HELP VIRUS HAS WIPED OUT MY DESKTOP,TASKBAR AND START UP MENU

Status
Not open for further replies.

tindo75

New Member
Thread author
Jan 15, 2015
1
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-01-2015
Ran by A Munawa (administrator) on AMUNAWA-HP on 15-01-2015 11:22:56
Running from C:\Users\A Munawa\Desktop\tool
Loaded Profiles: A Munawa & DefaultAppPool (Available profiles: A Munawa & DefaultAppPool)
Platform: Windows 7 Home Basic Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\Program Files\CDMA-1XDO\C+WEject.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
() C:\Program Files\Africom UI\bin\MonServiceUDisk.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Trend Media Corporation Limited) C:\Program Files (x86)\FlashGet Network\FlashGet 3\Flashget3.exe
() C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
(Nokia) C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Tonec Inc.) C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\idman.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(BitTorrent Inc.) C:\Users\A Munawa\AppData\Roaming\uTorrent\uTorrent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(APN LLC.) C:\Users\A Munawa\AppData\Local\VNT\vntldr.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\idmBroker.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6463592 2012-02-13] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2885904 2012-02-24] (Synaptics Incorporated)
HKLM\...\Run: [SetDefault] => C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [44880 2011-12-20] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DApp] => C:\Program Files\PCDApp\start.vbs [178 2014-04-10] ()
HKLM-x32\...\Run: [VNT] => C:\Program Files (x86)\VNT\vntldr.exe [196504 2014-06-14] (APN LLC.)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-12-16] (Hewlett-Packard)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\Run: [FlashGet 3] => C:\Program Files (x86)\FlashGet Network\FlashGet 3\Flashget3.exe [3090056 2012-03-15] (Trend Media Corporation Limited)
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\Run: [PC Suite Tray] => C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\Run: [IDMan] => C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\idman.exe [3825232 2013-11-19] (Tonec Inc.)
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7780120 2014-12-19] (SUPERAntiSpyware)
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\Run: [uTorrent] => C:\Users\A Munawa\AppData\Roaming\uTorrent\uTorrent.exe [1728336 2014-12-17] (BitTorrent Inc.)
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\MountPoints2: {0efbcc75-7399-11e3-a56f-a0b3ccc6d49e} - E:\Startme.exe
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\MountPoints2: {784d1360-3677-11e3-936e-74e54308c6b3} - G:\setup.exe
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\MountPoints2: {7947d100-1f5d-11e3-a919-74e54308c6b3} - G:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\MountPoints2: {821ef556-c764-11e2-98bd-a0b3ccc6d49e} - G:\LaunchU3.exe
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\MountPoints2: {8981165f-d465-11e2-a398-74e54308c6b3} - E:\AutoRun.exe
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\MountPoints2: {c08eb7a9-548a-11e4-a59b-74e54308c6b3} - H:\TL-Bootstrap.exe
HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\MountPoints2: {f7a081ea-f61b-11e3-9538-a0b3ccc6d49e} - E:\START.EXE
HKU\S-1-5-18\...\Run: [Advanced SystemCare 7] => "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)
BootExecute: autocheck autochk * 搀渀挀氀攀愀渀㘀㐀⸀攀砀攀搀渀挀氀攀愀渀㘀㐀⸀攀砀攀搀渀挀氀攀愀渀㘀㐀⸀攀砀攀搀渀挀氀攀愀渀㘀㐀⸀攀砀攀
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKU\S-1-5-21-534593773-3893946233-160603186-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?typ...xp&uid=TOSHIBAXMK3276GSX_52OGSJMNSXX52OGSJMNS
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?typ...xp&uid=TOSHIBAXMK3276GSX_52OGSJMNSXX52OGSJMNS
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/...MK3276GSX_52OGSJMNSXX52OGSJMNS&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/...MK3276GSX_52OGSJMNSXX52OGSJMNS&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?typ...xp&uid=TOSHIBAXMK3276GSX_52OGSJMNSXX52OGSJMNS
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?typ...xp&uid=TOSHIBAXMK3276GSX_52OGSJMNSXX52OGSJMNS
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/...MK3276GSX_52OGSJMNSXX52OGSJMNS&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/...MK3276GSX_52OGSJMNSXX52OGSJMNS&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-534593773-3893946233-160603186-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?typ...xp&uid=TOSHIBAXMK3276GSX_52OGSJMNSXX52OGSJMNS
HKU\S-1-5-21-534593773-3893946233-160603186-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?typ...xp&uid=TOSHIBAXMK3276GSX_52OGSJMNSXX52OGSJMNS
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.bing.com?pc=CMNTDF
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&u...XMK3276GSX_52OGSJMNSXX52OGSJMNS&ts=1380690632
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = http://go.speedbit.com/search.aspx?s=DC8a&q={searchTerms}
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2002} URL = http://dts.search.ask.com/sr?src=ie...ME002&o=APN10641&apn_ptnrs=AG2&q={searchTerms}
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://uk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/...MK3276GSX_52OGSJMNSXX52OGSJMNS&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/...MK3276GSX_52OGSJMNSXX52OGSJMNS&q={searchTerms}
SearchScopes: HKLM-x32 -> {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = http://go.speedbit.com/search.aspx?s=E1Faya1&q={searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2002} URL = http://dts.search.ask.com/sr?src=ie...ME002&o=APN10641&apn_ptnrs=AG2&q={searchTerms}
SearchScopes: HKU\S-1-5-21-534593773-3893946233-160603186-1001 -> DefaultScope {EA80D4D9-B531-48D1-9214-7BB2492EBAF8} URL = http://www.bing.com/search?FORM=U219DF&PC=U219&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-534593773-3893946233-160603186-1001 -> EDA5F67F2C434E5682D88CF8FBD04859 URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=541231&p={searchTerms}
SearchScopes: HKU\S-1-5-21-534593773-3893946233-160603186-1001 -> {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = http://go.speedbit.com/search.aspx?s=E1Faya1&q={searchTerms}
SearchScopes: HKU\S-1-5-21-534593773-3893946233-160603186-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2002} URL = http://dts.search.ask.com/sr?src=ie...ME002&o=APN10641&apn_ptnrs=AG2&q={searchTerms}
SearchScopes: HKU\S-1-5-21-534593773-3893946233-160603186-1001 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL =
SearchScopes: HKU\S-1-5-21-534593773-3893946233-160603186-1001 -> {EA80D4D9-B531-48D1-9214-7BB2492EBAF8} URL = http://www.bing.com/search?FORM=U219DF&PC=U219&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://uk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
BHO: Ask Toolbar -> {41524553-2D56-3700-76A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ARES-V7\Passport_x64.dll (APN LLC.)
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: KangoBHO -> {A88DE8D3-9C38-4F0D-8981-A4C17F7677A1} -> C:\Program Files (x86)\Notificatoin\1.0.0\KangoBHO64.dll (Kango)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
BHO-x32: ContributeBHO Class -> {074C1DC5-9320-4A9A-947D-C042949C6216} -> C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
BHO-x32: Ask Toolbar -> {41524553-2D56-3700-76A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ARES-V7\Passport.dll (APN LLC.)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: KangoBHO -> {A88DE8D3-9C38-4F0D-8981-A4C17F7677A1} -> C:\Program Files (x86)\Notificatoin\1.0.0\KangoBHO.dll (Kango)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: FlashGetBHO -> {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} -> C:\Users\A Munawa\AppData\Roaming\FlashGetBHO\FlashGetBHO.dll (Trend Media Group)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - Kango - {F051F6BF-82D9-49A7-9E6C-BA63CDB487D2} - C:\Program Files (x86)\Notificatoin\1.0.0\KangoBHO64.dll (Kango)
Toolbar: HKLM - Ask Toolbar - {41524553-2D56-3700-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ARES-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - Ask Toolbar - {41524553-2D56-3700-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ARES-V7\Passport.dll (APN LLC.)
Toolbar: HKLM-x32 - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
Toolbar: HKU\S-1-5-21-534593773-3893946233-160603186-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.8.1

FireFox:
========
FF ProfilePath: C:\Users\A Munawa\AppData\Roaming\Mozilla\Firefox\Profiles\amti03w8.default-1403032347680
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: webssearches
FF SelectedSearchEngine: webssearches
FF Homepage: hxxp://istart.webssearches.com/?type=hp&ts=1421220321&from=exp&uid=TOSHIBAXMK3276GSX_52OGSJMNSXX52OGSJMNS
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npBitCometAgent.dll (BitComet)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll (Adobe Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF SearchPlugin: C:\Users\A Munawa\AppData\Roaming\Mozilla\Firefox\Profiles\amti03w8.default-1403032347680\searchplugins\webssearches.xml
FF Extension: General Downloader plugin - C:\Users\A Munawa\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\@generaldownloader.com [2013-10-25]
FF Extension: BYTubeD - Bulk YouTube video Downloader - C:\Users\A Munawa\AppData\Roaming\Mozilla\Firefox\Profiles\amti03w8.default-1403032347680\Extensions\bytubed@cs213.cse.iitk.ac.in [2014-06-17]
FF Extension: Fast Start - C:\Users\A Munawa\AppData\Roaming\Mozilla\Firefox\Profiles\amti03w8.default-1403032347680\Extensions\faststartff@gmail.com [2015-01-14]
FF Extension: FF Toolbar - C:\Users\A Munawa\AppData\Roaming\Mozilla\Firefox\Profiles\amti03w8.default-1403032347680\Extensions\fftoolbar2014@etech.com [2015-01-14]
FF Extension: unisalese - C:\Users\A Munawa\AppData\Roaming\Mozilla\Firefox\Profiles\amti03w8.default-1403032347680\Extensions\jb@5JcH.org [2015-01-14]
FF Extension: FlashGot - C:\Users\A Munawa\AppData\Roaming\Mozilla\Firefox\Profiles\amti03w8.default-1403032347680\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2014-06-17]
FF Extension: ScrapBook - C:\Users\A Munawa\AppData\Roaming\Mozilla\Firefox\Profiles\amti03w8.default-1403032347680\Extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}.xpi [2014-06-18]
FF Extension: DownThemAll! - C:\Users\A Munawa\AppData\Roaming\Mozilla\Firefox\Profiles\amti03w8.default-1403032347680\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2014-06-17]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com [2014-12-11]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-12-11]
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha693.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha693\ff
FF Extension: Media Player - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha693\ff [2014-01-30]
FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox
FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox [2014-04-26]
FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
FF Extension: Adobe Contribute Toolbar - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2014-11-08]
FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\A Munawa\AppData\Roaming\Mozilla\Firefox\Profiles\amti03w8.default-1403032347680\extensions\fftoolbar2014@etech.com
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\A Munawa\AppData\Roaming\Mozilla\Firefox\Profiles\amti03w8.default-1403032347680\extensions\faststartff@gmail.com
FF HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\Firefox\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\A Munawa\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\A Munawa\AppData\Roaming\IDM\idmmzcc5 [2014-08-15]
FF HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\A Munawa\AppData\Roaming\IDM\idmmzcc5
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://istart.webssearches.com/?typ...xp&uid=TOSHIBAXMK3276GSX_52OGSJMNSXX52OGSJMNS

