Solved I can't get rid of Buy n Save. Please help!!

Helllo,

My name is Argus and and I will be helping you with your computer problems.

Before we begin, please note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The logs can take some time to research, so please be patient with me.
  • Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
  • Instructions that I give are for your system only!
  • Please do not run any tools until requested ! The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.
  • Please perform all steps in the order received. If you can't understand something don't hesitate to ask.
  • Again I would like to remind you to make no further changes to your computer unless I direct you to do so. I will not help you if you do not follow my instructions.




warning.gif
Rules and policies

We won't support any piracy.
That being told, if any evidence of illegal OS, software, cracks/keygens or any other will be revealed, any further assistance will be suspended. If you are aware that there is this kind of stuff on your machine, remove it before proceeding!
The same applies to any use of P2P software: uTorrent, BitTorrent, Vuze, Kazaa, Ares... We don't provide any help for P2P, except for their removal. All P2P software has to be uninstalled or at least fully disabled before proceeding!

Failure to follow these guidelines will result with closing your topic and withdrawning any assistance.



FRST.gif
Scan with Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-02-2015
Ran by bruce at 2015-02-18 14:20:13
Running from C:\Users\bruce\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

8ta connect (HKLM\...\8ta connect) (Version: 16.002.10.02.372 - Huawei Technologies Co.,Ltd)
Adobe Flash Player ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 9.0.124.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
ATI Catalyst Install Manager (HKLM\...\{B274376B-F928-53DE-2B89-563DB3B4BE75}) (Version: 3.0.604.0 - ATI Technologies, Inc.)
BlackBerry Device Software Updater (HKLM\...\{5BF3423C-4397-4FE3-A318-C9850EA24CB3}) (Version: 8.0.0.46 - Research In Motion Ltd)
Blouberg Ridge P (HKLM\...\Blouberg Ridge P_is1) (Version: - D6 Technology)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Branding (Version: 1.00.0000 - Your Company Name) Hidden
ccc-core-static (Version: 0108.2146.2565.38893 - ATI) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.02 - Piriform)
Dropbox (HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.)
EA Download Manager (Version: 4.0.0.462 - Electronic Arts) Hidden
Google Chrome (HKLM\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Drive (HKLM\...\{C60F3836-333A-4AE2-B526-CFDBA143A9BA}) (Version: 1.18.7821.2489 - Google, Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
PIXresizer 2.0.3 (HKLM\...\PIXresizer_is1) (Version: - Bluefive software)
Samsung Kies3 (HKLM\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14113.3 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (Version: 3.2.14113.3 - Samsung Electronics Co., Ltd.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Skins (Version: 0108.2146.2565.38893 - ATI) Hidden
Skype Click to Call (HKLM\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
SkypEmoticons (HKLM\...\SkypEmoticons_is1) (Version: - ) <==== ATTENTION
Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 9.1.0.0 - Synaptics)
Table View High School (HKLM\...\Table View High School_is1) (Version: - D6 Technology)
TeamViewer 9 (HKLM\...\TeamViewer 9) (Version: 9.0.38846 - TeamViewer)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)

==================== Restore Points =========================

11-02-2015 12:36:39 Windows Update
11-02-2015 13:10:16 Removed Free YouTube Downloader Converter
11-02-2015 13:24:54 Removed GTA San Andreas
11-02-2015 13:27:13 Removed GTAIII
11-02-2015 13:28:16 Removed Halo 2 Dedicated Server
11-02-2015 13:29:45 Removed Halo 2 for Windows Vista
11-02-2015 13:31:06 Removed LIVE gaming on Windows Runtime Version 1.0.6027
11-02-2015 13:33:00 Removed Rockstar Games Social Club
11-02-2015 13:34:24 Removed Need for Speed™ Undercover
11-02-2015 15:54:09 Windows Update
12-02-2015 15:09:04 Windows Update
16-02-2015 09:04:44 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {2AD27402-E1A6-4786-B38E-F93577EA3FD5} - System32\Tasks\DTChk => C:\Users\Public\Util\DTChk.exe [2014-05-14] (Search Results, LLC) <==== ATTENTION
Task: {2FFA1FB7-2FF6-4881-A3F9-58A5F26D3CAA} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {39E9B66A-B7D1-424A-8F42-F16D3103391A} - System32\Tasks\RegistryDr_Start => C:\Program Files\Registry Dr\RegistryDr.exe <==== ATTENTION
Task: {4378151F-97D3-4894-85CC-41572FF75AD9} - System32\Tasks\Adobe online update program => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {5BC2A1B6-B47B-44EE-98CA-2596E1ED1521} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-28] (Google Inc.)
Task: {60C17A4E-1689-49BC-A386-EFFDB13B6768} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-28] (Google Inc.)
Task: {74EB13A7-B729-480A-948F-9669DCB7E8B4} - System32\Tasks\{146D86D5-A264-4A9B-B192-7C68A69AFED1} => pcalua.exe -a D:\setup.EXE -d D:\
Task: {9270A89C-55A7-482E-8D51-2218CF223F61} - \WPD\SqmUpload_S-1-5-21-1695450602-631600950-3695078651-1000 No Task File <==== ATTENTION
Task: {9BDD794D-8BAB-4DD9-83DD-B735FE8AF8AB} - System32\Tasks\{5CBF8717-6DFE-45CB-9F39-579C6720FE9E} => pcalua.exe -a "C:\Users\bruce\Downloads\msg (1).exe" -d C:\Users\bruce\Downloads
Task: {B1B9A982-2020-4E75-B98E-722BCABFF198} - System32\Tasks\{3624D882-D548-4A11-AB84-6F1E0084CF8A} => pcalua.exe -a C:\Users\bruce\Desktop\WDM_R273.exe -d C:\Users\bruce\Desktop
Task: {C0440829-DCED-43E8-AAAE-AC1CD7865D73} - System32\Tasks\LaunchApp => C:\Program Files\MyPC Backup\MyPC Backup.exe <==== ATTENTION
Task: {C1525484-FFE7-4AD2-BBDE-8AB6909A9CBF} - System32\Tasks\DTReg => C:\Windows\system32\config\systemprofile\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe <==== ATTENTION
Task: {D302B9BA-A1EB-41D8-B81E-FD8CCC380ABD} - System32\Tasks\{2D6EC121-F0E2-4BD8-9D7A-51430B9C699A} => pcalua.exe -a C:\Users\bruce\Downloads\spurgeon.exe -d C:\Users\bruce\Downloads
Task: {DE03ABF3-12FB-45D5-BDF1-E8BF097360B8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-01-20] (Piriform Ltd)
Task: {EB2BFE77-EC4F-41D8-8217-B917F46251E1} - System32\Tasks\{9653D9F2-4B0E-4DDC-BBCB-E3A2746CC179} => pcalua.exe -a C:\Users\bruce\Desktop\WDM_R273[1].exe -d C:\Users\bruce\Desktop
Task: {F02D9A3A-E7FD-4BA4-B389-AA956D95B061} - System32\Tasks\{1FBCCBC5-26D6-4256-A97A-1D306B14035C} => pcalua.exe -a "E:\8ta connect\setup.exe" -d "E:\8ta connect"
Task: {F4A1C541-4248-4B1A-AE9E-959211993613} - System32\Tasks\{2EEF9EAD-0D1C-4625-93EA-77138D17CEA9} => pcalua.exe -a C:\Users\bruce\Downloads\pnt.exe -d C:\Users\bruce\Downloads
Task: {F9FBE49E-244C-48FA-9568-2D64EDAB9600} - System32\Tasks\{BEE6B2F2-0671-4EB0-BEEB-560618C5BA3F} => pcalua.exe -a D:\Install.exe -d D:\
Task: {FC8D3C8D-80CD-431F-A8C7-54414389FE74} - System32\Tasks\{210FA47C-AFA2-48D8-8FE5-257237689B2B} => pcalua.exe -a D:\setup.exe -d D:\

