Ask, keeps overpowering google on one site only cant stop it!

Page 1 of 2 1, 2  Next

View previous topic View next topic Go down

Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Wed 27 Nov 2013, 9:16 am

i'm new and hpoe this is where I'm suposed to post it . this is what Shows up in adwCleaner

# AdwCleaner v3.013 - Report created 26/11/2013 at 15:09:50
# Updated 24/11/2013 by Xplode
# Operating System : Windows (TM) Vista Business Service Pack 2 (64 bits)
# Username : myComputer - MYCOMPUTER-PC
# Running from : C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\adwcleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : SafetyNutManager

***** [ Files / Folders ] *****

File Found : C:\END
Folder Found C:\Program Files (x86)\adawaretb
Folder Found C:\Program Files (x86)\Conduit
Folder Found C:\Program Files (x86)\Movies Toolbar
Folder Found C:\Program Files (x86)\Toolbar Cleaner
Folder Found C:\ProgramData\BitGuard
Folder Found C:\ProgramData\blekko toolbars
Folder Found C:\ProgramData\Browser Manager
Folder Found C:\ProgramData\BrowserProtect
Folder Found C:\ProgramData\SafetyNut
Folder Found C:\ProgramData\VisualBee
Folder Found C:\ProgramData\wincert
Folder Found C:\Users\myComputer\AppData\Local\Conduit
Folder Found C:\Users\myComputer\AppData\Local\torch
Folder Found C:\Users\myComputer\AppData\Local\visualbeeexe
Folder Found C:\Users\myComputer\AppData\LocalLow\adawaretb
Folder Found C:\Users\myComputer\AppData\LocalLow\Conduit
Folder Found C:\Users\myComputer\AppData\LocalLow\iac
Folder Found C:\Users\myComputer\AppData\LocalLow\PriceGong
Folder Found C:\Users\myComputer\AppData\Roaming\DriverCure

***** [ Shortcuts ] *****


***** [ Registry ] *****

Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\MOVIES~1\SAFETY~1\SAFETY~2.DLL
Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~3\Wincert\WIN32C~1.DLL
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\MOVIES~1\SAFETY~1\x64\SAFETY~2.DLL
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~3\Wincert\WIN64C~1.DLL
Key Found : HKCU\Software\AppDataLow\Software\adawaretb
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\Classes\pokki
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\ilivid
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{52DB1893-8A90-4192-AEDE-08E00B8F8484}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\adawaretb
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Found : HKCU\Software\SafetyNut
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\torch
Key Found : HKCU\Software\visualbee
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\ilivid
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{52DB1893-8A90-4192-AEDE-08E00B8F8484}
Key Found : [x64] HKCU\Software\SafetyNut
Key Found : [x64] HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\torch
Key Found : [x64] HKCU\Software\visualbee
Key Found : HKLM\Software\adawaretb
Key Found : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Found : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Key Found : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Classes\MoviesToolbarHelper.DNSGuard
Key Found : HKLM\SOFTWARE\Classes\MoviesToolbarHelper.DNSGuard.1
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3282137
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3287822
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3292575
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3297986
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52DB1893-8A90-4192-AEDE-08E00B8F8484}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cltmngsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
Key Found : HKLM\Software\SafetyNut
Key Found : HKLM\Software\Toolbar Cleaner
Key Found : HKLM\Software\torch
Key Found : HKLM\Software\visualbee
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52DB1893-8A90-4192-AEDE-08E00B8F8484}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x86]

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16520


-\\ Google Chrome v

[ File : C:\Users\myComputer\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found : homepage
Found : urls_to_restore_on_startup
Found : homepage
Found : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [9158 octets] - [26/11/2013 15:09:50]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [9218 octets] ##########

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by Superdave on Thu 28 Nov 2013, 6:39 am

Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*****************************************************************
Remove the Adware:

  • Please close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with OK
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.

*********************************************
Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
*************************************************
Please download Junkware Removal Tool to your desktop.

Warning! Once the scan is complete JRT will shut down your browser with NO warning.

Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
*****************************************
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Thu 28 Nov 2013, 9:50 am

Thanks for the help. I'm doing things one step at a time in the order you wrote the# AdwCleaner v3.013 - Report created 27/11/2013 at 15:42:28
# Updated 24/11/2013 by Xplode
# Operating System : Windows (TM) Vista Business Service Pack 2 (64 bits)
# Username : myComputer - MYCOMPUTER-PC
# Running from : C:\Users\myComputer\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

[!] Folder Deleted : C:\ProgramData\BitGuard
[!] Folder Deleted : C:\ProgramData\blekko toolbars
[!] Folder Deleted : C:\ProgramData\Browser Manager
[!] Folder Deleted : C:\ProgramData\BrowserProtect
[!] Folder Deleted : C:\ProgramData\VisualBee
[!] Folder Deleted : C:\ProgramData\wincert
[!] Folder Deleted : C:\Program Files (x86)\adawaretb
[!] Folder Deleted : C:\Program Files (x86)\Conduit
[!] Folder Deleted : C:\Program Files (x86)\Movies Toolbar
[!] Folder Deleted : C:\Program Files (x86)\Toolbar Cleaner
[!] Folder Deleted : C:\Program Files (x86)\TornTV.com
[!] Folder Deleted : C:\Users\myComputer\AppData\Local\Conduit
[!] Folder Deleted : C:\Users\myComputer\AppData\Local\torch
[!] Folder Deleted : C:\Users\myComputer\AppData\Local\visualbeeexe
[!] Folder Deleted : C:\Users\myComputer\AppData\LocalLow\adawaretb
[!] Folder Deleted : C:\Users\myComputer\AppData\LocalLow\Conduit
[!] Folder Deleted : C:\Users\myComputer\AppData\LocalLow\iac
[!] Folder Deleted : C:\Users\myComputer\AppData\LocalLow\PriceGong
[!] Folder Deleted : C:\Users\myComputer\AppData\Roaming\DriverCure
[!] Folder Deleted : C:\Users\myComputer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Classes\pokki
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Key Deleted : HKLM\SOFTWARE\Classes\MoviesToolbarHelper.DNSGuard
Key Deleted : HKLM\SOFTWARE\Classes\MoviesToolbarHelper.DNSGuard.1
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cltmngsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3282137
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3287822
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3292575
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3297986
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{52DB1893-8A90-4192-AEDE-08E00B8F8484}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52DB1893-8A90-4192-AEDE-08E00B8F8484}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52DB1893-8A90-4192-AEDE-08E00B8F8484}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\SafetyNut
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\torch
Key Deleted : HKCU\Software\visualbee
Key Deleted : HKCU\Software\AppDataLow\Software\adawaretb
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\adawaretb
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\SafetyNut
Key Deleted : HKLM\Software\Toolbar Cleaner
Key Deleted : HKLM\Software\torch
Key Deleted : HKLM\Software\visualbee
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\adawaretb
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~3\Wincert\WIN64C~1.DLL
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\MOVIES~1\SAFETY~1\x64\SAFETY~2.DLL

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16520


-\\ Google Chrome v

[ File : C:\Users\myComputer\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [9346 octets] - [26/11/2013 15:09:50]
AdwCleaner[R1].txt - [9452 octets] - [27/11/2013 15:40:28]
AdwCleaner[S0].txt - [8698 octets] - [27/11/2013 15:42:28]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8758 octets] ##########
m. Here is the the log/file

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Thu 28 Nov 2013, 11:57 am

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
[You must be registered and logged in to see this link.]

Database version: v2013.04.13.04

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
myComputer :: MYCOMPUTER-PC [administrator]

Protection: Enabled

4/13/2013 9:17:28 AM
mbam-log-2013-04-13 (09-17-28).txt

Scan type: Full scan (C:\|E:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 305150
Time elapsed: 26 minute(s), 8 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Thu 28 Nov 2013, 2:24 pm

When I click on Security Check by screen317 I get a black screen that says to press any key to continue, arter pressing
a key it says it has been aborted.

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Thu 28 Nov 2013, 2:28 pm

You have gortten rid of the Ask.com search eng. it no longer shows takes over from google,however now instead of the ask.com coming up in a google search, google can not find the site,instead I get the symbol and words that mean I'm no longer on the internet. My daughters pc still can find the site with google like always.

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Thu 28 Nov 2013, 2:44 pm

I just deleted malwarebytes temporarilly and ran Security Check by screen317 again .this is what I got .
Results of screen317's Security Check version 0.99.77
Windows Vista Service Pack 2 x64 (UAC is enabled)
Internet Explorer 9
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 45
Adobe Reader 10.1.8 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
Windows Defender MSASCui.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
Windows Defender MSASCui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 3 % Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by Superdave on Fri 29 Nov 2013, 4:56 am

Looking over your log it seems you don't have any antivirus software.

Before we continue download and install a free antivirus.

Remember to only install one antivirus!

1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) MicroSoft Security Essentials All versions and all languages.
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.
*********************************************
Please defrag you harddrive soon. (SSD means Solid State Drive)

Please download Rooter and Save it to your desktop.

  • Double click it to start the tool.Vista and Windows7 run as administrator.
  • Click Scan.
  • Eventually, a Notepad file containing the report will open, also found at C:\Rooter.txt. Post that log in your next reply.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Fri 29 Nov 2013, 12:04 pm

Thank You Dave. I just installed AVG as you said.
In your first note to me you said not to run any scans etc. I have installed AVG but not done a scan. Should I do one?

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by Superdave on Fri 29 Nov 2013, 12:37 pm

Please run the Junkware Removal tool and post the log.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.

•Check
•Click the button.
•Accept any security warnings from your browser.

  • Leave the check mark next to Remove found threats.