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxp://istart.webssearches.com/?type=hp&ts=1421220321&from=exp&uid=TOSHIBAXMK3276GSX_52OGSJMNSXX52OGSJMNS
CHR StartupUrls: Default -> "hxxp://istart.webssearches.com/?type=hp&ts=1421220321&from=exp&uid=TOSHIBAXMK3276GSX_52OGSJMNSXX52OGSJMNS"
CHR DefaultSearchKeyword: Default -> webssearches
CHR DefaultSearchURL: Default -> http://istart.webssearches.com/web/...MK3276GSX_52OGSJMNSXX52OGSJMNS&q={searchTerms}
CHR Profile: C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-25]
CHR Extension: (Google Drive) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-25]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-29]
CHR Extension: (YouTube) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-25]
CHR Extension: (Google Search) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-25]
CHR Extension: (Download Manager) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\daoidaoebhfcgccdpgjjcbdginkofmfe [2014-06-12]
CHR Extension: (Downloadr - Download Manager) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjihnjejboipjmadkpmknccijhibnpfe [2014-06-12]
CHR Extension: (FlareGet Integration) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoboanjcaobnfchcnlgjhmnmogmnbipb [2014-05-05]
CHR Extension: (IDM Integration Module) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [2014-08-15]
CHR Extension: (FVD Downloader) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2014-05-05]
CHR Extension: (Google Wallet) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-25]
CHR Extension: (Click&Clean App) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2014-05-05]
CHR Extension: (Gmail) - C:\Users\A Munawa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-25]
CHR HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\Chrome\Extension: [hmhfbmpdiffkamakhdbcgojfnbnlcenm] - C:\ProgramData\Microsoft\Windows\DRM\Server\notificatoin_1.0.0.crx [2013-11-28]
CHR HKLM-x32\...\Chrome\Extension: [aaaaibegohjoodbpgmpdfckhihkipgpb] - C:\ProgramData\AskPartnerNetwork\Toolbar\ARES-V7\CRX\ToolbarCR.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [bdgpjclefcppbhifgmbncakhhphkggdb] - No Path
CHR HKLM-x32\...\Chrome\Extension: [cpddmhjignockmjbknmmfngpjjbbpkfh] - No Path
CHR HKLM-x32\...\Chrome\Extension: [gkcbebbklfkjeocpmoamnopdllfekind] - C:\Users\A Munawa\AppData\Roaming\General Downloader\Extensions\gdchrome.crx [2013-10-25]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - No Path
CHR HKLM-x32\...\Chrome\Extension: [hmhfbmpdiffkamakhdbcgojfnbnlcenm] - C:\ProgramData\Microsoft\Windows\DRM\Server\notificatoin_1.0.0.crx [2013-11-28]
CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2014-04-26]
CHR HKLM-x32\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2014-07-10]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM-x32\...\Chrome\Extension: [oikhdfmobnceneiablilhgijpkiknahf] - No Path
CHR HKLM-x32\...\Chrome\Extension: [pcidejejpblipcjpnkfkddlkmgndblch] - C:\Users\A Munawa\AppData\Roaming\General Downloader\Extensions\GenCrawler.crx [2013-10-25]
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://istart.webssearches.com/?typ...xp&uid=TOSHIBAXMK3276GSX_52OGSJMNSXX52OGSJMNS

