bradrice76
New Member
I somehow got this adware program (BetterMarkit) stuck on my computer. It isn't anything but an annoyance, but trying to just read a story or mouse of a picture it's a HUGE one. I've read the short explanations on other pages on how to remove - I followed these instructions which included:
1. removing the actual program in Programs and Features (first removal still left the name (removed icon). Second removal stated it couldn't be found and removed it from list of programs.
2. Opened up Explorer and went to Programs and Manage Addons - program was not found but I did disable everything but Flash and Windows Media Player.
3. Explorer - Internet Options - Advanced - Reset - checked box reset personal options and reset it. (the first processed failed (with an X) not able to figure out why failed - link goes to a page that doesn't really explain why). The next 3 processes here were successful.
------------------------------------------------------------------------------------
I came across someone who it seemed had a similar problem with a "Re-Markit" and presumed (probably incorrectly) it may require the same steps here for anyone to help me. If not sorry for the waste of space -
Instructions I followed were from - http://www.computerforum.com/228391-re-markit-cant-get-rid-thing.html
1. # AdwCleaner v4.102 - Report created 28/11/2014 at 10:39:36
# Updated 23/11/2014 by Xplode
# Database : 2014-11-27.1 [Live]
# Operating System : Windows 8.1 (64 bits)
# Username : Brad Rice - DESKTOP
# Running from : C:\Users\Brad Rice\AppData\Local\Microsoft\Windows\INetCache\IE\5AE61J4E\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\AVG Security Toolbar
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\LinkSwift
Folder Deleted : C:\WINDOWS\SysWOW64\AI_RecycleBin
Folder Deleted : C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\Application Updater
Folder Deleted : C:\Users\Brad Rice\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Brad Rice\AppData\Local\CrashRpt
Folder Deleted : C:\Users\Brad Rice\AppData\Roaming\Mozilla\Firefox\Profiles\2w91t0s7.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
File Deleted : C:\END
File Deleted : C:\Users\Brad Rice\AppData\Roaming\Mozilla\Firefox\Profiles\2w91t0s7.default\user.js
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\Uninstall QuickTime.lnk
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\.bdc
Key Deleted : HKLM\SOFTWARE\Classes\.bgl
Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\AppDataLow\Software\BetterMarkIt
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v26.0 (en-US)
[2w91t0s7.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename", "Search The Web");
[2w91t0s7.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Search The Web");
*************************
AdwCleaner[R0].txt - [4636 octets] - [28/11/2014 10:36:51]
AdwCleaner[S0].txt - [4509 octets] - [28/11/2014 10:39:36]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4569 octets] ##########
----------------------------------------------------------------------------------------
2. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.9 (11.15.2014:2)
OS: Windows 8.1 x64
Ran by Brad Rice on Fri 11/28/2014 at 10:45:18.90
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
~~~ Files
Successfully deleted: [File] "C:\WINDOWS\wininit.ini"
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 11/28/2014 at 10:46:55.50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
3. Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 11/28/2014
Scan Time: 10:48:56 AM
Logfile: Malware Log.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.28.04
Rootkit Database: v2014.11.22.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Brad Rice
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 368919
Time Elapsed: 7 min, 37 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
4. OTL logfile created on: 11/28/2014 10:58:40 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Brad Rice\AppData\Local\Microsoft\Windows\INetCache\IE\20D0YU0X
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.87 Gb Total Physical Memory | 6.36 Gb Available Physical Memory | 80.83% Memory free
81.11 Gb Paging File | 79.61 Gb Available in Paging File | 98.15% Paging File free
Paging file location(s): c:\pagefile.sys 75000 75000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 914.10 Gb Total Space | 88.74 Gb Free Space | 9.71% Space Free | Partition Type: NTFS
Drive E: | 653.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 1.84 Gb Total Space | 0.49 Gb Free Space | 26.95% Space Free | Partition Type: FAT
Computer Name: DESKTOP | User Name: Brad Rice | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Brad Rice\AppData\Local\Microsoft\Windows\INetCache\IE\20D0YU0X\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Razer\RzWizard\RzWizard.exe (Razer Inc.)
PRC - C:\Program Files (x86)\Razer\RzWizard\RzWizardService.exe (Razer Inc.)
PRC - C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe ()
PRC - C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe (LeapFrog Enterprises, Inc.)
PRC - C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (CyberLink)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - c:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\7159bb28e23de8ed898a2acb1dbfef6c\System.ServiceModel.Internals.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\1c09d6db83322a23a1744d75c4836f85\SMDiagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\43edd630a9f8cd6ac38c527b106ec94f\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\6281ab590224520bad7c4f5b3ef37575\System.Xaml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\70c6bf4a51d18b4a9a1805cd48d1caad\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\055a9f703a30ece9cce1f6a130a296b5\System.ServiceModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\ab763e7f2c7532e9fe8f587995105156\System.Runtime.Serialization.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\8efdc7a3726640f79d9333da88accaf8\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\00fc7d14bbb38db00e4103912c041adf\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\eb62bc6e97d1d2aafbf3a101d7f029e1\PresentationFramework.Aero2.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\377e9afc870e7d53922fbcfd6023b2f7\PresentationFramework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\a1799dc618cfa61adb75b82311884c3d\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\b8e2e79f70d09551560548cda72e2c51\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\483443985708dc5439abe7fd6350abe4\System.Core.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\1c5fe4cb68f67046baec4c3a854f722f\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\c90ef9a73ea0044641d31b19023aad61\mscorlib.ni.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (OutfoxTvService) -- C:\Program Files\OutfoxTV\OutfoxTvService.exe File not found
SRV:64bit: - (IEEtwCollectorService) -- C:\WINDOWS\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (AudioEndpointBuilder) -- C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:64bit: - (WdNisSvc) -- C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (PrintNotify) -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:64bit: - (SystemEventsBroker) -- C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (BrokerInfrastructure) -- C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:64bit: - (workfolderssvc) -- C:\Windows\SysNative\workfolderssvc.dll (Microsoft Corporation)
SRV:64bit: - (lfsvc) -- C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
SRV:64bit: - (AppXSvc) -- C:\Windows\SysNative\AppXDeploymentServer.dll (Microsoft Corporation)
SRV:64bit: - (Netlogon) -- C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:64bit: - (WSService) -- C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:64bit: - (LSM) -- C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:64bit: - (Wcmsvc) -- C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:64bit: - (DeviceAssociationService) -- C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:64bit: - (wlidsvc) -- C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppReadiness) -- C:\Windows\SysNative\AppReadiness.dll (Microsoft Corporation)
SRV:64bit: - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe (McAfee, Inc.)
SRV:64bit: - (WEPHOSTSVC) -- C:\Windows\SysNative\wephostsvc.dll (Microsoft Corporation)
SRV:64bit: - (EFS) -- C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:64bit: - (WiaRpc) -- C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:64bit: - (svsvc) -- C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:64bit: - (fhsvc) -- C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:64bit: - (NcaSvc) -- C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicvss) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmictimesync) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicshutdown) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicrdv) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmickvpexchange) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicheartbeat) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicguestinterface) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (smphost) -- C:\Windows\SysNative\smphost.dll (Microsoft Corporation)
SRV:64bit: - (ScDeviceEnum) -- C:\Windows\SysNative\ScDeviceEnum.dll (Microsoft Corporation)
SRV:64bit: - (KeyIso) -- C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:64bit: - (TimeBroker) -- C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (netprofm) -- C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:64bit: - (NcbService) -- C:\Windows\SysNative\ncbservice.dll (Microsoft Corporation)
SRV:64bit: - (VaultSvc) -- C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:64bit: - (DsmSvc) -- C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:64bit: - (NcdAutoSetup) -- C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:64bit: - (ePowerSvc) -- C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (Intel(R) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (BRSptStub) -- C:\ProgramData\BitRaider\BRSptStub.exe (BitRaider, LLC)
SRV - (ArcService) -- C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe (Perfect World Entertainment Inc)
SRV - (RzWizardService) -- C:\Program Files (x86)\Razer\RzWizard\RzWizardService.exe (Razer Inc.)