•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Fri 29 Nov 2013, 2:36 pm

This is the results of the jrt scan

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows (TM) Vista Business x64
Ran by myComputer on Thu 11/28/2013 at 19:44:52.07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 11/28/2013 at 19:50:11.44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Fri 29 Nov 2013, 4:15 pm

Scan Log
Version of virus signature database: 9109 (20131128)
Date: 11/28/2013 Time: 9:04:28 PM
Scanned disks, folders and files: C:\
C:\hiberfil.sys - error opening [4]
C:\pagefile.sys - error opening [4]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\adawareDx.dll.vir - a variant of Win32/Toolbar.Visicom.B potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\adawaretb.dll.vir - a variant of Win32/Toolbar.Visicom.A potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\dtUser.exe.vir - a variant of Win32/Toolbar.Visicom.C potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\Helper.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\safetyldr.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\safetyldr_u.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\x64\safetyldr.dll.vir - a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\x64\safetyldr_u.dll.vir - a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Users\myComputer\AppData\Local\torch\User Data\Default\Cache\f_000001.vir » GZIP - is OK (internal scanning not performed)
C:\AdwCleaner\Quarantine\C\Users\myComputer\AppData\Local\torch\User Data\Default\Cache\f_000002.vir » GZIP - is OK (internal scanning not performed)
C:\AdwCleaner\Quarantine\C\Users\myComputer\AppData\Local\torch\User Data\Default\Cache\f_000005.vir » GZIP - is OK (internal scanning not performed)
C:\Program Files\ESET\ESET NOD32 Antivirus\eset.chm » CHM - is OK (internal scanning not performed)
C:\Program Files\Vuze\Azureus2.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\bunndle.zip » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\swt.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\.install4j\i4jruntime.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\.install4j\user.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\alt-rt.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\alt-string.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\charsets.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\deploy.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\jce.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\jsse.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\management-agent.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\plugin.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\resources.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\rt.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\deploy\ffjcext.zip » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\ext\dns_sd.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\ext\dnsns.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\ext\localedata.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\ext\sunjce_provider.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\ext\sunmscapi.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\im\indicim.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\im\thaiim.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\security\local_policy.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\security\US_export_policy.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azitunes\azitunes_0.3.1.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azitunes\jacob_1.17.2.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azitunes\libProcessAccess_0.1.3.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azplugins\azplugins_2.1.6.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azplugins\azplugins_2.1.7.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azrating\azrating_1.3.1.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azupdater\azupdaterpatcher_1.8.17.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azupdater\Updater.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azupnpav\azupnpav_0.4.4.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azupnpav\azupnpav_0.4.6.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azupnpav\azupnpav_0.4.7.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Windows Media Player\Skins\Revert.wmz » ZIP - is OK (internal scanning not performed)
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\DEXEchoSign.spi » ZIP - is OK (internal scanning not performed)
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\DEXShare.spi » ZIP - is OK (internal scanning not performed)
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg » ZIP - is OK (internal scanning not performed)
C:\Program Files (x86)\AVG\AVG2014\avgdg_us.chm » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\AVG\AVG2014\avgf_us.chm » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\AVG\AVG2014\avgls_us.chm » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\AVG\AVG2014\js.dat » CAB - is OK (internal scanning not performed)
C:\Program Files (x86)\AVG\AVG2014\banners\banners.zip » ZIP - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\CS\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\DA\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\DE\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\EL\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\EN\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\ES\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\FI\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\FR\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\HU\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\ID\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\IT\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\JP\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\KO\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\NL\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\NO\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\PL\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\PT\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\RU\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\SC\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\SV\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\TC\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\TH\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\TR\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarHelper_signed.msi » MSI - is OK (internal scanning not performed)
C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.chm » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\chameleon.chm » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\VideoLAN\VLC\skins\default.vlt » GZIP - is OK (internal scanning not performed)
C:\ProgramData\Adobe\ARM\Reader_10.1.6\AdobeARM.bin » 7ZIP - is OK (internal scanning not performed)
C:\ProgramData\Adobe\ARM\Reader_10.1.6\ARM.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\Adobe\ARM\Reader_10.1.6\Reader10Manifest.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AA1000000001}\AcroRead.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AA1000000001}\Data1.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\AntiRka.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\Antivira.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\Avgx64.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\base2a.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\basea.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\COREa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\COREx64.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\Emailsa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\GUIa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\IDPa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\lng_usa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\ResShlda.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\SrchSrfa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\SSHttpBa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\TDIDrva.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\TuneUpa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\Updatea.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\Downloaded Installations\{F075020E-43B2-4F2C-9723-C81CE162E7B6}\6b807045-53e5-49a1-8a7a-3af210c0b686\bafd8c5e-7324-4659-8719-fdcb010084da.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\ESET\ESET NOD32 Antivirus\Installer\3f7.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ar\a49df2b4-ae4f-486c-9e4e-31b2900b20d8.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\cs\08e75736-78a7-43e1-b63c-9f2814526d3d.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\da\b8a18584-cd8f-4268-b468-5b263bd4616b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\de\60fc900c-1b1e-4d90-99f3-ad06e134128b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\el\19ca6d9e-77d4-43e5-93ea-c4484a9fea8f.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\en\f873c895-065a-4eb5-a2c0-243b74ae0127.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\en-US\670add03-954d-4bf1-96cb-a0a00d51b423.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\es\3a15cbe1-10b3-40e3-99d3-047745360684.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\fi\3adb9d9e-258d-4e8e-99c1-b555f31b8064.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\fr\9d9d5a2e-2de3-400a-bd3a-399dbf7beb56.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\he\d52cb5fd-39dc-46a7-b7e1-fbb37312baa8.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\hu\4c9965f4-b86c-4ea3-b282-d50b41d82e24.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\it\4c1f18dd-10fd-4fbe-a04f-1e118e042431.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ja\0b6540df-217f-4a8d-adff-a6671ac175b7.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ko\62a730f9-7801-4cdf-b5b1-d2c73b2f7b7b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\nb\4900d51e-0dd0-4ad0-a789-a3a9a3f61eed.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\nl\01163500-5409-40bf-9a0e-e958817e4a08.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\pl\e6d83363-070d-4b86-b369-cc461f32dd7a.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\pt\40bd21c0-1b6d-4cb7-9c66-4e54993ceebc.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ru\be091111-5413-4448-8ab0-d3baaaad11bb.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\sv\e47753e9-a50b-4da4-868f-2e0519d7cb1e.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\tr\ba21126f-e4e9-4def-a9d6-b2a8ecf1d0fb.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\zh-CN\53e27d45-71fe-4bb4-81ae-90136385005c.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\zh-TW\208652e3-ad1a-43dc-9768-d7552dcf6cc1.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1025\1025.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1026\1026.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1028\1028.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1029\1029.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1030\1030.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1031\1031.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1032\1032.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1033\1033.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1034\1034.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1035\1035.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1036\1036.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1037\1037.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1038\1038.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1040\1040.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1041\1041.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1042\1042.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1043\1043.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1044\1044.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1045\1045.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1046\1046.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1048\1048.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1049\1049.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1050\1050.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1051\1051.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1053\1053.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1054\1054.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1055\1055.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1057\1057.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1060\1060.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1061\1061.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1062\1062.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1063\1063.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\2052\2052.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\MFAData\setup_tp.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\MFAData\pack\Avgx64.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log - error opening [4]
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log - error opening [4]
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb - error opening [4]
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb - error opening [4]
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report155e6cb8\Report.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\Skype.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeToolbars.msi » MSI - is OK (internal scanning not performed)
C:\System Volume Information\{00eb3faf-57de-11e3-9ca9-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{00eb3fc3-57de-11e3-9ca9-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{00eb3fc7-57de-11e3-9ca9-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{0836bc44-56fa-11e3-b890-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{12e9f942-58a4-11e3-8fc6-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{12e9f946-58a4-11e3-8fc6-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{12e9f94a-58a4-11e3-8fc6-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{12e9f94e-58a4-11e3-8fc6-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{20115774-5659-11e3-b979-9e4da3e1b7be}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{2011577e-5659-11e3-b979-9e4da3e1b7be}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{20115784-5659-11e3-b979-9e4da3e1b7be}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{5e8d946e-5639-11e3-938a-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{5e8d9472-5639-11e3-938a-b06e2274047b}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{5e8d9476-5639-11e3-938a-b06e2274047b}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{5e8d947a-5639-11e3-938a-b06e2274047b}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{652a2cac-5647-11e3-92b6-cdc054e3d695}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{af16f3b0-551d-11e3-b5d6-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{ba6df4ac-578d-11e3-a913-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\Users\All Users\Adobe\ARM\Reader_10.1.6\AdobeARM.bin » 7ZIP - is OK (internal scanning not performed)
C:\Users\All Users\Adobe\ARM\Reader_10.1.6\ARM.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Adobe\ARM\Reader_10.1.6\Reader10Manifest.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AA1000000001}\AcroRead.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AA1000000001}\Data1.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\AntiRka.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\Antivira.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\Avgx64.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\base2a.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\basea.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\COREa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\COREx64.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\Emailsa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\GUIa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\IDPa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\lng_usa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\ResShlda.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\SrchSrfa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\SSHttpBa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\TDIDrva.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\TuneUpa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\Updatea.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\Downloaded Installations\{F075020E-43B2-4F2C-9723-C81CE162E7B6}\6b807045-53e5-49a1-8a7a-3af210c0b686\bafd8c5e-7324-4659-8719-fdcb010084da.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\ESET\ESET NOD32 Antivirus\Installer\3f7.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ar\a49df2b4-ae4f-486c-9e4e-31b2900b20d8.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\cs\08e75736-78a7-43e1-b63c-9f2814526d3d.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\da\b8a18584-cd8f-4268-b468-5b263bd4616b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\de\60fc900c-1b1e-4d90-99f3-ad06e134128b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\el\19ca6d9e-77d4-43e5-93ea-c4484a9fea8f.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\en\f873c895-065a-4eb5-a2c0-243b74ae0127.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\en-US\670add03-954d-4bf1-96cb-a0a00d51b423.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\es\3a15cbe1-10b3-40e3-99d3-047745360684.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\fi\3adb9d9e-258d-4e8e-99c1-b555f31b8064.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\fr\9d9d5a2e-2de3-400a-bd3a-399dbf7beb56.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\he\d52cb5fd-39dc-46a7-b7e1-fbb37312baa8.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\hu\4c9965f4-b86c-4ea3-b282-d50b41d82e24.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\it\4c1f18dd-10fd-4fbe-a04f-1e118e042431.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ja\0b6540df-217f-4a8d-adff-a6671ac175b7.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ko\62a730f9-7801-4cdf-b5b1-d2c73b2f7b7b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\nb\4900d51e-0dd0-4ad0-a789-a3a9a3f61eed.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\nl\01163500-5409-40bf-9a0e-e958817e4a08.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\pl\e6d83363-070d-4b86-b369-cc461f32dd7a.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\pt\40bd21c0-1b6d-4cb7-9c66-4e54993ceebc.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ru\be091111-5413-4448-8ab0-d3baaaad11bb.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\sv\e47753e9-a50b-4da4-868f-2e0519d7cb1e.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\tr\ba21126f-e4e9-4def-a9d6-b2a8ecf1d0fb.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\zh-CN\53e27d45-71fe-4bb4-81ae-90136385005c.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\zh-TW\208652e3-ad1a-43dc-9768-d7552dcf6cc1.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1025\1025.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1026\1026.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1028\1028.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1029\1029.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1030\1030.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1031\1031.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1032\1032.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1033\1033.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1034\1034.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1035\1035.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1036\1036.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1037\1037.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1038\1038.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1040\1040.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1041\1041.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1042\1042.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1043\1043.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1044\1044.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1045\1045.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1046\1046.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1048\1048.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1049\1049.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1050\1050.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1051\1051.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1053\1053.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1054\1054.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1055\1055.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1057\1057.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1060\1060.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1061\1061.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1062\1062.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1063\1063.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\2052\2052.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\MFAData\setup_tp.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\MFAData\pack\Avgx64.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\MSS.log - error opening [4]
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\MSStmp.log - error opening [4]
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\tmp.edb - error opening [4]
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb - error opening [4]
C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report155e6cb8\Report.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\Skype.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeToolbars.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\ntuser.dat - error opening [4]

