WiredWX Hobby Weather ToolsLog in

 


Ask, keeps overpowering google on one site only cant stop it!

2 posters

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
This is the results of the jrt scan

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows (TM) Vista Business x64
Ran by myComputer on Thu 11/28/2013 at 19:44:52.07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 11/28/2013 at 19:50:11.44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
Scan Log
Version of virus signature database: 9109 (20131128)
Date: 11/28/2013 Time: 9:04:28 PM
Scanned disks, folders and files: C:\
C:\hiberfil.sys - error opening [4]
C:\pagefile.sys - error opening [4]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\adawareDx.dll.vir - a variant of Win32/Toolbar.Visicom.B potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\adawaretb.dll.vir - a variant of Win32/Toolbar.Visicom.A potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\dtUser.exe.vir - a variant of Win32/Toolbar.Visicom.C potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\Helper.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\safetyldr.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\safetyldr_u.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\x64\safetyldr.dll.vir - a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\x64\safetyldr_u.dll.vir - a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application - action selection postponed until scan completion
C:\AdwCleaner\Quarantine\C\Users\myComputer\AppData\Local\torch\User Data\Default\Cache\f_000001.vir » GZIP - is OK (internal scanning not performed)
C:\AdwCleaner\Quarantine\C\Users\myComputer\AppData\Local\torch\User Data\Default\Cache\f_000002.vir » GZIP - is OK (internal scanning not performed)
C:\AdwCleaner\Quarantine\C\Users\myComputer\AppData\Local\torch\User Data\Default\Cache\f_000005.vir » GZIP - is OK (internal scanning not performed)
C:\Program Files\ESET\ESET NOD32 Antivirus\eset.chm » CHM - is OK (internal scanning not performed)
C:\Program Files\Vuze\Azureus2.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\bunndle.zip » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\swt.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\.install4j\i4jruntime.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\.install4j\user.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\alt-rt.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\alt-string.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\charsets.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\deploy.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\jce.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\jsse.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\management-agent.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\plugin.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\resources.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\rt.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\deploy\ffjcext.zip » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\ext\dns_sd.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\ext\dnsns.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\ext\localedata.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\ext\sunjce_provider.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\ext\sunmscapi.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\im\indicim.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\im\thaiim.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\security\local_policy.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\jre\lib\security\US_export_policy.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azitunes\azitunes_0.3.1.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azitunes\jacob_1.17.2.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azitunes\libProcessAccess_0.1.3.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azplugins\azplugins_2.1.6.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azplugins\azplugins_2.1.7.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azrating\azrating_1.3.1.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azupdater\azupdaterpatcher_1.8.17.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azupdater\Updater.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azupnpav\azupnpav_0.4.4.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azupnpav\azupnpav_0.4.6.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Vuze\plugins\azupnpav\azupnpav_0.4.7.jar » ZIP - is OK (internal scanning not performed)
C:\Program Files\Windows Media Player\Skins\Revert.wmz » ZIP - is OK (internal scanning not performed)
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\DEXEchoSign.spi » ZIP - is OK (internal scanning not performed)
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\DEXShare.spi » ZIP - is OK (internal scanning not performed)
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg » ZIP - is OK (internal scanning not performed)
C:\Program Files (x86)\AVG\AVG2014\avgdg_us.chm » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\AVG\AVG2014\avgf_us.chm » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\AVG\AVG2014\avgls_us.chm » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\AVG\AVG2014\js.dat » CAB - is OK (internal scanning not performed)
C:\Program Files (x86)\AVG\AVG2014\banners\banners.zip » ZIP - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\CS\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\DA\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\DE\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\EL\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\EN\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\ES\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\FI\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\FR\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\HU\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\ID\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\IT\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\JP\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\KO\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\NL\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\NO\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\PL\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\PT\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\RU\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\SC\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\SV\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\TC\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\TH\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Canon\Solution Menu EX\LangInfo\TR\CNSEHELP.CHM » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarHelper_signed.msi » MSI - is OK (internal scanning not performed)
C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.chm » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\chameleon.chm » CHM - is OK (internal scanning not performed)
C:\Program Files (x86)\VideoLAN\VLC\skins\default.vlt » GZIP - is OK (internal scanning not performed)
C:\ProgramData\Adobe\ARM\Reader_10.1.6\AdobeARM.bin » 7ZIP - is OK (internal scanning not performed)
C:\ProgramData\Adobe\ARM\Reader_10.1.6\ARM.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\Adobe\ARM\Reader_10.1.6\Reader10Manifest.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AA1000000001}\AcroRead.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AA1000000001}\Data1.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\AntiRka.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\Antivira.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\Avgx64.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\base2a.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\basea.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\COREa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\COREx64.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\Emailsa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\GUIa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\IDPa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\lng_usa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\ResShlda.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\SrchSrfa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\SSHttpBa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\TDIDrva.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\TuneUpa.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\AVG2014\SetupBackup\Updatea.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\Downloaded Installations\{F075020E-43B2-4F2C-9723-C81CE162E7B6}\6b807045-53e5-49a1-8a7a-3af210c0b686\bafd8c5e-7324-4659-8719-fdcb010084da.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\ESET\ESET NOD32 Antivirus\Installer\3f7.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ar\a49df2b4-ae4f-486c-9e4e-31b2900b20d8.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\cs\08e75736-78a7-43e1-b63c-9f2814526d3d.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\da\b8a18584-cd8f-4268-b468-5b263bd4616b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\de\60fc900c-1b1e-4d90-99f3-ad06e134128b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\el\19ca6d9e-77d4-43e5-93ea-c4484a9fea8f.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\en\f873c895-065a-4eb5-a2c0-243b74ae0127.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\en-US\670add03-954d-4bf1-96cb-a0a00d51b423.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\es\3a15cbe1-10b3-40e3-99d3-047745360684.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\fi\3adb9d9e-258d-4e8e-99c1-b555f31b8064.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\fr\9d9d5a2e-2de3-400a-bd3a-399dbf7beb56.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\he\d52cb5fd-39dc-46a7-b7e1-fbb37312baa8.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\hu\4c9965f4-b86c-4ea3-b282-d50b41d82e24.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\it\4c1f18dd-10fd-4fbe-a04f-1e118e042431.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ja\0b6540df-217f-4a8d-adff-a6671ac175b7.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ko\62a730f9-7801-4cdf-b5b1-d2c73b2f7b7b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\nb\4900d51e-0dd0-4ad0-a789-a3a9a3f61eed.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\nl\01163500-5409-40bf-9a0e-e958817e4a08.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\pl\e6d83363-070d-4b86-b369-cc461f32dd7a.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\pt\40bd21c0-1b6d-4cb7-9c66-4e54993ceebc.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ru\be091111-5413-4448-8ab0-d3baaaad11bb.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\sv\e47753e9-a50b-4da4-868f-2e0519d7cb1e.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\tr\ba21126f-e4e9-4def-a9d6-b2a8ecf1d0fb.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\zh-CN\53e27d45-71fe-4bb4-81ae-90136385005c.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\zh-TW\208652e3-ad1a-43dc-9768-d7552dcf6cc1.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1025\1025.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1026\1026.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1028\1028.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1029\1029.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1030\1030.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1031\1031.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1032\1032.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1033\1033.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1034\1034.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1035\1035.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1036\1036.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1037\1037.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1038\1038.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1040\1040.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1041\1041.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1042\1042.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1043\1043.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1044\1044.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1045\1045.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1046\1046.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1048\1048.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1049\1049.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1050\1050.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1051\1051.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1053\1053.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1054\1054.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1055\1055.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1057\1057.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1060\1060.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1061\1061.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1062\1062.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\1063\1063.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\HP\HP Deskjet 1000 J110 series\Help\2052\2052.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\MFAData\setup_tp.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\MFAData\pack\Avgx64.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log - error opening [4]
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log - error opening [4]
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb - error opening [4]
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb - error opening [4]
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report155e6cb8\Report.cab » CAB - is OK (internal scanning not performed)
C:\ProgramData\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\Skype.msi » MSI - is OK (internal scanning not performed)
C:\ProgramData\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeToolbars.msi » MSI - is OK (internal scanning not performed)
C:\System Volume Information\{00eb3faf-57de-11e3-9ca9-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{00eb3fc3-57de-11e3-9ca9-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{00eb3fc7-57de-11e3-9ca9-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{0836bc44-56fa-11e3-b890-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{12e9f942-58a4-11e3-8fc6-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{12e9f946-58a4-11e3-8fc6-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{12e9f94a-58a4-11e3-8fc6-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{12e9f94e-58a4-11e3-8fc6-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{20115774-5659-11e3-b979-9e4da3e1b7be}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{2011577e-5659-11e3-b979-9e4da3e1b7be}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{20115784-5659-11e3-b979-9e4da3e1b7be}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{5e8d946e-5639-11e3-938a-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{5e8d9472-5639-11e3-938a-b06e2274047b}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{5e8d9476-5639-11e3-938a-b06e2274047b}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{5e8d947a-5639-11e3-938a-b06e2274047b}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{652a2cac-5647-11e3-92b6-cdc054e3d695}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{af16f3b0-551d-11e3-b5d6-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\System Volume Information\{ba6df4ac-578d-11e3-a913-90fba616ba97}{3808876b-c176-4e48-b7ae-04046e6cc752} - error opening [4]
C:\Users\All Users\Adobe\ARM\Reader_10.1.6\AdobeARM.bin » 7ZIP - is OK (internal scanning not performed)
C:\Users\All Users\Adobe\ARM\Reader_10.1.6\ARM.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Adobe\ARM\Reader_10.1.6\Reader10Manifest.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AA1000000001}\AcroRead.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AA1000000001}\Data1.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\AntiRka.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\Antivira.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\Avgx64.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\base2a.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\basea.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\COREa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\COREx64.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\Emailsa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\GUIa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\IDPa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\lng_usa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\ResShlda.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\SrchSrfa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\SSHttpBa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\TDIDrva.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\TuneUpa.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\AVG2014\SetupBackup\Updatea.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\Downloaded Installations\{F075020E-43B2-4F2C-9723-C81CE162E7B6}\6b807045-53e5-49a1-8a7a-3af210c0b686\bafd8c5e-7324-4659-8719-fdcb010084da.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\ESET\ESET NOD32 Antivirus\Installer\3f7.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ar\a49df2b4-ae4f-486c-9e4e-31b2900b20d8.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\cs\08e75736-78a7-43e1-b63c-9f2814526d3d.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\da\b8a18584-cd8f-4268-b468-5b263bd4616b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\de\60fc900c-1b1e-4d90-99f3-ad06e134128b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\el\19ca6d9e-77d4-43e5-93ea-c4484a9fea8f.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\en\f873c895-065a-4eb5-a2c0-243b74ae0127.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\en-US\670add03-954d-4bf1-96cb-a0a00d51b423.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\es\3a15cbe1-10b3-40e3-99d3-047745360684.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\fi\3adb9d9e-258d-4e8e-99c1-b555f31b8064.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\fr\9d9d5a2e-2de3-400a-bd3a-399dbf7beb56.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\he\d52cb5fd-39dc-46a7-b7e1-fbb37312baa8.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\hu\4c9965f4-b86c-4ea3-b282-d50b41d82e24.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\it\4c1f18dd-10fd-4fbe-a04f-1e118e042431.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ja\0b6540df-217f-4a8d-adff-a6671ac175b7.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ko\62a730f9-7801-4cdf-b5b1-d2c73b2f7b7b.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\nb\4900d51e-0dd0-4ad0-a789-a3a9a3f61eed.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\nl\01163500-5409-40bf-9a0e-e958817e4a08.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\pl\e6d83363-070d-4b86-b369-cc461f32dd7a.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\pt\40bd21c0-1b6d-4cb7-9c66-4e54993ceebc.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\ru\be091111-5413-4448-8ab0-d3baaaad11bb.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\sv\e47753e9-a50b-4da4-868f-2e0519d7cb1e.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\tr\ba21126f-e4e9-4def-a9d6-b2a8ecf1d0fb.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\zh-CN\53e27d45-71fe-4bb4-81ae-90136385005c.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\DeviceMetadataStore\zh-TW\208652e3-ad1a-43dc-9768-d7552dcf6cc1.devicemetadata-ms » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1025\1025.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1026\1026.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1028\1028.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1029\1029.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1030\1030.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1031\1031.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1032\1032.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1033\1033.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1034\1034.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1035\1035.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1036\1036.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1037\1037.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1038\1038.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1040\1040.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1041\1041.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1042\1042.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1043\1043.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1044\1044.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1045\1045.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1046\1046.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1048\1048.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1049\1049.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1050\1050.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1051\1051.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1053\1053.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1054\1054.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1055\1055.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1057\1057.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1060\1060.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1061\1061.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1062\1062.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\1063\1063.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\HP\HP Deskjet 1000 J110 series\Help\2052\2052.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\MFAData\setup_tp.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\MFAData\pack\Avgx64.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\MSS.log - error opening [4]
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\MSStmp.log - error opening [4]
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\tmp.edb - error opening [4]
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb - error opening [4]
C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report155e6cb8\Report.cab » CAB - is OK (internal scanning not performed)
C:\Users\All Users\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\Skype.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeToolbars.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\ntuser.dat - error opening [4]