SRV - (PrintNotify) -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (lfsvc) -- C:\Windows\SysWOW64\GeofenceMonitorService.dll (Microsoft Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (LeapFrog Connect Device Service) -- C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe (LeapFrog Enterprises, Inc.)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (StorSvc) -- C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (smphost) -- C:\Windows\SysWOW64\smphost.dll (Microsoft Corporation)
SRV - (AtherosSvc) -- C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (Qualcomm Atheros Commnucations)
SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (NAUpdate) -- c:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (IconMan_R) -- C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (ICCS) -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)
SRV - (GamesAppService) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (webinstrH) -- C:\Windows\SysNative\drivers\webinstrH.sys (Corsica)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (WdFilter) -- C:\Windows\SysNative\drivers\WdFilter.sys (Microsoft Corporation)
DRV:64bit: - (WdNisDrv) -- C:\Windows\SysNative\drivers\WdNisDrv.sys (Microsoft Corporation)
DRV:64bit: - (WdBoot) -- C:\Windows\SysNative\drivers\WdBoot.sys (Microsoft Corporation)
DRV:64bit: - (GPIOClx0101) -- C:\Windows\SysNative\drivers\msgpioclx.sys (Microsoft Corporation)
DRV:64bit: - (USBHUB3) -- C:\Windows\SysNative\drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:64bit: - (spaceport) -- C:\Windows\SysNative\drivers\spaceport.sys (Microsoft Corporation)
DRV:64bit: - (NdisImPlatform) -- C:\Windows\SysNative\drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:64bit: - (wpcfltr) -- C:\Windows\SysNative\drivers\wpcfltr.sys (Microsoft Corporation)
DRV:64bit: - (CLFS) -- C:\Windows\SysNative\drivers\clfs.sys (Microsoft Corporation)
DRV:64bit: - (Wof) -- C:\WINDOWS\SysNative\drivers\wof.sys (Microsoft Corporation)
DRV:64bit: - (WFPLWFS) -- C:\Windows\SysNative\drivers\wfplwfs.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (USBXHCI) -- C:\Windows\SysNative\drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:64bit: - (UCX01000) -- C:\Windows\SysNative\drivers\UCX01000.SYS (Microsoft Corporation)
DRV:64bit: - (sdstor) -- C:\Windows\SysNative\drivers\sdstor.sys (Microsoft Corporation)
DRV:64bit: - (ReFS) -- C:\WINDOWS\SysNative\drivers\refs.sys (Microsoft Corporation)
DRV:64bit: - (BasicRender) -- C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
DRV:64bit: - (SCDEmu) -- C:\WINDOWS\SysNative\drivers\scdemu.sys (Power Software Ltd)
DRV:64bit: - (stornvme) -- C:\Windows\SysNative\drivers\stornvme.sys (Microsoft Corporation)
DRV:64bit: - (BthLEEnum) -- C:\Windows\SysNative\drivers\BthLEEnum.sys (Microsoft Corporation)
DRV:64bit: - (intelpep) -- C:\Windows\SysNative\drivers\intelpep.sys (Microsoft Corporation)
DRV:64bit: - (pdc) -- C:\Windows\SysNative\drivers\pdc.sys (Microsoft Corporation)
DRV:64bit: - (SerCx2) -- C:\Windows\SysNative\drivers\SerCx2.sys (Microsoft Corporation)
DRV:64bit: - (VerifierExt) -- C:\Windows\SysNative\drivers\VerifierExt.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (intaud_WaveExtensible) -- C:\Windows\SysNative\drivers\intelaud.sys (Intel Corporation)
DRV:64bit: - (iwdbus) -- C:\Windows\SysNative\drivers\iwdbus.sys (Intel Corporation)
DRV:64bit: - (condrv) -- C:\Windows\SysNative\drivers\condrv.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\WINDOWS\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (dam) -- C:\Windows\SysNative\drivers\dam.sys (Microsoft Corporation)
DRV:64bit: - (acpiex) -- C:\Windows\SysNative\drivers\acpiex.sys (Microsoft Corporation)
DRV:64bit: - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (mvumis) -- C:\Windows\SysNative\drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (msgpiowin32) -- C:\Windows\SysNative\drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (LSI_SSS) -- C:\Windows\SysNative\drivers\lsi_sss.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (LSI_SAS3) -- C:\Windows\SysNative\drivers\lsi_sas3.sys (LSI Corporation)
DRV:64bit: - (ADP80XX) -- C:\Windows\SysNative\drivers\adp80xx.sys (PMC-Sierra)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (3ware) -- C:\Windows\SysNative\drivers\3ware.sys (LSI)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (EhStorTcgDrv) -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:64bit: - (EhStorClass) -- C:\Windows\SysNative\drivers\EhStorClass.sys (Microsoft Corporation)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (VSTXRAID) -- C:\Windows\SysNative\drivers\VSTXRAID.SYS (VIA Corporation)
DRV:64bit: - (UASPStor) -- C:\Windows\SysNative\drivers\uaspstor.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology, Inc.)
DRV:64bit: - (storahci) -- C:\Windows\SysNative\drivers\storahci.sys (Microsoft Corporation)
DRV:64bit: - (SpbCx) -- C:\Windows\SysNative\drivers\SpbCx.sys (Microsoft Corporation)
DRV:64bit: - (SerCx) -- C:\Windows\SysNative\drivers\SerCx.sys (Microsoft Corporation)
DRV:64bit: - (UEFI) -- C:\Windows\SysNative\drivers\uefi.sys (Microsoft Corporation)
DRV:64bit: - (vpci) -- C:\Windows\SysNative\drivers\vpci.sys (Microsoft Corporation)
DRV:64bit: - (WpdUpFltr) -- C:\Windows\SysNative\drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:64bit: - (ahcache) -- C:\Windows\SysNative\drivers\ahcache.sys (Microsoft Corporation)
DRV:64bit: - (BasicDisplay) -- C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:64bit: - (HyperVideo) -- C:\Windows\SysNative\drivers\HyperVideo.sys (Microsoft Corporation)
DRV:64bit: - (mshidumdf) -- C:\Windows\SysNative\drivers\mshidumdf.sys (Microsoft Corporation)
DRV:64bit: - (acpitime) -- C:\Windows\SysNative\drivers\acpitime.sys (Microsoft Corporation)
DRV:64bit: - (acpipagr) -- C:\Windows\SysNative\drivers\acpipagr.sys (Microsoft Corporation)
DRV:64bit: - (BthAvrcpTg) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:64bit: - (kdnic) -- C:\Windows\SysNative\drivers\kdnic.sys (Microsoft Corporation)
DRV:64bit: - (gencounter) -- C:\Windows\SysNative\drivers\vmgencounter.sys (Microsoft Corporation)
DRV:64bit: - (npsvctrig) -- C:\Windows\SysNative\drivers\npsvctrig.sys (Microsoft Corporation)
DRV:64bit: - (bthhfhid) -- C:\Windows\SysNative\drivers\BthhfHid.sys (Microsoft Corporation)
DRV:64bit: - (hyperkbd) -- C:\Windows\SysNative\drivers\hyperkbd.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (BthHFEnum) -- C:\Windows\SysNative\drivers\bthhfenum.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (hidi2c) -- C:\Windows\SysNative\drivers\hidi2c.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (netvsc) -- C:\Windows\SysNative\drivers\netvsc63.sys (Microsoft Corporation)
DRV:64bit: - (NdisVirtualBus) -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys (Microsoft Corporation)
DRV:64bit: - (MsLldp) -- C:\Windows\SysNative\drivers\mslldp.sys (Microsoft Corporation)
DRV:64bit: - (Ndu) -- C:\Windows\SysNative\drivers\Ndu.sys (Microsoft Corporation)
DRV:64bit: - (FxPPM) -- C:\Windows\SysNative\drivers\fxppm.sys (Microsoft Corporation)
DRV:64bit: - (bcmfn2) -- C:\Windows\SysNative\drivers\bcmfn2.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (iaStorAV) -- C:\Windows\SysNative\drivers\iaStorAV.sys (Intel Corporation)
DRV:64bit: - (iaLPSSi_GPIO) -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys (Intel Corporation)
DRV:64bit: - (iaLPSSi_I2C) -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys (Intel Corporation)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athw8x.sys (Qualcomm Atheros Communications, Inc.)
DRV:64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Qualcomm Atheros)
DRV:64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Qualcomm Atheros)
DRV:64bit: - (iaStorA) -- C:\Windows\SysNative\drivers\iaStorA.sys (Intel Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (e1cexpress) -- C:\Windows\SysNative\drivers\e1c63x64.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV - (BRDriver64_1_3_3_E02B25FC) -- C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys (BitRaider)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {4AEA64AF-5DA5-48E7-9D86-151EC55A5A39}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{4AEA64AF-5DA5-48E7-9D86-151EC55A5A39}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAGWJS
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {4AEA64AF-5DA5-48E7-9D86-151EC55A5A39}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{4AEA64AF-5DA5-48E7-9D86-151EC55A5A39}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAGWJS
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 85 F8 99 A1 1F 0B D0 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0
FF - prefs.js..keyword.URL: ""
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@perfectworld.com/npArcPlayNowPlugin: C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKCU\Software\MozillaPlugins\thehappycloud.com/HappyCloudPlugin: C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{FC555378-24E8-38BC-E367-AC341D736C1C}: C:\Program Files (x86)\ver0BetterMarkIt\184.xpi
[2013/08/11 09:25:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Brad Rice\AppData\Roaming\Mozilla\Extensions
[2014/11/28 10:39:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Brad Rice\AppData\Roaming\Mozilla\Firefox\Profiles\2w91t0s7.default\extensions
[2014/08/09 08:32:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/01/18 02:14:29 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) -- C:\USERS\BRAD RICE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2W91T0S7.DEFAULT\EXTENSIONS\{607B689F-7600-45E4-B8E5-887F72DAB15C}
File not found (No name found) -- C:\USERS\BRAD RICE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2W91T0S7.DEFAULT\EXTENSIONS\[email protected]
O1 HOSTS File: ([2013/08/22 08:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ArcPluginIEBHO Class) - {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} - C:\Program Files (x86)\Perfect World Entertainment\Arc\plugins\ArcPluginIE.dll (Perfect World Entertainment Inc)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [BtPreLoad] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtPreLoad.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Arc] C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcLauncher.exe (Perfect World Entertainment)
O4 - HKLM..\Run: [Monitor] C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (Power Software Ltd)
O4 - HKLM..\Run: [RzWizard] C:\Program Files (x86)\Razer\RzWizard\RzWizard.exe (Razer Inc.)
O4 - HKCU..\Run: [AVG-Secure-Search-Update_0414c] C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe ()
O4 - HKCU..\Run: [Battle.net] "C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe" --autostarted File not found
O4 - Startup: C:\Users\Brad Rice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk = C:\Users\Brad Rice\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SafeModeBlockNonAdmins = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com/bin/srldetect_intel_4.5.22.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{924B6229-2AA2-4BA6-850D-ED7ACE203FE9}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/10/24 20:15:56 | 000,921,600 | R--- | M] (Quarium, Inc.) - E:\autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2002/10/24 20:15:56 | 000,000,053 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{6abe57e4-9628-11e3-bf48-24fd523b0f48}\Shell - "" = AutoRun
O33 - MountPoints2\{6abe57e4-9628-11e3-bf48-24fd523b0f48}\Shell\AutoRun\command - "" = "G:\AutoRun.exe"
O33 - MountPoints2\{f48989f7-af8a-11e2-be6a-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f48989f7-af8a-11e2-be6a-806e6f6e6963}\Shell\AutoRun\command - "" = E:\autorun.exe -- [2002/10/24 20:15:56 | 000,921,600 | R--- | M] (Quarium, Inc.)
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = "D:\Autorun.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/11/28 10:45:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2014/11/28 10:38:06 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Desktop\New folder (3)
[2014/11/28 10:36:19 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/11/26 09:19:10 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\Heroes of the Storm
[2014/11/26 09:17:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm
[2014/11/26 08:42:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Heroes of the Storm
[2014/11/26 07:15:17 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Desktop\movies want
[2014/11/26 02:16:52 | 000,064,232 | ---- | C] (Corsica) -- C:\WINDOWS\SysNative\drivers\webinstrH.sys
[2014/11/24 21:01:36 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Desktop\New folder
[2014/11/23 02:30:35 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\Star Wars - The Old Republic
[2014/11/23 02:29:02 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\HeroBlade Logs
[2014/11/23 01:33:23 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\BitRaider
[2014/11/23 01:33:23 | 000,000,000 | ---D | C] -- C:\ProgramData\BitRaider
[2014/11/23 01:33:04 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\SWTORPerf
[2014/11/23 01:30:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Electronic Arts
[2014/11/23 01:30:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\BioWare
[2014/11/22 23:53:56 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\TERA
[2014/11/22 20:47:36 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\RIFT
[2014/11/22 20:47:36 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\RIFT
[2014/11/22 19:36:00 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\Glyph
[2014/11/22 19:36:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Glyph
[2014/11/22 19:35:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Glyph
[2014/11/22 19:21:37 | 000,000,000 | -H-D | C] -- C:\ArcTemp
[2014/11/22 19:21:08 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Arc
[2014/11/22 18:44:46 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Arc
[2014/11/22 18:44:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
[2014/11/22 18:44:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Perfect World Entertainment
[2014/11/22 18:22:11 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\Funcom
[2014/11/22 18:21:58 | 000,000,000 | ---D | C] -- C:\ProgramData\media center programs
[2014/11/22 18:21:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Funcom
[2014/11/22 08:18:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2014/11/22 07:50:20 | 000,000,000 | ---D | C] -- C:\ProgramData\GFACE
[2014/11/22 07:50:18 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\wf-launcher
[2014/11/22 07:49:31 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warface Launcher
[2014/11/22 07:49:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Crytek
[2014/11/22 06:01:31 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\Ubisoft
[2014/11/22 06:01:14 | 000,000,000 | -HSD | C] -- C:\Users\Brad Rice\wc
[2014/11/22 06:01:10 | 000,000,000 | -HSD | C] -- C:\Users\Brad Rice\AppData\Roaming\wyUpdate AU
[2014/11/22 06:01:06 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duel of Champions Launcher
[2014/11/22 06:01:05 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Ubisoft
[2014/11/22 04:23:23 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Happy Cloud
[2014/11/22 04:23:17 | 000,000,000 | ---D | C] -- C:\ProgramData\HappyCloud
[2014/11/20 00:48:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Angels
[2014/11/20 00:48:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\League of Angels
[2014/11/18 01:11:21 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\11bitstudios
[2014/11/18 01:11:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\This War of Mine
[2014/11/18 01:11:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\This War of Mine
[2014/11/13 01:41:35 | 000,000,000 | -HSD | C] -- C:\Users\Brad Rice\AppData\Local\EmieBrowserModeList
[2014/11/05 17:54:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\directx
[2014/11/05 17:54:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grand Theft Auto San Andreas + MultiPlayer [0.3e]
[2014/11/05 17:51:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Grand Theft Auto San Andreas + MultiPlayer [0.3e]
[2014/11/05 17:13:58 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\Square Enix
[2014/11/05 17:09:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Final Fantasy VII
[2014/11/05 17:09:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Final Fantasy VII
[2014/11/05 16:54:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tiger Woods
[2014/11/04 15:24:57 | 000,118,832 | ---- | C] (MicroQuill Software Publishing, Inc.) -- C:\WINDOWS\SysWow64\SHW32.DLL
[2014/11/04 00:43:44 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\GTA Vice City User Files
[2014/11/04 00:34:52 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2014/11/04 00:34:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2014/11/04 00:34:52 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\InstallShield Installation Information
[2014/11/04 00:34:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Rockstar Games
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/11/28 10:48:24 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2014/11/28 10:47:00 | 000,863,592 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2014/11/28 10:47:00 | 000,730,408 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2014/11/28 10:47:00 | 000,135,520 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2014/11/28 10:42:30 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/11/28 10:40:46 | 000,000,388 | ---- | M] () -- C:\WINDOWS\tasks\AVG-Secure-Search-Update_0414c_rmv.job
[2014/11/28 10:40:45 | 000,001,716 | ---- | M] () -- C:\WINDOWS\tasks\WOOFYCO.job
[2014/11/28 10:40:45 | 000,001,362 | ---- | M] () -- C:\WINDOWS\tasks\CJ.job
[2014/11/28 10:40:45 | 000,000,388 | ---- | M] () -- C:\WINDOWS\tasks\AVG-Secure-Search-Update_0414c_rel.job
[2014/11/28 10:40:28 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014/11/28 10:40:25 | 2467,659,775 | -HS- | M] () -- C:\hiberfil.sys
[2014/11/28 10:02:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/11/27 01:17:11 | 000,001,121 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/11/26 21:05:16 | 000,002,035 | ---- | M] () -- C:\WINDOWS\patsearch.bin
[2014/11/26 09:17:42 | 000,001,208 | ---- | M] () -- C:\Users\Public\Desktop\Heroes of the Storm.lnk
[2014/11/26 02:16:52 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_webinstrH_01009.Wdf
[2014/11/26 02:16:37 | 000,064,232 | ---- | M] (Corsica) -- C:\WINDOWS\SysNative\drivers\webinstrH.sys
[2014/11/22 18:44:34 | 000,001,858 | ---- | M] () -- C:\Users\Public\Desktop\Arc.lnk
[2014/11/22 07:53:50 | 000,001,119 | ---- | M] () -- C:\Users\Brad Rice\Desktop\Duel of Champions Launcher.lnk
[2014/11/22 07:49:32 | 000,001,936 | ---- | M] () -- C:\Users\Brad Rice\Desktop\Warface Launcher.lnk
[2014/11/18 01:11:14 | 000,001,122 | ---- | M] () -- C:\Users\Public\Desktop\This War of Mine.lnk
[2014/11/12 22:26:05 | 000,337,808 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2014/11/05 18:04:10 | 000,001,305 | ---- | M] () -- C:\Users\Brad Rice\Desktop\gta_sa - Shortcut.lnk
[2014/11/05 17:09:11 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Final Fantasy VII.lnk
[2014/11/05 16:22:57 | 000,000,876 | ---- | M] () -- C:\Users\Public\Desktop\Age of Empires II HD.lnk
[2014/11/04 00:37:43 | 000,001,317 | ---- | M] () -- C:\Users\Brad Rice\Desktop\gta-vc - Shortcut.lnk
[2014/10/31 12:00:54 | 000,071,078 | ---- | M] () -- C:\Users\Brad Rice\Documents\cc_20141031_130040.reg
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/11/26 09:17:42 | 000,001,208 | ---- | C] () -- C:\Users\Public\Desktop\Heroes of the Storm.lnk
[2014/11/26 02:16:52 | 000,002,035 | ---- | C] () -- C:\WINDOWS\patsearch.bin
[2014/11/26 02:16:52 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_webinstrH_01009.Wdf
[2014/11/26 02:14:00 | 000,001,362 | ---- | C] () -- C:\WINDOWS\tasks\CJ.job
[2014/11/26 02:13:42 | 000,001,716 | ---- | C] () -- C:\WINDOWS\tasks\WOOFYCO.job
[2014/11/22 18:44:34 | 000,001,858 | ---- | C] () -- C:\Users\Public\Desktop\Arc.lnk
[2014/11/22 07:49:32 | 000,001,936 | ---- | C] () -- C:\Users\Brad Rice\Desktop\Warface Launcher.lnk
[2014/11/22 06:01:06 | 000,001,119 | ---- | C] () -- C:\Users\Brad Rice\Desktop\Duel of Champions Launcher.lnk
[2014/11/18 01:11:14 | 000,001,122 | ---- | C] () -- C:\Users\Public\Desktop\This War of Mine.lnk
[2014/11/12 05:15:39 | 000,389,176 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2014/11/05 18:04:10 | 000,001,305 | ---- | C] () -- C:\Users\Brad Rice\Desktop\gta_sa - Shortcut.lnk
[2014/11/05 17:09:10 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Final Fantasy VII.lnk
[2014/11/05 16:22:57 | 000,000,888 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Age of Empires II HD.lnk
[2014/11/05 16:22:57 | 000,000,876 | ---- | C] () -- C:\Users\Public\Desktop\Age of Empires II HD.lnk
[2014/11/04 00:37:43 | 000,001,317 | ---- | C] () -- C:\Users\Brad Rice\Desktop\gta-vc - Shortcut.lnk
[2014/10/31 12:00:45 | 000,071,078 | ---- | C] () -- C:\Users\Brad Rice\Documents\cc_20141031_130040.reg
[2014/09/01 03:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Brad Rice\AppData\Roaming\CJ
[2014/09/01 03:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Brad Rice\AppData\Roaming\WOOFYCO
[2014/06/23 00:13:48 | 000,000,017 | ---- | C] () -- C:\Users\Brad Rice\AppData\Local\resmon.resmoncfg
[2014/05/28 00:56:35 | 000,000,048 | ---- | C] () -- C:\Users\Brad Rice\jagex_cl_runescape_LIVE.dat
[2014/05/28 00:56:35 | 000,000,024 | ---- | C] () -- C:\Users\Brad Rice\random.dat
[2014/05/09 09:50:14 | 000,000,000 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
[2014/05/05 11:21:45 | 000,597,244 | ---- | C] () -- C:\WINDOWS\SysWow64\igvpkrng700.bin
[2014/05/05 11:21:42 | 000,064,512 | ---- | C] () -- C:\WINDOWS\SysWow64\igdde32.dll
[2014/05/05 11:21:41 | 000,755,048 | ---- | C] () -- C:\WINDOWS\SysWow64\igcodeckrng700.bin
[2014/04/29 01:31:52 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014/03/18 04:35:49 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2013/12/10 11:33:12 | 000,000,866 | RHS- | C] () -- C:\Users\Brad Rice\ntuser.pol
[2013/10/03 23:42:46 | 000,343,040 | ---- | C] () -- C:\WINDOWS\SysWow64\igdmd32.dll
[2013/10/03 23:42:38 | 000,142,848 | ---- | C] () -- C:\WINDOWS\SysWow64\igdail32.dll
[2013/08/24 00:28:36 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2013/08/22 10:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013/08/22 10:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013/08/22 09:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013/08/22 02:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013/08/21 22:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013/08/21 18:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013/08/21 18:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
========== ZeroAccess Check ==========
[2014/02/01 17:16:22 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/08/30 19:15:33 | 021,197,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/08/30 17:59:13 | 018,723,112 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 04:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/21 21:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 04:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014/04/05 21:24:08 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\.minecraft
[2014/11/18 01:11:21 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\11bitstudios
[2014/11/22 19:21:36 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Arc
[2014/07/28 13:13:27 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Awesomium
[2014/11/27 01:13:49 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Azureus
[2014/07/23 19:24:40 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Battle.net
[2014/05/10 12:50:15 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\ConverterLite
[2014/06/27 01:06:34 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Curse
[2014/10/14 21:16:07 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Curse Client
[2014/03/10 08:49:29 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Hoyle
[2014/03/10 08:49:29 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Hoyle FaceCreator
[2014/05/28 01:33:53 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\LolClient
[2014/03/27 08:24:22 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\MediaPlayerLite
[2014/02/26 05:50:36 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\PlayFirst
[2014/02/08 02:54:10 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\PowerISO
[2013/09/25 17:53:02 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\raidcall
[2014/11/22 20:54:55 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\RIFT
[2014/05/28 00:21:31 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Riot Games
[2014/02/01 23:34:28 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\The Creative Assembly
[2014/05/30 23:42:52 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\TS3Client
[2014/11/22 06:01:05 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Ubisoft
[2013/08/08 09:51:03 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\WildTangent
[2014/11/22 06:01:10 | 000,000,000 | -HSD | M] -- C:\Users\Brad Rice\AppData\Roaming\wyUpdate AU
========== Purity Check ==========
< End of report >
--------------------------------------------------------------------------------------
Thanks for any help anyone can give me. Happy Holidays.
1. removing the actual program in Programs and Features (first removal still left the name (removed icon). Second removal stated it couldn't be found and removed it from list of programs.
2. Opened up Explorer and went to Programs and Manage Addons - program was not found but I did disable everything but Flash and Windows Media Player.
3. Explorer - Internet Options - Advanced - Reset - checked box reset personal options and reset it. (the first processed failed (with an X) not able to figure out why failed - link goes to a page that doesn't really explain why). The next 3 processes here were successful.
------------------------------------------------------------------------------------
I came across someone who it seemed had a similar problem with a "Re-Markit" and presumed (probably incorrectly) it may require the same steps here for anyone to help me. If not sorry for the waste of space -
Instructions I followed were from - http://www.computerforum.com/228391-re-markit-cant-get-rid-thing.html
1. # AdwCleaner v4.102 - Report created 28/11/2014 at 10:39:36
# Updated 23/11/2014 by Xplode
# Database : 2014-11-27.1 [Live]
# Operating System : Windows 8.1 (64 bits)
# Username : Brad Rice - DESKTOP
# Running from : C:\Users\Brad Rice\AppData\Local\Microsoft\Windows\INetCache\IE\5AE61J4E\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\AVG Security Toolbar
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\LinkSwift
Folder Deleted : C:\WINDOWS\SysWOW64\AI_RecycleBin
Folder Deleted : C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\Application Updater
Folder Deleted : C:\Users\Brad Rice\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Brad Rice\AppData\Local\CrashRpt
Folder Deleted : C:\Users\Brad Rice\AppData\Roaming\Mozilla\Firefox\Profiles\2w91t0s7.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
File Deleted : C:\END
File Deleted : C:\Users\Brad Rice\AppData\Roaming\Mozilla\Firefox\Profiles\2w91t0s7.default\user.js
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\Uninstall QuickTime.lnk
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\.bdc
Key Deleted : HKLM\SOFTWARE\Classes\.bgl
Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\AppDataLow\Software\BetterMarkIt
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v26.0 (en-US)
[2w91t0s7.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename", "Search The Web");
[2w91t0s7.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Search The Web");
*************************
AdwCleaner[R0].txt - [4636 octets] - [28/11/2014 10:36:51]
AdwCleaner[S0].txt - [4509 octets] - [28/11/2014 10:39:36]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4569 octets] ##########
----------------------------------------------------------------------------------------
2. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.9 (11.15.2014:2)
OS: Windows 8.1 x64
Ran by Brad Rice on Fri 11/28/2014 at 10:45:18.90
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
~~~ Files
Successfully deleted: [File] "C:\WINDOWS\wininit.ini"
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 11/28/2014 at 10:46:55.50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
3. Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 11/28/2014
Scan Time: 10:48:56 AM
Logfile: Malware Log.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.28.04
Rootkit Database: v2014.11.22.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Brad Rice
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 368919
Time Elapsed: 7 min, 37 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
4. OTL logfile created on: 11/28/2014 10:58:40 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Brad Rice\AppData\Local\Microsoft\Windows\INetCache\IE\20D0YU0X
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.87 Gb Total Physical Memory | 6.36 Gb Available Physical Memory | 80.83% Memory free
81.11 Gb Paging File | 79.61 Gb Available in Paging File | 98.15% Paging File free
Paging file location(s): c:\pagefile.sys 75000 75000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 914.10 Gb Total Space | 88.74 Gb Free Space | 9.71% Space Free | Partition Type: NTFS
Drive E: | 653.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 1.84 Gb Total Space | 0.49 Gb Free Space | 26.95% Space Free | Partition Type: FAT
Computer Name: DESKTOP | User Name: Brad Rice | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Brad Rice\AppData\Local\Microsoft\Windows\INetCache\IE\20D0YU0X\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Razer\RzWizard\RzWizard.exe (Razer Inc.)
PRC - C:\Program Files (x86)\Razer\RzWizard\RzWizardService.exe (Razer Inc.)
PRC - C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe ()
PRC - C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe (LeapFrog Enterprises, Inc.)
PRC - C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (CyberLink)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - c:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\7159bb28e23de8ed898a2acb1dbfef6c\System.ServiceModel.Internals.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\1c09d6db83322a23a1744d75c4836f85\SMDiagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\43edd630a9f8cd6ac38c527b106ec94f\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\6281ab590224520bad7c4f5b3ef37575\System.Xaml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\70c6bf4a51d18b4a9a1805cd48d1caad\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\055a9f703a30ece9cce1f6a130a296b5\System.ServiceModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\ab763e7f2c7532e9fe8f587995105156\System.Runtime.Serialization.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\8efdc7a3726640f79d9333da88accaf8\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\00fc7d14bbb38db00e4103912c041adf\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\eb62bc6e97d1d2aafbf3a101d7f029e1\PresentationFramework.Aero2.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\377e9afc870e7d53922fbcfd6023b2f7\PresentationFramework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\a1799dc618cfa61adb75b82311884c3d\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\b8e2e79f70d09551560548cda72e2c51\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\483443985708dc5439abe7fd6350abe4\System.Core.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\1c5fe4cb68f67046baec4c3a854f722f\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\c90ef9a73ea0044641d31b19023aad61\mscorlib.ni.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (OutfoxTvService) -- C:\Program Files\OutfoxTV\OutfoxTvService.exe File not found
SRV:64bit: - (IEEtwCollectorService) -- C:\WINDOWS\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (AudioEndpointBuilder) -- C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:64bit: - (WdNisSvc) -- C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (PrintNotify) -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:64bit: - (SystemEventsBroker) -- C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (BrokerInfrastructure) -- C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:64bit: - (workfolderssvc) -- C:\Windows\SysNative\workfolderssvc.dll (Microsoft Corporation)
SRV:64bit: - (lfsvc) -- C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
SRV:64bit: - (AppXSvc) -- C:\Windows\SysNative\AppXDeploymentServer.dll (Microsoft Corporation)
SRV:64bit: - (Netlogon) -- C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:64bit: - (WSService) -- C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:64bit: - (LSM) -- C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:64bit: - (Wcmsvc) -- C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:64bit: - (DeviceAssociationService) -- C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:64bit: - (wlidsvc) -- C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppReadiness) -- C:\Windows\SysNative\AppReadiness.dll (Microsoft Corporation)
SRV:64bit: - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe (McAfee, Inc.)
SRV:64bit: - (WEPHOSTSVC) -- C:\Windows\SysNative\wephostsvc.dll (Microsoft Corporation)
SRV:64bit: - (EFS) -- C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:64bit: - (WiaRpc) -- C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:64bit: - (svsvc) -- C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:64bit: - (fhsvc) -- C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:64bit: - (NcaSvc) -- C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicvss) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmictimesync) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicshutdown) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicrdv) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmickvpexchange) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicheartbeat) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicguestinterface) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (smphost) -- C:\Windows\SysNative\smphost.dll (Microsoft Corporation)
SRV:64bit: - (ScDeviceEnum) -- C:\Windows\SysNative\ScDeviceEnum.dll (Microsoft Corporation)
SRV:64bit: - (KeyIso) -- C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:64bit: - (TimeBroker) -- C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (netprofm) -- C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:64bit: - (NcbService) -- C:\Windows\SysNative\ncbservice.dll (Microsoft Corporation)
SRV:64bit: - (VaultSvc) -- C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:64bit: - (DsmSvc) -- C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:64bit: - (NcdAutoSetup) -- C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:64bit: - (ePowerSvc) -- C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (Intel(R) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (BRSptStub) -- C:\ProgramData\BitRaider\BRSptStub.exe (BitRaider, LLC)
SRV - (ArcService) -- C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe (Perfect World Entertainment Inc)
SRV - (RzWizardService) -- C:\Program Files (x86)\Razer\RzWizard\RzWizardService.exe (Razer Inc.)
SRV - (PrintNotify) -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (lfsvc) -- C:\Windows\SysWOW64\GeofenceMonitorService.dll (Microsoft Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (LeapFrog Connect Device Service) -- C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe (LeapFrog Enterprises, Inc.)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (StorSvc) -- C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (smphost) -- C:\Windows\SysWOW64\smphost.dll (Microsoft Corporation)
SRV - (AtherosSvc) -- C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (Qualcomm Atheros Commnucations)
SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (NAUpdate) -- c:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (IconMan_R) -- C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (ICCS) -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)
SRV - (GamesAppService) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (webinstrH) -- C:\Windows\SysNative\drivers\webinstrH.sys (Corsica)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (WdFilter) -- C:\Windows\SysNative\drivers\WdFilter.sys (Microsoft Corporation)
DRV:64bit: - (WdNisDrv) -- C:\Windows\SysNative\drivers\WdNisDrv.sys (Microsoft Corporation)
DRV:64bit: - (WdBoot) -- C:\Windows\SysNative\drivers\WdBoot.sys (Microsoft Corporation)
DRV:64bit: - (GPIOClx0101) -- C:\Windows\SysNative\drivers\msgpioclx.sys (Microsoft Corporation)
DRV:64bit: - (USBHUB3) -- C:\Windows\SysNative\drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:64bit: - (spaceport) -- C:\Windows\SysNative\drivers\spaceport.sys (Microsoft Corporation)
DRV:64bit: - (NdisImPlatform) -- C:\Windows\SysNative\drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:64bit: - (wpcfltr) -- C:\Windows\SysNative\drivers\wpcfltr.sys (Microsoft Corporation)
DRV:64bit: - (CLFS) -- C:\Windows\SysNative\drivers\clfs.sys (Microsoft Corporation)
DRV:64bit: - (Wof) -- C:\WINDOWS\SysNative\drivers\wof.sys (Microsoft Corporation)
DRV:64bit: - (WFPLWFS) -- C:\Windows\SysNative\drivers\wfplwfs.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (USBXHCI) -- C:\Windows\SysNative\drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:64bit: - (UCX01000) -- C:\Windows\SysNative\drivers\UCX01000.SYS (Microsoft Corporation)
DRV:64bit: - (sdstor) -- C:\Windows\SysNative\drivers\sdstor.sys (Microsoft Corporation)
DRV:64bit: - (ReFS) -- C:\WINDOWS\SysNative\drivers\refs.sys (Microsoft Corporation)
DRV:64bit: - (BasicRender) -- C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
DRV:64bit: - (SCDEmu) -- C:\WINDOWS\SysNative\drivers\scdemu.sys (Power Software Ltd)
DRV:64bit: - (stornvme) -- C:\Windows\SysNative\drivers\stornvme.sys (Microsoft Corporation)
DRV:64bit: - (BthLEEnum) -- C:\Windows\SysNative\drivers\BthLEEnum.sys (Microsoft Corporation)
DRV:64bit: - (intelpep) -- C:\Windows\SysNative\drivers\intelpep.sys (Microsoft Corporation)
DRV:64bit: - (pdc) -- C:\Windows\SysNative\drivers\pdc.sys (Microsoft Corporation)
DRV:64bit: - (SerCx2) -- C:\Windows\SysNative\drivers\SerCx2.sys (Microsoft Corporation)
DRV:64bit: - (VerifierExt) -- C:\Windows\SysNative\drivers\VerifierExt.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (intaud_WaveExtensible) -- C:\Windows\SysNative\drivers\intelaud.sys (Intel Corporation)
DRV:64bit: - (iwdbus) -- C:\Windows\SysNative\drivers\iwdbus.sys (Intel Corporation)
DRV:64bit: - (condrv) -- C:\Windows\SysNative\drivers\condrv.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\WINDOWS\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (dam) -- C:\Windows\SysNative\drivers\dam.sys (Microsoft Corporation)
DRV:64bit: - (acpiex) -- C:\Windows\SysNative\drivers\acpiex.sys (Microsoft Corporation)
DRV:64bit: - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (mvumis) -- C:\Windows\SysNative\drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (msgpiowin32) -- C:\Windows\SysNative\drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (LSI_SSS) -- C:\Windows\SysNative\drivers\lsi_sss.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (LSI_SAS3) -- C:\Windows\SysNative\drivers\lsi_sas3.sys (LSI Corporation)
DRV:64bit: - (ADP80XX) -- C:\Windows\SysNative\drivers\adp80xx.sys (PMC-Sierra)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (3ware) -- C:\Windows\SysNative\drivers\3ware.sys (LSI)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (EhStorTcgDrv) -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:64bit: - (EhStorClass) -- C:\Windows\SysNative\drivers\EhStorClass.sys (Microsoft Corporation)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (VSTXRAID) -- C:\Windows\SysNative\drivers\VSTXRAID.SYS (VIA Corporation)
DRV:64bit: - (UASPStor) -- C:\Windows\SysNative\drivers\uaspstor.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology, Inc.)
DRV:64bit: - (storahci) -- C:\Windows\SysNative\drivers\storahci.sys (Microsoft Corporation)
DRV:64bit: - (SpbCx) -- C:\Windows\SysNative\drivers\SpbCx.sys (Microsoft Corporation)
DRV:64bit: - (SerCx) -- C:\Windows\SysNative\drivers\SerCx.sys (Microsoft Corporation)
DRV:64bit: - (UEFI) -- C:\Windows\SysNative\drivers\uefi.sys (Microsoft Corporation)
DRV:64bit: - (vpci) -- C:\Windows\SysNative\drivers\vpci.sys (Microsoft Corporation)
DRV:64bit: - (WpdUpFltr) -- C:\Windows\SysNative\drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:64bit: - (ahcache) -- C:\Windows\SysNative\drivers\ahcache.sys (Microsoft Corporation)
DRV:64bit: - (BasicDisplay) -- C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:64bit: - (HyperVideo) -- C:\Windows\SysNative\drivers\HyperVideo.sys (Microsoft Corporation)
DRV:64bit: - (mshidumdf) -- C:\Windows\SysNative\drivers\mshidumdf.sys (Microsoft Corporation)
DRV:64bit: - (acpitime) -- C:\Windows\SysNative\drivers\acpitime.sys (Microsoft Corporation)
DRV:64bit: - (acpipagr) -- C:\Windows\SysNative\drivers\acpipagr.sys (Microsoft Corporation)
DRV:64bit: - (BthAvrcpTg) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:64bit: - (kdnic) -- C:\Windows\SysNative\drivers\kdnic.sys (Microsoft Corporation)
DRV:64bit: - (gencounter) -- C:\Windows\SysNative\drivers\vmgencounter.sys (Microsoft Corporation)
DRV:64bit: - (npsvctrig) -- C:\Windows\SysNative\drivers\npsvctrig.sys (Microsoft Corporation)
DRV:64bit: - (bthhfhid) -- C:\Windows\SysNative\drivers\BthhfHid.sys (Microsoft Corporation)
DRV:64bit: - (hyperkbd) -- C:\Windows\SysNative\drivers\hyperkbd.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (BthHFEnum) -- C:\Windows\SysNative\drivers\bthhfenum.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (hidi2c) -- C:\Windows\SysNative\drivers\hidi2c.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (netvsc) -- C:\Windows\SysNative\drivers\netvsc63.sys (Microsoft Corporation)
DRV:64bit: - (NdisVirtualBus) -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys (Microsoft Corporation)
DRV:64bit: - (MsLldp) -- C:\Windows\SysNative\drivers\mslldp.sys (Microsoft Corporation)
DRV:64bit: - (Ndu) -- C:\Windows\SysNative\drivers\Ndu.sys (Microsoft Corporation)
DRV:64bit: - (FxPPM) -- C:\Windows\SysNative\drivers\fxppm.sys (Microsoft Corporation)
DRV:64bit: - (bcmfn2) -- C:\Windows\SysNative\drivers\bcmfn2.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (iaStorAV) -- C:\Windows\SysNative\drivers\iaStorAV.sys (Intel Corporation)
DRV:64bit: - (iaLPSSi_GPIO) -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys (Intel Corporation)
DRV:64bit: - (iaLPSSi_I2C) -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys (Intel Corporation)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athw8x.sys (Qualcomm Atheros Communications, Inc.)
