Ramdom .exe has stopped working

speedx77x

Member
So when im on my desktop and not doing anything i keep on getting these random .exe has stopped working errors and im not sure what to do.

WWcK285.jpg


The one I've been getting today is mseyqkoezid.exe

Thursday i was getting Phoenix.exe and zfzhukqqmnud.exe

Do i have a virus? If so what program should i use?
 
Let's start with some scans

Please download Malwarebytes' Anti-Malware from here or here and save it to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version. Please keep updating until it says you have the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • A log will be saved automatically which you can access by clicking on the Logs tab within Malwarebytes' Anti-Malware

If for some reason Malwarebytes will not install or run please download and run Rkill.scr, Rkill.exe, or Rkill.com. If you are still having issues running rkill then try downloading these renamed versions of the same program.

EXPLORER.EXE
IEXPLORE.EXE
USERINIT.EXE
WINLOGON.EXE

But DO NOT reboot the system and then try installing or running Malwarebytes. If Rkill (which is a black box) appears and then disappears right away or you get a message saying rkill is infected, keep trying to run rkill until it over powers the infection and temporarily kills it. Once a log appears on the screen, you can try running malwarebytes or downloading other programs.



Download the HijackThis installer from here.
Run the installer and choose Install, indicating that you accept the licence agreement. The installer will place a shortcut on your desktop and launch HijackThis.

Vista and Windows 7 users must right click on the hijackthis icon and click on run as. If the run as option doesn't appear then press and hold the shift key while right clicking on the icon to get it to appear.


Click Do a system scan and save a logfile

Most of what HijackThis lists will be harmless or even essential, don't fix anything yet.

When the hijackthis log appears in a notepad file, click on the edit menu, click select all, then click on the edit menu again and click on copy. Come back to your reply and right click on your mouse and click on paste.

Post the logfile that HijackThis produces along with the Malwarebytes Anti-Malware log
 
Thanks it worked i used Malwarebytes' Anti-Malware BTW. Now i just have to uninstall Catalyst Control Center because it gives me so many problems.
 
Please post the logs as you may not be totally infection free, and that way we can get you cleaned up as best as possible and maybe find some other issues you didn't know you had.
 
Here's the last log

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.09.28.08

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Ryan :: RYAN-PC [administrator]

9/28/2013 12:44:59 PM
mbam-log-2013-09-28 (12-44-59).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 213648
Time elapsed: 15 minute(s), 56 second(s)

Memory Processes Detected: 1
C:\Users\Ryan\AppData\Roaming\Sony Creative Software Inc\tutle.exe (Trojan.Dropper) -> 3492 -> Delete on reboot.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 77
HKCR\CLSID\{52F8C28C-DEC6-6CCC-8CFD-18A4CFD005EE} (PUP.Optional.MultiPlug.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{52F8C28C-DEC6-6CCC-8CFD-18A4CFD005EE} (PUP.Optional.MultiPlug.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{52F8C28C-DEC6-6CCC-8CFD-18A4CFD005EE} (PUP.Optional.MultiPlug.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{52F8C28C-DEC6-6CCC-8CFD-18A4CFD005EE} (PUP.Optional.MultiPlug.A) -> No action taken.
HKCR\CLSID\{81E1C144-66F5-3D8A-3432-7C4924D09AB6} (PUP.Optional.MultiPlug.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{81E1C144-66F5-3D8A-3432-7C4924D09AB6} (PUP.Optional.MultiPlug.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{81E1C144-66F5-3D8A-3432-7C4924D09AB6} (PUP.Optional.MultiPlug.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{81E1C144-66F5-3D8A-3432-7C4924D09AB6} (PUP.Optional.MultiPlug.A) -> No action taken.
HKCR\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1} (PUP.Optional.BabylonToolBar.A) -> No action taken.
HKCR\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892} (PUP.Optional.PricePeep.A) -> No action taken.
HKCR\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB} (PUP.Optional.BabylonToolBar.A) -> No action taken.
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> No action taken.
HKCR\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\AppID\{F85FA3F2-D2C8-4D4D-BB1C-3181E691AF2B} (PUP.FaceThemes) -> No action taken.
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> No action taken.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> No action taken.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> No action taken.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> No action taken.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> No action taken.
HKCR\CLSID\{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> No action taken.
HKCR\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (PUP.Optional.PricePeep.A) -> No action taken.
HKCR\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408} (PUP.Optional.PricePeep.A) -> No action taken.
HKCR\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8} (PUP.Optional.PricePeep.A) -> No action taken.
HKCR\PricePeep.PricePeepBho.1 (PUP.Optional.PricePeep.A) -> No action taken.
HKCR\PricePeep.PricePeepBho (PUP.Optional.PricePeep.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (PUP.Optional.PricePeep.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (PUP.Optional.PricePeep.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (PUP.Optional.PricePeep.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{acd6a209-4aaf-4b1c-9930-b82fa131e958} (PUP.FCTPlugin) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{acd6a209-4aaf-4b1c-9930-b82fa131e958} (PUP.FCTPlugin) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} (PUP.Optional.Delta.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542} (PUP.Optional.BabylonToolBar.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2} (PUP.Optional.SelectionLinks) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2} (PUP.Optional.SelectionLinks) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2} (PUP.Optional.SelectionLinks) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2} (PUP.Optional.SelectionLinks) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{924C3DC2-8E4E-432E-F973-9A2174A39774} (PUP.Optional.SilentInstall.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A2C00D0B-C7D2-558E-8EE4-59A71274B47C} (PUP.Optional.Tarma.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5984BD42-D30D-3EEF-F40A-1F3A707CAD95} (PUP.Optional.Tarma.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E46A083F-3960-AB09-F92E-72E36735D0AF} (PUP.Optional.Tarma.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{88F92795-BC74-F238-3AF8-59CF6E4430D1} (PUP.Optional.Tarma.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhiteSmoke_New Toolbar (PUP.Optional.WhiteSmoke.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C1C3E833-420E-4D78-9BA7-86AEBB272384} (PUP.Optional.TopArcadeHits.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PricePeep (PUP.Optional.PricePeep.A) -> No action taken.
HKCR\AppID\PricePeep.DLL (PUP.Optional.PricePeep.A) -> No action taken.
HKCU\SOFTWARE\BabylonToolbar (PUP.Optional.BabylonToolBar.A) -> No action taken.
HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> No action taken.
HKCU\SOFTWARE\DELTA\DELTA (PUP.Optional.Delta.A) -> No action taken.
HKCU\Software\1ClickDownload (PUP.Optional.1ClickDownload.A) -> No action taken.
HKCU\Software\DataMngr (PUP.Optional.DataMngr.A) -> No action taken.
HKCU\Software\AppDataLow\SProtector (PUP.Optional.SProtector.A) -> No action taken.
HKCU\Software\AppDataLow\Software\PricePeep (PUP.Optional.PricePeep.A) -> No action taken.
HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> No action taken.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> No action taken.
HKLM\SOFTWARE\BabylonToolbar (PUP.Optional.Babylon.A) -> No action taken.
HKLM\SOFTWARE\Delta\delta\Instl (PUP.Optional.Delta.A) -> No action taken.
HKLM\SOFTWARE\Google\Chrome\Extensions\kincjchfokkeneeofpeefomkikfkiedl (PUP.FCTPlugin) -> No action taken.
HKLM\SOFTWARE\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk (PUP.Optional.Gophoto.A) -> No action taken.
HKLM\SYSTEM\CurrentControlSet\Services\FastFreeConverterUpdt (PUP.Optional.FastFreeConverter.A) -> No action taken.
HKCR\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (Adware.Agent) -> Quarantined and deleted successfully.
HKCR\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408} (Adware.Agent) -> Quarantined and deleted successfully.
HKCR\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8} (Adware.Agent) -> Quarantined and deleted successfully.
HKCR\PricePeep.PricePeepBho.1 (Adware.Agent) -> Quarantined and deleted successfully.
HKCR\PricePeep.PricePeepBho (Adware.Agent) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (Adware.Agent) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (Adware.Agent) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (Adware.Agent) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C1C3E833-420E-4D78-9BA7-86AEBB272384} (Adware.GameVance) -> Quarantined and deleted successfully.
HKCU\Software\DC3_FEXEC (Malware.Trace) -> Quarantined and deleted successfully.
HKCU\Software\PC Health Kit (Rogue.PCHealthKit) -> Quarantined and deleted successfully.
HKCU\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Detected: 11
HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> Data: -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> Data: WhiteSmoke New Toolbar -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> Data: -> No action taken.
HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{739df940-c5ee-4bab-9d7e-270894ae687a} (PUP.Optional.WhiteSmoke.A) -> Data: -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{739df940-c5ee-4bab-9d7e-270894ae687a} (PUP.Optional.WhiteSmoke.A) -> Data: -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Data: -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Data: Delta Toolbar -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{739df940-c5ee-4bab-9d7e-270894ae687a} (PUP.Optional.WhiteSmoke.A) -> Data: -> No action taken.
HKCU\SOFTWARE\Delta\Delta|tlbrSrchUrl (PUP.Optional.Delta.A) -> Data: -> No action taken.
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Data: 0W1M2Z0F1D1Q1P1R1O0O1H -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Keyboard Inf. (Trojan.Dropper) -> Data: C:\Users\Ryan\AppData\Roaming\Sony Creative Software Inc\tutle.exe -> Quarantined and deleted successfully.

Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs (PUP.Optional.SProtect.A) -> Bad: (c:\progra~2\savesh~1\sprote~1.dll) Good: () -> No action taken.

Folders Detected: 27
C:\Program Files (x86)\Object (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\content (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\defaults (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\defaults\preferences (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\locale (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\locale\en-US (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\skin (PUP.FCTPlugin) -> No action taken.
C:\Users\Ryan\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\YourFileDownloader (PUP.Optional.YourfileDownloader.A) -> No action taken.
C:\Users\Ryan\AppData\Local\TopArcadeHits (PUP.Optional.TopArcadeHits.A) -> No action taken.
C:\Program Files (x86)\PricePeep (PUP.Optional.PricePeep.A) -> No action taken.
C:\Users\Ryan\AppData\Roaming\Delta (PUP.Optional.Delta.A) -> No action taken.
C:\Program Files (x86)\Gophoto.it (PUP.Optional.Gophoto.A) -> No action taken.
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Cache (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053} (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Cache (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D} (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\Cache (PUP.Optional.Tarma.A) -> No action taken.
C:\Users\Ryan\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\Ryan\AppData\Roaming\OpenCandy\DED4F32233404EE284E9EC4D804C139E (PUP.Optional.OpenCandy) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Kit (Rogue.PCHealthKit) -> Quarantined and deleted successfully.