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2010-05-08 13:48 - 2010-05-08 13:48 - 00229376 _____ () C:\ProgramData\DatacardService\DCService.exe
2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2015-02-10 23:00 - 2015-02-10 23:00 - 00750080 _____ () C:\Users\bruce\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-02-18 09:30 - 2015-02-18 09:30 - 00043008 _____ () c:\users\bruce\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqlxqzq.dll
2015-02-10 23:00 - 2015-02-10 23:00 - 00047616 _____ () C:\Users\bruce\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-02-10 23:00 - 2015-02-10 23:00 - 00865280 _____ () C:\Users\bruce\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-02-10 23:00 - 2015-02-10 23:00 - 00200704 _____ () C:\Users\bruce\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2014-12-20 10:49 - 2014-12-06 03:50 - 01677128 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll
2014-12-20 10:49 - 2014-12-06 03:50 - 14913352 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-02-14 15:46 - 2013-02-14 15:46 - 01044048 _____ () C:\Program Files\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2014-12-20 10:49 - 2014-12-06 03:50 - 09009480 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.95\pdf.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:373E1720
AlternateDataStreams: C:\Users\bruce\Downloads\EL HLB Minnaar The Waves Painting and Waterproofing Specialists.eml:OECustomProperty
AlternateDataStreams: C:\Users\bruce\Downloads\noname (1).eml:OECustomProperty
AlternateDataStreams: C:\Users\bruce\Downloads\noname (2).eml:OECustomProperty
AlternateDataStreams: C:\Users\bruce\Downloads\noname.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1695450602-631600950-3695078651-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\bruce\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 172.16.56.250

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Shortcut to BackInfo.exe.lnk => C:\Windows\pss\Shortcut to BackInfo.exe.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^bruce^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CCC.lnk => C:\Windows\pss\CCC.lnk.Startup
MSCONFIG\startupfolder: C:^Users^bruce^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: d6_6699 => C:\Program Files\D6 Technology\d6_6699\d6\d6_6699.exe
MSCONFIG\startupreg: d6_6892 => C:\Program Files\D6 Technology\d6_6892\d6\d6_6892.exe
MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
MSCONFIG\startupreg: iLivid => "C:\Users\bruce\AppData\Local\iLivid\iLivid.exe" -autorun
MSCONFIG\startupreg: mobilegeni daemon => C:\Program Files\Mobogenie\DaemonProcess.exe
MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
MSCONFIG\startupreg: RIMBBLaunchAgent.exe => C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
MSCONFIG\startupreg: se => "C:\Users\bruce\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: StartCCC => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
MSCONFIG\startupreg: SynTPEnh => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

==================== Accounts: =============================

Administrator (S-1-5-21-1695450602-631600950-3695078651-500 - Administrator - Disabled)
bruce (S-1-5-21-1695450602-631600950-3695078651-1002 - Administrator - Enabled) => C:\Users\bruce
Guest (S-1-5-21-1695450602-631600950-3695078651-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1695450602-631600950-3695078651-1004 - Limited - Enabled)

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/11/2015 01:13:46 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: bruce-PC)
Description: Application or service 'YouTubeDownloaderConverter' could not be restarted.

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7813

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7813

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 74563062

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 74563062

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/06/2015 01:08:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8015

Error: (02/06/2015 01:08:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8015

Error: (02/06/2015 01:08:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


System errors:
=============
Error: (02/15/2015 09:02:06 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (02/15/2015 06:23:23 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.191.4641.0

Update Source: %NT AUTHORITY59

Update Stage: 4.7.0205.00

Source Path: 4.7.0205.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\SYSTEM

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (02/15/2015 06:23:10 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureCommand with the following error:
%%5

Error: (02/15/2015 06:23:01 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error:
%%5

Error: (02/15/2015 04:26:00 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (02/15/2015 02:20:16 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.191.4641.0

Update Source: %NT AUTHORITY59

Update Stage: 4.7.0205.00

Source Path: 4.7.0205.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\SYSTEM

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (02/15/2015 01:37:04 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (02/15/2015 01:36:16 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {005A3A96-BAC4-4B0A-94EA-C0CE100EA736}

Error: (02/15/2015 01:36:00 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.191.4641.0

Update Source: %NT AUTHORITY59

Update Stage: 4.7.0205.00

Source Path: 4.7.0205.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\SYSTEM

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (02/13/2015 05:24:11 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}


Microsoft Office Sessions:
=========================
Error: (02/11/2015 01:13:46 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: bruce-PC)
Description: 0CertifiedBrowserService.exeYouTubeDownloaderConverter0302621783720

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7813

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7813

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 74563062

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 74563062

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/06/2015 01:08:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8015

Error: (02/06/2015 01:08:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8015

Error: (02/06/2015 01:08:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


==================== Memory info ===========================

Processor: Mobile AMD Sempron(tm) Processor 3500+
Percentage of memory in use: 68%
Total physical RAM: 1278.17 MB
Available physical RAM: 399.04 MB
Total Pagefile: 2556.34 MB
Available Pagefile: 1337.06 MB
Total Virtual: 2047.88 MB
Available Virtual: 1901.44 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.48 GB) (Free:269.38 GB) NTFS
Drive z: () (Network) (Total:465.42 GB) (Free:375.38 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3E78BA79)
Partition 1: (Active) - (Size=283 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.5 GB) - (Type=07 NTFS)

==================== End Of Log ============================


Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-02-2015
Ran by bruce (administrator) on BRUCE-PC on 18-02-2015 14:18:22
Running from C:\Users\bruce\Downloads
Loaded Profiles: bruce (Available profiles: bruce)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\tv_w32.exe
(Dropbox, Inc.) C:\Users\bruce\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\Run: [] => [X]
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\MountPoints2: E - E:\AutoRun.exe
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\MountPoints2: {9ab9c3fc-7846-11e3-b6f5-001636ed47c3} - E:\LaunchU3.exe -a
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\MountPoints2: {a005315a-577e-11e3-a1ee-001636ed47c3} - E:\AutoRun.exe
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\MountPoints2: {a0053175-577e-11e3-a1ee-001636ed47c3} - E:\AutoRun.exe
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
Startup: C:\Users\bruce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nsri.org.za/
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://howzit.msn.com/?ocid=iehp
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.everitt.westernseaboard.co.za/
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=224&itype=a&ver=15005&tm=575&src=ds&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1695450602-631600950-3695078651-1002 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1695450602-631600950-3695078651-1002 -> {569C96FA-ED3B-46A4-BFF6-8854FD364A30} URL = http://www.mysearchresults.com/search?c=3523&t=01&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1695450602-631600950-3695078651-1002 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=224&itype=a&ver=15005&tm=575&src=ds&p={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: MineimumPuriicee -> {94cacc75-b63b-4184-b361-d80bf18e7619} -> C:\ProgramData\MineimumPuriicee\OqdzQUdY4Rg7CS.dll ()
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 172.16.56.250
Tcpip\..\Interfaces\{9E88E912-13A7-4890-AE64-A50B099A44B0}: [NameServer] 196.7.7.7 196.7.8.9
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\Firefox\Extensions: [freegames4357@BestOffers] - C:\Users\bruce\AppData\Roaming\Mozilla\Extensions\freegames4357@BestOffers

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR DefaultSearchKeyword: Default -> EF0401BE2CE25594A0884EAE54B82B9E4B23AD7CB6A885369D602CDDD3A4D858
CHR DefaultSearchURL: Default -> 453BC05C3BE20B255EC301D6A1325919931B9CF6F1664B9EBA67E7A05F8BBBD1
CHR Profile: C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-28]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-23]
CHR Extension: (YouTube) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-28]
CHR Extension: (Google Search) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-28]
CHR Extension: (Google Wallet) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-28]
CHR Extension: (Gmail) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-28]
CHR Extension: (BuyNisaaVe) - C:\ProgramData\inlpipemefpffokmnllbdijhecpllffc\ [2013-11-28]
CHR Extension: (BuyNseaaVieo) - C:\ProgramData\lmjagemdpijelinfebhmbacejjiaklhb\ [2013-11-28]
CHR Profile: C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-31]
CHR Extension: (Google Docs) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-31]
CHR Extension: (Google Drive) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-31]
CHR Extension: (No Name) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bejnhdlplbjhffionohbdnpcbobfejcc [2014-12-31]
CHR Extension: (YouTube) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-31]
CHR Extension: (Google Search) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-31]
CHR Extension: (Google Sheets) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-31]
CHR Extension: (winnie the pooh) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\golfgdoojafiippacodpnlfkmclpdgmo [2014-12-31]
CHR Extension: (Skype Click to Call) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-12-31]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-12-31]
CHR Extension: (No Name) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmgcfemagnogdodbambjhdcmfcpicngl [2014-12-31]
CHR Extension: (Gmail) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-31]
CHR Extension: (Default-Search) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\poimdfnhgefmnkeefbjibbiemlimdnof [2014-12-31]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM\...\Chrome\Extension: [poimdfnhgefmnkeefbjibbiemlimdnof] - No Path
CHR HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - No Path