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-02-15] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3432976 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 CDROM_Detect; C:\Program Files\CDMA-1XDO\C+WEject.exe [269312 2011-09-07] () [File not signed]
S4 CLPSLS; C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [1267000 2011-11-23] (COMODO)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-09-18] (Freemake) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed]
S4 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [853288 2007-09-20] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-09-20] (Nero AG)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1134584 2012-02-20] (PDF Complete Inc)
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2013-09-13] (arvato digital services llc)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 UDisk Monitor; C:\Program Files\Africom UI\bin\MonServiceUDisk.exe [404992 2011-01-14] () [File not signed]
R2 vToolbarUpdater12.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe [927840 2013-03-14] ()
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2012-01-04] (Advanced Micro Devices)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [260888 2014-12-08] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [203544 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [274200 2014-10-10] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [31080 2013-03-14] (AVG Technologies)
S3 CT_QUALCOMM_U_drv; C:\Windows\System32\DRIVERS\CT_QUALCOMM_U_drv.sys [118016 2009-04-27] (QUALCOMM Incorporated)
S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1x64.sys [28008 2012-12-13] (Windows (R) Win 7 DDK provider)
R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [30752 2014-03-19] (EldoS Corporation)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-04-25] (GFI Software)
S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [12800 2009-12-16] (ZTE Incorporated)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R1 RawDisk3; C:\Windows\system32\drivers\rawdsk3.sys [32912 2014-08-12] (EldoS Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [290520 2014-02-22] (Realtek Semiconductor Corp.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2013-12-24] (IObit)
S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver.sys [21264 2012-02-24] (Synaptics Incorporated)
S3 zgchsdiag; C:\Windows\System32\DRIVERS\zgchsdiag.sys [150656 2009-12-16] (ZTE Incorporated)
S3 zgchsmdm; C:\Windows\System32\DRIVERS\zgchsmdm.sys [150656 2009-12-16] (ZTE Incorporated)
S3 ztemtusbser; C:\Windows\System32\DRIVERS\CT_ZTEMT_U_USBSER.sys [120704 2011-01-14] (ZTEMT Incorporated)
S1 CSN5PDTS82; System32\Drivers\CSN5PDTS82.sys [X]
S1 CSN5PDTS82x64; System32\Drivers\CSN5PDTS82x64.sys [X]
S3 SBUpdd; \??\C:\Program Files\Common Files\SpeedBit\SBUpdate\sbw.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-15 11:22 - 2015-01-15 11:22 - 00000000 ____D () C:\Users\A Munawa\Desktop\tool
2015-01-15 11:21 - 2015-01-15 11:23 - 00000000 ____D () C:\FRST
2015-01-15 10:16 - 2014-03-12 15:17 - 00002009 _____ () C:\Windows\system32\Drivers\etc\hosts.20150115-101605.backup
2015-01-14 21:47 - 2015-01-14 21:47 - 00001066 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2015-01-14 21:47 - 2015-01-14 21:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-01-14 16:17 - 2015-01-14 17:43 - 00002720 _____ () C:\Users\A Munawa\Desktop\unhide.txt
2015-01-14 16:07 - 2015-01-14 16:25 - 00004338 _____ () C:\Users\A Munawa\Desktop\Rkill.txt
2015-01-14 16:03 - 2014-08-29 04:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-01-14 16:03 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-01-14 15:18 - 2014-08-30 04:10 - 06583296 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-01-14 15:18 - 2014-08-30 03:50 - 05702656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-01-14 13:37 - 2015-01-14 13:37 - 00000134 _____ () C:\Users\A Munawa\Desktop\Microsoft Fix it.url
2015-01-14 13:28 - 2014-12-12 07:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 13:28 - 2014-12-12 07:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 13:28 - 2014-12-12 07:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 13:28 - 2014-12-12 07:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 13:28 - 2014-12-12 07:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 13:28 - 2014-12-12 07:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 13:28 - 2014-12-12 07:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 12:57 - 2014-12-19 05:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 12:56 - 2014-12-19 03:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 12:56 - 2014-12-06 06:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 12:56 - 2014-12-06 05:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 12:56 - 2014-12-06 05:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 12:44 - 2014-12-11 19:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 12:25 - 2015-01-14 20:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-01-14 12:25 - 2015-01-14 12:25 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-01-14 12:25 - 2015-01-14 12:25 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2015-01-14 12:24 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2015-01-14 09:49 - 2015-01-14 09:49 - 16307195 _____ () C:\Users\A Munawa\Downloads\Fren Dem - 2015 (GS Music Ent)(Reggaeworldcrew.net)By Paul Rwc.rar
2015-01-14 09:18 - 2015-01-14 20:38 - 00000000 ____D () C:\Program Files (x86)\GoForFilesUpdater
2015-01-14 09:18 - 2015-01-14 09:18 - 00003106 _____ () C:\Windows\System32\Tasks\Update Service GoForFiles
2015-01-14 09:11 - 2015-01-14 09:12 - 00000000 ____D () C:\Program Files (x86)\unIsalles
2015-01-14 09:08 - 2015-01-14 20:36 - 00000000 ____D () C:\ProgramData\17493798923026759263
2015-01-14 09:08 - 2015-01-14 09:12 - 00000000 ____D () C:\Program Files (x86)\unisalese
2015-01-14 09:07 - 2015-01-14 20:36 - 00000000 ____D () C:\ProgramData\oolloccpejoincfipilpinahmlipahfk
2015-01-14 09:04 - 2015-01-14 09:12 - 00000000 ____D () C:\ProgramData\{c7182a66-d6e4-e88e-c718-82a66d6ea99b}
2015-01-13 15:55 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-01-13 15:55 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-01-13 15:55 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-01-13 15:55 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-01-13 15:55 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-01-13 15:55 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-01-13 15:55 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-01-13 15:55 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-01-13 15:55 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2015-01-13 15:55 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2015-01-13 15:55 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-01-13 15:55 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-01-13 15:55 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-01-13 15:55 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-01-13 15:55 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2015-01-13 15:54 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-01-13 15:54 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2015-01-13 15:54 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2015-01-13 15:54 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2015-01-13 15:54 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2015-01-13 09:16 - 2015-01-13 22:27 - 00000000 ____D () C:\Users\A Munawa\Desktop\01 JANUARY 2015
2015-01-12 19:29 - 2015-01-12 19:31 - 00000000 ____D () C:\Users\A Munawa\Documents\CAR KEY CUTTING AND PROGRAMMING
2015-01-10 14:49 - 2015-01-10 13:09 - 03926674 _____ () C:\Users\A Munawa\Downloads\SHoRTY - Baby Toy - January 2015 - Kan Kan Riddim.mp4
2015-01-10 14:49 - 2014-12-28 18:11 - 48872549 _____ () C:\Users\A Munawa\Downloads\PapaRazzi Riddim Mix {PROMO} JAN 2015 (Heavy Beat Records) mix by djeasy.mp4
2015-01-10 14:47 - 2015-01-01 10:12 - 36348197 _____ () C:\Users\A Munawa\Downloads\Rhaatid Riddim Mix (Januray 2015) Djtzinas - Cast A Blast Records.mp4
2015-01-10 14:44 - 2015-01-04 10:22 - 06307408 _____ () C:\Users\A Munawa\Downloads\Jahvillani - Nah Let You Go [Non Stop Riddim] January 2015.mp4
2015-01-10 14:44 - 2014-12-07 19:57 - 43635993 _____ () C:\Users\A Munawa\Downloads\HIGH LIFE RIDDIM MIX BY DJ-BLAKE.mp4
2015-01-10 14:41 - 2015-01-05 10:59 - 03779891 _____ () C:\Users\A Munawa\Downloads\Reggae, Capleton, I Rise, Celestial Riddim, January, 2015.mp4
2015-01-10 14:40 - 2015-01-08 14:16 - 08495252 _____ () C:\Users\A Munawa\Downloads\I-Octane - Neva Sell Out ●Brit Jam Flesh Riddim● Dancehall 2015.mp4
2015-01-10 14:40 - 2015-01-06 18:31 - 08586935 _____ () C:\Users\A Munawa\Downloads\Justus - Life After Death - Tribute Riddim - January 2015 - JA Productions.mp4
2015-01-10 14:31 - 2015-01-08 21:55 - 12438304 _____ () C:\Users\A Munawa\Downloads\KARAMANTI - BIG WOMAN TING - OMV - @BLAKKWUMAN22 - DANCEHALL - 2015 - @21STHAPILOS.mp4
2015-01-10 14:29 - 2015-01-04 09:35 - 05983728 _____ () C:\Users\A Munawa\Downloads\Assassin aka Agent Sasco - Different Thing [WOW!! Riddim] Biggy Music - Dancehall January 2015.mp4
2015-01-10 14:28 - 2015-01-02 08:22 - 15220743 _____ () C:\Users\A Munawa\Downloads\LEFTSIDE GANJA OFFICIAL VIDEO - YouTube.mp4
2015-01-10 14:28 - 2014-12-30 00:44 - 05572095 _____ () C:\Users\A Munawa\Downloads\King Blasta - To Be Free - IPhone U Sport Riddim (2015) @dancehallhot.mp4
2015-01-10 14:26 - 2015-01-01 16:50 - 03799709 _____ () C:\Users\A Munawa\Downloads\Jayharno - How Yuh Suh Pretty - IPhone U Sport Riddim (2015) @dancehallhot.mp4
2015-01-10 14:25 - 2014-12-30 00:40 - 04802078 _____ () C:\Users\A Munawa\Downloads\Spugy B and Kello - Tell A Dutty Gyal - IPhone U Sport Riddim (2015) @dancehallhot.mp4
2015-01-10 14:25 - 2014-12-30 00:36 - 05148413 _____ () C:\Users\A Munawa\Downloads\Khemistry - Beauty - IPhone U Sport Riddim (2015) @dancehallhot.mp4
2015-01-10 14:24 - 2014-12-30 00:01 - 04861330 _____ () C:\Users\A Munawa\Downloads\Alozade - Love U So - IPhone U Sport Riddim (2015) @dancehallhot.mp4
2015-01-10 14:20 - 2015-01-02 07:33 - 47466105 _____ () C:\Users\A Munawa\Downloads\iPhone U Sport Riddim - Dancehall January 2015 - Riddimmix by Mangotree Sound.mp4
2015-01-10 14:20 - 2015-01-01 07:03 - 05254905 _____ () C:\Users\A Munawa\Downloads\Agent Sasco - Get Mad [Robin Hype Remix] - IPhone U Sport Riddim (2015) @dancehallhot.mp4
2015-01-10 14:20 - 2014-12-30 00:32 - 05745651 _____ () C:\Users\A Munawa\Downloads\Kalambo - Look Inna Mi Eye - IPhone U Sport Riddim (2015) @dancehallhot.mp4
2015-01-10 14:20 - 2014-12-30 00:13 - 04097955 _____ () C:\Users\A Munawa\Downloads\Kirk Diamond - Man A Don - IPhone U Sport Riddim (2015) @dancehallhot.mp4
2015-01-10 14:19 - 2015-01-11 18:38 - 00003609 _____ () C:\Users\A Munawa\Downloads\download_links_bytubed@cs213.cse.iitk.ac.in.html
2015-01-09 17:30 - 2015-01-15 09:45 - 00001008 _____ () C:\Windows\setupact.log
2015-01-09 17:30 - 2015-01-14 11:41 - 00006356 _____ () C:\Windows\PFRO.log
2015-01-09 17:30 - 2015-01-09 17:30 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-07 14:38 - 2015-01-12 08:55 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Foxit Software
2014-12-24 15:36 - 2014-12-13 07:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-24 15:36 - 2014-12-13 05:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-21 16:58 - 2014-12-21 16:58 - 00000811 _____ () C:\Users\A Munawa\AppData\Roaming\imagetuner.ini
2014-12-21 16:57 - 2014-12-21 16:57 - 00000000 ____D () C:\My Photos
2014-12-21 16:54 - 2014-12-21 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glorylogic
2014-12-21 16:54 - 2014-12-21 16:54 - 00000000 ____D () C:\Program Files (x86)\Glorylogic
2014-12-19 15:45 - 2015-01-14 09:29 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
2014-12-19 15:44 - 2015-01-14 20:35 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\TornTV.com
2014-12-18 19:37 - 2014-12-18 19:37 - 00000000 ____D () C:\Users\A Munawa\Desktop\JIGGA
2014-12-18 17:56 - 2014-12-18 17:59 - 00000000 ____D () C:\Users\A Munawa\Desktop\Mozambique
2014-12-17 17:31 - 2014-12-17 18:09 - 365677524 _____ () C:\Users\A Munawa\Downloads\Hotel.Impossible.S05E06.Masters.Of.My.Domain.HDTV.x264.mp4
2014-12-17 17:02 - 2015-01-15 11:22 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\uTorrent
2014-12-17 12:25 - 2015-01-14 09:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-12-17 12:19 - 2015-01-14 20:37 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-12-17 12:19 - 2015-01-14 20:36 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-12-17 12:19 - 2015-01-14 20:36 - 00000000 ____D () C:\Program Files\iTunes
2014-12-17 12:19 - 2014-12-17 12:19 - 00000000 ____D () C:\Program Files\iPod
2014-12-17 12:08 - 2014-12-17 13:16 - 669303845 _____ () C:\Users\A Munawa\Downloads\IntotheStorm2014.mkv
2014-12-17 11:59 - 2014-12-13 15:23 - 123248147 _____ () C:\Users\A Munawa\Downloads\Hotel Impossible Season 5 Episode 8 - Packing Heat - FULL EPISODE.mp4
2014-12-17 11:59 - 2014-02-14 13:35 - 172815933 _____ () C:\Users\A Munawa\Downloads\Restaurant Impossible Season 5 Episode 4 - Full Complete Episode - Unedited - Unrated version!.mp4
2014-12-17 11:59 - 2014-02-09 07:02 - 148300022 _____ () C:\Users\A Munawa\Downloads\Restaurant Impossible Season 5 Episode 3.mp4
2014-12-17 11:36 - 2014-12-17 11:36 - 00014480 _____ () C:\Users\A Munawa\Downloads\[kickass.so]hotel.impossible.s05e06.masters.of.my.domain.hdtv.x264.t1.torrent
2014-12-17 11:33 - 2014-12-17 11:45 - 626342849 _____ () C:\Users\A Munawa\Downloads\thelookalike.mkv