Files Detected: 159
C:\Program Files (x86)\SaveShare\sprotector.dll (PUP.Optional.SProtect.A) -> No action taken.
C:\ProgramData\syafe saVe\52154a0d29aeb.dll (PUP.Optional.MultiPlug.A) -> No action taken.
C:\ProgramData\sAafei savE\5219456a322a5.dll (PUP.Optional.MultiPlug.A) -> No action taken.
C:\Users\Ryan\AppData\Local\SwvUpdater\Updater.exe (PUP.Software.Updater) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\prxtbWhit.dll (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\PricePeep\pricepeep.dll (PUP.Optional.PricePeep.A) -> No action taken.
C:\ProgramData\Brouwse2saave\5174361e896e7.dll (PUP.Optional.MultiPlug.A) -> No action taken.
C:\ProgramData\InstallMate\{0990ED06-0A82-4BA1-A94A-42A0D273CFF0}\Setup.exe (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\InstallMate\{0990ED06-0A82-4BA1-A94A-42A0D273CFF0}\TsuDll.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\InstallMate\{2351CFD1-6D57-493B-ABD0-2575F8B2ED27}\Setup.exe (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\InstallMate\{2351CFD1-6D57-493B-ABD0-2575F8B2ED27}\TsuDll.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\InstallMate\{7D789C08-708C-466C-A487-38AEA69BBEFE}\Setup.exe (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\InstallMate\{7D789C08-708C-466C-A487-38AEA69BBEFE}\TsuDll.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\InstallMate\{A4A97720-5DCE-4DE5-AF0E-15EC7F4A55D6}\Setup.exe (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\InstallMate\{A4A97720-5DCE-4DE5-AF0E-15EC7F4A55D6}\TsuDll.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\sAafei savE\uninstall.exe (PUP.Optional.SilentInstall.A) -> No action taken.
C:\ProgramData\syafe saVe\uninstall.exe (PUP.Optional.SilentInstall.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\Setup.exe (PUP.Optional.Tarma.A) -> No action taken.
C:\Users\Ryan\AppData\Roaming\PowerISO\Upgrade\PowerISO5.exe (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\Ryan\Downloads\actual.multiple.monitors.4.1_2 (1).exe (PUP.Optional.4Squared) -> No action taken.
C:\Users\Ryan\Downloads\actual.multiple.monitors.4.1_2.exe (PUP.Optional.4Squared) -> No action taken.
C:\Users\Ryan\Downloads\Borderlands_2_Steam_Keygen_exe.exe (PUP.BundleInstaller.DW) -> No action taken.
C:\Users\Ryan\Downloads\CallofDutyBlackOpsIISKIDROW_downloader_by_PirateBayMirror.exe (PUP.Optional.Somoto) -> No action taken.
C:\Users\Ryan\Downloads\DownloadManager.exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\hans zimmer - epilogue main theme - crysis 2 soundtrack.exe (PUP.Optional.4Squared) -> No action taken.
C:\Users\Ryan\Downloads\Nico_vega-All-Albums-(Special-Edition).exe (PUP.BundleInstaller.DW) -> No action taken.
C:\Users\Ryan\Downloads\PAYDAY.2.Update.5-FTS.rar (1).exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\PAYDAY.2.Update.5-FTS.rar.exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\Photoshop CS6 .dll Replacement.rar (PUP.RiskwareTool.CK) -> No action taken.
C:\Users\Ryan\Downloads\playpickle-setup.exe (PUP.Optional.DownloadAdmin) -> No action taken.
C:\Users\Ryan\Downloads\PutLockerDownloader.exe (PUP.Optional.OneClickDownloader.A) -> No action taken.
C:\Users\Ryan\Downloads\SC-9688741C11.part1.rar.exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\SC-9688741C11.part2.rar (1).exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\SC-9688741C11.part2.rar.exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\Secret File.rar (PUP.RiskwareTool.CK) -> No action taken.
C:\Users\Ryan\Downloads\Setup (1).exe (PUP.Optional.Smart) -> No action taken.
C:\Users\Ryan\Downloads\SimCity 5 (SimCity 2013) CRACK - SKIDROW.rar.exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\SimCity Limited Edition Original KeyGen (1).exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\SimCity Limited Edition Original KeyGen.exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\SimCity_2013_Offline_Crack_NO_SURVEYS_downloader_us_99286.exe (PUP.Optional.GoForFiles.A) -> No action taken.
C:\Users\Ryan\Downloads\simcity_2013_offline_crack_torrent_downloader_us_99286.exe (PUP.Optional.GoForFiles.A) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_call-of-duty-world-at-war-mod-tools.exe (PUP.Optional.Softonic) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_digital-paintball-3.exe (PUP.Optional.Softonic) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_ds3-tool.exe (PUP.Optional.Softonic) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_enditall.exe (PUP.Optional.Softonic) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_renegade-paintball.exe (PUP.Optional.Softonic) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_trayit.exe (PUP.Optional.Softonic) -> No action taken.
C:\Users\Ryan\Downloads\SR4.Crack.rar_18290765_14_p9ef.exe (Trojan.Onlinegames) -> No action taken.
C:\Users\Ryan\Downloads\Update.exe (PUP.Optional.Ibryte) -> No action taken.
C:\Users\Ryan\Downloads\UploadingDesktop.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ryan\Downloads\video-media-download_setup.exe (PUP.Downware) -> No action taken.
C:\Users\Ryan\Downloads\VIO_Player_Setup (1).exe (PUP.Optional.Ibryte) -> No action taken.
C:\Users\Ryan\Downloads\VIO_Player_Setup (2).exe (PUP.Optional.Ibryte) -> No action taken.
C:\Users\Ryan\Downloads\VIO_Player_Setup.exe (PUP.Optional.Ibryte) -> No action taken.
C:\Users\Ryan\Downloads\Win7Themes_Downloader.exe (PUP.Optional.DealPly) -> No action taken.
C:\Users\Ryan\Downloads\winrar setup.exe (PUP.AdBundle) -> No action taken.
C:\Users\Ryan\AppData\Local\Conduit\CT3289075\uTorrentControl_v6AutoUpdateHelper.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Ryan\AppData\Local\Conduit\CT3290228\WhiteSmoke_NewAutoUpdateHelper.exe (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Users\Ryan\Local Settings\Temporary Internet Files\Content.IE5\146NYCRU\search_defender_166[1].exe (PUP.Optional.SProtect.A) -> No action taken.
C:\Windows\Tasks\AmiUpdXp.job (PUP.Software.Updater) -> No action taken.
C:\Program Files (x86)\Object\status.txt (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\config.ini (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\enable.txt (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\status2.txt (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\build.sh (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\chrome.manifest (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\config_build.sh (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\files (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\install.rdf (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\readme.txt (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\content\.DS_Store (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\content\firefoxOverlay.xul (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\content\installid.js (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\content\overlay.js (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\content\sudoku.js (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\defaults\.DS_Store (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\defaults\preferences\.DS_Store (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\defaults\preferences\._sudoku.js (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\defaults\preferences\sudoku.js (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\locale\.DS_Store (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\locale\en-US\.DS_Store (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\locale\en-US\sudoku.dtd (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\locale\en-US\sudoku.properties (PUP.FCTPlugin) -> No action taken.
C:\Program Files (x86)\Object\facetheme\skin\overlay.css (PUP.FCTPlugin) -> No action taken.
C:\Users\Ryan\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\ToolbarContextMenu.xml (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\GottenAppsContextMenu.xml (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\hk64tbWhit.dll (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\hktbWhit.dll (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\ldrtbWhit.dll (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\OtherAppsContextMenu.xml (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\SharedAppsContextMenu.xml (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\tbWhit.dll (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\toolbar.cfg (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\uninstall.exe (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\WhiteSmoke_New\WhiteSmoke_NewToolbarHelper.exe (PUP.Optional.WhiteSmoke.A) -> No action taken.
C:\Program Files (x86)\YourFileDownloader\htmlayout.dll (PUP.Optional.YourfileDownloader.A) -> No action taken.
C:\Program Files (x86)\YourFileDownloader\Downloader.exe (PUP.Optional.YourfileDownloader.A) -> No action taken.
C:\Program Files (x86)\YourFileDownloader\YourFile.exe (PUP.Optional.YourfileDownloader.A) -> No action taken.
C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe (PUP.Optional.YourfileDownloader.A) -> No action taken.
C:\Users\Ryan\AppData\Local\TopArcadeHits\tah.config (PUP.Optional.TopArcadeHits.A) -> No action taken.
C:\Users\Ryan\AppData\Local\TopArcadeHits\uninstaller.exe (PUP.Optional.TopArcadeHits.A) -> No action taken.
C:\Users\Ryan\AppData\Local\TopArcadeHits\updater.exe (PUP.Optional.TopArcadeHits.A) -> No action taken.
C:\Windows\Tasks\TopArcadeHits.job (PUP.Optional.TopArcadeHits.A) -> No action taken.
C:\Program Files (x86)\PricePeep\installer.ico (PUP.Optional.PricePeep.A) -> No action taken.
C:\Program Files (x86)\PricePeep\uninstall.exe (PUP.Optional.PricePeep.A) -> No action taken.
C:\Program Files (x86)\PricePeep\unutil.exe (PUP.Optional.PricePeep.A) -> No action taken.
C:\Users\Ryan\AppData\Roaming\Delta\sqlite3.dll (PUP.Optional.Delta.A) -> No action taken.
C:\Program Files (x86)\Gophoto.it\gophotoit14.crx (PUP.Optional.Gophoto.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.dat (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.exe (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.ico (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setup.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\Setup.dat (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\Setup.ico (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setup.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\Users\Ryan\AppData\Roaming\OpenCandy\DED4F32233404EE284E9EC4D804C139E\TuneUpUtilities2013_2200318_en-US.exe (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\Ryan\AppData\Roaming\Sony Creative Software Inc\tutle.exe (Trojan.Dropper) -> Delete on reboot.
C:\Program Files (x86)\PricePeep\pricepeep.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\DisplayFusion\tutle.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\NVIDIA\msdn.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\TuneUp Software\msdn.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\webex\pools.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\WinRAR\msdn.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\YourFileDownloader\msdn.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\Temp\RarSFX43\cgminer-nogpu.exe (Trojan.BitMiner) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\Temp\RarSFX43\phoenix.exe (Trojan.BitMiner) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\Temp\RarSFX73\cgminer-nogpu.exe (Trojan.BitCoinMiner) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\Temp\RarSFX74\cgminer-nogpu.exe (Trojan.BitCoinMiner) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\Temp\RarSFX75\cgminer-nogpu.exe (Trojan.BitCoinMiner) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\actual.multiple.monitors.4.1_2 1.rar (Trojan.MSIL) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\actual.multiple.monitors.4.1_2.rar (Trojan.MSIL) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\Borderlands 2 Key Generator.exe (PasswordStealer.MSIL) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\Borderlands 2 Steam Key Generator 2013 (1).rar (PasswordStealer.MSIL) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\Borderlands 2 Steam Key Generator 2013.rar (PasswordStealer.MSIL) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\CodecPerformerSetup.exe (Adware.InstallBrain) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\Skyrim multiplayer coop crack.rar (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\TopArcadeHits\uninstaller.exe (Adware.GameVance) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\TopArcadeHits\updater.exe (Adware.GameVance) -> Quarantined and deleted successfully.
C:\Windows\System32\Reg.reg (Malware.Trace) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\Reg.reg (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\test.exe (Backdoor.Messa) -> Quarantined and deleted successfully.
C:\Users\Ryan\Templates\Temp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Kit\PC Health Kit.lnk (Rogue.PCHealthKit) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Kit\Help.lnk (Rogue.PCHealthKit) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Kit\PC Health Kit on the Web.lnk (Rogue.PCHealthKit) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Kit\Uninstall PC Health Kit.lnk (Rogue.PCHealthKit) -> Quarantined and deleted successfully.