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 BlackBerry Device Manager; C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2014-01-21] (BlackBerry Limited) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] () [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 EMSCR; C:\Windows\System32\DRIVERS\EMS7SK.sys [62208 2013-11-26] (ENE Technology Inc.)
R3 ESDCR; C:\Windows\System32\DRIVERS\ESD7SK.sys [42240 2013-11-26] (ENE Technology Inc.)
R3 ESMCR; C:\Windows\System32\DRIVERS\ESM7SK.sys [76928 2013-11-26] (ENE Technology Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl.sys [18944 2014-08-15] (Apple Inc.) [File not signed]
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb.sys [68096 2013-12-02] (BlackBerry Limited)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2014-08-15] (Apple, Inc.) [File not signed]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-18 14:18 - 2015-02-18 14:19 - 00017003 _____ () C:\Users\bruce\Downloads\FRST.txt
2015-02-18 14:17 - 2015-02-18 14:18 - 00000000 ____D () C:\FRST
2015-02-18 14:16 - 2015-02-18 14:17 - 01125888 _____ (Farbar) C:\Users\bruce\Downloads\FRST.exe
2015-02-12 09:39 - 2015-02-12 09:39 - 00002755 _____ () C:\Users\bruce\Downloads\invite.ics
2015-02-12 09:38 - 2015-02-12 09:38 - 00006398 _____ () C:\Users\bruce\Downloads\smime (8).p7s
2015-02-12 08:18 - 2015-01-23 05:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-02-12 08:18 - 2015-01-23 05:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-11 14:27 - 2015-02-18 09:29 - 00000616 _____ () C:\Windows\setupact.log
2015-02-11 14:27 - 2015-02-11 14:27 - 00000000 _____ () C:\Windows\setuperr.log
2015-02-11 14:25 - 2015-02-11 14:25 - 00000000 ____D () C:\Windows\pss
2015-02-11 12:46 - 2015-01-15 09:46 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-11 12:46 - 2015-01-15 09:46 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-11 12:46 - 2015-01-15 09:43 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-02-11 12:46 - 2015-01-15 09:43 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-02-11 12:46 - 2015-01-15 09:42 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-11 12:46 - 2015-01-15 09:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-02-11 12:46 - 2015-01-15 09:42 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-02-11 12:46 - 2015-01-15 09:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-02-11 12:46 - 2015-01-15 09:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-11 12:46 - 2015-01-15 09:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-02-11 12:46 - 2015-01-15 09:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-11 12:46 - 2015-01-15 06:21 - 00369968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-11 12:44 - 2015-01-09 03:45 - 02380288 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-11 12:41 - 2015-01-14 07:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-02-11 12:41 - 2015-01-14 07:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-11 12:40 - 2015-02-04 04:54 - 00482304 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-11 12:40 - 2015-02-04 04:53 - 00767488 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-11 12:40 - 2015-02-04 04:53 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-11 12:40 - 2015-02-04 04:53 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-11 12:40 - 2015-02-04 04:53 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-11 12:40 - 2015-02-04 04:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-02-11 12:40 - 2015-02-04 04:49 - 00886784 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-11 12:40 - 2015-01-28 01:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-02-11 12:40 - 2014-11-26 05:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-11 12:40 - 2014-10-04 03:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-02-11 12:40 - 2014-10-04 03:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-02-11 12:39 - 2015-01-14 07:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-11 12:39 - 2015-01-12 04:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-11 12:39 - 2015-01-12 04:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 12:39 - 2015-01-12 04:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-02-11 12:39 - 2015-01-12 04:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-02-11 12:39 - 2015-01-12 04:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-11 12:39 - 2015-01-12 03:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-02-11 12:39 - 2015-01-12 03:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-11 12:39 - 2015-01-12 03:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-11 12:39 - 2015-01-12 03:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-02-11 12:39 - 2015-01-12 03:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 12:39 - 2015-01-12 03:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-11 12:39 - 2015-01-12 03:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 12:39 - 2015-01-12 03:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-02-11 12:39 - 2015-01-12 03:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-11 12:39 - 2015-01-12 03:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-11 12:39 - 2015-01-12 03:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-11 12:39 - 2015-01-12 03:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-11 12:39 - 2015-01-12 03:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-11 12:39 - 2015-01-12 03:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-11 12:39 - 2015-01-12 02:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-11 12:39 - 2015-01-12 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-02-11 12:38 - 2015-01-12 04:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-11 12:38 - 2015-01-12 04:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-11 12:38 - 2015-01-12 04:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-11 12:38 - 2015-01-12 04:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-11 12:38 - 2015-01-12 03:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-11 12:38 - 2015-01-12 03:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-02-11 12:36 - 2014-12-12 07:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-02-11 12:35 - 2015-01-13 04:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-11 12:35 - 2014-12-08 04:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-11 12:02 - 2015-02-11 12:02 - 00001060 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2015-02-11 12:02 - 2015-02-11 12:02 - 00001048 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2015-02-10 09:29 - 2015-02-10 09:29 - 00012800 _____ () C:\Users\bruce\Downloads\cmainfo (92).xls
2015-02-10 09:26 - 2015-02-10 09:26 - 00011776 _____ () C:\Users\bruce\Downloads\cmainfo (91).xls
2015-02-10 09:23 - 2015-02-10 09:23 - 00009728 _____ () C:\Users\bruce\Downloads\cmainfo (90).xls
2015-02-10 09:19 - 2015-02-10 09:19 - 00009728 _____ () C:\Users\bruce\Downloads\cmainfo (89).xls
2015-02-10 09:15 - 2015-02-10 09:15 - 00008704 _____ () C:\Users\bruce\Downloads\cmainfo (88).xls
2015-01-29 13:23 - 2015-01-29 13:23 - 00007680 _____ () C:\Users\bruce\Downloads\cmainfo (87).xls
2015-01-27 09:29 - 2015-01-27 09:29 - 00612952 _____ () C:\Users\bruce\Downloads\Load Shedding Schedule 12112014.xlsx
2015-01-26 14:08 - 2015-01-26 14:08 - 00254464 _____ () C:\Users\bruce\Desktop\E-Mail List - Feb - March '15.xls
2015-01-26 14:06 - 2015-01-26 14:06 - 00248832 _____ () C:\Users\bruce\Downloads\E-Mail List - Feb - March '15.xls
2015-01-26 14:06 - 2015-01-26 14:06 - 00218624 _____ () C:\Users\bruce\Desktop\Tele List - Feb - March '15.xls
2015-01-26 13:56 - 2015-01-26 13:56 - 00208896 _____ () C:\Users\bruce\Downloads\Tele List - Feb - March '15.xls
2015-01-23 09:38 - 2015-01-23 09:39 - 00000236 _____ () C:\Users\bruce\Downloads\download.htm

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-18 14:18 - 2013-11-28 13:06 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Outlook Files
2015-02-18 13:57 - 2013-11-28 10:15 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-18 13:56 - 2013-11-27 16:36 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\D
2015-02-18 13:28 - 2013-11-26 19:45 - 01762724 _____ () C:\Windows\WindowsUpdate.log
2015-02-18 12:57 - 2013-11-28 10:15 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-18 11:30 - 2009-07-14 06:34 - 00033008 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-18 11:30 - 2009-07-14 06:34 - 00033008 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-18 09:30 - 2013-12-03 14:32 - 00000000 ___RD () C:\Users\bruce\Dropbox
2015-02-18 09:30 - 2013-12-03 13:58 - 00000000 ____D () C:\Users\bruce\AppData\Roaming\Dropbox
2015-02-18 09:29 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-17 11:29 - 2013-11-27 16:36 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\General
2015-02-16 14:15 - 2013-11-27 16:41 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Recipes
2015-02-16 08:39 - 2013-12-03 14:32 - 00001017 _____ () C:\Users\bruce\Desktop\Dropbox.lnk
2015-02-16 08:39 - 2013-12-03 14:02 - 00000000 ____D () C:\Users\bruce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-15 21:01 - 2014-08-25 17:57 - 00000000 ____D () C:\Users\bruce\AppData\Roaming\vlc
2015-02-15 13:27 - 2009-01-01 00:19 - 00785302 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-13 10:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-02-13 10:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-02-12 12:33 - 2014-05-31 10:39 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Wait Until Dark
2015-02-12 07:55 - 2009-07-14 06:33 - 00409712 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-12 07:53 - 2014-12-11 08:58 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-12 07:53 - 2014-05-06 14:23 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-11 15:58 - 2011-06-17 17:01 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-11 15:58 - 2009-07-14 04:04 - 00000591 _____ () C:\Windows\win.ini
2015-02-11 14:23 - 2013-12-06 13:10 - 00000000 ____D () C:\Users\bruce\AppData\Roaming\Skype
2015-02-11 13:33 - 2014-04-13 13:05 - 00000000 ____D () C:\Program Files\Rockstar Games
2015-02-11 13:33 - 2014-02-27 20:15 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-02-11 13:30 - 2013-12-28 09:37 - 00000000 ____D () C:\Program Files\Microsoft Games
2015-02-11 13:30 - 2013-12-28 09:36 - 00000000 ____D () C:\Users\bruce\AppData\Local\Microsoft Game Studios
2015-02-11 13:30 - 2013-12-28 09:35 - 00000000 ____D () C:\ProgramData\Microsoft Games
2015-02-11 13:30 - 2013-12-28 09:32 - 00000000 ____D () C:\Users\bruce\AppData\Roaming\Microsoft Game Studios
2015-02-11 13:29 - 2014-02-27 20:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2015-02-11 13:27 - 2014-06-15 20:39 - 00000000 ____D () C:\Program Files\Common Files\InstallShield
2015-02-11 13:17 - 2014-02-19 12:11 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-02-11 13:17 - 2014-02-19 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-02-11 13:16 - 2014-02-19 12:10 - 00000000 ____D () C:\Program Files\CCleaner
2015-02-11 13:09 - 2014-12-24 16:29 - 00000000 ____D () C:\Program Files\Driver Pro
2015-02-11 13:09 - 2014-01-21 11:14 - 00000000 ___RD () C:\Users\bruce\Google Drive
2015-02-11 13:03 - 2013-11-28 10:10 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-11 12:47 - 2011-11-15 18:22 - 113756392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-11 12:41 - 2013-12-14 09:26 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-02-11 12:41 - 2013-11-27 09:45 - 00001945 _____ () C:\Windows\epplauncher.mif
2015-02-11 12:40 - 2013-11-27 09:44 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-02-11 11:19 - 2009-07-14 06:53 - 00032644 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-09 13:07 - 2013-11-27 16:38 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Paige
2015-02-05 13:52 - 2014-07-09 11:33 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-03 20:26 - 2013-11-27 16:35 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Camryn
2015-01-29 13:35 - 2014-01-17 12:28 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Chas Everitt
2015-01-23 11:04 - 2014-03-05 11:18 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Proofs of Payment

==================== Files in the root of some directories =======

2014-01-17 11:55 - 2014-01-17 12:06 - 0038434 _____ () C:\Users\bruce\AppData\Roaming\Comma Separated Values (Windows).ADR
2013-12-02 15:18 - 2014-12-29 10:25 - 0009683 _____ () C:\Users\bruce\AppData\Roaming\Rim.Desktop.Exception.log
2013-12-02 15:08 - 2015-01-14 11:28 - 0002009 _____ () C:\Users\bruce\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2013-12-02 15:18 - 2014-12-29 10:25 - 0003619 _____ () C:\Users\bruce\AppData\Roaming\Rim.DesktopHelper.Exception.log
2014-06-18 10:24 - 2014-12-29 10:25 - 0003234 _____ () C:\Users\bruce\AppData\Roaming\Rim.Transcoder.Exception.log
2013-11-28 11:45 - 2013-11-28 12:33 - 0033193 _____ () C:\Users\bruce\AppData\Roaming\UserTile.png
2014-06-18 10:25 - 2014-06-18 10:27 - 0032256 _____ () C:\Users\bruce\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-09 18:01 - 2014-02-09 18:28 - 0001041 _____ () C:\ProgramData\hpzinstall.log

Some content of TEMP:
====================
C:\Users\bruce\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqlxqzq.dll
C:\Users\bruce\AppData\Local\Temp\sldlext.dll
C:\Users\bruce\AppData\Local\Temp\SLDL_DLL.dll
C:\Users\bruce\AppData\Local\Temp\StartUp.exe
C:\Users\bruce\AppData\Local\Temp\TnPCacheEngine.exe
C:\Users\bruce\AppData\Local\Temp\TnPUI.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-13 10:11

==================== End Of Log ============================
 
Okay.

FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif
​
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 

Attachments

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 15-02-2015
Ran by bruce at 2015-02-18 17:05:51 Run:2
Running from C:\Users\bruce\Downloads
Loaded Profiles: bruce (Available profiles: bruce)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
closeprocesses:
emptytemp:
Task: {2AD27402-E1A6-4786-B38E-F93577EA3FD5} - System32\Tasks\DTChk => C:\Users\Public\Util\DTChk.exe [2014-05-14] (Search Results, LLC) <==== ATTENTION
Task: {39E9B66A-B7D1-424A-8F42-F16D3103391A} - System32\Tasks\RegistryDr_Start => C:\Program Files\Registry Dr\RegistryDr.exe <==== ATTENTION
Task: {9270A89C-55A7-482E-8D51-2218CF223F61} - \WPD\SqmUpload_S-1-5-21-1695450602-631600950-3695078651-1000 No Task File <==== ATTENTION
Task: {C0440829-DCED-43E8-AAAE-AC1CD7865D73} - System32\Tasks\LaunchApp => C:\Program Files\MyPC Backup\MyPC Backup.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
AlternateDataStreams: C:\Users\bruce\Downloads\EL HLB Minnaar The Waves Painting and Waterproofing Specialists.eml:OECustomProperty
AlternateDataStreams: C:\Users\bruce\Downloads\noname (1).eml:OECustomProperty
AlternateDataStreams: C:\Users\bruce\Downloads\noname (2).eml:OECustomProperty
AlternateDataStreams: C:\Users\bruce\Downloads\noname.eml:OECustomProperty
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\Run: [] => [X]
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\MountPoints2: E - E:\AutoRun.exe
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\MountPoints2: {9ab9c3fc-7846-11e3-b6f5-001636ed47c3} - E:\LaunchU3.exe -a
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\MountPoints2: {a005315a-577e-11e3-a1ee-001636ed47c3} - E:\AutoRun.exe
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\MountPoints2: {a0053175-577e-11e3-a1ee-001636ed47c3} - E:\AutoRun.exe
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=224&itype=a&ver=15005&tm=575&src=ds&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1695450602-631600950-3695078651-1002 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1695450602-631600950-3695078651-1002 -> {569C96FA-ED3B-46A4-BFF6-8854FD364A30} URL = http://www.mysearchresults.com/search?c=3523&t=01&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1695450602-631600950-3695078651-1002 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=224&itype=a&ver=15005&tm=575&src=ds&p={searchTerms}
CHR DefaultSearchKeyword: Default -> EF0401BE2CE25594A0884EAE54B82B9E4B23AD7CB6A885369D602CDDD3A4D858
CHR DefaultSearchURL: Default -> 453BC05C3BE20B255EC301D6A1325919931B9CF6F1664B9EBA67E7A05F8BBBD1
CHR Extension: (BuyNisaaVe) - C:\ProgramData\inlpipemefpffokmnllbdijhecpllffc\ [2013-11-28]
CHR Extension: (BuyNseaaVieo) - C:\ProgramData\lmjagemdpijelinfebhmbacejjiaklhb\ [2013-11-28]
C:\ProgramData\inlpipemefpffokmnllbdijhecpllffc
C:\ProgramData\lmjagemdpijelinfebhmbacejjiaklhb
CHR Extension: (No Name) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmgcfemagnogdodbambjhdcmfcpicngl [2014-12-31]
C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmgcfemagnogdodbambjhdcmfcpicngl
CHR HKLM\...\Chrome\Extension: [poimdfnhgefmnkeefbjibbiemlimdnof] - No Path
CHR HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - No Path

*****************

Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AD27402-E1A6-4786-B38E-F93577EA3FD5} => Key not found.
C:\Windows\System32\Tasks\DTChk not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DTChk => Key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{39E9B66A-B7D1-424A-8F42-F16D3103391A} => Key not found.
C:\Windows\System32\Tasks\RegistryDr_Start not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegistryDr_Start => Key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9270A89C-55A7-482E-8D51-2218CF223F61} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-1695450602-631600950-3695078651-1000 => Key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0440829-DCED-43E8-AAAE-AC1CD7865D73} => Key not found.
C:\Windows\System32\Tasks\LaunchApp not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchApp => Key not found.
"C:\ProgramData\TEMP" => ":373E1720" ADS not found.
C:\Users\bruce\Downloads\EL HLB Minnaar The Waves Painting and Waterproofing Specialists.eml => ":OECustomProperty" ADS removed successfully.
C:\Users\bruce\Downloads\noname (1).eml => ":OECustomProperty" ADS removed successfully.
C:\Users\bruce\Downloads\noname (2).eml => ":OECustomProperty" ADS removed successfully.
C:\Users\bruce\Downloads\noname.eml => ":OECustomProperty" ADS removed successfully.
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value not found.
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E => Key not found.
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9ab9c3fc-7846-11e3-b6f5-001636ed47c3} => Key not found.
HKCR\CLSID\{9ab9c3fc-7846-11e3-b6f5-001636ed47c3} => Key not found.
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a005315a-577e-11e3-a1ee-001636ed47c3} => Key not found.
HKCR\CLSID\{a005315a-577e-11e3-a1ee-001636ed47c3} => Key not found.
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a0053175-577e-11e3-a1ee-001636ed47c3} => Key not found.
HKCR\CLSID\{a0053175-577e-11e3-a1ee-001636ed47c3} => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsersafeguard.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dprotectsvc.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchinstaller.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotector.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings64.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\umbrella.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\utiljumpflip.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroids.exe => Key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroidsservice.exe => Key not found.
"C:\Windows\system32\GroupPolicy\Machine" => File/Directory not found.
HKLM\SOFTWARE\Policies\Google => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => Key not found.
HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => Key not found.
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found.
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{569C96FA-ED3B-46A4-BFF6-8854FD364A30} => Key not found.
HKCR\CLSID\{569C96FA-ED3B-46A4-BFF6-8854FD364A30} => Key not found.
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => Key not found.
HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => Key not found.
Chrome DefaultSearchKeyword not detected.
Chrome DefaultSearchURL not detected.
C:\ProgramData\inlpipemefpffokmnllbdijhecpllffc\ directory not found.
C:\ProgramData\lmjagemdpijelinfebhmbacejjiaklhb\ directory not found.
"C:\ProgramData\inlpipemefpffokmnllbdijhecpllffc" => File/Directory not found.
"C:\ProgramData\lmjagemdpijelinfebhmbacejjiaklhb" => File/Directory not found.
C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmgcfemagnogdodbambjhdcmfcpicngl directory not found.
"C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmgcfemagnogdodbambjhdcmfcpicngl" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\poimdfnhgefmnkeefbjibbiemlimdnof => Key not found.
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\SOFTWARE\Google\Chrome\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh => Key not found.
EmptyTemp: => Removed 16 MB temporary data.


The system needed a reboot.

==== End of Fixlog 17:06:17 ====
 
FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-02-2015
Ran by bruce (administrator) on BRUCE-PC on 18-02-2015 17:29:19
Running from C:\Users\bruce\Downloads
Loaded Profiles: bruce (Available profiles: bruce)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\ProgramData\DatacardService\DCService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\tv_w32.exe
(Dropbox, Inc.) C:\Users\bruce\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\bruce\Downloads\FRST (2).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

Startup: C:\Users\bruce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nsri.org.za/
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://howzit.msn.com/?ocid=iehp
HKU\S-1-5-21-1695450602-631600950-3695078651-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.everitt.westernseaboard.co.za/
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: MineimumPuriicee -> {94cacc75-b63b-4184-b361-d80bf18e7619} -> C:\ProgramData\MineimumPuriicee\OqdzQUdY4Rg7CS.dll ()
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 172.16.56.250
Tcpip\..\Interfaces\{9E88E912-13A7-4890-AE64-A50B099A44B0}: [NameServer] 196.7.7.7 196.7.8.9
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\Firefox\Extensions: [freegames4357@BestOffers] - C:\Users\bruce\AppData\Roaming\Mozilla\Extensions\freegames4357@BestOffers

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR DefaultSearchKeyword: Default -> EF0401BE2CE25594A0884EAE54B82B9E4B23AD7CB6A885369D602CDDD3A4D858
CHR DefaultSearchURL: Default -> 453BC05C3BE20B255EC301D6A1325919931B9CF6F1664B9EBA67E7A05F8BBBD1
CHR Profile: C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-28]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-23]
CHR Extension: (YouTube) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-28]
CHR Extension: (Google Search) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-28]
CHR Extension: (Google Wallet) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-28]
CHR Extension: (Gmail) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-28]
CHR Profile: C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-31]
CHR Extension: (Google Docs) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-31]
CHR Extension: (Google Drive) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-31]
CHR Extension: (No Name) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bejnhdlplbjhffionohbdnpcbobfejcc [2014-12-31]
CHR Extension: (YouTube) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-31]
CHR Extension: (Google Search) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-31]
CHR Extension: (Google Sheets) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-31]
CHR Extension: (winnie the pooh) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\golfgdoojafiippacodpnlfkmclpdgmo [2014-12-31]
CHR Extension: (Skype Click to Call) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-12-31]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-12-31]
CHR Extension: (Gmail) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-31]
CHR Extension: (Default-Search) - C:\Users\bruce\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\poimdfnhgefmnkeefbjibbiemlimdnof [2014-12-31]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 BlackBerry Device Manager; C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2014-01-21] (BlackBerry Limited) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] () [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 EMSCR; C:\Windows\System32\DRIVERS\EMS7SK.sys [62208 2013-11-26] (ENE Technology Inc.)
R3 ESDCR; C:\Windows\System32\DRIVERS\ESD7SK.sys [42240 2013-11-26] (ENE Technology Inc.)
R3 ESMCR; C:\Windows\System32\DRIVERS\ESM7SK.sys [76928 2013-11-26] (ENE Technology Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl.sys [18944 2014-08-15] (Apple Inc.) [File not signed]
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb.sys [68096 2013-12-02] (BlackBerry Limited)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2014-08-15] (Apple, Inc.) [File not signed]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-18 17:23 - 2015-02-18 17:24 - 01125888 _____ (Farbar) C:\Users\bruce\Downloads\FRST (2).exe
2015-02-18 17:02 - 2015-02-18 17:03 - 01125888 _____ (Farbar) C:\Users\bruce\Downloads\FRST (1).exe
2015-02-18 16:50 - 2015-02-18 16:50 - 00004406 _____ () C:\Users\bruce\Desktop\fixlist.txt
2015-02-18 14:20 - 2015-02-18 14:29 - 00024950 _____ () C:\Users\bruce\Downloads\Addition.txt
2015-02-18 14:18 - 2015-02-18 17:30 - 00014209 _____ () C:\Users\bruce\Downloads\FRST.txt
2015-02-18 14:17 - 2015-02-18 17:29 - 00000000 ____D () C:\FRST
2015-02-18 14:16 - 2015-02-18 14:17 - 01125888 _____ (Farbar) C:\Users\bruce\Downloads\FRST.exe
2015-02-12 09:39 - 2015-02-12 09:39 - 00002755 _____ () C:\Users\bruce\Downloads\invite.ics
2015-02-12 09:38 - 2015-02-12 09:38 - 00006398 _____ () C:\Users\bruce\Downloads\smime (8).p7s
2015-02-12 08:18 - 2015-01-23 05:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-02-12 08:18 - 2015-01-23 05:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-11 14:27 - 2015-02-18 17:10 - 00000728 _____ () C:\Windows\setupact.log
2015-02-11 14:27 - 2015-02-11 14:27 - 00000000 _____ () C:\Windows\setuperr.log
2015-02-11 14:25 - 2015-02-11 14:25 - 00000000 ____D () C:\Windows\pss
2015-02-11 12:46 - 2015-01-15 09:46 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-11 12:46 - 2015-01-15 09:46 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-11 12:46 - 2015-01-15 09:43 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-02-11 12:46 - 2015-01-15 09:43 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-02-11 12:46 - 2015-01-15 09:42 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-11 12:46 - 2015-01-15 09:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-02-11 12:46 - 2015-01-15 09:42 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-02-11 12:46 - 2015-01-15 09:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-02-11 12:46 - 2015-01-15 09:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-11 12:46 - 2015-01-15 09:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-02-11 12:46 - 2015-01-15 09:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-11 12:46 - 2015-01-15 06:21 - 00369968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-11 12:44 - 2015-01-09 03:45 - 02380288 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-11 12:41 - 2015-01-14 07:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-02-11 12:41 - 2015-01-14 07:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-11 12:40 - 2015-02-04 04:54 - 00482304 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-11 12:40 - 2015-02-04 04:53 - 00767488 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-11 12:40 - 2015-02-04 04:53 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-11 12:40 - 2015-02-04 04:53 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-11 12:40 - 2015-02-04 04:53 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-11 12:40 - 2015-02-04 04:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-02-11 12:40 - 2015-02-04 04:49 - 00886784 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-11 12:40 - 2015-01-28 01:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-02-11 12:40 - 2014-11-26 05:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-11 12:40 - 2014-10-04 03:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-02-11 12:40 - 2014-10-04 03:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-02-11 12:39 - 2015-01-14 07:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-11 12:39 - 2015-01-12 04:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-11 12:39 - 2015-01-12 04:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 12:39 - 2015-01-12 04:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-02-11 12:39 - 2015-01-12 04:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-02-11 12:39 - 2015-01-12 04:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-11 12:39 - 2015-01-12 03:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-02-11 12:39 - 2015-01-12 03:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-11 12:39 - 2015-01-12 03:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-11 12:39 - 2015-01-12 03:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-02-11 12:39 - 2015-01-12 03:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 12:39 - 2015-01-12 03:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-11 12:39 - 2015-01-12 03:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 12:39 - 2015-01-12 03:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-02-11 12:39 - 2015-01-12 03:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-11 12:39 - 2015-01-12 03:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-11 12:39 - 2015-01-12 03:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-11 12:39 - 2015-01-12 03:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-11 12:39 - 2015-01-12 03:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-11 12:39 - 2015-01-12 03:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-11 12:39 - 2015-01-12 02:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-11 12:39 - 2015-01-12 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-02-11 12:39 - 2015-01-10 08:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-02-11 12:38 - 2015-01-12 04:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-11 12:38 - 2015-01-12 04:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-11 12:38 - 2015-01-12 04:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-11 12:38 - 2015-01-12 04:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-11 12:38 - 2015-01-12 03:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-11 12:38 - 2015-01-12 03:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-02-11 12:36 - 2014-12-12 07:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-02-11 12:35 - 2015-01-13 04:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-11 12:35 - 2014-12-08 04:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-11 12:02 - 2015-02-11 12:02 - 00001060 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2015-02-11 12:02 - 2015-02-11 12:02 - 00001048 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2015-02-10 09:29 - 2015-02-10 09:29 - 00012800 _____ () C:\Users\bruce\Downloads\cmainfo (92).xls
2015-02-10 09:26 - 2015-02-10 09:26 - 00011776 _____ () C:\Users\bruce\Downloads\cmainfo (91).xls
2015-02-10 09:23 - 2015-02-10 09:23 - 00009728 _____ () C:\Users\bruce\Downloads\cmainfo (90).xls
2015-02-10 09:19 - 2015-02-10 09:19 - 00009728 _____ () C:\Users\bruce\Downloads\cmainfo (89).xls
2015-02-10 09:15 - 2015-02-10 09:15 - 00008704 _____ () C:\Users\bruce\Downloads\cmainfo (88).xls
2015-01-29 13:23 - 2015-01-29 13:23 - 00007680 _____ () C:\Users\bruce\Downloads\cmainfo (87).xls
2015-01-27 09:29 - 2015-01-27 09:29 - 00612952 _____ () C:\Users\bruce\Downloads\Load Shedding Schedule 12112014.xlsx
2015-01-26 14:08 - 2015-01-26 14:08 - 00254464 _____ () C:\Users\bruce\Desktop\E-Mail List - Feb - March '15.xls
2015-01-26 14:06 - 2015-01-26 14:06 - 00248832 _____ () C:\Users\bruce\Downloads\E-Mail List - Feb - March '15.xls
2015-01-26 14:06 - 2015-01-26 14:06 - 00218624 _____ () C:\Users\bruce\Desktop\Tele List - Feb - March '15.xls
2015-01-26 13:56 - 2015-01-26 13:56 - 00208896 _____ () C:\Users\bruce\Downloads\Tele List - Feb - March '15.xls
2015-01-23 09:38 - 2015-01-23 09:39 - 00000236 _____ () C:\Users\bruce\Downloads\download.htm

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-18 17:26 - 2013-11-28 13:06 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Outlook Files
2015-02-18 17:18 - 2013-11-26 19:45 - 01795132 _____ () C:\Windows\WindowsUpdate.log
2015-02-18 17:18 - 2009-07-14 06:34 - 00033008 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-18 17:18 - 2009-07-14 06:34 - 00033008 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-18 17:11 - 2013-12-03 14:32 - 00000000 ___RD () C:\Users\bruce\Dropbox
2015-02-18 17:11 - 2013-12-03 13:58 - 00000000 ____D () C:\Users\bruce\AppData\Roaming\Dropbox
2015-02-18 17:11 - 2013-11-28 10:15 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-18 17:10 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-18 17:06 - 2014-10-17 12:55 - 00053685 _____ () C:\Users\bruce\Downloads\noname (2).eml
2015-02-18 17:06 - 2014-09-22 10:59 - 00034150 _____ () C:\Users\bruce\Downloads\EL HLB Minnaar The Waves Painting and Waterproofing Specialists.eml
2015-02-18 17:06 - 2014-08-28 09:01 - 00025043 _____ () C:\Users\bruce\Downloads\noname (1).eml
2015-02-18 17:06 - 2014-08-28 08:59 - 00204934 _____ () C:\Users\bruce\Downloads\noname.eml
2015-02-18 17:05 - 2013-11-28 10:15 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-18 16:54 - 2014-04-27 09:17 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-02-18 16:54 - 2013-12-02 14:03 - 00000008 __RSH () C:\Users\bruce\ntuser.pol
2015-02-18 16:54 - 2013-11-26 19:46 - 00000000 ____D () C:\Users\bruce
2015-02-18 16:51 - 2009-07-14 04:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-02-18 13:56 - 2013-11-27 16:36 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\D
2015-02-17 11:29 - 2013-11-27 16:36 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\General
2015-02-16 14:15 - 2013-11-27 16:41 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Recipes
2015-02-16 08:39 - 2013-12-03 14:32 - 00001017 _____ () C:\Users\bruce\Desktop\Dropbox.lnk
2015-02-16 08:39 - 2013-12-03 14:02 - 00000000 ____D () C:\Users\bruce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-15 21:01 - 2014-08-25 17:57 - 00000000 ____D () C:\Users\bruce\AppData\Roaming\vlc
2015-02-15 13:27 - 2009-01-01 00:19 - 00785302 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-13 10:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-02-13 10:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-02-12 12:33 - 2014-05-31 10:39 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Wait Until Dark
2015-02-12 07:55 - 2009-07-14 06:33 - 00409712 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-12 07:53 - 2014-12-11 08:58 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-12 07:53 - 2014-05-06 14:23 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-11 15:58 - 2011-06-17 17:01 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-11 15:58 - 2009-07-14 04:04 - 00000591 _____ () C:\Windows\win.ini
2015-02-11 14:23 - 2013-12-06 13:10 - 00000000 ____D () C:\Users\bruce\AppData\Roaming\Skype
2015-02-11 13:33 - 2014-04-13 13:05 - 00000000 ____D () C:\Program Files\Rockstar Games
2015-02-11 13:33 - 2014-02-27 20:15 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-02-11 13:30 - 2013-12-28 09:37 - 00000000 ____D () C:\Program Files\Microsoft Games
2015-02-11 13:30 - 2013-12-28 09:36 - 00000000 ____D () C:\Users\bruce\AppData\Local\Microsoft Game Studios
2015-02-11 13:30 - 2013-12-28 09:35 - 00000000 ____D () C:\ProgramData\Microsoft Games
2015-02-11 13:30 - 2013-12-28 09:32 - 00000000 ____D () C:\Users\bruce\AppData\Roaming\Microsoft Game Studios
2015-02-11 13:29 - 2014-02-27 20:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2015-02-11 13:27 - 2014-06-15 20:39 - 00000000 ____D () C:\Program Files\Common Files\InstallShield
2015-02-11 13:17 - 2014-02-19 12:11 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-02-11 13:17 - 2014-02-19 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-02-11 13:16 - 2014-02-19 12:10 - 00000000 ____D () C:\Program Files\CCleaner
2015-02-11 13:09 - 2014-12-24 16:29 - 00000000 ____D () C:\Program Files\Driver Pro
2015-02-11 13:09 - 2014-01-21 11:14 - 00000000 ___RD () C:\Users\bruce\Google Drive
2015-02-11 13:03 - 2013-11-28 10:10 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-11 12:47 - 2011-11-15 18:22 - 113756392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-11 12:41 - 2013-12-14 09:26 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-02-11 12:41 - 2013-11-27 09:45 - 00001945 _____ () C:\Windows\epplauncher.mif
2015-02-11 12:40 - 2013-11-27 09:44 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-02-11 11:19 - 2009-07-14 06:53 - 00032644 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-09 13:07 - 2013-11-27 16:38 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Paige
2015-02-05 13:52 - 2014-07-09 11:33 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-03 20:26 - 2013-11-27 16:35 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Camryn
2015-01-29 13:35 - 2014-01-17 12:28 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Chas Everitt
2015-01-23 11:04 - 2014-03-05 11:18 - 00000000 ____D () C:\Users\bruce\Desktop\Documents\Proofs of Payment

==================== Files in the root of some directories =======

2014-01-17 11:55 - 2014-01-17 12:06 - 0038434 _____ () C:\Users\bruce\AppData\Roaming\Comma Separated Values (Windows).ADR
2013-12-02 15:18 - 2014-12-29 10:25 - 0009683 _____ () C:\Users\bruce\AppData\Roaming\Rim.Desktop.Exception.log
2013-12-02 15:08 - 2015-01-14 11:28 - 0002009 _____ () C:\Users\bruce\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2013-12-02 15:18 - 2014-12-29 10:25 - 0003619 _____ () C:\Users\bruce\AppData\Roaming\Rim.DesktopHelper.Exception.log
2014-06-18 10:24 - 2014-12-29 10:25 - 0003234 _____ () C:\Users\bruce\AppData\Roaming\Rim.Transcoder.Exception.log
2013-11-28 11:45 - 2013-11-28 12:33 - 0033193 _____ () C:\Users\bruce\AppData\Roaming\UserTile.png
2014-06-18 10:25 - 2014-06-18 10:27 - 0032256 _____ () C:\Users\bruce\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-09 18:01 - 2014-02-09 18:28 - 0001041 _____ () C:\ProgramData\hpzinstall.log

Some content of TEMP:
====================
C:\Users\bruce\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxpuav2.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-13 10:11

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-02-2015
Ran by bruce at 2015-02-18 17:32:10
Running from C:\Users\bruce\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

8ta connect (HKLM\...\8ta connect) (Version: 16.002.10.02.372 - Huawei Technologies Co.,Ltd)
Adobe Flash Player ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 9.0.124.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
ATI Catalyst Install Manager (HKLM\...\{B274376B-F928-53DE-2B89-563DB3B4BE75}) (Version: 3.0.604.0 - ATI Technologies, Inc.)
BlackBerry Device Software Updater (HKLM\...\{5BF3423C-4397-4FE3-A318-C9850EA24CB3}) (Version: 8.0.0.46 - Research In Motion Ltd)
Blouberg Ridge P (HKLM\...\Blouberg Ridge P_is1) (Version: - D6 Technology)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Branding (Version: 1.00.0000 - Your Company Name) Hidden
ccc-core-static (Version: 0108.2146.2565.38893 - ATI) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.02 - Piriform)
Dropbox (HKU\S-1-5-21-1695450602-631600950-3695078651-1002\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.)
EA Download Manager (Version: 4.0.0.462 - Electronic Arts) Hidden
Google Chrome (HKLM\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Drive (HKLM\...\{C60F3836-333A-4AE2-B526-CFDBA143A9BA}) (Version: 1.18.7821.2489 - Google, Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
PIXresizer 2.0.3 (HKLM\...\PIXresizer_is1) (Version: - Bluefive software)
Samsung Kies3 (HKLM\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14113.3 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (Version: 3.2.14113.3 - Samsung Electronics Co., Ltd.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Skins (Version: 0108.2146.2565.38893 - ATI) Hidden
Skype Click to Call (HKLM\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
SkypEmoticons (HKLM\...\SkypEmoticons_is1) (Version: - ) <==== ATTENTION
Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 9.1.0.0 - Synaptics)
Table View High School (HKLM\...\Table View High School_is1) (Version: - D6 Technology)
TeamViewer 9 (HKLM\...\TeamViewer 9) (Version: 9.0.38846 - TeamViewer)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1695450602-631600950-3695078651-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\bruce\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)

==================== Restore Points =========================

11-02-2015 12:36:39 Windows Update
11-02-2015 13:10:16 Removed Free YouTube Downloader Converter
11-02-2015 13:24:54 Removed GTA San Andreas
11-02-2015 13:27:13 Removed GTAIII
11-02-2015 13:28:16 Removed Halo 2 Dedicated Server
11-02-2015 13:29:45 Removed Halo 2 for Windows Vista
11-02-2015 13:31:06 Removed LIVE gaming on Windows Runtime Version 1.0.6027
11-02-2015 13:33:00 Removed Rockstar Games Social Club
11-02-2015 13:34:24 Removed Need for Speed™ Undercover
11-02-2015 15:54:09 Windows Update
12-02-2015 15:09:04 Windows Update
16-02-2015 09:04:44 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {2FFA1FB7-2FF6-4881-A3F9-58A5F26D3CAA} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {4378151F-97D3-4894-85CC-41572FF75AD9} - System32\Tasks\Adobe online update program => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {5BC2A1B6-B47B-44EE-98CA-2596E1ED1521} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-28] (Google Inc.)
Task: {60C17A4E-1689-49BC-A386-EFFDB13B6768} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-28] (Google Inc.)
Task: {74EB13A7-B729-480A-948F-9669DCB7E8B4} - System32\Tasks\{146D86D5-A264-4A9B-B192-7C68A69AFED1} => pcalua.exe -a D:\setup.EXE -d D:\
Task: {9BDD794D-8BAB-4DD9-83DD-B735FE8AF8AB} - System32\Tasks\{5CBF8717-6DFE-45CB-9F39-579C6720FE9E} => pcalua.exe -a "C:\Users\bruce\Downloads\msg (1).exe" -d C:\Users\bruce\Downloads
Task: {B1B9A982-2020-4E75-B98E-722BCABFF198} - System32\Tasks\{3624D882-D548-4A11-AB84-6F1E0084CF8A} => pcalua.exe -a C:\Users\bruce\Desktop\WDM_R273.exe -d C:\Users\bruce\Desktop
Task: {C1525484-FFE7-4AD2-BBDE-8AB6909A9CBF} - System32\Tasks\DTReg => C:\Windows\system32\config\systemprofile\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe <==== ATTENTION
Task: {D302B9BA-A1EB-41D8-B81E-FD8CCC380ABD} - System32\Tasks\{2D6EC121-F0E2-4BD8-9D7A-51430B9C699A} => pcalua.exe -a C:\Users\bruce\Downloads\spurgeon.exe -d C:\Users\bruce\Downloads
Task: {DE03ABF3-12FB-45D5-BDF1-E8BF097360B8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-01-20] (Piriform Ltd)
Task: {EB2BFE77-EC4F-41D8-8217-B917F46251E1} - System32\Tasks\{9653D9F2-4B0E-4DDC-BBCB-E3A2746CC179} => pcalua.exe -a C:\Users\bruce\Desktop\WDM_R273[1].exe -d C:\Users\bruce\Desktop
Task: {F02D9A3A-E7FD-4BA4-B389-AA956D95B061} - System32\Tasks\{1FBCCBC5-26D6-4256-A97A-1D306B14035C} => pcalua.exe -a "E:\8ta connect\setup.exe" -d "E:\8ta connect"
Task: {F4A1C541-4248-4B1A-AE9E-959211993613} - System32\Tasks\{2EEF9EAD-0D1C-4625-93EA-77138D17CEA9} => pcalua.exe -a C:\Users\bruce\Downloads\pnt.exe -d C:\Users\bruce\Downloads
Task: {F9FBE49E-244C-48FA-9568-2D64EDAB9600} - System32\Tasks\{BEE6B2F2-0671-4EB0-BEEB-560618C5BA3F} => pcalua.exe -a D:\Install.exe -d D:\
Task: {FC8D3C8D-80CD-431F-A8C7-54414389FE74} - System32\Tasks\{210FA47C-AFA2-48D8-8FE5-257237689B2B} => pcalua.exe -a D:\setup.exe -d D:\

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2010-05-08 13:48 - 2010-05-08 13:48 - 00229376 _____ () C:\ProgramData\DatacardService\DCService.exe
2015-02-10 23:00 - 2015-02-10 23:00 - 00750080 _____ () C:\Users\bruce\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-02-18 17:11 - 2015-02-18 17:11 - 00043008 _____ () c:\users\bruce\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxpuav2.dll
2015-02-10 23:00 - 2015-02-10 23:00 - 00047616 _____ () C:\Users\bruce\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-02-10 23:00 - 2015-02-10 23:00 - 00865280 _____ () C:\Users\bruce\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-02-10 23:00 - 2015-02-10 23:00 - 00200704 _____ () C:\Users\bruce\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-02-14 15:46 - 2013-02-14 15:46 - 01044048 _____ () C:\Program Files\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2014-12-20 10:49 - 2014-12-06 03:50 - 09009480 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.95\pdf.dll
2014-12-20 10:49 - 2014-12-06 03:50 - 01677128 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll
2014-12-20 10:49 - 2014-12-06 03:50 - 14913352 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\bruce\Downloads\EL HLB Minnaar The Waves Painting and Waterproofing Specialists.eml:OECustomProperty
AlternateDataStreams: C:\Users\bruce\Downloads\noname (1).eml:OECustomProperty
AlternateDataStreams: C:\Users\bruce\Downloads\noname (2).eml:OECustomProperty
AlternateDataStreams: C:\Users\bruce\Downloads\noname.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1695450602-631600950-3695078651-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\bruce\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 172.16.56.250

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Shortcut to BackInfo.exe.lnk => C:\Windows\pss\Shortcut to BackInfo.exe.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^bruce^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CCC.lnk => C:\Windows\pss\CCC.lnk.Startup
MSCONFIG\startupfolder: C:^Users^bruce^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: d6_6699 => C:\Program Files\D6 Technology\d6_6699\d6\d6_6699.exe
MSCONFIG\startupreg: d6_6892 => C:\Program Files\D6 Technology\d6_6892\d6\d6_6892.exe
MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
MSCONFIG\startupreg: iLivid => "C:\Users\bruce\AppData\Local\iLivid\iLivid.exe" -autorun
MSCONFIG\startupreg: mobilegeni daemon => C:\Program Files\Mobogenie\DaemonProcess.exe
MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
MSCONFIG\startupreg: RIMBBLaunchAgent.exe => C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
MSCONFIG\startupreg: se => "C:\Users\bruce\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: StartCCC => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
MSCONFIG\startupreg: SynTPEnh => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

==================== Accounts: =============================

Administrator (S-1-5-21-1695450602-631600950-3695078651-500 - Administrator - Disabled)
bruce (S-1-5-21-1695450602-631600950-3695078651-1002 - Administrator - Enabled) => C:\Users\bruce
Guest (S-1-5-21-1695450602-631600950-3695078651-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1695450602-631600950-3695078651-1004 - Limited - Enabled)

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/11/2015 01:13:46 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: bruce-PC)
Description: Application or service 'YouTubeDownloaderConverter' could not be restarted.

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7813

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7813

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 74563062

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 74563062

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/06/2015 01:08:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8015

Error: (02/06/2015 01:08:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8015

Error: (02/06/2015 01:08:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


System errors:
=============
Error: (02/18/2015 05:06:42 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
%%1056

Error: (02/18/2015 05:06:37 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (02/18/2015 05:06:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Modules Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

Error: (02/18/2015 05:06:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (02/18/2015 05:06:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (02/18/2015 05:06:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (02/18/2015 05:05:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Interactive Services Detection service terminated unexpectedly. It has done this 1 time(s).

Error: (02/18/2015 05:05:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

Error: (02/18/2015 05:05:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Office Software Protection Platform service terminated unexpectedly. It has done this 1 time(s).

Error: (02/18/2015 05:05:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s).


Microsoft Office Sessions:
=========================
Error: (02/11/2015 01:13:46 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: bruce-PC)
Description: 0CertifiedBrowserService.exeYouTubeDownloaderConverter0302621783720

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7813

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7813

Error: (02/07/2015 10:01:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 74563062

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 74563062

Error: (02/07/2015 09:50:20 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/06/2015 01:08:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8015

Error: (02/06/2015 01:08:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8015

Error: (02/06/2015 01:08:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


==================== Memory info ===========================

Processor: Mobile AMD Sempron(tm) Processor 3500+
Percentage of memory in use: 62%
Total physical RAM: 1278.17 MB
Available physical RAM: 482.43 MB
Total Pagefile: 2556.34 MB
Available Pagefile: 1353.74 MB
Total Virtual: 2047.88 MB
Available Virtual: 1920.77 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.48 GB) (Free:294.38 GB) NTFS
Drive z: () (Network) (Total:465.42 GB) (Free:375.35 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3E78BA79)
Partition 1: (Active) - (Size=283 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.5 GB) - (Type=07 NTFS)

==================== End Of Log ============================
 
Very good.

Chrome installation is altered by malware. Reinstall is needed.

Close all Chrome windows and tabs.
Go to the Start menu > Control Panel.
Click Programs and Features.
Double-click Google Chrome.
Click Uninstall from the confirmation dialog. Delete your user profile information, like your browser preferences, bookmarks, and history, select the "Also delete your browsing data" checkbox.


Download and install new Chrome
https://www.google.com/intl/en/chrome/browser/desktop/
 
We will delete all used tools.

Download DelFix by Xplode and save it to your desktop.
  • Run the tool by right click on the
    51a5ce45263de-delfix.png
    icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run and wait until the tool completes his work.
  • All tools we used should be gone. Tool will create an report for you (C:\DelFix.txt)
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
 
Hi Argus

Thank you so much for sorting out this problem for me - I am very grateful!!!

Have a great day! Below is the report from DelFix.

Kind regards

Bruce (Sandyman)

# DelFix v10.8 - Logfile created 19/02/2015 at 08:24:42
# Updated 29/07/2014 by Xplode
# Username : bruce - BRUCE-PC
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\Users\bruce\Downloads\Addition.txt
Deleted : C:\Users\bruce\Downloads\Fixlog.txt
Deleted : C:\Users\bruce\Downloads\FRST (1).exe
Deleted : C:\Users\bruce\Downloads\FRST (2).exe
Deleted : C:\Users\bruce\Downloads\FRST.exe
Deleted : C:\Users\bruce\Downloads\FRST.txt

~ Cleaning system restore ...

Deleted : RP #238 [Windows Update | 02/11/2015 10:36:39]
Deleted : RP #239 [Removed Free YouTube Downloader Converter | 02/11/2015 11:10:16]
Deleted : RP #241 [Removed GTA San Andreas | 02/11/2015 11:24:54]
Deleted : RP #243 [Removed GTAIII | 02/11/2015 11:27:13]
Deleted : RP #245 [Removed Halo 2 Dedicated Server | 02/11/2015 11:28:16]
Deleted : RP #246 [Removed Halo 2 for Windows Vista | 02/11/2015 11:29:45]
Deleted : RP #247 [Removed LIVE gaming on Windows Runtime Version 1.0.6027 | 02/11/2015 11:31:06]
Deleted : RP #248 [Removed Rockstar Games Social Club | 02/11/2015 11:33:00]
Deleted : RP #249 [Removed Need for Speed™ Undercover | 02/11/2015 11:34:24]
Deleted : RP #250 [Windows Update | 02/11/2015 13:54:09]
Deleted : RP #251 [Windows Update | 02/12/2015 13:09:04]
Deleted : RP #252 [Windows Update | 02/16/2015 07:04:44]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top