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Fri 29 Nov 2013, 4:21 pm

the log was to long to send at once. I'm sending the second half now.
:\Users\All Users\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\Skype.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeToolbars.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\ntuser.dat - error opening [4]
C:\Users\myComputer\ntuser.dat.LOG1 - error opening [4]
C:\Users\myComputer\ntuser.dat.LOG2 - error opening [4]
C:\Users\myComputer\AppData\Local\Downloaded Installations\{4D0FF23C-E8F9-4AC8-B28C-93044A6ABC78}\Ad-Aware Antivirus.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000001 » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000002 » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000003 » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000004 » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Update\1.3.21.165\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Update\Download\{D0AB2EBC-931B-4013-9FEB-C9C4C2225C8C}\4.9.1.16010\googletalkpluginaccel.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{228C12F2-58A6-11E3-8FC6-90FBA616BA97}.dat - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{228C12F3-58A6-11E3-8FC6-90FBA616BA97}.dat - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3A57218F-58AB-11E3-8FC6-90FBA616BA97}.dat - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Windows\UsrClass.dat - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\469CD4XZ\GetContent[1].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\469CD4XZ\GetContent[2].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\favicon[4].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\GetContent[1].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\GetContent[2].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\msgr11us.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ProgramFilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\msgr11us.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\OnlineScanner[1].cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » vcredist_x86.exe » CAB » vcredis1.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » vcredist_x86.exe » CAB » vcredist.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » applause_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » applause_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » beep_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » beep_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » belch_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » belch_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » bomb_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » bomb_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » brokenglass_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » brokenglass_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » cough_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » cough_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » cow_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » cow_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » drumroll_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » drumroll_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » grouplaff_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » grouplaff_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » guitar_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » guitar_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » moan_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » moan_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » ooh_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » ooh_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » scream_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » scream_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » trombone_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » trombone_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\GetContent[1].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\GetContent[2].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\GetContent[3].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\GetContent[4].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\GetContent[5].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\msgr11ca.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ProgramFilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\msgr11ca.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\onlinescan[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\Safe+Haven+28201329+720p+BrRip+x264+-+YIFY.exe - a variant of Win32/4Shared.K potentially unwanted application - action selection postponed until scan completion
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\store[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\ytb_setup_9_1_0_18_3_1_0[1] » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\ytb_setup_9_1_0_18_3_1_0[1] » NSIS » ytb_setup.exe » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\ytb_setup_9_1_0_18_3_1_0[1] » NSIS » ytoolbar.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\ActivateService[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\GetContent[1].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\GetContent[2].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\GetContent[3].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\GetContent[4].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\GetContent[5].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » aucheck - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » jaureg - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » jucheck - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » jusched - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » task.xml - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » task64.xml - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\msgr11us.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ProgramFilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\msgr11us.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK63WLFV\GetContent[1].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK63WLFV\GetContent[2].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK63WLFV\msgr11ca.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ProgramFilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK63WLFV\msgr11ca.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\058F5TXD\Boots[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\058F5TXD\product_download[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1N5J9Z5S\50006+50425[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1N5J9Z5S\AntiVir_Personal_Edition_7_d955[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1N5J9Z5S\Boots[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1Z2SMZ17\50006+50425[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\31PMH0XJ\apiplayer3-vfl9ml4uN[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\31PMH0XJ\HikingCamping[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\31PMH0XJ\tos[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7T7CK9NB\Boots[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\92UGB74L\Avast_Home_Edition_d1968[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BD493RX1\50006+50425[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BD493RX1\download[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GDQT0Y6L\50006+50425[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IE2DZZU8\majorgeeks_com[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JGOR97LD\Boots[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S98GGZLV\Comodo_AntiVirus_d5109[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S98GGZLV\jukPlayer[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SP13OWYT\PIE[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZJ6WA7RT\BrightcovePlayer[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZJ6WA7RT\offerdetail4512[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0db1904e\Report.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows Mail\Local Folders\Drafts\19CD2D37-00000003.eml » MIME - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows Mail\Local Folders\Drafts\2F8A3E66-00000004.eml » MIME - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows Mail\Local Folders\Drafts\3AF33F7C-00000002.eml » MIME - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\2D944DC7-00000001.eml » MIME - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie2.1.32.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\mobogenie.apk » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\MUServer.apk » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\3397051458870376.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\aefeatman_v_1.2.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\aercm_0.3.2.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\aercm_0.3.4.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azemp-win32_3.3.10.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azemp-win32_3.3.12.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azemp-win32_3.4.1.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azlocprov_0.1.6.3.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azutp-win32_0.2.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azutp-win32_0.3.10.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azutp-win32_0.3.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\bafd8c5e-7324-4659-8719-fdcb010084da.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawaretb.dll - a variant of Win32/Toolbar.Visicom.A potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawareDx.dll - a variant of Win32/Toolbar.Visicom.B potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » dtUser.exe - a variant of Win32/Toolbar.Visicom.C potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » lavasoft_search_plugin.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawaretb.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawaretb.dll - a variant of Win32/Toolbar.Visicom.A potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawareDx.dll - a variant of Win32/Toolbar.Visicom.B potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » dtUser.exe - a variant of Win32/Toolbar.Visicom.C potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » lavasoft_search_plugin.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawaretb.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\jar_cache3994757568100908451.tmp » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » aucheck - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » jaureg - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » jucheck - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » jusched - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » task.xml - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » task64.xml - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\mlab-win32_0.1.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\setupA9_.exe » NSIS » Mobogenie.7z » 7ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Skype.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\SkypeToolbars.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\TFR21EF.tmp » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\TFR7E5.tmp » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_4.9.0.0_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_4.9.0.0a_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_5.0.0.0a_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_5.0.0.0b_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_5.0.0.0c_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_5.1.0.0_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ymsgr2 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ymsgr3 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ymsgr4 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ymsgr5 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\._msigeplugin61\Google Earth.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j13CA.tmp_dir1383355442\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j1FE9.tmp_dir1371872321\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j241A.tmp_dir1385008951\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j254B.tmp_dir1370636554\i4jruntime.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j254B.tmp_dir1370636554\platform.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j254B.tmp_dir1370636554\user.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j25AC.tmp_dir1362670160\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j28B5.tmp_dir1371516611\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j290.tmp_dir1373298140\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j29D2.tmp_dir1384353963\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j2AF.tmp_dir1368765705\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j30A0.tmp_dir1371372355\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j3141.tmp_dir1385511169\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j362D.tmp_dir1375575694\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j3680.tmp_dir1382597291\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j3813.tmp_dir1366500850\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j3880.tmp_dir1370739040\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j3A23.tmp_dir1381538531\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j40.tmp_dir1368752300\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j407C.tmp_dir1365652697\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j4452.tmp_dir1370739371\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j4B9.tmp_dir1384311815\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j50C1.tmp_dir1365652374\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j5273.tmp_dir1369061240\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j52E0.tmp_dir1369018209\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j53E9.tmp_dir1368151154\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j5A9E.tmp_dir1373323476\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j5C4B.tmp_dir1371351377\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j5F7D.tmp_dir1384286541\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j6049.tmp_dir1372987184\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j6171.tmp_dir1369976902\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j624D.tmp_dir1359789430\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j6509.tmp_dir1363938097\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j65C4.tmp_dir1374243586\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j65F4.tmp_dir1373764344\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j66B3.tmp_dir1383946943\platform.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j6B8F.tmp_dir1357708809\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j7A6C.tmp_dir1384286024\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j7BB4.tmp_dir1373061582\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j8EBC.tmp_dir1383946691\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j903E.tmp_dir1373822261\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j904D.tmp_dir1379348723\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j907C.tmp_dir1372453495\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9185.tmp_dir1381538553\i4jruntime.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9185.tmp_dir1381538553\platform.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9185.tmp_dir1381538553\user.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j92CD.tmp_dir1383437788\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j95C9.tmp_dir1378092979\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9630.tmp_dir1365407299\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9858.tmp_dir1373929441\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9C13.tmp_dir1367727655\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jA27B.tmp_dir1372836219\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jA36F.tmp_dir1378660238\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jA4B7.tmp_dir1357684422\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jA84F.tmp_dir1374021468\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jA894.tmp_dir1371797655\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jAD9C.tmp_dir1376186435\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jADA5.tmp_dir1384111193\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jAFE.tmp_dir1385532797\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jB7FC.tmp_dir1371175142\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jBA64.tmp_dir1379793499\i4jruntime.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jBA64.tmp_dir1379793499\platform.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jBA64.tmp_dir1379793499\user.