(end)
 
You have a ton of adware on your system.

Please rerun malwarebytes and make you check everything to delete it and then post the new log.

And then run the following.


1.

Please download and run TDSSkiller

When the program opens, click on the start scan button.

tdssstartscan_zps32a151cd.jpg


TDSSKiller will now scan your computer for the TDSS infection. When the scan has finished it will display a result screen stating whether or not the infection was found on your computer. If it was found it will display a screen similar to the one below.

2663-2-eng.png


To remove the infections simply click on the Continue button and TDSSKiller will attempt to clean them or remove them.

After trying to clean them it will pop up with the results of the scan and its actions.

2663_3_en.png


Please reboot the system if asked to do so.

After running there will be a log that will be located at the root of your c:\ drive labeled tdsskiller with a series of numbers after it example, C:\TDSSKiller.2.4.7_23.07.2010_15.31.43_log.txt

Please open the log and copy and paste it back here.


2.

Please download AdwCleaner by Xplode onto your Desktop.



•Please close all open programs and internet browsers.
•Double click on adwcleaner.exe to run the tool.
•Click on Scan.
•After the scan you will need to click on clean for it to delete the adware.
•Your computer will be rebooted automatically. A text file will open after the restart.
•Please post the content of that logfile in your reply.
•You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.

3.

Download the HijackThis installer from here.
Run the installer and choose Install, indicating that you accept the licence agreement. The installer will place a shortcut on your desktop and launch HijackThis.

Vista and Windows 7 users must right click on the hijackthis icon and click on run as. If the run as option doesn't appear then press and hold the shift key while right clicking on the icon to get it to appear.


Click Do a system scan and save a logfile

Most of what HijackThis lists will be harmless or even essential, don't fix anything yet.

When the hijackthis log appears in a notepad file, click on the edit menu, click select all, then click on the edit menu again and click on copy. Come back to your reply and right click on your mouse and click on paste.

Post the logfile that HijackThis produces
 
Here's the Malware Log and i didnt delete everything becasue i needed to keep some files for Payday and Saints Row. And HjackThis gave me a blank notepad

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.09.28.08

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Ryan :: RYAN-PC [administrator]

9/29/2013 12:33:50 PM
mbam-log-2013-09-29 (12-33-50).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 215438
Time elapsed: 13 minute(s), 14 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 56
HKCR\CLSID\{52F8C28C-DEC6-6CCC-8CFD-18A4CFD005EE} (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{52F8C28C-DEC6-6CCC-8CFD-18A4CFD005EE} (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{52F8C28C-DEC6-6CCC-8CFD-18A4CFD005EE} (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{52F8C28C-DEC6-6CCC-8CFD-18A4CFD005EE} (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{81E1C144-66F5-3D8A-3432-7C4924D09AB6} (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{81E1C144-66F5-3D8A-3432-7C4924D09AB6} (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{81E1C144-66F5-3D8A-3432-7C4924D09AB6} (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{81E1C144-66F5-3D8A-3432-7C4924D09AB6} (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
HKCR\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1} (PUP.Optional.BabylonToolBar.A) -> Quarantined and deleted successfully.
HKCR\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892} (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
HKCR\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB} (PUP.Optional.BabylonToolBar.A) -> Quarantined and deleted successfully.
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.
HKCR\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} (PUP.Optional.Wajam.A) -> Quarantined and deleted successfully.
HKCR\AppID\{F85FA3F2-D2C8-4D4D-BB1C-3181E691AF2B} (PUP.FaceThemes) -> Quarantined and deleted successfully.
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\CLSID\{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{acd6a209-4aaf-4b1c-9930-b82fa131e958} (PUP.FCTPlugin) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{acd6a209-4aaf-4b1c-9930-b82fa131e958} (PUP.FCTPlugin) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542} (PUP.Optional.BabylonToolBar.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2} (PUP.Optional.SelectionLinks) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2} (PUP.Optional.SelectionLinks) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2} (PUP.Optional.SelectionLinks) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2} (PUP.Optional.SelectionLinks) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{924C3DC2-8E4E-432E-F973-9A2174A39774} (PUP.Optional.SilentInstall.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A2C00D0B-C7D2-558E-8EE4-59A71274B47C} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5984BD42-D30D-3EEF-F40A-1F3A707CAD95} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E46A083F-3960-AB09-F92E-72E36735D0AF} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{88F92795-BC74-F238-3AF8-59CF6E4430D1} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhiteSmoke_New Toolbar (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PricePeep (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
HKCR\AppID\PricePeep.DLL (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\BabylonToolbar (PUP.Optional.BabylonToolBar.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\DELTA\DELTA (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.
HKCU\Software\1ClickDownload (PUP.Optional.1ClickDownload.A) -> Quarantined and deleted successfully.
HKCU\Software\DataMngr (PUP.Optional.DataMngr.A) -> Quarantined and deleted successfully.
HKCU\Software\AppDataLow\SProtector (PUP.Optional.SProtector.A) -> Quarantined and deleted successfully.
HKCU\Software\AppDataLow\Software\PricePeep (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\BabylonToolbar (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Delta\delta\Instl (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\kincjchfokkeneeofpeefomkikfkiedl (PUP.FCTPlugin) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk (PUP.Optional.Gophoto.A) -> Quarantined and deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\FastFreeConverterUpdt (PUP.Optional.FastFreeConverter.A) -> Quarantined and deleted successfully.

Registry Values Detected: 10
HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> Data: WhiteSmoke New Toolbar -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{739DF940-C5EE-4BAB-9D7E-270894AE687A} (PUP.Optional.WhiteSmoke.A) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{739df940-c5ee-4bab-9d7e-270894ae687a} (PUP.Optional.WhiteSmoke.A) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{739df940-c5ee-4bab-9d7e-270894ae687a} (PUP.Optional.WhiteSmoke.A) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Data: Delta Toolbar -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{739df940-c5ee-4bab-9d7e-270894ae687a} (PUP.Optional.WhiteSmoke.A) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Delta\Delta|tlbrSrchUrl (PUP.Optional.Delta.A) -> Data: -> Quarantined and deleted successfully.
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Data: 0W1M2Z0F1D1Q1P1R1O0O1H -> Quarantined and deleted successfully.

Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs (PUP.Optional.SProtect.A) -> Bad: (c:\progra~2\savesh~1\sprote~1.dll) Good: () -> Quarantined and repaired successfully.

Folders Detected: 26
C:\Program Files (x86)\Object (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\content (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\defaults (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\defaults\preferences (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\locale (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\locale\en-US (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\skin (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\YourFileDownloader (PUP.Optional.YourfileDownloader.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\TopArcadeHits (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\PricePeep (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\Delta (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Gophoto.it (PUP.Optional.Gophoto.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Cache (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Cache (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\Cache (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\OpenCandy\DED4F32233404EE284E9EC4D804C139E (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.

Files Detected: 130
C:\Users\Ryan\Downloads\actual.multiple.monitors.4.1_2 (1).exe (PUP.Optional.4Squared) -> No action taken.
C:\Users\Ryan\Downloads\actual.multiple.monitors.4.1_2.exe (PUP.Optional.4Squared) -> No action taken.
C:\Users\Ryan\Downloads\Borderlands_2_Steam_Keygen_exe.exe (PUP.BundleInstaller.DW) -> No action taken.
C:\Users\Ryan\Downloads\CallofDutyBlackOpsIISKIDROW_downloader_by_PirateBayMirror.exe (PUP.Optional.Somoto) -> No action taken.
C:\Users\Ryan\Downloads\hans zimmer - epilogue main theme - crysis 2 soundtrack.exe (PUP.Optional.4Squared) -> No action taken.
C:\Users\Ryan\Downloads\Nico_vega-All-Albums-(Special-Edition).exe (PUP.BundleInstaller.DW) -> No action taken.
C:\Users\Ryan\Downloads\PAYDAY.2.Update.5-FTS.rar (1).exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\PAYDAY.2.Update.5-FTS.rar.exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\Photoshop CS6 .dll Replacement.rar (PUP.RiskwareTool.CK) -> No action taken.
C:\Users\Ryan\Downloads\PutLockerDownloader.exe (PUP.Optional.OneClickDownloader.A) -> No action taken.
C:\Users\Ryan\Downloads\SC-9688741C11.part1.rar.exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\SC-9688741C11.part2.rar (1).exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\SC-9688741C11.part2.rar.exe (PUP.Optional.Installex) -> No action taken.
C:\Users\Ryan\Downloads\Secret File.rar (PUP.RiskwareTool.CK) -> No action taken.
C:\Users\Ryan\Downloads\Setup (1).exe (PUP.Optional.Smart) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_call-of-duty-world-at-war-mod-tools.exe (PUP.Optional.Softonic) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_digital-paintball-3.exe (PUP.Optional.Softonic) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_ds3-tool.exe (PUP.Optional.Softonic) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_enditall.exe (PUP.Optional.Softonic) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_renegade-paintball.exe (PUP.Optional.Softonic) -> No action taken.
C:\Users\Ryan\Downloads\SoftonicDownloader_for_trayit.exe (PUP.Optional.Softonic) -> No action taken.
C:\Program Files (x86)\SaveShare\sprotector.dll (PUP.Optional.SProtect.A) -> Delete on reboot.
C:\ProgramData\syafe saVe\52154a0d29aeb.dll (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
C:\ProgramData\sAafei savE\5219456a322a5.dll (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\SwvUpdater\Updater.exe (PUP.Software.Updater) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\prxtbWhit.dll (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\ProgramData\Brouwse2saave\5174361e896e7.dll (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{0990ED06-0A82-4BA1-A94A-42A0D273CFF0}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{0990ED06-0A82-4BA1-A94A-42A0D273CFF0}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{2351CFD1-6D57-493B-ABD0-2575F8B2ED27}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{2351CFD1-6D57-493B-ABD0-2575F8B2ED27}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{7D789C08-708C-466C-A487-38AEA69BBEFE}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{7D789C08-708C-466C-A487-38AEA69BBEFE}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{A4A97720-5DCE-4DE5-AF0E-15EC7F4A55D6}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{A4A97720-5DCE-4DE5-AF0E-15EC7F4A55D6}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\sAafei savE\uninstall.exe (PUP.Optional.SilentInstall.A) -> Quarantined and deleted successfully.
C:\ProgramData\syafe saVe\uninstall.exe (PUP.Optional.SilentInstall.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\PowerISO\Upgrade\PowerISO5.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\Temp\BQcow2wpl8G.exe (Trojan.BitCoinMiner) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\Temp\EFOYN4mIPek.exe (Trojan.BitCoinMiner) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\Temp\RarSFX0\cgminer-nogpu.exe (Trojan.BitCoinMiner) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\Temp\RarSFX1\cgminer-nogpu.exe (Trojan.BitCoinMiner) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\DownloadManager.exe (PUP.Optional.Installex) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\playpickle-setup.exe (PUP.Optional.DownloadAdmin) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\SimCity 5 (SimCity 2013) CRACK - SKIDROW.rar.exe (PUP.Optional.Installex) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\SimCity Limited Edition Original KeyGen (1).exe (PUP.Optional.Installex) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\SimCity Limited Edition Original KeyGen.exe (PUP.Optional.Installex) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\SimCity_2013_Offline_Crack_NO_SURVEYS_downloader_us_99286.exe (PUP.Optional.GoForFiles.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\simcity_2013_offline_crack_torrent_downloader_us_99286.exe (PUP.Optional.GoForFiles.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\SR4.Crack.rar_18290765_14_p9ef.exe (Trojan.Onlinegames) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\Update.exe (PUP.Optional.Ibryte) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\UploadingDesktop.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\video-media-download_setup.exe (PUP.Downware) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\VIO_Player_Setup (1).exe (PUP.Optional.Ibryte) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\VIO_Player_Setup (2).exe (PUP.Optional.Ibryte) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\VIO_Player_Setup.exe (PUP.Optional.Ibryte) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\Win7Themes_Downloader.exe (PUP.Optional.DealPly) -> Quarantined and deleted successfully.
C:\Users\Ryan\Downloads\winrar setup.exe (PUP.AdBundle) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\Conduit\CT3289075\uTorrentControl_v6AutoUpdateHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\Conduit\CT3290228\WhiteSmoke_NewAutoUpdateHelper.exe (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\Local Settings\Temporary Internet Files\Content.IE5\146NYCRU\search_defender_166[1].exe (PUP.Optional.SProtect.A) -> Quarantined and deleted successfully.
C:\Windows\Tasks\AmiUpdXp.job (PUP.Software.Updater) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\status.txt (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\config.ini (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\enable.txt (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\status2.txt (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\build.sh (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\chrome.manifest (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\config_build.sh (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\files (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\install.rdf (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\readme.txt (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\content\.DS_Store (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\content\firefoxOverlay.xul (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\content\installid.js (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\content\overlay.js (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\content\sudoku.js (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\defaults\.DS_Store (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\defaults\preferences\.DS_Store (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\defaults\preferences\._sudoku.js (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\defaults\preferences\sudoku.js (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\locale\.DS_Store (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\locale\en-US\.DS_Store (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\locale\en-US\sudoku.dtd (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\locale\en-US\sudoku.properties (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Object\facetheme\skin\overlay.css (PUP.FCTPlugin) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\ToolbarContextMenu.xml (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\GottenAppsContextMenu.xml (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\hk64tbWhit.dll (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\hktbWhit.dll (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\ldrtbWhit.dll (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\OtherAppsContextMenu.xml (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\SharedAppsContextMenu.xml (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\tbWhit.dll (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\toolbar.cfg (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\uninstall.exe (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\WhiteSmoke_New\WhiteSmoke_NewToolbarHelper.exe (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\YourFileDownloader\htmlayout.dll (PUP.Optional.YourfileDownloader.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\YourFileDownloader\Downloader.exe (PUP.Optional.YourfileDownloader.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\YourFileDownloader\YourFile.exe (PUP.Optional.YourfileDownloader.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe (PUP.Optional.YourfileDownloader.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Local\TopArcadeHits\tah.config (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully.
C:\Windows\Tasks\TopArcadeHits.job (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\PricePeep\installer.ico (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\PricePeep\uninstall.exe (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\PricePeep\unutil.exe (PUP.Optional.PricePeep.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\Delta\sqlite3.dll (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Gophoto.it\gophotoit14.crx (PUP.Optional.Gophoto.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Users\Ryan\AppData\Roaming\OpenCandy\DED4F32233404EE284E9EC4D804C139E\TuneUpUtilities2013_2200318_en-US.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.

(end)


Here's the AdwCleaner:
# AdwCleaner v3.005 - Report created 29/09/2013 at 14:11:48
# Updated 22/09/2013 by Xplode
# Operating System : Windows 7 Professional (64 bits)
# Username : Ryan - RYAN-PC
# Running from : C:\Users\Ryan\Desktop\adwcleaner (1).exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : BackupStack
[#] Service Deleted : vToolbarUpdater14.2.0
[#] Service Deleted : Yontoo Desktop Updater

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\GameTap Web Player
Folder Deleted : C:\ProgramData\Premium
Folder Deleted : C:\ProgramData\SoftSafe
Folder Deleted : C:\ProgramData\Splashtop
Folder Deleted : C:\ProgramData\StarApp
Folder Deleted : C:\ProgramData\Brouwse2saave
Folder Deleted : C:\ProgramData\sAafei savE
Folder Deleted : C:\ProgramData\syafe saVe
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip Registry Optimizer
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\sAafei savE
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\syafe saVe
Folder Deleted : C:\Program Files (x86)\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\File Type Helper
Folder Deleted : C:\Program Files (x86)\OApps
Folder Deleted : C:\Program Files (x86)\WinZip Registry Optimizer
Folder Deleted : C:\Program Files (x86)\uTorrentControl2
Folder Deleted : C:\Program Files (x86)\uTorrentControl_v2
Folder Deleted : C:\Program Files (x86)\uTorrentControl_v6
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Users\Ryan\AppData\Local\apn
Folder Deleted : C:\Users\Ryan\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Ryan\AppData\Local\Conduit
Folder Deleted : C:\Users\Ryan\AppData\Local\Coupon Companion Plugin
Folder Deleted : C:\Users\Ryan\AppData\Local\cre
Folder Deleted : C:\Users\Ryan\AppData\Local\PackageAware
Folder Deleted : C:\Users\Ryan\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\Ryan\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Ryan\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\Ryan\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Ryan\AppData\LocalLow\Fast Free Converter
Folder Deleted : C:\Users\Ryan\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Ryan\AppData\LocalLow\Brouwse2saave
Folder Deleted : C:\Users\Ryan\AppData\LocalLow\sAafei savE
Folder Deleted : C:\Users\Ryan\AppData\LocalLow\syafe saVe
[x] Not Deleted : C:\Users\Ryan\AppData\LocalLow\uTorrentControl2
[x] Not Deleted : C:\Users\Ryan\AppData\LocalLow\uTorrentControl_v2
[x] Not Deleted : C:\Users\Ryan\AppData\LocalLow\uTorrentControl_v6
Folder Deleted : C:\Users\Ryan\AppData\LocalLow\WhiteSmoke_New
Folder Deleted : C:\Users\Ryan\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\Ryan\AppData\Roaming\ExpressFiles
Folder Deleted : C:\Users\Ryan\AppData\Roaming\Splashtop
Folder Deleted : C:\Users\Ryan\AppData\Roaming\Yontoo
Folder Deleted : C:\Users\Ryan\AppData\Roaming\yourfiledownloader
Folder Deleted : C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Deleted : C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
Folder Deleted : C:\Program Files (x86)\Mozilla Firefox\Extensions\[email protected]
Folder Deleted : C:\Program Files (x86)\Mozilla Firefox\Extensions\[email protected]
File Deleted : C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\Extensions\[email protected]
File Deleted : C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\[opt]rs0\Extensions\[email protected]
File Deleted : C:\END
File Deleted : C:\Windows\SysWOW64\Yealt.dll
File Deleted : C:\Windows\System32\roboot64.exe
File Deleted : C:\Windows\Tasks\YourFile Update.job

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{EB132DB0-A4CA-11DF-9732-0E29E0D72085}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Key Deleted : HKCU\Software\Google\Chrome\Extensions\gelpfbcidpeeelkmkjbofkcpihkcachn
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\tracing\askpartnercobrandingtool_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_703c874a
Key Deleted : HKLM\SOFTWARE\5f0d8dbbc6fbe45
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3072253
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3289075
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3290228
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_digital-paintball-3_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_digital-paintball-3_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_enditall_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_enditall_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_hamachi_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_hamachi_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_renegade-paintball_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_renegade-paintball_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_trayit_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_trayit_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{40C78C4E-5AE5-4762-9B7D-D2DE31B03B77}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{687578B9-7132-4A7A-80E4-30EE31099E03}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4AAF2A6-F6D1-49A5-BA1A-B20735DF1955}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{82EC639E-6E81-4E03-9325-90975446E4B0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{40C78C4E-5AE5-4762-9B7D-D2DE31B03B77}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{687578B9-7132-4A7A-80E4-30EE31099E03}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{40C78C4E-5AE5-4762-9B7D-D2DE31B03B77}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A13CC898-9CA9-4578-9629-B328422FF014}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFE66D00-A56A-4F7F-81D7-4A28C5816D6C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{687578B9-7132-4A7A-80E4-30EE31099E03}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4AAF2A6-F6D1-49A5-BA1A-B20735DF1955}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82EC639E-6E81-4E03-9325-90975446E4B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{40C78C4E-5AE5-4762-9B7D-D2DE31B03B77}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{687578B9-7132-4A7A-80E4-30EE31099E03}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D4AAF2A6-F6D1-49A5-BA1A-B20735DF1955}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{82EC639E-6E81-4E03-9325-90975446E4B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C51EEBB7-0174-4816-B925-BD4E855BF152}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B8982223-2377-49A5-80FE-257AE433D250}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{92DC8A10-63A1-4913-80AB-472F4445238C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2C9D6C5-996F-452E-BE31-5694DAA2F83F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78363700-9E01-4EC7-BF0E-5218F07269A2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A96B1AB8-BC84-45F9-B504-4F67BBCADE66}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E86F3B8A-F89A-4329-A5F8-9C4D0410E04C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11BF52C6-4610-454D-9BFD-3538229B3CB6}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C99FDC39-A1AE-4B24-8D71-E5274F8D7C54}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{687578B9-7132-4A7A-80E4-30EE31099E03}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{687578B9-7132-4A7A-80E4-30EE31099E03}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{687578B9-7132-4A7A-80E4-30EE31099E03}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{687578B9-7132-4A7A-80E4-30EE31099E03}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YourFileDownloader
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl2
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v6
Key Deleted : HKCU\Software\AppDataLow\Software\WhiteSmoke_New
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Delta
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\Software\Fast Free Converter
Key Deleted : HKLM\Software\InfoAtoms
Key Deleted : HKLM\Software\SP Global
Key Deleted : HKLM\Software\SProtector
Key Deleted : HKLM\Software\systweak
Key Deleted : HKLM\Software\YourFileDownloader
Key Deleted : HKLM\Software\uTorrentControl2
Key Deleted : HKLM\Software\uTorrentControl_v2
Key Deleted : HKLM\Software\uTorrentControl_v6
Key Deleted : HKLM\Software\WhiteSmoke_New
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl2 Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v2 Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v6 Toolbar
Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16476


-\\ Mozilla Firefox v

[ File : C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\[opt]rs0\prefs.js ]


-\\ Google Chrome v

[ File : C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [24129 octets] - [29/09/2013 13:46:20]
AdwCleaner[R1].txt - [24192 octets] - [29/09/2013 14:02:10]
AdwCleaner[S0].txt - [22870 octets] - [29/09/2013 14:11:48]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [22931 octets] ##########
 
Vista and Windows 7 users must right click on the hijackthis icon and click on run as. If the run as option doesn't appear then press and hold the shift key while right clicking on the icon to get it to appear.

Hence why that was in red why hijackthis is giving you a blank screen.
 
Hence why that was in red why hijackthis is giving you a blank screen.

Oops i feel like an idiot now sorry but here you go:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:47:16 PM, on 9/29/2013
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16476)
Boot mode: Normal

Running processes:
C:\Users\Ryan\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Actual Multiple Monitors\ActualMultipleMonitorsCenter.exe
C:\Users\Ryan\AppData\Local\Temp\RarSFX43\SystemWideUserIdle.exe
C:\Users\Ryan\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\iTunesKeys\iTunesKeys.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Tunngle\Tunngle.exe
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;<local>;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
R3 - URLSearchHook: (no name) - {efb1e45a-148d-40f9-a3f0-09d5577f9970} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A071936A-AB6B-4978-9342-E47C06FCDEC1} - (no file)
O2 - BHO: Price Check by AOL - {D25B97E9-62B2-40CE-BECF-E43A7B879072} - C:\Program Files (x86)\Price Check by AOL\aolpricecheck.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Control Center] C:\Program Files (x86)\ASUS\WLAN Card Utilities\CenterAgent.exe
O4 - HKLM\..\Run: [CrashHandle] C:\Users\Ryan\AppData\Local\Temp\RarSFX43\SystemWideUserIdle.exe
O4 - HKLM\..\Run: [MSIAfterburner] "C:\Program Files (x86)\MSI Afterburner\MSIAfterburnerWrapper.exe" /s
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [EasyTune] "C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe"
O4 - HKCU\..\Run: [CPU-Z] C:\Users\Ryan\AppData\Roaming\Daemon\cpuz.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Ryan\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [Actual Multiple Monitors] "C:\Program Files (x86)\Actual Multiple Monitors\ActualMultipleMonitorsCenter.exe"
O4 - HKCU\..\Run: [CrashHandle] C:\Users\Ryan\AppData\Local\Temp\RarSFX43\SystemWideUserIdle.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_client_4.4.26.0.cab
O16 - DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} (GameTap Player) -
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\windows\syswow64\nvinit.dll c:\windows\syswow64\nvinit.dll c:\progra~2\nvidia~1\nvstre~1\rxinput.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: ASUS Wireless Card Service (ASWLCCSvc) - Unknown owner - C:\Program Files (x86)\ASUS\WLAN Card Utilities\ASWLCCSVC.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GSService - Unknown owner - C:\Windows\SysWOW64\GSService.exe (file missing)
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: Perforce - Perforce Software Inc. - C:\Program Files\Perforce\Server\p4s.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Smart TimeLock Service (Smart TimeLock) - Gigabyte Technology CO., LTD. - C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\Windows\system32\UAService7.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12426 bytes
 
Did you run the tdsskiller program yet? Still have a bunch of cleanup yet to do.

Please download Junkware Removal Tool to your desktop.

•Shutdown your antivirus to avoid any conflicts.

•Very important that you run the tool in this manner:
Right-mouse click JRT.exe and select Run as administrator
Do NOT just double-click it.

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Post the contents of JRT.txt in your next message.

I also need you to post an uninstall list using hijackthis.

Open hijackthis, click on open misc tools section, click on open uninstall manager, click on save list and save it. Then copy and paste the contents back here.
 
Back
Top