Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Internet Explorer hijacking? 'proxy server isn't responding' issue


  • This topic is locked This topic is locked
13 replies to this topic

#1 sepa14

sepa14

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:04:23 AM

Posted 30 September 2014 - 05:38 PM

This Windows 7 PC recently had an infection. I've run Malwarebytes and a few other things, and the infection seems to be gone. However, an issue remains:

 

When attempting to browse with Internet Explorer, any URL I request (www.google.com, www.yahoo.com) gives an error page that says, "The proxy server isn't responding." The given proxy address is pointing at localhost. I am able to browse in Firefox, but I need Internet Explorer to work as well.

 

I cannot disable the "Use proxy server for your LAN" setting under Internet Options -> Connections -> LAN settings.

 

I do not have the knowledge to resolve this problem. Please help. Thank you.

 

DDS LOG=====================================

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17280  BrowserJavaVersion: 10.65.2
Run by Bonnie at 17:26:23 on 2014-09-30
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.2013.852 [GMT -5:00]
.
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (x86)\iWin Games\iWinTrusted.exe
C:\Program Files\Acer\Acer Updater\UpdaterService.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Pogo Games\PGMTrusted.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
C:\Windows\system32\taskeng.exe
c:\program files (x86)\teamviewer\version9\TeamViewer_Desktop.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://yahoo.com/
uSearch Bar = Preserve
uSearch Page = hxxps://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
mStart Page = hxxps://www.yahoo.com?fr=hp-avast&type=iedef
mSearch Bar = hxxps://www.yahoo.com?fr=hp-avast&type=iedef
mSearch Page = hxxps://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
mWinlogon: Userinit = userinit.exe,
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: {11111111-1111-1111-1111-110311551110} - <orphaned>
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: {C6AA1C90-331E-9C00-E122-305F2CF3FEA7} - <orphaned>
BHO: {C8B60FC9-DA76-13C8-285A-C9220CB1516D} - <orphaned>
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: {F0C9EBCD-1519-9ABE-E962-ADC22AE53B5B} - <orphaned>
BHO: {fbdff406-2c4c-5d35-8469-34bb67ea3353} - <orphaned>
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
uRun: [BitTorrent Sync] "C:\Program Files (x86)\BitTorrent Sync\BTSync.exe"  /MINIMIZED
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [ospd_us_137] <no file>
dRunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid}
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\PASTAQ~1.LNK - C:\Program Files (x86)\pastaleads\PastaLeadsWinApp.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
TCP: NameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{70CC2DD5-62F7-4C27-A5A8-CE015DDA83BD} : DHCPNameServer = 75.75.76.76 75.75.75.75
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
x64-BHO: {11111111-1111-1111-1111-110311551110} - <orphaned>
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - LocalServer32 - <no file>
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Bonnie\AppData\Roaming\Mozilla\Firefox\Profiles\io25vpy0.default\
FF - prefs.js: browser.search.defaulturl - hxxps://search.yahoo.com/yhs/search
FF - prefs.js: browser.startup.homepage - startpage.com
FF - prefs.js: keyword.URL - hxxps://search.yahoo.com/yhs/search
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\17\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Bonnie\AppData\Roaming\Mozilla\plugins\np-mswmp.dll
FF - plugin: C:\Windows\npapi.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
FF - ExtSQL: !HIDDEN! 2013-01-03 17:58; smartwebprinting@hp.com; C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2013-3-20 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2013-3-20 224896]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswsnx.sys [2013-3-20 1041168]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswsp.sys [2013-3-20 427360]
R2 aswHwid;avast! HardwareID;C:\Windows\System32\drivers\aswHwid.sys [2014-5-15 29208]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-3-20 79184]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-7-22 50344]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2013-4-22 822504]
R2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2011-5-29 36456]
R2 iWinTrusted;iWinTrusted;C:\Program Files (x86)\iWin Games\iWinTrusted.exe [2013-10-23 179368]
R2 Live Updater Service;Live Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2011-11-10 244624]
R2 PGMTrusted;PGMTrusted;C:\Program Files (x86)\Pogo Games\PGMTrusted.exe [2012-10-29 519920]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-9-30 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-9-30 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-9-30 171928]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2013-6-26 523944]
R2 TeamViewer9;TeamViewer 9;C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-5-5 4799760]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-11-10 291328]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2013-6-26 767144]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2013-6-26 273576]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2013-6-26 28840]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2013-6-26 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2013-6-26 207528]
S2 aswStm;aswStm;C:\Windows\System32\drivers\aswstm.sys [2014-1-16 92008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S3 GamesAppIntegrationService;GamesAppIntegrationService;C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2013-9-5 255040]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 203344]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-9-13 111616]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-2-13 19456]
S3 taphss6;Anchorfree HSS VPN Adapter;C:\Windows\System32\drivers\taphss6.sys [2013-6-20 42184]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-2-13 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-2-13 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-1-4 1255736]
S4 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-5-4 503080]
S4 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2014-09-30 21:47:35    --------    d-----w-    C:\AdwCleaner
2014-09-30 21:44:57    75888    ----a-w-    C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2DABC634-1D50-4470-829F-0F0E94A118E2}\offreg.dll
2014-09-30 21:17:12    21040    ----a-w-    C:\Windows\System32\sdnclean64.exe
2014-09-30 21:17:11    --------    d-----w-    C:\ProgramData\Spybot - Search & Destroy
2014-09-30 21:17:04    --------    d-----w-    C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-09-30 16:42:02    --------    d-----w-    C:\Program Files\CCleaner
2014-09-30 16:28:35    122584    ----a-w-    C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-09-30 16:28:23    91352    ----a-w-    C:\Windows\System32\drivers\mbamchameleon.sys
2014-09-30 16:28:23    63704    ----a-w-    C:\Windows\System32\drivers\mwac.sys
2014-09-30 16:28:23    25816    ----a-w-    C:\Windows\System32\drivers\mbam.sys
2014-09-30 16:28:23    --------    d-----w-    C:\ProgramData\Malwarebytes
2014-09-30 16:28:23    --------    d-----w-    C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-30 16:00:21    --------    d-----w-    C:\Users\Bonnie\AppData\Local\ElevatedDiagnostics
2014-09-30 15:32:35    --------    d-----w-    C:\Program Files (x86)\Spyware Clear
2014-09-30 15:26:53    1935872    ----a-w-    C:\Windows\SysWow64\8962268
2014-09-30 11:09:35    11578928    ----a-w-    C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2DABC634-1D50-4470-829F-0F0E94A118E2}\mpengine.dll
2014-09-26 10:48:59    --------    d-----w-    C:\Program Files (x86)\Danse Macabre - Moulin Rouge Collectors Edition
2014-09-24 11:17:49    2048    ----a-w-    C:\Windows\SysWow64\tzres.dll
2014-09-24 11:17:49    2048    ----a-w-    C:\Windows\System32\tzres.dll
2014-09-22 17:17:49    --------    d-----w-    C:\Program Files (x86)\4 Elements II
2014-09-22 12:03:58    --------    d-----w-    C:\ProgramData\PicColorData
2014-09-22 12:02:23    358616    ----a-w-    C:\Windows\System32\ColorMedia64.dll
2014-09-21 13:57:18    --------    d-----w-    C:\Users\Bonnie\AppData\Roaming\blg
2014-09-21 13:57:18    --------    d-----w-    C:\ProgramData\blg
2014-09-21 12:08:54    --------    d-----w-    C:\Program Files (x86)\Forgotten Kingdoms - Dream of Ruin Collectors Edition
2014-09-20 20:43:14    --------    d-----w-    C:\Program Files (x86)\Mystika 2 - The Sanctuary
2014-09-19 12:35:55    --------    d-----w-    C:\Program Files (x86)\Grim Facade - The Artist and The Pretender Collectors Edition
2014-09-18 19:23:40    --------    d-----w-    C:\ProgramData\Veronica&BoD
2014-09-18 19:03:48    --------    d-----w-    C:\Users\Bonnie\AppData\Roaming\Jewel Keepers Easter Island
2014-09-18 17:55:32    --------    d-----w-    C:\Users\Bonnie\AppData\Roaming\TFS2
2014-09-18 17:48:10    --------    d-----w-    C:\Users\Bonnie\AppData\Roaming\Saved Games
2014-09-18 12:14:27    --------    d-----w-    C:\Program Files (x86)\Witches Legacy - The Ties That Bind Collectors Edition
2014-09-18 11:11:44    --------    d-----w-    C:\Program Files (x86)\9 Clues - The Ward
2014-09-17 13:52:02    --------    d-----w-    C:\ProgramData\rokapublish
2014-09-17 11:07:26    --------    d-----w-    C:\Program Files (x86)\Into the Haze
2014-09-16 16:30:58    --------    d-----w-    C:\Users\Bonnie\AppData\Roaming\Frozen Kingdom
2014-09-16 13:44:42    --------    d-----w-    C:\Users\Bonnie\AppData\Roaming\GreenSauceGames
2014-09-16 12:11:24    --------    d-----w-    C:\Program Files (x86)\Melissa K and the Heart of Gold
2014-09-14 11:54:03    --------    d-----w-    C:\Users\Bonnie\AppData\Roaming\Friendly Cactus
2014-09-14 11:51:07    --------    d-----w-    C:\Program Files (x86)\Shrouded Tales - The Spellbound Land Collectors Edition
2014-09-12 11:38:26    --------    d-----w-    C:\3088a2bde847e7b8c9
2014-09-12 11:35:46    2777088    ----a-w-    C:\Windows\System32\msmpeg2vdec.dll
2014-09-12 11:35:46    2285056    ----a-w-    C:\Windows\SysWow64\msmpeg2vdec.dll
2014-09-11 11:14:13    --------    d-----w-    C:\Users\Bonnie\AppData\Roaming\BoonTrollGames
2014-09-11 09:07:41    793600    ----a-w-    C:\Windows\SysWow64\TSWorkspace.dll
2014-09-11 09:07:41    1031168    ----a-w-    C:\Windows\System32\TSWorkspace.dll
2014-09-11 09:07:19    2565120    ----a-w-    C:\Windows\System32\d3d10warp.dll
2014-09-11 09:07:19    1987584    ----a-w-    C:\Windows\SysWow64\d3d10warp.dll
2014-09-11 09:07:01    728064    ----a-w-    C:\Windows\System32\kerberos.dll
2014-09-11 09:07:00    550912    ----a-w-    C:\Windows\SysWow64\kerberos.dll
2014-09-11 09:07:00    1460736    ----a-w-    C:\Windows\System32\lsasrv.dll
2014-09-11 09:06:59    96768    ----a-w-    C:\Windows\SysWow64\sspicli.dll
2014-09-11 09:06:59    22016    ----a-w-    C:\Windows\SysWow64\secur32.dll
2014-09-11 09:06:39    578048    ----a-w-    C:\Windows\System32\aepdu.dll
2014-09-11 09:06:36    424448    ----a-w-    C:\Windows\System32\aeinv.dll
2014-09-03 11:51:46    --------    d-----w-    C:\Users\Bonnie\AppData\Roaming\Urchin
2014-09-02 10:43:58    --------    d-----w-    C:\Program Files (x86)\Elixir of Immortality
.
==================== Find3M  ====================
.
2014-09-24 14:14:27    71344    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-24 14:14:27    701104    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2014-09-15 14:06:02    278152    ------w-    C:\Windows\System32\MpSigStub.exe
2014-08-23 02:07:00    404480    ----a-w-    C:\Windows\System32\gdi32.dll
2014-08-23 01:45:55    311808    ----a-w-    C:\Windows\SysWow64\gdi32.dll
2014-08-23 00:59:01    3163648    ----a-w-    C:\Windows\System32\win32k.sys
2014-08-18 22:29:49    2724864    ----a-w-    C:\Windows\System32\mshtml.tlb
2014-08-18 22:29:35    4096    ----a-w-    C:\Windows\System32\ieetwcollectorres.dll
2014-08-18 22:19:53    5833728    ----a-w-    C:\Windows\System32\jscript9.dll
2014-08-18 22:15:34    547328    ----a-w-    C:\Windows\System32\vbscript.dll
2014-08-18 22:15:09    66048    ----a-w-    C:\Windows\System32\iesetup.dll
2014-08-18 22:14:38    48640    ----a-w-    C:\Windows\System32\ieetwproxystub.dll
2014-08-18 22:14:10    83968    ----a-w-    C:\Windows\System32\MshtmlDac.dll
2014-08-18 22:08:55    4232704    ----a-w-    C:\Windows\SysWow64\jscript9.dll
2014-08-18 22:03:47    139264    ----a-w-    C:\Windows\System32\ieUnatt.exe
2014-08-18 22:03:37    111616    ----a-w-    C:\Windows\System32\ieetwcollector.exe
2014-08-18 22:03:01    758272    ----a-w-    C:\Windows\System32\jscript9diag.dll
2014-08-18 21:57:44    2724864    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2014-08-18 21:56:17    940032    ----a-w-    C:\Windows\System32\MsSpellCheckingFacility.exe
2014-08-18 21:46:26    454656    ----a-w-    C:\Windows\SysWow64\vbscript.dll
2014-08-18 21:45:23    61952    ----a-w-    C:\Windows\SysWow64\iesetup.dll
2014-08-18 21:45:12    72704    ----a-w-    C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-08-18 21:44:44    51200    ----a-w-    C:\Windows\SysWow64\ieetwproxystub.dll
2014-08-18 21:44:09    61952    ----a-w-    C:\Windows\SysWow64\MshtmlDac.dll
2014-08-18 21:36:07    112128    ----a-w-    C:\Windows\SysWow64\ieUnatt.exe
2014-08-18 21:35:24    597504    ----a-w-    C:\Windows\SysWow64\jscript9diag.dll
2014-08-18 21:23:17    2104832    ----a-w-    C:\Windows\System32\inetcpl.cpl
2014-08-18 21:23:16    1249280    ----a-w-    C:\Windows\System32\mshtmlmedia.dll
2014-08-18 21:22:48    60416    ----a-w-    C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-08-18 21:15:13    2310656    ----a-w-    C:\Windows\System32\wininet.dll
2014-08-18 21:08:54    2014208    ----a-w-    C:\Windows\SysWow64\inetcpl.cpl
2014-08-18 21:07:44    1068032    ----a-w-    C:\Windows\SysWow64\mshtmlmedia.dll
2014-08-18 20:46:48    1812992    ----a-w-    C:\Windows\SysWow64\wininet.dll
2014-07-25 07:35:46    875688    ----a-w-    C:\Windows\SysWow64\msvcr120_clr0400.dll
2014-07-25 04:47:06    869544    ----a-w-    C:\Windows\System32\msvcr120_clr0400.dll
2014-07-22 09:40:05    92008    ----a-w-    C:\Windows\System32\drivers\aswstm.sys
2014-07-22 09:40:04    65776    ----a-w-    C:\Windows\System32\drivers\aswRvrt.sys
2014-07-22 09:40:04    224896    ----a-w-    C:\Windows\System32\drivers\aswVmm.sys
2014-07-22 09:40:04    1041168    ----a-w-    C:\Windows\System32\drivers\aswsnx.sys
2014-07-22 09:40:03    93568    ----a-w-    C:\Windows\System32\drivers\aswRdr2.sys
2014-07-22 09:40:03    79184    ----a-w-    C:\Windows\System32\drivers\aswMonFlt.sys
2014-07-22 09:40:03    29208    ----a-w-    C:\Windows\System32\drivers\aswHwid.sys
2014-07-22 09:40:01    43152    ----a-w-    C:\Windows\avastSS.scr
2014-07-14 02:02:45    1216000    ----a-w-    C:\Windows\System32\rpcrt4.dll
2014-07-14 01:40:58    664064    ----a-w-    C:\Windows\SysWow64\rpcrt4.dll
2014-07-11 08:02:05    98216    ----a-w-    C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-07-09 02:03:23    7168    ----a-w-    C:\Windows\System32\KBDYAK.DLL
2014-07-09 02:03:22    7168    ----a-w-    C:\Windows\System32\KBDBASH.DLL
2014-07-09 01:31:42    7168    ----a-w-    C:\Windows\SysWow64\KBDYAK.DLL
2014-07-09 01:31:41    6656    ----a-w-    C:\Windows\SysWow64\KBDBASH.DLL
.
============= FINISH: 17:27:13.78 ===============
 

Attached Files



BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 39,955 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:23 AM

Posted 05 October 2014 - 01:15 PM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Download Malwarebytes' Anti-Malware from Here

Double-click mbam-setup-2.X.X.XXXX.exe to install the application (X's are the current version number).
  • Make sure a checkmark is placed next to Launch Malwarebytes' Anti-Malware, then click Finish.
  • Once MBAM opens, when it says Your databases are out of date, click the Fix Now button.
  • Click the Settings tab at the top, and then in the left column, select Detections and Protections, and if not already checked place a checkmark in the selection box for Scan for rootkits.
  • Click the Scan tab at the top of the program window, select Threat Scan and click the Scan Now button.
  • If you receive a message that updates are available, click the Update Now button (the update will be downloaded, installed, and the scan will start).
  • The scan may take some time to finish,so please be patient.
  • If potential threats are detected, ensure that Quarantine is selected as the Action for all the listed items, and click the Apply Actions button.
  • While still on the Scan tab, click the link for View detailed log, and in the window that opens click the Export button, select Text file (*.txt), and save the log to your Desktop.
  • The log is automatically saved by MBAM and can also be viewed by clicking the History tab and then selecting Application Logs.
POST THE LOG FOR MY REVIEW.

Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.

===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
===

Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
===

Please paste the logs in your next reply DO NOT ATTACH THEM unless specified.
To attach a file select the "More Reply Option" and follow the instructions.

How is the computer running?
Wait for further instructions.

#3 sepa14

sepa14
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:04:23 AM

Posted 05 October 2014 - 09:38 PM

Changes may have been made to the computer since I posted my original topic. If you would like me to re-run DDS I can do so.

My mother described a "Java update" that left Internet Explorer with the issue described above. From her description, I don't know whether this "update" was legitimate or possibly a malware ad. I don't use this PC myself, so I can't provide further details.

She installs and plays games from websites such as iWin, which I've heard rumor may contain malware. I'm not entirely sure how these are getting onto her computer, but this isn't the first time we've had issues.

After running a virus scan and CCleaner, the PC seems to run well, except for this issue. Speed is good, no unusal popups.


Steps I took:

- Followed instructions regarding Malwarebytes
- Malewarebytes asked me to restart before I could export the scan log to my desktop. Chose to restart.
- After restart, went to History tab, selected Scan Log from today's date, and exported to desktop. (Log is posted below.)

- Followed instructions regarding AdwCleaner
- Deselected items related to iWin and Alawar, as these seem to be necessary for my mother's games. (If you think these are related to the issue, I will delete them.)
- AdwCleaner requested reboot after Cleaning. Chose to reboot.

- Follow instructions regarding FarBar

====================Logs=======================

===================MBAM======================

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 10/5/2014
Scan Time: 8:33:28 PM
Logfile: MBAMlog.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.10.05.08
Rootkit Database: v2014.09.19.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Bonnie

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 320653
Time Elapsed: 16 min, 13 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 12
PUP.Optional.Adpeak.A, HKLM\SOFTWARE\allday savings, Quarantined, [03821ed12d4edb5b503401199b684bb5],
PUP.Optional.OneSoftPerDay.A, HKLM\SOFTWARE\WOW6432NODE\ONESOFTPERDAY, Quarantined, [701546a94b308da9937c67a91ce7b34d],
PUP.Optional.WhiteSmoke.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WhiteSmoke_US Toolbar, Quarantined, [7c096a85d0abdc5a8c5922f3d13208f8],
PUP.Optional.Adpeak, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{19DC5AB8-0792-4875-8F1B-896C5A9CE6AE}, Quarantined, [681d16d97cffa98d3d36550fae56a45c],
PUP.Optional.iWebar.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\iWebar, Quarantined, [a6df8669e4977cba340660dfa0634eb2],
PUP.Optional.Adpeak, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Scorpion Saver, Quarantined, [3352faf562193df91156b4907d86f709],
PUP.Optional.LevelQualityWatcher.A, HKU\S-1-5-21-1266221820-170093003-908648241-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Level Quality Watcher, Quarantined, [394c7877f6856acc1d283ef8e91aff01],
PUP.Optional.TidyNetwork.A, HKU\S-1-5-21-1266221820-170093003-908648241-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\TidyNetwork, Quarantined, [82034fa0aecdae883ae62f0df0137888],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110311551110}, Quarantined, [fa8bef00b4c7cc6a2daea67348bdd828],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110311551110}, Quarantined, [fa8bef00b4c7cc6a2daea67348bdd828],

Registry Values: 2
PUP.Optional.OneSoftPerDay.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|ospd_us_137, Quarantined, [30554ba46a11af870b06739d7c877987],
PUP.Optional.Adpeak, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{19DC5AB8-0792-4875-8F1B-896C5A9CE6AE}|DisplayName, Level Quality Watcher, Quarantined, [681d16d97cffa98d3d36550fae56a45c]

Registry Data: 0
(No malicious items detected)

Folders: 16
PUP.Optional.PicColor.A, C:\ProgramData\PicColorData, Quarantined, [c4c147a8f98231055603215ea85ca858],
PUP.Optional.ScorpionSaver, C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\oclgomenfkljhfkfflghppidonpkljjg, Quarantined, [bcc917d8710a39fd753b0fd422e035cb],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Common, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.GlobalUpdate.A, C:\Users\Bonnie\AppData\Local\Temp\comh.378124, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\firefox, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\firefox\chrome, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\opal, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.AdPeak.A, C:\Program Files\B021CBBD-E38E-4F8C-8E93-6624B0597A23, Quarantined, [d4b146a964179f9732eece37966d639d],
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo, Quarantined, [3550faf5403b191d5cf77392c83be11f],