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-15 11:17 - 2013-05-03 08:51 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-15 11:17 - 2013-05-03 08:51 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-15 11:17 - 2013-05-03 08:51 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-15 11:17 - 2013-05-03 08:51 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-15 10:55 - 2013-04-24 15:46 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-15 10:52 - 2014-02-21 08:16 - 01529170 _____ () C:\Windows\WindowsUpdate.log
2015-01-15 09:55 - 2009-07-14 06:45 - 00022624 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-15 09:55 - 2009-07-14 06:45 - 00022624 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-15 09:51 - 2013-09-05 17:56 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-15 09:47 - 2014-06-23 20:50 - 00000438 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-01-15 09:47 - 2013-09-10 12:50 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\BITS
2015-01-15 09:47 - 2013-08-03 10:17 - 00000000 ____D () C:\ProgramData\PDFC
2015-01-15 09:46 - 2013-06-16 11:39 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-01-15 09:46 - 2013-04-24 15:46 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-15 09:45 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-14 23:07 - 2013-04-05 16:07 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\DMCache
2015-01-14 23:07 - 2013-03-09 15:21 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\vlc
2015-01-14 21:41 - 2014-03-08 09:43 - 00003222 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForAMUNAWA-HP$
2015-01-14 21:41 - 2014-03-08 09:43 - 00000346 _____ () C:\Windows\Tasks\HPCeeScheduleForAMUNAWA-HP$.job
2015-01-14 20:42 - 2014-03-12 14:53 - 00000000 ____D () C:\Program Files (x86)\Adobe Media Player
2015-01-14 20:42 - 2014-02-22 10:15 - 00000000 ____D () C:\DrvInstall
2015-01-14 20:39 - 2014-06-21 21:51 - 00000000 ____D () C:\Program Files (x86)\BearShare Applications
2015-01-14 20:39 - 2014-06-11 15:10 - 00000000 ____D () C:\Program Files (x86)\Ares
2015-01-14 20:39 - 2014-03-12 14:46 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-14 20:39 - 2014-03-10 10:58 - 00000000 ____D () C:\Program Files (x86)\Business-in-a-Box
2015-01-14 20:39 - 2013-11-16 17:50 - 00000000 ____D () C:\Program Files (x86)\Breakaway
2015-01-14 20:39 - 2013-10-27 23:21 - 00000000 ____D () C:\Program Files (x86)\AviSynth 2.5
2015-01-14 20:39 - 2013-06-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2015-01-14 20:39 - 2013-06-13 23:30 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2015-01-14 20:39 - 2013-05-05 15:51 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP
2015-01-14 20:39 - 2013-03-14 19:10 - 00000000 ____D () C:\Program Files (x86)\BurnAware Free
2015-01-14 20:39 - 2012-06-10 01:39 - 00000000 ____D () C:\Program Files (x86)\AMD APP
2015-01-14 20:39 - 2012-06-10 01:35 - 00000000 ____D () C:\Program Files (x86)\Atheros
2015-01-14 20:38 - 2014-08-13 14:44 - 00000000 ____D () C:\Program Files (x86)\DriverToolkit
2015-01-14 20:38 - 2014-05-18 16:59 - 00000000 ____D () C:\Program Files (x86)\Graphic Equalizer Studio 2014
2015-01-14 20:38 - 2014-03-31 20:22 - 00000000 ____D () C:\Program Files (x86)\Free Windows Cleanup Tool
2015-01-14 20:38 - 2013-10-16 21:59 - 00000000 ____D () C:\Program Files (x86)\Fixed CDMA Dial-up Tool
2015-01-14 20:38 - 2013-08-14 12:54 - 00000000 ____D () C:\Program Files (x86)\Freemake
2015-01-14 20:38 - 2013-06-16 16:46 - 00000000 ____D () C:\Program Files (x86)\FilesFrog Update Checker
2015-01-14 20:38 - 2013-05-23 14:13 - 00000000 ____D () C:\Program Files (x86)\FlashGet
2015-01-14 20:38 - 2013-05-10 22:23 - 00000000 ____D () C:\Program Files (x86)\Full Video Converter Free 9
2015-01-14 20:38 - 2013-04-24 15:46 - 00000000 ____D () C:\Program Files (x86)\GUMD1B.tmp
2015-01-14 20:38 - 2013-04-24 15:46 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-14 20:38 - 2013-03-10 17:45 - 00000000 ____D () C:\Program Files (x86)\Disco XT Demo
2015-01-14 20:38 - 2012-04-03 07:34 - 00000000 ____D () C:\Program Files (x86)\HP Games
2015-01-14 20:38 - 2012-04-03 07:23 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2015-01-14 20:37 - 2014-12-11 15:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-14 20:37 - 2014-12-06 10:00 - 00000000 ____D () C:\Program Files\3G USB Modem
2015-01-14 20:37 - 2014-11-08 16:34 - 00000000 ____D () C:\Program Files\Common Files\Protexis
2015-01-14 20:37 - 2014-08-19 21:10 - 00000000 ____D () C:\Program Files (x86)\Red Eye Remover
2015-01-14 20:37 - 2014-08-15 11:10 - 00000000 ____D () C:\Program Files (x86)\Internet Download Manager
2015-01-14 20:37 - 2014-08-13 15:04 - 00000000 ____D () C:\Program Files (x86)\mHotspot
2015-01-14 20:37 - 2014-07-12 22:34 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-14 20:37 - 2014-06-18 19:03 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-14 20:37 - 2014-06-11 15:13 - 00000000 ____D () C:\Program Files (x86)\VNT
2015-01-14 20:37 - 2014-06-06 23:38 - 00000000 ____D () C:\Program Files (x86)\SoulseekQt
2015-01-14 20:37 - 2014-05-18 16:52 - 00000000 ____D () C:\Program Files (x86)\VirtualDJ
2015-01-14 20:37 - 2014-04-01 17:23 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-01-14 20:37 - 2014-03-12 14:48 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-01-14 20:37 - 2014-02-13 00:35 - 00000000 ____D () C:\Program Files (x86)\Turbo Internet
2015-01-14 20:37 - 2014-01-24 00:04 - 00000000 ____D () C:\Program Files (x86)\IDA
2015-01-14 20:37 - 2013-11-21 16:10 - 00000000 ____D () C:\Program Files (x86)\Kozaka
2015-01-14 20:37 - 2013-10-27 23:21 - 00000000 ____D () C:\Program Files (x86)\K-Lite Codec Pack
2015-01-14 20:37 - 2013-10-08 17:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-14 20:37 - 2013-09-19 18:56 - 00000000 ____D () C:\Program Files (x86)\JetAudio
2015-01-14 20:37 - 2013-07-25 09:59 - 00000000 ____D () C:\Program Files (x86)\Zoom Player
2015-01-14 20:37 - 2013-06-24 23:33 - 00000000 ____D () C:\Program Files (x86)\PC Connectivity Solution
2015-01-14 20:37 - 2013-06-13 23:31 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-01-14 20:37 - 2013-06-13 23:30 - 00000000 ____D () C:\Program Files\Bonjour
2015-01-14 20:37 - 2013-05-23 22:33 - 00000000 ____D () C:\Program Files (x86)\WinPcap
2015-01-14 20:37 - 2013-05-22 20:54 - 00000000 ____D () C:\Program Files (x86)\Nokia
2015-01-14 20:37 - 2013-04-25 23:21 - 00000000 ____D () C:\Program Files (x86)\IObit
2015-01-14 20:37 - 2013-04-25 22:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-01-14 20:37 - 2013-04-03 19:33 - 00000000 ____D () C:\Program Files\CDMA-1XDO
2015-01-14 20:37 - 2013-03-11 19:32 - 00000000 ____D () C:\Program Files (x86)\iWisoft Free Video Converter
2015-01-14 20:37 - 2013-01-23 22:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2015-01-14 20:37 - 2013-01-23 22:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft ActiveSync
2015-01-14 20:37 - 2013-01-23 22:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio
2015-01-14 20:37 - 2013-01-23 22:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2015-01-14 20:37 - 2013-01-11 08:16 - 00000000 ____D () C:\Program Files\Africom UI
2015-01-14 20:37 - 2012-06-10 01:58 - 00000000 ____D () C:\Program Files (x86)\SymSilent
2015-01-14 20:37 - 2012-06-10 01:39 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2015-01-14 20:37 - 2012-06-10 01:38 - 00000000 ____D () C:\Program Files\ATI Technologies
2015-01-14 20:37 - 2012-06-10 01:34 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-01-14 20:37 - 2012-04-03 07:48 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-01-14 20:37 - 2012-04-03 07:45 - 00000000 ____D () C:\Program Files (x86)\PDF Complete
2015-01-14 20:37 - 2012-04-03 07:34 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
2015-01-14 20:37 - 2012-04-03 07:29 - 00000000 ___RD () C:\Program Files (x86)\Online Services
2015-01-14 20:37 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2015-01-14 20:37 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-01-14 20:36 - 2014-11-08 16:38 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-14 20:36 - 2014-10-31 17:53 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-01-14 20:36 - 2014-07-11 20:29 - 00000000 ____D () C:\Program Files\Shareaza
2015-01-14 20:36 - 2014-06-03 08:31 - 00000000 ____D () C:\savw_100_sa
2015-01-14 20:36 - 2014-05-27 17:57 - 00000000 ____D () C:\Program Files\PCDApp
2015-01-14 20:36 - 2014-05-23 18:39 - 00000000 ____D () C:\Program Files\WinRAR
2015-01-14 20:36 - 2014-05-17 11:48 - 00000000 ____D () C:\Program Files\DJ Mix Pro
2015-01-14 20:36 - 2014-04-01 17:23 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-01-14 20:36 - 2013-11-26 18:30 - 00000000 ____D () C:\ProgramData\ProductData
2015-01-14 20:36 - 2013-11-15 13:52 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2015-01-14 20:36 - 2013-10-03 21:10 - 00000000 ____D () C:\ProgramData\GetRight
2015-01-14 20:36 - 2013-09-16 14:06 - 00000000 ____D () C:\ProgramData\SpeedBit
2015-01-14 20:36 - 2013-06-13 23:34 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-01-14 20:36 - 2013-06-13 23:30 - 00000000 ____D () C:\ProgramData\Apple
2015-01-14 20:36 - 2013-05-22 20:56 - 00000000 ____D () C:\Program Files\DIFX
2015-01-14 20:36 - 2013-05-21 17:17 - 00000000 ____D () C:\ProgramData\InstallMate
2015-01-14 20:36 - 2013-04-25 23:21 - 00000000 ____D () C:\ProgramData\IObit
2015-01-14 20:36 - 2013-04-25 22:05 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-01-14 20:36 - 2013-04-25 09:26 - 00000000 ____D () C:\ProgramData\Nero
2015-01-14 20:36 - 2012-06-10 01:57 - 00000000 ____D () C:\ProgramData\CyberLink
2015-01-14 20:36 - 2012-06-10 01:52 - 00000000 ____D () C:\ProgramData\Norton
2015-01-14 20:36 - 2012-06-10 01:37 - 00000000 ____D () C:\Program Files\Synaptics
2015-01-14 20:36 - 2012-04-03 07:47 - 00000000 ____D () C:\Program Files\Windows Live
2015-01-14 20:36 - 2012-04-03 07:46 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2015-01-14 20:36 - 2012-04-03 07:45 - 00000000 ____D () C:\ProgramData\Skype
2015-01-14 20:36 - 2012-04-03 07:34 - 00000000 ____D () C:\ProgramData\WildTangent
2015-01-14 20:36 - 2012-02-24 03:22 - 00000000 ____D () C:\Program Files\Hewlett-Packard
2015-01-14 20:36 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-01-14 20:36 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Microsoft Games
2015-01-14 20:35 - 2014-11-22 15:42 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\WindSolutions
2015-01-14 20:35 - 2014-11-20 18:48 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\Backuptrans iPhone WhatsApp Transfer
2015-01-14 20:35 - 2014-10-01 00:26 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\RHEng
2015-01-14 20:35 - 2014-06-23 20:48 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\1BN_(www.1bn.in)
2015-01-14 20:35 - 2014-06-11 15:13 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\VNT
2015-01-14 20:35 - 2014-05-27 17:55 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\26148
2015-01-14 20:35 - 2014-05-27 16:27 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\FlashGetBHO
2015-01-14 20:35 - 2014-05-14 19:22 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\GetGo Software
2015-01-14 20:35 - 2014-05-14 18:35 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\systweak
2015-01-14 20:35 - 2014-03-21 15:11 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2015-01-14 20:35 - 2014-03-21 15:11 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\IDM
2015-01-14 20:35 - 2014-02-28 21:32 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Software Update
2015-01-14 20:35 - 2014-02-15 10:55 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Go!Zilla
2015-01-14 20:35 - 2014-01-24 00:04 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Internet Download Accelerator
2015-01-14 20:35 - 2013-11-21 16:10 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\SwvUpdater
2015-01-14 20:35 - 2013-11-07 12:10 - 00000000 ____D () C:\TDdownload
2015-01-14 20:35 - 2013-10-05 23:57 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\BitLord
2015-01-14 20:35 - 2013-10-05 19:16 - 00000000 ____D () C:\Users\A Munawa\.frostwire5
2015-01-14 20:35 - 2013-10-03 21:07 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\GetRight
2015-01-14 20:35 - 2013-09-10 12:50 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\FlashgetSetup
2015-01-14 20:35 - 2013-06-23 19:22 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\OpenCandy
2015-01-14 20:35 - 2013-05-28 19:13 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\Chris_Pietschmann_(http__
2015-01-14 20:35 - 2013-05-25 08:04 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\YouTubeBatchDownloader
2015-01-14 20:35 - 2013-05-25 08:04 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\utd
2015-01-14 20:35 - 2013-05-24 16:38 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\BabSolution
2015-01-14 20:35 - 2013-05-23 22:31 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Orbit
2015-01-14 20:35 - 2013-05-22 20:58 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Nokia
2015-01-14 20:35 - 2013-05-20 20:33 - 00000000 ____D () C:\Users\A Munawa\Documents\EA Games
2015-01-14 20:35 - 2013-04-25 23:21 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\IObit
2015-01-14 20:35 - 2013-04-04 10:58 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\PDF Software
2015-01-14 20:35 - 2013-03-17 15:53 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\dvdcss
2015-01-14 20:35 - 2013-03-16 21:31 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\WebApp
2015-01-14 20:35 - 2013-03-13 19:21 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\MediaMonkey
2015-01-14 20:35 - 2013-03-13 07:31 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\Torch
2015-01-14 20:35 - 2013-02-22 18:59 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\TeraCopy
2015-01-14 20:35 - 2013-01-03 14:15 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\PDFC
2015-01-14 20:35 - 2013-01-03 14:13 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Skype
2015-01-14 20:35 - 2013-01-03 14:10 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\Hewlett-Packard
2015-01-14 20:35 - 2013-01-03 14:00 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\RemEngine
2015-01-14 20:35 - 2013-01-03 14:00 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\Hewlett-Packard_Company
2015-01-14 20:35 - 2011-02-10 21:23 - 00000000 ____D () C:\SYSTEM.SAV
2015-01-14 20:35 - 2011-02-10 21:23 - 00000000 ____D () C:\SWSetup
2015-01-14 20:34 - 2014-11-15 16:52 - 00000000 ____D () C:\Users\A Munawa\Downloads\more programming
2015-01-14 20:34 - 2014-06-05 17:51 - 00000000 ___RD () C:\Users\A Munawa\Dropbox
2015-01-14 20:34 - 2013-11-13 12:37 - 00000000 ____D () C:\Users\Public\Documents\COMODO
2015-01-14 20:34 - 2013-05-29 13:06 - 00000000 ___RD () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-14 20:34 - 2013-05-29 13:06 - 00000000 ___RD () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-14 20:34 - 2013-03-16 21:30 - 00000000 ____D () C:\Users\Public\CyberLink
2015-01-14 20:34 - 2013-01-17 15:55 - 00000000 ____D () C:\Users\A Munawa\Documents\Youcam
2015-01-14 20:34 - 2013-01-03 13:58 - 00000000 ____D () C:\Users\A Munawa
2015-01-14 20:34 - 2012-04-03 07:50 - 00000000 ____D () C:\Windows\en
2015-01-14 20:34 - 2009-07-14 05:20 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-14 20:34 - 2009-07-14 05:20 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-14 20:34 - 2009-07-14 05:20 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-14 20:34 - 2009-07-14 05:20 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-14 20:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Cursors
2015-01-14 20:33 - 2012-06-10 01:40 - 00000000 ____D () C:\Windows\Hewlett-Packard
2015-01-14 20:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\IME
2015-01-14 20:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help
2015-01-14 20:32 - 2014-04-20 22:31 - 00000000 ____D () C:\Windows\SysWOW64\directx
2015-01-14 20:32 - 2013-09-21 23:00 - 00000000 ____D () C:\Windows\SysWOW64\Plugins
2015-01-14 20:32 - 2013-09-11 20:44 - 00000000 ____D () C:\Windows\pss
2015-01-14 20:32 - 2013-05-30 10:02 - 00000000 ____D () C:\YouTubeGet
2015-01-14 20:32 - 2013-02-10 09:21 - 00000000 ____D () C:\Windows\SysWOW64\%COREALLUSERPATH%
2015-01-14 20:32 - 2013-01-23 22:15 - 00000000 ____D () C:\Windows\SHELLNEW
2015-01-14 20:32 - 2012-06-10 01:35 - 00000000 ____D () C:\Windows\SysWOW64\sda
2015-01-14 20:32 - 2012-06-10 01:34 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2015-01-14 20:32 - 2012-04-03 07:45 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2015-01-14 20:32 - 2009-07-14 06:45 - 00000000 ____D () C:\Windows\Setup
2015-01-14 20:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\TAPI
2015-01-14 20:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Recovery
2015-01-14 20:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2015-01-14 20:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\security
2015-01-14 20:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2015-01-14 20:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-01-14 18:22 - 2013-07-25 03:03 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 17:53 - 2013-05-13 09:06 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-14 16:35 - 2013-01-03 14:14 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{C7D5B8CE-DAFD-41E5-8A9B-7065A533FAC9}
2015-01-14 14:15 - 2013-04-05 16:07 - 00000000 ____D () C:\Users\A Munawa\Downloads\Video
2015-01-14 12:09 - 2014-03-10 12:14 - 00000000 ____D () C:\Users\A Munawa\Documents\Business-in-a-Box Files
2015-01-14 10:21 - 2013-04-05 16:07 - 00000000 ____D () C:\Users\A Munawa\Downloads\Compressed
2015-01-14 09:29 - 2014-12-15 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-01-14 09:29 - 2014-12-06 10:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3G USB Modem
2015-01-14 09:29 - 2014-11-22 15:42 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Control Center
2015-01-14 09:29 - 2014-11-20 18:49 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Backuptrans iPhone WhatsApp Transfer
2015-01-14 09:29 - 2014-11-17 15:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2015-01-14 09:29 - 2014-11-08 17:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5
2015-01-14 09:29 - 2014-11-08 16:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)
2015-01-14 09:29 - 2014-10-31 17:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-01-14 09:29 - 2014-08-19 21:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Eye Remover
2015-01-14 09:29 - 2014-08-15 11:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2015-01-14 09:29 - 2014-08-13 15:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mHotspot
2015-01-14 09:29 - 2014-08-13 14:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverToolkit
2015-01-14 09:29 - 2014-08-13 10:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-01-14 09:29 - 2014-07-24 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MarySoft
2015-01-14 09:29 - 2014-07-12 22:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-01-14 09:29 - 2014-07-06 13:25 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2015-01-14 09:29 - 2014-06-14 21:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2015-01-14 09:29 - 2014-06-06 23:38 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SoulseekQt
2015-01-14 09:29 - 2014-05-28 15:34 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-01-14 09:29 - 2014-05-27 16:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlashGet3.7
2015-01-14 09:29 - 2014-05-23 18:39 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-01-14 09:29 - 2014-05-23 18:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-01-14 09:29 - 2014-05-18 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Graphic Equalizer Studio 2014
2015-01-14 09:29 - 2014-05-18 16:52 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
2015-01-14 09:29 - 2014-05-17 11:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DJ Mix Pro
2015-01-14 09:29 - 2014-04-26 16:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2015-01-14 09:29 - 2014-04-25 17:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-14 09:29 - 2014-03-12 14:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2015-01-14 09:29 - 2014-02-21 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 3
2015-01-14 09:29 - 2013-10-27 23:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2015-01-14 09:29 - 2013-10-27 23:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
2015-01-14 09:29 - 2013-10-16 21:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fixed CDMA Dial-up Tool
2015-01-14 09:29 - 2013-09-19 18:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COWON Media Center - jetAudio
2015-01-14 09:29 - 2013-07-25 10:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zoom Player
2015-01-14 09:29 - 2013-06-24 23:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia PC Suite
2015-01-14 09:29 - 2013-06-09 17:05 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-01-14 09:29 - 2013-05-23 22:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
2015-01-14 09:29 - 2013-05-10 22:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Full Video Converter Free 9
2015-01-14 09:29 - 2013-05-06 15:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\King James Version
2015-01-14 09:29 - 2013-04-25 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-01-14 09:29 - 2013-04-25 09:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 8
2015-01-14 09:29 - 2013-04-03 19:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDMA-1XDO
2015-01-14 09:29 - 2013-03-14 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BurnAware Free
2015-01-14 09:29 - 2013-03-11 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iWisoft Free Video Converter
2015-01-14 09:29 - 2013-01-23 22:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-01-14 09:29 - 2013-01-11 08:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Africom
2015-01-14 09:29 - 2013-01-03 13:58 - 00000000 ___RD () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-14 09:29 - 2013-01-03 13:58 - 00000000 ___RD () C:\Users\A Munawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-14 09:29 - 2012-04-03 07:49 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2015-01-14 09:29 - 2012-04-03 07:46 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat
2015-01-14 09:29 - 2012-04-03 07:45 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eReaders and Document Viewers
2015-01-14 09:29 - 2012-04-03 07:29 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2015-01-14 09:29 - 2012-04-03 07:28 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2015-01-14 09:29 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-14 09:29 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-14 09:29 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-14 08:57 - 2014-06-04 18:28 - 00000000 ____D () C:\$AVG
2015-01-14 08:30 - 2014-05-28 15:22 - 00000000 ____D () C:\Users\A Munawa\AppData\Roaming\Dropbox
2015-01-13 22:25 - 2014-10-07 13:59 - 00000000 ____D () C:\Users\A Munawa\Desktop\hip hop
2015-01-13 22:20 - 2014-09-14 14:43 - 00000000 ____D () C:\Users\A Munawa\Desktop\Compressed done
2015-01-13 21:55 - 2013-04-24 08:51 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2015-01-13 21:54 - 2013-06-19 10:35 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2015-01-13 20:13 - 2014-01-30 09:59 - 00000258 __RSH () C:\ProgramData\ntuser.pol
2015-01-13 16:10 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2015-01-13 15:34 - 2009-07-14 07:13 - 00864880 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-12 19:43 - 2014-05-19 14:08 - 00000000 ____D () C:\Users\A Munawa\Desktop\l
2015-01-12 19:33 - 2014-11-13 11:10 - 00000000 ____D () C:\Users\A Munawa\Desktop\zimdancehall
2015-01-09 17:10 - 2013-03-17 14:22 - 00000000 ____D () C:\Users\A Munawa\AppData\Local\CrashDumps
2015-01-03 10:29 - 2013-12-05 23:01 - 00000000 ____D () C:\Users\A Munawa\Documents\DOCUMENTS MUM
2014-12-21 21:22 - 2014-10-19 18:42 - 00000000 ____D () C:\Users\A Munawa\Downloads\AUTOMOTIVE CAR KEY CUTTINGF AND CODING
2014-12-19 20:02 - 2013-04-24 15:37 - 00000085 _____ () C:\Windows\wininit.ini
2014-12-18 19:47 - 2014-12-15 19:38 - 00000000 ____D () C:\Users\A Munawa\Desktop\internet cafe
2014-12-18 13:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-12-17 13:02 - 2013-10-05 18:33 - 00000000 ____D () C:\Users\A Munawa\Documents\BitLord
2014-12-17 12:15 - 2014-08-29 11:10 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-12-17 12:06 - 2014-12-11 15:49 - 00001520 _____ () C:\Users\A Munawa\Downloads\watch_links_bytubed@cs213.cse.iitk.ac.in.html