DRV:64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Qualcomm Atheros)
DRV:64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Qualcomm Atheros)
DRV:64bit: - (iaStorA) -- C:\Windows\SysNative\drivers\iaStorA.sys (Intel Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (e1cexpress) -- C:\Windows\SysNative\drivers\e1c63x64.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV - (BRDriver64_1_3_3_E02B25FC) -- C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys (BitRaider)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {4AEA64AF-5DA5-48E7-9D86-151EC55A5A39}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{4AEA64AF-5DA5-48E7-9D86-151EC55A5A39}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAGWJS
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {4AEA64AF-5DA5-48E7-9D86-151EC55A5A39}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{4AEA64AF-5DA5-48E7-9D86-151EC55A5A39}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAGWJS
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 85 F8 99 A1 1F 0B D0 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0
FF - prefs.js..keyword.URL: ""
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@perfectworld.com/npArcPlayNowPlugin: C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKCU\Software\MozillaPlugins\thehappycloud.com/HappyCloudPlugin: C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{FC555378-24E8-38BC-E367-AC341D736C1C}: C:\Program Files (x86)\ver0BetterMarkIt\184.xpi
[2013/08/11 09:25:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Brad Rice\AppData\Roaming\Mozilla\Extensions
[2014/11/28 10:39:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Brad Rice\AppData\Roaming\Mozilla\Firefox\Profiles\2w91t0s7.default\extensions
[2014/08/09 08:32:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/01/18 02:14:29 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) -- C:\USERS\BRAD RICE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2W91T0S7.DEFAULT\EXTENSIONS\{607B689F-7600-45E4-B8E5-887F72DAB15C}
File not found (No name found) -- C:\USERS\BRAD RICE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2W91T0S7.DEFAULT\EXTENSIONS\[email protected]
O1 HOSTS File: ([2013/08/22 08:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ArcPluginIEBHO Class) - {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} - C:\Program Files (x86)\Perfect World Entertainment\Arc\plugins\ArcPluginIE.dll (Perfect World Entertainment Inc)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [BtPreLoad] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtPreLoad.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Arc] C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcLauncher.exe (Perfect World Entertainment)
O4 - HKLM..\Run: [Monitor] C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (Power Software Ltd)
O4 - HKLM..\Run: [RzWizard] C:\Program Files (x86)\Razer\RzWizard\RzWizard.exe (Razer Inc.)
O4 - HKCU..\Run: [AVG-Secure-Search-Update_0414c] C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe ()
O4 - HKCU..\Run: [Battle.net] "C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe" --autostarted File not found
O4 - Startup: C:\Users\Brad Rice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk = C:\Users\Brad Rice\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SafeModeBlockNonAdmins = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com/bin/srldetect_intel_4.5.22.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{924B6229-2AA2-4BA6-850D-ED7ACE203FE9}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/10/24 20:15:56 | 000,921,600 | R--- | M] (Quarium, Inc.) - E:\autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2002/10/24 20:15:56 | 000,000,053 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{6abe57e4-9628-11e3-bf48-24fd523b0f48}\Shell - "" = AutoRun
O33 - MountPoints2\{6abe57e4-9628-11e3-bf48-24fd523b0f48}\Shell\AutoRun\command - "" = "G:\AutoRun.exe"
O33 - MountPoints2\{f48989f7-af8a-11e2-be6a-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f48989f7-af8a-11e2-be6a-806e6f6e6963}\Shell\AutoRun\command - "" = E:\autorun.exe -- [2002/10/24 20:15:56 | 000,921,600 | R--- | M] (Quarium, Inc.)
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = "D:\Autorun.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/11/28 10:45:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2014/11/28 10:38:06 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Desktop\New folder (3)
[2014/11/28 10:36:19 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/11/26 09:19:10 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\Heroes of the Storm
[2014/11/26 09:17:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm
[2014/11/26 08:42:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Heroes of the Storm
[2014/11/26 07:15:17 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Desktop\movies want
[2014/11/26 02:16:52 | 000,064,232 | ---- | C] (Corsica) -- C:\WINDOWS\SysNative\drivers\webinstrH.sys
[2014/11/24 21:01:36 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Desktop\New folder
[2014/11/23 02:30:35 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\Star Wars - The Old Republic
[2014/11/23 02:29:02 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\HeroBlade Logs
[2014/11/23 01:33:23 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\BitRaider
[2014/11/23 01:33:23 | 000,000,000 | ---D | C] -- C:\ProgramData\BitRaider
[2014/11/23 01:33:04 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\SWTORPerf
[2014/11/23 01:30:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Electronic Arts
[2014/11/23 01:30:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\BioWare
[2014/11/22 23:53:56 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\TERA
[2014/11/22 20:47:36 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\RIFT
[2014/11/22 20:47:36 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\RIFT
[2014/11/22 19:36:00 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\Glyph
[2014/11/22 19:36:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Glyph
[2014/11/22 19:35:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Glyph
[2014/11/22 19:21:37 | 000,000,000 | -H-D | C] -- C:\ArcTemp
[2014/11/22 19:21:08 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Arc
[2014/11/22 18:44:46 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Arc
[2014/11/22 18:44:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
[2014/11/22 18:44:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Perfect World Entertainment
[2014/11/22 18:22:11 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\Funcom
[2014/11/22 18:21:58 | 000,000,000 | ---D | C] -- C:\ProgramData\media center programs
[2014/11/22 18:21:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Funcom
[2014/11/22 08:18:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2014/11/22 07:50:20 | 000,000,000 | ---D | C] -- C:\ProgramData\GFACE
[2014/11/22 07:50:18 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\wf-launcher
[2014/11/22 07:49:31 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warface Launcher
[2014/11/22 07:49:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Crytek
[2014/11/22 06:01:31 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Local\Ubisoft
[2014/11/22 06:01:14 | 000,000,000 | -HSD | C] -- C:\Users\Brad Rice\wc
[2014/11/22 06:01:10 | 000,000,000 | -HSD | C] -- C:\Users\Brad Rice\AppData\Roaming\wyUpdate AU
[2014/11/22 06:01:06 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duel of Champions Launcher
[2014/11/22 06:01:05 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Ubisoft
[2014/11/22 04:23:23 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Happy Cloud
[2014/11/22 04:23:17 | 000,000,000 | ---D | C] -- C:\ProgramData\HappyCloud
[2014/11/20 00:48:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Angels
[2014/11/20 00:48:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\League of Angels
[2014/11/18 01:11:21 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\11bitstudios
[2014/11/18 01:11:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\This War of Mine
[2014/11/18 01:11:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\This War of Mine
[2014/11/13 01:41:35 | 000,000,000 | -HSD | C] -- C:\Users\Brad Rice\AppData\Local\EmieBrowserModeList
[2014/11/05 17:54:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\directx
[2014/11/05 17:54:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grand Theft Auto San Andreas + MultiPlayer [0.3e]
[2014/11/05 17:51:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Grand Theft Auto San Andreas + MultiPlayer [0.3e]
[2014/11/05 17:13:58 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\Square Enix
[2014/11/05 17:09:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Final Fantasy VII
[2014/11/05 17:09:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Final Fantasy VII
[2014/11/05 16:54:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tiger Woods
[2014/11/04 15:24:57 | 000,118,832 | ---- | C] (MicroQuill Software Publishing, Inc.) -- C:\WINDOWS\SysWow64\SHW32.DLL
[2014/11/04 00:43:44 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\Documents\GTA Vice City User Files
[2014/11/04 00:34:52 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2014/11/04 00:34:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2014/11/04 00:34:52 | 000,000,000 | ---D | C] -- C:\Users\Brad Rice\AppData\Roaming\InstallShield Installation Information
[2014/11/04 00:34:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Rockstar Games
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/11/28 10:48:24 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2014/11/28 10:47:00 | 000,863,592 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2014/11/28 10:47:00 | 000,730,408 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2014/11/28 10:47:00 | 000,135,520 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2014/11/28 10:42:30 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/11/28 10:40:46 | 000,000,388 | ---- | M] () -- C:\WINDOWS\tasks\AVG-Secure-Search-Update_0414c_rmv.job
[2014/11/28 10:40:45 | 000,001,716 | ---- | M] () -- C:\WINDOWS\tasks\WOOFYCO.job
[2014/11/28 10:40:45 | 000,001,362 | ---- | M] () -- C:\WINDOWS\tasks\CJ.job
[2014/11/28 10:40:45 | 000,000,388 | ---- | M] () -- C:\WINDOWS\tasks\AVG-Secure-Search-Update_0414c_rel.job
[2014/11/28 10:40:28 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014/11/28 10:40:25 | 2467,659,775 | -HS- | M] () -- C:\hiberfil.sys
[2014/11/28 10:02:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/11/27 01:17:11 | 000,001,121 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/11/26 21:05:16 | 000,002,035 | ---- | M] () -- C:\WINDOWS\patsearch.bin
[2014/11/26 09:17:42 | 000,001,208 | ---- | M] () -- C:\Users\Public\Desktop\Heroes of the Storm.lnk
[2014/11/26 02:16:52 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_webinstrH_01009.Wdf
[2014/11/26 02:16:37 | 000,064,232 | ---- | M] (Corsica) -- C:\WINDOWS\SysNative\drivers\webinstrH.sys
[2014/11/22 18:44:34 | 000,001,858 | ---- | M] () -- C:\Users\Public\Desktop\Arc.lnk
[2014/11/22 07:53:50 | 000,001,119 | ---- | M] () -- C:\Users\Brad Rice\Desktop\Duel of Champions Launcher.lnk
[2014/11/22 07:49:32 | 000,001,936 | ---- | M] () -- C:\Users\Brad Rice\Desktop\Warface Launcher.lnk
[2014/11/18 01:11:14 | 000,001,122 | ---- | M] () -- C:\Users\Public\Desktop\This War of Mine.lnk
[2014/11/12 22:26:05 | 000,337,808 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2014/11/05 18:04:10 | 000,001,305 | ---- | M] () -- C:\Users\Brad Rice\Desktop\gta_sa - Shortcut.lnk
[2014/11/05 17:09:11 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Final Fantasy VII.lnk
[2014/11/05 16:22:57 | 000,000,876 | ---- | M] () -- C:\Users\Public\Desktop\Age of Empires II HD.lnk
[2014/11/04 00:37:43 | 000,001,317 | ---- | M] () -- C:\Users\Brad Rice\Desktop\gta-vc - Shortcut.lnk
[2014/10/31 12:00:54 | 000,071,078 | ---- | M] () -- C:\Users\Brad Rice\Documents\cc_20141031_130040.reg
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/11/26 09:17:42 | 000,001,208 | ---- | C] () -- C:\Users\Public\Desktop\Heroes of the Storm.lnk
[2014/11/26 02:16:52 | 000,002,035 | ---- | C] () -- C:\WINDOWS\patsearch.bin
[2014/11/26 02:16:52 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_webinstrH_01009.Wdf
[2014/11/26 02:14:00 | 000,001,362 | ---- | C] () -- C:\WINDOWS\tasks\CJ.job
[2014/11/26 02:13:42 | 000,001,716 | ---- | C] () -- C:\WINDOWS\tasks\WOOFYCO.job
[2014/11/22 18:44:34 | 000,001,858 | ---- | C] () -- C:\Users\Public\Desktop\Arc.lnk
[2014/11/22 07:49:32 | 000,001,936 | ---- | C] () -- C:\Users\Brad Rice\Desktop\Warface Launcher.lnk
[2014/11/22 06:01:06 | 000,001,119 | ---- | C] () -- C:\Users\Brad Rice\Desktop\Duel of Champions Launcher.lnk
[2014/11/18 01:11:14 | 000,001,122 | ---- | C] () -- C:\Users\Public\Desktop\This War of Mine.lnk
[2014/11/12 05:15:39 | 000,389,176 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2014/11/05 18:04:10 | 000,001,305 | ---- | C] () -- C:\Users\Brad Rice\Desktop\gta_sa - Shortcut.lnk
[2014/11/05 17:09:10 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Final Fantasy VII.lnk
[2014/11/05 16:22:57 | 000,000,888 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Age of Empires II HD.lnk
[2014/11/05 16:22:57 | 000,000,876 | ---- | C] () -- C:\Users\Public\Desktop\Age of Empires II HD.lnk
[2014/11/04 00:37:43 | 000,001,317 | ---- | C] () -- C:\Users\Brad Rice\Desktop\gta-vc - Shortcut.lnk
[2014/10/31 12:00:45 | 000,071,078 | ---- | C] () -- C:\Users\Brad Rice\Documents\cc_20141031_130040.reg
[2014/09/01 03:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Brad Rice\AppData\Roaming\CJ
[2014/09/01 03:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Brad Rice\AppData\Roaming\WOOFYCO
[2014/06/23 00:13:48 | 000,000,017 | ---- | C] () -- C:\Users\Brad Rice\AppData\Local\resmon.resmoncfg
[2014/05/28 00:56:35 | 000,000,048 | ---- | C] () -- C:\Users\Brad Rice\jagex_cl_runescape_LIVE.dat
[2014/05/28 00:56:35 | 000,000,024 | ---- | C] () -- C:\Users\Brad Rice\random.dat
[2014/05/09 09:50:14 | 000,000,000 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
[2014/05/05 11:21:45 | 000,597,244 | ---- | C] () -- C:\WINDOWS\SysWow64\igvpkrng700.bin
[2014/05/05 11:21:42 | 000,064,512 | ---- | C] () -- C:\WINDOWS\SysWow64\igdde32.dll
[2014/05/05 11:21:41 | 000,755,048 | ---- | C] () -- C:\WINDOWS\SysWow64\igcodeckrng700.bin
[2014/04/29 01:31:52 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014/03/18 04:35:49 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2013/12/10 11:33:12 | 000,000,866 | RHS- | C] () -- C:\Users\Brad Rice\ntuser.pol
[2013/10/03 23:42:46 | 000,343,040 | ---- | C] () -- C:\WINDOWS\SysWow64\igdmd32.dll
[2013/10/03 23:42:38 | 000,142,848 | ---- | C] () -- C:\WINDOWS\SysWow64\igdail32.dll
[2013/08/24 00:28:36 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2013/08/22 10:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013/08/22 10:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013/08/22 09:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013/08/22 02:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013/08/21 22:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013/08/21 18:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013/08/21 18:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
========== ZeroAccess Check ==========
[2014/02/01 17:16:22 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/08/30 19:15:33 | 021,197,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/08/30 17:59:13 | 018,723,112 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 04:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/21 21:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 04:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014/04/05 21:24:08 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\.minecraft
[2014/11/18 01:11:21 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\11bitstudios
[2014/11/22 19:21:36 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Arc
[2014/07/28 13:13:27 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Awesomium
[2014/11/27 01:13:49 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Azureus
[2014/07/23 19:24:40 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Battle.net
[2014/05/10 12:50:15 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\ConverterLite
[2014/06/27 01:06:34 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Curse
[2014/10/14 21:16:07 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Curse Client
[2014/03/10 08:49:29 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Hoyle
[2014/03/10 08:49:29 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Hoyle FaceCreator
[2014/05/28 01:33:53 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\LolClient
[2014/03/27 08:24:22 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\MediaPlayerLite
[2014/02/26 05:50:36 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\PlayFirst
[2014/02/08 02:54:10 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\PowerISO
[2013/09/25 17:53:02 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\raidcall
[2014/11/22 20:54:55 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\RIFT
[2014/05/28 00:21:31 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Riot Games
[2014/02/01 23:34:28 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\The Creative Assembly
[2014/05/30 23:42:52 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\TS3Client
[2014/11/22 06:01:05 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\Ubisoft
[2013/08/08 09:51:03 | 000,000,000 | ---D | M] -- C:\Users\Brad Rice\AppData\Roaming\WildTangent
[2014/11/22 06:01:10 | 000,000,000 | -HSD | M] -- C:\Users\Brad Rice\AppData\Roaming\wyUpdate AU
========== Purity Check ==========
< End of report >
--------------------------------------------------------------------------------------
Thanks for any help anyone can give me. Happy Holidays.