Files: 540
PUP.Optional.IdleCrawler.A, C:\Users\Bonnie\AppData\Local\Temp\8945541361, Quarantined, [a5e0e8074c2fae88b0765ee781847d83],
PUP.Optional.InstallIQ, C:\Users\Bonnie\Downloads\7zip_installer_d162802.exe, Quarantined, [5b2aa04f3f3c5fd75dca86a720e1f907],
PUP.Optional.Iwin, C:\Users\Bonnie\Downloads\lost-souls-timeless-fables-setup.exe, Quarantined, [d0b5608f9cdff83e3cf737f9996742be],
PUP.Optional.ScramblePacker.A, C:\Users\Bonnie\AppData\Local\Installer\Install_4566\cr.exe, Quarantined, [e99c559a1566a492ae18315dff025da3],
PUP.Optional.PastaQuotes.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PastaQuotes.lnk, Quarantined, [5b2a935ce7941d195e09f11e80838878],
PUP.Optional.MyStartTB.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\mystarttb.xml, Quarantined, [671ea14e463547ef82bf30146e95de22],
PUP.Optional.PicColor.A, C:\ProgramData\PicColorData\PicColorService.log, Quarantined, [c4c147a8f98231055603215ea85ca858],
PUP.Optional.PicColor.A, C:\ProgramData\PicColorData\Config.bin, Quarantined, [c4c147a8f98231055603215ea85ca858],
PUP.Optional.PicColor.A, C:\ProgramData\PicColorData\Config.bin.bus, Quarantined, [c4c147a8f98231055603215ea85ca858],
PUP.Optional.PicColor.A, C:\ProgramData\PicColorData\PicColorServiceSetup.log, Quarantined, [c4c147a8f98231055603215ea85ca858],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMedia.ini, Quarantined, [1e670ce3a1dacc6aa824a5dada2afe02],
PUP.Optional.ColorMedia.A, C:\Windows\System32\ColorMediaOff.ini, Quarantined, [1e67f5fa314a23136568a6d950b4ab55],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMediaOff.ini, Quarantined, [760fcd22a0db7cba3499f28d897b619f],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\log.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\MinecraftShims64.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\npTNT2.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\npTNT2Ghost.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\PARTNER.TNT, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\passport.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\passport64.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\pinnedSearch.htm, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\pinnedSearch_FindWide.htm, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\progress.1.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\regsvr.1.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\RemoteSkin.wms, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\sqlite.1.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\tnt2chrome.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\TNT2User.exe, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\TNT2UserPS.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\TNT2UserPS64.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\TntMagicDel.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\UnInjLib.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\UnInjLib64.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\UNINSTALL.TNT, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\UninstallDlg.1.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\untar.1.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\UPDATE.TNT, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\xpi.tar, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\2.0.0.1635\zipunzip.1.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Common\GameConsole.exe, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Common\pinnedSearch.htm, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\icon.ico, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\inst.ini, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\LastSession.log, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\os10705.xml, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\PARTNER.9.TNT, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\partner.dat, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\passport.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\passport64.dll, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\runt.ini, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\tnt_32x32.png, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\toolbar10705@findwide.com.xpi, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.TidyNetwork.A, C:\Users\Bonnie\AppData\Local\TNT2\Profiles\10705\yah10705.xml, Quarantined, [afd6707f1863fe38cc59af35f111a35d],
PUP.Optional.GlobalUpdate.A, C:\Users\Bonnie\AppData\Local\Temp\comh.378124\GoogleCrashHandler.exe, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.GlobalUpdate.A, C:\Users\Bonnie\AppData\Local\Temp\comh.378124\GoogleUpdate.exe, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.GlobalUpdate.A, C:\Users\Bonnie\AppData\Local\Temp\comh.378124\GoogleUpdateBroker.exe, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.GlobalUpdate.A, C:\Users\Bonnie\AppData\Local\Temp\comh.378124\GoogleUpdateHelper.msi, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.GlobalUpdate.A, C:\Users\Bonnie\AppData\Local\Temp\comh.378124\GoogleUpdateOnDemand.exe, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.GlobalUpdate.A, C:\Users\Bonnie\AppData\Local\Temp\comh.378124\goopdate.dll, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.GlobalUpdate.A, C:\Users\Bonnie\AppData\Local\Temp\comh.378124\goopdateres_en.dll, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.GlobalUpdate.A, C:\Users\Bonnie\AppData\Local\Temp\comh.378124\npGoogleUpdate4.dll, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.GlobalUpdate.A, C:\Users\Bonnie\AppData\Local\Temp\comh.378124\psmachine.dll, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.GlobalUpdate.A, C:\Users\Bonnie\AppData\Local\Temp\comh.378124\psuser.dll, Quarantined, [592c0ee195e69c9a241b33c903ff34cc],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\ftstart.dat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898704817075668705_Jewel Match Double Pack.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900853102845898750_EchoesOfThePast_TheRevengeOfTheWitch_SE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900921739894152703_The Curse of the Werewolves CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6901005896836057585_AlexanderTheGreat.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6901051787780479472_FierceTalesTheDogsHeartCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6901148133673164026_angels.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6901165329565560234_Newshawk.exe.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6901306850236601306_DarkDimensions_WaxBeauty.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6901319385649037788_TwistedLands3.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7262116250582187749_TheDramaQueenMurderPC.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7262353264883172328_Big Kahuna Reef 3.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7262517228904047852_SolitaireMystery.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_5496754829849370113_cruiseDirectorLauncher.exe.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6576940448177238785_Middleport.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6576952943881570573_ASJotLS_Platinum_PC_EN.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6576968821191508743_Jewels Of The Gods.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6576974883359278600_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6576991722703010563_ChroniclesOfWAW.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577021723037284126_LesMiserables2.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577030959517585933_Panopticon_PathofReflections.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577045472079860225_ASJotLS_Standard_PC_EN.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900484824803933183_TowerofElements.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900491782416516852_SableMaze_SullivanRiver_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900526886986330615_MysteryTrackers_TheFourAcesCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900552607785428732_DarkMysteries_TheSoulKeeperCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900558602886418166_btw_launcher.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900603750840357876_FairyTaleMysteries_ThePuppetThief_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900642525171044607_WitchAmulet.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900677648823602157_The Beast of Lycan Isle CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900677658438915034_LostSecrets_November1963.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900711084328493808_Abyss_TheWraithsofEden.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900722786593863674_ForbiddenSecrets_AlienTown.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2463030718314954499_PhantomRE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577051532986781953_PortalOfEvil_StolenRunes.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577220896775812104_Voyage to Fantasy - Part I.exe.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577407527101506875_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897844514189403131_BigCityAdventureRio.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898016693474220663_jane_angel_2.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898188769500375949_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898505581267583394_The_Fall_Of_The_New_Age_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900286712937027047_Shadows.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900315902685122016_TalesOfTerror_CrimsonDawn.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900327013940096251_MirrorMysteries2_ForgottenKingdoms.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900377088020918264_UnfinishedTales_IllicitLoveCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900394446507976703_BigCityAdventureParis.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900419811217266686_WS_TheStoryOfTideville.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900433884556368895_MayanProphecies_ShipOfSpiritsCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900439803553114353_WOD_BlackWidow_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900445486540306169_GothicFiction_DarkSaga.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900457845657273080_TheVailOfMystery.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900038368614968061_FairlyTwistedTales_ThePriceOfARose.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900061186208785151_COMA.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900061218419069183_Matchmaker2.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900084137791261415_MysteryoftheAncients_CurseoftheBlackWater.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900167934232155864_SilentScreamII_TheBride.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900174008887363028_HauntedLegends_TheUndertakerCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900174787782553497_MysteriesoftheMind_Coma_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900180490704624338_MountainTrap.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900202612800103882_ZodiacProphecies_TheSerpentBearer.exe.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900219862016354004_WOD_BlackWidow.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900220113740332246_TheSaintAbyssOfDespair.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900253736926877930_DarkLoreMysteries_TheHuntForTruth.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7262958780680366045_MysteryStories_MountainsOfMadness.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7263122031029303789_mysteryvalley.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7263508858856765599_4 Elements.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7263560554955090588_Crimson Thief.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7263617523616851358_SpiritsOfMystery_AmberMaiden.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7263720295478479033_PrincessIsabella_ReturnoftheCurse.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7406644029266473452_WhiteHaven.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7407040091637845449_XIII.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7407495300568927699_GrimFacade_MysteryOfVenice.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7408342448022769850_TheRevenge.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899774919534145989_LesMiserables.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899784017128150453_The_Missing_Island_of_Lost_Ships.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899794927542661025_GrimTales_TheStoneQueenCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899811732289707159_Chimeras_TuneOfRevenge.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899840068512654265_NightmareRealm2_InTheEndCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899842052385297101_SpiritsOfMystery_DarkMinotaur_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899846273241388503_Castle_NeverJudgeABookByItsCover.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899859656283925953_NamarielLegends_IronLord_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899925120498263750_Vampires.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899944704561466604_game.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_1733867407066557442_Mysteryville.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_1734064926339783032_DreamDayWedding.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_1735096481368351628_game.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_1737037443902636032_Dream Day Wedding - Married in Manhattan.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_1737303276864098970_4 Elements.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2460094645614427554_LittleShopWorldTraveler.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2460455330307613515_Samantha Swift and the Mystery from Atlantis.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2460580967327004695_Waverly.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2460737319027785506_BigCityAdventureVan.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2460744857737509690_theClumsys2.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2460895513208781542_Mortimer.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2461016347489254948_Minds Eye.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2461382210665023974_cruiseClues.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2461881265675082907_GoldenTrails.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2461881343745831843_bloodCurse.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2462016318817563119_MysteryPISanFrancisco.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2462161414527922505_Escape from Frankensteins Castle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2462610989521019993_VacationQuest.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_2462951188393127425_Secret Legacy_Kate Brooks.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899573083748596812_Apothecarium - The Renaissance of Evil  CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899579109247447406_Maestro_MusicFromTheVoid.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899625368176852805_Bundler.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899646743123450518_Otherworld_OmensOfSummer_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899653117244792242_DeathPages_GhostLibraryCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899692764274979674_Maestro_MusicFromTheVoid_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899703400538177437_BigCityAdventureTokyo.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899731782046539407_Enchantia_WrathOfThePhoenixQueen_CE.exe.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899731902068267413_CursedFates_TheHeadlessHorsemanCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899732094647218610_The_Torment_of_Whitewall.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899734993948921510_WizardsCurse.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899425650247695051_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899426110385522286_NaturalThreat2.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899463348967957286_SeaLegends_PhantasmalLight_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899468044952159586_TheKeepersTheOrdersLastSecret_ce.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899468111534596952_Familiar_Strangers.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899484000384700409_TimeMysteries_TheFinalEnigma.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899485286053075274_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899489339276684152_FamilyTales_TheSisters.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899489792875073612_PuppetShow_DestinyUndone_CE_RC.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899495517629248628_Timeless_The_Lost_Castle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899495536061451892_HallowedLegends_ShipOfBones.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899522622463229961_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898975964695091838_Tales of Lagoona 2.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899009799112596297_Questerium_SinisterTrinity_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899030137630867357_game.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899086529586318476_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899338267359845119_EmpressOfTheDeep3_LegacyOfThePhoenixCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899346563505379835_PhenomenonMeteorite.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899349828399538945_SmallTownTerrors_PilgrimsHookCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899370677257660465_NightMysteries.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899372490340632362_TreasureMastersInc_TheLostCity.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899372830597010670_LivingLegends_IceRose_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899375368037689550_LegacyTales_MercyoftheGallows_SE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899387849202988369_App.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899404703736681487_ApothecariumSE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_1352294442294737151_FierceTalesTheDogsHeartSE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_1352317281944854527_DarkArcana_TheCarnival.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_1352339836045830143_3Musketeers.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898706774984912419_Love Alchemy.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898706880381691647_MemoriesPC_HD20140404.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898712078118231259_dream_hills.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898713213037468927_TheHauntedHouse.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898730394711298151_Christmas Adventure - Candy Storm.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898747609070104637_Excursions_of_Evil.exe.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898815523577300510_Questerium_SinisterTrinity.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898819599892573771_Greed_Full.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898849537307215903_dance_of_death.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898857176849464078_Dark Angels Masquerade of Shadows.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898894368108130100_TheFarKingdoms.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898533750766392543_ShadowShelter.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898539787742614296_AsBoS_Standard_PC_EN.exe.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898556507320776411_Darkmoor_Manor.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898577656464750982_App.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898593490866585270_ShtrigaSummerCamp.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898612258194520046_AsBoS_Platinum_PC_EN.exe.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898612301592232879_Legacy_WI.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898624125518468075_MexicanaDeadlyHoliday.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898690991512921324_Nearwood_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898700553743598837_Esoterica_HollowEarth.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898700755296635414_Finding Hope.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898219984149398663_Alice2.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898299173097828710_SecretBunkerUSSR.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898310465542649481_Call of Atlantis Treasures of Poseidon.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898332649939953813_Murder, She Wrote 2 - Return to Cabot Cove.exe.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898345021463373498_The_Fall_Of_The_New_Age.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898426084569429269_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898463933115361700_Game.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898470290617032173_Paranormal.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898477164131765487_Hero Returns.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898491752899649792_lair.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898017446075101288_Psych.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898025396104349429_MysteryExpeditionPrisonersOfIce.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898033301676482339_game.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898068243578863333_jane_angel_2.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898098022509585031_parkRanger2.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898102897725396853_CurseOfSilentMarshes.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898103884168963955_Castle_Secrets_Between_Day_And_Night.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898106711010970684_App.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898136020468281205_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898183033334026994_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897868972770966518_Neverville.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897878206205475823_PortalOfEvil_StolenRunesCE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897881312434427092_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897920081481281535_brainbow.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897943440619090417_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897948374677825877_StatueOfLiberty.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897953979331791159_School Bus Fun.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897956507796254673_Amber's Tales The Isle Of Dead Ships Premium Edition.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897988188617458309_Witchcraft.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897993724558245461_FamilyVacation.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577058705408233737_GatsbyWin32.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577065190946218509_Starter.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577092979645417223_ArtifactsOfEternity.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577109909924059936_TimeMachine.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577144443143620097_foodcritic.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577147056336745729_BigCityAdventureLondonClassic.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577164942421547521_App.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577178550594345217_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577184364163196673_InsaneCold.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577189730188608259_DeadlyPuzzles_Toymaker.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577220839096509192_Morgiana.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6898906112676613440_Crystals of Time.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899409773601773070_Azada_Elementa_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899539084285949783_Chimeras_TuneOfRevenge.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899765785367151247_DarkCanvas_BrushWithDeath.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6899982018572751842_The_Great_Unknown_Houdinis_Castle_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900276377114520043_Journey_TheHeartofGaia.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900478789134299391_JewelMatch_WinterWonderland.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6900757825493660671_AlexanderTheGreat.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_7262602416693094143_The Secret of Margrave Manor.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577263380239638043_Warlock.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577286188158036750_ChronicleKeepers_TheDreamingGarden.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577290247930102023_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577295615505218071_Starter.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577308327361569588_Geisha.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577324327586442550_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577340327265386541_HomeMakeover.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577362521655176727_Bundler.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577370734100189715_Vida.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577379937252884552_EvilPumpkin.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577403679144056617_TheCursedIsland_MaskOfBaragus_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577431557927425331_EvilPumpkin.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577463976393085267_SacraHouseCECompilation.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577483922988942406_LostSouls_TimelessFables_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577492724465544821_FamilyVacation2.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577533770579353173_LostLands_DarkOverlord_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577540385813374794_BlackViper.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577561051078625377_EldersOfTime.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577568739544558942_NewYorkMysteries_SecretsOfTheMafia_CE.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577568791766086841_Perfect Murder.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6577578631576977228_LostSouls_TimelessFables.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897841435393907453_Bundle.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\drm_6897842373054156238_HopeLake.ifn.stdat, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{13052209-0444-0229-4731-71510F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{13052331-6728-0194-4851-45275F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{13152333-1983-0604-5831-01438F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{17033866-7740-0706-6552-74427F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{17035089-4648-0136-8352-16285F0FF4IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{17X340X6-X492-0633-9781-3032XF0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24060009-0464-0561-4421-75540F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24060405-0533-0030-7611-35150F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24060703-0731-0902-7781-55060F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24060809-0551-0320-8782-15420F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69201124-3813-0367-3162-40267F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69300147-2478-0778-2552-34976F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69300221-6986-0201-6352-40049F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69300455-9784-0565-7272-30809F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69300555-4860-0288-6412-81668F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69300604-1252-0517-1042-46071F0FF4IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69300640-3375-0084-0352-78760F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69300745-2782-0549-3662-06719F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69300752-6278-0659-3863-36743F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000505-0260-0778-5422-87320F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000701-0108-0432-8492-38080F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000922-2173-0989-4152-27036F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69001050-8589-0683-6052-75851F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69001106-0532-0956-5561-02340F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69001300-0685-0023-6601-13060F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69100855-0310-0284-5892-87504F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69200421-6981-0121-7262-66868F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69200478-0482-0480-3932-31831F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{72062501-0722-0890-4042-78520F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{72062600-0241-0669-3092-41430F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{72063500-0885-0885-6762-55990F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{72063601-0752-0361-6852-13580F0FF4IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65X769X4-X044-0817-7233-8785XF0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65X769X5-X294-0388-1573-0573XF0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65X770X3-X095-0951-7582-5933XF0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65X772X2-X083-0909-6502-9192XF0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65X772X6-X338-0023-9632-8043XF0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65X774X0-X367-0914-4052-6617XF0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65X774X9-X272-0446-5542-4821XF0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65X775X3-X377-0057-9353-3173XF0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24061808-0134-0374-5832-18430F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077108-0436-0416-3192-66730F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65376946-8882-0119-1504-87433F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098100-0289-0772-5393-68530F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098601-0230-0159-2233-28790F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099307-0283-0059-7013-06700F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099629-4276-0427-4974-96743F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X983X4-X502-0146-3373-3498XF0FF4IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X993X7-X067-0725-7663-0465XF0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000006-0118-0620-8781-51510F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000502-0688-0698-6332-06150F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69200637-4765-0843-8912-50344F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000006-0121-0841-9061-91830F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000008-0413-0779-1261-14150F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000107-0400-0888-7361-30280F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000205-0373-0692-6871-79300F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000207-0637-0711-4521-00430F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000208-0671-0293-7021-70470F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000302-0701-0394-0091-62510F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000357-9708-0802-0912-82647F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000403-0388-0455-6361-88950F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000403-0980-0355-3111-43530F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000404-0548-0654-0301-61690F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69000407-0878-0913-4291-93910F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69X000X3-X836-0861-4961-8061XF0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69X001X6-X793-0423-2151-5864XF0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69X001X8-X049-0070-4621-4338XF0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69X002X0-X261-0280-0101-3882XF0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69X002X2-X011-0374-0331-2246XF0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69X003X1-X590-0268-5121-2016XF0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69X003X9-X444-0650-7971-6703XF0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69X004X9-X178-0241-6511-6852XF0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69X006X7-X764-0882-3602-2157XF0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68197808-5131-0243-4423-70929F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68197994-3344-0061-9094-04177F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68198436-2393-0311-5363-17007F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68198452-2608-0456-9424-92696F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68198497-0716-0413-1764-54870F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68198513-8978-0774-2613-42967F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68198714-3760-0907-0104-46376F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68199408-8979-0287-5073-36125F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68199412-2611-0038-5523-22862F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24062001-0631-0881-7561-31190F0FF4IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24063003-0071-0831-4951-44990F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24161091-2634-0748-9252-49488F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24360508-6096-0732-7002-46952F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24362136-4141-0452-7922-25052F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24X613X8-X221-0066-5021-3974XF0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24X618X8-X126-0567-5082-2907XF0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24X626X1-X098-0952-1012-9993XF0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{24X629X5-X118-0839-3122-7425XF0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{54X967X5-X482-0984-9373-0113XF0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099703-0190-0206-8263-74130F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099706-0578-0536-7153-12470F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099707-0491-0953-4143-59890F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099708-0401-0712-8153-04530F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099720-6340-0053-8174-74372F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099763-4499-0394-8924-15109F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099801-0173-0228-9704-71590F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099804-0205-0238-5294-71010F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099804-0627-0324-1384-85030F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099908-0201-0857-2754-18420F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X978X4-X451-0418-9403-3131XF0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X979X2-X008-0148-1283-1535XF0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X980X1-X669-0347-4223-0663XF0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X980X2-X539-0610-4343-9429XF0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X980X3-X330-0167-6483-2339XF0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X980X9-X802-0250-9583-5031XF0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X983X3-X264-0993-9953-3813XF0FF4IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099308-0784-0920-2983-83690F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099400-0977-0360-1773-30700F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099406-0334-0896-7953-72860F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099406-0804-0495-2153-95860F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099406-0811-0153-4593-69520F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099408-0400-0038-4703-04090F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099409-0553-0606-1453-18920F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099503-0908-0428-5943-97830F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099507-0910-0924-7443-74060F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099527-2308-0374-8593-68123F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099602-0536-0817-6853-28050F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099605-0311-0724-4793-22420F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68397945-5397-0933-1794-11593F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68398108-3303-0333-4023-69944F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68398249-3917-0309-7824-87108F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68398710-3481-0707-5664-87053F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68398741-0321-0303-7464-89276F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68399337-7536-0803-7684-95504F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68399337-9249-0034-0634-23625F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68399422-8565-0024-7694-50518F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68399448-1528-0605-3074-52745F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68399552-8262-0246-3224-99615F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X994X0-X470-0373-6683-1487XF0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X994X8-X933-0927-6683-4152XF0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X994X9-X551-0762-9243-8628XF0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X997X3-X178-0204-6533-9407XF0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X997X9-X492-0754-2663-1025XF0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X998X4-X006-0851-2654-4265XF0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X999X2-X512-0049-8264-3750XF0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X999X4-X470-0456-1464-6604XF0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{69X010X5-X178-0778-0471-9472XF0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098700-0055-0374-3593-88370F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098700-0075-0529-6633-54140F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098805-0717-0684-9463-40780F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099000-0979-0911-2593-62970F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099003-0013-0763-0863-73570F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099303-0826-0735-9843-51190F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099304-0656-0350-5373-98350F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68099304-0982-0839-9533-89450F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68297804-4143-0539-3904-74539F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68297904-6837-0467-7824-58776F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68297908-1818-0861-7454-83097F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68298061-9744-0607-5103-12881F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68298180-7388-0416-8964-39553F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68298183-7602-0046-8284-12054F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68298622-1412-0551-8464-80753F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68298699-3099-0151-2924-13247F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68298781-9207-0811-8234-12594F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68298900-8611-0267-6614-34400F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68299078-2652-0958-6314-84769F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68299654-6674-0312-3454-05182F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68299793-0209-0464-7215-86102F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68299845-7965-0628-3924-59538F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098100-0671-0101-0973-06840F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098108-0876-0950-0373-59490F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098201-0998-0414-9393-86630F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098301-0046-0554-2643-94810F0FF4IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098407-0029-0061-7033-21730F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098409-0175-0289-9643-97920F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098503-1375-0076-6393-25433F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098505-0650-0732-0773-64110F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098507-0765-0646-4753-09820F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098580-6558-0126-7584-33947F0FF4IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098601-0225-0819-4523-00460F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X985X9-X349-0086-6583-5270XF0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X987X0-X677-0498-4913-2419XF0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X987X0-X688-0038-1693-1647XF0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X987X3-X039-0471-1293-8151XF0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X988X1-X552-0357-7303-0510XF0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X988X1-X959-0989-2573-3771XF0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X988X4-X953-0730-7213-5903XF0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X988X9-X436-0810-8133-0100XF0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68X989X7-X596-0469-5094-1838XF0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65076909-0172-0270-3013-05630F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077002-0172-0303-7282-41260F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077005-0870-0540-8232-37370F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077009-0297-0964-5412-72230F0FF5IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077015-7153-0298-6782-19534F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077036-4519-0094-6212-85093F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077104-0444-0314-3622-00970F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077104-0705-0633-6742-57290F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077106-0494-0242-1542-75210F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68097804-7237-0305-4153-62387F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68097806-0897-0277-0963-65180F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68097807-0820-0620-5473-58230F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68097905-0650-0779-6253-46730F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68097909-0372-0455-8243-54610F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{68098006-0824-0357-8863-33330F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65177347-2073-0410-0183-97152F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65277137-1855-0059-4343-52177F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65277202-4089-0677-5812-21040F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65277450-8752-0710-1503-68750F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{72162975-7878-0068-0363-60450F0FF4IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{72263112-8203-0102-9302-37895F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{72263576-8055-0495-5093-05883F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{72263762-9029-0547-8473-90337F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{72X621X1-X625-0058-2181-7749XF0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{72X623X5-X326-0488-3172-2328XF0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{74308344-1244-0802-2762-98501F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{74X066X4-X402-0926-6472-3452XF0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{74X074X9-X530-0056-8922-7699XF0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65376947-0488-0335-9274-86005F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65377034-1547-0207-9863-02250F0FF1IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65377148-8973-0018-8603-82593F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65377239-0561-0550-5213-80710F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65377332-7432-0758-6443-25505F0FF4IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65377446-1397-0639-3083-52679F0FF6IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65377556-3879-0176-6083-68415F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65377557-3863-0157-6973-72281F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077180-8990-0992-4053-99369F0FF4IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077208-0618-0815-8032-67500F0FF7IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077269-3024-0793-0103-20237F0FF3IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077300-0832-0736-1562-95880F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077304-0032-0726-5382-65410F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077307-0993-0725-2882-45520F0FF8IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077346-5252-0165-5173-67275F0FF2IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077403-0155-0792-7422-53310F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077408-0392-0298-8942-24060F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077506-0105-0107-8623-53770F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077506-0873-0954-4553-89420F0FF0IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data\{65077594-0038-0581-3373-47948F0FF9IW}.dta, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\firefox\chrome.manifest, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\firefox\install.rdf, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\firefox\iWinArcadeLauncher.exe, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\firefox\version, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\firefox\chrome\iwinarcade.jar, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\opal\Flash.ocx, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\opal\FlashPlayerControl.dll, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\opal\opal.ver, Quarantined, [4a3bf8f77407d0668e57b04d60a2af51],
PUP.Optional.AdPeak.A, C:\Program Files\B021CBBD-E38E-4F8C-8E93-6624B0597A23\kzhxnitccw.dll, Quarantined, [d4b146a964179f9732eece37966d639d],
PUP.Optional.AdPeak.A, C:\Program Files\B021CBBD-E38E-4F8C-8E93-6624B0597A23\uninstaller.exe, Quarantined, [d4b146a964179f9732eece37966d639d],
PUP.Optional.MyStartTB.A, C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\preferences, Good: (), Bad: (        "homepage": "http://www.mystart.com/?pr=vmn&id=mystarttb&v=5_4&ent=hp_5127&src=5127",), Replaced,[ff86fef1b0cb5cda46e0be8a21e47f81]

Physical Sectors: 0
(No malicious items detected)


(end)

 

 

=================AdwCleaner=====================

 

# AdwCleaner v3.311 - Report created 05/10/2014 at 21:15:36
# Updated 30/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Bonnie - BONNIE-PC
# Running from : C:\Users\Bonnie\Downloads\adwcleaner_3.311.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

[x] Not Deleted : C:\ProgramData\iWin
[x] Not Deleted : C:\ProgramData\Alawar
[x] Not Deleted : C:\ProgramData\Alawar Entertainment
[x] Not Deleted : C:\ProgramData\Alawar Stargaze
[x] Not Deleted : C:\ProgramData\AlawarEntertainment
[x] Not Deleted : C:\ProgramData\AlawarWrapper
[x] Not Deleted : C:\Program Files (x86)\Alawar
[x] Not Deleted : C:\Users\Bonnie\AppData\Local\AlawarWrapper
[x] Not Deleted : C:\Users\Bonnie\AppData\Roaming\iWin
[x] Not Deleted : C:\Users\Bonnie\AppData\Roaming\Alawar
[x] Not Deleted : C:\Users\Bonnie\AppData\Roaming\Alawar Entertainment
[x] Not Deleted : C:\Users\Bonnie\AppData\Roaming\Alawar Stargaze
[x] Not Deleted : C:\Users\Bonnie\AppData\Roaming\AlawarEntertainment
[x] Not Deleted : C:\Users\Public\Documents\iWin
[x] Not Deleted : C:\Users\Public\Documents\AlawarWrapper

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

[x] Not Deleted : HKCU\Software\Alawar
[x] Not Deleted : HKLM\SOFTWARE\Alawar
[x] Not Deleted : [x64] HKCU\Software\Alawar

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280


-\\ Mozilla Firefox v32.0.3 (x86 en-US)

[ File : C:\Users\Bonnie\AppData\Roaming\Mozilla\Firefox\Profiles\io25vpy0.default\prefs.js ]


-\\ Google Chrome v

[ File : C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [32408 octets] - [30/09/2014 16:47:42]
AdwCleaner[R1].txt - [1958 octets] - [05/10/2014 21:11:33]
AdwCleaner[S0].txt - [32185 octets] - [30/09/2014 16:55:48]
AdwCleaner[S1].txt - [1938 octets] - [05/10/2014 21:15:36]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1998 octets] ##########

 

==================FarBar==================



Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-10-2014
Ran by Bonnie (administrator) on BONNIE-PC on 05-10-2014 21:25:20
Running from C:\Users\Bonnie\Downloads
Loaded Profile: Bonnie (Available profiles: Bonnie)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(iWin Inc.) C:\Program Files (x86)\iWin Games\iWinTrusted.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(iWin Inc.) C:\Program Files (x86)\Pogo Games\PGMTrusted.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\Ymsgr_tray.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10060320 2010-02-09] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-01] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-1266221820-170093003-908648241-1000\...\Run: [Messenger (Yahoo!)] => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.)
HKU\S-1-5-21-1266221820-170093003-908648241-1000\...\Run: [BitTorrent Sync] => "C:\Program Files (x86)\BitTorrent Sync\BTSync.exe"  /MINIMIZED
HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.yahoo.com?fr=hp-avast&type=iedef
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = https://www.yahoo.com?fr=hp-avast&type=iedef
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM-x32 - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - EE693ADA08364CF89C00F0C2930FD8B9 URL = http://findwide.com/serp?guid={B1AA3279-D90A-40B1-81A0-1D7E3283CAD9}&action=default_search&serpv=17&k={searchTerms}
SearchScopes: HKCU - Yahoo URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=oberhp&type=iwingamestoolbar
SearchScopes: HKCU - {508E9CD6-C60E-4335-BD7D-9C26D9D4EBC9} URL = http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10705
SearchScopes: HKCU - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - {7E669996-6613-4360-8652-77535EBEC57A} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3279141&CUI=UN10012430661249017&SSPV=SP_IEWSP06
SearchScopes: HKCU - {ACA0AFE5-A2E3-4192-B0F1-992B0206D83D} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000031&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=^TV&apn_dtid=^OSJ000^YY^US&apn_uid=E7C71EF5-68DA-4CC0-BE3E-6B023F76CF4F&apn_sauid=7EBD6A66-71A1-430E-859C-998D0C163966
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: No Name -> {C6AA1C90-331E-9C00-E122-305F2CF3FEA7} ->  No File
BHO-x32: No Name -> {C8B60FC9-DA76-13C8-285A-C9220CB1516D} ->  No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name -> {F0C9EBCD-1519-9ABE-E962-ADC22AE53B5B} ->  No File
BHO-x32: No Name -> {fbdff406-2c4c-5d35-8469-34bb67ea3353} ->  No File
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKCU - No Name - {16868B89-775C-4DD4-8C3F-41DDCA66EE5C} -  No File
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455}
DPF: HKLM-x32 {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab
Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75

FireFox:
========
FF ProfilePath: C:\Users\Bonnie\AppData\Roaming\Mozilla\Firefox\Profiles\io25vpy0.default
FF SearchEngineOrder.1: Yahoo! (Avast)
FF SearchEngineOrder.3: Bing
FF Homepage: startpage.com
FF Keyword.URL: https://search.yahoo.com/yhs/search
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @alawar.com/npapi -> C:\Windows\npapi.dll (Alawar)
FF Plugin-x32: @ei.MapsGalaxy_39.com/Plugin -> C:\Program Files (x86)\MapsGalaxy_39EI\Installr\1.bin\NP39EISB.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\17\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Bonnie\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Users\Bonnie\AppData\Roaming\Mozilla\Firefox\Profiles\io25vpy0.default\searchplugins\yahoo-avast.xml
FF Extension: Disconnect - C:\Users\Bonnie\AppData\Roaming\Mozilla\Firefox\Profiles\io25vpy0.default\Extensions\2.0@disconnect.me.xpi [2014-09-30]
FF Extension: NoScript - C:\Users\Bonnie\AppData\Roaming\Mozilla\Firefox\Profiles\io25vpy0.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-09-30]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-01-03]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-03-20]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.mystart.com/?pr=vmn&id=mystarttb&v=5_4&ent=hp_5127&src=5127"
CHR Profile: C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\afcjaomphinpjpdpojdjjnjgkadnocjk [2013-01-07]
CHR Extension: (Docs) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-16]
CHR Extension: (Google Drive) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-16]
CHR Extension: (YouTube) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-16]
CHR Extension: (Google Search) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-16]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddhnemokmpoejldnghacjmogmbapfhib [2013-01-05]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\dedhnpcpnekemegbgcmkhmlpnflgaggj [2014-04-27]
CHR Extension: (avast! Online Security) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-07-22]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-04-17]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\kladopbdfkipcnmapgdkjppcahffonfl [2013-01-08]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpfljmigolkmjdoplbnhddjcbedilhah [2013-01-06]
CHR Extension: (Google Wallet) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-16]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooiopmklfikoifgpamgpnohonfaknofk [2014-04-27]
CHR Extension: (Gmail) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-16]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-22]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-22] (AVAST Software)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [255040 2014-08-28] (WildTangent)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
S4 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 PGMTrusted; C:\Program Files (x86)\Pogo Games\PGMTrusted.exe [519920 2012-10-29] (iWin Inc.)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-22] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-22] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-22] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-22] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-22] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-22] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-22] ()
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-06-20] (Anchorfree Inc.)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-05 21:25 - 2014-10-05 21:25 - 00016393 _____ () C:\Users\Bonnie\Downloads\FRST.txt
2014-10-05 21:25 - 2014-10-05 21:25 - 00000000 ____D () C:\FRST
2014-10-05 21:24 - 2014-10-05 21:24 - 02109440 _____ (Farbar) C:\Users\Bonnie\Downloads\FRST64.exe
2014-10-05 21:23 - 2014-10-05 21:23 - 00002082 _____ () C:\Users\Bonnie\Desktop\AdwCleaner[S1].txt
2014-10-05 21:10 - 2014-10-05 21:10 - 01375089 _____ () C:\Users\Bonnie\Downloads\adwcleaner_3.311.exe
2014-10-05 20:31 - 2014-10-05 21:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-05 20:30 - 2014-10-05 20:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-05 20:30 - 2014-10-05 20:30 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-05 20:30 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-05 20:30 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-05 20:30 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-05 20:28 - 2014-10-05 20:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Bonnie\Downloads\mbam-setup-2.0.2.1012(1).exe
2014-10-05 06:49 - 2014-10-05 06:49 - 00002108 _____ () C:\Users\Public\Desktop\Play Fierce Tales - Feline Sight.lnk
2014-10-05 06:49 - 2014-10-05 06:49 - 00001284 _____ () C:\Users\Public\Desktop\More Great Games.lnk
2014-10-05 06:48 - 2014-10-05 06:50 - 00000000 ____D () C:\Program Files (x86)\Fierce Tales - Feline Sight
2014-10-05 06:48 - 2014-10-05 06:48 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fierce Tales - Feline Sight
2014-10-05 06:48 - 2014-10-05 06:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fierce Tales - Feline Sight
2014-10-04 16:41 - 2014-10-04 16:42 - 00000000 ____D () C:\Program Files (x86)\Dark Realm - Queen of Flames Collectors Edition
2014-10-04 16:41 - 2014-10-04 16:41 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dark Realm - Queen of Flames Collectors Edition
2014-10-04 16:41 - 2014-10-04 16:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dark Realm - Queen of Flames Collectors Edition
2014-10-04 16:33 - 2014-10-04 16:33 - 00237568 _____ (Big Fish Games) C:\Users\Bonnie\Downloads\dark-realm-queen-of-flames-collectors-edition_s1_l1_gF8343T1L1_d2370308122.exe
2014-10-01 04:18 - 2014-09-24 21:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-01 04:18 - 2014-09-24 20:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-09-30 17:20 - 2014-09-30 17:20 - 00688992 ____R (Swearware) C:\Users\Bonnie\Downloads\dds.scr
2014-09-30 17:06 - 2014-09-30 17:07 - 00041579 _____ () C:\Users\Bonnie\Downloads\Result.txt
2014-09-30 17:05 - 2014-09-30 17:06 - 00401920 _____ (Farbar) C:\Users\Bonnie\Downloads\MiniToolBox.exe
2014-09-30 16:47 - 2014-10-05 21:15 - 00000000 ____D () C:\AdwCleaner
2014-09-30 16:47 - 2014-09-30 16:47 - 01375089 _____ () C:\Users\Bonnie\Downloads\AdwCleaner.exe
2014-09-30 16:17 - 2014-10-02 09:36 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-09-30 16:17 - 2014-10-02 09:35 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-09-30 16:17 - 2014-09-30 16:17 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-09-30 16:14 - 2014-09-30 16:16 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Bonnie\Downloads\spybot-2.4.exe
2014-09-30 16:11 - 2014-09-30 16:11 - 01188194 _____ () C:\Users\Bonnie\Downloads\ProcessExplorer.zip
2014-09-30 16:11 - 2014-09-30 16:11 - 00000000 ____D () C:\Users\Bonnie\Downloads\ProcessExplorer
2014-09-30 15:54 - 2014-10-05 21:17 - 00185764 _____ () C:\Windows\PFRO.log
2014-09-30 15:54 - 2014-10-05 21:17 - 00000672 _____ () C:\Windows\setupact.log
2014-09-30 15:54 - 2014-09-30 15:54 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-30 11:40 - 2014-09-30 11:41 - 04965896 _____ (Piriform Ltd) C:\Users\Bonnie\Downloads\ccsetup418.exe
2014-09-30 11:28 - 2014-09-30 11:28 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-30 11:25 - 2014-09-30 11:26 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Bonnie\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-30 11:12 - 2014-09-30 11:12 - 00003366 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1266221820-170093003-908648241-1000
2014-09-30 11:12 - 2014-09-30 11:12 - 00003234 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1266221820-170093003-908648241-1000
2014-09-30 10:47 - 2014-09-30 10:47 - 00003344 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1266221820-170093003-908648241-1000
2014-09-30 10:36 - 2014-10-05 21:17 - 00001338 _____ () C:\Windows\Tasks\MPAP.job
2014-09-30 10:36 - 2014-09-30 10:36 - 00004368 _____ () C:\Windows\System32\Tasks\MPAP
2014-09-30 10:34 - 2014-09-30 10:34 - 00004720 _____ () C:\Windows\System32\Tasks\LBQVVVTO
2014-09-30 10:33 - 2014-10-05 21:17 - 00001690 _____ () C:\Windows\Tasks\LBQVVVTO.job
2014-09-30 10:32 - 2014-09-30 10:43 - 00000000 ____D () C:\Program Files (x86)\Spyware Clear
2014-09-30 10:26 - 2014-09-30 10:26 - 01935872 _____ (TODO: <Company name>) C:\Windows\SysWOW64\8962268
2014-09-29 08:06 - 2014-09-30 10:47 - 00003212 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1266221820-170093003-908648241-1000
2014-09-26 05:48 - 2014-09-28 06:14 - 00000000 ____D () C:\Program Files (x86)\Danse Macabre - Moulin Rouge Collectors Edition
2014-09-24 06:17 - 2014-09-09 17:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-24 06:17 - 2014-09-09 16:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-22 12:17 - 2014-09-26 04:56 - 00000000 ____D () C:\Program Files (x86)\4 Elements II
2014-09-22 07:02 - 2014-09-11 10:42 - 00358616 _____ (Say Media Group LTD) C:\Windows\system32\ColorMedia64.dll
2014-09-21 08:57 - 2014-09-21 08:57 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\blg
2014-09-21 08:57 - 2014-09-21 08:57 - 00000000 ____D () C:\ProgramData\blg
2014-09-21 07:08 - 2014-09-21 08:54 - 00000000 ____D () C:\Program Files (x86)\Forgotten Kingdoms - Dream of Ruin Collectors Edition
2014-09-20 15:43 - 2014-09-20 15:44 - 00000000 ____D () C:\Program Files (x86)\Mystika 2 - The Sanctuary
2014-09-19 07:35 - 2014-09-20 07:14 - 00000000 ____D () C:\Program Files (x86)\Grim Facade - The Artist and The Pretender Collectors Edition
2014-09-18 14:23 - 2014-09-18 14:23 - 00000000 ____D () C:\ProgramData\Veronica&BoD
2014-09-18 14:03 - 2014-09-18 14:03 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Jewel Keepers Easter Island
2014-09-18 12:55 - 2014-09-18 12:56 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\TFS2
2014-09-18 07:14 - 2014-09-20 08:29 - 00000000 ____D () C:\Program Files (x86)\Witches Legacy - The Ties That Bind Collectors Edition
2014-09-18 06:11 - 2014-09-18 07:10 - 00000000 ____D () C:\Program Files (x86)\9 Clues - The Ward
2014-09-18 06:04 - 2014-09-18 06:04 - 00002023 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-09-17 08:52 - 2014-09-17 08:52 - 00000000 ____D () C:\ProgramData\rokapublish
2014-09-17 06:07 - 2014-09-17 06:09 - 00000000 ____D () C:\Program Files (x86)\Into the Haze
2014-09-16 11:30 - 2014-09-16 11:30 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Frozen Kingdom
2014-09-16 08:44 - 2014-09-16 08:44 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\GreenSauceGames
2014-09-16 07:11 - 2014-09-17 06:06 - 00000000 ____D () C:\Program Files (x86)\Melissa K and the Heart of Gold
2014-09-14 06:54 - 2014-09-14 06:54 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Friendly Cactus
2014-09-14 06:51 - 2014-09-15 06:14 - 00000000 ____D () C:\Program Files (x86)\Shrouded Tales - The Spellbound Land Collectors Edition
2014-09-13 03:04 - 2014-08-19 13:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-13 03:04 - 2014-08-19 12:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-13 03:04 - 2014-08-18 18:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-13 03:04 - 2014-08-18 17:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-13 03:04 - 2014-08-18 17:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-13 03:04 - 2014-08-18 17:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-13 03:04 - 2014-08-18 17:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-13 03:04 - 2014-08-18 17:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-13 03:04 - 2014-08-18 17:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-13 03:04 - 2014-08-18 17:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-13 03:04 - 2014-08-18 17:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-13 03:04 - 2014-08-18 17:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-13 03:04 - 2014-08-18 17:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-13 03:04 - 2014-08-18 17:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-13 03:04 - 2014-08-18 17:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-13 03:04 - 2014-08-18 17:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-13 03:04 - 2014-08-18 17:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-13 03:04 - 2014-08-18 17:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-13 03:04 - 2014-08-18 17:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-13 03:04 - 2014-08-18 16:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-13 03:04 - 2014-08-18 16:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-13 03:04 - 2014-08-18 16:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-13 03:04 - 2014-08-18 16:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-13 03:04 - 2014-08-18 16:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-13 03:04 - 2014-08-18 16:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-13 03:04 - 2014-08-18 16:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-13 03:04 - 2014-08-18 16:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-13 03:04 - 2014-08-18 16:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-13 03:04 - 2014-08-18 16:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-13 03:04 - 2014-08-18 16:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-13 03:04 - 2014-08-18 16:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-13 03:04 - 2014-08-18 16:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-13 03:04 - 2014-08-18 16:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-13 03:04 - 2014-08-18 16:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-13 03:04 - 2014-08-18 16:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-13 03:04 - 2014-08-18 16:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-13 03:04 - 2014-08-18 16:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-13 03:04 - 2014-08-18 16:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-13 03:04 - 2014-08-18 16:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-13 03:04 - 2014-08-18 16:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-13 03:04 - 2014-08-18 16:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-13 03:04 - 2014-08-18 16:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-13 03:04 - 2014-08-18 16:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-13 03:04 - 2014-08-18 16:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-13 03:04 - 2014-08-18 16:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-13 03:04 - 2014-08-18 16:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-13 03:04 - 2014-08-18 16:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-13 03:04 - 2014-08-18 16:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-13 03:04 - 2014-08-18 16:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-13 03:04 - 2014-08-18 16:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-13 03:04 - 2014-08-18 16:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-13 03:04 - 2014-08-18 15:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-13 03:04 - 2014-08-18 15:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-13 03:04 - 2014-08-18 15:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-13 03:04 - 2014-08-18 15:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-13 03:04 - 2014-08-18 15:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-12 06:38 - 2014-09-12 06:38 - 00000000 ____D () C:\3088a2bde847e7b8c9
2014-09-12 06:35 - 2014-06-26 21:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-12 06:35 - 2014-06-26 20:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-11 06:14 - 2014-09-11 06:14 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\BoonTrollGames
2014-09-11 04:07 - 2014-08-01 06:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-11 04:07 - 2014-08-01 06:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-11 04:07 - 2014-07-06 21:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-11 04:07 - 2014-07-06 21:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-11 04:07 - 2014-07-06 20:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-11 04:07 - 2014-06-23 22:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-11 04:07 - 2014-06-23 21:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-11 04:06 - 2014-09-04 21:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-11 04:06 - 2014-09-04 21:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-11 04:06 - 2014-07-06 20:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-11 04:06 - 2014-07-06 20:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-05 21:25 - 2009-07-13 23:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-05 21:25 - 2009-07-13 23:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-05 21:21 - 2012-05-17 22:34 - 01590170 _____ () C:\Windows\WindowsUpdate.log
2014-10-05 21:20 - 2013-03-20 19:36 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-10-05 21:17 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-05 21:14 - 2013-01-03 18:50 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-05 21:03 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\security
2014-10-05 13:01 - 2013-01-03 18:39 - 00003934 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{AFCAF4DF-A72C-4E8A-B632-DC239D69E116}
2014-10-05 07:27 - 2012-05-17 22:47 - 00000000 ____D () C:\ProgramData\Temp
2014-10-05 06:51 - 2013-01-08 08:52 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\BlamGames
2014-10-05 06:50 - 2013-01-03 18:50 - 00255259 _____ () C:\Windows\wininit.ini
2014-10-05 06:48 - 2009-07-14 00:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-05 06:33 - 2014-05-28 14:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-04 18:10 - 2013-02-13 14:31 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\SoftGrid Client
2014-10-04 17:55 - 2013-01-04 10:36 - 00003412 _____ () C:\Windows\System32\Tasks\RunAsStdUser Task
2014-10-04 17:48 - 2013-07-10 04:49 - 00000000 ____D () C:\BigFishCache
2014-10-04 16:43 - 2013-05-16 08:36 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Mad Head Games
2014-10-02 09:44 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-10-02 09:42 - 2011-11-10 00:23 - 00002434 ____N () C:\Users\Public\Desktop\WildTangent Games App - acer.lnk
2014-10-01 07:13 - 2014-05-26 08:52 - 00000000 ____D () C:\Users\Bonnie\Documents\Calibre Library
2014-09-30 16:41 - 2014-05-05 13:32 - 00001106 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-09-30 12:44 - 2014-02-19 09:13 - 00000000 ____D () C:\Program Files (x86)\Real
2014-09-30 12:44 - 2014-02-19 09:12 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Real
2014-09-30 12:44 - 2014-02-19 09:12 - 00000000 ____D () C:\ProgramData\Real
2014-09-30 12:05 - 2007-07-11 20:49 - 00000000 ____D () C:\Windows\Panther
2014-09-30 11:48 - 2013-12-25 17:25 - 00000000 ____D () C:\temp
2014-09-30 10:58 - 2014-03-20 13:36 - 00000141 _____ () C:\Users\Bonnie\AppData\Roaming\WB.CFG
2014-09-30 10:57 - 2014-08-18 09:28 - 00000000 ____D () C:\Program Files (x86)\Alawar.en
2014-09-30 10:34 - 2013-02-24 07:39 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-30 06:07 - 2013-01-30 18:58 - 00001399 _____ () C:\Users\Bonnie\Desktop\Yahoo! Mail Internet Explorer.lnk
2014-09-30 06:07 - 2013-01-26 14:23 - 00001139 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-29 12:29 - 2009-07-13 21:34 - 00000537 _____ () C:\Windows\win.ini
2014-09-29 05:40 - 2013-02-03 09:42 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Boomzap
2014-09-28 07:01 - 2013-01-04 10:52 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Artifex Mundi
2014-09-27 07:10 - 2013-01-04 09:26 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Elephant Games
2014-09-26 05:50 - 2013-01-27 07:41 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Eipix
2014-09-24 09:14 - 2013-01-03 18:50 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-24 09:14 - 2013-01-03 18:50 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-24 09:14 - 2011-11-10 00:38 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-24 07:44 - 2013-02-07 11:40 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Deep Shadows
2014-09-24 07:44 - 2013-01-05 15:25 - 00000000 ____D () C:\ProgramData\AlawarWrapper
2014-09-22 12:36 - 2013-09-07 08:06 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Playrix Entertainment
2014-09-22 07:02 - 2013-01-03 18:50 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Mozilla
2014-09-22 05:41 - 2014-02-23 08:53 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Five-BN Games
2014-09-22 05:40 - 2014-09-03 06:51 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Urchin
2014-09-21 07:11 - 2013-01-18 07:39 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Vast Studios
2014-09-20 08:32 - 2013-01-31 15:50 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\DailyMagic
2014-09-20 08:32 - 2013-01-31 15:50 - 00000000 ____D () C:\ProgramData\DailyMagic
2014-09-19 08:52 - 2014-07-01 05:32 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Jewel Match 4
2014-09-19 07:37 - 2013-01-05 08:07 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\ERS Game Studios
2014-09-18 06:14 - 2013-08-04 07:36 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Tap It Games
2014-09-18 06:04 - 2011-11-10 00:37 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-09-17 06:25 - 2013-02-22 07:19 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\VendelGAMES
2014-09-15 09:06 - 2010-11-20 22:27 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-15 06:20 - 2013-01-09 23:39 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\EleFun Games
2014-09-14 09:56 - 2013-04-07 09:11 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\LittleGamesCompany
2014-09-14 06:53 - 2014-08-19 06:51 - 00000000 ____D () C:\Program Files (x86)\Ghosts of the Past - Bones of Meadows Town Collectors Edition
2014-09-13 08:05 - 2013-01-07 10:23 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\Awem
2014-09-13 03:02 - 2013-02-13 14:31 - 00775522 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-13 03:02 - 2009-07-14 00:13 - 00775522 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-12 06:39 - 2013-08-15 03:02 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-12 06:38 - 2013-01-03 19:49 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-12 06:35 - 2014-05-07 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-07 05:36 - 2013-05-01 06:03 - 00000000 ____D () C:\Users\Bonnie\AppData\Roaming\DominiGames

Some content of TEMP:
====================
C:\Users\Bonnie\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-03-04 19:42

==================== End Of Log ============================
 

FRST Addition is attached

Attached Files



#4 sepa14

sepa14
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:04:23 AM

Posted 05 October 2014 - 09:45 PM

I may have skipped these steps:

 


  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.

 

I did not choose Report. I Scanned, deselected, and Cleaned. Hopefully this isn't a problem.



#5 nasdaq

nasdaq

  • Malware Response Team
  • 39,955 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:23 AM

Posted 06 October 2014 - 07:50 AM

Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below.
 
start
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.yahoo.com?fr=hp-avast&type=iedef
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = https://www.yahoo.com?fr=hp-avast&type=iedef
SearchScopes: HKLM-x32 - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - EE693ADA08364CF89C00F0C2930FD8B9 URL = http://findwide.com/serp?guid={B1AA3279-D90A-40B1-81A0-1D7E3283CAD9}&action=default_search&serpv=17&k={searchTerms}
SearchScopes: HKCU - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - {7E669996-6613-4360-8652-77535EBEC57A} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3279141&CUI=UN10012430661249017&SSPV=SP_IEWSP06
SearchScopes: HKCU - {ACA0AFE5-A2E3-4192-B0F1-992B0206D83D} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000031&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=^TV&apn_dtid=^OSJ000^YY^US&apn_uid=E7C71EF5-68DA-4CC0-BE3E-6B023F76CF4F&apn_sauid=7EBD6A66-71A1-430E-859C-998D0C163966
BHO-x32: No Name -> {C6AA1C90-331E-9C00-E122-305F2CF3FEA7} ->  No File
BHO-x32: No Name -> {C8B60FC9-DA76-13C8-285A-C9220CB1516D} ->  No File
BHO-x32: No Name -> {F0C9EBCD-1519-9ABE-E962-ADC22AE53B5B} ->  No File
BHO-x32: No Name -> {fbdff406-2c4c-5d35-8469-34bb67ea3353} ->  No File
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKCU - No Name - {16868B89-775C-4DD4-8C3F-41DDCA66EE5C} -  No File
FF SearchEngineOrder.1: Yahoo! (Avast)
FF Homepage: startpage.com
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @ei.MapsGalaxy_39.com/Plugin -> C:\Program Files (x86)\MapsGalaxy_39EI\Installr\1.bin\NP39EISB.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF SearchPlugin: C:\Users\Bonnie\AppData\Roaming\Mozilla\Firefox\Profiles\io25vpy0.default\searchplugins\yahoo-avast.xml
CHR StartupUrls: Default -> "hxxp://www.mystart.com/?pr=vmn&id=mystarttb&v=5_4&ent=hp_5127&src=5127"
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\afcjaomphinpjpdpojdjjnjgkadnocjk [2013-01-07]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddhnemokmpoejldnghacjmogmbapfhib [2013-01-05]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\dedhnpcpnekemegbgcmkhmlpnflgaggj [2014-04-27]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\kladopbdfkipcnmapgdkjppcahffonfl [2013-01-08]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpfljmigolkmjdoplbnhddjcbedilhah [2013-01-06]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooiopmklfikoifgpamgpnohonfaknofk [2014-04-27]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:008586AE
AlternateDataStreams: C:\ProgramData\Temp:008FE370
AlternateDataStreams: C:\ProgramData\Temp:00D77978
AlternateDataStreams: C:\ProgramData\Temp:00D99749
AlternateDataStreams: C:\ProgramData\Temp:00F3978A
AlternateDataStreams: C:\ProgramData\Temp:012BC84F
AlternateDataStreams: C:\ProgramData\Temp:01F9D1B4
AlternateDataStreams: C:\ProgramData\Temp:0205B36B
AlternateDataStreams: C:\ProgramData\Temp:021496FB
AlternateDataStreams: C:\ProgramData\Temp:021703B2
AlternateDataStreams: C:\ProgramData\Temp:02DD996C
AlternateDataStreams: C:\ProgramData\Temp:036AA5DD
AlternateDataStreams: C:\ProgramData\Temp:041C0562
AlternateDataStreams: C:\ProgramData\Temp:041ED421
AlternateDataStreams: C:\ProgramData\Temp:04A18F36
AlternateDataStreams: C:\ProgramData\Temp:04BC9A2C
AlternateDataStreams: C:\ProgramData\Temp:04D30F4C
AlternateDataStreams: C:\ProgramData\Temp:04EAB86F
AlternateDataStreams: C:\ProgramData\Temp:0588E665
AlternateDataStreams: C:\ProgramData\Temp:06CC3FD3
AlternateDataStreams: C:\ProgramData\Temp:076F9EF8
AlternateDataStreams: C:\ProgramData\Temp:0785072C
AlternateDataStreams: C:\ProgramData\Temp:08767DE0
AlternateDataStreams: C:\ProgramData\Temp:087CB364
AlternateDataStreams: C:\ProgramData\Temp:09064307
AlternateDataStreams: C:\ProgramData\Temp:092BD83A
AlternateDataStreams: C:\ProgramData\Temp:09629F6E
AlternateDataStreams: C:\ProgramData\Temp:097274A2
AlternateDataStreams: C:\ProgramData\Temp:097C4B7D
AlternateDataStreams: C:\ProgramData\Temp:099BA123
AlternateDataStreams: C:\ProgramData\Temp:09AEED56
AlternateDataStreams: C:\ProgramData\Temp:0A701F26
AlternateDataStreams: C:\ProgramData\Temp:0AC0213C
AlternateDataStreams: C:\ProgramData\Temp:0AC32449
AlternateDataStreams: C:\ProgramData\Temp:0AD90625
AlternateDataStreams: C:\ProgramData\Temp:0ADCCF52
AlternateDataStreams: C:\ProgramData\Temp:0B278A1A
AlternateDataStreams: C:\ProgramData\Temp:0B55751B
AlternateDataStreams: C:\ProgramData\Temp:0B79AB8D
AlternateDataStreams: C:\ProgramData\Temp:0B9DC6BB
AlternateDataStreams: C:\ProgramData\Temp:0BBF232A
AlternateDataStreams: C:\ProgramData\Temp:0C2A17F2
AlternateDataStreams: C:\ProgramData\Temp:0C9E06A2
AlternateDataStreams: C:\ProgramData\Temp:0D278FB5
AlternateDataStreams: C:\ProgramData\Temp:0E10B960
AlternateDataStreams: C:\ProgramData\Temp:0EBD727C
AlternateDataStreams: C:\ProgramData\Temp:0F64164E
AlternateDataStreams: C:\ProgramData\Temp:0FAE191E
AlternateDataStreams: C:\ProgramData\Temp:104A1C3E
AlternateDataStreams: C:\ProgramData\Temp:10DB9BB7
AlternateDataStreams: C:\ProgramData\Temp:115EA582
AlternateDataStreams: C:\ProgramData\Temp:11C7FAE3
AlternateDataStreams: C:\ProgramData\Temp:120E44A4
AlternateDataStreams: C:\ProgramData\Temp:128B55C8
AlternateDataStreams: C:\ProgramData\Temp:12BCD9DC
AlternateDataStreams: C:\ProgramData\Temp:12D136AA
AlternateDataStreams: C:\ProgramData\Temp:13019F4B
AlternateDataStreams: C:\ProgramData\Temp:1322DDBD
AlternateDataStreams: C:\ProgramData\Temp:14B2E0BD
AlternateDataStreams: C:\ProgramData\Temp:16777CF9
AlternateDataStreams: C:\ProgramData\Temp:178BD71C
AlternateDataStreams: C:\ProgramData\Temp:186F8A82
AlternateDataStreams: C:\ProgramData\Temp:18A25CF1
AlternateDataStreams: C:\ProgramData\Temp:18B241CC
AlternateDataStreams: C:\ProgramData\Temp:18B5F839
AlternateDataStreams: C:\ProgramData\Temp:18E4BF6C
AlternateDataStreams: C:\ProgramData\Temp:19474103
AlternateDataStreams: C:\ProgramData\Temp:197E3428
AlternateDataStreams: C:\ProgramData\Temp:19F8EB29
AlternateDataStreams: C:\ProgramData\Temp:1A15E356
AlternateDataStreams: C:\ProgramData\Temp:1A259A13
AlternateDataStreams: C:\ProgramData\Temp:1A7FC483
AlternateDataStreams: C:\ProgramData\Temp:1AC933DC
AlternateDataStreams: C:\ProgramData\Temp:1B389835
AlternateDataStreams: C:\ProgramData\Temp:1B7E2022
AlternateDataStreams: C:\ProgramData\Temp:1B8AA588
AlternateDataStreams: C:\ProgramData\Temp:1B96CF22
AlternateDataStreams: C:\ProgramData\Temp:1C6D705B
AlternateDataStreams: C:\ProgramData\Temp:1CF1FB36
AlternateDataStreams: C:\ProgramData\Temp:1D5FADCD
AlternateDataStreams: C:\ProgramData\Temp:1E87A273
AlternateDataStreams: C:\ProgramData\Temp:1EC13383
AlternateDataStreams: C:\ProgramData\Temp:1EEF2E2E
AlternateDataStreams: C:\ProgramData\Temp:1F4F2F80
AlternateDataStreams: C:\ProgramData\Temp:1FF82161
AlternateDataStreams: C:\ProgramData\Temp:2043337E
AlternateDataStreams: C:\ProgramData\Temp:217A2324
AlternateDataStreams: C:\ProgramData\Temp:219DB32E
AlternateDataStreams: C:\ProgramData\Temp:220E9B9E
AlternateDataStreams: C:\ProgramData\Temp:2313511A
AlternateDataStreams: C:\ProgramData\Temp:234E9CC5
AlternateDataStreams: C:\ProgramData\Temp:236FF5C6
AlternateDataStreams: C:\ProgramData\Temp:2433F876
AlternateDataStreams: C:\ProgramData\Temp:24391EC1
AlternateDataStreams: C:\ProgramData\Temp:2636DE16
AlternateDataStreams: C:\ProgramData\Temp:2652902F
AlternateDataStreams: C:\ProgramData\Temp:2680DDD5
AlternateDataStreams: C:\ProgramData\Temp:268BA8AB
AlternateDataStreams: C:\ProgramData\Temp:26991AB9
AlternateDataStreams: C:\ProgramData\Temp:2727F067
AlternateDataStreams: C:\ProgramData\Temp:27A88EF2
AlternateDataStreams: C:\ProgramData\Temp:27D1368B
AlternateDataStreams: C:\ProgramData\Temp:282CE153
AlternateDataStreams: C:\ProgramData\Temp:28DFF83F
AlternateDataStreams: C:\ProgramData\Temp:29EA7E22
AlternateDataStreams: C:\ProgramData\Temp:2A27E0C5
AlternateDataStreams: C:\ProgramData\Temp:2AF322BF
AlternateDataStreams: C:\ProgramData\Temp:2B5C4773
AlternateDataStreams: C:\ProgramData\Temp:2B9555D8
AlternateDataStreams: C:\ProgramData\Temp:2BFBA0B7
AlternateDataStreams: C:\ProgramData\Temp:2C4F33F6
AlternateDataStreams: C:\ProgramData\Temp:2CA4B471
AlternateDataStreams: C:\ProgramData\Temp:2CB9631F
AlternateDataStreams: C:\ProgramData\Temp:2D133896
AlternateDataStreams: C:\ProgramData\Temp:2DC8330D
AlternateDataStreams: C:\ProgramData\Temp:2F0A4DCE
AlternateDataStreams: C:\ProgramData\Temp:2F360FB3
AlternateDataStreams: C:\ProgramData\Temp:2F474C84
AlternateDataStreams: C:\ProgramData\Temp:2F717FB3
AlternateDataStreams: C:\ProgramData\Temp:2F7C40B6
AlternateDataStreams: C:\ProgramData\Temp:2F947175
AlternateDataStreams: C:\ProgramData\Temp:30A9192A
AlternateDataStreams: C:\ProgramData\Temp:319D783D
AlternateDataStreams: C:\ProgramData\Temp:320208DA
AlternateDataStreams: C:\ProgramData\Temp:3241739E
AlternateDataStreams: C:\ProgramData\Temp:329BA65B
AlternateDataStreams: C:\ProgramData\Temp:32D2A239
AlternateDataStreams: C:\ProgramData\Temp:3313A48D
AlternateDataStreams: C:\ProgramData\Temp:3393A1CA
AlternateDataStreams: C:\ProgramData\Temp:33CF835F
AlternateDataStreams: C:\ProgramData\Temp:33E58057
AlternateDataStreams: C:\ProgramData\Temp:3480F458
AlternateDataStreams: C:\ProgramData\Temp:3487C53E
AlternateDataStreams: C:\ProgramData\Temp:35501BA4
AlternateDataStreams: C:\ProgramData\Temp:35E8E596
AlternateDataStreams: C:\ProgramData\Temp:363E775E
AlternateDataStreams: C:\ProgramData\Temp:3651A580
AlternateDataStreams: C:\ProgramData\Temp:366EFA1A
AlternateDataStreams: C:\ProgramData\Temp:36ED5C45
AlternateDataStreams: C:\ProgramData\Temp:37207201
AlternateDataStreams: C:\ProgramData\Temp:373E1720
AlternateDataStreams: C:\ProgramData\Temp:374CECA7
AlternateDataStreams: C:\ProgramData\Temp:37C279BE
AlternateDataStreams: C:\ProgramData\Temp:38534D53
AlternateDataStreams: C:\ProgramData\Temp:391535F9
AlternateDataStreams: C:\ProgramData\Temp:394EB021
AlternateDataStreams: C:\ProgramData\Temp:398D2775
AlternateDataStreams: C:\ProgramData\Temp:398EFF0F
AlternateDataStreams: C:\ProgramData\Temp:39DC8D60
AlternateDataStreams: C:\ProgramData\Temp:3A133158
AlternateDataStreams: C:\ProgramData\Temp:3A28C54D
AlternateDataStreams: C:\ProgramData\Temp:3AB569BA
AlternateDataStreams: C:\ProgramData\Temp:3ABC38E6
AlternateDataStreams: C:\ProgramData\Temp:3ADE134E
AlternateDataStreams: C:\ProgramData\Temp:3B633DE9
AlternateDataStreams: C:\ProgramData\Temp:3B71586E
AlternateDataStreams: C:\ProgramData\Temp:3BDF57F4
AlternateDataStreams: C:\ProgramData\Temp:3C8B784A
AlternateDataStreams: C:\ProgramData\Temp:3D1D487A
AlternateDataStreams: C:\ProgramData\Temp:3D3F1635
AlternateDataStreams: C:\ProgramData\Temp:3D507E52
AlternateDataStreams: C:\ProgramData\Temp:3D887DCC
AlternateDataStreams: C:\ProgramData\Temp:3D99ABFE
AlternateDataStreams: C:\ProgramData\Temp:3DB6F365
AlternateDataStreams: C:\ProgramData\Temp:3E8A3E87
AlternateDataStreams: C:\ProgramData\Temp:3FB26DBA
AlternateDataStreams: C:\ProgramData\Temp:3FD69132
AlternateDataStreams: C:\ProgramData\Temp:401CAF8F
AlternateDataStreams: C:\ProgramData\Temp:406E0034
AlternateDataStreams: C:\ProgramData\Temp:410A2E9A
AlternateDataStreams: C:\ProgramData\Temp:415E77AB
AlternateDataStreams: C:\ProgramData\Temp:417C2BC3
AlternateDataStreams: C:\ProgramData\Temp:41CB6858
AlternateDataStreams: C:\ProgramData\Temp:437B1C75
AlternateDataStreams: C:\ProgramData\Temp:44712999
AlternateDataStreams: C:\ProgramData\Temp:447856CD
AlternateDataStreams: C:\ProgramData\Temp:454191C8
AlternateDataStreams: C:\ProgramData\Temp:4548E058
AlternateDataStreams: C:\ProgramData\Temp:45936E12
AlternateDataStreams: C:\ProgramData\Temp:45A64DE6
AlternateDataStreams: C:\ProgramData\Temp:46283136
AlternateDataStreams: C:\ProgramData\Temp:469B47D8
AlternateDataStreams: C:\ProgramData\Temp:46CDAE37
AlternateDataStreams: C:\ProgramData\Temp:46EF121E
AlternateDataStreams: C:\ProgramData\Temp:470574B5
AlternateDataStreams: C:\ProgramData\Temp:4762F1D2
AlternateDataStreams: C:\ProgramData\Temp:48862C37
AlternateDataStreams: C:\ProgramData\Temp:489EA5E5
AlternateDataStreams: C:\ProgramData\Temp:48D6EA0F
AlternateDataStreams: C:\ProgramData\Temp:498B5975
AlternateDataStreams: C:\ProgramData\Temp:49EA4410
AlternateDataStreams: C:\ProgramData\Temp:4A448DB2
AlternateDataStreams: C:\ProgramData\Temp:4A5CFD3B
AlternateDataStreams: C:\ProgramData\Temp:4A8EB1C4
AlternateDataStreams: C:\ProgramData\Temp:4A906D4A
AlternateDataStreams: C:\ProgramData\Temp:4AA3DAA3
AlternateDataStreams: C:\ProgramData\Temp:4B6A9FDA
AlternateDataStreams: C:\ProgramData\Temp:4B7C28B1
AlternateDataStreams: C:\ProgramData\Temp:4B8122EA
AlternateDataStreams: C:\ProgramData\Temp:4C3B92C7
AlternateDataStreams: C:\ProgramData\Temp:4C5C1DD3
AlternateDataStreams: C:\ProgramData\Temp:4CFC5F70
AlternateDataStreams: C:\ProgramData\Temp:4D51EA2B
AlternateDataStreams: C:\ProgramData\Temp:4D6B6072
AlternateDataStreams: C:\ProgramData\Temp:4D8FCBEF
AlternateDataStreams: C:\ProgramData\Temp:4DCAC4BC
AlternateDataStreams: C:\ProgramData\Temp:4E79C4F8
AlternateDataStreams: C:\ProgramData\Temp:4EA002DF
AlternateDataStreams: C:\ProgramData\Temp:4EE95FE7
AlternateDataStreams: C:\ProgramData\Temp:4EFA2FC7
AlternateDataStreams: C:\ProgramData\Temp:4F49DA66
AlternateDataStreams: C:\ProgramData\Temp:4F852702
AlternateDataStreams: C:\ProgramData\Temp:4F8B72C9
AlternateDataStreams: C:\ProgramData\Temp:4FD3435F
AlternateDataStreams: C:\ProgramData\Temp:5008417E
AlternateDataStreams: C:\ProgramData\Temp:506698B2
AlternateDataStreams: C:\ProgramData\Temp:50868536
AlternateDataStreams: C:\ProgramData\Temp:5106F19A
AlternateDataStreams: C:\ProgramData\Temp:5164A01F
AlternateDataStreams: C:\ProgramData\Temp:517DBC32
AlternateDataStreams: C:\ProgramData\Temp:51A20D23
AlternateDataStreams: C:\ProgramData\Temp:51E66512
AlternateDataStreams: C:\ProgramData\Temp:52641FBE
AlternateDataStreams: C:\ProgramData\Temp:52C24010
AlternateDataStreams: C:\ProgramData\Temp:53F09A92
AlternateDataStreams: C:\ProgramData\Temp:5412DFA4
AlternateDataStreams: C:\ProgramData\Temp:54403233
AlternateDataStreams: C:\ProgramData\Temp:5453E5AF
AlternateDataStreams: C:\ProgramData\Temp:54AF9997
AlternateDataStreams: C:\ProgramData\Temp:54F0BBF5
AlternateDataStreams: C:\ProgramData\Temp:550E7893
AlternateDataStreams: C:\ProgramData\Temp:55374FBA
AlternateDataStreams: C:\ProgramData\Temp:5559517D
AlternateDataStreams: C:\ProgramData\Temp:55818279
AlternateDataStreams: C:\ProgramData\Temp:55BB2521
AlternateDataStreams: C:\ProgramData\Temp:561B1D2B
AlternateDataStreams: C:\ProgramData\Temp:57DFBE4E
AlternateDataStreams: C:\ProgramData\Temp:58447932
AlternateDataStreams: C:\ProgramData\Temp:587F3582
AlternateDataStreams: C:\ProgramData\Temp:58B3FE52
AlternateDataStreams: C:\ProgramData\Temp:597254A1
AlternateDataStreams: C:\ProgramData\Temp:59A6876B
AlternateDataStreams: C:\ProgramData\Temp:59C64924
AlternateDataStreams: C:\ProgramData\Temp:5A068EE1
AlternateDataStreams: C:\ProgramData\Temp:5A9F1AE5
AlternateDataStreams: C:\ProgramData\Temp:5ACE199E
AlternateDataStreams: C:\ProgramData\Temp:5B483FBC
AlternateDataStreams: C:\ProgramData\Temp:5BF8F61F
AlternateDataStreams: C:\ProgramData\Temp:5C28E25F
AlternateDataStreams: C:\ProgramData\Temp:5C353220
AlternateDataStreams: C:\ProgramData\Temp:5C3637D2
AlternateDataStreams: C:\ProgramData\Temp:5C3ED5BB
AlternateDataStreams: C:\ProgramData\Temp:5C42F64A
AlternateDataStreams: C:\ProgramData\Temp:5C5F2761
AlternateDataStreams: C:\ProgramData\Temp:5C9A6C78
AlternateDataStreams: C:\ProgramData\Temp:5CBA5665
AlternateDataStreams: C:\ProgramData\Temp:5D351BC6
AlternateDataStreams: C:\ProgramData\Temp:5D570144
AlternateDataStreams: C:\ProgramData\Temp:5DB36C47
AlternateDataStreams: C:\ProgramData\Temp:5E209A50
AlternateDataStreams: C:\ProgramData\Temp:5E481579
AlternateDataStreams: C:\ProgramData\Temp:605645B0
AlternateDataStreams: C:\ProgramData\Temp:607A99D7
AlternateDataStreams: C:\ProgramData\Temp:60E755E6
AlternateDataStreams: C:\ProgramData\Temp:611EAF9F
AlternateDataStreams: C:\ProgramData\Temp:61C53F55
AlternateDataStreams: C:\ProgramData\Temp:624A6897
AlternateDataStreams: C:\ProgramData\Temp:629F8518
AlternateDataStreams: C:\ProgramData\Temp:63BA523E
AlternateDataStreams: C:\ProgramData\Temp:63C48B80
AlternateDataStreams: C:\ProgramData\Temp:6407DD2D
AlternateDataStreams: C:\ProgramData\Temp:641A21EA
AlternateDataStreams: C:\ProgramData\Temp:64E05835
AlternateDataStreams: C:\ProgramData\Temp:65484F45
AlternateDataStreams: C:\ProgramData\Temp:669AB5E1
AlternateDataStreams: C:\ProgramData\Temp:66C764F5
AlternateDataStreams: C:\ProgramData\Temp:66F19688
AlternateDataStreams: C:\ProgramData\Temp:66F7E5A9
AlternateDataStreams: C:\ProgramData\Temp:674893F9
AlternateDataStreams: C:\ProgramData\Temp:67B6E7FA
AlternateDataStreams: C:\ProgramData\Temp:67E674B0
AlternateDataStreams: C:\ProgramData\Temp:680F6474
AlternateDataStreams: C:\ProgramData\Temp:68DE552E
AlternateDataStreams: C:\ProgramData\Temp:697DDE2B
AlternateDataStreams: C:\ProgramData\Temp:699EFEED
AlternateDataStreams: C:\ProgramData\Temp:69F562A6
AlternateDataStreams: C:\ProgramData\Temp:6A0A47E7
AlternateDataStreams: C:\ProgramData\Temp:6A4DFD85
AlternateDataStreams: C:\ProgramData\Temp:6A6D4AF4
AlternateDataStreams: C:\ProgramData\Temp:6A9CA6CB
AlternateDataStreams: C:\ProgramData\Temp:6AD65294
AlternateDataStreams: C:\ProgramData\Temp:6AF6BB0E
AlternateDataStreams: C:\ProgramData\Temp:6B709AD7
AlternateDataStreams: C:\ProgramData\Temp:6BEADDC0
AlternateDataStreams: C:\ProgramData\Temp:6C15BEAD
AlternateDataStreams: C:\ProgramData\Temp:6C74C778
AlternateDataStreams: C:\ProgramData\Temp:6CF828C2
AlternateDataStreams: C:\ProgramData\Temp:6D208D7A
AlternateDataStreams: C:\ProgramData\Temp:6DA9822F
AlternateDataStreams: C:\ProgramData\Temp:6DDBB86B
AlternateDataStreams: C:\ProgramData\Temp:6E39144C
AlternateDataStreams: C:\ProgramData\Temp:6EFFF8B9
AlternateDataStreams: C:\ProgramData\Temp:6F39FFF1
AlternateDataStreams: C:\ProgramData\Temp:70989864
AlternateDataStreams: C:\ProgramData\Temp:709E81D4
AlternateDataStreams: C:\ProgramData\Temp:72449E7D
AlternateDataStreams: C:\ProgramData\Temp:7247FE29
AlternateDataStreams: C:\ProgramData\Temp:7254CF01
AlternateDataStreams: C:\ProgramData\Temp:72C99D4E
AlternateDataStreams: C:\ProgramData\Temp:72E5CC07
AlternateDataStreams: C:\ProgramData\Temp:747457CF
AlternateDataStreams: C:\ProgramData\Temp:762408BA
AlternateDataStreams: C:\ProgramData\Temp:76682252
AlternateDataStreams: C:\ProgramData\Temp:7687A3E3
AlternateDataStreams: C:\ProgramData\Temp:795F6DEC
AlternateDataStreams: C:\ProgramData\Temp:79A7F369
AlternateDataStreams: C:\ProgramData\Temp:7A530D80
AlternateDataStreams: C:\ProgramData\Temp:7B9BB187
AlternateDataStreams: C:\ProgramData\Temp:7BE5BAAB
AlternateDataStreams: C:\ProgramData\Temp:7C27C41C
AlternateDataStreams: C:\ProgramData\Temp:7C3760E2
AlternateDataStreams: C:\ProgramData\Temp:7C5E403A
AlternateDataStreams: C:\ProgramData\Temp:7D938C9B
AlternateDataStreams: C:\ProgramData\Temp:7D9B1030
AlternateDataStreams: C:\ProgramData\Temp:7E0B06B5
AlternateDataStreams: C:\ProgramData\Temp:7E47A57F
AlternateDataStreams: C:\ProgramData\Temp:7E802BFF
AlternateDataStreams: C:\ProgramData\Temp:7EB93F0E
AlternateDataStreams: C:\ProgramData\Temp:7F477B0D
AlternateDataStreams: C:\ProgramData\Temp:7F4D8125
AlternateDataStreams: C:\ProgramData\Temp:7FD8AECC
AlternateDataStreams: C:\ProgramData\Temp:80974241
AlternateDataStreams: C:\ProgramData\Temp:80FA23CA
AlternateDataStreams: C:\ProgramData\Temp:8118F1F5
AlternateDataStreams: C:\ProgramData\Temp:823606DE
AlternateDataStreams: C:\ProgramData\Temp:82756AB7
AlternateDataStreams: C:\ProgramData\Temp:82D85D00
AlternateDataStreams: C:\ProgramData\Temp:8318A814
AlternateDataStreams: C:\ProgramData\Temp:83517407
AlternateDataStreams: C:\ProgramData\Temp:839A89FC
AlternateDataStreams: C:\ProgramData\Temp:8401B6D5
AlternateDataStreams: C:\ProgramData\Temp:841E0E1B
AlternateDataStreams: C:\ProgramData\Temp:8435AD8C
AlternateDataStreams: C:\ProgramData\Temp:843D8419
AlternateDataStreams: C:\ProgramData\Temp:852F2262
AlternateDataStreams: C:\ProgramData\Temp:860356DC
AlternateDataStreams: C:\ProgramData\Temp:864881BF
AlternateDataStreams: C:\ProgramData\Temp:865F21BF
AlternateDataStreams: C:\ProgramData\Temp:86A7B7DD
AlternateDataStreams: C:\ProgramData\Temp:86B6EFD4
AlternateDataStreams: C:\ProgramData\Temp:871526BA
AlternateDataStreams: C:\ProgramData\Temp:8751B175
AlternateDataStreams: C:\ProgramData\Temp:8836A712
AlternateDataStreams: C:\ProgramData\Temp:884C7316
AlternateDataStreams: C:\ProgramData\Temp:8866C899
AlternateDataStreams: C:\ProgramData\Temp:88AFFAC5
AlternateDataStreams: C:\ProgramData\Temp:88C5973F
AlternateDataStreams: C:\ProgramData\Temp:88FB7F72
AlternateDataStreams: C:\ProgramData\Temp:8A620099
AlternateDataStreams: C:\ProgramData\Temp:8B076EC5
AlternateDataStreams: C:\ProgramData\Temp:8B480195
AlternateDataStreams: C:\ProgramData\Temp:8C3C65BE
AlternateDataStreams: C:\ProgramData\Temp:8C84E358
AlternateDataStreams: C:\ProgramData\Temp:8C8D234C
AlternateDataStreams: C:\ProgramData\Temp:8D335A79
AlternateDataStreams: C:\ProgramData\Temp:8D565A9B
AlternateDataStreams: C:\ProgramData\Temp:8DBCF585
AlternateDataStreams: C:\ProgramData\Temp:8DC0DCD2
AlternateDataStreams: C:\ProgramData\Temp:8E11CC80
AlternateDataStreams: C:\ProgramData\Temp:8E3E8227
AlternateDataStreams: C:\ProgramData\Temp:8F1B55BE
AlternateDataStreams: C:\ProgramData\Temp:90BDAE7B
AlternateDataStreams: C:\ProgramData\Temp:91FE43FF
AlternateDataStreams: C:\ProgramData\Temp:9254F782
AlternateDataStreams: C:\ProgramData\Temp:927EC486
AlternateDataStreams: C:\ProgramData\Temp:92BD9737
AlternateDataStreams: C:\ProgramData\Temp:92C8CBEF
AlternateDataStreams: C:\ProgramData\Temp:92CA7E75
AlternateDataStreams: C:\ProgramData\Temp:92D35C13
AlternateDataStreams: C:\ProgramData\Temp:933D54A9
AlternateDataStreams: C:\ProgramData\Temp:938EB9FC
AlternateDataStreams: C:\ProgramData\Temp:9491C9C7
AlternateDataStreams: C:\ProgramData\Temp:94A31742
AlternateDataStreams: C:\ProgramData\Temp:94B25DF5
AlternateDataStreams: C:\ProgramData\Temp:94BD36A2
AlternateDataStreams: C:\ProgramData\Temp:952245B1
AlternateDataStreams: C:\ProgramData\Temp:9524D821
AlternateDataStreams: C:\ProgramData\Temp:95E8BA2F
AlternateDataStreams: C:\ProgramData\Temp:968F624D
AlternateDataStreams: C:\ProgramData\Temp:97427454
AlternateDataStreams: C:\ProgramData\Temp:97AAB7F2
AlternateDataStreams: C:\ProgramData\Temp:97BDBF49
AlternateDataStreams: C:\ProgramData\Temp:97C9EF7E
AlternateDataStreams: C:\ProgramData\Temp:9836B5E4
AlternateDataStreams: C:\ProgramData\Temp:98BD93BF
AlternateDataStreams: C:\ProgramData\Temp:98CF1A39
AlternateDataStreams: C:\ProgramData\Temp:991283D0
AlternateDataStreams: C:\ProgramData\Temp:99515FFA
AlternateDataStreams: C:\ProgramData\Temp:996104FC
AlternateDataStreams: C:\ProgramData\Temp:9968F0E2
AlternateDataStreams: C:\ProgramData\Temp:9AC8424E
AlternateDataStreams: C:\ProgramData\Temp:9ACC5E2D
AlternateDataStreams: C:\ProgramData\Temp:9CD7CD43
AlternateDataStreams: C:\ProgramData\Temp:9CE870B8
AlternateDataStreams: C:\ProgramData\Temp:9D0A16E4
AlternateDataStreams: C:\ProgramData\Temp:9E3D44B7
AlternateDataStreams: C:\ProgramData\Temp:9E410D29
AlternateDataStreams: C:\ProgramData\Temp:9E5EA7A3
AlternateDataStreams: C:\ProgramData\Temp:9F38BF31
AlternateDataStreams: C:\ProgramData\Temp:9F3CEEE6
AlternateDataStreams: C:\ProgramData\Temp:9F6E8CED
AlternateDataStreams: C:\ProgramData\Temp:A015B193
AlternateDataStreams: C:\ProgramData\Temp:A0921B2C
AlternateDataStreams: C:\ProgramData\Temp:A19DFC74
AlternateDataStreams: C:\ProgramData\Temp:A1FD5369
AlternateDataStreams: C:\ProgramData\Temp:A26C6E72
AlternateDataStreams: C:\ProgramData\Temp:A291068E
AlternateDataStreams: C:\ProgramData\Temp:A391510C
AlternateDataStreams: C:\ProgramData\Temp:A4241298
AlternateDataStreams: C:\ProgramData\Temp:A42B5698
AlternateDataStreams: C:\ProgramData\Temp:A477045F
AlternateDataStreams: C:\ProgramData\Temp:A4B4192F
AlternateDataStreams: C:\ProgramData\Temp:A4E7D25F
AlternateDataStreams: C:\ProgramData\Temp:A52D07E2
AlternateDataStreams: C:\ProgramData\Temp:A673F81E
AlternateDataStreams: C:\ProgramData\Temp:A6E01F67
AlternateDataStreams: C:\ProgramData\Temp:A6F28514
AlternateDataStreams: C:\ProgramData\Temp:A6FE7BCC
AlternateDataStreams: C:\ProgramData\Temp:A73595DE
AlternateDataStreams: C:\ProgramData\Temp:A76A1B1B
AlternateDataStreams: C:\ProgramData\Temp:A78B31DD
AlternateDataStreams: C:\ProgramData\Temp:A798AA1A
AlternateDataStreams: C:\ProgramData\Temp:A7C40691
AlternateDataStreams: C:\ProgramData\Temp:A8185163
AlternateDataStreams: C:\ProgramData\Temp:A819A132
AlternateDataStreams: C:\ProgramData\Temp:A8369371
AlternateDataStreams: C:\ProgramData\Temp:A88BE334
AlternateDataStreams: C:\ProgramData\Temp:A9223B61
AlternateDataStreams: C:\ProgramData\Temp:A9F13D2D
AlternateDataStreams: C:\ProgramData\Temp:AA5A61B2
AlternateDataStreams: C:\ProgramData\Temp:AA632E81
AlternateDataStreams: C:\ProgramData\Temp:AB0A5A80
AlternateDataStreams: C:\ProgramData\Temp:ABBFFEA2
AlternateDataStreams: C:\ProgramData\Temp:AD179392
AlternateDataStreams: C:\ProgramData\Temp:AD2DB2F9
AlternateDataStreams: C:\ProgramData\Temp:AD7BB754
AlternateDataStreams: C:\ProgramData\Temp:AE0B4487
AlternateDataStreams: C:\ProgramData\Temp:AE324BE5
AlternateDataStreams: C:\ProgramData\Temp:AEC59117
AlternateDataStreams: C:\ProgramData\Temp:AF2F9D4A
AlternateDataStreams: C:\ProgramData\Temp:AF465248
AlternateDataStreams: C:\ProgramData\Temp:AF841BA9
AlternateDataStreams: C:\ProgramData\Temp:AFB89C92
AlternateDataStreams: C:\ProgramData\Temp:B01EC114
AlternateDataStreams: C:\ProgramData\Temp:B0729CDB
AlternateDataStreams: C:\ProgramData\Temp:B21F2857
AlternateDataStreams: C:\ProgramData\Temp:B2735F9E
AlternateDataStreams: C:\ProgramData\Temp:B2CCDB69
AlternateDataStreams: C:\ProgramData\Temp:B2DC8D6B
AlternateDataStreams: C:\ProgramData\Temp:B317D7ED
AlternateDataStreams: C:\ProgramData\Temp:B328A983
AlternateDataStreams: C:\ProgramData\Temp:B33464A5
AlternateDataStreams: C:\ProgramData\Temp:B38BEEEE
AlternateDataStreams: C:\ProgramData\Temp:B392E17F
AlternateDataStreams: C:\ProgramData\Temp:B50D8729
AlternateDataStreams: C:\ProgramData\Temp:B54E4B5A
AlternateDataStreams: C:\ProgramData\Temp:B5FD4AA1
AlternateDataStreams: C:\ProgramData\Temp:B69CF390
AlternateDataStreams: C:\ProgramData\Temp:B6E58523
AlternateDataStreams: C:\ProgramData\Temp:B74BD6BF
AlternateDataStreams: C:\ProgramData\Temp:B7B127A5
AlternateDataStreams: C:\ProgramData\Temp:B88DC997
AlternateDataStreams: C:\ProgramData\Temp:B8EB1B99
AlternateDataStreams: C:\ProgramData\Temp:B961095A
AlternateDataStreams: C:\ProgramData\Temp:B9A99598
AlternateDataStreams: C:\ProgramData\Temp:B9C6EB6C
AlternateDataStreams: C:\ProgramData\Temp:BABCFD54
AlternateDataStreams: C:\ProgramData\Temp:BB99F46B
AlternateDataStreams: C:\ProgramData\Temp:BBC9C1EB
AlternateDataStreams: C:\ProgramData\Temp:BC8E9899
AlternateDataStreams: C:\ProgramData\Temp:BCF55336
AlternateDataStreams: C:\ProgramData\Temp:BD0A043E
AlternateDataStreams: C:\ProgramData\Temp:BD414E4B
AlternateDataStreams: C:\ProgramData\Temp:BD84F7D6
AlternateDataStreams: C:\ProgramData\Temp:BDDA21B6
AlternateDataStreams: C:\ProgramData\Temp:BEE39E9B
AlternateDataStreams: C:\ProgramData\Temp:BEF18713
AlternateDataStreams: C:\ProgramData\Temp:BF1E0621
AlternateDataStreams: C:\ProgramData\Temp:BF6C4AAC
AlternateDataStreams: C:\ProgramData\Temp:C00C7190
AlternateDataStreams: C:\ProgramData\Temp:C0BCE04B
AlternateDataStreams: C:\ProgramData\Temp:C0D23A2F
AlternateDataStreams: C:\ProgramData\Temp:C10635F6
AlternateDataStreams: C:\ProgramData\Temp:C1D3D9A3
AlternateDataStreams: C:\ProgramData\Temp:C22FB597
AlternateDataStreams: C:\ProgramData\Temp:C370B84F
AlternateDataStreams: C:\ProgramData\Temp:C3899C0B
AlternateDataStreams: C:\ProgramData\Temp:C3E7F2E9
AlternateDataStreams: C:\ProgramData\Temp:C48A983C
AlternateDataStreams: C:\ProgramData\Temp:C4A88D6B
AlternateDataStreams: C:\ProgramData\Temp:C4C09E44
AlternateDataStreams: C:\ProgramData\Temp:C5340FA1
AlternateDataStreams: C:\ProgramData\Temp:C55217E2
AlternateDataStreams: C:\ProgramData\Temp:C5A156B6
AlternateDataStreams: C:\ProgramData\Temp:C5D15631
AlternateDataStreams: C:\ProgramData\Temp:C6104C4F
AlternateDataStreams: C:\ProgramData\Temp:C669F3E1
AlternateDataStreams: C:\ProgramData\Temp:C76CFF82
AlternateDataStreams: C:\ProgramData\Temp:C76D8487
AlternateDataStreams: C:\ProgramData\Temp:C77802D8
AlternateDataStreams: C:\ProgramData\Temp:C7D35E8C
AlternateDataStreams: C:\ProgramData\Temp:C82CA1C0
AlternateDataStreams: C:\ProgramData\Temp:C89D1773
AlternateDataStreams: C:\ProgramData\Temp:C8E3A625
AlternateDataStreams: C:\ProgramData\Temp:C900B47A
AlternateDataStreams: C:\ProgramData\Temp:C98828D3
AlternateDataStreams: C:\ProgramData\Temp:CA1AFE85
AlternateDataStreams: C:\ProgramData\Temp:CB08ED9D
AlternateDataStreams: C:\ProgramData\Temp:CB3667AF
AlternateDataStreams: C:\ProgramData\Temp:CB5AA1E6
AlternateDataStreams: C:\ProgramData\Temp:CCB49694
AlternateDataStreams: C:\ProgramData\Temp:CCD8056E
AlternateDataStreams: C:\ProgramData\Temp:CDCDE97C
AlternateDataStreams: C:\ProgramData\Temp:CE3AADB7
AlternateDataStreams: C:\ProgramData\Temp:CF8AEC6E
AlternateDataStreams: C:\ProgramData\Temp:CFE19728
AlternateDataStreams: C:\ProgramData\Temp:D0005E5A
AlternateDataStreams: C:\ProgramData\Temp:D103E81E
AlternateDataStreams: C:\ProgramData\Temp:D1FE35E7
AlternateDataStreams: C:\ProgramData\Temp:D276CDF4
AlternateDataStreams: C:\ProgramData\Temp:D3A89E47
AlternateDataStreams: C:\ProgramData\Temp:D434342F
AlternateDataStreams: C:\ProgramData\Temp:D4DD372D
AlternateDataStreams: C:\ProgramData\Temp:D4E62FA9
AlternateDataStreams: C:\ProgramData\Temp:D4F5419A
AlternateDataStreams: C:\ProgramData\Temp:D5D75FF0
AlternateDataStreams: C:\ProgramData\Temp:D64DD961
AlternateDataStreams: C:\ProgramData\Temp:D6A43EB0
AlternateDataStreams: C:\ProgramData\Temp:D7740E2A
AlternateDataStreams: C:\ProgramData\Temp:D92A5893
AlternateDataStreams: C:\ProgramData\Temp:DA378DD8
AlternateDataStreams: C:\ProgramData\Temp:DA55B48C
AlternateDataStreams: C:\ProgramData\Temp:DB76C881
AlternateDataStreams: C:\ProgramData\Temp:DBB979D4
AlternateDataStreams: C:\ProgramData\Temp:DBC3D477
AlternateDataStreams: C:\ProgramData\Temp:DBE31BCC
AlternateDataStreams: C:\ProgramData\Temp:DBEF355E
AlternateDataStreams: C:\ProgramData\Temp:DC8E5CD4
AlternateDataStreams: C:\ProgramData\Temp:DC9915D2
AlternateDataStreams: C:\ProgramData\Temp:DD04902E
AlternateDataStreams: C:\ProgramData\Temp:DDE3F219
AlternateDataStreams: C:\ProgramData\Temp:DE0BD04E
AlternateDataStreams: C:\ProgramData\Temp:DE3ABE3D
AlternateDataStreams: C:\ProgramData\Temp:DE875C30
AlternateDataStreams: C:\ProgramData\Temp:DF2F7240
AlternateDataStreams: C:\ProgramData\Temp:DF5ABA3D
AlternateDataStreams: C:\ProgramData\Temp:DF5C005A
AlternateDataStreams: C:\ProgramData\Temp:DF7A2D3E
AlternateDataStreams: C:\ProgramData\Temp:DFDBC05C
AlternateDataStreams: C:\ProgramData\Temp:DFFB9E98
AlternateDataStreams: C:\ProgramData\Temp:E0365B26
AlternateDataStreams: C:\ProgramData\Temp:E0CAA39F
AlternateDataStreams: C:\ProgramData\Temp:E11D90D0
AlternateDataStreams: C:\ProgramData\Temp:E14FA16F
AlternateDataStreams: C:\ProgramData\Temp:E1520A02
AlternateDataStreams: C:\ProgramData\Temp:E21987F7
AlternateDataStreams: C:\ProgramData\Temp:E32D2701
AlternateDataStreams: C:\ProgramData\Temp:E3615992
AlternateDataStreams: C:\ProgramData\Temp:E40AB54F
AlternateDataStreams: C:\ProgramData\Temp:E40D7F76
AlternateDataStreams: C:\ProgramData\Temp:E4272706
AlternateDataStreams: C:\ProgramData\Temp:E4FD113F
AlternateDataStreams: C:\ProgramData\Temp:E51234A9
AlternateDataStreams: C:\ProgramData\Temp:E517FE76
AlternateDataStreams: C:\ProgramData\Temp:E5294695
AlternateDataStreams: C:\ProgramData\Temp:E534B4D1
AlternateDataStreams: C:\ProgramData\Temp:E5496666
AlternateDataStreams: C:\ProgramData\Temp:E5AF754F
AlternateDataStreams: C:\ProgramData\Temp:E5B07840
AlternateDataStreams: C:\ProgramData\Temp:E69366D6
AlternateDataStreams: C:\ProgramData\Temp:E6CDFB4A
AlternateDataStreams: C:\ProgramData\Temp:E7B4296D
AlternateDataStreams: C:\ProgramData\Temp:E87AB4E3
AlternateDataStreams: C:\ProgramData\Temp:E894A3ED
AlternateDataStreams: C:\ProgramData\Temp:E8BE0B80
AlternateDataStreams: C:\ProgramData\Temp:E8C44CB4
AlternateDataStreams: C:\ProgramData\Temp:E9049821
AlternateDataStreams: C:\ProgramData\Temp:E94FA418
AlternateDataStreams: C:\ProgramData\Temp:E96A2658
AlternateDataStreams: C:\ProgramData\Temp:E9C2F553
AlternateDataStreams: C:\ProgramData\Temp:EA10407C
AlternateDataStreams: C:\ProgramData\Temp:EA2D3047
AlternateDataStreams: C:\ProgramData\Temp:EA75C0D4
AlternateDataStreams: C:\ProgramData\Temp:EB4FEEF5
AlternateDataStreams: C:\ProgramData\Temp:EBDA62B1
AlternateDataStreams: C:\ProgramData\Temp:EC752217
AlternateDataStreams: C:\ProgramData\Temp:EC970DB6
AlternateDataStreams: C:\ProgramData\Temp:EDB03249
AlternateDataStreams: C:\ProgramData\Temp:EDF12A30
AlternateDataStreams: C:\ProgramData\Temp:EE2DD6CC
AlternateDataStreams: C:\ProgramData\Temp:EE445D7C
AlternateDataStreams: C:\ProgramData\Temp:EE9B2879
AlternateDataStreams: C:\ProgramData\Temp:EF0BD3A1
AlternateDataStreams: C:\ProgramData\Temp:EF0F3F33
AlternateDataStreams: C:\ProgramData\Temp:EF53A5CA
AlternateDataStreams: C:\ProgramData\Temp:F039D9FE
AlternateDataStreams: C:\ProgramData\Temp:F1174C93
AlternateDataStreams: C:\ProgramData\Temp:F135A76C
AlternateDataStreams: C:\ProgramData\Temp:F13867C6
AlternateDataStreams: C:\ProgramData\Temp:F13DDA30
AlternateDataStreams: C:\ProgramData\Temp:F176B6C6
AlternateDataStreams: C:\ProgramData\Temp:F193BFCF
AlternateDataStreams: C:\ProgramData\Temp:F2E878EB
AlternateDataStreams: C:\ProgramData\Temp:F2E92DCD
AlternateDataStreams: C:\ProgramData\Temp:F2F0A8AC
AlternateDataStreams: C:\ProgramData\Temp:F3A185AE
AlternateDataStreams: C:\ProgramData\Temp:F42BB562
AlternateDataStreams: C:\ProgramData\Temp:F437A62A
AlternateDataStreams: C:\ProgramData\Temp:F49868C8
AlternateDataStreams: C:\ProgramData\Temp:F4BF61E8
AlternateDataStreams: C:\ProgramData\Temp:F5082CD2
AlternateDataStreams: C:\ProgramData\Temp:F56BE392
AlternateDataStreams: C:\ProgramData\Temp:F66F0A25
AlternateDataStreams: C:\ProgramData\Temp:F74EC668
AlternateDataStreams: C:\ProgramData\Temp:F7F4DC88
AlternateDataStreams: C:\ProgramData\Temp:F816645E
AlternateDataStreams: C:\ProgramData\Temp:F817E159
AlternateDataStreams: C:\ProgramData\Temp:F83E8359
AlternateDataStreams: C:\ProgramData\Temp:F84EC1E0
AlternateDataStreams: C:\ProgramData\Temp:F8F070C2
AlternateDataStreams: C:\ProgramData\Temp:F94DE3B1
AlternateDataStreams: C:\ProgramData\Temp:FA7523FF
AlternateDataStreams: C:\ProgramData\Temp:FAFEC4B9
AlternateDataStreams: C:\ProgramData\Temp:FBD274CF
AlternateDataStreams: C:\ProgramData\Temp:FD4C7AD3
AlternateDataStreams: C:\ProgramData\Temp:FD646198
AlternateDataStreams: C:\ProgramData\Temp:FD6D11C9
AlternateDataStreams: C:\ProgramData\Temp:FD7DCDA6
AlternateDataStreams: C:\ProgramData\Temp:FE1028DD
AlternateDataStreams: C:\ProgramData\Temp:FF717A18
AlternateDataStreams: C:\ProgramData\Temp:FFA396CD
AlternateDataStreams: C:\ProgramData\Temp:FFC3922F

End
Save the files as fixlist.txt into the same folder as FRST

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
p.s.
If the SecurityCheck program fails to run for any reason, run it as an Administrator.

If the site is busy or not available use this mirror site:
http://www.bleepingcomputer.com/download/securitycheck/
===

How is the computer running now?

#6 sepa14

sepa14
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:04:23 AM

Posted 06 October 2014 - 08:49 AM

I followed all the steps given. IE still displays the "proxy server isn't responding" error, and I still cannot uncheck the proxy setting under LAN in options. (It's as if the settings aren't "saved.") I'm guessing the bug, whatever it was, screwed up a setting or even the application itself.

 

Could reinstalling IE possibly solve this? How would I go about that?

 

Computer seems fine otherwise.

 

 

====================FRST Fixlog======================

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-10-2014
Ran by Bonnie at 2014-10-06 08:21:06 Run:1
Running from C:\Users\Bonnie\Downloads
Loaded Profile: Bonnie (Available profiles: Bonnie)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.yahoo.com?fr=hp-avast&type=iedef
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = https://www.yahoo.com?fr=hp-avast&type=iedef
SearchScopes: HKLM-x32 - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - EE693ADA08364CF89C00F0C2930FD8B9 URL = http://findwide.com/serp?guid={B1AA3279-D90A-40B1-81A0-1D7E3283CAD9}&action=default_search&serpv=17&k={searchTerms}
SearchScopes: HKCU - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - {7E669996-6613-4360-8652-77535EBEC57A} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3279141&CUI=UN10012430661249017&SSPV=SP_IEWSP06
SearchScopes: HKCU - {ACA0AFE5-A2E3-4192-B0F1-992B0206D83D} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000031&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=^TV&apn_dtid=^OSJ000^YY^US&apn_uid=E7C71EF5-68DA-4CC0-BE3E-6B023F76CF4F&apn_sauid=7EBD6A66-71A1-430E-859C-998D0C163966
BHO-x32: No Name -> {C6AA1C90-331E-9C00-E122-305F2CF3FEA7} ->  No File
BHO-x32: No Name -> {C8B60FC9-DA76-13C8-285A-C9220CB1516D} ->  No File
BHO-x32: No Name -> {F0C9EBCD-1519-9ABE-E962-ADC22AE53B5B} ->  No File
BHO-x32: No Name -> {fbdff406-2c4c-5d35-8469-34bb67ea3353} ->  No File
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKCU - No Name - {16868B89-775C-4DD4-8C3F-41DDCA66EE5C} -  No File
FF SearchEngineOrder.1: Yahoo! (Avast)
FF Homepage: startpage.com
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @ei.MapsGalaxy_39.com/Plugin -> C:\Program Files (x86)\MapsGalaxy_39EI\Installr\1.bin\NP39EISB.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF SearchPlugin: C:\Users\Bonnie\AppData\Roaming\Mozilla\Firefox\Profiles\io25vpy0.default\searchplugins\yahoo-avast.xml
CHR StartupUrls: Default -> "hxxp://www.mystart.com/?pr=vmn&id=mystarttb&v=5_4&ent=hp_5127&src=5127"
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\afcjaomphinpjpdpojdjjnjgkadnocjk [2013-01-07]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddhnemokmpoejldnghacjmogmbapfhib [2013-01-05]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\dedhnpcpnekemegbgcmkhmlpnflgaggj [2014-04-27]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\kladopbdfkipcnmapgdkjppcahffonfl [2013-01-08]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpfljmigolkmjdoplbnhddjcbedilhah [2013-01-06]
CHR Extension: (No Name) - C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooiopmklfikoifgpamgpnohonfaknofk [2014-04-27]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:008586AE
AlternateDataStreams: C:\ProgramData\Temp:008FE370
AlternateDataStreams: C:\ProgramData\Temp:00D77978
AlternateDataStreams: C:\ProgramData\Temp:00D99749
AlternateDataStreams: C:\ProgramData\Temp:00F3978A
AlternateDataStreams: C:\ProgramData\Temp:012BC84F
AlternateDataStreams: C:\ProgramData\Temp:01F9D1B4
AlternateDataStreams: C:\ProgramData\Temp:0205B36B
AlternateDataStreams: C:\ProgramData\Temp:021496FB
AlternateDataStreams: C:\ProgramData\Temp:021703B2
AlternateDataStreams: C:\ProgramData\Temp:02DD996C
AlternateDataStreams: C:\ProgramData\Temp:036AA5DD
AlternateDataStreams: C:\ProgramData\Temp:041C0562
AlternateDataStreams: C:\ProgramData\Temp:041ED421
AlternateDataStreams: C:\ProgramData\Temp:04A18F36
AlternateDataStreams: C:\ProgramData\Temp:04BC9A2C
AlternateDataStreams: C:\ProgramData\Temp:04D30F4C
AlternateDataStreams: C:\ProgramData\Temp:04EAB86F
AlternateDataStreams: C:\ProgramData\Temp:0588E665
AlternateDataStreams: C:\ProgramData\Temp:06CC3FD3
AlternateDataStreams: C:\ProgramData\Temp:076F9EF8
AlternateDataStreams: C:\ProgramData\Temp:0785072C
AlternateDataStreams: C:\ProgramData\Temp:08767DE0
AlternateDataStreams: C:\ProgramData\Temp:087CB364
AlternateDataStreams: C:\ProgramData\Temp:09064307
AlternateDataStreams: C:\ProgramData\Temp:092BD83A
AlternateDataStreams: C:\ProgramData\Temp:09629F6E
AlternateDataStreams: C:\ProgramData\Temp:097274A2
AlternateDataStreams: C:\ProgramData\Temp:097C4B7D
AlternateDataStreams: C:\ProgramData\Temp:099BA123
AlternateDataStreams: C:\ProgramData\Temp:09AEED56
AlternateDataStreams: C:\ProgramData\Temp:0A701F26
AlternateDataStreams: C:\ProgramData\Temp:0AC0213C
AlternateDataStreams: C:\ProgramData\Temp:0AC32449
AlternateDataStreams: C:\ProgramData\Temp:0AD90625
AlternateDataStreams: C:\ProgramData\Temp:0ADCCF52
AlternateDataStreams: C:\ProgramData\Temp:0B278A1A
AlternateDataStreams: C:\ProgramData\Temp:0B55751B
AlternateDataStreams: C:\ProgramData\Temp:0B79AB8D
AlternateDataStreams: C:\ProgramData\Temp:0B9DC6BB
AlternateDataStreams: C:\ProgramData\Temp:0BBF232A
AlternateDataStreams: C:\ProgramData\Temp:0C2A17F2
AlternateDataStreams: C:\ProgramData\Temp:0C9E06A2
AlternateDataStreams: C:\ProgramData\Temp:0D278FB5
AlternateDataStreams: C:\ProgramData\Temp:0E10B960
AlternateDataStreams: C:\ProgramData\Temp:0EBD727C
AlternateDataStreams: C:\ProgramData\Temp:0F64164E
AlternateDataStreams: C:\ProgramData\Temp:0FAE191E
AlternateDataStreams: C:\ProgramData\Temp:104A1C3E
AlternateDataStreams: C:\ProgramData\Temp:10DB9BB7
AlternateDataStreams: C:\ProgramData\Temp:115EA582
AlternateDataStreams: C:\ProgramData\Temp:11C7FAE3
AlternateDataStreams: C:\ProgramData\Temp:120E44A4
AlternateDataStreams: C:\ProgramData\Temp:128B55C8
AlternateDataStreams: C:\ProgramData\Temp:12BCD9DC
AlternateDataStreams: C:\ProgramData\Temp:12D136AA
AlternateDataStreams: C:\ProgramData\Temp:13019F4B
AlternateDataStreams: C:\ProgramData\Temp:1322DDBD
AlternateDataStreams: C:\ProgramData\Temp:14B2E0BD
AlternateDataStreams: C:\ProgramData\Temp:16777CF9
AlternateDataStreams: C:\ProgramData\Temp:178BD71C
AlternateDataStreams: C:\ProgramData\Temp:186F8A82
AlternateDataStreams: C:\ProgramData\Temp:18A25CF1
AlternateDataStreams: C:\ProgramData\Temp:18B241CC
AlternateDataStreams: C:\ProgramData\Temp:18B5F839
AlternateDataStreams: C:\ProgramData\Temp:18E4BF6C
AlternateDataStreams: C:\ProgramData\Temp:19474103
AlternateDataStreams: C:\ProgramData\Temp:197E3428
AlternateDataStreams: C:\ProgramData\Temp:19F8EB29
AlternateDataStreams: C:\ProgramData\Temp:1A15E356
AlternateDataStreams: C:\ProgramData\Temp:1A259A13
AlternateDataStreams: C:\ProgramData\Temp:1A7FC483
AlternateDataStreams: C:\ProgramData\Temp:1AC933DC
AlternateDataStreams: C:\ProgramData\Temp:1B389835
AlternateDataStreams: C:\ProgramData\Temp:1B7E2022
AlternateDataStreams: C:\ProgramData\Temp:1B8AA588
AlternateDataStreams: C:\ProgramData\Temp:1B96CF22
AlternateDataStreams: C:\ProgramData\Temp:1C6D705B
AlternateDataStreams: C:\ProgramData\Temp:1CF1FB36
AlternateDataStreams: C:\ProgramData\Temp:1D5FADCD
AlternateDataStreams: C:\ProgramData\Temp:1E87A273
AlternateDataStreams: C:\ProgramData\Temp:1EC13383
AlternateDataStreams: C:\ProgramData\Temp:1EEF2E2E
AlternateDataStreams: C:\ProgramData\Temp:1F4F2F80
AlternateDataStreams: C:\ProgramData\Temp:1FF82161
AlternateDataStreams: C:\ProgramData\Temp:2043337E
AlternateDataStreams: C:\ProgramData\Temp:217A2324
AlternateDataStreams: C:\ProgramData\Temp:219DB32E
AlternateDataStreams: C:\ProgramData\Temp:220E9B9E
AlternateDataStreams: C:\ProgramData\Temp:2313511A
AlternateDataStreams: C:\ProgramData\Temp:234E9CC5
AlternateDataStreams: C:\ProgramData\Temp:236FF5C6
AlternateDataStreams: C:\ProgramData\Temp:2433F876
AlternateDataStreams: C:\ProgramData\Temp:24391EC1
AlternateDataStreams: C:\ProgramData\Temp:2636DE16
AlternateDataStreams: C:\ProgramData\Temp:2652902F
AlternateDataStreams: C:\ProgramData\Temp:2680DDD5
AlternateDataStreams: C:\ProgramData\Temp:268BA8AB
AlternateDataStreams: C:\ProgramData\Temp:26991AB9
AlternateDataStreams: C:\ProgramData\Temp:2727F067
AlternateDataStreams: C:\ProgramData\Temp:27A88EF2
AlternateDataStreams: C:\ProgramData\Temp:27D1368B
AlternateDataStreams: C:\ProgramData\Temp:282CE153
AlternateDataStreams: C:\ProgramData\Temp:28DFF83F
AlternateDataStreams: C:\ProgramData\Temp:29EA7E22
AlternateDataStreams: C:\ProgramData\Temp:2A27E0C5
AlternateDataStreams: C:\ProgramData\Temp:2AF322BF
AlternateDataStreams: C:\ProgramData\Temp:2B5C4773
AlternateDataStreams: C:\ProgramData\Temp:2B9555D8
AlternateDataStreams: C:\ProgramData\Temp:2BFBA0B7
AlternateDataStreams: C:\ProgramData\Temp:2C4F33F6
AlternateDataStreams: C:\ProgramData\Temp:2CA4B471
AlternateDataStreams: C:\ProgramData\Temp:2CB9631F
AlternateDataStreams: C:\ProgramData\Temp:2D133896
AlternateDataStreams: C:\ProgramData\Temp:2DC8330D
AlternateDataStreams: C:\ProgramData\Temp:2F0A4DCE
AlternateDataStreams: C:\ProgramData\Temp:2F360FB3
AlternateDataStreams: C:\ProgramData\Temp:2F474C84
AlternateDataStreams: C:\ProgramData\Temp:2F717FB3
AlternateDataStreams: C:\ProgramData\Temp:2F7C40B6
AlternateDataStreams: C:\ProgramData\Temp:2F947175
AlternateDataStreams: C:\ProgramData\Temp:30A9192A
AlternateDataStreams: C:\ProgramData\Temp:319D783D
AlternateDataStreams: C:\ProgramData\Temp:320208DA
AlternateDataStreams: C:\ProgramData\Temp:3241739E
AlternateDataStreams: C:\ProgramData\Temp:329BA65B
AlternateDataStreams: C:\ProgramData\Temp:32D2A239
AlternateDataStreams: C:\ProgramData\Temp:3313A48D
AlternateDataStreams: C:\ProgramData\Temp:3393A1CA
AlternateDataStreams: C:\ProgramData\Temp:33CF835F
AlternateDataStreams: C:\ProgramData\Temp:33E58057
AlternateDataStreams: C:\ProgramData\Temp:3480F458
AlternateDataStreams: C:\ProgramData\Temp:3487C53E
AlternateDataStreams: C:\ProgramData\Temp:35501BA4
AlternateDataStreams: C:\ProgramData\Temp:35E8E596
AlternateDataStreams: C:\ProgramData\Temp:363E775E
AlternateDataStreams: C:\ProgramData\Temp:3651A580
AlternateDataStreams: C:\ProgramData\Temp:366EFA1A
AlternateDataStreams: C:\ProgramData\Temp:36ED5C45
AlternateDataStreams: C:\ProgramData\Temp:37207201
AlternateDataStreams: C:\ProgramData\Temp:373E1720
AlternateDataStreams: C:\ProgramData\Temp:374CECA7
AlternateDataStreams: C:\ProgramData\Temp:37C279BE
AlternateDataStreams: C:\ProgramData\Temp:38534D53
AlternateDataStreams: C:\ProgramData\Temp:391535F9
AlternateDataStreams: C:\ProgramData\Temp:394EB021
AlternateDataStreams: C:\ProgramData\Temp:398D2775
AlternateDataStreams: C:\ProgramData\Temp:398EFF0F
AlternateDataStreams: C:\ProgramData\Temp:39DC8D60
AlternateDataStreams: C:\ProgramData\Temp:3A133158
AlternateDataStreams: C:\ProgramData\Temp:3A28C54D
AlternateDataStreams: C:\ProgramData\Temp:3AB569BA
AlternateDataStreams: C:\ProgramData\Temp:3ABC38E6
AlternateDataStreams: C:\ProgramData\Temp:3ADE134E
AlternateDataStreams: C:\ProgramData\Temp:3B633DE9
AlternateDataStreams: C:\ProgramData\Temp:3B71586E
AlternateDataStreams: C:\ProgramData\Temp:3BDF57F4
AlternateDataStreams: C:\ProgramData\Temp:3C8B784A
AlternateDataStreams: C:\ProgramData\Temp:3D1D487A
AlternateDataStreams: C:\ProgramData\Temp:3D3F1635
AlternateDataStreams: C:\ProgramData\Temp:3D507E52
AlternateDataStreams: C:\ProgramData\Temp:3D887DCC
AlternateDataStreams: C:\ProgramData\Temp:3D99ABFE
AlternateDataStreams: C:\ProgramData\Temp:3DB6F365
AlternateDataStreams: C:\ProgramData\Temp:3E8A3E87
AlternateDataStreams: C:\ProgramData\Temp:3FB26DBA
AlternateDataStreams: C:\ProgramData\Temp:3FD69132
AlternateDataStreams: C:\ProgramData\Temp:401CAF8F
AlternateDataStreams: C:\ProgramData\Temp:406E0034
AlternateDataStreams: C:\ProgramData\Temp:410A2E9A
AlternateDataStreams: C:\ProgramData\Temp:415E77AB
AlternateDataStreams: C:\ProgramData\Temp:417C2BC3
AlternateDataStreams: C:\ProgramData\Temp:41CB6858
AlternateDataStreams: C:\ProgramData\Temp:437B1C75
AlternateDataStreams: C:\ProgramData\Temp:44712999
AlternateDataStreams: C:\ProgramData\Temp:447856CD
AlternateDataStreams: C:\ProgramData\Temp:454191C8
AlternateDataStreams: C:\ProgramData\Temp:4548E058
AlternateDataStreams: C:\ProgramData\Temp:45936E12
AlternateDataStreams: C:\ProgramData\Temp:45A64DE6
AlternateDataStreams: C:\ProgramData\Temp:46283136
AlternateDataStreams: C:\ProgramData\Temp:469B47D8
AlternateDataStreams: C:\ProgramData\Temp:46CDAE37
AlternateDataStreams: C:\ProgramData\Temp:46EF121E
AlternateDataStreams: C:\ProgramData\Temp:470574B5
AlternateDataStreams: C:\ProgramData\Temp:4762F1D2
AlternateDataStreams: C:\ProgramData\Temp:48862C37
AlternateDataStreams: C:\ProgramData\Temp:489EA5E5
AlternateDataStreams: C:\ProgramData\Temp:48D6EA0F
AlternateDataStreams: C:\ProgramData\Temp:498B5975
AlternateDataStreams: C:\ProgramData\Temp:49EA4410
AlternateDataStreams: C:\ProgramData\Temp:4A448DB2
AlternateDataStreams: C:\ProgramData\Temp:4A5CFD3B
AlternateDataStreams: C:\ProgramData\Temp:4A8EB1C4
AlternateDataStreams: C:\ProgramData\Temp:4A906D4A
AlternateDataStreams: C:\ProgramData\Temp:4AA3DAA3
AlternateDataStreams: C:\ProgramData\Temp:4B6A9FDA
AlternateDataStreams: C:\ProgramData\Temp:4B7C28B1
AlternateDataStreams: C:\ProgramData\Temp:4B8122EA
AlternateDataStreams: C:\ProgramData\Temp:4C3B92C7
AlternateDataStreams: C:\ProgramData\Temp:4C5C1DD3
AlternateDataStreams: C:\ProgramData\Temp:4CFC5F70
AlternateDataStreams: C:\ProgramData\Temp:4D51EA2B
AlternateDataStreams: C:\ProgramData\Temp:4D6B6072
AlternateDataStreams: C:\ProgramData\Temp:4D8FCBEF
AlternateDataStreams: C:\ProgramData\Temp:4DCAC4BC
AlternateDataStreams: C:\ProgramData\Temp:4E79C4F8
AlternateDataStreams: C:\ProgramData\Temp:4EA002DF
AlternateDataStreams: C:\ProgramData\Temp:4EE95FE7
AlternateDataStreams: C:\ProgramData\Temp:4EFA2FC7
AlternateDataStreams: C:\ProgramData\Temp:4F49DA66
AlternateDataStreams: C:\ProgramData\Temp:4F852702
AlternateDataStreams: C:\ProgramData\Temp:4F8B72C9
AlternateDataStreams: C:\ProgramData\Temp:4FD3435F
AlternateDataStreams: C:\ProgramData\Temp:5008417E
AlternateDataStreams: C:\ProgramData\Temp:506698B2
AlternateDataStreams: C:\ProgramData\Temp:50868536
AlternateDataStreams: C:\ProgramData\Temp:5106F19A
AlternateDataStreams: C:\ProgramData\Temp:5164A01F
AlternateDataStreams: C:\ProgramData\Temp:517DBC32
AlternateDataStreams: C:\ProgramData\Temp:51A20D23
AlternateDataStreams: C:\ProgramData\Temp:51E66512
AlternateDataStreams: C:\ProgramData\Temp:52641FBE
AlternateDataStreams: C:\ProgramData\Temp:52C24010
AlternateDataStreams: C:\ProgramData\Temp:53F09A92
AlternateDataStreams: C:\ProgramData\Temp:5412DFA4
AlternateDataStreams: C:\ProgramData\Temp:54403233
AlternateDataStreams: C:\ProgramData\Temp:5453E5AF
AlternateDataStreams: C:\ProgramData\Temp:54AF9997
AlternateDataStreams: C:\ProgramData\Temp:54F0BBF5
AlternateDataStreams: C:\ProgramData\Temp:550E7893
AlternateDataStreams: C:\ProgramData\Temp:55374FBA
AlternateDataStreams: C:\ProgramData\Temp:5559517D
AlternateDataStreams: C:\ProgramData\Temp:55818279
AlternateDataStreams: C:\ProgramData\Temp:55BB2521
AlternateDataStreams: C:\ProgramData\Temp:561B1D2B
AlternateDataStreams: C:\ProgramData\Temp:57DFBE4E
AlternateDataStreams: C:\ProgramData\Temp:58447932
AlternateDataStreams: C:\ProgramData\Temp:587F3582
AlternateDataStreams: C:\ProgramData\Temp:58B3FE52
AlternateDataStreams: C:\ProgramData\Temp:597254A1
AlternateDataStreams: C:\ProgramData\Temp:59A6876B
AlternateDataStreams: C:\ProgramData\Temp:59C64924
AlternateDataStreams: C:\ProgramData\Temp:5A068EE1
AlternateDataStreams: C:\ProgramData\Temp:5A9F1AE5
AlternateDataStreams: C:\ProgramData\Temp:5ACE199E
AlternateDataStreams: C:\ProgramData\Temp:5B483FBC
AlternateDataStreams: C:\ProgramData\Temp:5BF8F61F
AlternateDataStreams: C:\ProgramData\Temp:5C28E25F
AlternateDataStreams: C:\ProgramData\Temp:5C353220
AlternateDataStreams: C:\ProgramData\Temp:5C3637D2
AlternateDataStreams: C:\ProgramData\Temp:5C3ED5BB
AlternateDataStreams: C:\ProgramData\Temp:5C42F64A
AlternateDataStreams: C:\ProgramData\Temp:5C5F2761
AlternateDataStreams: C:\ProgramData\Temp:5C9A6C78
AlternateDataStreams: C:\ProgramData\Temp:5CBA5665
AlternateDataStreams: C:\ProgramData\Temp:5D351BC6
AlternateDataStreams: C:\ProgramData\Temp:5D570144
AlternateDataStreams: C:\ProgramData\Temp:5DB36C47
AlternateDataStreams: C:\ProgramData\Temp:5E209A50
AlternateDataStreams: C:\ProgramData\Temp:5E481579
AlternateDataStreams: C:\ProgramData\Temp:605645B0
AlternateDataStreams: C:\ProgramData\Temp:607A99D7
AlternateDataStreams: C:\ProgramData\Temp:60E755E6
AlternateDataStreams: C:\ProgramData\Temp:611EAF9F
AlternateDataStreams: C:\ProgramData\Temp:61C53F55
AlternateDataStreams: C:\ProgramData\Temp:624A6897
AlternateDataStreams: C:\ProgramData\Temp:629F8518
AlternateDataStreams: C:\ProgramData\Temp:63BA523E
AlternateDataStreams: C:\ProgramData\Temp:63C48B80
AlternateDataStreams: C:\ProgramData\Temp:6407DD2D
AlternateDataStreams: C:\ProgramData\Temp:641A21EA
AlternateDataStreams: C:\ProgramData\Temp:64E05835
AlternateDataStreams: C:\ProgramData\Temp:65484F45
AlternateDataStreams: C:\ProgramData\Temp:669AB5E1
AlternateDataStreams: C:\ProgramData\Temp:66C764F5
AlternateDataStreams: C:\ProgramData\Temp:66F19688
AlternateDataStreams: C:\ProgramData\Temp:66F7E5A9
AlternateDataStreams: C:\ProgramData\Temp:674893F9
AlternateDataStreams: C:\ProgramData\Temp:67B6E7FA
AlternateDataStreams: C:\ProgramData\Temp:67E674B0
AlternateDataStreams: C:\ProgramData\Temp:680F6474
AlternateDataStreams: C:\ProgramData\Temp:68DE552E
AlternateDataStreams: C:\ProgramData\Temp:697DDE2B
AlternateDataStreams: C:\ProgramData\Temp:699EFEED
AlternateDataStreams: C:\ProgramData\Temp:69F562A6
AlternateDataStreams: C:\ProgramData\Temp:6A0A47E7
AlternateDataStreams: C:\ProgramData\Temp:6A4DFD85
AlternateDataStreams: C:\ProgramData\Temp:6A6D4AF4
AlternateDataStreams: C:\ProgramData\Temp:6A9CA6CB
AlternateDataStreams: C:\ProgramData\Temp:6AD65294
AlternateDataStreams: C:\ProgramData\Temp:6AF6BB0E
AlternateDataStreams: C:\ProgramData\Temp:6B709AD7
AlternateDataStreams: C:\ProgramData\Temp:6BEADDC0
AlternateDataStreams: C:\ProgramData\Temp:6C15BEAD
AlternateDataStreams: C:\ProgramData\Temp:6C74C778
AlternateDataStreams: C:\ProgramData\Temp:6CF828C2
AlternateDataStreams: C:\ProgramData\Temp:6D208D7A
AlternateDataStreams: C:\ProgramData\Temp:6DA9822F
AlternateDataStreams: C:\ProgramData\Temp:6DDBB86B
AlternateDataStreams: C:\ProgramData\Temp:6E39144C
AlternateDataStreams: C:\ProgramData\Temp:6EFFF8B9
AlternateDataStreams: C:\ProgramData\Temp:6F39FFF1
AlternateDataStreams: C:\ProgramData\Temp:70989864
AlternateDataStreams: C:\ProgramData\Temp:709E81D4
AlternateDataStreams: C:\ProgramData\Temp:72449E7D
AlternateDataStreams: C:\ProgramData\Temp:7247FE29
AlternateDataStreams: C:\ProgramData\Temp:7254CF01
AlternateDataStreams: C:\ProgramData\Temp:72C99D4E
AlternateDataStreams: C:\ProgramData\Temp:72E5CC07
AlternateDataStreams: C:\ProgramData\Temp:747457CF
AlternateDataStreams: C:\ProgramData\Temp:762408BA
AlternateDataStreams: C:\ProgramData\Temp:76682252
AlternateDataStreams: C:\ProgramData\Temp:7687A3E3
AlternateDataStreams: C:\ProgramData\Temp:795F6DEC
AlternateDataStreams: C:\ProgramData\Temp:79A7F369
AlternateDataStreams: C:\ProgramData\Temp:7A530D80
AlternateDataStreams: C:\ProgramData\Temp:7B9BB187
AlternateDataStreams: C:\ProgramData\Temp:7BE5BAAB
AlternateDataStreams: C:\ProgramData\Temp:7C27C41C
AlternateDataStreams: C:\ProgramData\Temp:7C3760E2
AlternateDataStreams: C:\ProgramData\Temp:7C5E403A
AlternateDataStreams: C:\ProgramData\Temp:7D938C9B
AlternateDataStreams: C:\ProgramData\Temp:7D9B1030
AlternateDataStreams: C:\ProgramData\Temp:7E0B06B5
AlternateDataStreams: C:\ProgramData\Temp:7E47A57F
AlternateDataStreams: C:\ProgramData\Temp:7E802BFF
AlternateDataStreams: C:\ProgramData\Temp:7EB93F0E
AlternateDataStreams: C:\ProgramData\Temp:7F477B0D
AlternateDataStreams: C:\ProgramData\Temp:7F4D8125
AlternateDataStreams: C:\ProgramData\Temp:7FD8AECC
AlternateDataStreams: C:\ProgramData\Temp:80974241
AlternateDataStreams: C:\ProgramData\Temp:80FA23CA
AlternateDataStreams: C:\ProgramData\Temp:8118F1F5
AlternateDataStreams: C:\ProgramData\Temp:823606DE
AlternateDataStreams: C:\ProgramData\Temp:82756AB7
AlternateDataStreams: C:\ProgramData\Temp:82D85D00
AlternateDataStreams: C:\ProgramData\Temp:8318A814
AlternateDataStreams: C:\ProgramData\Temp:83517407
AlternateDataStreams: C:\ProgramData\Temp:839A89FC
AlternateDataStreams: C:\ProgramData\Temp:8401B6D5
AlternateDataStreams: C:\ProgramData\Temp:841E0E1B
AlternateDataStreams: C:\ProgramData\Temp:8435AD8C
AlternateDataStreams: C:\ProgramData\Temp:843D8419
AlternateDataStreams: C:\ProgramData\Temp:852F2262
AlternateDataStreams: C:\ProgramData\Temp:860356DC
AlternateDataStreams: C:\ProgramData\Temp:864881BF
AlternateDataStreams: C:\ProgramData\Temp:865F21BF
AlternateDataStreams: C:\ProgramData\Temp:86A7B7DD
AlternateDataStreams: C:\ProgramData\Temp:86B6EFD4
AlternateDataStreams: C:\ProgramData\Temp:871526BA
AlternateDataStreams: C:\ProgramData\Temp:8751B175
AlternateDataStreams: C:\ProgramData\Temp:8836A712
AlternateDataStreams: C:\ProgramData\Temp:884C7316
AlternateDataStreams: C:\ProgramData\Temp:8866C899
AlternateDataStreams: C:\ProgramData\Temp:88AFFAC5
AlternateDataStreams: C:\ProgramData\Temp:88C5973F
AlternateDataStreams: C:\ProgramData\Temp:88FB7F72
AlternateDataStreams: C:\ProgramData\Temp:8A620099
AlternateDataStreams: C:\ProgramData\Temp:8B076EC5
AlternateDataStreams: C:\ProgramData\Temp:8B480195
AlternateDataStreams: C:\ProgramData\Temp:8C3C65BE
AlternateDataStreams: C:\ProgramData\Temp:8C84E358
AlternateDataStreams: C:\ProgramData\Temp:8C8D234C
AlternateDataStreams: C:\ProgramData\Temp:8D335A79
AlternateDataStreams: C:\ProgramData\Temp:8D565A9B
AlternateDataStreams: C:\ProgramData\Temp:8DBCF585
AlternateDataStreams: C:\ProgramData\Temp:8DC0DCD2
AlternateDataStreams: C:\ProgramData\Temp:8E11CC80
AlternateDataStreams: C:\ProgramData\Temp:8E3E8227
AlternateDataStreams: C:\ProgramData\Temp:8F1B55BE
AlternateDataStreams: C:\ProgramData\Temp:90BDAE7B
AlternateDataStreams: C:\ProgramData\Temp:91FE43FF
AlternateDataStreams: C:\ProgramData\Temp:9254F782
AlternateDataStreams: C:\ProgramData\Temp:927EC486
AlternateDataStreams: C:\ProgramData\Temp:92BD9737
AlternateDataStreams: C:\ProgramData\Temp:92C8CBEF
AlternateDataStreams: C:\ProgramData\Temp:92CA7E75
AlternateDataStreams: C:\ProgramData\Temp:92D35C13
AlternateDataStreams: C:\ProgramData\Temp:933D54A9
AlternateDataStreams: C:\ProgramData\Temp:938EB9FC
AlternateDataStreams: C:\ProgramData\Temp:9491C9C7
AlternateDataStreams: C:\ProgramData\Temp:94A31742
AlternateDataStreams: C:\ProgramData\Temp:94B25DF5
AlternateDataStreams: C:\ProgramData\Temp:94BD36A2
AlternateDataStreams: C:\ProgramData\Temp:952245B1
AlternateDataStreams: C:\ProgramData\Temp:9524D821
AlternateDataStreams: C:\ProgramData\Temp:95E8BA2F
AlternateDataStreams: C:\ProgramData\Temp:968F624D
AlternateDataStreams: C:\ProgramData\Temp:97427454
AlternateDataStreams: C:\ProgramData\Temp:97AAB7F2
AlternateDataStreams: C:\ProgramData\Temp:97BDBF49
AlternateDataStreams: C:\ProgramData\Temp:97C9EF7E
AlternateDataStreams: C:\ProgramData\Temp:9836B5E4
AlternateDataStreams: C:\ProgramData\Temp:98BD93BF
AlternateDataStreams: C:\ProgramData\Temp:98CF1A39
AlternateDataStreams: C:\ProgramData\Temp:991283D0
AlternateDataStreams: C:\ProgramData\Temp:99515FFA
AlternateDataStreams: C:\ProgramData\Temp:996104FC
AlternateDataStreams: C:\ProgramData\Temp:9968F0E2
AlternateDataStreams: C:\ProgramData\Temp:9AC8424E
AlternateDataStreams: C:\ProgramData\Temp:9ACC5E2D
AlternateDataStreams: C:\ProgramData\Temp:9CD7CD43
AlternateDataStreams: C:\ProgramData\Temp:9CE870B8
AlternateDataStreams: C:\ProgramData\Temp:9D0A16E4
AlternateDataStreams: C:\ProgramData\Temp:9E3D44B7
AlternateDataStreams: C:\ProgramData\Temp:9E410D29
AlternateDataStreams: C:\ProgramData\Temp:9E5EA7A3
AlternateDataStreams: C:\ProgramData\Temp:9F38BF31
AlternateDataStreams: C:\ProgramData\Temp:9F3CEEE6
AlternateDataStreams: C:\ProgramData\Temp:9F6E8CED
AlternateDataStreams: C:\ProgramData\Temp:A015B193
AlternateDataStreams: C:\ProgramData\Temp:A0921B2C
AlternateDataStreams: C:\ProgramData\Temp:A19DFC74
AlternateDataStreams: C:\ProgramData\Temp:A1FD5369
AlternateDataStreams: C:\ProgramData\Temp:A26C6E72
AlternateDataStreams: C:\ProgramData\Temp:A291068E
AlternateDataStreams: C:\ProgramData\Temp:A391510C
AlternateDataStreams: C:\ProgramData\Temp:A4241298
AlternateDataStreams: C:\ProgramData\Temp:A42B5698
AlternateDataStreams: C:\ProgramData\Temp:A477045F
AlternateDataStreams: C:\ProgramData\Temp:A4B4192F
AlternateDataStreams: C:\ProgramData\Temp:A4E7D25F
AlternateDataStreams: C:\ProgramData\Temp:A52D07E2
AlternateDataStreams: C:\ProgramData\Temp:A673F81E
AlternateDataStreams: C:\ProgramData\Temp:A6E01F67
AlternateDataStreams: C:\ProgramData\Temp:A6F28514
AlternateDataStreams: C:\ProgramData\Temp:A6FE7BCC
AlternateDataStreams: C:\ProgramData\Temp:A73595DE
AlternateDataStreams: C:\ProgramData\Temp:A76A1B1B
AlternateDataStreams: C:\ProgramData\Temp:A78B31DD
AlternateDataStreams: C:\ProgramData\Temp:A798AA1A
AlternateDataStreams: C:\ProgramData\Temp:A7C40691
AlternateDataStreams: C:\ProgramData\Temp:A8185163
AlternateDataStreams: C:\ProgramData\Temp:A819A132
AlternateDataStreams: C:\ProgramData\Temp:A8369371
AlternateDataStreams: C:\ProgramData\Temp:A88BE334
AlternateDataStreams: C:\ProgramData\Temp:A9223B61
AlternateDataStreams: C:\ProgramData\Temp:A9F13D2D
AlternateDataStreams: C:\ProgramData\Temp:AA5A61B2
AlternateDataStreams: C:\ProgramData\Temp:AA632E81
AlternateDataStreams: C:\ProgramData\Temp:AB0A5A80
AlternateDataStreams: C:\ProgramData\Temp:ABBFFEA2
AlternateDataStreams: C:\ProgramData\Temp:AD179392
AlternateDataStreams: C:\ProgramData\Temp:AD2DB2F9
AlternateDataStreams: C:\ProgramData\Temp:AD7BB754
AlternateDataStreams: C:\ProgramData\Temp:AE0B4487
AlternateDataStreams: C:\ProgramData\Temp:AE324BE5
AlternateDataStreams: C:\ProgramData\Temp:AEC59117
AlternateDataStreams: C:\ProgramData\Temp:AF2F9D4A
AlternateDataStreams: C:\ProgramData\Temp:AF465248
AlternateDataStreams: C:\ProgramData\Temp:AF841BA9
AlternateDataStreams: C:\ProgramData\Temp:AFB89C92
AlternateDataStreams: C:\ProgramData\Temp:B01EC114
AlternateDataStreams: C:\ProgramData\Temp:B0729CDB
AlternateDataStreams: C:\ProgramData\Temp:B21F2857
AlternateDataStreams: C:\ProgramData\Temp:B2735F9E
AlternateDataStreams: C:\ProgramData\Temp:B2CCDB69
AlternateDataStreams: C:\ProgramData\Temp:B2DC8D6B
AlternateDataStreams: C:\ProgramData\Temp:B317D7ED
AlternateDataStreams: C:\ProgramData\Temp:B328A983
AlternateDataStreams: C:\ProgramData\Temp:B33464A5
AlternateDataStreams: C:\ProgramData\Temp:B38BEEEE
AlternateDataStreams: C:\ProgramData\Temp:B392E17F
AlternateDataStreams: C:\ProgramData\Temp:B50D8729
AlternateDataStreams: C:\ProgramData\Temp:B54E4B5A
AlternateDataStreams: C:\ProgramData\Temp:B5FD4AA1
AlternateDataStreams: C:\ProgramData\Temp:B69CF390
AlternateDataStreams: C:\ProgramData\Temp:B6E58523
AlternateDataStreams: C:\ProgramData\Temp:B74BD6BF
AlternateDataStreams: C:\ProgramData\Temp:B7B127A5
AlternateDataStreams: C:\ProgramData\Temp:B88DC997
AlternateDataStreams: C:\ProgramData\Temp:B8EB1B99
AlternateDataStreams: C:\ProgramData\Temp:B961095A
AlternateDataStreams: C:\ProgramData\Temp:B9A99598
AlternateDataStreams: C:\ProgramData\Temp:B9C6EB6C
AlternateDataStreams: C:\ProgramData\Temp:BABCFD54
AlternateDataStreams: C:\ProgramData\Temp:BB99F46B
AlternateDataStreams: C:\ProgramData\Temp:BBC9C1EB
AlternateDataStreams: C:\ProgramData\Temp:BC8E9899
AlternateDataStreams: C:\ProgramData\Temp:BCF55336
AlternateDataStreams: C:\ProgramData\Temp:BD0A043E
AlternateDataStreams: C:\ProgramData\Temp:BD414E4B
AlternateDataStreams: C:\ProgramData\Temp:BD84F7D6
AlternateDataStreams: C:\ProgramData\Temp:BDDA21B6
AlternateDataStreams: C:\ProgramData\Temp:BEE39E9B
AlternateDataStreams: C:\ProgramData\Temp:BEF18713
AlternateDataStreams: C:\ProgramData\Temp:BF1E0621
AlternateDataStreams: C:\ProgramData\Temp:BF6C4AAC
AlternateDataStreams: C:\ProgramData\Temp:C00C7190
AlternateDataStreams: C:\ProgramData\Temp:C0BCE04B
AlternateDataStreams: C:\ProgramData\Temp:C0D23A2F
AlternateDataStreams: C:\ProgramData\Temp:C10635F6
AlternateDataStreams: C:\ProgramData\Temp:C1D3D9A3
AlternateDataStreams: C:\ProgramData\Temp:C22FB597
AlternateDataStreams: C:\ProgramData\Temp:C370B84F
AlternateDataStreams: C:\ProgramData\Temp:C3899C0B
AlternateDataStreams: C:\ProgramData\Temp:C3E7F2E9
AlternateDataStreams: C:\ProgramData\Temp:C48A983C
AlternateDataStreams: C:\ProgramData\Temp:C4A88D6B
AlternateDataStreams: C:\ProgramData\Temp:C4C09E44
AlternateDataStreams: C:\ProgramData\Temp:C5340FA1
AlternateDataStreams: C:\ProgramData\Temp:C55217E2
AlternateDataStreams: C:\ProgramData\Temp:C5A156B6
AlternateDataStreams: C:\ProgramData\Temp:C5D15631
AlternateDataStreams: C:\ProgramData\Temp:C6104C4F
AlternateDataStreams: C:\ProgramData\Temp:C669F3E1
AlternateDataStreams: C:\ProgramData\Temp:C76CFF82
AlternateDataStreams: C:\ProgramData\Temp:C76D8487
AlternateDataStreams: C:\ProgramData\Temp:C77802D8
AlternateDataStreams: C:\ProgramData\Temp:C7D35E8C
AlternateDataStreams: C:\ProgramData\Temp:C82CA1C0
AlternateDataStreams: C:\ProgramData\Temp:C89D1773
AlternateDataStreams: C:\ProgramData\Temp:C8E3A625
AlternateDataStreams: C:\ProgramData\Temp:C900B47A
AlternateDataStreams: C:\ProgramData\Temp:C98828D3
AlternateDataStreams: C:\ProgramData\Temp:CA1AFE85
AlternateDataStreams: C:\ProgramData\Temp:CB08ED9D
AlternateDataStreams: C:\ProgramData\Temp:CB3667AF
AlternateDataStreams: C:\ProgramData\Temp:CB5AA1E6
AlternateDataStreams: C:\ProgramData\Temp:CCB49694
AlternateDataStreams: C:\ProgramData\Temp:CCD8056E
AlternateDataStreams: C:\ProgramData\Temp:CDCDE97C
AlternateDataStreams: C:\ProgramData\Temp:CE3AADB7
AlternateDataStreams: C:\ProgramData\Temp:CF8AEC6E
AlternateDataStreams: C:\ProgramData\Temp:CFE19728
AlternateDataStreams: C:\ProgramData\Temp:D0005E5A
AlternateDataStreams: C:\ProgramData\Temp:D103E81E
AlternateDataStreams: C:\ProgramData\Temp:D1FE35E7
AlternateDataStreams: C:\ProgramData\Temp:D276CDF4
AlternateDataStreams: C:\ProgramData\Temp:D3A89E47
AlternateDataStreams: C:\ProgramData\Temp:D434342F
AlternateDataStreams: C:\ProgramData\Temp:D4DD372D
AlternateDataStreams: C:\ProgramData\Temp:D4E62FA9
AlternateDataStreams: C:\ProgramData\Temp:D4F5419A
AlternateDataStreams: C:\ProgramData\Temp:D5D75FF0
AlternateDataStreams: C:\ProgramData\Temp:D64DD961
AlternateDataStreams: C:\ProgramData\Temp:D6A43EB0
AlternateDataStreams: C:\ProgramData\Temp:D7740E2A
AlternateDataStreams: C:\ProgramData\Temp:D92A5893
AlternateDataStreams: C:\ProgramData\Temp:DA378DD8
AlternateDataStreams: C:\ProgramData\Temp:DA55B48C
AlternateDataStreams: C:\ProgramData\Temp:DB76C881
AlternateDataStreams: C:\ProgramData\Temp:DBB979D4
AlternateDataStreams: C:\ProgramData\Temp:DBC3D477
AlternateDataStreams: C:\ProgramData\Temp:DBE31BCC
AlternateDataStreams: C:\ProgramData\Temp:DBEF355E
AlternateDataStreams: C:\ProgramData\Temp:DC8E5CD4
AlternateDataStreams: C:\ProgramData\Temp:DC9915D2
AlternateDataStreams: C:\ProgramData\Temp:DD04902E
AlternateDataStreams: C:\ProgramData\Temp:DDE3F219
AlternateDataStreams: C:\ProgramData\Temp:DE0BD04E
AlternateDataStreams: C:\ProgramData\Temp:DE3ABE3D
AlternateDataStreams: C:\ProgramData\Temp:DE875C30
AlternateDataStreams: C:\ProgramData\Temp:DF2F7240
AlternateDataStreams: C:\ProgramData\Temp:DF5ABA3D
AlternateDataStreams: C:\ProgramData\Temp:DF5C005A
AlternateDataStreams: C:\ProgramData\Temp:DF7A2D3E
AlternateDataStreams: C:\ProgramData\Temp:DFDBC05C
AlternateDataStreams: C:\ProgramData\Temp:DFFB9E98
AlternateDataStreams: C:\ProgramData\Temp:E0365B26
AlternateDataStreams: C:\ProgramData\Temp:E0CAA39F
AlternateDataStreams: C:\ProgramData\Temp:E11D90D0
AlternateDataStreams: C:\ProgramData\Temp:E14FA16F
AlternateDataStreams: C:\ProgramData\Temp:E1520A02
AlternateDataStreams: C:\ProgramData\Temp:E21987F7
AlternateDataStreams: C:\ProgramData\Temp:E32D2701
AlternateDataStreams: C:\ProgramData\Temp:E3615992
AlternateDataStreams: C:\ProgramData\Temp:E40AB54F
AlternateDataStreams: C:\ProgramData\Temp:E40D7F76
AlternateDataStreams: C:\ProgramData\Temp:E4272706
AlternateDataStreams: C:\ProgramData\Temp:E4FD113F
AlternateDataStreams: C:\ProgramData\Temp:E51234A9
AlternateDataStreams: C:\ProgramData\Temp:E517FE76
AlternateDataStreams: C:\ProgramData\Temp:E5294695
AlternateDataStreams: C:\ProgramData\Temp:E534B4D1
AlternateDataStreams: C:\ProgramData\Temp:E5496666
AlternateDataStreams: C:\ProgramData\Temp:E5AF754F
AlternateDataStreams: C:\ProgramData\Temp:E5B07840
AlternateDataStreams: C:\ProgramData\Temp:E69366D6
AlternateDataStreams: C:\ProgramData\Temp:E6CDFB4A
AlternateDataStreams: C:\ProgramData\Temp:E7B4296D
AlternateDataStreams: C:\ProgramData\Temp:E87AB4E3
AlternateDataStreams: C:\ProgramData\Temp:E894A3ED
AlternateDataStreams: C:\ProgramData\Temp:E8BE0B80
AlternateDataStreams: C:\ProgramData\Temp:E8C44CB4
AlternateDataStreams: C:\ProgramData\Temp:E9049821
AlternateDataStreams: C:\ProgramData\Temp:E94FA418
AlternateDataStreams: C:\ProgramData\Temp:E96A2658
AlternateDataStreams: C:\ProgramData\Temp:E9C2F553
AlternateDataStreams: C:\ProgramData\Temp:EA10407C
AlternateDataStreams: C:\ProgramData\Temp:EA2D3047
AlternateDataStreams: C:\ProgramData\Temp:EA75C0D4
AlternateDataStreams: C:\ProgramData\Temp:EB4FEEF5
AlternateDataStreams: C:\ProgramData\Temp:EBDA62B1
AlternateDataStreams: C:\ProgramData\Temp:EC752217
AlternateDataStreams: C:\ProgramData\Temp:EC970DB6
AlternateDataStreams: C:\ProgramData\Temp:EDB03249
AlternateDataStreams: C:\ProgramData\Temp:EDF12A30
AlternateDataStreams: C:\ProgramData\Temp:EE2DD6CC
AlternateDataStreams: C:\ProgramData\Temp:EE445D7C
AlternateDataStreams: C:\ProgramData\Temp:EE9B2879
AlternateDataStreams: C:\ProgramData\Temp:EF0BD3A1
AlternateDataStreams: C:\ProgramData\Temp:EF0F3F33
AlternateDataStreams: C:\ProgramData\Temp:EF53A5CA
AlternateDataStreams: C:\ProgramData\Temp:F039D9FE
AlternateDataStreams: C:\ProgramData\Temp:F1174C93
AlternateDataStreams: C:\ProgramData\Temp:F135A76C
AlternateDataStreams: C:\ProgramData\Temp:F13867C6
AlternateDataStreams: C:\ProgramData\Temp:F13DDA30
AlternateDataStreams: C:\ProgramData\Temp:F176B6C6
AlternateDataStreams: C:\ProgramData\Temp:F193BFCF
AlternateDataStreams: C:\ProgramData\Temp:F2E878EB
AlternateDataStreams: C:\ProgramData\Temp:F2E92DCD
AlternateDataStreams: C:\ProgramData\Temp:F2F0A8AC
AlternateDataStreams: C:\ProgramData\Temp:F3A185AE
AlternateDataStreams: C:\ProgramData\Temp:F42BB562
AlternateDataStreams: C:\ProgramData\Temp:F437A62A
AlternateDataStreams: C:\ProgramData\Temp:F49868C8
AlternateDataStreams: C:\ProgramData\Temp:F4BF61E8
AlternateDataStreams: C:\ProgramData\Temp:F5082CD2
AlternateDataStreams: C:\ProgramData\Temp:F56BE392
AlternateDataStreams: C:\ProgramData\Temp:F66F0A25
AlternateDataStreams: C:\ProgramData\Temp:F74EC668
AlternateDataStreams: C:\ProgramData\Temp:F7F4DC88
AlternateDataStreams: C:\ProgramData\Temp:F816645E
AlternateDataStreams: C:\ProgramData\Temp:F817E159
AlternateDataStreams: C:\ProgramData\Temp:F83E8359
AlternateDataStreams: C:\ProgramData\Temp:F84EC1E0
AlternateDataStreams: C:\ProgramData\Temp:F8F070C2
AlternateDataStreams: C:\ProgramData\Temp:F94DE3B1
AlternateDataStreams: C:\ProgramData\Temp:FA7523FF
AlternateDataStreams: C:\ProgramData\Temp:FAFEC4B9
AlternateDataStreams: C:\ProgramData\Temp:FBD274CF
AlternateDataStreams: C:\ProgramData\Temp:FD4C7AD3
AlternateDataStreams: C:\ProgramData\Temp:FD646198
AlternateDataStreams: C:\ProgramData\Temp:FD6D11C9
AlternateDataStreams: C:\ProgramData\Temp:FD7DCDA6
AlternateDataStreams: C:\ProgramData\Temp:FE1028DD
AlternateDataStreams: C:\ProgramData\Temp:FF717A18
AlternateDataStreams: C:\ProgramData\Temp:FFA396CD
AlternateDataStreams: C:\ProgramData\Temp:FFC3922F

End

*****************

HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\EE693ADA08364CF89C00F0C2930FD8B9" => Key deleted successfully.
"HKCR\CLSID\EE693ADA08364CF89C00F0C2930FD8B9" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => Key deleted successfully.
"HKCR\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7E669996-6613-4360-8652-77535EBEC57A}" => Key deleted successfully.
"HKCR\CLSID\{7E669996-6613-4360-8652-77535EBEC57A}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ACA0AFE5-A2E3-4192-B0F1-992B0206D83D}" => Key deleted successfully.
"HKCR\CLSID\{ACA0AFE5-A2E3-4192-B0F1-992B0206D83D}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C6AA1C90-331E-9C00-E122-305F2CF3FEA7}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{C6AA1C90-331E-9C00-E122-305F2CF3FEA7}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C8B60FC9-DA76-13C8-285A-C9220CB1516D}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{C8B60FC9-DA76-13C8-285A-C9220CB1516D}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0C9EBCD-1519-9ABE-E962-ADC22AE53B5B}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{F0C9EBCD-1519-9ABE-E962-ADC22AE53B5B}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fbdff406-2c4c-5d35-8469-34bb67ea3353}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{fbdff406-2c4c-5d35-8469-34bb67ea3353}" => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully.
"HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully.
"HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{16868B89-775C-4DD4-8C3F-41DDCA66EE5C} => value deleted successfully.
"HKCR\CLSID\{16868B89-775C-4DD4-8C3F-41DDCA66EE5C}" => Key not found.
Firefox SearchEngineOrder.1 deleted successfully.
Firefox homepage deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@ei.MapsGalaxy_39.com/Plugin" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
C:\Users\Bonnie\AppData\Roaming\Mozilla\Firefox\Profiles\io25vpy0.default\searchplugins\yahoo-avast.xml => Moved successfully.
Chrome StartupUrls deleted successfully.
C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\afcjaomphinpjpdpojdjjnjgkadnocjk => Moved successfully.
C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddhnemokmpoejldnghacjmogmbapfhib => Moved successfully.
C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\dedhnpcpnekemegbgcmkhmlpnflgaggj => Moved successfully.
C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\kladopbdfkipcnmapgdkjppcahffonfl => Moved successfully.
C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpfljmigolkmjdoplbnhddjcbedilhah => Moved successfully.
C:\Users\Bonnie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooiopmklfikoifgpamgpnohonfaknofk => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
C:\ProgramData\Temp => ":008586AE" ADS removed successfully.
C:\ProgramData\Temp => ":008FE370" ADS removed successfully.
C:\ProgramData\Temp => ":00D77978" ADS removed successfully.
C:\ProgramData\Temp => ":00D99749" ADS removed successfully.
C:\ProgramData\Temp => ":00F3978A" ADS removed successfully.
C:\ProgramData\Temp => ":012BC84F" ADS removed successfully.
C:\ProgramData\Temp => ":01F9D1B4" ADS removed successfully.
C:\ProgramData\Temp => ":0205B36B" ADS removed successfully.
C:\ProgramData\Temp => ":021496FB" ADS removed successfully.
C:\ProgramData\Temp => ":021703B2" ADS removed successfully.
C:\ProgramData\Temp => ":02DD996C" ADS removed successfully.
C:\ProgramData\Temp => ":036AA5DD" ADS removed successfully.
C:\ProgramData\Temp => ":041C0562" ADS removed successfully.
C:\ProgramData\Temp => ":041ED421" ADS removed successfully.
C:\ProgramData\Temp => ":04A18F36" ADS removed successfully.
C:\ProgramData\Temp => ":04BC9A2C" ADS removed successfully.
C:\ProgramData\Temp => ":04D30F4C" ADS removed successfully.
C:\ProgramData\Temp => ":04EAB86F" ADS removed successfully.
C:\ProgramData\Temp => ":0588E665" ADS removed successfully.
C:\ProgramData\Temp => ":06CC3FD3" ADS removed successfully.
C:\ProgramData\Temp => ":076F9EF8" ADS removed successfully.
C:\ProgramData\Temp => ":0785072C" ADS removed successfully.
C:\ProgramData\Temp => ":08767DE0" ADS removed successfully.
C:\ProgramData\Temp => ":087CB364" ADS removed successfully.
C:\ProgramData\Temp => ":09064307" ADS removed successfully.
C:\ProgramData\Temp => ":092BD83A" ADS removed successfully.
C:\ProgramData\Temp => ":09629F6E" ADS removed successfully.
C:\ProgramData\Temp => ":097274A2" ADS removed successfully.
C:\ProgramData\Temp => ":097C4B7D" ADS removed successfully.
C:\ProgramData\Temp => ":099BA123" ADS removed successfully.
C:\ProgramData\Temp => ":09AEED56" ADS removed successfully.
C:\ProgramData\Temp => ":0A701F26" ADS removed successfully.
C:\ProgramData\Temp => ":0AC0213C" ADS removed successfully.
C:\ProgramData\Temp => ":0AC32449" ADS removed successfully.
C:\ProgramData\Temp => ":0AD90625" ADS removed successfully.
C:\ProgramData\Temp => ":0ADCCF52" ADS removed successfully.
C:\ProgramData\Temp => ":0B278A1A" ADS removed successfully.
C:\ProgramData\Temp => ":0B55751B" ADS removed successfully.
C:\ProgramData\Temp => ":0B79AB8D" ADS removed successfully.
C:\ProgramData\Temp => ":0B9DC6BB" ADS removed successfully.
C:\ProgramData\Temp => ":0BBF232A" ADS removed successfully.
C:\ProgramData\Temp => ":0C2A17F2" ADS removed successfully.
C:\ProgramData\Temp => ":0C9E06A2" ADS removed successfully.
C:\ProgramData\Temp => ":0D278FB5" ADS removed successfully.
C:\ProgramData\Temp => ":0E10B960" ADS removed successfully.
C:\ProgramData\Temp => ":0EBD727C" ADS removed successfully.
C:\ProgramData\Temp => ":0F64164E" ADS removed successfully.
C:\ProgramData\Temp => ":0FAE191E" ADS removed successfully.
C:\ProgramData\Temp => ":104A1C3E" ADS removed successfully.
C:\ProgramData\Temp => ":10DB9BB7" ADS removed successfully.
C:\ProgramData\Temp => ":115EA582" ADS removed successfully.
C:\ProgramData\Temp => ":11C7FAE3" ADS removed successfully.
C:\ProgramData\Temp => ":120E44A4" ADS removed successfully.
C:\ProgramData\Temp => ":128B55C8" ADS removed successfully.
C:\ProgramData\Temp => ":12BCD9DC" ADS removed successfully.
C:\ProgramData\Temp => ":12D136AA" ADS removed successfully.
C:\ProgramData\Temp => ":13019F4B" ADS removed successfully.
C:\ProgramData\Temp => ":1322DDBD" ADS removed successfully.
C:\ProgramData\Temp => ":14B2E0BD" ADS removed successfully.
C:\ProgramData\Temp => ":16777CF9" ADS removed successfully.
C:\ProgramData\Temp => ":178BD71C" ADS removed successfully.
C:\ProgramData\Temp => ":186F8A82" ADS removed successfully.
C:\ProgramData\Temp => ":18A25CF1" ADS removed successfully.
C:\ProgramData\Temp => ":18B241CC" ADS removed successfully.
C:\ProgramData\Temp => ":18B5F839" ADS removed successfully.
C:\ProgramData\Temp => ":18E4BF6C" ADS removed successfully.
C:\ProgramData\Temp => ":19474103" ADS removed successfully.
C:\ProgramData\Temp => ":197E3428" ADS removed successfully.
C:\ProgramData\Temp => ":19F8EB29" ADS removed successfully.
C:\ProgramData\Temp => ":1A15E356" ADS removed successfully.
C:\ProgramData\Temp => ":1A259A13" ADS removed successfully.
C:\ProgramData\Temp => ":1A7FC483" ADS removed successfully.
C:\ProgramData\Temp => ":1AC933DC" ADS removed successfully.
C:\ProgramData\Temp => ":1B389835" ADS removed successfully.
C:\ProgramData\Temp => ":1B7E2022" ADS removed successfully.
C:\ProgramData\Temp => ":1B8AA588" ADS removed successfully.
C:\ProgramData\Temp => ":1B96CF22" ADS removed successfully.
C:\ProgramData\Temp => ":1C6D705B" ADS removed successfully.
C:\ProgramData\Temp => ":1CF1FB36" ADS removed successfully.
C:\ProgramData\Temp => ":1D5FADCD" ADS removed successfully.
C:\ProgramData\Temp => ":1E87A273" ADS removed successfully.
C:\ProgramData\Temp => ":1EC13383" ADS removed successfully.
C:\ProgramData\Temp => ":1EEF2E2E" ADS removed successfully.
C:\ProgramData\Temp => ":1F4F2F80" ADS removed successfully.
C:\ProgramData\Temp => ":1FF82161" ADS removed successfully.
C:\ProgramData\Temp => ":2043337E" ADS removed successfully.
C:\ProgramData\Temp => ":217A2324" ADS removed successfully.
C:\ProgramData\Temp => ":219DB32E" ADS removed successfully.
C:\ProgramData\Temp => ":220E9B9E" ADS removed successfully.
C:\ProgramData\Temp => ":2313511A" ADS removed successfully.
C:\ProgramData\Temp => ":234E9CC5" ADS removed successfully.
C:\ProgramData\Temp => ":236FF5C6" ADS removed successfully.
C:\ProgramData\Temp => ":2433F876" ADS removed successfully.
C:\ProgramData\Temp => ":24391EC1" ADS removed successfully.
C:\ProgramData\Temp => ":2636DE16" ADS removed successfully.
C:\ProgramData\Temp => ":2652902F" ADS removed successfully.
C:\ProgramData\Temp => ":2680DDD5" ADS removed successfully.
C:\ProgramData\Temp => ":268BA8AB" ADS removed successfully.
C:\ProgramData\Temp => ":26991AB9" ADS removed successfully.
C:\ProgramData\Temp => ":2727F067" ADS removed successfully.
C:\ProgramData\Temp => ":27A88EF2" ADS removed successfully.
C:\ProgramData\Temp => ":27D1368B" ADS removed successfully.
C:\ProgramData\Temp => ":282CE153" ADS removed successfully.
C:\ProgramData\Temp => ":28DFF83F" ADS removed successfully.
C:\ProgramData\Temp => ":29EA7E22" ADS removed successfully.
C:\ProgramData\Temp => ":2A27E0C5" ADS removed successfully.
C:\ProgramData\Temp => ":2AF322BF" ADS removed successfully.
C:\ProgramData\Temp => ":2B5C4773" ADS removed successfully.
C:\ProgramData\Temp => ":2B9555D8" ADS removed successfully.
C:\ProgramData\Temp => ":2BFBA0B7" ADS removed successfully.
C:\ProgramData\Temp => ":2C4F33F6" ADS removed successfully.
C:\ProgramData\Temp => ":2CA4B471" ADS removed successfully.
C:\ProgramData\Temp => ":2CB9631F" ADS removed successfully.
C:\ProgramData\Temp => ":2D133896" ADS removed successfully.
C:\ProgramData\Temp => ":2DC8330D" ADS removed successfully.
C:\ProgramData\Temp => ":2F0A4DCE" ADS removed successfully.
C:\ProgramData\Temp => ":2F360FB3" ADS removed successfully.
C:\ProgramData\Temp => ":2F474C84" ADS removed successfully.
C:\ProgramData\Temp => ":2F717FB3" ADS removed successfully.
C:\ProgramData\Temp => ":2F7C40B6" ADS removed successfully.
C:\ProgramData\Temp => ":2F947175" ADS removed successfully.
C:\ProgramData\Temp => ":30A9192A" ADS removed successfully.
C:\ProgramData\Temp => ":319D783D" ADS removed successfully.
C:\ProgramData\Temp => ":320208DA" ADS removed successfully.
C:\ProgramData\Temp => ":3241739E" ADS removed successfully.
C:\ProgramData\Temp => ":329BA65B" ADS removed successfully.
C:\ProgramData\Temp => ":32D2A239" ADS removed successfully.
C:\ProgramData\Temp => ":3313A48D" ADS removed successfully.
C:\ProgramData\Temp => ":3393A1CA" ADS removed successfully.
C:\ProgramData\Temp => ":33CF835F" ADS removed successfully.
C:\ProgramData\Temp => ":33E58057" ADS removed successfully.
C:\ProgramData\Temp => ":3480F458" ADS removed successfully.
C:\ProgramData\Temp => ":3487C53E" ADS removed successfully.
C:\ProgramData\Temp => ":35501BA4" ADS removed successfully.
C:\ProgramData\Temp => ":35E8E596" ADS removed successfully.
C:\ProgramData\Temp => ":363E775E" ADS removed successfully.
C:\ProgramData\Temp => ":3651A580" ADS removed successfully.
C:\ProgramData\Temp => ":366EFA1A" ADS removed successfully.
C:\ProgramData\Temp => ":36ED5C45" ADS removed successfully.
C:\ProgramData\Temp => ":37207201" ADS removed successfully.
C:\ProgramData\Temp => ":373E1720" ADS removed successfully.
C:\ProgramData\Temp => ":374CECA7" ADS removed successfully.
C:\ProgramData\Temp => ":37C279BE" ADS removed successfully.
C:\ProgramData\Temp => ":38534D53" ADS removed successfully.
C:\ProgramData\Temp => ":391535F9" ADS removed successfully.
C:\ProgramData\Temp => ":394EB021" ADS removed successfully.
C:\ProgramData\Temp => ":398D2775" ADS removed successfully.
C:\ProgramData\Temp => ":398EFF0F" ADS removed successfully.
C:\ProgramData\Temp => ":39DC8D60" ADS removed successfully.
C:\ProgramData\Temp => ":3A133158" ADS removed successfully.
C:\ProgramData\Temp => ":3A28C54D" ADS removed successfully.
C:\ProgramData\Temp => ":3AB569BA" ADS removed successfully.
C:\ProgramData\Temp => ":3ABC38E6" ADS removed successfully.
C:\ProgramData\Temp => ":3ADE134E" ADS removed successfully.
C:\ProgramData\Temp => ":3B633DE9" ADS removed successfully.
C:\ProgramData\Temp => ":3B71586E" ADS removed successfully.
C:\ProgramData\Temp => ":3BDF57F4" ADS removed successfully.
C:\ProgramData\Temp => ":3C8B784A" ADS removed successfully.
C:\ProgramData\Temp => ":3D1D487A" ADS removed successfully.
C:\ProgramData\Temp => ":3D3F1635" ADS removed successfully.
C:\ProgramData\Temp => ":3D507E52" ADS removed successfully.
C:\ProgramData\Temp => ":3D887DCC" ADS removed successfully.
C:\ProgramData\Temp => ":3D99ABFE" ADS removed successfully.
C:\ProgramData\Temp => ":3DB6F365" ADS removed successfully.
C:\ProgramData\Temp => ":3E8A3E87" ADS removed successfully.
C:\ProgramData\Temp => ":3FB26DBA" ADS removed successfully.
C:\ProgramData\Temp => ":3FD69132" ADS removed successfully.
C:\ProgramData\Temp => ":401CAF8F" ADS removed successfully.
C:\ProgramData\Temp => ":406E0034" ADS removed successfully.
C:\ProgramData\Temp => ":410A2E9A" ADS removed successfully.
C:\ProgramData\Temp => ":415E77AB" ADS removed successfully.
C:\ProgramData\Temp => ":417C2BC3" ADS removed successfully.
C:\ProgramData\Temp => ":41CB6858" ADS removed successfully.
C:\ProgramData\Temp => ":437B1C75" ADS removed successfully.
C:\ProgramData\Temp => ":44712999" ADS removed successfully.
C:\ProgramData\Temp => ":447856CD" ADS removed successfully.
C:\ProgramData\Temp => ":454191C8" ADS removed successfully.
C:\ProgramData\Temp => ":4548E058" ADS removed successfully.
C:\ProgramData\Temp => ":45936E12" ADS removed successfully.
C:\ProgramData\Temp => ":45A64DE6" ADS removed successfully.
C:\ProgramData\Temp => ":46283136" ADS removed successfully.
C:\ProgramData\Temp => ":469B47D8" ADS removed successfully.
C:\ProgramData\Temp => ":46CDAE37" ADS removed successfully.
C:\ProgramData\Temp => ":46EF121E" ADS removed successfully.
C:\ProgramData\Temp => ":470574B5" ADS removed successfully.
C:\ProgramData\Temp => ":4762F1D2" ADS removed successfully.
C:\ProgramData\Temp => ":48862C37" ADS removed successfully.
C:\ProgramData\Temp => ":489EA5E5" ADS removed successfully.
C:\ProgramData\Temp => ":48D6EA0F" ADS removed successfully.
C:\ProgramData\Temp => ":498B5975" ADS removed successfully.
C:\ProgramData\Temp => ":49EA4410" ADS removed successfully.
C:\ProgramData\Temp => ":4A448DB2" ADS removed successfully.
C:\ProgramData\Temp => ":4A5CFD3B" ADS removed successfully.
C:\ProgramData\Temp => ":4A8EB1C4" ADS removed successfully.
C:\ProgramData\Temp => ":4A906D4A" ADS removed successfully.
C:\ProgramData\Temp => ":4AA3DAA3" ADS removed successfully.
C:\ProgramData\Temp => ":4B6A9FDA" ADS removed successfully.
C:\ProgramData\Temp => ":4B7C28B1" ADS removed successfully.
C:\ProgramData\Temp => ":4B8122EA" ADS removed successfully.
C:\ProgramData\Temp => ":4C3B92C7" ADS removed successfully.
C:\ProgramData\Temp => ":4C5C1DD3" ADS removed successfully.
C:\ProgramData\Temp => ":4CFC5F70" ADS removed successfully.
C:\ProgramData\Temp => ":4D51EA2B" ADS removed successfully.
C:\ProgramData\Temp => ":4D6B6072" ADS removed successfully.
C:\ProgramData\Temp => ":4D8FCBEF" ADS removed successfully.
C:\ProgramData\Temp => ":4DCAC4BC" ADS removed successfully.
C:\ProgramData\Temp => ":4E79C4F8" ADS removed successfully.
C:\ProgramData\Temp => ":4EA002DF" ADS removed successfully.
C:\ProgramData\Temp => ":4EE95FE7" ADS removed successfully.
C:\ProgramData\Temp => ":4EFA2FC7" ADS removed successfully.
C:\ProgramData\Temp => ":4F49DA66" ADS removed successfully.
C:\ProgramData\Temp => ":4F852702" ADS removed successfully.
C:\ProgramData\Temp => ":4F8B72C9" ADS removed successfully.
C:\ProgramData\Temp => ":4FD3435F" ADS removed successfully.
C:\ProgramData\Temp => ":5008417E" ADS removed successfully.
C:\ProgramData\Temp => ":506698B2" ADS removed successfully.
C:\ProgramData\Temp => ":50868536" ADS removed successfully.
C:\ProgramData\Temp => ":5106F19A" ADS removed successfully.
C:\ProgramData\Temp => ":5164A01F" ADS removed successfully.
C:\ProgramData\Temp => ":517DBC32" ADS removed successfully.
C:\ProgramData\Temp => ":51A20D23" ADS removed successfully.
C:\ProgramData\Temp => ":51E66512" ADS removed successfully.
C:\ProgramData\Temp => ":52641FBE" ADS removed successfully.
C:\ProgramData\Temp => ":52C24010" ADS removed successfully.
C:\ProgramData\Temp => ":53F09A92" ADS removed successfully.
C:\ProgramData\Temp => ":5412DFA4" ADS removed successfully.
C:\ProgramData\Temp => ":54403233" ADS removed successfully.
C:\ProgramData\Temp => ":5453E5AF" ADS removed successfully.
C:\ProgramData\Temp => ":54AF9997" ADS removed successfully.
C:\ProgramData\Temp => ":54F0BBF5" ADS removed successfully.
C:\ProgramData\Temp => ":550E7893" ADS removed successfully.
C:\ProgramData\Temp => ":55374FBA" ADS removed successfully.
C:\ProgramData\Temp => ":5559517D" ADS removed successfully.
C:\ProgramData\Temp => ":55818279" ADS removed successfully.
C:\ProgramData\Temp => ":55BB2521" ADS removed successfully.
C:\ProgramData\Temp => ":561B1D2B" ADS removed successfully.
C:\ProgramData\Temp => ":57DFBE4E" ADS removed successfully.
C:\ProgramData\Temp => ":58447932" ADS removed successfully.
C:\ProgramData\Temp => ":587F3582" ADS removed successfully.
C:\ProgramData\Temp => ":58B3FE52" ADS removed successfully.
C:\ProgramData\Temp => ":597254A1" ADS removed successfully.
C:\ProgramData\Temp => ":59A6876B" ADS removed successfully.
C:\ProgramData\Temp => ":59C64924" ADS removed successfully.
C:\ProgramData\Temp => ":5A068EE1" ADS removed successfully.
C:\ProgramData\Temp => ":5A9F1AE5" ADS removed successfully.
C:\ProgramData\Temp => ":5ACE199E" ADS removed successfully.
C:\ProgramData\Temp => ":5B483FBC" ADS removed successfully.
C:\ProgramData\Temp => ":5BF8F61F" ADS removed successfully.
C:\ProgramData\Temp => ":5C28E25F" ADS removed successfully.
C:\ProgramData\Temp => ":5C353220" ADS removed successfully.
C:\ProgramData\Temp => ":5C3637D2" ADS removed successfully.
C:\ProgramData\Temp => ":5C3ED5BB" ADS removed successfully.
C:\ProgramData\Temp => ":5C42F64A" ADS removed successfully.
C:\ProgramData\Temp => ":5C5F2761" ADS removed successfully.
C:\ProgramData\Temp => ":5C9A6C78" ADS removed successfully.
C:\ProgramData\Temp => ":5CBA5665" ADS removed successfully.
C:\ProgramData\Temp => ":5D351BC6" ADS removed successfully.
C:\ProgramData\Temp => ":5D570144" ADS removed successfully.
C:\ProgramData\Temp => ":5DB36C47" ADS removed successfully.
C:\ProgramData\Temp => ":5E209A50" ADS removed successfully.
C:\ProgramData\Temp => ":5E481579" ADS removed successfully.
C:\ProgramData\Temp => ":605645B0" ADS removed successfully.
C:\ProgramData\Temp => ":607A99D7" ADS removed successfully.
C:\ProgramData\Temp => ":60E755E6" ADS removed successfully.
C:\ProgramData\Temp => ":611EAF9F" ADS removed successfully.
C:\ProgramData\Temp => ":61C53F55" ADS removed successfully.
C:\ProgramData\Temp => ":624A6897" ADS removed successfully.
C:\ProgramData\Temp => ":629F8518" ADS removed successfully.
C:\ProgramData\Temp => ":63BA523E" ADS removed successfully.
C:\ProgramData\Temp => ":63C48B80" ADS removed successfully.
C:\ProgramData\Temp => ":6407DD2D" ADS removed successfully.
C:\ProgramData\Temp => ":641A21EA" ADS removed successfully.
C:\ProgramData\Temp => ":64E05835" ADS removed successfully.
C:\ProgramData\Temp => ":65484F45" ADS removed successfully.
C:\ProgramData\Temp => ":669AB5E1" ADS removed successfully.
C:\ProgramData\Temp => ":66C764F5" ADS removed successfully.
C:\ProgramData\Temp => ":66F19688" ADS removed successfully.
C:\ProgramData\Temp => ":66F7E5A9" ADS removed successfully.
C:\ProgramData\Temp => ":674893F9" ADS removed successfully.
C:\ProgramData\Temp => ":67B6E7FA" ADS removed successfully.
C:\ProgramData\Temp => ":67E674B0" ADS removed successfully.
C:\ProgramData\Temp => ":680F6474" ADS removed successfully.
C:\ProgramData\Temp => ":68DE552E" ADS removed successfully.
C:\ProgramData\Temp => ":697DDE2B" ADS removed successfully.
C:\ProgramData\Temp => ":699EFEED" ADS removed successfully.
C:\ProgramData\Temp => ":69F562A6" ADS removed successfully.
C:\ProgramData\Temp => ":6A0A47E7" ADS removed successfully.
C:\ProgramData\Temp => ":6A4DFD85" ADS removed successfully.
C:\ProgramData\Temp => ":6A6D4AF4" ADS removed successfully.
C:\ProgramData\Temp => ":6A9CA6CB" ADS removed successfully.
C:\ProgramData\Temp => ":6AD65294" ADS removed successfully.
C:\ProgramData\Temp => ":6AF6BB0E" ADS removed successfully.
C:\ProgramData\Temp => ":6B709AD7" ADS removed successfully.
C:\ProgramData\Temp => ":6BEADDC0" ADS removed successfully.
C:\ProgramData\Temp => ":6C15BEAD" ADS removed successfully.
C:\ProgramData\Temp => ":6C74C778" ADS removed successfully.
C:\ProgramData\Temp => ":6CF828C2" ADS removed successfully.
C:\ProgramData\Temp => ":6D208D7A" ADS removed successfully.
C:\ProgramData\Temp => ":6DA9822F" ADS removed successfully.
C:\ProgramData\Temp => ":6DDBB86B" ADS removed successfully.
C:\ProgramData\Temp => ":6E39144C" ADS removed successfully.
C:\ProgramData\Temp => ":6EFFF8B9" ADS removed successfully.
C:\ProgramData\Temp => ":6F39FFF1" ADS removed successfully.
C:\ProgramData\Temp => ":70989864" ADS removed successfully.
C:\ProgramData\Temp => ":709E81D4" ADS removed successfully.
C:\ProgramData\Temp => ":72449E7D" ADS removed successfully.
C:\ProgramData\Temp => ":7247FE29" ADS removed successfully.
C:\ProgramData\Temp => ":7254CF01" ADS removed successfully.
C:\ProgramData\Temp => ":72C99D4E" ADS removed successfully.
C:\ProgramData\Temp => ":72E5CC07" ADS removed successfully.
C:\ProgramData\Temp => ":747457CF" ADS removed successfully.
C:\ProgramData\Temp => ":762408BA" ADS removed successfully.
C:\ProgramData\Temp => ":76682252" ADS removed successfully.
C:\ProgramData\Temp => ":7687A3E3" ADS removed successfully.
C:\ProgramData\Temp => ":795F6DEC" ADS removed successfully.
C:\ProgramData\Temp => ":79A7F369" ADS removed successfully.
C:\ProgramData\Temp => ":7A530D80" ADS removed successfully.
C:\ProgramData\Temp => ":7B9BB187" ADS removed successfully.
C:\ProgramData\Temp => ":7BE5BAAB" ADS removed successfully.
C:\ProgramData\Temp => ":7C27C41C" ADS removed successfully.
C:\ProgramData\Temp => ":7C3760E2" ADS removed successfully.
C:\ProgramData\Temp => ":7C5E403A" ADS removed successfully.
C:\ProgramData\Temp => ":7D938C9B" ADS removed successfully.
C:\ProgramData\Temp => ":7D9B1030" ADS removed successfully.
C:\ProgramData\Temp => ":7E0B06B5" ADS removed successfully.
C:\ProgramData\Temp => ":7E47A57F" ADS removed successfully.
C:\ProgramData\Temp => ":7E802BFF" ADS removed successfully.
C:\ProgramData\Temp => ":7EB93F0E" ADS removed successfully.
C:\ProgramData\Temp => ":7F477B0D" ADS removed successfully.
C:\ProgramData\Temp => ":7F4D8125" ADS removed successfully.
C:\ProgramData\Temp => ":7FD8AECC" ADS removed successfully.
C:\ProgramData\Temp => ":80974241" ADS removed successfully.
C:\ProgramData\Temp => ":80FA23CA" ADS removed successfully.
C:\ProgramData\Temp => ":8118F1F5" ADS removed successfully.
C:\ProgramData\Temp => ":823606DE" ADS removed successfully.
C:\ProgramData\Temp => ":82756AB7" ADS removed successfully.
C:\ProgramData\Temp => ":82D85D00" ADS removed successfully.
C:\ProgramData\Temp => ":8318A814" ADS removed successfully.
C:\ProgramData\Temp => ":83517407" ADS removed successfully.
C:\ProgramData\Temp => ":839A89FC" ADS removed successfully.
C:\ProgramData\Temp => ":8401B6D5" ADS removed successfully.
C:\ProgramData\Temp => ":841E0E1B" ADS removed successfully.
C:\ProgramData\Temp => ":8435AD8C" ADS removed successfully.
C:\ProgramData\Temp => ":843D8419" ADS removed successfully.
C:\ProgramData\Temp => ":852F2262" ADS removed successfully.
C:\ProgramData\Temp => ":860356DC" ADS removed successfully.
C:\ProgramData\Temp => ":864881BF" ADS removed successfully.
C:\ProgramData\Temp => ":865F21BF" ADS removed successfully.
C:\ProgramData\Temp => ":86A7B7DD" ADS removed successfully.
C:\ProgramData\Temp => ":86B6EFD4" ADS removed successfully.
C:\ProgramData\Temp => ":871526BA" ADS removed successfully.
C:\ProgramData\Temp => ":8751B175" ADS removed successfully.
C:\ProgramData\Temp => ":8836A712" ADS removed successfully.
C:\ProgramData\Temp => ":884C7316" ADS removed successfully.
C:\ProgramData\Temp => ":8866C899" ADS removed successfully.
C:\ProgramData\Temp => ":88AFFAC5" ADS removed successfully.
C:\ProgramData\Temp => ":88C5973F" ADS removed successfully.
C:\ProgramData\Temp => ":88FB7F72" ADS removed successfully.
C:\ProgramData\Temp => ":8A620099" ADS removed successfully.
C:\ProgramData\Temp => ":8B076EC5" ADS removed successfully.
C:\ProgramData\Temp => ":8B480195" ADS removed successfully.
C:\ProgramData\Temp => ":8C3C65BE" ADS removed successfully.
C:\ProgramData\Temp => ":8C84E358" ADS removed successfully.
C:\ProgramData\Temp => ":8C8D234C" ADS removed successfully.
C:\ProgramData\Temp => ":8D335A79" ADS removed successfully.
C:\ProgramData\Temp => ":8D565A9B" ADS removed successfully.
C:\ProgramData\Temp => ":8DBCF585" ADS removed successfully.
C:\ProgramData\Temp => ":8DC0DCD2" ADS removed successfully.
C:\ProgramData\Temp => ":8E11CC80" ADS removed successfully.
C:\ProgramData\Temp => ":8E3E8227" ADS removed successfully.
C:\ProgramData\Temp => ":8F1B55BE" ADS removed successfully.
C:\ProgramData\Temp => ":90BDAE7B" ADS removed successfully.
C:\ProgramData\Temp => ":91FE43FF" ADS removed successfully.
C:\ProgramData\Temp => ":9254F782" ADS removed successfully.
C:\ProgramData\Temp => ":927EC486" ADS removed successfully.
C:\ProgramData\Temp => ":92BD9737" ADS removed successfully.
C:\ProgramData\Temp => ":92C8CBEF" ADS removed successfully.
C:\ProgramData\Temp => ":92CA7E75" ADS removed successfully.
C:\ProgramData\Temp => ":92D35C13" ADS removed successfully.
C:\ProgramData\Temp => ":933D54A9" ADS removed successfully.
C:\ProgramData\Temp => ":938EB9FC" ADS removed successfully.
C:\ProgramData\Temp => ":9491C9C7" ADS removed successfully.
C:\ProgramData\Temp => ":94A31742" ADS removed successfully.
C:\ProgramData\Temp => ":94B25DF5" ADS removed successfully.
C:\ProgramData\Temp => ":94BD36A2" ADS removed successfully.
C:\ProgramData\Temp => ":952245B1" ADS removed successfully.
C:\ProgramData\Temp => ":9524D821" ADS removed successfully.
C:\ProgramData\Temp => ":95E8BA2F" ADS removed successfully.
C:\ProgramData\Temp => ":968F624D" ADS removed successfully.
C:\ProgramData\Temp => ":97427454" ADS removed successfully.
C:\ProgramData\Temp => ":97AAB7F2" ADS removed successfully.
C:\ProgramData\Temp => ":97BDBF49" ADS removed successfully.
C:\ProgramData\Temp => ":97C9EF7E" ADS removed successfully.
C:\ProgramData\Temp => ":9836B5E4" ADS removed successfully.
C:\ProgramData\Temp => ":98BD93BF" ADS removed successfully.
C:\ProgramData\Temp => ":98CF1A39" ADS removed successfully.
C:\ProgramData\Temp => ":991283D0" ADS removed successfully.
C:\ProgramData\Temp => ":99515FFA" ADS removed successfully.
C:\ProgramData\Temp => ":996104FC" ADS removed successfully.
C:\ProgramData\Temp => ":9968F0E2" ADS removed successfully.
C:\ProgramData\Temp => ":9AC8424E" ADS removed successfully.
C:\ProgramData\Temp => ":9ACC5E2D" ADS removed successfully.
C:\ProgramData\Temp => ":9CD7CD43" ADS removed successfully.
C:\ProgramData\Temp => ":9CE870B8" ADS removed successfully.
C:\ProgramData\Temp => ":9D0A16E4" ADS removed successfully.
C:\ProgramData\Temp => ":9E3D44B7" ADS removed successfully.
C:\ProgramData\Temp => ":9E410D29" ADS removed successfully.
C:\ProgramData\Temp => ":9E5EA7A3" ADS removed successfully.
C:\ProgramData\Temp => ":9F38BF31" ADS removed successfully.
C:\ProgramData\Temp => ":9F3CEEE6" ADS removed successfully.
C:\ProgramData\Temp => ":9F6E8CED" ADS removed successfully.
C:\ProgramData\Temp => ":A015B193" ADS removed successfully.
C:\ProgramData\Temp => ":A0921B2C" ADS removed successfully.
C:\ProgramData\Temp => ":A19DFC74" ADS removed successfully.
C:\ProgramData\Temp => ":A1FD5369" ADS removed successfully.
C:\ProgramData\Temp => ":A26C6E72" ADS removed successfully.
C:\ProgramData\Temp => ":A291068E" ADS removed successfully.
C:\ProgramData\Temp => ":A391510C" ADS removed successfully.
C:\ProgramData\Temp => ":A4241298" ADS removed successfully.
C:\ProgramData\Temp => ":A42B5698" ADS removed successfully.
C:\ProgramData\Temp => ":A477045F" ADS removed successfully.
C:\ProgramData\Temp => ":A4B4192F" ADS removed successfully.
C:\ProgramData\Temp => ":A4E7D25F" ADS removed successfully.
C:\ProgramData\Temp => ":A52D07E2" ADS removed successfully.
C:\ProgramData\Temp => ":A673F81E" ADS removed successfully.
C:\ProgramData\Temp => ":A6E01F67" ADS removed successfully.
C:\ProgramData\Temp => ":A6F28514" ADS removed successfully.
C:\ProgramData\Temp => ":A6FE7BCC" ADS removed successfully.
C:\ProgramData\Temp => ":A73595DE" ADS removed successfully.
C:\ProgramData\Temp => ":A76A1B1B" ADS removed successfully.
C:\ProgramData\Temp => ":A78B31DD" ADS removed successfully.
C:\ProgramData\Temp => ":A798AA1A" ADS removed successfully.
C:\ProgramData\Temp => ":A7C40691" ADS removed successfully.
C:\ProgramData\Temp => ":A8185163" ADS removed successfully.
C:\ProgramData\Temp => ":A819A132" ADS removed successfully.
C:\ProgramData\Temp => ":A8369371" ADS removed successfully.
C:\ProgramData\Temp => ":A88BE334" ADS removed successfully.
C:\ProgramData\Temp => ":A9223B61" ADS removed successfully.
C:\ProgramData\Temp => ":A9F13D2D" ADS removed successfully.
C:\ProgramData\Temp => ":AA5A61B2" ADS removed successfully.
C:\ProgramData\Temp => ":AA632E81" ADS removed successfully.
C:\ProgramData\Temp => ":AB0A5A80" ADS removed successfully.
C:\ProgramData\Temp => ":ABBFFEA2" ADS removed successfully.
C:\ProgramData\Temp => ":AD179392" ADS removed successfully.
C:\ProgramData\Temp => ":AD2DB2F9" ADS removed successfully.
C:\ProgramData\Temp => ":AD7BB754" ADS removed successfully.
C:\ProgramData\Temp => ":AE0B4487" ADS removed successfully.
C:\ProgramData\Temp => ":AE324BE5" ADS removed successfully.
C:\ProgramData\Temp => ":AEC59117" ADS removed successfully.
C:\ProgramData\Temp => ":AF2F9D4A" ADS removed successfully.
C:\ProgramData\Temp => ":AF465248" ADS removed successfully.
C:\ProgramData\Temp => ":AF841BA9" ADS removed successfully.
C:\ProgramData\Temp => ":AFB89C92" ADS removed successfully.
C:\ProgramData\Temp => ":B01EC114" ADS removed successfully.
C:\ProgramData\Temp => ":B0729CDB" ADS removed successfully.
C:\ProgramData\Temp => ":B21F2857" ADS removed successfully.
C:\ProgramData\Temp => ":B2735F9E" ADS removed successfully.
C:\ProgramData\Temp => ":B2CCDB69" ADS removed successfully.
C:\ProgramData\Temp => ":B2DC8D6B" ADS removed successfully.
C:\ProgramData\Temp => ":B317D7ED" ADS removed successfully.
C:\ProgramData\Temp => ":B328A983" ADS removed successfully.
C:\ProgramData\Temp => ":B33464A5" ADS removed successfully.
C:\ProgramData\Temp => ":B38BEEEE" ADS removed successfully.
C:\ProgramData\Temp => ":B392E17F" ADS removed successfully.
C:\ProgramData\Temp => ":B50D8729" ADS removed successfully.
C:\ProgramData\Temp => ":B54E4B5A" ADS removed successfully.
C:\ProgramData\Temp => ":B5FD4AA1" ADS removed successfully.
C:\ProgramData\Temp => ":B69CF390" ADS removed successfully.
C:\ProgramData\Temp => ":B6E58523" ADS removed successfully.
C:\ProgramData\Temp => ":B74BD6BF" ADS removed successfully.
C:\ProgramData\Temp => ":B7B127A5" ADS removed successfully.
C:\ProgramData\Temp => ":B88DC997" ADS removed successfully.
C:\ProgramData\Temp => ":B8EB1B99" ADS removed successfully.
C:\ProgramData\Temp => ":B961095A" ADS removed successfully.
C:\ProgramData\Temp => ":B9A99598" ADS removed successfully.
C:\ProgramData\Temp => ":B9C6EB6C" ADS removed successfully.
C:\ProgramData\Temp => ":BABCFD54" ADS removed successfully.
C:\ProgramData\Temp => ":BB99F46B" ADS removed successfully.
C:\ProgramData\Temp => ":BBC9C1EB" ADS removed successfully.
C:\ProgramData\Temp => ":BC8E9899" ADS removed successfully.
C:\ProgramData\Temp => ":BCF55336" ADS removed successfully.
C:\ProgramData\Temp => ":BD0A043E" ADS removed successfully.
C:\ProgramData\Temp => ":BD414E4B" ADS removed successfully.
C:\ProgramData\Temp => ":BD84F7D6" ADS removed successfully.
C:\ProgramData\Temp => ":BDDA21B6" ADS removed successfully.
C:\ProgramData\Temp => ":BEE39E9B" ADS removed successfully.
C:\ProgramData\Temp => ":BEF18713" ADS removed successfully.
C:\ProgramData\Temp => ":BF1E0621" ADS removed successfully.
C:\ProgramData\Temp => ":BF6C4AAC" ADS removed successfully.
C:\ProgramData\Temp => ":C00C7190" ADS removed successfully.
C:\ProgramData\Temp => ":C0BCE04B" ADS removed successfully.
C:\ProgramData\Temp => ":C0D23A2F" ADS removed successfully.
C:\ProgramData\Temp => ":C10635F6" ADS removed successfully.
C:\ProgramData\Temp => ":C1D3D9A3" ADS removed successfully.
C:\ProgramData\Temp => ":C22FB597" ADS removed successfully.
C:\ProgramData\Temp => ":C370B84F" ADS removed successfully.
C:\ProgramData\Temp => ":C3899C0B" ADS removed successfully.
C:\ProgramData\Temp => ":C3E7F2E9" ADS removed successfully.
C:\ProgramData\Temp => ":C48A983C" ADS removed successfully.
C:\ProgramData\Temp => ":C4A88D6B" ADS removed successfully.
C:\ProgramData\Temp => ":C4C09E44" ADS removed successfully.
C:\ProgramData\Temp => ":C5340FA1" ADS removed successfully.
C:\ProgramData\Temp => ":C55217E2" ADS removed successfully.
C:\ProgramData\Temp => ":C5A156B6" ADS removed successfully.
C:\ProgramData\Temp => ":C5D15631" ADS removed successfully.
C:\ProgramData\Temp => ":C6104C4F" ADS removed successfully.
C:\ProgramData\Temp => ":C669F3E1" ADS removed successfully.
C:\ProgramData\Temp => ":C76CFF82" ADS removed successfully.
C:\ProgramData\Temp => ":C76D8487" ADS removed successfully.
C:\ProgramData\Temp => ":C77802D8" ADS removed successfully.
C:\ProgramData\Temp => ":C7D35E8C" ADS removed successfully.
C:\ProgramData\Temp => ":C82CA1C0" ADS removed successfully.
C:\ProgramData\Temp => ":C89D1773" ADS removed successfully.
C:\ProgramData\Temp => ":C8E3A625" ADS removed successfully.
C:\ProgramData\Temp => ":C900B47A" ADS removed successfully.
C:\ProgramData\Temp => ":C98828D3" ADS removed successfully.
C:\ProgramData\Temp => ":CA1AFE85" ADS removed successfully.
C:\ProgramData\Temp => ":CB08ED9D" ADS removed successfully.
C:\ProgramData\Temp => ":CB3667AF" ADS removed successfully.
C:\ProgramData\Temp => ":CB5AA1E6" ADS removed successfully.
C:\ProgramData\Temp => ":CCB49694" ADS removed successfully.
C:\ProgramData\Temp => ":CCD8056E" ADS removed successfully.
C:\ProgramData\Temp => ":CDCDE97C" ADS removed successfully.
C:\ProgramData\Temp => ":CE3AADB7" ADS removed successfully.
C:\ProgramData\Temp => ":CF8AEC6E" ADS removed successfully.
C:\ProgramData\Temp => ":CFE19728" ADS removed successfully.
C:\ProgramData\Temp => ":D0005E5A" ADS removed successfully.
C:\ProgramData\Temp => ":D103E81E" ADS removed successfully.
C:\ProgramData\Temp => ":D1FE35E7" ADS removed successfully.
C:\ProgramData\Temp => ":D276CDF4" ADS removed successfully.
C:\ProgramData\Temp => ":D3A89E47" ADS removed successfully.
C:\ProgramData\Temp => ":D434342F" ADS removed successfully.
C:\ProgramData\Temp => ":D4DD372D" ADS removed successfully.
C:\ProgramData\Temp => ":D4E62FA9" ADS removed successfully.
C:\ProgramData\Temp => ":D4F5419A" ADS removed successfully.
C:\ProgramData\Temp => ":D5D75FF0" ADS removed successfully.
C:\ProgramData\Temp => ":D64DD961" ADS removed successfully.
C:\ProgramData\Temp => ":D6A43EB0" ADS removed successfully.
C:\ProgramData\Temp => ":D7740E2A" ADS removed successfully.
C:\ProgramData\Temp => ":D92A5893" ADS removed successfully.
C:\ProgramData\Temp => ":DA378DD8" ADS removed successfully.
C:\ProgramData\Temp => ":DA55B48C" ADS removed successfully.
C:\ProgramData\Temp => ":DB76C881" ADS removed successfully.
C:\ProgramData\Temp => ":DBB979D4" ADS removed successfully.
C:\ProgramData\Temp => ":DBC3D477" ADS removed successfully.
C:\ProgramData\Temp => ":DBE31BCC" ADS removed successfully.
C:\ProgramData\Temp => ":DBEF355E" ADS removed successfully.
C:\ProgramData\Temp => ":DC8E5CD4" ADS removed successfully.
C:\ProgramData\Temp => ":DC9915D2" ADS removed successfully.
C:\ProgramData\Temp => ":DD04902E" ADS removed successfully.
C:\ProgramData\Temp => ":DDE3F219" ADS removed successfully.
C:\ProgramData\Temp => ":DE0BD04E" ADS removed successfully.
C:\ProgramData\Temp => ":DE3ABE3D" ADS removed successfully.
C:\ProgramData\Temp => ":DE875C30" ADS removed successfully.
C:\ProgramData\Temp => ":DF2F7240" ADS removed successfully.
C:\ProgramData\Temp => ":DF5ABA3D" ADS removed successfully.
C:\ProgramData\Temp => ":DF5C005A" ADS removed successfully.
C:\ProgramData\Temp => ":DF7A2D3E" ADS removed successfully.
C:\ProgramData\Temp => ":DFDBC05C" ADS removed successfully.
C:\ProgramData\Temp => ":DFFB9E98" ADS removed successfully.
C:\ProgramData\Temp => ":E0365B26" ADS removed successfully.
C:\ProgramData\Temp => ":E0CAA39F" ADS removed successfully.
C:\ProgramData\Temp => ":E11D90D0" ADS removed successfully.
C:\ProgramData\Temp => ":E14FA16F" ADS removed successfully.
C:\ProgramData\Temp => ":E1520A02" ADS removed successfully.
C:\ProgramData\Temp => ":E21987F7" ADS removed successfully.
C:\ProgramData\Temp => ":E32D2701" ADS removed successfully.
C:\ProgramData\Temp => ":E3615992" ADS removed successfully.
C:\ProgramData\Temp => ":E40AB54F" ADS removed successfully.
C:\ProgramData\Temp => ":E40D7F76" ADS removed successfully.
C:\ProgramData\Temp => ":E4272706" ADS removed successfully.
C:\ProgramData\Temp => ":E4FD113F" ADS removed successfully.
C:\ProgramData\Temp => ":E51234A9" ADS removed successfully.
C:\ProgramData\Temp => ":E517FE76" ADS removed successfully.
C:\ProgramData\Temp => ":E5294695" ADS removed successfully.
C:\ProgramData\Temp => ":E534B4D1" ADS removed successfully.
C:\ProgramData\Temp => ":E5496666" ADS removed successfully.
C:\ProgramData\Temp => ":E5AF754F" ADS removed successfully.
C:\ProgramData\Temp => ":E5B07840" ADS removed successfully.
C:\ProgramData\Temp => ":E69366D6" ADS removed successfully.
C:\ProgramData\Temp => ":E6CDFB4A" ADS removed successfully.
C:\ProgramData\Temp => ":E7B4296D" ADS removed successfully.
C:\ProgramData\Temp => ":E87AB4E3" ADS removed successfully.
C:\ProgramData\Temp => ":E894A3ED" ADS removed successfully.
C:\ProgramData\Temp => ":E8BE0B80" ADS removed successfully.
C:\ProgramData\Temp => ":E8C44CB4" ADS removed successfully.
C:\ProgramData\Temp => ":E9049821" ADS removed successfully.
C:\ProgramData\Temp => ":E94FA418" ADS removed successfully.
C:\ProgramData\Temp => ":E96A2658" ADS removed successfully.
C:\ProgramData\Temp => ":E9C2F553" ADS removed successfully.
C:\ProgramData\Temp => ":EA10407C" ADS removed successfully.
C:\ProgramData\Temp => ":EA2D3047" ADS removed successfully.
C:\ProgramData\Temp => ":EA75C0D4" ADS removed successfully.
C:\ProgramData\Temp => ":EB4FEEF5" ADS removed successfully.
C:\ProgramData\Temp => ":EBDA62B1" ADS removed successfully.
C:\ProgramData\Temp => ":EC752217" ADS removed successfully.
C:\ProgramData\Temp => ":EC970DB6" ADS removed successfully.
C:\ProgramData\Temp => ":EDB03249" ADS removed successfully.
C:\ProgramData\Temp => ":EDF12A30" ADS removed successfully.
C:\ProgramData\Temp => ":EE2DD6CC" ADS removed successfully.
C:\ProgramData\Temp => ":EE445D7C" ADS removed successfully.
C:\ProgramData\Temp => ":EE9B2879" ADS removed successfully.
C:\ProgramData\Temp => ":EF0BD3A1" ADS removed successfully.
C:\ProgramData\Temp => ":EF0F3F33" ADS removed successfully.
C:\ProgramData\Temp => ":EF53A5CA" ADS removed successfully.
C:\ProgramData\Temp => ":F039D9FE" ADS removed successfully.
C:\ProgramData\Temp => ":F1174C93" ADS removed successfully.
C:\ProgramData\Temp => ":F135A76C" ADS removed successfully.
C:\ProgramData\Temp => ":F13867C6" ADS removed successfully.
C:\ProgramData\Temp => ":F13DDA30" ADS removed successfully.
C:\ProgramData\Temp => ":F176B6C6" ADS removed successfully.
C:\ProgramData\Temp => ":F193BFCF" ADS removed successfully.
C:\ProgramData\Temp => ":F2E878EB" ADS removed successfully.
C:\ProgramData\Temp => ":F2E92DCD" ADS removed successfully.
C:\ProgramData\Temp => ":F2F0A8AC" ADS removed successfully.
C:\ProgramData\Temp => ":F3A185AE" ADS removed successfully.
C:\ProgramData\Temp => ":F42BB562" ADS removed successfully.
C:\ProgramData\Temp => ":F437A62A" ADS removed successfully.
C:\ProgramData\Temp => ":F49868C8" ADS removed successfully.
C:\ProgramData\Temp => ":F4BF61E8" ADS removed successfully.
C:\ProgramData\Temp => ":F5082CD2" ADS removed successfully.
C:\ProgramData\Temp => ":F56BE392" ADS removed successfully.
C:\ProgramData\Temp => ":F66F0A25" ADS removed successfully.
C:\ProgramData\Temp => ":F74EC668" ADS removed successfully.
C:\ProgramData\Temp => ":F7F4DC88" ADS removed successfully.
C:\ProgramData\Temp => ":F816645E" ADS removed successfully.
C:\ProgramData\Temp => ":F817E159" ADS removed successfully.
C:\ProgramData\Temp => ":F83E8359" ADS removed successfully.
C:\ProgramData\Temp => ":F84EC1E0" ADS removed successfully.
C:\ProgramData\Temp => ":F8F070C2" ADS removed successfully.
C:\ProgramData\Temp => ":F94DE3B1" ADS removed successfully.
C:\ProgramData\Temp => ":FA7523FF" ADS removed successfully.
C:\ProgramData\Temp => ":FAFEC4B9" ADS removed successfully.
C:\ProgramData\Temp => ":FBD274CF" ADS removed successfully.
C:\ProgramData\Temp => ":FD4C7AD3" ADS removed successfully.
C:\ProgramData\Temp => ":FD646198" ADS removed successfully.
C:\ProgramData\Temp => ":FD6D11C9" ADS removed successfully.
C:\ProgramData\Temp => ":FD7DCDA6" ADS removed successfully.
C:\ProgramData\Temp => ":FE1028DD" ADS removed successfully.
C:\ProgramData\Temp => ":FF717A18" ADS removed successfully.
C:\ProgramData\Temp => ":FFA396CD" ADS removed successfully.
C:\ProgramData\Temp => ":FFC3922F" ADS removed successfully.

==== End of Fixlog ====

 

 

==================Security Check results===================

 

Results of screen317's Security Check version 0.99.88  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
avast! Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:`````````
 Nancy Drew: The Silent Spy
 Java 7 Update 65  
 Java version out of Date!
 Adobe Flash Player 15.0.0.152  
 Adobe Reader 10.1.12 Adobe Reader out of Date!  
 Mozilla Firefox (32.0.3)
````````Process Check: objlist.exe by Laurent````````  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast avastui.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 20% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
 



#7 sepa14

sepa14
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:04:23 AM

Posted 10 October 2014 - 04:20 AM

It's been a while since I replied. If this issue can't be resolved, I understand. If worst comes to worst I know how to reinstall Windows.



#8 sepa14

sepa14
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:04:23 AM

Posted 10 October 2014 - 05:10 AM

If it helps at all, I found a thread on another forum that describes a problem like mine. Perhaps we could try some of the things they did?

 

http://forums.whatthetech.com/index.php?s=28e90576d05cbf2fa589e9e76111e2d8&showtopic=127397

 

I have not done anything suggested in this thread. I am still waiting for your instructions.



#9 nasdaq

nasdaq

  • Malware Response Team
  • 39,955 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:23 AM

Posted 10 October 2014 - 08:44 AM


The only thing that was done with the OTL tool was to reset your IP.
Execute the following.

Open the StartBtn.gif > run box and type cmd and hit OK
type
ipconfig /flushdns <-- (The space between g and / is needed) press the Enter key.

Repeat with:
ipconfig /release

Repeat with:
ipconfig /renew

Then type Exit, hit the Enter key
*/*

If that fails then run this tool.


Please download MiniToolBox to Desktop and run it.

Check mark the following boxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List last 10 Event Viewer log
  • List content of Hosts
  • List IP Configuration
  • List Winsock Entries
  • Click Go and copy/paste the log (Result.txt) into your next post.
  • Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
Keep me posted.

#10 sepa14

sepa14
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:04:23 AM

Posted 11 October 2014 - 09:39 AM

Followed your instructions. The problem remains. IE complains about proxy, cannot uncheck proxy option under LAN settings.

 

 

MiniToolBox by Farbar  Version: 21-07-2014
Ran by Bonnie (administrator) on 11-10-2014 at 09:33:18
Running from "C:\Users\Bonnie\Downloads"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================

"network.proxy.type", 0

"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================



========================= IP Configuration: ================================

Realtek PCIe GBE Family Controller = Local Area Connection (Connected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# End of IPv4 configuration



Windows IP Configuration

   Host Name . . . . . . . . . . . . : Bonnie-PC
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : hsd1.mn.comcast.net.

Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . : hsd1.mn.comcast.net.
   Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
   Physical Address. . . . . . . . . : EC-A8-6B-94-90-2D
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::daa:7734:ffd7:d68b%11(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.1.100(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Saturday, October 11, 2014 9:30:29 AM
   Lease Expires . . . . . . . . . . : Sunday, October 12, 2014 9:30:29 AM
   Default Gateway . . . . . . . . . : 192.168.1.1
   DHCP Server . . . . . . . . . . . : 192.168.1.1
   DHCPv6 IAID . . . . . . . . . . . : 200058987
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-17-47-7A-AC-EC-A8-6B-94-90-2D
   DNS Servers . . . . . . . . . . . : 75.75.76.76
                                       75.75.75.75
   NetBIOS over Tcpip. . . . . . . . : Enabled
Server:  cdns02.comcast.net
Address:  75.75.76.76

Name:    google.com
Addresses:  2607:f8b0:4009:800::1008
      74.125.225.129
      74.125.225.130
      74.125.225.137
      74.125.225.136
      74.125.225.134
      74.125.225.131
      74.125.225.132
      74.125.225.133
      74.125.225.142
      74.125.225.128
      74.125.225.135


Pinging google.com [74.125.225.97] with 32 bytes of data:
Reply from 74.125.225.97: bytes=32 time=40ms TTL=54
Reply from 74.125.225.97: bytes=32 time=41ms TTL=54

Ping statistics for 74.125.225.97:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 40ms, Maximum = 41ms, Average = 40ms
Server:  cdns02.comcast.net
Address:  75.75.76.76

Name:    yahoo.com
Addresses:  206.190.36.45
      98.139.183.24
      98.138.253.109


Pinging yahoo.com [206.190.36.45] with 32 bytes of data:
Reply from 206.190.36.45: bytes=32 time=67ms TTL=51
Reply from 206.190.36.45: bytes=32 time=69ms TTL=51

Ping statistics for 206.190.36.45:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 67ms, Maximum = 69ms, Average = 68ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 11...ec a8 6b 94 90 2d ......Realtek PCIe GBE Family Controller
  1...........................Software Loopback Interface 1
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1    192.168.1.100     20
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.1.0    255.255.255.0         On-link     192.168.1.100    276
    192.168.1.100  255.255.255.255         On-link     192.168.1.100    276
    192.168.1.255  255.255.255.255         On-link     192.168.1.100    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link     192.168.1.100    276
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link     192.168.1.100    276
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  1    306 ::1/128                  On-link
 11    276 fe80::/64                On-link
 11    276 fe80::daa:7734:ffd7:d68b/128
                                    On-link
  1    306 ff00::/8                 On-link
 11    276 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (10/11/2014 05:14:08 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/11/2014 05:10:24 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/10/2014 07:25:29 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/09/2014 06:24:12 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/08/2014 07:43:33 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/07/2014 06:48:28 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/06/2014 08:24:55 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/05/2014 09:18:32 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/05/2014 09:05:05 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/05/2014 08:22:26 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (10/06/2014 09:35:58 AM) (Source: Service Control Manager) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.

Error: (09/30/2014 04:58:09 PM) (Source: Service Control Manager) (User: )
Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error:
%%1053

Error: (09/30/2014 04:58:09 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Scanner Service service to connect.

Error: (09/30/2014 04:32:08 PM) (Source: Service Control Manager) (User: )
Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error:
%%1053

Error: (09/30/2014 04:32:08 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Scanner Service service to connect.

Error: (09/30/2014 04:28:53 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (09/30/2014 04:28:53 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (09/30/2014 04:28:43 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (09/30/2014 04:28:43 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (09/30/2014 04:28:41 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068


Microsoft Office Sessions:
=========================
Error: (10/11/2014 05:14:08 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/11/2014 05:10:24 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/10/2014 07:25:29 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/09/2014 06:24:12 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/08/2014 07:43:33 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/07/2014 06:48:28 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/06/2014 08:24:55 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/05/2014 09:18:32 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/05/2014 09:05:05 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/05/2014 08:22:26 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


**** End of log ****
 



#11 nasdaq

nasdaq

  • Malware Response Team
  • 39,955 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:23 AM

Posted 11 October 2014 - 01:04 PM


Refer to this page.
Suggestion by colins.betts
The original issue was that I was unable to uncheck the Proxy server settings.
https://www.daniweb.com/hardware-and-software/microsoft-windows/threads/15558/cant-turn-off-proxy-server-in-my-connections-setting

You can also try the other suggestions.

Hope it helps.

===

If that fails I suggest you start a new topic in the Networking forum
http://www.bleepingcomputer.com/forums/forum21.html
Someone may have a better solution.

#12 sepa14

sepa14
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:04:23 AM

Posted 11 October 2014 - 08:40 PM

It's fixed!

 

Oh, the solution was so simple I can't believe I didn't think of it myself! It was one of the answers in the post you linked me to:

 

 

open your IE as an Administrator, Goto tools>Internet Options>Connections Tab, Click on LAN settings and Uncheck proxy as well as "Automatically Detect Settings". Restart your browser.. It should work..

 

Emphasis on as an administrator (right-click the icon and select "Run as admin.") I guess the option simply wasn't "sticking" otherwise.

 

Thank you for your help and patience with this frustrating issue, nasdaq.



#13 nasdaq

nasdaq

  • Malware Response Team
  • 39,955 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:23 AM

Posted 12 October 2014 - 08:56 AM

Glad we could help.

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
Latest version is Java JRE 7u67.

You can manually check your present version and update as recommended.
https://www.java.com/en/download/installed.jsp

Be careful not to install malware posing as Java update!
Important read this blog.
http://blog.trendmicro.com/trendlabs-security-intelligence/malware-poses-as-an-update-for-java-0-day-fix/

Quoted from the page.
"In light of the recent events surrounding Java, users must seriously consider their use of Java. Do they really need it? If yes, make sure that users follow the steps we recommended and get the security update directly from the official oracle website." at:
http://www.oracle.com/technetwork/java/javase/downloads/index.html

How to disable Java in your browsers
http://www.infoworld.com/t/web-browsers/how-disable-java-in-your-browsers-210882


If present remove the old version(s) of Java using the Add/Remove Programs applet.

Java 7 Update 65

===

If all is well.

To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/
===

#14 nasdaq

nasdaq

  • Malware Response Team
  • 39,955 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:23 AM

Posted 19 October 2014 - 09:11 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users