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jBD3.tmp_dir1385361894\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jCBF1.tmp_dir1382148584\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jCCA3.tmp_dir1372311316\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jCFAE.tmp_dir1363749072\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jCFBF.tmp_dir1366522774\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jD1A6.tmp_dir1363498099\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jD5E4.tmp_dir1374935372\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jDA09.tmp_dir1370636535\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jDF4D.tmp_dir1365950704\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jE6C7.tmp_dir1375762147\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jEB3.tmp_dir1363873998\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jF028.tmp_dir1367780621\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jF08B.tmp_dir1368235901\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jF5F0.tmp_dir1361157262\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jF6C.tmp_dir1382292848\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jF6FC.tmp_dir1373168368\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jFD4F.tmp_dir1384650851\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jFF50.tmp_dir1379793320\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\EsetTempDir\ei_91F6.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\fullpackage_temp\package1.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\fullpackage_temp\package2.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\3397051458113855551.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\33970514581298536.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\339705145814912790.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\33970514581684873.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\33970514581714482.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\LR8IQTTY\Microsoft.Live.Silverlight.Slideshow_en__QGSaf16HgTRKJJz8Olo6w2[1].Xap » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\MATS-Temp\Results\Performance_result.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\MircosoftStudio\package1.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\scoped_dir_3976_17521\drop_to_s.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\scoped_dir_3976_19381\ask_toolbar_6_0_0.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\scoped_dir_3976_19385\youtube.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{0D8B0D61-5024-4295-8E40-78396ADAF555}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{3544C8D4-4EB9-40C1-8B84-E0C402AE99A8}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{4EA8E78D-8BDF-40BE-B41A-51EE52A4196C}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{652EFC24-2AEA-469D-92FF-E6FB4FF59458}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{8F7CA7A8-3E6B-4C23-8FAA-D668AFB22627}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{BD026C92-C987-468B-9A22-C021F7997A0E}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{E367888F-2E43-469E-AD28-BEC74749EE66}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000001 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000003 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000004 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000005 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000007 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000009 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_00000d » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\AU\au.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\AU\au.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\22e17456-37242cd5 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\6b30ec21-5facd6eb » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\2e712b26-7e14b560 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\1ca2666b-28ce97ea » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Adobe\Acrobat\10.0\ServicesRdr\com_2E_adobe_2E_acrobat_2E_services_2E_cfg_5F_10_2E_1_2E_5_2E_2.cfg » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Adobe\Acrobat\10.0\ServicesRdr\com_2E_adobe_2E_acrobat_2E_services_2E_cfg_5F_10_2E_1_2E_8_2E_1.cfg » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Adobe\Acrobat\10.0\ServicesRdr\com_2E_adobe_2E_acrobat_2E_services_2E_DEXShare_5F_10_2E_1_2E_5_2E_2.spi » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Adobe\Acrobat\10.0\ServicesRdr\com_2E_adobe_2E_acrobat_2E_services_2E_DEXShare_5F_10_2E_1_2E_8_2E_1.spi » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aefeatman_v\aefeatman_v_1.2.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aefeatman_v\aefeatman_v_1.2.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.2.0.0.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.3.0.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.3.2.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.3.4.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.3.7.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.4.3.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.3.10.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.3.10.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.3.12.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.3.12.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.4.1.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.4.1.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\libmprCanvas_1.3.6.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azlocprov\azlocprov_0.1.1.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azlocprov\azlocprov_0.1.4.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azlocprov\azlocprov_0.1.6.3.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azlocprov\azlocprov_0.1.6.3.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azrating\azrating_1.4.2.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azrating\azrating_1.4.3.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.2.9.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.2.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.3.10.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.3.10.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.3.9.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.3.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\mlab\mlab_0.1.9.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\mlab\mlab_0.1.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\Downloads\Resize_My_Pictures.zip » ZIP - is OK (internal scanning not performed)
C:\Windows\Downloaded Installations\{CA7D4921-377A-43B2-870C-9718101C24DE}\SILKYPIX Developer Studio 3.0 for PENTAX.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\authfw.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\ipsecpolicy.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\lug.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\mmc.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\saferconcepts.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\snmp.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\spolsconcepts.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\sys_srv.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\tpmadmin.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\IME\imekr8\help\imkrpd.chm » CHM - is OK (internal scanning not performed)
C:\Windows\Installer\10cae26f.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\152d21f8.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\176832f2.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\193ee8.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\1a4291.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\24cd271.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\2642dda.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\2642de6.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\27fdba.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\2a1a58.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\2afe64.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\2bcd7f07.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\3433a5.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\409b3be.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\45c3f57.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\45c3f73.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\45c3f7a.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\48ae7ac.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\48ae7b2.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\48ae7b6.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\48ae7ba.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\6eeabc2.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\96e048.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\dexshare.spi » ZIP - is OK (internal scanning not performed)
C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg » ZIP - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\chrome\chrome.jar » ZIP - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.cab » CAB - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\netfx_core.mzz » CAB - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\netfx_core_x64.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Windows6.0-KB956250-v6001-x64.msu » CAB - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Windows6.1-KB958488-v6001-x64.msu » CAB - is OK (internal scanning not performed)
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT - error opening [4]
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 - error opening [4]
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 - error opening [4]
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - error opening [4]
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - error opening [4]
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT - error opening [4]
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 - error opening [4]
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 - error opening [4]
C:\Windows\SoftwareDistribution\AuthCabs\authcab.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\authcab.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\AuthCabs\Redir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\AuthCabs\Redir\9482F4B4-E343-43B6-B170-9A65BC822C77\wuredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\Download\6a54a0de1fee168c620014cc7de09a55b139fe47 » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\Download\73432f90b50c5de7d0e566193fd8430d\Windows6.0-KB956250-x64.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\Download\e5ee985038e4aa2a8f2ffc72a8f93973\windows6.0-kb2763674-x64-express.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\SelfUpdate\Handler\WuSetupHandler.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\muredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\wuredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\wuredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 » CAB - is OK (internal scanning not performed)
C:\Windows\System32\spool\drivers\x64\PCC\hpvpl04.inf_2a66245c.cab » CAB - is OK (internal scanning not performed)
C:\Windows\System32\spool\drivers\x64\PCC\ntprint.inf_05612b59.cab » CAB - is OK (internal scanning not performed)
C:\Windows\System32\spool\drivers\x64\PCC\prnms001.inf_6b0743f8.cab » CAB - is OK (internal scanning not performed)
C:\Windows\System32\spool\drivers\x64\PCC\prnms002.inf_1d6c7442.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 » CAB - is OK (internal scanning not performed)
C:\Windows\Temp\._msigeplugin61\Google Earth.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Temp\Low\MSI\SkypeToolbars.msi » MSI - is OK (internal scanning not performed)
C:\Windows\WindowsMobile\mui\0409\wm_devmgr.chm » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_divasx64.inf_31bf3856ad364e35_6.0.6001.18000_none_607ed84088ce5846\te_protm.2qm » TAR - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_divasx64.inf_31bf3856ad364e35_6.0.6001.18000_none_607ed84088ce5846\te_protm.am » TAR - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_divasx64.inf_31bf3856ad364e35_6.0.6001.18000_none_607ed84088ce5846\te_protm.pm2 » TAR - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_divasx64.inf_31bf3856ad364e35_6.0.6001.18000_none_607ed84088ce5846\te_protm.pm3 » TAR - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_microsoft-windows-ime-korean-help_31bf3856ad364e35_6.0.6000.16386_none_ea0e957fd04399fa\imkrpd.chm » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_microsoft-windows-localizeddrivers_31bf3856ad364e35_6.0.6000.16386_en-us_d8b4b68e802ab022\locdrv.cab » CAB - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_microsoft-windows-mediaplayer-skins_31bf3856ad364e35_6.0.6000.16386_none_0348fbb194e52ab6\Revert.wmz » ZIP - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_microsoft-windows-mediaplayer-skins_31bf3856ad364e35_6.0.6002.18005_none_076b36b98ef206d6\Revert.wmz » ZIP - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.authfw.resources_31bf3856ad364e35_6.0.6001.18000_en-us_711362beca1f1b35\authfw.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.file_srv.resources_31bf3856ad364e35_6.0.6000.16386_en-us_1cac41e6587c725a\file_srv.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.ipsecpolicy.resources_31bf3856ad364e35_6.0.6001.18000_en-us_b35cd72c48686e0e\ipsecpolicy.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.lug.resources_31bf3856ad364e35_6.0.6001.18000_en-us_8943128f03b691ba\lug.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.mmc.resources_31bf3856ad364e35_6.0.6001.18000_en-us_18fc747d85dba53d\mmc.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.qos.resources_31bf3856ad364e35_6.0.6000.16386_en-us_83fe6986d82fd383\QoS.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.saf..oncepts_v.resources_31bf3856ad364e35_6.0.6001.18000_en-us_82344fc18d37ba8b\saferconcepts.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.snmp.resources_31bf3856ad364e35_6.0.6001.18000_en-us_456fac32cddee97c\snmp.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.spo..oncepts_v.resources_31bf3856ad364e35_6.0.6001.18000_en-us_1965166542567787\spolsconcepts.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.sys_srv.resources_31bf3856ad364e35_6.0.6000.16386_en-us_4a77b04e1ac35639\sys_srv.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.sys_srv.resources_31bf3856ad364e35_6.0.6001.18000_en-us_4cae724a17ae670d\sys_srv.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.tpmadmin.resources_31bf3856ad364e35_6.0.6001.18000_en-us_f4cbc4a39c40000c\tpmadmin.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_winmobil.inf.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3e94b5b83de50ccc\wm_devmgr.chm » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_winmobil.inf_31bf3856ad364e35_6.0.6001.18000_none_fba2ba8917dbe2f8\wmdevmgr.chm » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_winmobil.inf_31bf3856ad364e35_6.0.6002.18005_none_fd8e339514fdae44\wmdevmgr.chm » CHM - is OK (internal scanning not performed)
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\adawareDx.dll.vir - a variant of Win32/Toolbar.Visicom.B potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\adawaretb.dll.vir - a variant of Win32/Toolbar.Visicom.A potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\dtUser.exe.vir - a variant of Win32/Toolbar.Visicom.C potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\Helper.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\safetyldr.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\safetyldr_u.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\x64\safetyldr.dll.vir - a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\x64\safetyldr_u.dll.vir - a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application - cleaned by deleting - quarantined [1]
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\Safe+Haven+28201329+720p+BrRip+x264+-+YIFY.exe - a variant of Win32/4Shared.K potentially unwanted application - cleaned by deleting - quarantined [1]
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawaretb.dll - a variant of Win32/Toolbar.Visicom.A potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawareDx.dll - a variant of Win32/Toolbar.Visicom.B potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » dtUser.exe - a variant of Win32/Toolbar.Visicom.C potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » lavasoft_search_plugin.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawaretb.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawaretb.dll - a variant of Win32/Toolbar.Visicom.A potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawareDx.dll - a variant of Win32/Toolbar.Visicom.B potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » dtUser.exe - a variant of Win32/Toolbar.Visicom.C potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » lavasoft_search_plugin.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawaretb.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
Number of scanned objects: 124460
Number of threats found: 15
Number of cleaned objects: 15
Time of completion: 10:09:26 PM Total scanning time: 3898 sec (01:04:58)

Notes:
[1] Object has been deleted as it only contained the virus body.
[4] Object cannot be opened. It may be in use by another application or operating system.

