014-11-27 14:51 - 00000000 ____D () C:\Users\AL\Incomplete
2015-01-10 22:30 - 2009-07-14 02:45 - 00000000 ___RD () C:\Users\Public\Recorded TV
2015-01-10 21:31 - 2014-11-27 14:49 - 00000000 ____D () C:\Users\AL\AppData\Roaming\MP3Rocket
2015-01-08 21:02 - 2014-11-25 19:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-12-23 22:29 - 2009-07-14 00:13 - 00781782 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-20 20:38 - 2014-11-25 18:45 - 00000000 ____D () C:\Users\AL\AppData\Local\Microsoft Help
2014-12-20 17:16 - 2014-11-25 19:23 - 00000000 ____D () C:\Users\AL\AppData\Roaming\Adobe
2014-12-17 09:04 - 2014-12-04 20:48 - 494074667 _____ () C:\Windows\MEMORY.DMP
2014-12-17 09:04 - 2014-12-04 20:48 - 00000000 ____D () C:\Windows\Minidump
Some content of TEMP:
====================
C:\Users\AL\AppData\Local\Temp\HitmanPro.exe
C:\Users\AL\AppData\Local\Temp\Quarantine.exe
C:\Users\AL\AppData\Local\Temp\SpOrder.dll
C:\Users\AL\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-04 12:47
==================== End Of Log ============================