Some content of TEMP:
====================
C:\Users\A Munawa\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpnrmwii.dll
C:\Users\A Munawa\AppData\Local\Temp\Foxit Updater.exe
C:\Users\A Munawa\AppData\Local\Temp\ShellHook.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-18 12:43

==================== End Of Log ============================

ADDITIONAL
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-01-2015
Ran by A Munawa at 2015-01-15 11:27:08
Running from C:\Users\A Munawa\Desktop\tool
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\uTorrent) (Version: 3.4.2.37252 - BitTorrent Inc.)
3G USB Modem (HKLM\...\3G USB Modem_is1) (Version: - )
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9120 - Adobe Systems Inc.)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Creative Suite 5 Master Collection (HKLM-x32\...\{288DB08D-0708-4A94-B055-55B99E39EB62}) (Version: 5.0 - Adobe Systems Incorporated)
Adobe Flash Player 10 Plugin (HKLM-x32\...\{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}) (Version: 10.1.52.14 - Adobe Systems, Inc.)
Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.257 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe OnLocation CS5 Royalty Content (HKLM-x32\...\{7816FDDE-40D4-482D-AD7D-97858985DB3E}) (Version: 5.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.3.633 - Adobe Systems, Inc.)
Advanced Archive Password Recovery (HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\Advanced Archive Password Recovery) (Version: 4.53 - ElcomSoft Co. Ltd.)
Africom UI (HKLM\...\ZTEWireless-101_is1) (Version: - )
AMD Catalyst Install Manager (HKLM\...\{F56D7C41-9105-8F4B-C791-06BA190CA281}) (Version: 3.0.868.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ask Toolbar (HKLM-x32\...\{41524553-2D56-3700-76A7-A758B70C0F00}) (Version: 12.15.0.166 - APN, LLC) <==== ATTENTION
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5645 - AVG Technologies)
AVG 2015 (Version: 15.0.4260 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.5645 - AVG Technologies) Hidden
AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version: - )
Backuptrans iPhone WhatsApp Transfer 3.2.06 (HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\Backuptrans iPhone WhatsApp Transfer) (Version: 3.2.06 - Backuptrans)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BurnAware Free 7.3 (HKLM-x32\...\BurnAware Free_is1) (Version: - Burnaware)
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.1.3341 - CDBurnerXP)
CDMA-1XDO (HKLM\...\CDMA-1XDO_is1) (Version: - )
CGS17_Setup_x64 (Version: 17.0 - Corel Corporation) Hidden
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
COMODO GeekBuddy (HKLM-x32\...\COMODO GeekBuddy) (Version: 3.3.217083.59 - COMODO)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CopyTrans Control Center Uninstall Only (HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Corel Graphics - Windows Shell Extension (HKLM\...\_{4AB916EE-ABA8-4079-9889-745798B6D809}) (Version: 17.0.0.491 - Corel Corporation)
Corel Graphics - Windows Shell Extension (Version: 17.0.491 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 32 Bit (Version: 17.0.491 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Capture (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Common (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Connect (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Custom Data (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Draw (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - EN (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Filters (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - FontNav (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - IPM Content (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - IPM T (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - PHOTO-PAINT (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Photozoom Plugin (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Redist (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Setup Files (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - VBA (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - VideoBrowser (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 - Writing Tools (x64) (Version: 17.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X7 (64-Bit) (HKLM\...\_{5CB73140-806C-42C6-A05A-1AFD0E92DEB5}) (Version: 17.0.0.491 - Corel Corporation)
COWON Media Center - jetAudio Basic VX (HKLM-x32\...\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}) (Version: 8.0.17 - COWON)
CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5.3817 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.3.5010 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DriverToolkit version 8.3.5.0 (HKLM-x32\...\{D66BF89F-B0A2-48F5-A2E4-242EB645AB76}_is1) (Version: 8.3.5.0 - Megaify Software)
Dropbox (HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
ESU for Microsoft Windows 7 SP1 (HKLM-x32\...\{4F34A145-8CF3-400C-B5DB-2B1BF604304D}) (Version: 5.1.4 - Hewlett-Packard)
Evernote v. 4.5.2 (HKLM-x32\...\{8CE152BA-1D16-11E1-867D-984BE15F174E}) (Version: 4.5.2.5904 - Evernote Corp.)
FilesFrog Update Checker (HKLM-x32\...\FilesFrog Update Checker) (Version: - ) <==== ATTENTION
Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden
Fixed CDMA Dial-up Tool (HKLM-x32\...\{88D613F4-D4AE-48F1-BF73-66A1886FB214}) (Version: 1.01.1111 - zte)
FlashGet3.7 (HKLM-x32\...\FlashGet3.7) (Version: 3.7.0.1203 - http://www.FlashGet.com)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 5.4.3.920 - Foxit Corporation)
Free Red-eye Reduction Tool for Windows version 1.0 (HKLM-x32\...\{76D8B343-1631-49DF-9F99-1119C917657B}_is1) (Version: 1.0 - LifeSniffer, Inc.)
Freemake Video Converter version 4.1.4 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.4 - Ellora Assets Corporation)
Full Video Converter Free 9 (HKLM-x32\...\{D7A1BF13-4DA3-4391-855D-D61ADADF74A6}_is1) (Version: - Full Video Studio)
GOM Audio (HKLM-x32\...\GomAudio) (Version: 2.0.7.1108 - Gretech Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
Hoyle Card Games (x32 Version: 2.2.0.95 - WildTangent) Hidden
HP Documentation (HKLM-x32\...\{DB183033-C2DD-4A37-B43C-943DD4B28C77}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent)
HP Launch Box (HKLM\...\{5A847522-375C-4D05-BD3D-88C450CC047F}) (Version: 1.1.5 - Hewlett-Packard Company)
HP On Screen Display (HKLM-x32\...\{ED1BD69A-07E3-418C-91F1-D856582581BF}) (Version: 1.3.5 - Hewlett-Packard Company)
HP Power Manager (HKLM-x32\...\{7E799992-5DA0-4A1A-9443-B1836B063FEC}) (Version: 1.4.8 - Hewlett-Packard Company)
HP Quick Launch (HKLM-x32\...\{53B17A98-5BF0-40BC-AAFF-850A357975AC}) (Version: 2.7.2 - Hewlett-Packard Company)
HP Security Assistant (HKLM\...\{D3AA8FD3-5FFA-4CFC-BA8E-99BFC6A41943}) (Version: 3.0.2 - Hewlett-Packard Company)
HP Setup (HKLM-x32\...\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15430.4033 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\...\{675D093B-815D-47FD-AB2C-192EC751E8E2}) (Version: 4.6.10.1 - Hewlett-Packard Company)
Image Tuner 4.9 (HKLM-x32\...\Image Tuner_is1) (Version: - Glorylogic)
Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version: - Tonec Inc.)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
iWisoft Free Video Converter 1.2 (HKLM-x32\...\iWisoft Free Video Converter_is1) (Version: 1.2 - www.easy-video-converter.com)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
King James Version (HKLM-x32\...\{D80F734E-8AF8-470E-9C58-48F01581FCF4}) (Version: 1.0.1 - Free PC Bible)
K-Lite Codec Pack 9.2.0 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.2.0 - )
Maryfi - English (HKLM-x32\...\{70DC8913-5212-4936-AC8C-B366F55045CF}) (Version: 1.1.0 - MarySoft)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
mHotspot version 7.6.0.0 (HKLM-x32\...\{beeb7906-9268-4520-8850-8d8af9b1c7c8}_is1) (Version: 7.6.0.0 - 1BN Software Pvt. Ltd.)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2003 Web Components (HKLM-x32\...\{90A40409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office XP Web Components (HKLM-x32\...\{90260409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Research Mesh Virtual WIFI (HKLM-x32\...\{3F586E56-913B-4C6D-889B-F591485E069D}) (Version: 1.0.0 - Microsoft Corp)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2012 (HKLM-x32\...\{89ca2a32-2b52-4595-8dfd-6fe4757958d0}) (Version: 11.0.51108 - Microsoft Corporation)
MixPad Multitrack Recording Software (HKLM-x32\...\MixPad) (Version: 3.60 - NCH Software)
Mozilla Firefox 34.0.5 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 en-US)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSVC80_x64 (Version: 1.0.1.0 - Nokia) Hidden
MSVC80_x86 (x32 Version: 1.0.1.0 - Nokia) Hidden
MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 8 (HKLM-x32\...\{B944FA21-81AF-4A77-8328-CE4F4CC51033}) (Version: 8.10.21 - Nero AG)
Nokia Connectivity Cable Driver (HKLM-x32\...\{A57025CC-5F2E-4D01-B387-06DB10500D43}) (Version: 7.1.78.0 - Nokia)
Nokia PC Suite (HKLM-x32\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia)
Nokia PC Suite (x32 Version: 7.1.180.94 - Nokia) Hidden
Nokia Software Updater (HKLM-x32\...\{D043E0F8-5EFA-4102-A863-08F39D9DF2F4}) (Version: 02.04.005.41445 - Nokia Corporation)
Notificatoin (HKLM-x32\...\{A88DE8D3-9C38-4F0D-8981-A4C17F7677A1}) (Version: 1.0.0 - KangoExtensions) <==== ATTENTION
opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (Version: 11.0.51108 - Microsoft Corporation) Hidden
Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - PTB (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden
PC Connectivity Solution (HKLM-x32\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)
PC Data App (HKLM-x32\...\PCData App) (Version: - ) <==== ATTENTION
PDF Complete Corporate Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.87 - PDF Complete, Inc)
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
Pixillion Image Converter (HKLM-x32\...\Pixillion) (Version: 2.73 - NCH Software)
PxMergeModule (x32 Version: 1.00.0000 - Your Company Name) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.51.116.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6577 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.29005 - Realtek Semiconductor Corp.)
Red Eye Remover 2.0 (HKLM-x32\...\Red Eye Remover_is1) (Version: - )
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Smart Defrag 3 (HKLM-x32\...\Smart Defrag 3_is1) (Version: 3.1 - IObit)
SoulseekQt (HKLM-x32\...\SoulseekQt) (Version: - )
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1158 - SUPERAntiSpyware.com)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.0.1.0 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.29947 - TeamViewer)
TornTV (HKLM-x32\...\1ClickDownload) (Version: 2.1 Build 26473 - TornTV.com) <==== ATTENTION
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Update Service GoForFiles (HKU\S-1-5-21-534593773-3893946233-160603186-1001\...\Update Service GoForFiles) (Version: 3.15.03 - http://www.usedfile.biz) <==== ATTENTION
VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
VirtualDJ Home FREE (HKLM-x32\...\{77C2D5D4-ADC5-49F9-B36E-5992FCF35EA3}) (Version: 7.4.1 - Atomix Productions)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.6 (HKLM-x32\...\VLC media player) (Version: 2.0.6 - VideoLAN)
webssearches uninstall (HKLM-x32\...\webssearches uninstall) (Version: - webssearches) <==== ATTENTION
WildTangent Games App (HP Games) (x32 Version: 4.0.5.36 - WildTangent) Hidden
Windows Driver Package - Nokia Modem (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia)
Windows Driver Package - Nokia Modem (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia)
Windows Driver Package - Nokia Modem (05/22/2008 3.8) (HKLM\...\C5A76DC11BABDA0A881E7BE8DDEB641365A77FFD) (Version: 05/22/2008 3.8 - Nokia)
Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1) (HKLM\...\9CD348AE9C64C4B939B624E8E24F3903EFDFC82B) (Version: 05/22/2008 7.00.0.1 - Nokia)
Windows Driver Package - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Zoom Player (remove only) (HKLM-x32\...\ZoomPlayer) (Version: - )
Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (Version: 11.0.51108 - Microsoft Corporation) Hidden
Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x86) - RUS (x32 Version: 11.0.51108 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-534593773-3893946233-160603186-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\A Munawa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-534593773-3893946233-160603186-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\A Munawa\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-534593773-3893946233-160603186-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\A Munawa\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-534593773-3893946233-160603186-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\A Munawa\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-534593773-3893946233-160603186-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\A Munawa\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-534593773-3893946233-160603186-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\A Munawa\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-534593773-3893946233-160603186-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\A Munawa\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-534593773-3893946233-160603186-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\A Munawa\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-534593773-3893946233-160603186-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\A Munawa\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points =========================

14-01-2015 11:47:30 kenny
14-01-2015 17:48:55 Windows Update
14-01-2015 19:14:51 Restore Operation

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2015-01-15 10:16 - 00451914 ____R C:\Windows\system32\Drivers\etc\hosts
0.0.0.0 localhost
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
0.0.0.0 localhost
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {02A6531F-8779-4709-BDA4-B3C31029372F} - System32\Tasks\{C2F66875-45C3-4D31-ADC9-CE86F43174EC} => pcalua.exe -a "C:\Users\A Munawa\Desktop\software\Jet AUDio7_BASIC.exe" -d "C:\Users\A Munawa\Desktop\software"
Task: {069C0C45-5FE9-4CC9-AC2C-E3B463853686} - System32\Tasks\{0A38D334-733D-44E9-82BE-E94F1ECD8D75} => pcalua.exe -a "C:\Users\A Munawa\Downloads\Programs\RemoveRedEye_2.exe" -d "C:\Users\A Munawa\Downloads\Programs"
Task: {0810C699-629E-4A76-8709-2481D75A0FC7} - System32\Tasks\HPCeeScheduleForAMUNAWA-HP$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {1A4009BE-D51F-4C08-9F9B-F28E97717323} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {3B8BC06A-BEA9-4210-8C56-77424572A8D7} - System32\Tasks\Driver Booster SkipUAC (A Munawa) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {3EA93ABE-C630-47A5-8ABE-2BDFDA5E00F0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-24] (Google Inc.)
Task: {498474B2-3A6C-4939-B677-FE7B5BD90B04} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {52D53408-A39B-4FBC-9AAE-929FB6F0D4A1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {5A068A3A-252E-4B83-B136-F4CDC6386791} - System32\Tasks\{04CF2713-FBD2-4D35-8323-DF1BA1C04A76} => C:\Program Files (x86)\FlareGet\flareget.exe
Task: {6436FB44-4412-4969-AA21-C820634D12E4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-24] (Google Inc.)
Task: {74E941AD-9997-4E94-AFCB-7A432CFE672A} - System32\Tasks\{1A2C0517-92E2-4075-BF42-C20B67005100} => pcalua.exe -a F:\CoolPDFReaderInstall.exe -d F:\
Task: {7AAAD4AA-852D-4CB4-8FD8-39CACF81E505} - System32\Tasks\Express FilesUpdate => C:\Program Files (x86)\ExpressFiles\EFUpdater.exe <==== ATTENTION
Task: {81EEEE5E-9B0C-4D95-A09B-AEC69279F064} - System32\Tasks\{721F21E0-8DE5-428F-B4F1-25A4D211D59A} => pcalua.exe -a "C:\Users\A Munawa\AppData\Local\Temp\Rar$EXa0.152\NFS prostreet disc 1working\Support\Need for Speed ProStreet_code.exe"
Task: {9681B3F1-1B58-4ABD-BB8F-F57150C89AE1} - System32\Tasks\{92D966EC-8239-411C-910E-53F04289B5BF} => C:\Users\A Munawa\Desktop\NFSHP2.EXE
Task: {97618B94-0CA6-4D2A-9A50-26868DD0DA9D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {99FDD25C-8479-46BB-BE51-17F7F48C301A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {9A0027CD-3914-4158-95BF-FDC52761D115} - System32\Tasks\{7CF29026-4C9C-499A-BDC4-03DFAA175F76} => pcalua.exe -a "F:\SOFTWARE\Setup\Nokia Pc 2009\Nokia_PC_Suite_7_0_9_2_EA.exe" -d "F:\SOFTWARE\Setup\Nokia Pc 2009"
Task: {9F4C76C8-7F41-43ED-B9E6-B2DE8C45B535} - System32\Tasks\SmartDefrag3_Update => C:\Program Files (x86)\IObit\Smart Defrag 3\AutoUpdate.exe [2014-03-10] (IObit)
Task: {A467F16E-3DE3-4C56-BCFA-06AD2212F0A1} - System32\Tasks\{B79CA206-49E5-45EC-A5BB-CE6A47ABA249} => C:\Program Files (x86)\FlareGet\flareget.exe
Task: {A6F7A11E-8D55-422B-A2BB-3100EDE02D36} - System32\Tasks\{B4C4FB28-4AB6-48C9-98AF-17E0B3E72E54} => pcalua.exe -a C:\Downloads\dap10i_0a94fa8f79_setup.exe -d C:\Downloads
Task: {B0E61EC2-C87F-4935-94DF-8E0A1481F3FC} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {B189D90D-7148-4004-BE12-F750A3875B54} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {C10A4BF2-A4C4-49C0-A0E9-1FC2403233B9} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {C5E18FA3-6493-4CA1-8255-5DD77A0C7AD1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {C72456B9-8926-44FD-97E9-CC70B65FD10B} - System32\Tasks\{5F4710B6-E703-4BE1-B947-70F3C0312188} => C:\Users\A Munawa\Desktop\NFSHP2.EXE
Task: {C829C584-6408-4E99-B1B6-AE57D1C1AF51} - System32\Tasks\AdobeAAMUpdater-1.0-AMunawa-HP-A Munawa => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)
Task: {C9F2BD56-F2FD-4B17-8094-92C15E7FF82A} - System32\Tasks\SmartDefrag3_Startup => C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe [2014-03-10] (IObit)
Task: {D04C69E5-BE5D-4FF8-A1AB-3DB80AE8A97D} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-02-11] (CyberLink)
Task: {D1E0F3A0-0B1F-454C-8F66-6EBF1C76B59D} - System32\Tasks\{B5CE94B9-07E4-4DFA-B9B2-786718736601} => C:\Users\A Munawa\Desktop\NFSHP2.EXE
Task: {D9BFDA8A-1B85-48B8-AEFF-AEBEDE3DE3C0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-15] (Adobe Systems Incorporated)
Task: {DBD237FB-3BC3-473C-A46B-5C9C732BCA4E} - System32\Tasks\{B8C39171-F8FC-426F-B25F-291C1342CCB4} => pcalua.exe -a "F:\SOFTWARE\Setup\Nokia Pc 2009\Nokia_PC_Suite_rel_6_85_12_0_por_web.exe" -d "F:\SOFTWARE\Setup\Nokia Pc 2009"
Task: {DDB98E5C-9CF8-42ED-B02D-FEAA454AE43E} - System32\Tasks\{144BE270-BDDE-47B2-AF68-9499B0BA564E} => pcalua.exe -a F:\Office_ProfessionalPlus_2010\setup.exe -d F:\Office_ProfessionalPlus_2010
Task: {E01B2456-CF7C-4F6D-B7ED-E91B5BCE391B} - System32\Tasks\Update Service GoForFiles => C:\Program Files (x86)\GoForFilesUpdater\GoForFilesUpdater.exe <==== ATTENTION
Task: {ED28F2C3-2D65-492D-82F5-44D3343BE25F} - System32\Tasks\{9F7BF939-219B-43CC-8ABB-0C712D13C204} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&amp;ver=6.16.0.105&amp;LastError=12002
Task: {F0158905-2A53-42C2-BE0E-268F1C324AF0} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForAMUNAWA-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Loaded Modules (whitelisted) =============

2013-04-03 19:33 - 2011-09-07 11:00 - 00269312 _____ () C:\Program Files\CDMA-1XDO\C+WEject.exe
2013-01-11 08:16 - 2011-01-14 09:29 - 00404992 _____ () C:\Program Files\Africom UI\bin\MonServiceUDisk.exe
2013-03-14 19:10 - 2013-03-14 19:10 - 00927840 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe
2011-12-20 08:34 - 2011-12-20 08:34 - 00108880 _____ () C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-02-21 17:10 - 2012-09-05 18:55 - 00892288 _____ () C:\Program Files (x86)\IObit\Smart Defrag 3\webres.dll
2015-01-14 12:24 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2015-01-14 12:24 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2015-01-14 12:24 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2012-03-15 04:00 - 2012-03-15 04:00 - 00249856 _____ () C:\Program Files (x86)\FlashGet Network\FlashGet 3\BugReport.dll
2012-03-15 04:06 - 2012-03-15 04:06 - 00059016 _____ () C:\Program Files (x86)\FlashGet Network\FlashGet 3\zlib.dll
2012-03-15 04:00 - 2012-03-15 04:00 - 00262144 _____ () C:\Program Files (x86)\FlashGet Network\FlashGet 3\ckcore.dll
2012-06-26 13:11 - 2012-06-26 13:11 - 02302040 _____ () C:\Program Files (x86)\Nokia\Nokia PC Suite 7\QtCore4.dll
2012-06-26 13:11 - 2012-06-26 13:11 - 08197208 _____ () C:\Program Files (x86)\Nokia\Nokia PC Suite 7\QtGui4.dll
2012-06-26 13:11 - 2012-06-26 13:11 - 00345688 _____ () C:\Program Files (x86)\Nokia\Nokia PC Suite 7\QtXml4.dll
2012-06-26 13:10 - 2012-06-26 13:10 - 00202328 _____ () C:\Program Files (x86)\Nokia\Nokia PC Suite 7\imageformats\qjpeg4.dll
2012-06-26 13:10 - 2012-06-26 13:10 - 00027736 _____ () C:\Program Files (x86)\Nokia\Nokia PC Suite 7\imageformats\qsvg4.dll
2012-06-26 13:11 - 2012-06-26 13:11 - 00282200 _____ () C:\Program Files (x86)\Nokia\Nokia PC Suite 7\QtSvg4.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\A Munawa\Downloads:Shareaza.GUID
AlternateDataStreams: C:\Users\A Munawa\Downloads\BROCHURES USING WINDOWS:Shareaza.GUID
AlternateDataStreams: C:\Users\A Munawa\Downloads\BUCKET:Shareaza.GUID
AlternateDataStreams: C:\Users\A Munawa\Downloads\Compressed:Shareaza.GUID
AlternateDataStreams: C:\Users\A Munawa\Downloads\Documents:Shareaza.GUID
AlternateDataStreams: C:\Users\A Munawa\Downloads\Music:Shareaza.GUID
AlternateDataStreams: C:\Users\A Munawa\Downloads\Programs:Shareaza.GUID
AlternateDataStreams: C:\Users\A Munawa\Downloads\Video:Shareaza.GUID
AlternateDataStreams: C:\ProgramData\Temp:56E2E879
AlternateDataStreams: C:\ProgramData\Temp:661DFA1C

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CLPSLS => ""="Service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: EagleGet =>
MSCONFIG\startupreg: FlashGet 3 => "C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe" -minimize
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: NBKeyScan => "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
MSCONFIG\startupreg: PC Suite Tray => "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray

========================= Accounts: ==========================

A Munawa (S-1-5-21-534593773-3893946233-160603186-1001 - Administrator - Enabled) => C:\Users\A Munawa
Administrator (S-1-5-21-534593773-3893946233-160603186-500 - Administrator - Disabled)
Guest (S-1-5-21-534593773-3893946233-160603186-501 - Limited - Disabled)

==================== Faulty Device Manager Devices =============

Name: CSN5PDTS82x64 NDIS Protocol Driver
Description: CSN5PDTS82x64 NDIS Protocol Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: CSN5PDTS82x64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/15/2015 11:20:20 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SDWelcome.exe version 2.4.40.130 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 4fc

Start Time: 01d03097f11e2963

Termination Time: 702

Application Path: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe

Report Id: a6b52aba-9c97-11e4-ac8e-a0b3ccc6d49e

Error: (01/15/2015 10:10:07 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 388567

Error: (01/15/2015 10:10:07 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 388567

Error: (01/15/2015 10:10:07 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/15/2015 09:46:45 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/14/2015 09:28:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 784716

Error: (01/14/2015 09:28:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 784716

Error: (01/14/2015 09:28:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/14/2015 09:04:45 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: An unspecified error occurred during System Restore: (kenny). Additional information: 0x80070005.

Error: (01/14/2015 08:54:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (01/15/2015 10:26:33 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Dnscache service.

Error: (01/15/2015 10:10:04 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.

Error: (01/15/2015 09:47:29 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error:
%%1053

Error: (01/15/2015 09:47:29 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Scanner Service service to connect.

Error: (01/15/2015 09:46:59 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
CSN5PDTS82
CSN5PDTS82x64

Error: (01/15/2015 09:46:36 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error:
%%1053

Error: (01/15/2015 09:46:36 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Scanner Service service to connect.

Error: (01/14/2015 08:55:59 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
CSN5PDTS82
CSN5PDTS82x64

Error: (01/14/2015 08:55:59 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Freemake Improver service hung on starting.

Error: (01/14/2015 08:54:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error:
%%1053


Microsoft Office Sessions:
=========================
Error: (01/15/2015 11:20:20 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: SDWelcome.exe2.4.40.1304fc01d03097f11e2963702C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exea6b52aba-9c97-11e4-ac8e-a0b3ccc6d49e

Error: (01/15/2015 10:10:07 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 388567

Error: (01/15/2015 10:10:07 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 388567

Error: (01/15/2015 10:10:07 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/15/2015 09:46:45 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/14/2015 09:28:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 784716

Error: (01/14/2015 09:28:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 784716

Error: (01/14/2015 09:28:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/14/2015 09:04:45 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: kenny0x80070005

Error: (01/14/2015 08:54:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
Date: 2014-02-14 14:47:59.280
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-11-14 16:04:57.830
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: AMD E2-1800 APU with Radeon(tm) HD Graphics
Percentage of memory in use: 82%
Total physical RAM: 1640.37 MB
Available physical RAM: 291.68 MB
Total Pagefile: 3280.73 MB
Available Pagefile: 1154.16 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:278.29 GB) (Free:47.03 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Recovery) (Fixed) (Total:19.51 GB) (Free:2.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 86DCC603)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=278.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=19.5 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=103 MB) - (Type=0C)

==================== End Of Log ============================
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top