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by Superdave on Sat 30 Nov 2013, 7:29 am

How's your computer working now?

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Sat 30 Nov 2013, 8:00 am

I no longer have "ask.com" taking over the search from google, but now when I type the name of the bank into google,the " internet explore can not access this page " comes up ,as if my pc went off line. My daughters laptop has no problem accessing the bank. It only does it on that one bank . even if I try to trick it by finding a site that mentions the bank ,and click on it from there the same thing happens.
Oh, but my pc is lightning quick,after I did what you said to. I also enjoy reading the Tips and Tricks book I got.

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by Superdave on Sat 30 Nov 2013, 10:39 am

Is it possible that the site is blocked? What browser are you using?

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Sat 30 Nov 2013, 5:32 pm

I use internet explore. I'm not sure how the site could be blocked. I sent them a note asking if things were working properly and they said yes. They won't have blocked me .

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Sat 30 Nov 2013, 5:48 pm

I just clicked on "diagnose problem" in the window that said internert explorer could not access this page, then went to advanced security and clicked on tlt or some similar letters ,they wern't checked yet. Now I can access the banks website, but when I try to access my acct this is what comes up. I believe this happened once before and it turned out I was using a cashed old site??? Maybe I have it wrong ,but it was something like that. I don't think I fixed it because I believe I got another ( second hand ) pc right after that.
There is a problem with this website's security certificate.


The security certificate presented by this website was issued for a different website's address.

Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server.
We recommend that you close this webpage and do not continue to this website.
Click here to close this webpage.
Continue to this website (not recommended).
More information


If you arrived at this page by clicking a link, check the website address in the address bar to be sure that it is the address you were expecting.
When going to a website with an address such as [You must be registered and logged in to see this link.] try adding the 'www' to the address, [You must be registered and logged in to see this link.]

For more information, see "Certificate Errors" in Internet Explorer Help.



neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Sat 30 Nov 2013, 6:06 pm

I just noticed a pop up at the website saying they may be down on the 30th of this month. Thats about now,depending what time zone they are in.So Please don't bother with anything at this time. I'll check tomorrow when they are finished updating things and send a note.
Thanks for all your help.

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Sun 01 Dec 2013, 4:12 am

Well, sadly the website is finished updating and I still get this window poping up.
There is a problem with this website's security certificate.


The security certificate presented by this website was issued for a different website's address.

Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server.
We recommend that you close this webpage and do not continue to this website.
Click here to close this webpage.
Continue to this website (not recommended).
More information


If you arrived at this page by clicking a link, check the website address in the address bar to be sure that it is the address you were expecting.
When going to a website with an address such as [You must be registered and logged in to see this link.] try adding the 'www' to the address, [You must be registered and logged in to see this link.]

For more information, see "Certificate Errors" in Internet Explorer Help.
How can I update my certificate ,if thats what's required ?

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by Superdave on Sun 01 Dec 2013, 7:07 am

Please check this site.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Sun 01 Dec 2013, 12:26 pm

I went to the site and followed insructions. The address bar turned red once I clicked on " continue anyway,we recommend you dont continue " . I was able to proceed to the login page,however they said the password or acct number was wrong,but it isn,t wrong.The address bar remains red.. Is there anything else I can do? This hapened once before ,I phoned them and was told my pc must be going to an old cashed site of theres. Could this be? I never did figure it out cause I switched pc's shortly after that.

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by Superdave on Sun 01 Dec 2013, 1:30 pm

Please run AdwCleaner and delete those infections.

Download Combofix from any of the links below, and save it to your DESKTOP.
If your version of Windows defaults to you download folder you will need to copy it to your desktop.

Link 1
Link 2
Link 3

To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.

  • Close any open windows and double click ComboFix.exe to run it.

    You will see the following image:



Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:



As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.



Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.

Superdave
Tech Staff


Tech Staff

Posts : 4193
Joined : 2010-02-01
Operating System : Windows 8.1 and a dual-boot with XP Home SP3