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
the log was to long to send at once. I'm sending the second half now.
:\Users\All Users\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\Skype.msi » MSI - is OK (internal scanning not performed)
C:\Users\All Users\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeToolbars.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\ntuser.dat - error opening [4]
C:\Users\myComputer\ntuser.dat.LOG1 - error opening [4]
C:\Users\myComputer\ntuser.dat.LOG2 - error opening [4]
C:\Users\myComputer\AppData\Local\Downloaded Installations\{4D0FF23C-E8F9-4AC8-B28C-93044A6ABC78}\Ad-Aware Antivirus.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000001 » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000002 » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000003 » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000004 » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Update\1.3.21.165\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Google\Update\Download\{D0AB2EBC-931B-4013-9FEB-C9C4C2225C8C}\4.9.1.16010\googletalkpluginaccel.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{228C12F2-58A6-11E3-8FC6-90FBA616BA97}.dat - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{228C12F3-58A6-11E3-8FC6-90FBA616BA97}.dat - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3A57218F-58AB-11E3-8FC6-90FBA616BA97}.dat - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Windows\UsrClass.dat - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - error opening [4]
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\469CD4XZ\GetContent[1].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\469CD4XZ\GetContent[2].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\favicon[4].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\GetContent[1].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\GetContent[2].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\msgr11us.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ProgramFilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\msgr11us.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\OnlineScanner[1].cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » vcredist_x86.exe » CAB » vcredis1.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » vcredist_x86.exe » CAB » vcredist.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » applause_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » applause_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » beep_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » beep_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » belch_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » belch_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » bomb_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » bomb_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » brokenglass_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » brokenglass_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » cough_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » cough_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » cow_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » cow_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » drumroll_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » drumroll_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » grouplaff_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » grouplaff_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » guitar_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » guitar_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » moan_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » moan_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » ooh_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » ooh_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » scream_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » scream_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » trombone_bmp.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JY4V65S6\ymsgr1150_0228_us[1] » WISE » trombone_mp3.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\GetContent[1].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\GetContent[2].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\GetContent[3].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\GetContent[4].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\GetContent[5].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\msgr11ca.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ProgramFilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\msgr11ca.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\onlinescan[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\Safe+Haven+28201329+720p+BrRip+x264+-+YIFY.exe - a variant of Win32/4Shared.K potentially unwanted application - action selection postponed until scan completion
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\store[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\ytb_setup_9_1_0_18_3_1_0[1] » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\ytb_setup_9_1_0_18_3_1_0[1] » NSIS » ytb_setup.exe » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\ytb_setup_9_1_0_18_3_1_0[1] » NSIS » ytoolbar.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\ActivateService[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\GetContent[1].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\GetContent[2].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\GetContent[3].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\GetContent[4].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\GetContent[5].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » aucheck - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » jaureg - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » jucheck - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » jusched - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » task.xml - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\JavaSetup7u25.exe » CAB » task64.xml - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\msgr11us.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ProgramFilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PT0A3310\msgr11us.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK63WLFV\GetContent[1].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK63WLFV\GetContent[2].aspx » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK63WLFV\msgr11ca.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ProgramFilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK63WLFV\msgr11ca.exe » NSIS » ymsgr_suite_setup.exe » NSIS » ilesDir - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\058F5TXD\Boots[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\058F5TXD\product_download[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1N5J9Z5S\50006+50425[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1N5J9Z5S\AntiVir_Personal_Edition_7_d955[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1N5J9Z5S\Boots[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1Z2SMZ17\50006+50425[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\31PMH0XJ\apiplayer3-vfl9ml4uN[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\31PMH0XJ\HikingCamping[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\31PMH0XJ\tos[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7T7CK9NB\Boots[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\92UGB74L\Avast_Home_Edition_d1968[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BD493RX1\50006+50425[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BD493RX1\download[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GDQT0Y6L\50006+50425[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IE2DZZU8\majorgeeks_com[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JGOR97LD\Boots[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S98GGZLV\Comodo_AntiVirus_d5109[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S98GGZLV\jukPlayer[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SP13OWYT\PIE[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZJ6WA7RT\BrightcovePlayer[1].swf » CWS » file.swf - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZJ6WA7RT\offerdetail4512[1].htm » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0db1904e\Report.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows Mail\Local Folders\Drafts\19CD2D37-00000003.eml » MIME - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows Mail\Local Folders\Drafts\2F8A3E66-00000004.eml » MIME - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows Mail\Local Folders\Drafts\3AF33F7C-00000002.eml » MIME - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\2D944DC7-00000001.eml » MIME - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie2.1.32.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\mobogenie.apk » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\MUServer.apk » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\3397051458870376.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\aefeatman_v_1.2.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\aercm_0.3.2.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\aercm_0.3.4.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azemp-win32_3.3.10.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azemp-win32_3.3.12.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azemp-win32_3.4.1.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azlocprov_0.1.6.3.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azutp-win32_0.2.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azutp-win32_0.3.10.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\azutp-win32_0.3.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\bafd8c5e-7324-4659-8719-fdcb010084da.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawaretb.dll - a variant of Win32/Toolbar.Visicom.A potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawareDx.dll - a variant of Win32/Toolbar.Visicom.B potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » dtUser.exe - a variant of Win32/Toolbar.Visicom.C potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » lavasoft_search_plugin.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawaretb.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawaretb.dll - a variant of Win32/Toolbar.Visicom.A potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawareDx.dll - a variant of Win32/Toolbar.Visicom.B potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » dtUser.exe - a variant of Win32/Toolbar.Visicom.C potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » lavasoft_search_plugin.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawaretb.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\jar_cache3994757568100908451.tmp » GZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » aucheck - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » jaureg - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » jucheck - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » jusched - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » task.xml - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe » CAB » task64.xml - archive damaged - the file could not be extracted.
C:\Users\myComputer\AppData\Local\Temp\mlab-win32_0.1.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\setupA9_.exe » NSIS » Mobogenie.7z » 7ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Skype.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\SkypeToolbars.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\TFR21EF.tmp » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\TFR7E5.tmp » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_4.9.0.0_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_4.9.0.0a_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_5.0.0.0a_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_5.0.0.0b_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_5.0.0.0c_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Vuze_5.1.0.0_win64.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ymsgr2 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ymsgr3 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ymsgr4 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ymsgr5 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\._msigeplugin61\Google Earth.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j13CA.tmp_dir1383355442\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j1FE9.tmp_dir1371872321\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j241A.tmp_dir1385008951\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j254B.tmp_dir1370636554\i4jruntime.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j254B.tmp_dir1370636554\platform.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j254B.tmp_dir1370636554\user.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j25AC.tmp_dir1362670160\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j28B5.tmp_dir1371516611\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j290.tmp_dir1373298140\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j29D2.tmp_dir1384353963\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j2AF.tmp_dir1368765705\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j30A0.tmp_dir1371372355\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j3141.tmp_dir1385511169\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j362D.tmp_dir1375575694\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j3680.tmp_dir1382597291\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j3813.tmp_dir1366500850\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j3880.tmp_dir1370739040\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j3A23.tmp_dir1381538531\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j40.tmp_dir1368752300\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j407C.tmp_dir1365652697\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j4452.tmp_dir1370739371\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j4B9.tmp_dir1384311815\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j50C1.tmp_dir1365652374\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j5273.tmp_dir1369061240\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j52E0.tmp_dir1369018209\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j53E9.tmp_dir1368151154\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j5A9E.tmp_dir1373323476\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j5C4B.tmp_dir1371351377\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j5F7D.tmp_dir1384286541\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j6049.tmp_dir1372987184\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j6171.tmp_dir1369976902\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j624D.tmp_dir1359789430\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j6509.tmp_dir1363938097\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j65C4.tmp_dir1374243586\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j65F4.tmp_dir1373764344\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j66B3.tmp_dir1383946943\platform.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j6B8F.tmp_dir1357708809\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j7A6C.tmp_dir1384286024\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j7BB4.tmp_dir1373061582\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j8EBC.tmp_dir1383946691\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j903E.tmp_dir1373822261\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j904D.tmp_dir1379348723\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j907C.tmp_dir1372453495\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9185.tmp_dir1381538553\i4jruntime.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9185.tmp_dir1381538553\platform.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9185.tmp_dir1381538553\user.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j92CD.tmp_dir1383437788\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j95C9.tmp_dir1378092979\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9630.tmp_dir1365407299\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9858.tmp_dir1373929441\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4j9C13.tmp_dir1367727655\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jA27B.tmp_dir1372836219\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jA36F.tmp_dir1378660238\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jA4B7.tmp_dir1357684422\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jA84F.tmp_dir1374021468\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jA894.tmp_dir1371797655\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jAD9C.tmp_dir1376186435\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jADA5.tmp_dir1384111193\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jAFE.tmp_dir1385532797\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jB7FC.tmp_dir1371175142\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jBA64.tmp_dir1379793499\i4jruntime.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jBA64.tmp_dir1379793499\platform.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jBA64.tmp_dir1379793499\user.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jBD3.tmp_dir1385361894\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jCBF1.tmp_dir1382148584\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jCCA3.tmp_dir1372311316\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jCFAE.tmp_dir1363749072\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jCFBF.tmp_dir1366522774\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jD1A6.tmp_dir1363498099\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jD5E4.tmp_dir1374935372\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jDA09.tmp_dir1370636535\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jDF4D.tmp_dir1365950704\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jE6C7.tmp_dir1375762147\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jEB3.tmp_dir1363873998\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jF028.tmp_dir1367780621\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jF08B.tmp_dir1368235901\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jF5F0.tmp_dir1361157262\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jF6C.tmp_dir1382292848\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jF6FC.tmp_dir1373168368\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jFD4F.tmp_dir1384650851\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\e4jFF50.tmp_dir1379793320\exe4jlib.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\EsetTempDir\ei_91F6.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\fullpackage_temp\package1.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\fullpackage_temp\package2.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\3397051458113855551.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\33970514581298536.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\339705145814912790.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\33970514581684873.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\33970514581714482.tmp » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\LR8IQTTY\Microsoft.Live.Silverlight.Slideshow_en__QGSaf16HgTRKJJz8Olo6w2[1].Xap » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\MATS-Temp\Results\Performance_result.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\MircosoftStudio\package1.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\scoped_dir_3976_17521\drop_to_s.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\scoped_dir_3976_19381\ask_toolbar_6_0_0.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\scoped_dir_3976_19385\youtube.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{0D8B0D61-5024-4295-8E40-78396ADAF555}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{3544C8D4-4EB9-40C1-8B84-E0C402AE99A8}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{4EA8E78D-8BDF-40BE-B41A-51EE52A4196C}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{652EFC24-2AEA-469D-92FF-E6FB4FF59458}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{8F7CA7A8-3E6B-4C23-8FAA-D668AFB22627}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{BD026C92-C987-468B-9A22-C021F7997A0E}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\{E367888F-2E43-469E-AD28-BEC74749EE66}\GoogleUpdateHelper.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000001 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000003 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000004 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000005 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000007 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_000009 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Google\GoogleEarth\webdata\f_00000d » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\AU\au.cab » CAB - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\AU\au.msi » MSI - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\22e17456-37242cd5 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\6b30ec21-5facd6eb » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\2e712b26-7e14b560 » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\1ca2666b-28ce97ea » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Adobe\Acrobat\10.0\ServicesRdr\com_2E_adobe_2E_acrobat_2E_services_2E_cfg_5F_10_2E_1_2E_5_2E_2.cfg » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Adobe\Acrobat\10.0\ServicesRdr\com_2E_adobe_2E_acrobat_2E_services_2E_cfg_5F_10_2E_1_2E_8_2E_1.cfg » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Adobe\Acrobat\10.0\ServicesRdr\com_2E_adobe_2E_acrobat_2E_services_2E_DEXShare_5F_10_2E_1_2E_5_2E_2.spi » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Adobe\Acrobat\10.0\ServicesRdr\com_2E_adobe_2E_acrobat_2E_services_2E_DEXShare_5F_10_2E_1_2E_8_2E_1.spi » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aefeatman_v\aefeatman_v_1.2.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aefeatman_v\aefeatman_v_1.2.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.2.0.0.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.3.0.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.3.2.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.3.4.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.3.7.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\aercm\aercm_0.4.3.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.3.10.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.3.10.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.3.12.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.3.12.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.4.1.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\azemp_3.4.1.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azemp\libmprCanvas_1.3.6.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azlocprov\azlocprov_0.1.1.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azlocprov\azlocprov_0.1.4.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azlocprov\azlocprov_0.1.6.3.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azlocprov\azlocprov_0.1.6.3.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azrating\azrating_1.4.2.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azrating\azrating_1.4.3.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.2.9.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.2.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.3.10.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.3.10.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.3.9.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\azutp\azutp_0.3.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\mlab\mlab_0.1.9.jar » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Roaming\Azureus\plugins\mlab\mlab_0.1.9.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\Downloads\Resize_My_Pictures.zip » ZIP - is OK (internal scanning not performed)
C:\Windows\Downloaded Installations\{CA7D4921-377A-43B2-870C-9718101C24DE}\SILKYPIX Developer Studio 3.0 for PENTAX.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\authfw.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\ipsecpolicy.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\lug.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\mmc.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\saferconcepts.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\snmp.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\spolsconcepts.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\sys_srv.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\Help\mui\0409\tpmadmin.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\IME\imekr8\help\imkrpd.chm » CHM - is OK (internal scanning not performed)
C:\Windows\Installer\10cae26f.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\152d21f8.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\176832f2.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\193ee8.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\1a4291.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\24cd271.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\2642dda.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\2642de6.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\27fdba.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\2a1a58.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\2afe64.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\2bcd7f07.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\3433a5.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\409b3be.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\45c3f57.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\45c3f73.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\45c3f7a.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\48ae7ac.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\48ae7b2.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\48ae7b6.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\48ae7ba.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\6eeabc2.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\96e048.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\dexshare.spi » ZIP - is OK (internal scanning not performed)
C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg » ZIP - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\chrome\chrome.jar » ZIP - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.cab » CAB - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\netfx_core.mzz » CAB - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\netfx_core_x64.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Windows6.0-KB956250-v6001-x64.msu » CAB - is OK (internal scanning not performed)
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Windows6.1-KB958488-v6001-x64.msu » CAB - is OK (internal scanning not performed)
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT - error opening [4]
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 - error opening [4]
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 - error opening [4]
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - error opening [4]
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - error opening [4]
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT - error opening [4]
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 - error opening [4]
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 - error opening [4]
C:\Windows\SoftwareDistribution\AuthCabs\authcab.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\authcab.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\AuthCabs\Redir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\AuthCabs\Redir\9482F4B4-E343-43B6-B170-9A65BC822C77\wuredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\Download\6a54a0de1fee168c620014cc7de09a55b139fe47 » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\Download\73432f90b50c5de7d0e566193fd8430d\Windows6.0-KB956250-x64.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\Download\e5ee985038e4aa2a8f2ffc72a8f93973\windows6.0-kb2763674-x64-express.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\SelfUpdate\Handler\WuSetupHandler.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\muredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\WuRedir\7971F918-A847-4430-9279-4A52D1EFE18D\wuredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\wuredir.cab » CAB - is OK (internal scanning not performed)
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 » CAB - is OK (internal scanning not performed)
C:\Windows\System32\spool\drivers\x64\PCC\hpvpl04.inf_2a66245c.cab » CAB - is OK (internal scanning not performed)
C:\Windows\System32\spool\drivers\x64\PCC\ntprint.inf_05612b59.cab » CAB - is OK (internal scanning not performed)
C:\Windows\System32\spool\drivers\x64\PCC\prnms001.inf_6b0743f8.cab » CAB - is OK (internal scanning not performed)
C:\Windows\System32\spool\drivers\x64\PCC\prnms002.inf_1d6c7442.cab » CAB - is OK (internal scanning not performed)
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 » CAB - is OK (internal scanning not performed)
C:\Windows\Temp\._msigeplugin61\Google Earth.msi » MSI - is OK (internal scanning not performed)
C:\Windows\Temp\Low\MSI\SkypeToolbars.msi » MSI - is OK (internal scanning not performed)
C:\Windows\WindowsMobile\mui\0409\wm_devmgr.chm » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_divasx64.inf_31bf3856ad364e35_6.0.6001.18000_none_607ed84088ce5846\te_protm.2qm » TAR - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_divasx64.inf_31bf3856ad364e35_6.0.6001.18000_none_607ed84088ce5846\te_protm.am » TAR - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_divasx64.inf_31bf3856ad364e35_6.0.6001.18000_none_607ed84088ce5846\te_protm.pm2 » TAR - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_divasx64.inf_31bf3856ad364e35_6.0.6001.18000_none_607ed84088ce5846\te_protm.pm3 » TAR - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_microsoft-windows-ime-korean-help_31bf3856ad364e35_6.0.6000.16386_none_ea0e957fd04399fa\imkrpd.chm » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_microsoft-windows-localizeddrivers_31bf3856ad364e35_6.0.6000.16386_en-us_d8b4b68e802ab022\locdrv.cab » CAB - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_microsoft-windows-mediaplayer-skins_31bf3856ad364e35_6.0.6000.16386_none_0348fbb194e52ab6\Revert.wmz » ZIP - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_microsoft-windows-mediaplayer-skins_31bf3856ad364e35_6.0.6002.18005_none_076b36b98ef206d6\Revert.wmz » ZIP - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.authfw.resources_31bf3856ad364e35_6.0.6001.18000_en-us_711362beca1f1b35\authfw.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.file_srv.resources_31bf3856ad364e35_6.0.6000.16386_en-us_1cac41e6587c725a\file_srv.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.ipsecpolicy.resources_31bf3856ad364e35_6.0.6001.18000_en-us_b35cd72c48686e0e\ipsecpolicy.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.lug.resources_31bf3856ad364e35_6.0.6001.18000_en-us_8943128f03b691ba\lug.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.mmc.resources_31bf3856ad364e35_6.0.6001.18000_en-us_18fc747d85dba53d\mmc.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.qos.resources_31bf3856ad364e35_6.0.6000.16386_en-us_83fe6986d82fd383\QoS.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.saf..oncepts_v.resources_31bf3856ad364e35_6.0.6001.18000_en-us_82344fc18d37ba8b\saferconcepts.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.snmp.resources_31bf3856ad364e35_6.0.6001.18000_en-us_456fac32cddee97c\snmp.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.spo..oncepts_v.resources_31bf3856ad364e35_6.0.6001.18000_en-us_1965166542567787\spolsconcepts.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.sys_srv.resources_31bf3856ad364e35_6.0.6000.16386_en-us_4a77b04e1ac35639\sys_srv.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.sys_srv.resources_31bf3856ad364e35_6.0.6001.18000_en-us_4cae724a17ae670d\sys_srv.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_server-help-chm.tpmadmin.resources_31bf3856ad364e35_6.0.6001.18000_en-us_f4cbc4a39c40000c\tpmadmin.CHM » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_winmobil.inf.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3e94b5b83de50ccc\wm_devmgr.chm » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_winmobil.inf_31bf3856ad364e35_6.0.6001.18000_none_fba2ba8917dbe2f8\wmdevmgr.chm » CHM - is OK (internal scanning not performed)
C:\Windows\winsxs\amd64_winmobil.inf_31bf3856ad364e35_6.0.6002.18005_none_fd8e339514fdae44\wmdevmgr.chm » CHM - is OK (internal scanning not performed)
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\adawareDx.dll.vir - a variant of Win32/Toolbar.Visicom.B potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\adawaretb.dll.vir - a variant of Win32/Toolbar.Visicom.A potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\adawaretb\dtUser.exe.vir - a variant of Win32/Toolbar.Visicom.C potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\Helper.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\safetyldr.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\safetyldr_u.dll.vir - a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\x64\safetyldr.dll.vir - a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application - cleaned by deleting - quarantined [1]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\SafetyNut\x64\safetyldr_u.dll.vir - a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application - cleaned by deleting - quarantined [1]
C:\Users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PB2UC0V8\Safe+Haven+28201329+720p+BrRip+x264+-+YIFY.exe - a variant of Win32/4Shared.K potentially unwanted application - cleaned by deleting - quarantined [1]
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawaretb.dll - a variant of Win32/Toolbar.Visicom.A potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawareDx.dll - a variant of Win32/Toolbar.Visicom.B potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » dtUser.exe - a variant of Win32/Toolbar.Visicom.C potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » lavasoft_search_plugin.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\caf1373e-be8a-413d-a22a-18b5d80ad730.exe » NSIS » adawaretb.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawaretb.dll - a variant of Win32/Toolbar.Visicom.A potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawareDx.dll - a variant of Win32/Toolbar.Visicom.B potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » dtUser.exe - a variant of Win32/Toolbar.Visicom.C potentially unwanted application
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » lavasoft_search_plugin.zip » ZIP - is OK (internal scanning not performed)
C:\Users\myComputer\AppData\Local\Temp\ebbd3eef-f3b6-4fb1-8e0e-cd08a2cea569.exe » NSIS » adawaretb.crx » CHROMEEXTENSION - is OK (internal scanning not performed)
Number of scanned objects: 124460
Number of threats found: 15
Number of cleaned objects: 15
Time of completion: 10:09:26 PM Total scanning time: 3898 sec (01:04:58)

Notes:
[1] Object has been deleted as it only contained the virus body.
[4] Object cannot be opened. It may be in use by another application or operating system.

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
How's your computer working now?

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I no longer have "ask.com" taking over the search from google, but now when I type the name of the bank into google,the " internet explore can not access this page " comes up ,as if my pc went off line. My daughters laptop has no problem accessing the bank. It only does it on that one bank . even if I try to trick it by finding a site that mentions the bank ,and click on it from there the same thing happens.
Oh, but my pc is lightning quick,after I did what you said to. I also enjoy reading the Tips and Tricks book I got.

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
Is it possible that the site is blocked? What browser are you using?

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I use internet explore. I'm not sure how the site could be blocked. I sent them a note asking if things were working properly and they said yes. They won't have blocked me .

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I just clicked on "diagnose problem" in the window that said internert explorer could not access this page, then went to advanced security and clicked on tlt or some similar letters ,they wern't checked yet. Now I can access the banks website, but when I try to access my acct this is what comes up. I believe this happened once before and it turned out I was using a cashed old site??? Maybe I have it wrong ,but it was something like that. I don't think I fixed it because I believe I got another ( second hand ) pc right after that.
There is a problem with this website's security certificate.


The security certificate presented by this website was issued for a different website's address.

Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server.
We recommend that you close this webpage and do not continue to this website.
Click here to close this webpage.
Continue to this website (not recommended).
More information


If you arrived at this page by clicking a link, check the website address in the address bar to be sure that it is the address you were expecting.
When going to a website with an address such as https://example.com, try adding the 'www' to the address, https://www.example.com.

For more information, see "Certificate Errors" in Internet Explorer Help.


descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I just noticed a pop up at the website saying they may be down on the 30th of this month. Thats about now,depending what time zone they are in.So Please don't bother with anything at this time. I'll check tomorrow when they are finished updating things and send a note.
Thanks for all your help.

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
Well, sadly the website is finished updating and I still get this window poping up.
There is a problem with this website's security certificate.


The security certificate presented by this website was issued for a different website's address.

Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server.
We recommend that you close this webpage and do not continue to this website.
Click here to close this webpage.
Continue to this website (not recommended).
More information


If you arrived at this page by clicking a link, check the website address in the address bar to be sure that it is the address you were expecting.
When going to a website with an address such as https://example.com, try adding the 'www' to the address, https://www.example.com.

For more information, see "Certificate Errors" in Internet Explorer Help.
How can I update my certificate ,if thats what's required ?

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
Please check this site.

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I went to the site and followed insructions. The address bar turned red once I clicked on " continue anyway,we recommend you dont continue " . I was able to proceed to the login page,however they said the password or acct number was wrong,but it isn,t wrong.The address bar remains red.. Is there anything else I can do? This hapened once before ,I phoned them and was told my pc must be going to an old cashed site of theres. Could this be? I never did figure it out cause I switched pc's shortly after that.

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
Please run AdwCleaner and delete those infections.

Download Combofix from any of the links below, and save it to your DESKTOP.
If your version of Windows defaults to you download folder you will need to copy it to your desktop.

Link 1
Link 2
Link 3

To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.

  • Close any open windows and double click ComboFix.exe to run it.

    You will see the following image:

Ask, keeps overpowering google on one site only cant stop it! - Page 2 NSIS_disclaimer_ENG

Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:

Ask, keeps overpowering google on one site only cant stop it! - Page 2 NSIS_extraction

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.

Ask, keeps overpowering google on one site only cant stop it! - Page 2 RcAuto1

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Ask, keeps overpowering google on one site only cant stop it! - Page 2 Whatnext

Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
I'll post this in two parts
ComboFix 13-11-27.01 - myComputer 12/01/2013 10:42:07.2.2 - x64
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.4094.2414 [GMT -7:00]
Running from: c:\users\myComputer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YTY4OSHC\ComboFix.exe
AV: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: ESET NOD32 Antivirus 7.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
SP: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: ESET NOD32 Antivirus 7.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\ydi.log
.
.
((((((((((((((((((((((((( Files Created from 2013-11-01 to 2013-12-01 )))))))))))))))))))))))))))))))
.
.
2013-12-01 18:33 . 2013-12-01 18:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-01 10:56 . 2013-12-01 10:56 -------- d-----w- c:\users\myComputer\AppData\Local\ESET
2013-11-29 03:43 . 2013-11-29 03:43 -------- d-----w- c:\program files\ESET
2013-11-29 00:47 . 2013-11-29 00:47 -------- d-----w- c:\users\myComputer\AppData\Roaming\AVG2014
2013-11-29 00:46 . 2013-11-29 00:46 -------- d-----w- c:\users\myComputer\AppData\Roaming\TuneUp Software
2013-11-29 00:45 . 2013-12-01 18:35 -------- d-----w- c:\programdata\AVG2014
2013-11-29 00:45 . 2013-11-29 00:45 -------- d-----w- C:\$AVG
2013-11-29 00:45 . 2013-11-29 00:45 -------- d-----w- c:\program files (x86)\AVG
2013-11-29 00:41 . 2013-12-01 17:10 -------- d-----w- c:\programdata\MFAData
2013-11-29 00:41 . 2013-11-29 03:00 -------- d-----w- c:\users\myComputer\AppData\Local\Avg2014
2013-11-29 00:41 . 2013-11-29 00:41 -------- d-----w- c:\users\myComputer\AppData\Local\MFAData
2013-11-28 03:55 . 2013-11-18 08:28 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{71ADEC8A-24EC-4322-8DCA-6FC540A33935}\mpengine.dll
2013-11-28 00:28 . 2013-11-28 00:28 -------- d-----w- c:\windows\ERUNT
2013-11-27 14:28 . 2013-11-27 14:28 -------- d-----w- c:\users\wangjihua
2013-11-27 06:27 . 2013-11-27 06:27 -------- d-----w- c:\users\myComputer\.android
2013-11-27 06:27 . 2013-11-27 14:28 -------- d-----w- c:\users\myComputer\AppData\Local\cache
2013-11-27 06:27 . 2013-11-27 14:29 -------- d-----w- c:\users\myComputer\AppData\Local\Mobogenie
2013-11-27 06:26 . 2013-11-27 14:29 -------- d-----w- c:\program files (x86)\Mobogenie
2013-11-27 05:49 . 2013-11-27 05:49 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-27 05:49 . 2013-11-27 05:49 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-11-26 22:09 . 2013-11-28 03:39 -------- d-----w- C:\AdwCleaner
2013-11-26 15:27 . 2013-11-27 22:53 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-11-26 15:27 . 2013-04-04 21:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-26 15:17 . 2013-11-26 15:17 -------- d-----w- c:\programdata\AVAST Software
2013-11-26 14:30 . 2013-11-27 00:23 -------- d-----w- c:\users\myComputer\AppData\Local\LogMeIn Rescue Applet
2013-11-26 06:45 . 2013-11-26 06:45 -------- d-----w- c:\programdata\HitmanPro
2013-11-26 03:11 . 2013-11-26 03:11 -------- d-----w- c:\programdata\Pure Networks
2013-11-14 10:03 . 2013-10-13 14:36 96768 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-14 10:03 . 2013-10-13 14:35 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-14 10:03 . 2013-10-13 09:25 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-11-14 10:03 . 2013-10-13 16:04 183024 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2013-11-14 10:03 . 2013-10-13 14:46 996352 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-11-14 10:03 . 2013-10-13 14:44 305152 ----a-w- c:\program files\Internet Explorer\IEShims.dll
2013-11-14 10:03 . 2013-10-13 10:49 149744 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll
2013-11-14 10:03 . 2013-10-13 09:33 768512 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\vgx\VGX.dll
2013-11-14 10:03 . 2013-10-13 09:29 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-13 14:38 . 2013-10-11 04:23 462848 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-11-13 14:38 . 2013-10-11 04:23 781824 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-11-13 14:38 . 2013-10-11 02:07 596480 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2013-11-13 14:38 . 2013-10-03 15:02 1278976 ----a-w- c:\windows\system32\crypt32.dll
2013-11-13 14:38 . 2013-10-03 12:45 993792 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-11-13 14:38 . 2013-10-03 15:03 389632 ----a-w- c:\windows\system32\gdi32.dll
2013-11-13 14:38 . 2013-10-03 12:46 304128 ----a-w- c:\windows\SysWow64\gdi32.dll
2013-11-13 14:38 . 2013-09-04 02:31 404992 ----a-w- c:\windows\system32\drivers\afd.sys
2013-11-13 03:16 . 2013-11-13 03:16 -------- d-----w- c:\users\myComputer\AppData\Local\MaxiGet Download Manager
2013-11-13 03:16 . 2013-11-13 03:20 -------- d-----w- c:\users\myComputer\AppData\Local\Maxiget
2013-11-06 04:55 . 2013-11-06 04:55 150808 ----a-w- c:\windows\system32\drivers\avgdiska.sys
2013-11-05 04:52 . 2013-11-05 04:52 240920 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2013-11-05 04:19 . 2013-11-05 04:19 -------- d-----w- c:\windows\Sun
2013-11-05 04:19 . 2013-11-26 05:30 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-11-05 04:18 . 2013-10-08 14:50 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-11-05 04:16 . 2013-11-05 04:19 -------- d-----w- c:\programdata\Oracle
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-14 10:01 . 2006-11-02 12:35 82896128 ----a-w- c:\windows\system32\mrt.exe
2013-11-11 12:50 . 2013-01-09 02:38 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-01 06:00 . 2013-11-01 06:00 212280 ----a-w- c:\windows\system32\drivers\avgldx64.sys
2013-11-01 05:49 . 2013-11-01 05:49 294712 ----a-w- c:\windows\system32\drivers\avgloga.sys
2013-10-25 05:25 . 2013-10-25 05:25 194872 ----a-w- c:\windows\system32\drivers\avgidsha.sys
2013-10-01 07:52 . 2013-10-01 07:52 123704 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
2013-09-17 22:17 . 2013-09-17 22:17 239320 ----a-w- c:\windows\system32\drivers\eamonm.sys
2013-09-17 22:17 . 2013-09-17 22:17 239296 ----a-w- c:\windows\system32\drivers\edevmon.sys
2013-09-17 22:17 . 2013-09-17 22:17 168256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2013-09-17 22:17 . 2013-09-17 22:17 157432 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2013-09-10 07:43 . 2013-09-10 07:43 31544 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
"ForceActiveDesktopOn"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\rjatydimofu.exe]
"debugger"=tasklist.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Browsing Protection]
2013-01-31 15:11 542632 ----a-w- c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]
2010-04-02 18:18 1185112 ----a-w- c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-07-02 16:16 254336 ----a-w- c:\program files (x86)\Common Files\Java\Java Update\jusched.exe
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-27 05:49]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-09 03:16]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-09 03:16]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-929725188-2267044026-2474493764-1000Core.job
- c:\users\myComputer\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-21 00:38]
.
2013-12-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-929725188-2267044026-2474493764-1000UA.job
- c:\users\myComputer\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-21 00:38]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2013-09-12 5618456]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mSearch Page = hxxp://do-search.com/web/?type=ds&ts=1385533547&from=ild&uid=HitachiXHDP725016GLA380_GEM864RH27AR4E27AR4EX&q={searchTerms}
mLocal Page = c:\windows\SysWOW64\blank.htm
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
Toolbar-10 - (no file)
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
HKLM-Run-SBRegRebootCleaner - c:\program files (x86)\Ad-Aware Antivirus\SBRC.exe
AddRemove-Coupon Printer for Windows5.0.0.0 - c:\program files (x86)\Coupons\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Data]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Networking]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET CLR Networking 4.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET Data Provider for Oracle]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NET Data Provider for SqlServer]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.NETFramework]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ACPI]
"ImagePath"="system32\drivers\acpi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AdobeARMservice]
"ImagePath"="\"c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AdobeFlashPlayerUpdateSvc]
"ImagePath"="c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adp94xx]
"ImagePath"="\SystemRoot\system32\drivers\adp94xx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpahci]
"ImagePath"="\SystemRoot\system32\drivers\adpahci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpu160m]
"ImagePath"="\SystemRoot\system32\drivers\adpu160m.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adpu320]
"ImagePath"="\SystemRoot\system32\drivers\adpu320.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adsi]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AeLookupSvc]
"ServiceDll"="%SystemRoot%\System32\aelupsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AFD]
"ImagePath"="\SystemRoot\system32\drivers\afd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\agp440]
"ImagePath"="\SystemRoot\system32\drivers\agp440.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aic78xx]
"ImagePath"="\SystemRoot\system32\drivers\djsvs.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ALG]
"ImagePath"="%SystemRoot%\System32\alg.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aliide]
"ImagePath"="\SystemRoot\system32\drivers\aliide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AMD External Events Utility]
"ImagePath"="%SystemRoot%\system32\atiesrxx.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdide]
"ImagePath"="\SystemRoot\system32\drivers\amdide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AmdK8]
"ImagePath"="\SystemRoot\system32\drivers\amdk8.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdkmdag]
"ImagePath"="system32\DRIVERS\atikmdag.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdkmdap]
"ImagePath"="system32\DRIVERS\atikmpag.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Appinfo]
"ServiceDll"="%SystemRoot%\System32\appinfo.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AppMgmt]
"ServiceDll"="%SystemRoot%\System32\appmgmts.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\arc]
"ImagePath"="\SystemRoot\system32\drivers\arc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\arcsas]
"ImagePath"="\SystemRoot\system32\drivers\arcsas.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AsyncMac]
"ImagePath"="system32\DRIVERS\asyncmac.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\atapi]
"ImagePath"="system32\drivers\atapi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Atierecord]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AudioEndpointBuilder]
"ServiceDll"="%SystemRoot%\System32\Audiosrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AudioSrv]
"ServiceDll"="%SystemRoot%\System32\Audiosrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avg]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgdiska]
"ImagePath"="system32\DRIVERS\avgdiska.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSAgent]
"ImagePath"="\"c:\program files (x86)\AVG\AVG2014\avgidsagent.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSDriver]
"ImagePath"="system32\DRIVERS\avgidsdrivera.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVGIDSHA]
"ImagePath"="system32\DRIVERS\avgidsha.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgldx64]
"ImagePath"="system32\DRIVERS\avgldx64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgloga]
"ImagePath"="system32\DRIVERS\avgloga.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgmfx64]
"ImagePath"="system32\DRIVERS\avgmfx64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgrkx64]
"ImagePath"="system32\DRIVERS\avgrkx64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Avgtdia]
"ImagePath"="system32\DRIVERS\avgtdia.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avgwd]
"ImagePath"="\"c:\program files (x86)\AVG\AVG2014\avgwdsvc.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BattC]
"MofImagePath"="system32\drivers\battc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BFE]
"ServiceDll"="%SystemRoot%\System32\bfe.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BITS]
"ServiceDll"="%systemroot%\system32\qmgr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\blbdrive]
"ImagePath"="\SystemRoot\system32\drivers\blbdrive.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bowser]
"ImagePath"="system32\DRIVERS\bowser.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrFiltLo]
"ImagePath"="\SystemRoot\system32\drivers\brfiltlo.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrFiltUp]
"ImagePath"="\SystemRoot\system32\drivers\brfiltup.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Browser]
"ServiceDll"="%SystemRoot%\System32\browser.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Brserid]
"ImagePath"="\SystemRoot\system32\drivers\brserid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrSerWdm]
"ImagePath"="\SystemRoot\system32\drivers\brserwdm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrUsbMdm]
"ImagePath"="\SystemRoot\system32\drivers\brusbmdm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrUsbSer]
"ImagePath"="\SystemRoot\system32\drivers\brusbser.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BTHMODEM]
"ImagePath"="\SystemRoot\system32\drivers\bthmodem.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BTHPORT]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\catchme]
"ImagePath"="\??\c:\combofix\catchme.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cdfs]
"ImagePath"="system32\DRIVERS\cdfs.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cdrom]
"ImagePath"="system32\DRIVERS\cdrom.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CertPropSvc]
"ServiceDll"="%SystemRoot%\System32\certprop.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\circlass]
"ImagePath"="\SystemRoot\system32\drivers\circlass.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CLFS]
"ImagePath"="System32\CLFS.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v2.0.50727_32]
"ImagePath"="%systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v2.0.50727_64]
"ImagePath"="%systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v4.0.30319_32]
"ImagePath"="c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v4.0.30319_64]
"ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdide]
"ImagePath"="\SystemRoot\system32\drivers\cmdide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Compbatt]
"ImagePath"="\SystemRoot\system32\drivers\compbatt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\COMSysApp]
"ImagePath"="%SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crcdisk]
"ImagePath"="system32\drivers\crcdisk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CryptSvc]
"ServiceDll"="%SystemRoot%\system32\cryptsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CSC]
"ImagePath"="system32\drivers\csc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CscService]
"ServiceDll"="%SystemRoot%\System32\cscsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DCLocator]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DcomLaunch]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DfsC]
"ImagePath"="System32\Drivers\dfsc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DFSR]
"ImagePath"="%SystemRoot%\system32\DFSR.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dhcp]
"ServiceDll"="%SystemRoot%\system32\dhcpcsvc.dll"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\disk]
"ImagePath"="system32\drivers\disk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache]
"ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\dot3svc]
"ServiceDll"="%SystemRoot%\System32\dot3svc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPS]
"ServiceDll"="%SystemRoot%\system32\dps.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\drmkaud]
"ImagePath"="system32\drivers\drmkaud.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DXGKrnl]
"ImagePath"="\SystemRoot\System32\drivers\dxgkrnl.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\E1G60]
"ImagePath"="system32\DRIVERS\E1G6032E.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\eamonm]
"ImagePath"="system32\DRIVERS\eamonm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EapHost]
"ServiceDll"="%SystemRoot%\System32\eapsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ecache]
"ImagePath"="System32\drivers\ecache.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\edevmon]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ehdrv]
"ImagePath"="system32\DRIVERS\ehdrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ekrn]
"ImagePath"="\"c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\elxstor]
"ImagePath"="\SystemRoot\system32\drivers\elxstor.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EmdCache]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EMDMgmt]
"ServiceDll"="%systemroot%\system32\emdmgmt.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\epfwwfpr]
"ImagePath"="system32\DRIVERS\epfwwfpr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ErrDev]
"ImagePath"="\SystemRoot\system32\drivers\errdev.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ESENT]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog]
"ServiceDll"="%SystemRoot%\System32\wevtsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventSystem]
"ServiceDll"="%systemroot%\system32\es.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\exfat]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fastfat]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Fax]
"ImagePath"="%systemroot%\system32\fxssvc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fdc]
"ImagePath"="system32\DRIVERS\fdc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fdPHost]
"ServiceDll"="%SystemRoot%\system32\fdPHost.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FDResPub]
"ServiceDll"="%SystemRoot%\system32\fdrespub.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FileInfo]
"ImagePath"="system32\drivers\fileinfo.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Filetrace]
"ImagePath"="system32\drivers\filetrace.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\flpydisk]
"ImagePath"="system32\DRIVERS\flpydisk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FltMgr]
"ImagePath"="system32\drivers\fltmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FontCache]
"ServiceDll"="%SystemRoot%\system32\FntCache.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FontCache3.0.0.0]
"ImagePath"="%systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Fs_Rec]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gagp30kx]
"ImagePath"="\SystemRoot\system32\drivers\gagp30kx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gfiark]
"ImagePath"="system32\drivers\gfiark.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gpsvc]
"ServiceDll"="%SystemRoot%\System32\gpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gupdate]
"ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /svc"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gupdatem]
"ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /medsvc"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gusvc]
"ImagePath"="\"c:\program files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HdAudAddService]
"ImagePath"="system32\drivers\HdAudio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HDAudBus]
"ImagePath"="system32\DRIVERS\HDAudBus.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidBth]
"ImagePath"="\SystemRoot\system32\drivers\hidbth.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidIr]
"ImagePath"="\SystemRoot\system32\drivers\hidir.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hidserv]
"ServiceDll"="%SystemRoot%\System32\hidserv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HidUsb]
"ImagePath"="system32\DRIVERS\hidusb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hkmsvc]
"ServiceDLL"="%SystemRoot%\system32\kmsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HpCISSs]
"ImagePath"="\SystemRoot\system32\drivers\hpcisss.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HTTP]
"ImagePath"="system32\drivers\HTTP.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i2omp]
"ImagePath"="\SystemRoot\system32\drivers\i2omp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i8042prt]
"ImagePath"="system32\DRIVERS\i8042prt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iaStorV]
"ImagePath"="\SystemRoot\system32\drivers\iastorv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IDriverT]
"ImagePath"="\"c:\program files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\idsvc]
"ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iirsp]
"ImagePath"="\SystemRoot\system32\drivers\iirsp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IKEEXT]
"ServiceDll"="%SystemRoot%\System32\ikeext.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\inetaccs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\intelide]
"ImagePath"="system32\drivers\intelide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\intelppm]
"ImagePath"="system32\DRIVERS\intelppm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPBusEnum]
"ServiceDll"="%SystemRoot%\system32\ipbusenum.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IpFilterDriver]
"ImagePath"="system32\DRIVERS\ipfltdrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iphlpsvc]
"ServiceDll"="%SystemRoot%\System32\iphlpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IpInIp]
"ImagePath"="system32\DRIVERS\ipinip.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPMIDRV]
"ImagePath"="\SystemRoot\system32\drivers\ipmidrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPNAT]
"ImagePath"="system32\DRIVERS\ipnat.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IRENUM]
"ImagePath"="system32\drivers\irenum.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\isapnp]
"ImagePath"="\SystemRoot\system32\drivers\isapnp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iScsiPrt]
"ImagePath"="system32\DRIVERS\msiscsi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iteatapi]
"ImagePath"="\SystemRoot\system32\drivers\iteatapi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iteraid]
"ImagePath"="\SystemRoot\system32\drivers\iteraid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kbdclass]
"ImagePath"="system32\DRIVERS\kbdclass.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kbdhid]
"ImagePath"="system32\DRIVERS\kbdhid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KeyIso]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KSecDD]
"ImagePath"="System32\Drivers\ksecdd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ksthunk]
"ImagePath"="\SystemRoot\system32\drivers\ksthunk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KtmRm]
"ServiceDll"="%systemroot%\system32\msdtckrm.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanServer]
"ServiceDll"="%SystemRoot%\System32\srvsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanWorkstation]
"ServiceDll"="%SystemRoot%\System32\wkssvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldap]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lltdio]
"ImagePath"="system32\DRIVERS\lltdio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lltdsvc]
"ServiceDll"="%SystemRoot%\System32\lltdsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lmhosts]
"ServiceDll"="%SystemRoot%\System32\lmhsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Lsa]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_FC]
"ImagePath"="\SystemRoot\system32\drivers\lsi_fc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_SAS]
"ImagePath"="\SystemRoot\system32\drivers\lsi_sas.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LSI_SCSI]
"ImagePath"="\SystemRoot\system32\drivers\lsi_scsi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\luafv]
"ImagePath"="\SystemRoot\system32\drivers\luafv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMProtector]
"ImagePath"="\??\c:\windows\system32\drivers\mbam.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMScheduler]
"ImagePath"="\"c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMService]
"ImagePath"="\"c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\megasas]
"ImagePath"="\SystemRoot\system32\drivers\megasas.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MegaSR]
"ImagePath"="\SystemRoot\system32\drivers\megasr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MMCSS]
"ServiceDll"="%SystemRoot%\system32\mmcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Modem]
"ImagePath"="system32\drivers\modem.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\monitor]
"ImagePath"="system32\DRIVERS\monitor.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouclass]
"ImagePath"="system32\DRIVERS\mouclass.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mouhid]
"ImagePath"="system32\DRIVERS\mouhid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MountMgr]
"ImagePath"="System32\drivers\mountmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mpio]
"ImagePath"="\SystemRoot\system32\drivers\mpio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mpsdrv]
"ImagePath"="System32\drivers\mpsdrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MpsSvc]
"ServiceDll"="%SystemRoot%\system32\mpssvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mraid35x]
"ImagePath"="\SystemRoot\system32\drivers\mraid35x.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MRxDAV]
"ImagePath"="\SystemRoot\system32\drivers\mrxdav.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb]
"ImagePath"="system32\DRIVERS\mrxsmb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb10]
"ImagePath"="system32\DRIVERS\mrxsmb10.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mrxsmb20]
"ImagePath"="system32\DRIVERS\mrxsmb20.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msahci]
"ImagePath"="\SystemRoot\system32\drivers\msahci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msdsm]
"ImagePath"="\SystemRoot\system32\drivers\msdsm.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC]
"ImagePath"="%SystemRoot%\System32\msdtc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC Bridge 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC Bridge 4.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Msfs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msisadrv]
"ImagePath"="system32\drivers\msisadrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSiSCSI]
"ServiceDll"="%systemroot%\system32\iscsiexe.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSKSSRV]
"ImagePath"="system32\drivers\MSKSSRV.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSPCLOCK]
"ImagePath"="system32\drivers\MSPCLOCK.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSPQM]
"ImagePath"="system32\drivers\MSPQM.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MsRPC]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSSCNTRS]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mssmbios]
"ImagePath"="system32\DRIVERS\mssmbios.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSTEE]
"ImagePath"="system32\drivers\MSTEE.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mup]
"ImagePath"="System32\Drivers\mup.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\napagent]
"ServiceDLL"="%SystemRoot%\system32\qagentRT.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NativeWifiP]
"ImagePath"="system32\DRIVERS\nwifi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NDIS]
"ImagePath"="system32\drivers\ndis.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NdisTapi]
"ImagePath"="system32\DRIVERS\ndistapi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ndisuio]
"ImagePath"="system32\DRIVERS\ndisuio.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NdisWan]
"ImagePath"="system32\DRIVERS\ndiswan.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NDProxy]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetBIOS]
"ImagePath"="system32\DRIVERS\netbios.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\netbt]
"ImagePath"="System32\DRIVERS\netbt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Netlogon]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Netman]
"ServiceDll"="%SystemRoot%\System32\netman.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\netprofm]
"ServiceDll"="%SystemRoot%\System32\netprofm.dll"

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetTcpPortSharing]
"ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nfrd960]
"ImagePath"="\SystemRoot\system32\drivers\nfrd960.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NlaSvc]
"ServiceDll"="%SystemRoot%\System32\nlasvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Npfs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsi]
"ServiceDll"="%systemroot%\system32\nsisvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsiproxy]
"ImagePath"="system32\drivers\nsiproxy.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTDS]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ntfs]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Null]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nvraid]
"ImagePath"="\SystemRoot\system32\drivers\nvraid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nvstor]
"ImagePath"="\SystemRoot\system32\drivers\nvstor.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nv_agp]
"ImagePath"="\SystemRoot\system32\drivers\nv_agp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NwlnkFlt]
"ImagePath"="system32\DRIVERS\nwlnkflt.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NwlnkFwd]
"ImagePath"="system32\DRIVERS\nwlnkfwd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ohci1394]
"ImagePath"="\SystemRoot\system32\drivers\ohci1394.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\p2pimsvc]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\p2psvc]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Parport]
"ImagePath"="system32\DRIVERS\parport.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\partmgr]
"ImagePath"="System32\drivers\partmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PcaSvc]
"ServiceDll"="%SystemRoot%\System32\pcasvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pci]
"ImagePath"="system32\drivers\pci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pciide]
"ImagePath"="\SystemRoot\system32\drivers\pciide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pcmcia]
"ImagePath"="\SystemRoot\system32\drivers\pcmcia.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PEAUTH]
"ImagePath"="system32\drivers\peauth.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfDisk]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfHost]
"ImagePath"="%SystemRoot%\SysWow64\perfhost.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfNet]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfOS]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfProc]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ph3xIB64]
"ImagePath"="system32\DRIVERS\Ph3xIB64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pla]
"ServiceDll"="%systemroot%\system32\pla.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PlugPlay]
"ServiceDll"="%SystemRoot%\system32\umpnpmgr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PNRPAutoReg]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PNRPsvc]
"ServiceDll"="%SystemRoot%\system32\p2psvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PolicyAgent]
"ServiceDll"="%SystemRoot%\System32\ipsecsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PortProxy]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PptpMiniport]
"ImagePath"="system32\DRIVERS\raspptp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Processor]
"ImagePath"="\SystemRoot\system32\drivers\processr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProfSvc]
"ServiceDll"="%systemroot%\system32\profsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProtectedStorage]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PSched]
"ImagePath"="system32\DRIVERS\pacer.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ql2300]
"ImagePath"="\SystemRoot\system32\drivers\ql2300.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ql40xx]
"ImagePath"="\SystemRoot\system32\drivers\ql40xx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\QWAVE]
"ServiceDll"="%windir%\system32\qwave.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\QWAVEdrv]
"ImagePath"="\SystemRoot\system32\drivers\qwavedrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasAcd]
"ImagePath"="System32\DRIVERS\rasacd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasAuto]
"ServiceDll"="%SystemRoot%\System32\rasauto.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Rasl2tp]
"ImagePath"="system32\DRIVERS\rasl2tp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasMan]
"ServiceDll"="%SystemRoot%\System32\rasmans.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasPppoe]
"ImagePath"="system32\DRIVERS\raspppoe.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasSstp]
"ImagePath"="system32\DRIVERS\rassstp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdbss]
"ImagePath"="system32\DRIVERS\rdbss.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPCDD]
"ImagePath"="System32\DRIVERS\RDPCDD.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPDD]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdpdr]
"ImagePath"="system32\DRIVERS\rdpdr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPENCDD]
"ImagePath"="system32\drivers\rdpencdd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPNP]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDPWD]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess]
"ServiceDLL"="%SystemRoot%\System32\mprdim.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteRegistry]
"ServiceDll"="%SystemRoot%\system32\regsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcLocator]
"ImagePath"="%SystemRoot%\system32\locator.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcSs]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rspndr]
"ImagePath"="system32\DRIVERS\rspndr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SamSs]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sbp2port]
"ImagePath"="\SystemRoot\system32\drivers\sbp2port.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SCardSvr]
"ServiceDll"="%SystemRoot%\System32\SCardSvr.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Schedule]
"ServiceDll"="%systemroot%\system32\schedsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SCPolicySvc]
"ServiceDll"="%SystemRoot%\System32\certprop.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SDRSVC]
"ServiceDll"="%Systemroot%\System32\SDRSVC.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\secdrv]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\seclogon]
"ServiceDll"="%windir%\system32\seclogon.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SENS]
"ServiceDll"="%SystemRoot%\system32\sens.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Serenum]
"ImagePath"="system32\DRIVERS\serenum.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Serial]
"ImagePath"="system32\DRIVERS\serial.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sermouse]
"ImagePath"="\SystemRoot\system32\drivers\sermouse.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelEndpoint 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelOperation 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceModelService 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SessionEnv]
"ServiceDLL"="%SystemRoot%\system32\sessenv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffdisk]
"ImagePath"="\SystemRoot\system32\drivers\sffdisk.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffp_mmc]
"ImagePath"="\SystemRoot\system32\drivers\sffp_mmc.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sffp_sd]
"ImagePath"="\SystemRoot\system32\drivers\sffp_sd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sfloppy]
"ImagePath"="\SystemRoot\system32\drivers\sfloppy.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess]
"ServiceDll"="%SystemRoot%\System32\ipnathlp.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ShellHWDetection]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SiSRaid2]
"ImagePath"="\SystemRoot\system32\drivers\sisraid2.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SiSRaid4]
"ImagePath"="\SystemRoot\system32\drivers\sisraid4.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\slsvc]
"ImagePath"="%SystemRoot%\system32\SLsvc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SLUINotify]
"ServiceDll"="%SystemRoot%\system32\SLUINotify.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Smb]
"ImagePath"="system32\DRIVERS\smb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SMSvcHost 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SMSvcHost 4.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SNMPTRAP]
"ImagePath"="%SystemRoot%\System32\snmptrap.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\spldr]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Spooler]
"ImagePath"="%SystemRoot%\System32\spoolsv.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srv]
"ImagePath"="System32\DRIVERS\srv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srv2]
"ImagePath"="System32\DRIVERS\srv2.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srvnet]
"ImagePath"="System32\DRIVERS\srvnet.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSDPSRV]
"ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SstpSvc]
"ServiceDll"="%SystemRoot%\system32\sstpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\stisvc]
"ServiceDll"="%SystemRoot%\System32\wiaservc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\swenum]
"ImagePath"="system32\DRIVERS\swenum.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\swprv]
"ServiceDll"="%Systemroot%\System32\swprv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Symc8xx]
"ImagePath"="\SystemRoot\system32\drivers\symc8xx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sym_hi]
"ImagePath"="\SystemRoot\system32\drivers\sym_hi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sym_u3]
"ImagePath"="\SystemRoot\system32\drivers\sym_u3.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysMain]
"ServiceDll"="%systemroot%\system32\sysmain.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TabletInputService]
"ServiceDll"="%SystemRoot%\System32\TabSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv]
"ServiceDll"="%SystemRoot%\System32\tapisrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TBS]
"ServiceDll"="%SystemRoot%\System32\tbssvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip]
"ImagePath"="System32\drivers\tcpip.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6]
"ImagePath"="system32\DRIVERS\tcpip.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tcpipreg]
"ImagePath"="System32\drivers\tcpipreg.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDPIPE]
"ImagePath"="system32\drivers\tdpipe.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDTCP]
"ImagePath"="system32\drivers\tdtcp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tdx]
"ImagePath"="system32\DRIVERS\tdx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TermDD]
"ImagePath"="system32\DRIVERS\termdd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TermService]
"ServiceDll"="%SystemRoot%\System32\termsrv.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Themes]
"ServiceDll"="%SystemRoot%\system32\shsvcs.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\THREADORDER]
"ServiceDll"="%SystemRoot%\system32\mmcss.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks]
"ServiceDll"="%SystemRoot%\System32\trkwks.dll"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrustedInstaller]
"ImagePath"="%SystemRoot%\servicing\TrustedInstaller.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TSDDD]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tssecsrv]
"ImagePath"="System32\DRIVERS\tssecsrv.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tunmp]
"ImagePath"="system32\DRIVERS\tunmp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tunnel]
"ImagePath"="system32\DRIVERS\tunnel.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uagp35]
"ImagePath"="\SystemRoot\system32\drivers\uagp35.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\udfs]
"ImagePath"="system32\DRIVERS\udfs.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UGatherer]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UGTHRSVC]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UI0Detect]
"ImagePath"="%SystemRoot%\system32\UI0Detect.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uliagpkx]
"ImagePath"="\SystemRoot\system32\drivers\uliagpkx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uliahci]
"ImagePath"="\SystemRoot\system32\drivers\uliahci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UlSata]
"ImagePath"="\SystemRoot\system32\drivers\ulsata.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ulsata2]
"ImagePath"="\SystemRoot\system32\drivers\ulsata2.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\umbus]
"ImagePath"="system32\DRIVERS\umbus.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UmRdpService]
"ServiceDll"="%SystemRoot%\System32\umrdp.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\upnphost]
"ServiceDll"="%SystemRoot%\System32\upnphost.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usb]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbbus]
"ImagePath"="system32\DRIVERS\lgx64bus.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbccgp]
"ImagePath"="system32\DRIVERS\usbccgp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbcir]
"ImagePath"="\SystemRoot\system32\drivers\usbcir.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UsbDiag]
"ImagePath"="system32\DRIVERS\lgx64diag.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbehci]
"ImagePath"="system32\DRIVERS\usbehci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UsbGps]
"ImagePath"="system32\DRIVERS\lgx64gps.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbhub]
"ImagePath"="system32\DRIVERS\usbhub.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\USBModem]
"ImagePath"="system32\DRIVERS\lgx64modem.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbohci]
"ImagePath"="\SystemRoot\system32\drivers\usbohci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbprint]
"ImagePath"="system32\DRIVERS\usbprint.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbscan]
"ImagePath"="system32\DRIVERS\usbscan.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\USBSTOR]
"ImagePath"="system32\DRIVERS\USBSTOR.SYS"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usbuhci]
"ImagePath"="system32\DRIVERS\usbuhci.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UxSms]
"ServiceDll"="%SystemRoot%\System32\uxsms.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vds]
"ImagePath"="%SystemRoot%\System32\vds.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vga]
"ImagePath"="system32\DRIVERS\vgapnp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VgaSave]
"ImagePath"="\SystemRoot\System32\drivers\vga.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\viaide]
"ImagePath"="\SystemRoot\system32\drivers\viaide.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volmgr]
"ImagePath"="system32\drivers\volmgr.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volmgrx]
"ImagePath"="System32\drivers\volmgrx.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\volsnap]
"ImagePath"="system32\drivers\volsnap.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vsmraid]
"ImagePath"="\SystemRoot\system32\drivers\vsmraid.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS]
"ImagePath"="%systemroot%\system32\vssvc.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W32Time]
"ServiceDll"="%systemroot%\system32\w32time.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W3SVC]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WacomPen]
"ImagePath"="\SystemRoot\system32\drivers\wacompen.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wanarp]
"ImagePath"="system32\DRIVERS\wanarp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wanarpv6]
"ImagePath"="system32\DRIVERS\wanarp.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wbengine]
"ImagePath"="\"%systemroot%\system32\wbengine.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wcncsvc]
"ServiceDll"="%SystemRoot%\System32\wcncsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WcsPlugInService]
"ServiceDll"="%SystemRoot%\System32\WcsPlugInService.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wd]
"ImagePath"="\SystemRoot\system32\drivers\wd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wdf01000]
"ImagePath"="system32\drivers\Wdf01000.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WdiServiceHost]
"ServiceDll"="%SystemRoot%\system32\wdi.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WdiSystemHost]
"ServiceDll"="%SystemRoot%\system32\wdi.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebClient]
"ServiceDll"="%SystemRoot%\System32\webclnt.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wecsvc]
"ServiceDll"="%SystemRoot%\system32\wecsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wercplsupport]
"ServiceDll"="%SystemRoot%\System32\wercplsupport.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WerSvc]
"ServiceDll"="%SystemRoot%\System32\WerSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinDefend]
"ServiceDll"="%ProgramFiles%\Windows Defender\mpsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Windows Workflow Foundation 3.0.0.0]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinHttpAutoProxySvc]
"ServiceDll"="winhttp.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winmgmt]
"ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinRM]
"ServiceDll"="%SystemRoot%\system32\WsmSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wlansvc]
"ServiceDll"="%SystemRoot%\System32\wlansvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiAcpi]
"ImagePath"="\SystemRoot\system32\drivers\wmiacpi.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiApRpl]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wmiApSrv]
"ImagePath"="%systemroot%\system32\wbem\WmiApSrv.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WMPNetworkSvc]
"ImagePath"="\"%ProgramFiles%\Windows Media Player\wmpnetwk.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WPDBusEnum]
"ServiceDll"="%SystemRoot%\system32\wpdbusenum.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WpdUsb]
"ImagePath"="system32\DRIVERS\wpdusb.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WPFFontCache_v0400]
"ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ws2ifsl]
"ImagePath"="\SystemRoot\system32\drivers\ws2ifsl.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WSearch]
"ImagePath"="%systemroot%\system32\SearchIndexer.exe /Embedding"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WSearchIdxPi]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv]
"ServiceDll"="%systemroot%\system32\wuaueng.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WudfPf]
"ImagePath"="system32\drivers\WudfPf.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WUDFRd]
"ImagePath"="system32\DRIVERS\WUDFRd.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wudfsvc]
"ServiceDll"="%SystemRoot%\System32\WUDFSvc.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\YahooAUService]
"ImagePath"="\"c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yksvc]
"ServiceDll"="%SystemRoot%\System32\ykx64mpcoinst.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yukonx64]
"ImagePath"="system32\DRIVERS\yk60x64.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{07171AC2-0D2A-427d-BCE5-B6C2D6C7058B}]
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{8E7FF6BA-8E5A-46B1-B8A4-EE49F9A0BFAE}]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-12-01 11:36:53
ComboFix-quarantined-files.txt 2013-12-01 18:36
.
Pre-Run: 89,275,867,136 bytes free
Post-Run: 90,324,500,480 bytes free
.
- - End Of File - - CA6DB3391309F7C4696CF27EA8632809
5C616939100B85E558DA92B899A0FC36

descriptionAsk, keeps overpowering google on one site only cant stop it! - Page 2 EmptyRe: Ask, keeps overpowering google on one site only cant stop it!

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum