Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-07-2014 02
Ran by Yai (administrator) on YAI-PC on 01-08-2014 07:44:57
Running from C:\Users\Yai\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Webroot) C:\Program Files\Webroot\WRSA.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BBSvc.EXE
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Coupons.com Inc.) C:\Program Files (x86)\Coupons\CouponPrinterService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Memeo) C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(Webroot) C:\Program Files\Webroot\WRSA.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Google Inc.) C:\Users\Yai\AppData\Local\Google\Update\GoogleUpdate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Seagate LLC) C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\Toshiba\widimon\widimon.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\SeaPort.EXE
(Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\mpas-d_bd_1.179.1461.0.exe
(Microsoft Corporation) C:\f2962da22cb5798dabd3a7\MpMiniSigStub.exe
(Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [590256 2011-09-23] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [712096 2011-12-14] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710560 2011-11-25] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38824 2011-06-28] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1548208 2011-11-24] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [989056 2012-02-13] (TOSHIBA Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2868496 2012-02-24] (Synaptics Incorporated)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12452456 2012-02-22] (Realtek Semiconductor)
HKLM-x32\...\Run: [TSleepSrv] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe [253312 2011-11-21] (TOSHIBA)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-07-18] (Intel Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM-x32\...\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [764536 2014-07-30] (Webroot)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoViewOnDrive] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\...\Policies\Explorer: [NoViewContextMenu] 0
HKLM\...\Policies\Explorer: [NoShellSearchButton] 0
HKLM\...\Policies\Explorer: [NoFind] 0
HKLM\...\Policies\Explorer: [NoFile] 0
HKLM\...\Policies\Explorer: [HideClock] 0
HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\...\Policies\Explorer: [NoSetFolders] 0
HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\...\Policies\Explorer: [NoSetTaskbar] 0
HKLM\...\Policies\Explorer: [NoDeletePrinter] 0
HKLM\...\Policies\Explorer: [NoDFSTab] 0
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\...\Policies\Explorer: [NoLogoff] 0
HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 0
HKLM\...\Policies\Explorer: [NoSaveSettings] 0
HKLM\...\Policies\Explorer: [NoHardwareTab] 0
HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\...\Policies\Explorer: [NoDesktop] 0
HKU\.DEFAULT\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1081224 2013-02-05] (Autodesk, Inc.)
HKU\.DEFAULT\...\Policies\system: [DisableCMD] 0
HKU\.DEFAULT\...\Policies\system: [NoDispAppearancePage] 0
HKU\.DEFAULT\...\Policies\system: [NoDispBackgroundPage] 0
HKU\.DEFAULT\...\Policies\system: [NoDispSettingsPage] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoFolderOptions] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoControlPanel] 0
HKU\.DEFAULT\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\.DEFAULT\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\.DEFAULT\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\.DEFAULT\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoFind] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoFile] 0
HKU\.DEFAULT\...\Policies\Explorer: [HideClock] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoSetFolders] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoDFSTab] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoLogoff] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoResolveSearch] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoSaveSettings] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoHardwareTab] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\.DEFAULT\...\MountPoints2: {335de3db-53f9-11e3-8886-00266c264d14} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-02-01] (Google Inc.)
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Run: [Google Update] => C:\Users\Yai\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-11-11] (Google Inc.)
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: []
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\MountPoints2: D - D:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\MountPoints2: F - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\MountPoints2: {25e37647-f7de-11e2-ba6b-00266c264d14} - D:\TL-Bootstrap.exe
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\MountPoints2: {25e376e7-f7de-11e2-ba6b-00266c264d14} - D:\MotoCastSetup.exe -a
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\MountPoints2: {335de3db-53f9-11e3-8886-00266c264d14} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\MountPoints2: {3e495bbe-6ca3-11e2-a1bb-ec9c38f8810b} - H:\TL_Bootstrap.exe
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\MountPoints2: {744ed03e-fdeb-11e2-b73e-00266c264d14} - D:\MotoCastSetup.exe -a
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\MountPoints2: {8bcfcb3c-5afc-11e3-bcc3-00266c264d14} - D:\iLinker.exe
HKU\S-1-5-21-3953454205-2245465809-1353616732-1000\...\MountPoints2: {af640abf-7286-11e3-a1a9-00266c264d14} - D:\VZW_Software_upgrade_assistant.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install Webroot FF RunOnce.lnk
ShortcutTarget: Install Webroot FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install Webroot IE RunOnce.lnk
ShortcutTarget: Install Webroot IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (No File)
Startup: C:\Users\Yai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Canon IJ Status Monitor Canon MX450 series Printer.lnk
ShortcutTarget: Canon IJ Status Monitor Canon MX450 series Printer.lnk -> C:\Users\Yai\CNMSSC~1.DLL,SMStarterEntryPoint CNBJNP_180CACF816B0;Canon MX450 series Printer;cnmss Canon MX450 series Printer (Local).dll;Canon IJ Status Monitor Canon MX450 series Printer.lnk (No File)
ShellIconOverlayIdentifiers: AutoCAD Digital Signatures Icon Overlay Handler -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\system32\AcSignIcon.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: ShellExt1 -> {2012DE06-50C0-48BD-ACDE-88F95D4CAD1F} => C:\Program Files (x86)\4Sync\ShellExt.dll ()
ShellIconOverlayIdentifiers: ShellExt2 -> {C72C6188-BEF2-46E5-A89A-52F0ED75219E} => C:\Program Files (x86)\4Sync\ShellExt.dll ()
ShellIconOverlayIdentifiers: ShellExt3 -> {C92F6BC2-AF61-4C0E-80E0-939B8282DDB7} => C:\Program Files (x86)\4Sync\ShellExt.dll ()
ShellIconOverlayIdentifiers: ShellExt4 -> {CB1EFEF8-D5E0-49D1-B768-41B48B1D7803} => C:\Program Files (x86)\4Sync\ShellExt.dll ()
ShellIconOverlayIdentifiers: _WrSyncExcl -> {8D7FC74C-E409-42DF-8EEE-69D45FAE2F30} => C:\windows\system32\WRusr.dll (Webroot)
ShellIconOverlayIdentifiers: _WrSyncGreen -> {6DA1ED92-315E-4D0B-B354-9D5F519DBA95} => C:\windows\system32\WRusr.dll (Webroot)
ShellIconOverlayIdentifiers: _WrSyncRed -> {1914B27A-33C8-46F8-A1C2-F993268D4564} => C:\windows\system32\WRusr.dll (Webroot)
ShellIconOverlayIdentifiers: _WrSyncYellow -> {C14874EA-ACE4-4A47-8A81-18C4D1C40868} => C:\windows\system32\WRusr.dll (Webroot)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://speedial.com/?f=1&a=spd_md_1...GtByE0F0EyByE0A0C0E0DtDzy2Q&cr=1771114938&ir=
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=US&userid=4a88a6b1-cd00-443e-88c1-9476f510c4ac&searchtype=ds&q={searchTerms}&installDate=28/07/2013
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar =
http://search.msn.com/spbasic.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchURL =
http://home.microsoft.com/access/autosearch.asp?p=%s
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {31090377-0740-419E-BEFC-A56E50500D5B} URL =
SearchScopes: HKLM - {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO
SearchScopes: HKLM-x32 - DefaultScope {DD698B83-A519-4BF5-9E90-4CCDC55591B4} URL =
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=US&userid=4a88a6b1-cd00-443e-88c1-9476f510c4ac&searchtype=ds&q={searchTerms}&installDate=28/07/2013
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://speedial.com/results.php?f=4&q={searchTerms}&a=spd_md_14_26_ch&cd=2XzuyEtN2Y1L1Qzuzy0CyE0EtAyCtAzy0DyE0AtC0FyEtByDtN0D0Tzu0SzytDzztN1L2XzutBtFtBtCtFtCtCtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyBtA0C0AyByCzyzztGyDtC0C0EtG0B0B0CtCtGyEtDyC0DtGtD0DtB0F0FtCtD0F0F0DyC0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0CyB0A0BzzzzyCtG0D0ByB0DtGzz0F0C0BtG0DtB0C0FtGtByE0F0EyByE0A0C0E0DtDzy2Q&cr=1771114938&ir=
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=US&userid=4a88a6b1-cd00-443e-88c1-9476f510c4ac&searchtype=ds&q={searchTerms}&installDate=28/07/2013
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://speedial.com/results.php?f=4&q={searchTerms}&a=spd_md_14_26_ch&cd=2XzuyEtN2Y1L1Qzuzy0CyE0EtAyCtAzy0DyE0AtC0FyEtByDtN0D0Tzu0SzytDzztN1L2XzutBtFtBtCtFtCtCtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyBtA0C0AyByCzyzztGyDtC0C0EtG0B0B0CtCtGyEtDyC0DtGtD0DtB0F0FtCtD0F0F0DyC0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0CyB0A0BzzzzyCtG0D0ByB0DtGzz0F0C0BtG0DtB0C0FtGtByE0F0EyByE0A0C0E0DtDzy2Q&cr=1771114938&ir=
SearchScopes: HKCU - {049C64F6-E1C2-46CE-8F5C-D08BDD6919D9} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
SearchScopes: HKCU - {31090377-0740-419E-BEFC-A56E50500D5B} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {DD698B83-A519-4BF5-9E90-4CCDC55591B4} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL =
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll (CANON INC.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll (LastPass)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar64.dll (Webroot)
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Webroot\WRData\PKG\Vistax64\wrflt.dll (Webroot)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll (TOSHIBA Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll (LastPass)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll (Webroot)
BHO-x32: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Webroot\WRData\PKG\Vistax86\wrflt.dll (Webroot)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (TOSHIBA Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll (LastPass)
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar64.dll (Webroot)
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll (LastPass)
Toolbar: HKLM-x32 - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll (Webroot)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
FireFox:
========
FF ProfilePath: C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default
FF DefaultSearchEngine: Speedial
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", "");
FF SelectedSearchEngine: Speedial
FF Homepage: hxxp://speedial.com/?f=1&a=spd_md_14_26_ch&cd=2XzuyEtN2Y1L1Qzuzy0CyE0EtAyCtAzy0DyE0AtC0FyEtByDtN0D0Tzu0SzytDzztN1L2XzutBtFtBtCtFtCtCtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyBtA0C0AyByCzyzztGyDtC0C0EtG0B0B0CtCtGyEtDyC0DtGtD0DtB0F0FtCtD0F0F0DyC0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0CyB0A0BzzzzyCtG0D0ByB0DtGzz0F0C0BtG0DtB0C0FtGtByE0F0EyByE0A0C0E0DtDzy2Q&cr=1771114938&ir=
FF Keyword.URL: hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=407453&p=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass64.dll (LastPass)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @Motive.com/NpMotive,version=1.0 - C:\Program Files (x86)\ATT\8.3.1.18\ma\bin\npMotive.dll No File
FF Plugin-x32: @Motive.com/npMotiveRequest,version=1.0 - C:\Program Files (x86)\Common Files\Motive\npMotiveRequest.dll (Alcatel-Lucent)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Yai\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Yai\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF user.js: detected! => C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll (Coupons, Inc.)
FF SearchPlugin: C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\searchplugins\aol-search.xml
FF SearchPlugin: C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\searchplugins\conduit.xml
FF SearchPlugin: C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\searchplugins\safeguard-secure-search.xml
FF SearchPlugin: C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\searchplugins\Speedial.xml
FF SearchPlugin: C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\searchplugins\yahoo_ff.xml
FF Extension: Flash Video Downloader - Full HD Download - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\
[email protected] [2014-05-24]
FF Extension: Click&Clean - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\
[email protected] [2013-07-29]
FF Extension: SaveeRPro - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\
[email protected] [2014-07-10]
FF Extension: LastPass - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\
[email protected] [2014-05-08]
FF Extension: AOL Toolbar - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} [2014-01-05]
FF Extension: Webroot Password Manager - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\{8ac62a8b-8b3f-43ba-9b1a-90c299b9dfda} [2014-07-30]
FF Extension: appbario13 - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\{976cd962-e0ca-4337-aea7-d93fae63a79c} [2013-12-28]
FF Extension: Speedial - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\{fa95f577-07cb-4470-ac90-e843f5f83c52} [2014-06-29]
FF Extension: Tube Enhancer Plus - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\
[email protected] [2013-08-27]
FF Extension: Slick Savings - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\
[email protected] [2014-05-14]
FF Extension: FastestFox - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\
[email protected] [2013-07-29]
FF Extension: Thumbnail Zoom Plus - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\
[email protected] [2013-07-29]
FF Extension: Tile Tabs - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\
[email protected] [2013-07-29]
FF Extension: Start Page - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}.xpi [2014-05-14]
FF Extension: DownThemAll! - C:\Users\Yai\AppData\Roaming\Mozilla\Firefox\Profiles\gf2jlqhu.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2013-07-29]
FF Extension: Motive Extension - C:\Program Files (x86)\Mozilla Firefox\extensions\
[email protected].xpi [2014-05-14]
FF Extension: Motive Extension - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\
[email protected] [2014-05-14]
FF HKLM-x32\...\Firefox\Extensions: [{DAC3F861-B30D-40dd-9166-F4E75327FAC7}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-03-29]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\...\Firefox\Extensions: [
[email protected]] - C:\Program Files (x86)\Mozilla Firefox\extensions\
[email protected]
FF HKLM-x32\...\Firefox\Extensions: [
[email protected]] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-04-16]
FF HKLM-x32\...\Firefox\Extensions: [
[email protected]] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Extension: Webroot Filtering Extension - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer [2014-07-30]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "https://www.google.com/"
CHR NewTab: "chrome-extension://ncdfeghkpohnalmpblddmnppfooljekh/core/newpage-pop.html", "chrome-extension://bakijjialdiiboeaknfpmflphhmljfkd/content/newtab/newtab.html"
CHR Extension: (Google Drive) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-27]
CHR Extension: (Speedial) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd [2014-06-26]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-23]
CHR Extension: (WOT) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-04-07]
CHR Extension: (YouTube) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-07]
CHR Extension: (GeoGebra) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2014-07-27]
CHR Extension: (Google Cast) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2014-04-07]
CHR Extension: (Classic Games) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpckajjkmjncafjlkielcgheibdlnfgc [2014-07-27]
CHR Extension: (Go Extensions) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdlogpoaigpjcfjfllhjdaniobkjnkmg [2014-04-07]
CHR Extension: (Bible Inspiration Quotes) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\cefjlnahlihagmakdigkomidanbcheol [2014-07-27]
CHR Extension: (Slacker Radio) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckngegfcpnbbcejpfnakcdcjgigaiole [2014-07-27]
CHR Extension: (Videostream for Google Chromecast) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2014-07-27]
CHR Extension: (Spotify - Music for every moment) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2014-04-07]
CHR Extension: (Search by Image (by Google)) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2014-07-27]
CHR Extension: (AutoCAD 360) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcjeclnkejmbepoibfnamioojinoopln [2014-04-07]
CHR Extension: (Read Later Fast) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\decdfngdidijkdjgbknlnepdljfaepji [2014-07-27]
CHR Extension: (Circles Share) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm [2014-06-09]
CHR Extension: (ESPN Cricinfo) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlklinjgampohhihndkofhhaahoicoip [2014-04-07]
CHR Extension: (NYTimes) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecmphppfkcfflgglcokcbdkofpfegoel [2014-07-27]
CHR Extension: (Motive Extension) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\edmgmpmklgfbohogafcfobonnkogchec [2014-02-05]
CHR Extension: (Facebook news) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\edoadhjjfgeniilpmnoaddaihjkkhheb [2014-07-27]
CHR Extension: (Torrent Turbo Search App) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\eegbffmjdkflkcfncpfjjbggbdlnbdif [2014-04-07]
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2014-04-18]
CHR Extension: (500px) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\egpociadnldbkfkjpmjoaibnbcoeplja [2014-07-27]
CHR Extension: (Box - 10GB of FREE storage) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnkaeblpdcamcioiiabclakabcbjmbl [2014-04-07]
CHR Extension: (Pandora) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl [2014-04-07]
CHR Extension: (Google Play Movies) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\fppdphmgcddhjeddoeghpjefkdlccljb [2014-04-07]
CHR Extension: (Watch TV Shows Online Free) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggnjneabfkaklfkpcjfddehokkgojffb [2014-07-27]
CHR Extension: (AdBlock) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-07]
CHR Extension: (Ebay Shopping Assistant by Spigot) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj [2014-01-26]
CHR Extension: (TweetDeck by Twitter) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2014-04-07]
CHR Extension: (SearchPreview) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcjdanpjacpeeppdjkppebobilhaglfo [2014-04-07]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2014-05-08]
CHR Extension: (Flixster) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgbpjlnkjhllfgfdmieompodgaefjcfh [2014-04-07]
CHR Extension: (Feedly - News, Blogs and Youtube) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\hipbfijinpcgfogaopmgehiegacbhmob [2014-07-27]
CHR Extension: (AirDroid) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkgndiocipalkpejnpafdbdlfdjihomd [2014-04-07]
CHR Extension: (Google Keep - notes and lists) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2014-04-07]
CHR Extension: (Music Player for Google Drive) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnfeekfpnjbdmelcapngdgkjnhgijjkh [2014-04-07]
CHR Extension: (Crackle) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfamoapbmmmlknoopmmfofgladlinic [2014-04-07]
CHR Extension: (Kindle Cloud Reader) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2014-04-07]
CHR Extension: (Domain Error Assistant) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj [2014-04-07]
CHR Extension: (Dribbble HD) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ichgbbciejbjechpkakbegaaenamkpib [2014-06-30]
CHR Extension: (Pixlr Editor) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmaknaampgiegkcjlimdiidlhopknpk [2014-04-07]
CHR Extension: (Incognito This!) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\icnaplnkjfjncegmphmlfpggildllbho [2014-05-06]
CHR Extension: (Google Play Music) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg [2014-04-07]
CHR Extension: (RealDownloader) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-04-02]
CHR Extension: (The Weather Channel for Chrome) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\iflpcokdamgefbghpdipcibmhlkdopop [2014-04-07]
CHR Extension: (Dropbox) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2014-04-07]
CHR Extension: (appbario13) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\iolllphbfidpiigenecjjflaefapfnef [2014-04-02]
CHR Extension: (SoundCloud) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipebkipbeggmmkjjljenoblnfaenambp [2014-07-27]
CHR Extension: (Bitcasa Everywhere) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbebdjcjllheeclffnofhgcimmlkkbon [2014-04-30]
CHR Extension: (MOG Music) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgljcanfdcmdnncaneopdlcgjlkgpenj [2014-07-27]
CHR Extension: (Earth) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\jieopfhnlbjmbpckpdhfdedccdmngdac [2014-04-07]
CHR Extension: (Pocket Website) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\jijgclgmgjipgefcnnnibgllfonlfdap [2014-04-07]
CHR Extension: (StumbleUpon) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg [2014-07-27]
CHR Extension: (Google Voice (by Google)) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo [2014-05-06]
CHR Extension: (Daily Horoscope) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjcmmiilfdkoehhfpcgkmnnnhkpkjnjn [2014-07-27]
CHR Extension: (Webroot Filtering Extension) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjeghcllfecehndceplomkocgfbklffd [2014-07-30]
CHR Extension: (Hootsuite) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\kneloppijbcidgidihgdjnooihjcdbij [2014-07-27]
CHR Extension: (Google Play) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2014-04-07]
CHR Extension: (Evernote Web) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2014-04-07]
CHR Extension: (Pinterest ) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldekkfiehnegbjkcmalkfcgfecambndd [2014-07-27]
CHR Extension: (Google Maps) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-04-07]
CHR Extension: (Extensions Manager (aka Switcher)) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpleipinonnoibneeejgjnoeekmbopbc [2014-05-06]
CHR Extension: (stingyTV) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcpdhldalfjnjgbpeiafgbklgkgoojbh [2014-07-27]
CHR Extension: (PocketCloud) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\mddnnaelaienpmompfgedlmpbkpbnhpb [2014-07-27]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2014-04-07]
CHR Extension: (Slick Savings) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk [2014-04-07]
CHR Extension: (Pocket) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2014-04-07]
CHR Extension: (Incredible StartPage - Productive Start Page) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdfeghkpohnalmpblddmnppfooljekh [2014-04-07]
CHR Extension: (Hangouts) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2014-05-06]
CHR Extension: (LastPass Vault) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncliohomlfopnmlfkepkcbnhmeijkhhf [2014-04-07]
CHR Extension: (OneDrive) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2014-07-27]
CHR Extension: (Google Wallet) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-14]
CHR Extension: (Google Chrome to Phone Extension) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco [2014-07-27]
CHR Extension: (Any.do) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocgddccilgpeepgglnlpchkpgamkgmld [2014-04-07]
CHR Extension: (My Chrome Theme) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2014-07-27]
CHR Extension: (Webroot Password Manager) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab [2014-07-31]
CHR Extension: (Picasa) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-04-07]
CHR Extension: (Instagram for Chrome) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnbmdkdflhjiclaoiiifmheknpccalb [2014-07-27]
CHR Extension: (GoPhoto.it) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk [2014-04-02]
CHR Extension: (Amazon Shopping Assistant by Spigot) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp [2014-01-26]
CHR Extension: (Evernote Web Clipper) - C:\Users\Yai\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-04-07]
CHR HKCU\...\Chrome\Extension: [iolllphbfidpiigenecjjflaefapfnef] - C:\Users\Yai\AppData\Local\CRE\iolllphbfidpiigenecjjflaefapfnef.crx [2013-09-24]
CHR HKLM-x32\...\Chrome\Extension: [edmgmpmklgfbohogafcfobonnkogchec] - C:\Program Files (x86)\Common Files\Motive\extensions\MotiveRequest.crx [2014-02-05]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2013-12-21]
CHR HKLM-x32\...\Chrome\Extension: [hbcennhacfaagdopikcegfcobcadeocj] - C:\Program Files (x86)\Common Files\Spigot\GC\saebay_1.1.crx [2013-10-14]
CHR HKLM-x32\...\Chrome\Extension: [icdlfehblmklkikfigmjhbmmpmkmpooj] - C:\Program Files (x86)\Common Files\Spigot\GC\ErrorAssistant_1.3.crx [2013-12-27]
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-03-06]
CHR HKLM-x32\...\Chrome\Extension: [iolllphbfidpiigenecjjflaefapfnef] - C:\Users\Yai\AppData\Local\CRE\iolllphbfidpiigenecjjflaefapfnef.crx [2013-09-24]
CHR HKLM-x32\...\Chrome\Extension: [jbpkiefagocgkmemidfngdkamloieekf] - C:\Program Files (x86)\TornTV.com\torn11.crx [2013-09-24]
CHR HKLM-x32\...\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - C:\ProgramData\WRData\PKG\CHROME\CHROME_1.0.0.32.crx [2014-07-30]
CHR HKLM-x32\...\Chrome\Extension: [mhkaekfpcppmmioggniknbnbdbcigpkk] - C:\Users\Yai\AppData\Local\Slick Savings\coupons.crx [2014-01-26]
CHR HKLM-x32\...\Chrome\Extension: [nbmafkdmkkckhggblphicnnhlgljnoje] - C:\Program Files (x86)\TornTV.com\torn2_10.crx [2014-01-26]
CHR HKLM-x32\...\Chrome\Extension: [okfhiodnpcnnnpgbjbhfebjnbagmfhab] - C:\ProgramData\WRData\pkg\lpchrome.crx [2014-07-30]
CHR HKLM-x32\...\Chrome\Extension: [pfmopbbadnfoelckkcmjjeaaegjpjjbk] - C:\Program Files (x86)\Gophoto.it\gophotoit14.crx [2012-07-31]
CHR HKLM-x32\...\Chrome\Extension: [pfndaklgolladniicklehhancnlgocpp] - C:\Program Files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx [2012-11-22]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.) [File not signed]
R2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [176624 2014-02-13] (Coupons.com Inc.)
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [1384992 2013-10-02] (Fitbit, Inc.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-01-20] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-01-20] (Intel Corporation)
S2 leagateDashboardService; C:\windows\System32\leagateDashboardService.dll [1607680 2013-12-23] () [File not signed]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-06] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 Thpsrv; C:\windows\system32\ThpSrv.exe [558592 2011-04-20] (TOSHIBA Corporation) [File not signed]
R2 TosCoSrv; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [580608 2012-02-02] (TOSHIBA Corporation) [File not signed]
R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [764536 2014-07-30] (Webroot)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation)
S2 HPSLPSVC; C:\Users\Yai\AppData\Local\Temp\7zS3F06\hpslpsvc64.dll [X]
S2 KMSEmulator; No ImagePath
S2 MCLIENT; No ImagePath
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [36096 2013-05-21] (Advanced Micro Devices, Inc.)
S3 BTCFilterService; No ImagePath
S1 ccSet_MCLIENT; No ImagePath
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-02-01] (DT Soft Ltd)
S1 lsnfd; No ImagePath
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
S3 motandroidusb; No ImagePath
S3 motccgp; No ImagePath
S3 motccgpfl; No ImagePath
S3 MotoSwitchService; No ImagePath
S3 Motousbnet; No ImagePath
S3 motusbdevice; No ImagePath
S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MREMP50a64; C:\Program Files\Common Files\Motive\MREMP50a64.SYS [43008 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50a64; C:\Program Files\Common Files\Motive\MRESP50a64.SYS [40960 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
S3 prl_virtual_sound; C:\Windows\System32\DRIVERS\prl_virtual_sound.sys [45800 2014-04-16] (Parallels Holdings, Ltd. and its affiliates.)
R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [290520 2013-10-24] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\System32\DRIVERS\Smb_driver.sys [22800 2012-02-24] (Synaptics Incorporated)
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [114176 2014-07-30] (Webroot)
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
U0 SR;
U2 srservice;
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
NETSVC: leagateDashboardService -> C:\windows\System32\leagateDashboardService.dll ()
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-01 07:44 - 2014-08-01 07:45 - 00063625 _____ () C:\Users\Yai\Downloads\FRST.txt
2014-08-01 07:44 - 2014-08-01 07:45 - 00000000 ____D () C:\FRST
2014-08-01 07:43 - 2014-08-01 07:43 - 02094080 _____ (Farbar) C:\Users\Yai\Downloads\FRST64.exe
2014-08-01 07:40 - 2014-05-14 11:23 - 02477536 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2014-08-01 07:40 - 2014-05-14 11:23 - 00058336 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2014-08-01 07:40 - 2014-05-14 11:23 - 00044512 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2014-08-01 07:40 - 2014-05-14 11:21 - 02620928 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2014-08-01 07:39 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2014-08-01 07:39 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2014-08-01 07:39 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2014-08-01 07:39 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2014-08-01 00:32 - 2014-08-01 00:32 - 00018241 _____ () C:\Users\Yai\Desktop\Documents\hijackthis.log
2014-08-01 00:31 - 2014-08-01 00:31 - 00018241 _____ () C:\Users\Yai\Downloads\hijackthis.log
2014-08-01 00:28 - 2014-08-01 00:28 - 00388608 _____ (Trend Micro Inc.) C:\Users\Yai\Downloads\HijackThis.exe
2014-07-31 13:06 - 2014-07-31 13:06 - 00000776 _____ () C:\Users\Yai\Desktop\Webroot SecureAnywhere.lnk
2014-07-30 22:54 - 2014-07-30 22:55 - 00000000 ____D () C:\Users\Yai\AppData\Local\lptmp1577920504
2014-07-30 22:52 - 2014-08-01 07:45 - 00000000 ____D () C:\ProgramData\WRData
2014-07-30 22:52 - 2014-07-30 22:53 - 00000000 ____D () C:\Program Files\Webroot
2014-07-30 22:52 - 2014-07-30 22:52 - 00153256 _____ (Webroot) C:\windows\SysWOW64\WRusr.dll
2014-07-30 22:52 - 2014-07-30 22:52 - 00114176 _____ (Webroot) C:\windows\system32\Drivers\WRkrn.sys
2014-07-30 22:52 - 2014-07-30 22:52 - 00103816 _____ (Webroot) C:\windows\system32\WRusr.dll
2014-07-30 22:52 - 2014-07-30 22:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
2014-07-30 22:50 - 2014-07-30 22:51 - 00764536 _____ (Webroot) C:\Users\Yai\Downloads\wsainstall.exe
2014-07-30 07:30 - 2014-07-31 22:26 - 00018120 _____ () C:\windows\PFRO.log
2014-07-29 01:23 - 2014-07-29 01:23 - 00015998 _____ () C:\Users\Yai\Downloads\[kickass.to]kid.ink.main.chick.remix.feat.chris.brown.french.montana.yo.gotti.tyga.lil.bibby.2014.single.torrent
2014-07-29 01:22 - 2014-07-29 01:22 - 00008604 _____ () C:\Users\Yai\Downloads\[kickass.to]tyga.ft.young.thug.hookah.mp3.torrent
2014-07-29 01:22 - 2014-07-29 01:22 - 00003471 _____ () C:\Users\Yai\Downloads\[kickass.to]ca.h.out.she.twerkin.remix.ft.juicy.j.lil.boosie.ty.dolla.sign.kid.ink.mp3.torrent
2014-07-29 01:20 - 2014-07-29 01:20 - 00003126 _____ () C:\Users\Yai\Downloads\[kickass.to]jeezy.ft.jay.z.seen.it.all.320kbps.2014.torrent
2014-07-29 01:19 - 2014-07-29 01:19 - 00014033 _____ () C:\Users\Yai\Downloads\[kickass.to]rich.gang.lifestyle.feat.young.thug.rich.homie.quan.2014.single.torrent
2014-07-29 01:19 - 2014-07-29 01:19 - 00010013 _____ () C:\Users\Yai\Downloads\[kickass.to]jason.derulo.wiggle.ft.snoop.dogg.mp3.320kbps.torrent
2014-07-29 01:18 - 2014-07-29 01:18 - 00014032 _____ () C:\Users\Yai\Downloads\[kickass.to]t.i.about.the.money.feat.young.thug.2014.single.torrent
2014-07-29 01:17 - 2014-07-29 01:17 - 00011018 _____ () C:\Users\Yai\Downloads\[kickass.to]5.seconds.of.summer.amnesia.2014.itunes.single.the.hh.torrent
2014-07-29 01:15 - 2014-07-29 01:15 - 00013458 _____ () C:\Users\Yai\Downloads\[kickass.to]august.alsina.numb.feat.b.o.b.yo.gotti.2013.single.torrent
2014-07-29 01:15 - 2014-07-29 01:15 - 00009329 _____ () C:\Users\Yai\Downloads\[kickass.to]mr.probz.waves.2013.single.torrent
2014-07-29 01:14 - 2014-07-29 01:14 - 00003392 _____ () C:\Users\Yai\Downloads\[kickass.to]ajr.i.m.ready.2014.torrent
2014-07-29 01:13 - 2014-07-29 01:13 - 00014181 _____ () C:\Users\Yai\Downloads\[kickass.to]drake.0.to.100.the.catch.up.2014.single.torrent
2014-07-29 01:12 - 2014-07-29 01:12 - 00011881 _____ () C:\Users\Yai\Downloads\[kickass.to]electro.house.steve.aoki.chris.lake.tujamo.delirious.boneless.feat.kid.ink.ultra.ul5420.2014.mp3.320.kbps.edm.rg.torrent
2014-07-29 01:09 - 2014-07-29 01:09 - 00002887 _____ () C:\Users\Yai\Downloads\[kickass.to]tiesto.wasted.ft.matthew.koma.2014.torrent
2014-07-29 01:09 - 2014-07-29 01:09 - 00000987 _____ () C:\Users\Yai\Downloads\[kickass.to]tove.lo.habits.stay.high.the.chainsmokers.extended.mix.mp3.edm.rg.mousr.torrent
2014-07-29 01:08 - 2014-07-29 01:08 - 00013917 _____ () C:\Users\Yai\Downloads\[kickass.to]coldplay.a.sky.full.of.stars.2014.single.torrent
2014-07-29 01:07 - 2014-07-29 01:07 - 00011400 _____ () C:\Users\Yai\Downloads\[kickass.to]ingrid.michaelson.girls.chase.boys.single.2014.torrent
2014-07-29 01:07 - 2014-07-29 01:07 - 00003456 _____ () C:\Users\Yai\Downloads\[kickass.to]echosmith.cool.kids.2013.torrent
2014-07-29 01:05 - 2014-07-29 01:05 - 00008343 _____ () C:\Users\Yai\Downloads\[kickass.to]demi.lovato.really.dont.care.solo.version.2014.hipnhop.mp3.torrent
2014-07-29 01:04 - 2014-07-29 01:04 - 00013938 _____ () C:\Users\Yai\Downloads\[kickass.to]john.legend.all.of.me.2013.single.torrent
2014-07-29 01:03 - 2014-07-29 01:03 - 00010792 _____ () C:\Users\Yai\Downloads\[kickass.to]t.i.no.mediocre.feat.iggy.azalea.2014.single.torrent
2014-07-29 01:02 - 2014-07-29 01:02 - 00007724 _____ () C:\Users\Yai\Downloads\[kickass.to]lil.wayne.believe.me.feat.drake.torrent
2014-07-29 01:01 - 2014-07-29 01:01 - 00012701 _____ () C:\Users\Yai\Downloads\[kickass.to]chris.brown.new.flame.feat.usher.rick.ross.2014.single.torrent
2014-07-29 01:01 - 2014-07-29 01:01 - 00003930 _____ () C:\Users\Yai\Downloads\[kickass.to]nicki.minaj.no.flex.zone.remix.mp3.torrent
2014-07-29 01:00 - 2014-07-29 01:00 - 00003151 _____ () C:\Users\Yai\Downloads\[kickass.to]becky.g.shower.2014.torrent
2014-07-29 00:58 - 2014-07-29 00:58 - 00011919 _____ () C:\Users\Yai\Downloads\[kickass.to]onerepublic.love.runs.out.2014.single.torrent
2014-07-29 00:58 - 2014-07-29 00:58 - 00011269 _____ () C:\Users\Yai\Downloads\[kickass.to]ariana.grande.break.free.feat.zedd.2014.single.torrent
2014-07-29 00:57 - 2014-07-29 00:57 - 00002697 _____ () C:\Users\Yai\Downloads\[kickass.to]charli.xcx.boom.clap.2014.torrent
2014-07-29 00:56 - 2014-07-29 00:56 - 00012132 _____ () C:\Users\Yai\Downloads\[kickass.to]tinashe.2.on.feat.schoolboy.q.2014.single.torrent
2014-07-29 00:12 - 2014-07-29 00:12 - 00010065 _____ () C:\Users\Yai\Downloads\[kickass.to]ariana.grande.problem.feat.iggy.azalea.itunes.320.torrent
2014-07-29 00:11 - 2014-07-29 00:11 - 00010558 _____ () C:\Users\Yai\Downloads\[kickass.to]iggy.azalea.fancy.feat.charli.xcx.2014.single.torrent
2014-07-29 00:11 - 2014-07-29 00:11 - 00010184 _____ () C:\Users\Yai\Downloads\[kickass.to]maroon.5.maps.2014.single.torrent
2014-07-29 00:10 - 2014-07-29 00:10 - 00013943 _____ () C:\Users\Yai\Downloads\[kickass.to]jeremih.don.t.tell.em.feat.yg.2014.single.torrent
2014-07-29 00:08 - 2014-07-29 00:08 - 00011988 _____ () C:\Users\Yai\Downloads\[kickass.to]clean.bandit.ft.jess.glynne.rather.be.ft.jess.glynne.rather.be.mp3.zaankanter.torrent
2014-07-29 00:08 - 2014-07-29 00:08 - 00010381 _____ () C:\Users\Yai\Downloads\[kickass.to]pharrell.williams.come.get.it.bae.feat.miley.cyrus.mp3.320kbps.torrent
2014-07-29 00:07 - 2014-07-29 00:07 - 00009270 _____ () C:\Users\Yai\Downloads\[kickass.to]sam.smith.stay.with.me.2014.single.torrent
2014-07-29 00:06 - 2014-07-29 00:06 - 00013386 _____ () C:\Users\Yai\Downloads\[kickass.to]disclosure.feat.sam.smith.latch.torrent
2014-07-29 00:05 - 2014-07-29 00:05 - 00011744 _____ () C:\Users\Yai\Downloads\[kickass.to]magic.rude.single.torrent
2014-07-29 00:02 - 2014-07-29 00:02 - 00003764 _____ () C:\Users\Yai\Downloads\[kickass.to]rihanna.what.now.2013.torrent
2014-07-28 23:55 - 2014-07-28 23:55 - 00017477 _____ () C:\Users\Yai\Downloads\[kickass.to]rihanna.the.woman.in.black.2011.torrent
2014-07-28 23:44 - 2014-07-28 23:44 - 00012764 _____ () C:\Users\Yai\Downloads\[kickass.to]nico.and.vinz.am.i.wrong.torrent
2014-07-28 23:29 - 2014-07-28 23:29 - 00001215 _____ () C:\Users\Yai\Downloads\[kickass.to]stay.rihanna.feat.mikky.ekko.zertop.320kbps.torrent
2014-07-28 23:26 - 2014-07-28 23:26 - 00002420 _____ () C:\Users\Yai\Downloads\[kickass.to]get.lucky.featuring.pharrell.mp3.torrent
2014-07-28 12:31 - 2014-07-29 23:12 - 00000701 _____ () C:\Users\Yai\Desktop\Documents\07-28-14.txt
2014-07-27 22:26 - 2014-08-01 07:31 - 00000616 _____ () C:\windows\setupact.log
2014-07-27 22:26 - 2014-07-27 22:26 - 00000000 _____ () C:\windows\setuperr.log
2014-07-27 14:15 - 2014-08-01 07:45 - 00189787 _____ () C:\windows\WindowsUpdate.log
2014-07-26 08:44 - 2014-07-26 08:44 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\LastPass
2014-07-22 18:41 - 2014-07-11 02:56 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-07-22 18:40 - 2014-07-22 18:40 - 00004489 _____ () C:\windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-22 18:40 - 2014-07-11 03:02 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-22 18:40 - 2014-07-11 02:56 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-07-22 18:40 - 2014-07-11 02:55 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-07-22 17:10 - 2014-07-22 17:10 - 00018344 _____ () C:\Users\Yai\Downloads\[kickass.to]nuts.magazine.2011.biggest.boobs.18.24.february.2011.torrent
2014-07-22 17:08 - 2014-07-22 17:08 - 00003409 _____ () C:\Users\Yai\Downloads\[kickass.to]nuts.magazine.the.uncensored.version.tvs.sexiest.girls.and.more.14.february.2014.torrent
2014-07-22 17:07 - 2014-07-22 17:07 - 00033649 _____ () C:\Users\Yai\Downloads\[kickass.to]nuts.magazine.18.april.2014.the.uncensored.version.torrent
2014-07-22 17:07 - 2014-07-22 17:07 - 00016657 _____ () C:\Users\Yai\Downloads\[kickass.to]nuts.magazine.april.4.2014.uk.pdf.torrent
2014-07-22 17:06 - 2014-07-22 17:06 - 00019533 _____ () C:\Users\Yai\Downloads\[kickass.to]18.nuts.magazine.the.uncensored.version.march.28.2014.march.26.2014.pdf.torrent
2014-07-22 17:06 - 2014-07-22 17:06 - 00017137 _____ () C:\Users\Yai\Downloads\[kickass.to]nuts.magazine.21.february.2014.the.uncensored.version.torrent
2014-07-20 22:37 - 2014-07-20 22:37 - 00013327 _____ () C:\Users\Yai\Downloads\[kickass.to]perfect.*****.say.yes.to.love.2014.320kbps.torrent
2014-07-20 22:36 - 2014-07-20 22:36 - 00019458 _____ () C:\Users\Yai\Downloads\[kickass.to]neneh.cherry.blank.project.2014.torrent
2014-07-20 22:36 - 2014-07-20 22:36 - 00014137 _____ () C:\Users\Yai\Downloads\[kickass.to]perfect.*****.say.yes.to.love.2014.flac.torrent
2014-07-20 22:35 - 2014-07-20 22:35 - 00015627 _____ () C:\Users\Yai\Downloads\[rutracker.org].t4688107.torrent
2014-07-20 22:32 - 2014-07-20 22:32 - 00013862 _____ () C:\Users\Yai\Downloads\[rutracker.org].t4769273.torrent
2014-07-20 22:29 - 2014-07-20 22:29 - 00016844 _____ () C:\Users\Yai\Downloads\[kickass.to]lydia.loveless.somewhere.else.mp3.320.19glide58.h33t.torrent
2014-07-20 22:25 - 2014-07-20 22:25 - 00019656 _____ () C:\Users\Yai\Downloads\[kickass.to]james.vincent.mcmorrow.2.albums.2011.2014.mp3.320.torrent
2014-07-20 22:25 - 2014-07-20 22:25 - 00017471 _____ () C:\Users\Yai\Downloads\[kickass.to]isaiah.rashad.cilvia.demo.2014.itunes.torrent
2014-07-20 22:21 - 2014-07-20 22:21 - 00017600 _____ () C:\Users\Yai\Downloads\[kickass.to]2014.hurray.for.the.riff.raff.small.town.heroes.320.kbps.100.xy.torrent
2014-07-20 22:13 - 2014-07-20 22:13 - 00014727 _____ () C:\Users\Yai\Downloads\[kickass.to]future.honest.2014.album.deluxe.version.mp3.torrent
2014-07-20 21:52 - 2014-07-20 21:52 - 00057043 _____ () C:\Users\Yai\Downloads\[kickass.to]conor.oberst.upside.down.mountain.mp3.320.2014.trfkad.torrent
2014-07-20 21:27 - 2014-07-20 21:27 - 00018228 _____ () C:\Users\Yai\Downloads\[kickass.to]angel.olsen.burn.your.fire.for.no.witness.2014.320kbps.cbr.mp3.vx.p2pdl.torrent
2014-07-20 21:23 - 2014-07-20 21:23 - 00016879 _____ () C:\Users\Yai\Downloads\[kickass.to]alternative.rock.the.afghan.whigs.do.to.the.beast.2014.by.jamal.the.moroccan.torrent
2014-07-20 21:03 - 2014-07-20 21:03 - 00223078 _____ () C:\Users\Yai\Downloads\[kickass.to]wolfgang.amadeus.mozart.discography.tntvillage.torrent
2014-07-16 12:24 - 2014-07-16 12:24 - 00000046 _____ () C:\Users\Default\AppData\Roaming\WB.CFG
2014-07-16 12:24 - 2014-07-16 12:24 - 00000046 _____ () C:\Users\Default User\AppData\Roaming\WB.CFG
2014-07-15 08:27 - 2014-07-18 17:16 - 00000000 ____D () C:\lptmp23433
2014-07-13 19:52 - 2014-07-13 19:52 - 00001754 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-07-13 19:52 - 2014-07-13 19:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-13 19:50 - 2014-07-13 19:52 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-07-13 19:50 - 2014-07-13 19:52 - 00000000 ____D () C:\Program Files\iTunes
2014-07-13 19:50 - 2014-07-13 19:52 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-07-13 19:50 - 2014-07-13 19:50 - 00000000 ____D () C:\Program Files\iPod
2014-07-09 16:48 - 2014-06-29 21:09 - 00519168 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-07-09 16:48 - 2014-06-29 21:04 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-07-09 16:48 - 2014-06-17 21:18 - 00692736 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2014-07-09 16:48 - 2014-06-17 20:51 - 00646144 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe
2014-07-09 16:48 - 2014-06-17 20:10 - 03157504 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-07-09 16:48 - 2014-06-06 05:10 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-07-09 16:48 - 2014-06-06 04:44 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2014-07-09 16:48 - 2014-05-30 01:45 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2014-07-09 16:47 - 2014-06-20 15:14 - 00266424 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-07-09 16:47 - 2014-06-20 14:39 - 00240824 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-07-09 16:47 - 2014-06-18 20:39 - 23464448 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-07-09 16:47 - 2014-06-18 20:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-07-09 16:47 - 2014-06-18 20:06 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-07-09 16:47 - 2014-06-18 19:48 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-07-09 16:47 - 2014-06-18 19:42 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-07-09 16:47 - 2014-06-18 19:42 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-07-09 16:47 - 2014-06-18 19:41 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-07-09 16:47 - 2014-06-18 19:41 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-07-09 16:47 - 2014-06-18 19:32 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-07-09 16:47 - 2014-06-18 19:31 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-07-09 16:47 - 2014-06-18 19:26 - 00598016 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-07-09 16:47 - 2014-06-18 19:24 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-07-09 16:47 - 2014-06-18 19:24 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-07-09 16:47 - 2014-06-18 19:23 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-07-09 16:47 - 2014-06-18 19:16 - 17276416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-07-09 16:47 - 2014-06-18 19:14 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-07-09 16:47 - 2014-06-18 19:09 - 00452608 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-07-09 16:47 - 2014-06-18 18:59 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 16:47 - 2014-06-18 18:56 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-07-09 16:47 - 2014-06-18 18:53 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-07-09 16:47 - 2014-06-18 18:51 - 05721088 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-07-09 16:47 - 2014-06-18 18:50 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-07-09 16:47 - 2014-06-18 18:48 - 00292864 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-07-09 16:47 - 2014-06-18 18:39 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-07-09 16:47 - 2014-06-18 18:38 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-07-09 16:47 - 2014-06-18 18:37 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-07-09 16:47 - 2014-06-18 18:36 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-07-09 16:47 - 2014-06-18 18:35 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-07-09 16:47 - 2014-06-18 18:33 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-07-09 16:47 - 2014-06-18 18:32 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-07-09 16:47 - 2014-06-18 18:28 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-07-09 16:47 - 2014-06-18 18:28 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-07-09 16:47 - 2014-06-18 18:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-07-09 16:47 - 2014-06-18 18:27 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-07-09 16:47 - 2014-06-18 18:25 - 00442368 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-07-09 16:47 - 2014-06-18 18:23 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-07-09 16:47 - 2014-06-18 18:22 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-07-09 16:47 - 2014-06-18 18:12 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-07-09 16:47 - 2014-06-18 18:06 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-09 16:47 - 2014-06-18 18:01 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-07-09 16:47 - 2014-06-18 17:59 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-07-09 16:47 - 2014-06-18 17:58 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-07-09 16:47 - 2014-06-18 17:58 - 00239616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-07-09 16:47 - 2014-06-18 17:52 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-07-09 16:47 - 2014-06-18 17:51 - 13527040 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-07-09 16:47 - 2014-06-18 17:49 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-07-09 16:47 - 2014-06-18 17:46 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-07-09 16:47 - 2014-06-18 17:45 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-07-09 16:47 - 2014-06-18 17:35 - 11742208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-07-09 16:47 - 2014-06-18 17:34 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-07-09 16:47 - 2014-06-18 17:15 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-07-09 16:47 - 2014-06-18 17:13 - 01791488 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-07-09 16:47 - 2014-06-18 17:09 - 01139200 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-07-09 16:47 - 2014-06-18 17:07 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-07-09 16:47 - 2014-06-05 09:45 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2014-07-09 16:47 - 2014-06-05 09:26 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2014-07-09 16:47 - 2014-06-05 09:25 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2014-07-09 16:47 - 2014-05-30 03:08 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2014-07-09 16:47 - 2014-05-30 03:08 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-07-09 16:47 - 2014-05-30 03:08 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-07-09 16:47 - 2014-05-30 03:08 - 00307200 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2014-07-09 16:47 - 2014-05-30 03:08 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-07-09 16:47 - 2014-05-30 03:08 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-07-09 16:47 - 2014-05-30 03:08 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-07-09 16:47 - 2014-05-30 02:52 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2014-07-09 16:47 - 2014-05-30 02:52 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2014-07-09 16:47 - 2014-05-30 02:52 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2014-07-09 16:47 - 2014-05-30 02:52 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2014-07-09 16:47 - 2014-05-30 02:52 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2014-07-09 16:47 - 2014-05-30 02:52 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-07-09 16:47 - 2014-05-30 02:52 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-07-07 23:21 - 2014-07-07 23:21 - 00262144 _____ () C:\windows\system32\config\elam
2014-07-04 13:09 - 2014-07-04 13:09 - 00000000 ____D () C:\Users\Yai\AppData\Local\{2D5E9BFF-B561-4838-8D7F-D4317E46DA37}
2014-07-02 20:30 - 2014-07-02 20:30 - 00001990 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
LastRegBack: 2014-07-28 09:43
==================== End Of Log ============================