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Mon 02 Dec 2013, 5:42 am

I'll post this in two parts
ComboFix 13-11-27.01 - myComputer 12/01/2013 10:42:07.2.2 - x64
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.4094.2414 [GMT -7:00]
Running from: c:\users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YTY4OSHC\ComboFix.exe
AV: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: ESET NOD32 Antivirus 7.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
SP: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: ESET NOD32 Antivirus 7.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\ydi.log
.
.
((((((((((((((((((((((((( Files Created from 2013-11-01 to 2013-12-01 )))))))))))))))))))))))))))))))
.
.
2013-12-01 18:33 . 2013-12-01 18:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-01 10:56 . 2013-12-01 10:56 -------- d-----w- c:\users\myComputer\AppData\Local\ESET
2013-11-29 03:43 . 2013-11-29 03:43 -------- d-----w- c:\program files\ESET
2013-11-29 00:47 . 2013-11-29 00:47 -------- d-----w- c:\users\myComputer\AppData\Roaming\AVG2014
2013-11-29 00:46 . 2013-11-29 00:46 -------- d-----w- c:\users\myComputer\AppData\Roaming\TuneUp Software
2013-11-29 00:45 . 2013-12-01 18:35 -------- d-----w- c:\programdata\AVG2014
2013-11-29 00:45 . 2013-11-29 00:45 -------- d-----w- C:\$AVG
2013-11-29 00:45 . 2013-11-29 00:45 -------- d-----w- c:\program files (x86)\AVG
2013-11-29 00:41 . 2013-12-01 17:10 -------- d-----w- c:\programdata\MFAData
2013-11-29 00:41 . 2013-11-29 03:00 -------- d-----w- c:\users\myComputer\AppData\Local\Avg2014
2013-11-29 00:41 . 2013-11-29 00:41 -------- d-----w- c:\users\myComputer\AppData\Local\MFAData
2013-11-28 03:55 . 2013-11-18 08:28 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{71ADEC8A-24EC-4322-8DCA-6FC540A33935}\mpengine.dll
2013-11-28 00:28 . 2013-11-28 00:28 -------- d-----w- c:\windows\ERUNT
2013-11-27 14:28 . 2013-11-27 14:28 -------- d-----w- c:\users\wangjihua
2013-11-27 06:27 . 2013-11-27 06:27 -------- d-----w- c:\users\myComputer\.android
2013-11-27 06:27 . 2013-11-27 14:28 -------- d-----w- c:\users\myComputer\AppData\Local\cache
2013-11-27 06:27 . 2013-11-27 14:29 -------- d-----w- c:\users\myComputer\AppData\Local\Mobogenie
2013-11-27 06:26 . 2013-11-27 14:29 -------- d-----w- c:\program files (x86)\Mobogenie
2013-11-27 05:49 . 2013-11-27 05:49 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-27 05:49 . 2013-11-27 05:49 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-11-26 22:09 . 2013-11-28 03:39 -------- d-----w- C:\AdwCleaner
2013-11-26 15:27 . 2013-11-27 22:53 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-11-26 15:27 . 2013-04-04 21:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-26 15:17 . 2013-11-26 15:17 -------- d-----w- c:\programdata\AVAST Software
2013-11-26 14:30 . 2013-11-27 00:23 -------- d-----w- c:\users\myComputer\AppData\Local\LogMeIn Rescue Applet
2013-11-26 06:45 . 2013-11-26 06:45 -------- d-----w- c:\programdata\HitmanPro
2013-11-26 03:11 . 2013-11-26 03:11 -------- d-----w- c:\programdata\Pure Networks
2013-11-14 10:03 . 2013-10-13 14:36 96768 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-14 10:03 . 2013-10-13 14:35 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-14 10:03 . 2013-10-13 09:25 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-11-14 10:03 . 2013-10-13 16:04 183024 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2013-11-14 10:03 . 2013-10-13 14:46 996352 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-11-14 10:03 . 2013-10-13 14:44 305152 ----a-w- c:\program files\Internet Explorer\IEShims.dll
2013-11-14 10:03 . 2013-10-13 10:49 149744 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll
2013-11-14 10:03 . 2013-10-13 09:33 768512 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\vgx\VGX.dll
2013-11-14 10:03 . 2013-10-13 09:29 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-13 14:38 . 2013-10-11 04:23 462848 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-11-13 14:38 . 2013-10-11 04:23 781824 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-11-13 14:38 . 2013-10-11 02:07 596480 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2013-11-13 14:38 . 2013-10-03 15:02 1278976 ----a-w- c:\windows\system32\crypt32.dll
2013-11-13 14:38 . 2013-10-03 12:45 993792 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-11-13 14:38 . 2013-10-03 15:03 389632 ----a-w- c:\windows\system32\gdi32.dll
2013-11-13 14:38 . 2013-10-03 12:46 304128 ----a-w- c:\windows\SysWow64\gdi32.dll
2013-11-13 14:38 . 2013-09-04 02:31 404992 ----a-w- c:\windows\system32\drivers\afd.sys
2013-11-13 03:16 . 2013-11-13 03:16 -------- d-----w- c:\users\myComputer\AppData\Local\MaxiGet Download Manager
2013-11-13 03:16 . 2013-11-13 03:20 -------- d-----w- c:\users\myComputer\AppData\Local\Maxiget
2013-11-06 04:55 . 2013-11-06 04:55 150808 ----a-w- c:\windows\system32\drivers\avgdiska.sys
2013-11-05 04:52 . 2013-11-05 04:52 240920 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2013-11-05 04:19 . 2013-11-05 04:19 -------- d-----w- c:\windows\Sun
2013-11-05 04:19 . 2013-11-26 05:30 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-11-05 04:18 . 2013-10-08 14:50 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-11-05 04:16 . 2013-11-05 04:19 -------- d-----w- c:\programdata\Oracle
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-14 10:01 . 2006-11-02 12:35 82896128 ----a-w- c:\windows\system32\mrt.exe
2013-11-11 12:50 . 2013-01-09 02:38 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-01 06:00 . 2013-11-01 06:00 212280 ----a-w- c:\windows\system32\drivers\avgldx64.sys
2013-11-01 05:49 . 2013-11-01 05:49 294712 ----a-w- c:\windows\system32\drivers\avgloga.sys
2013-10-25 05:25 . 2013-10-25 05:25 194872 ----a-w- c:\windows\system32\drivers\avgidsha.sys
2013-10-01 07:52 . 2013-10-01 07:52 123704 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
2013-09-17 22:17 . 2013-09-17 22:17 239320 ----a-w- c:\windows\system32\drivers\eamonm.sys
2013-09-17 22:17 . 2013-09-17 22:17 239296 ----a-w- c:\windows\system32\drivers\edevmon.sys
2013-09-17 22:17 . 2013-09-17 22:17 168256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2013-09-17 22:17 . 2013-09-17 22:17 157432 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2013-09-10 07:43 . 2013-09-10 07:43 31544 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
"ForceActiveDesktopOn"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\rjatydimofu.exe]
"debugger"=tasklist.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Browsing Protection]
2013-01-31 15:11 542632 ----a-w- c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]
2010-04-02 18:18 1185112 ----a-w- c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-07-02 16:16 254336 ----a-w- c:\program files (x86)\Common Files\Java\Java Update\jusched.exe
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-27 05:49]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-09 03:16]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-09 03:16]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-929725188-2267044026-2474493764-1000Core.job
- c:\users\myComputer\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-21 00:38]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-929725188-2267044026-2474493764-1000UA.job
- c:\users\myComputer\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-21 00:38]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2013-09-12 5618456]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = [You must be registered and logged in to see this link.]
uDefault_Page_URL = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
mDefault_Page_URL = [You must be registered and logged in to see this link.]
mDefault_Search_URL = [You must be registered and logged in to see this link.]
mSearch Page = [You must be registered and logged in to see this link.]
mLocal Page = c:\windows\SysWOW64\blank.htm
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
Toolbar-10 - (no file)
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
HKLM-Run-SBRegRebootCleaner - c:\program files (x86)\Ad-Aware Antivirus\SBRC.exe
AddRemove-Coupon Printer for Windows5.0.0.0 - c:\program files (x86)\Coupons\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Data]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Networking]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Networking 4.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET Data Provider for Oracle]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET Data Provider for SqlServer]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NETFramework]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ACPI]
"ImagePath"="system32\drivers\acpi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AdobeARMservice]
"ImagePath"="\"c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AdobeFlashPlayerUpdateSvc]
"ImagePath"="c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adp94xx]
"ImagePath"="\SystemRoot\system32\drivers\adp94xx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpahci]
"ImagePath"="\SystemRoot\system32\drivers\adpahci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpu160m]
"ImagePath"="\SystemRoot\system32\drivers\adpu160m.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpu320]
"ImagePath"="\SystemRoot\system32\drivers\adpu320.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adsi]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AeLookupSvc]
"ServiceDll"="%SystemRoot%\System32\aelupsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AFD]
"ImagePath"="\SystemRoot\system32\drivers\afd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\agp440]
"ImagePath"="\SystemRoot\system32\drivers\agp440.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aic78xx]
"ImagePath"="\SystemRoot\system32\drivers\djsvs.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ALG]
"ImagePath"="%SystemRoot%\System32\alg.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aliide]
"ImagePath"="\SystemRoot\system32\drivers\aliide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AMD External Events Utility]
"ImagePath"="%SystemRoot%\system32\atiesrxx.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdide]
"ImagePath"="\SystemRoot\system32\drivers\amdide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AmdK8]
"ImagePath"="\SystemRoot\system32\drivers\amdk8.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdkmdag]
"ImagePath"="system32\DRIVERS\atikmdag.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdkmdap]
"ImagePath"="system32\DRIVERS\atikmpag.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Appinfo]
"ServiceDll"="%SystemRoot%\System32\appinfo.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AppMgmt]
"ServiceDll"="%SystemRoot%\System32\appmgmts.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\arc]
"ImagePath"="\SystemRoot\system32\drivers\arc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\arcsas]
"ImagePath"="\SystemRoot\system32\drivers\arcsas.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AsyncMac]
"ImagePath"="system32\DRIVERS\asyncmac.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\atapi]
"ImagePath"="system32\drivers\atapi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Atierecord]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AudioEndpointBuilder]
"ServiceDll"="%SystemRoot%\System32\Audiosrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AudioSrv]
"ServiceDll"="%SystemRoot%\System32\Audiosrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avg]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgdiska]
"ImagePath"="system32\DRIVERS\avgdiska.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSAgent]
"ImagePath"="\"c:\program files (x86)\AVG\AVG2014\avgidsagent.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSDriver]
"ImagePath"="system32\DRIVERS\avgidsdrivera.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSHA]
"ImagePath"="system32\DRIVERS\avgidsha.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgldx64]
"ImagePath"="system32\DRIVERS\avgldx64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgloga]
"ImagePath"="system32\DRIVERS\avgloga.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgmfx64]
"ImagePath"="system32\DRIVERS\avgmfx64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgrkx64]
"ImagePath"="system32\DRIVERS\avgrkx64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgtdia]
"ImagePath"="system32\DRIVERS\avgtdia.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avgwd]
"ImagePath"="\"c:\program files (x86)\AVG\AVG2014\avgwdsvc.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BattC]
"MofImagePath"="system32\drivers\battc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BFE]
"ServiceDll"="%SystemRoot%\System32\bfe.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BITS]
"ServiceDll"="%systemroot%\system32\qmgr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\blbdrive]
"ImagePath"="\SystemRoot\system32\drivers\blbdrive.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bowser]
"ImagePath"="system32\DRIVERS\bowser.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrFiltLo]
"ImagePath"="\SystemRoot\system32\drivers\brfiltlo.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrFiltUp]
"ImagePath"="\SystemRoot\system32\drivers\brfiltup.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Browser]
"ServiceDll"="%SystemRoot%\System32\browser.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Brserid]
"ImagePath"="\SystemRoot\system32\drivers\brserid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrSerWdm]
"ImagePath"="\SystemRoot\system32\drivers\brserwdm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrUsbMdm]
"ImagePath"="\SystemRoot\system32\drivers\brusbmdm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrUsbSer]
"ImagePath"="\SystemRoot\system32\drivers\brusbser.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BTHMODEM]
"ImagePath"="\SystemRoot\system32\drivers\bthmodem.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BTHPORT]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\catchme]
"ImagePath"="\??\c:\combofix\catchme.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cdfs]
"ImagePath"="system32\DRIVERS\cdfs.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cdrom]
"ImagePath"="system32\DRIVERS\cdrom.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CertPropSvc]
"ServiceDll"="%SystemRoot%\System32\certprop.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\circlass]
"ImagePath"="\SystemRoot\system32\drivers\circlass.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CLFS]
"ImagePath"="System32\CLFS.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v2.0.50727_32]
"ImagePath"="%systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v2.0.50727_64]
"ImagePath"="%systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v4.0.30319_32]
"ImagePath"="c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v4.0.30319_64]
"ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdide]
"ImagePath"="\SystemRoot\system32\drivers\cmdide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Compbatt]
"ImagePath"="\SystemRoot\system32\drivers\compbatt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\COMSysApp]
"ImagePath"="%SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crcdisk]
"ImagePath"="system32\drivers\crcdisk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CryptSvc]
"ServiceDll"="%SystemRoot%\system32\cryptsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSC]
"ImagePath"="system32\drivers\csc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CscService]
"ServiceDll"="%SystemRoot%\System32\cscsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DCLocator]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DcomLaunch]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DfsC]
"ImagePath"="System32\Drivers\dfsc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DFSR]
"ImagePath"="%SystemRoot%\system32\DFSR.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dhcp]
"ServiceDll"="%SystemRoot%\system32\dhcpcsvc.dll"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\disk]
"ImagePath"="system32\drivers\disk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache]
"ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\dot3svc]
"ServiceDll"="%SystemRoot%\System32\dot3svc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPS]
"ServiceDll"="%SystemRoot%\system32\dps.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\drmkaud]
"ImagePath"="system32\drivers\drmkaud.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DXGKrnl]
"ImagePath"="\SystemRoot\System32\drivers\dxgkrnl.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\E1G60]
"ImagePath"="system32\DRIVERS\E1G6032E.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\eamonm]
"ImagePath"="system32\DRIVERS\eamonm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EapHost]
"ServiceDll"="%SystemRoot%\System32\eapsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ecache]
"ImagePath"="System32\drivers\ecache.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\edevmon]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ehdrv]
"ImagePath"="system32\DRIVERS\ehdrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ekrn]
"ImagePath"="\"c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\elxstor]
"ImagePath"="\SystemRoot\system32\drivers\elxstor.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EmdCache]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EMDMgmt]
"ServiceDll"="%systemroot%\system32\emdmgmt.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\epfwwfpr]
"ImagePath"="system32\DRIVERS\epfwwfpr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ErrDev]
"ImagePath"="\SystemRoot\system32\drivers\errdev.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ESENT]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog]
"ServiceDll"="%SystemRoot%\System32\wevtsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventSystem]
"ServiceDll"="%systemroot%\system32\es.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\exfat]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fastfat]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Fax]
"ImagePath"="%systemroot%\system32\fxssvc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fdc]
"ImagePath"="system32\DRIVERS\fdc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fdPHost]
"ServiceDll"="%SystemRoot%\system32\fdPHost.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FDResPub]
"ServiceDll"="%SystemRoot%\system32\fdrespub.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FileInfo]
"ImagePath"="system32\drivers\fileinfo.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Filetrace]
"ImagePath"="system32\drivers\filetrace.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\flpydisk]
"ImagePath"="system32\DRIVERS\flpydisk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FltMgr]
"ImagePath"="system32\drivers\fltmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FontCache]
"ServiceDll"="%SystemRoot%\system32\FntCache.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FontCache3.0.0.0]
"ImagePath"="%systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Fs_Rec]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gagp30kx]
"ImagePath"="\SystemRoot\system32\drivers\gagp30kx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gfiark]
"ImagePath"="system32\drivers\gfiark.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gpsvc]
"ServiceDll"="%SystemRoot%\System32\gpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gupdate]
"ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /svc"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gupdatem]
"ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /medsvc"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gusvc]
"ImagePath"="\"c:\program files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HdAudAddService]
"ImagePath"="system32\drivers\HdAudio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HDAudBus]
"ImagePath"="system32\DRIVERS\HDAudBus.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidBth]
"ImagePath"="\SystemRoot\system32\drivers\hidbth.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidIr]
"ImagePath"="\SystemRoot\system32\drivers\hidir.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hidserv]
"ServiceDll"="%SystemRoot%\System32\hidserv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidUsb]
"ImagePath"="system32\DRIVERS\hidusb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hkmsvc]
"ServiceDLL"="%SystemRoot%\system32\kmsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HpCISSs]
"ImagePath"="\SystemRoot\system32\drivers\hpcisss.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HTTP]
"ImagePath"="system32\drivers\HTTP.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i2omp]
"ImagePath"="\SystemRoot\system32\drivers\i2omp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i8042prt]
"ImagePath"="system32\DRIVERS\i8042prt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iaStorV]
"ImagePath"="\SystemRoot\system32\drivers\iastorv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IDriverT]
"ImagePath"="\"c:\program files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\idsvc]
"ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iirsp]
"ImagePath"="\SystemRoot\system32\drivers\iirsp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IKEEXT]
"ServiceDll"="%SystemRoot%\System32\ikeext.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\inetaccs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\intelide]
"ImagePath"="system32\drivers\intelide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\intelppm]
"ImagePath"="system32\DRIVERS\intelppm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPBusEnum]
"ServiceDll"="%SystemRoot%\system32\ipbusenum.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IpFilterDriver]
"ImagePath"="system32\DRIVERS\ipfltdrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iphlpsvc]
"ServiceDll"="%SystemRoot%\System32\iphlpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IpInIp]
"ImagePath"="system32\DRIVERS\ipinip.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPMIDRV]
"ImagePath"="\SystemRoot\system32\drivers\ipmidrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPNAT]
"ImagePath"="system32\DRIVERS\ipnat.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IRENUM]
"ImagePath"="system32\drivers\irenum.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\isapnp]
"ImagePath"="\SystemRoot\system32\drivers\isapnp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iScsiPrt]
"ImagePath"="system32\DRIVERS\msiscsi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iteatapi]
"ImagePath"="\SystemRoot\system32\drivers\iteatapi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iteraid]
"ImagePath"="\SystemRoot\system32\drivers\iteraid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kbdclass]
"ImagePath"="system32\DRIVERS\kbdclass.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kbdhid]
"ImagePath"="system32\DRIVERS\kbdhid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KeyIso]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KSecDD]
"ImagePath"="System32\Drivers\ksecdd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ksthunk]
"ImagePath"="\SystemRoot\system32\drivers\ksthunk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KtmRm]
"ServiceDll"="%systemroot%\system32\msdtckrm.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanServer]
"ServiceDll"="%SystemRoot%\System32\srvsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanWorkstation]
"ServiceDll"="%SystemRoot%\System32\wkssvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldap]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lltdio]
"ImagePath"="system32\DRIVERS\lltdio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lltdsvc]
"ServiceDll"="%SystemRoot%\System32\lltdsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lmhosts]
"ServiceDll"="%SystemRoot%\System32\lmhsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Lsa]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_FC]
"ImagePath"="\SystemRoot\system32\drivers\lsi_fc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_SAS]
"ImagePath"="\SystemRoot\system32\drivers\lsi_sas.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_SCSI]
"ImagePath"="\SystemRoot\system32\drivers\lsi_scsi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\luafv]
"ImagePath"="\SystemRoot\system32\drivers\luafv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMProtector]
"ImagePath"="\??\c:\windows\system32\drivers\mbam.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMScheduler]
"ImagePath"="\"c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMService]
"ImagePath"="\"c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\megasas]
"ImagePath"="\SystemRoot\system32\drivers\megasas.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MegaSR]
"ImagePath"="\SystemRoot\system32\drivers\megasr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MMCSS]
"ServiceDll"="%SystemRoot%\system32\mmcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Modem]
"ImagePath"="system32\drivers\modem.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\monitor]
"ImagePath"="system32\DRIVERS\monitor.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouclass]
"ImagePath"="system32\DRIVERS\mouclass.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouhid]
"ImagePath"="system32\DRIVERS\mouhid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MountMgr]
"ImagePath"="System32\drivers\mountmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mpio]
"ImagePath"="\SystemRoot\system32\drivers\mpio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mpsdrv]
"ImagePath"="System32\drivers\mpsdrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MpsSvc]
"ServiceDll"="%SystemRoot%\system32\mpssvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mraid35x]
"ImagePath"="\SystemRoot\system32\drivers\mraid35x.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MRxDAV]
"ImagePath"="\SystemRoot\system32\drivers\mrxdav.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb]
"ImagePath"="system32\DRIVERS\mrxsmb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb10]
"ImagePath"="system32\DRIVERS\mrxsmb10.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb20]
"ImagePath"="system32\DRIVERS\mrxsmb20.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msahci]
"ImagePath"="\SystemRoot\system32\drivers\msahci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msdsm]
"ImagePath"="\SystemRoot\system32\drivers\msdsm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC]
"ImagePath"="%SystemRoot%\System32\msdtc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC Bridge 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC Bridge 4.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Msfs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msisadrv]
"ImagePath"="system32\drivers\msisadrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSiSCSI]
"ServiceDll"="%systemroot%\system32\iscsiexe.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSKSSRV]
"ImagePath"="system32\drivers\MSKSSRV.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSPCLOCK]
"ImagePath"="system32\drivers\MSPCLOCK.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSPQM]
"ImagePath"="system32\drivers\MSPQM.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MsRPC]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSSCNTRS]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mssmbios]
"ImagePath"="system32\DRIVERS\mssmbios.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSTEE]
"ImagePath"="system32\drivers\MSTEE.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mup]
"ImagePath"="System32\Drivers\mup.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\napagent]
"ServiceDLL"="%SystemRoot%\system32\qagentRT.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NativeWifiP]
"ImagePath"="system32\DRIVERS\nwifi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NDIS]
"ImagePath"="system32\drivers\ndis.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NdisTapi]
"ImagePath"="system32\DRIVERS\ndistapi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ndisuio]
"ImagePath"="system32\DRIVERS\ndisuio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NdisWan]
"ImagePath"="system32\DRIVERS\ndiswan.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NDProxy]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetBIOS]
"ImagePath"="system32\DRIVERS\netbios.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\netbt]
"ImagePath"="System32\DRIVERS\netbt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Netlogon]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Netman]
"ServiceDll"="%SystemRoot%\System32\netman.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\netprofm]
"ServiceDll"="%SystemRoot%\System32\netprofm.dll"

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by neilw on Mon 02 Dec 2013, 5:43 am


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetTcpPortSharing]
"ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nfrd960]
"ImagePath"="\SystemRoot\system32\drivers\nfrd960.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NlaSvc]
"ServiceDll"="%SystemRoot%\System32\nlasvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Npfs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsi]
"ServiceDll"="%systemroot%\system32\nsisvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsiproxy]
"ImagePath"="system32\drivers\nsiproxy.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTDS]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ntfs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Null]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nvraid]
"ImagePath"="\SystemRoot\system32\drivers\nvraid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nvstor]
"ImagePath"="\SystemRoot\system32\drivers\nvstor.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nv_agp]
"ImagePath"="\SystemRoot\system32\drivers\nv_agp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NwlnkFlt]
"ImagePath"="system32\DRIVERS\nwlnkflt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NwlnkFwd]
"ImagePath"="system32\DRIVERS\nwlnkfwd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ohci1394]
"ImagePath"="\SystemRoot\system32\drivers\ohci1394.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\p2pimsvc]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\p2psvc]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Parport]
"ImagePath"="system32\DRIVERS\parport.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\partmgr]
"ImagePath"="System32\drivers\partmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PcaSvc]
"ServiceDll"="%SystemRoot%\System32\pcasvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pci]
"ImagePath"="system32\drivers\pci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pciide]
"ImagePath"="\SystemRoot\system32\drivers\pciide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pcmcia]
"ImagePath"="\SystemRoot\system32\drivers\pcmcia.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PEAUTH]
"ImagePath"="system32\drivers\peauth.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfDisk]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfHost]
"ImagePath"="%SystemRoot%\SysWow64\perfhost.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfNet]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfOS]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfProc]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ph3xIB64]
"ImagePath"="system32\DRIVERS\Ph3xIB64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pla]
"ServiceDll"="%systemroot%\system32\pla.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PlugPlay]
"ServiceDll"="%SystemRoot%\system32\umpnpmgr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PNRPAutoReg]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PNRPsvc]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PolicyAgent]
"ServiceDll"="%SystemRoot%\System32\ipsecsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PortProxy]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PptpMiniport]
"ImagePath"="system32\DRIVERS\raspptp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Processor]
"ImagePath"="\SystemRoot\system32\drivers\processr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProfSvc]
"ServiceDll"="%systemroot%\system32\profsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProtectedStorage]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PSched]
"ImagePath"="system32\DRIVERS\pacer.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ql2300]
"ImagePath"="\SystemRoot\system32\drivers\ql2300.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ql40xx]
"ImagePath"="\SystemRoot\system32\drivers\ql40xx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\QWAVE]
"ServiceDll"="%windir%\system32\qwave.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\QWAVEdrv]
"ImagePath"="\SystemRoot\system32\drivers\qwavedrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasAcd]
"ImagePath"="System32\DRIVERS\rasacd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasAuto]
"ServiceDll"="%SystemRoot%\System32\rasauto.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Rasl2tp]
"ImagePath"="system32\DRIVERS\rasl2tp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasMan]
"ServiceDll"="%SystemRoot%\System32\rasmans.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasPppoe]
"ImagePath"="system32\DRIVERS\raspppoe.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasSstp]
"ImagePath"="system32\DRIVERS\rassstp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdbss]
"ImagePath"="system32\DRIVERS\rdbss.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPCDD]
"ImagePath"="System32\DRIVERS\RDPCDD.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPDD]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdpdr]
"ImagePath"="system32\DRIVERS\rdpdr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPENCDD]
"ImagePath"="system32\drivers\rdpencdd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPNP]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPWD]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess]
"ServiceDLL"="%SystemRoot%\System32\mprdim.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteRegistry]
"ServiceDll"="%SystemRoot%\system32\regsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcLocator]
"ImagePath"="%SystemRoot%\system32\locator.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcSs]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rspndr]
"ImagePath"="system32\DRIVERS\rspndr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SamSs]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sbp2port]
"ImagePath"="\SystemRoot\system32\drivers\sbp2port.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SCardSvr]
"ServiceDll"="%SystemRoot%\System32\SCardSvr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Schedule]
"ServiceDll"="%systemroot%\system32\schedsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SCPolicySvc]
"ServiceDll"="%SystemRoot%\System32\certprop.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SDRSVC]
"ServiceDll"="%Systemroot%\System32\SDRSVC.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\secdrv]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\seclogon]
"ServiceDll"="%windir%\system32\seclogon.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SENS]
"ServiceDll"="%SystemRoot%\system32\sens.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Serenum]
"ImagePath"="system32\DRIVERS\serenum.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Serial]
"ImagePath"="system32\DRIVERS\serial.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sermouse]
"ImagePath"="\SystemRoot\system32\drivers\sermouse.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelEndpoint 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelOperation 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelService 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SessionEnv]
"ServiceDLL"="%SystemRoot%\system32\sessenv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffdisk]
"ImagePath"="\SystemRoot\system32\drivers\sffdisk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffp_mmc]
"ImagePath"="\SystemRoot\system32\drivers\sffp_mmc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffp_sd]
"ImagePath"="\SystemRoot\system32\drivers\sffp_sd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sfloppy]
"ImagePath"="\SystemRoot\system32\drivers\sfloppy.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess]
"ServiceDll"="%SystemRoot%\System32\ipnathlp.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ShellHWDetection]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SiSRaid2]
"ImagePath"="\SystemRoot\system32\drivers\sisraid2.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SiSRaid4]
"ImagePath"="\SystemRoot\system32\drivers\sisraid4.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\slsvc]
"ImagePath"="%SystemRoot%\system32\SLsvc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SLUINotify]
"ServiceDll"="%SystemRoot%\system32\SLUINotify.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Smb]
"ImagePath"="system32\DRIVERS\smb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SMSvcHost 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SMSvcHost 4.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SNMPTRAP]
"ImagePath"="%SystemRoot%\System32\snmptrap.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\spldr]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Spooler]
"ImagePath"="%SystemRoot%\System32\spoolsv.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srv]
"ImagePath"="System32\DRIVERS\srv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srv2]
"ImagePath"="System32\DRIVERS\srv2.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srvnet]
"ImagePath"="System32\DRIVERS\srvnet.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSDPSRV]
"ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SstpSvc]
"ServiceDll"="%SystemRoot%\system32\sstpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\stisvc]
"ServiceDll"="%SystemRoot%\System32\wiaservc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\swenum]
"ImagePath"="system32\DRIVERS\swenum.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\swprv]
"ServiceDll"="%Systemroot%\System32\swprv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Symc8xx]
"ImagePath"="\SystemRoot\system32\drivers\symc8xx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sym_hi]
"ImagePath"="\SystemRoot\system32\drivers\sym_hi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sym_u3]
"ImagePath"="\SystemRoot\system32\drivers\sym_u3.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysMain]
"ServiceDll"="%systemroot%\system32\sysmain.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TabletInputService]
"ServiceDll"="%SystemRoot%\System32\TabSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv]
"ServiceDll"="%SystemRoot%\System32\tapisrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TBS]
"ServiceDll"="%SystemRoot%\System32\tbssvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip]
"ImagePath"="System32\drivers\tcpip.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6]
"ImagePath"="system32\DRIVERS\tcpip.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tcpipreg]
"ImagePath"="System32\drivers\tcpipreg.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDPIPE]
"ImagePath"="system32\drivers\tdpipe.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDTCP]
"ImagePath"="system32\drivers\tdtcp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tdx]
"ImagePath"="system32\DRIVERS\tdx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TermDD]
"ImagePath"="system32\DRIVERS\termdd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TermService]
"ServiceDll"="%SystemRoot%\System32\termsrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Themes]
"ServiceDll"="%SystemRoot%\system32\shsvcs.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\THREADORDER]
"ServiceDll"="%SystemRoot%\system32\mmcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks]
"ServiceDll"="%SystemRoot%\System32\trkwks.dll"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrustedInstaller]
"ImagePath"="%SystemRoot%\servicing\TrustedInstaller.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TSDDD]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tssecsrv]
"ImagePath"="System32\DRIVERS\tssecsrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tunmp]
"ImagePath"="system32\DRIVERS\tunmp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tunnel]
"ImagePath"="system32\DRIVERS\tunnel.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uagp35]
"ImagePath"="\SystemRoot\system32\drivers\uagp35.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\udfs]
"ImagePath"="system32\DRIVERS\udfs.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UGatherer]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UGTHRSVC]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UI0Detect]
"ImagePath"="%SystemRoot%\system32\UI0Detect.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uliagpkx]
"ImagePath"="\SystemRoot\system32\drivers\uliagpkx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uliahci]
"ImagePath"="\SystemRoot\system32\drivers\uliahci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UlSata]
"ImagePath"="\SystemRoot\system32\drivers\ulsata.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ulsata2]
"ImagePath"="\SystemRoot\system32\drivers\ulsata2.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\umbus]
"ImagePath"="system32\DRIVERS\umbus.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UmRdpService]
"ServiceDll"="%SystemRoot%\System32\umrdp.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\upnphost]
"ServiceDll"="%SystemRoot%\System32\upnphost.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usb]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbbus]
"ImagePath"="system32\DRIVERS\lgx64bus.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbccgp]
"ImagePath"="system32\DRIVERS\usbccgp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbcir]
"ImagePath"="\SystemRoot\system32\drivers\usbcir.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UsbDiag]
"ImagePath"="system32\DRIVERS\lgx64diag.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbehci]
"ImagePath"="system32\DRIVERS\usbehci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UsbGps]
"ImagePath"="system32\DRIVERS\lgx64gps.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbhub]
"ImagePath"="system32\DRIVERS\usbhub.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\USBModem]
"ImagePath"="system32\DRIVERS\lgx64modem.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbohci]
"ImagePath"="\SystemRoot\system32\drivers\usbohci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbprint]
"ImagePath"="system32\DRIVERS\usbprint.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbscan]
"ImagePath"="system32\DRIVERS\usbscan.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\USBSTOR]
"ImagePath"="system32\DRIVERS\USBSTOR.SYS"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbuhci]
"ImagePath"="system32\DRIVERS\usbuhci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UxSms]
"ServiceDll"="%SystemRoot%\System32\uxsms.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vds]
"ImagePath"="%SystemRoot%\System32\vds.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vga]
"ImagePath"="system32\DRIVERS\vgapnp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VgaSave]
"ImagePath"="\SystemRoot\System32\drivers\vga.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\viaide]
"ImagePath"="\SystemRoot\system32\drivers\viaide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volmgr]
"ImagePath"="system32\drivers\volmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volmgrx]
"ImagePath"="System32\drivers\volmgrx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volsnap]
"ImagePath"="system32\drivers\volsnap.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vsmraid]
"ImagePath"="\SystemRoot\system32\drivers\vsmraid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS]
"ImagePath"="%systemroot%\system32\vssvc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W32Time]
"ServiceDll"="%systemroot%\system32\w32time.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W3SVC]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WacomPen]
"ImagePath"="\SystemRoot\system32\drivers\wacompen.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wanarp]
"ImagePath"="system32\DRIVERS\wanarp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wanarpv6]
"ImagePath"="system32\DRIVERS\wanarp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wbengine]
"ImagePath"="\"%systemroot%\system32\wbengine.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wcncsvc]
"ServiceDll"="%SystemRoot%\System32\wcncsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WcsPlugInService]
"ServiceDll"="%SystemRoot%\System32\WcsPlugInService.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wd]
"ImagePath"="\SystemRoot\system32\drivers\wd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wdf01000]
"ImagePath"="system32\drivers\Wdf01000.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WdiServiceHost]
"ServiceDll"="%SystemRoot%\system32\wdi.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WdiSystemHost]
"ServiceDll"="%SystemRoot%\system32\wdi.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebClient]
"ServiceDll"="%SystemRoot%\System32\webclnt.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wecsvc]
"ServiceDll"="%SystemRoot%\system32\wecsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wercplsupport]
"ServiceDll"="%SystemRoot%\System32\wercplsupport.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WerSvc]
"ServiceDll"="%SystemRoot%\System32\WerSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinDefend]
"ServiceDll"="%ProgramFiles%\Windows Defender\mpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Windows Workflow Foundation 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinHttpAutoProxySvc]
"ServiceDll"="winhttp.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winmgmt]
"ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinRM]
"ServiceDll"="%SystemRoot%\system32\WsmSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wlansvc]
"ServiceDll"="%SystemRoot%\System32\wlansvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiAcpi]
"ImagePath"="\SystemRoot\system32\drivers\wmiacpi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiApRpl]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wmiApSrv]
"ImagePath"="%systemroot%\system32\wbem\WmiApSrv.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WMPNetworkSvc]
"ImagePath"="\"%ProgramFiles%\Windows Media Player\wmpnetwk.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WPDBusEnum]
"ServiceDll"="%SystemRoot%\system32\wpdbusenum.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WpdUsb]
"ImagePath"="system32\DRIVERS\wpdusb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WPFFontCache_v0400]
"ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ws2ifsl]
"ImagePath"="\SystemRoot\system32\drivers\ws2ifsl.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WSearch]
"ImagePath"="%systemroot%\system32\SearchIndexer.exe /Embedding"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WSearchIdxPi]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv]
"ServiceDll"="%systemroot%\system32\wuaueng.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WudfPf]
"ImagePath"="system32\drivers\WudfPf.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WUDFRd]
"ImagePath"="system32\DRIVERS\WUDFRd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wudfsvc]
"ServiceDll"="%SystemRoot%\System32\WUDFSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\YahooAUService]
"ImagePath"="\"c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yksvc]
"ServiceDll"="%SystemRoot%\System32\ykx64mpcoinst.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yukonx64]
"ImagePath"="system32\DRIVERS\yk60x64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{07171AC2-0D2A-427d-BCE5-B6C2D6C7058B}]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{8E7FF6BA-8E5A-46B1-B8A4-EE49F9A0BFAE}]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-12-01 11:36:53
ComboFix-quarantined-files.txt 2013-12-01 18:36
.
Pre-Run: 89,275,867,136 bytes free
Post-Run: 90,324,500,480 bytes free
.
- - End Of File - - CA6DB3391309F7C4696CF27EA8632809
5C616939100B85E558DA92B899A0FC36

neilw

Newbie Surfer
Newbie Surfer

Posts : 36
Joined : 2013-11-27
Operating System : vista

View user profile

Back to top Go down

Re: Ask, keeps overpowering google on one site only cant stop it!

Post by Sponsored content Today at 12:47 pm


Sponsored content


Back to top Go down

Page 1 of 2 1, 2  Next

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum