1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

pop up windows

Discussion in 'Virus & Other Malware Removal' started by quenosabe, Mar 6, 2015.

Thread Status:
Not open for further replies.
Advertisement
  1. quenosabe

    quenosabe Thread Starter

    Joined:
    Apr 17, 2012
    Messages:
    39
    Hi, this is my wife`s computer, we did the mistake of taking it to an acquaintance of us for repair, he did some repairs as the computer is somewhat faster, installed spy bot and avast antivirus free ed.

    Well now it has more problems, any link we click makes pop up windows apear, one of which is efix.com

    The original problem was/still is, that when watching movies online (ex. veetle) the playback stalls and you have to keep moving the mouse for the movie to play.

    I am more concerned with the windows popping up.

    Here is the tsg info:

    Tech Support Guy System Info Utility version 1.0.0.2
    OS Version: Microsoft Windows 7 Starter, Service Pack 1, 32 bit
    Processor: Pentium(R) Dual-Core CPU T4500 @ 2.30GHz, x64 Family 6 Model 23 Stepping 10
    Processor Count: 2
    RAM: 1976 Mb
    Graphics Card: Mobile Intel(R) 4 Series Express Chipset Family, 796 Mb
    Hard Drives: C: Total - 287533 MB, Free - 229099 MB; F: Total - 2035 MB, Free - 2025 MB;
    Motherboard: Hewlett-Packard, 1526
    Antivirus: avast! Antivirus, Updated and Enabled
     
  2. DanoNH

    DanoNH Malware Specialist

    Joined:
    Dec 31, 1969
    Messages:
    106
    First Name:
    Dan
    Hello and Welcome to Tech Support Guy!

    My name is Dan, and I'll be helping you with your issues. If someone else is helping you, either here or at another malware removal assistance site, please let me know so that I may direct my efforts to helping another user. The Staff at Tech Support Guy are ALL volunteers; please keep that in mind if I don’t answer your post as quickly as you’d like. I give what time I can. PLEASE be patient. ;)

    I am currently in training, so there will be another person reviewing my work. This may cause a bit of a delay in my responses, but on the positive side, you will have two sets of eyes reviewing your logs instead of one... :cool:

    • Please note that you should have Administrator rights to perform any fixes.

    • Before we proceed, you may wish to print these instructions for easy reference during the fix. Please be aware that many of the required URLs are hyperlinks in the blue names shown on your screen. Part of the fix may require you to be in Safe Mode, which might not allow you to access the internet, or my instructions.

    • Please understand that malware removal is a complicated, multi-step process. Therefore please stay with me until I tell you that your system is clean. Please do NOT make any system or program changes, or run ANY tools unless I specifically ask you to. Attempting malware removal or clean-up yourself will only extend the time it will take to get your system clean. If you get stuck or have questions, please stop and ask so I can help you.

    • Be sure to back up any personal data files you need to keep (documents, photos, etc.) to a USB flash drive or external hard disk. While every attempt will be made to precisely repair the infections on your computer, due to the complexity and unpredictability of malware clean-up, there is always a risk of data loss.

    • When posting logs, please Copy & Paste the log file contents into a reply. Use multiple posts if necessary, but please do not attach them or post them on a file hosting site.

    OK, let's get started...


    Please download Farbar Recovery Scan Tool and save it to your Desktop.

    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

    • Right click on FRST on your Desktop and choose Run as Administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens, if asked, click Yes to disclaimer.
    • Make sure the Addition.txt check-box is checked.
    • Press Scan button.
    • It will produce two logs called FRST.txt and Addition.txt in the same directory the tool is run from.
    • Please copy and paste the contents of both of those logs back here.
     
  3. quenosabe

    quenosabe Thread Starter

    Joined:
    Apr 17, 2012
    Messages:
    39
  4. DanoNH

    DanoNH Malware Specialist

    Joined:
    Dec 31, 1969
    Messages:
    106
    First Name:
    Dan
    You need the 64 bit version. Let me know if you can't download it.
     
  5. quenosabe

    quenosabe Thread Starter

    Joined:
    Apr 17, 2012
    Messages:
    39
  6. DanoNH

    DanoNH Malware Specialist

    Joined:
    Dec 31, 1969
    Messages:
    106
    First Name:
    Dan
    What web browser are you using to download? Infections may be blocking the download.

    Let's try Safe Mode with Networking:

    NOTE: Please print these instructions or copy/paste them into a notepad file as part of the fix will be in Safe Mode and you will be unable to access this site.


    • Turn your computer off through Shut Down.
    • Wait a few seconds, then turn it back on.
    • Once your computer's manufacturer logo (eg. 'Dell') starts to show, start pressing the F8 key repeatedly.
    • Keep pressing it until the Windows Advanced Options Menu loads up.
    • Make sure 'Safe Mode with Networking' is selected, navigate to it by using the arrow keys.
    • Press enter, and your computer will start booting into Safe Mode with Networking.
    Once booted and logged in:

    Run FRST

    Please download Farbar Recovery Scan Tool and save it to your DESKTOP.
    (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/)

    Note: You need to run the version compatible with your system. Your system needs the 64-bit version.


    • Right click on FRST on your Desktop and choose Run as Administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens, if asked, click Yes to disclaimer.
    • Make sure the Addition.txt check-box is checked.
    • Press Scan button.
    • It will produce two logs called FRST.txt and Addition.txt in the same directory the tool is run from.
    • Please copy and paste the contents of both of those logs back here.
     
  7. quenosabe

    quenosabe Thread Starter

    Joined:
    Apr 17, 2012
    Messages:
    39
    Hi Dan, was using firefox, now switched to chrome.

    The 64 bit did not work, as my system runs on 32 bit...

    Here are the results:

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-03-2015
    Ran by iselba (administrator) on ISELBA-HP on 07-03-2015 08:06:49
    Running from C:\Users\iselba\Desktop
    Loaded Profiles: iselba (Available profiles: iselba)
    Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Español (España, internacional)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Safe Mode (with Networking)
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [QLBController] => C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company)
    HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
    HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1684776 2010-01-22] (Synaptics Incorporated)
    HKLM\...\Run: [WirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
    HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
    HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
    HKLM\...\Run: [ACQTMOUSE] => C:\Program Files\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe [501760 2008-08-01] ()
    HKLM\...\Run: [vProt] => C:\Program Files\AVG Secure Search\vprot.exe [2640408 2014-08-26] ()
    HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [495708 2015-02-03] (IDT, Inc.)
    HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
    HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5513424 2015-03-03] (Avast Software s.r.o.)
    HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [335232 2015-02-10] (Oracle Corporation)
    Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-01-22] (Hewlett-Packard Company)
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-01-26] (Google Inc.)
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5496600 2015-01-20] (Piriform Ltd)
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\...\Policies\system: [LogonHoursAction] 2
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\...\MountPoints2: {2be8b766-5f2f-11e0-b685-1cc1deb8d26d} - D:\LaunchU3.exe -a
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\...\MountPoints2: {b043abf2-91d3-11e2-bb49-1cc1deb8d26d} - D:\iStudio.exe
    Startup: C:\Users\iselba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (Avast Software s.r.o.)
    BootExecute: autocheck autochk * sdnclean.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hp&ts...HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=ds&ts=1423947936&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hp&ts...HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=ds&ts=1423947936&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&q={searchTerms}
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hp&ts...HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hp&ts...HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX
    URLSearchHook: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 - (No Name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File
    URLSearchHook: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 - (No Name) - {93a3111f-4f74-4ed8-895e-d9708497629e} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll (MindSpark)
    URLSearchHook: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=ds&ts=1423947936&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&q={searchTerms}
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=ds&ts=1423947936&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&q={searchTerms}
    SearchScopes: HKLM -> {AA74C1E3-044F-4DEE-9963-9FED50D139A3} URL = http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
    SearchScopes: HKLM -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm072^YYA^mx&si=pconverter&ptb=0B1FDA34-96E2-4E81-B1AE-12874FB91B62&ind=2013092818&n=77fd5bd2&psa=&st=sb&searchfor={searchTerms}
    SearchScopes: HKU\.DEFAULT -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
    SearchScopes: HKU\.DEFAULT -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL =
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {AA74C1E3-044F-4DEE-9963-9FED50D139A3} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    BHO: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files\XTab\SupTab.dll [2015-01-16] (Thinknice Co. Limited)
    BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
    BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-06] (Oracle Corporation)
    BHO: No Name -> {84FF7BD6-B47F-46F8-9130-01B2696B36CB} -> No File
    BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-03] (Avast Software s.r.o.)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
    BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02] (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    BHO: AVG Security Toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Secure Search\18.1.9.799\AVG Secure Search_toolbar.dll [2014-08-26] (AVG Secure Search)
    BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-03-27] (Google Inc.)
    BHO: Search Assistant BHO -> {c547c6c2-561b-4169-a2a5-20ba771ca93b} -> C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll [2013-09-28] (MindSpark)
    BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-06] (Oracle Corporation)
    BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
    Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02] (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
    Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
    Toolbar: HKLM - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\18.1.9.799\AVG Secure Search_toolbar.dll [2014-08-26] (AVG Secure Search)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-03-27] (Google Inc.)
    Toolbar: HKU\.DEFAULT -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    Toolbar: HKU\.DEFAULT -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-03-27] (Google Inc.)
    Toolbar: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    Toolbar: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
    Toolbar: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
    Toolbar: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-03-27] (Google Inc.)
    Toolbar: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File []
    Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File []
    Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File []
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll [2014-08-11] (AVG Secure Search)
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

    FireFox:
    ========
    FF ProfilePath: C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default
    FF NewTab: chrome://quick_start/content/index.html
    FF DefaultSearchEngine: key-find
    FF SelectedSearchEngine: key-find
    FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
    FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File
    FF Plugin: @ei.RadioRage_4j.com/Plugin -> C:\Program Files\RadioRage_4jEI\Installr\1.bin\NP4jEISB.dll No File
    FF Plugin: @ei.Zwinky_5q.com/Plugin -> C:\Program Files\Zwinky_5qEI\Installr\1.bin\NP5qEISB.dll No File
    FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-11-18] (Foxit Corporation)
    FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-06] (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-06] (Oracle Corporation)
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
    FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
    FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
    FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
    FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files\Veetle\plugins\npVeetle.dll [2012-01-13] (Veetle Inc)
    FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files\Veetle\Player\npvlc.dll [2012-01-13] (Veetle Inc)
    FF Plugin: @VideoDownloadConverter_4z.com/Plugin -> C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll No File
    FF user.js: detected! => C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\user.js [2015-03-07]
    FF SearchPlugin: C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\searchplugins\askcom.xml [2013-06-21]
    FF SearchPlugin: C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\searchplugins\iminent.xml [2014-01-01]
    FF SearchPlugin: C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\searchplugins\key-find.xml [2015-02-16]
    FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml [2014-06-22]
    FF Extension: Fast Start - C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\Extensions\[email protected] [2015-02-14]
    FF Extension: FF Toolbar - C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\Extensions\[email protected] [2015-02-14]
    FF Extension: Adblock Plus Pop-up Addon - C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\Extensions\[email protected] [2012-09-23]
    FF Extension: Test Pilot - C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\Extensions\[email protected] [2012-09-04]
    FF Extension: Adblock Plus - C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-10-15]
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\ProgramData\AVG Secure Search\FireFoxExt\18.1.9.799
    FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\18.1.9.799 [2014-08-25]
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\extensions\[email protected]
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\extensions\[email protected]
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
    FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-03-03]

    Chrome:
    =======
    CHR HomePage: Default -> hxxp://www.key-find.com/?type=hp&ts=1423947936&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX
    CHR DefaultSearchKeyword: Default -> key-find
    CHR DefaultSuggestURL: Default ->
    CHR Profile: C:\Users\iselba\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Drive) - C:\Users\iselba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-01]
    CHR Extension: (YouTube) - C:\Users\iselba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-01]
    CHR Extension: (Google Search) - C:\Users\iselba\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-01]
    CHR Extension: (AdBlock) - C:\Users\iselba\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-07-27]
    CHR Extension: (Avast Online Security) - C:\Users\iselba\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-06]
    CHR Extension: (AVG Security Toolbar) - C:\Users\iselba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2013-11-30]
    CHR Extension: (Google Wallet) - C:\Users\iselba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-30]
    CHR Extension: (Gmail) - C:\Users\iselba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-01]
    CHR HKLM\...\Chrome\Extension: [aaaaojmikegpiepcfdkkjaplodkpfmlo] - C:\Users\iselba\AppData\Local\APN\GoogleCRXs\apnorjtoolbar.crx [Not Found]
    CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-03]
    CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\18.1.0.443\avg.crx [2014-04-27]

    ========================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-11-02] (LSI Corporation)
    S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-03-03] (Avast Software s.r.o.)
    S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3205216 2015-03-03] (Avast Software)
    S3 AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe [167264 2011-11-10] ()
    S3 Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [3537672 2010-06-29] (Motorola, Inc.)
    S3 Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [824584 2010-05-20] (Motorola, Inc.)
    S2 Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [512776 2010-05-20] (Motorola, Inc.)
    S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2010-12-13] (Macrovision Europe Ltd.) [File not signed]
    S2 FoxitCloudUpdateService; C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [244448 2014-10-28] (Foxit Software Inc.)
    S2 HP Support Assistant Service; C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
    S2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company)
    S2 IHProtect Service; C:\Program Files\XTab\ProtectService.exe [158896 2015-01-16] (XTab system)
    S2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-01-22] (Hewlett-Packard Company) [File not signed]
    S2 Net Driver HPZ12; C:\windows\system32\HPZinw12.dll [44032 2009-05-14] (Hewlett-Packard) [File not signed]
    S2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2010-01-12] (PDF Complete Inc)
    S2 pfsvc_1.10.0.9; C:\Program Files\PhraseFinder_1.10.0.9\Service\pfsvc.exe [278608 2015-02-06] (Phrase Finder)
    S2 Pml Driver HPZ12; C:\windows\system32\HPZipm12.dll [53760 2009-05-14] (Hewlett-Packard) [File not signed]
    S2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
    S2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
    S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
    S2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\STacSV.exe [229458 2015-02-03] (IDT, Inc.)
    S2 VideoDownloadConverter_4zService; C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe [42504 2013-09-28] (COMPANYVERS_NAME)
    S2 vToolbarUpdater18.1.9; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-11] (AVG Secure Search)
    R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S2 aswHwid; C:\windows\system32\drivers\aswHwid.sys [24144 2015-03-03] ()
    S2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [73440 2015-03-03] (Avast Software s.r.o.)
    R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [81728 2015-03-03] (Avast Software s.r.o.)
    S0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49904 2015-03-03] ()
    S1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [788272 2015-03-03] (Avast Software s.r.o.)
    S1 aswSP; C:\windows\system32\drivers\aswSP.sys [427480 2015-03-03] (Avast Software s.r.o.)
    S2 aswStm; C:\windows\system32\drivers\aswStm.sys [106912 2015-03-03] (Avast Software s.r.o.)
    S0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [206976 2015-03-03] ()
    R1 avgtp; C:\windows\system32\drivers\avgtpx86.sys [42784 2014-08-11] (AVG Technologies)
    S3 BTMCOM; C:\windows\System32\Drivers\btmcom.sys [41344 2010-04-09] (Motorola, Inc.)
    S3 BTMUSB; C:\windows\System32\Drivers\btmusb.sys [377344 2010-07-08] (Motorola, Inc.)
    S1 HWiNFO32; C:\windows\system32\drivers\HWiNFO32.SYS [23840 2015-02-03] (REALiX(tm))
    R1 pfnfd_1_10_0_9; C:\windows\System32\drivers\pfnfd_1_10_0_9.sys [52728 2015-02-06] (Phrase Finder)
    S3 SNP2UVC; C:\windows\System32\DRIVERS\snp2uvc.sys [1763968 2010-04-27] ()
    S2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220240 2015-03-03] (Avast Software)

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-03-07 08:06 - 2015-03-07 08:07 - 00026576 _____ () C:\Users\iselba\Desktop\FRST.txt
    2015-03-07 08:06 - 2015-03-07 08:06 - 00000000 ____D () C:\FRST
    2015-03-07 08:04 - 2015-03-07 08:04 - 01134080 _____ (Farbar) C:\Users\iselba\Desktop\FRST.exe
    2015-03-07 08:02 - 2015-03-07 08:02 - 02094592 _____ (Farbar) C:\Users\iselba\Desktop\FRST64.exe
    2015-03-06 23:46 - 2015-03-06 23:47 - 00000000 ____D () C:\Program Files\Mozilla Firefox
    2015-03-06 23:17 - 2015-03-06 23:17 - 00000000 ____D () C:\Program Files\Common Files\Java
    2015-03-06 19:17 - 2015-03-06 19:17 - 00509440 _____ (Tech Support Guy System) C:\Users\iselba\Downloads\SysInfo(1).exe
    2015-03-06 19:16 - 2015-03-06 19:17 - 00509440 _____ (Tech Support Guy System) C:\Users\iselba\Downloads\SysInfo.exe
    2015-03-06 18:48 - 2015-03-06 23:16 - 00096680 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge.dll
    2015-03-06 18:48 - 2015-03-06 23:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2015-03-06 18:48 - 2015-03-06 18:48 - 00175528 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
    2015-03-06 18:48 - 2015-03-06 18:48 - 00175528 _____ (Oracle Corporation) C:\windows\system32\java.exe
    2015-03-06 18:42 - 2015-03-06 18:42 - 00002091 _____ () C:\Users\Public\Desktop\Foxit Reader.lnk
    2015-03-06 18:42 - 2015-03-06 18:42 - 00000000 ____D () C:\Users\Public\Foxit Software
    2015-03-06 18:42 - 2015-03-06 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
    2015-03-04 17:38 - 2015-03-07 07:51 - 00000280 _____ () C:\windows\setupact.log
    2015-03-04 17:38 - 2015-03-04 17:38 - 00000000 _____ () C:\windows\setuperr.log
    2015-03-04 08:57 - 2015-03-04 08:58 - 00016410 _____ () C:\Users\iselba\Documents\cc_20150304_085753.reg
    2015-03-03 17:40 - 2015-03-03 17:40 - 00008448 _____ () C:\Users\iselba\Documents\cc_20150303_174030.reg
    2015-03-03 17:34 - 2015-03-03 17:35 - 00000000 ____D () C:\windows\system32\vbox
    2015-03-03 17:33 - 2015-03-03 17:33 - 00000000 ____D () C:\Users\iselba\AppData\Roaming\AVAST Software
    2015-03-03 17:32 - 2015-03-03 17:32 - 00788272 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswSnx.sys
    2015-03-03 17:32 - 2015-03-03 17:32 - 00427480 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswSP.sys
    2015-03-03 17:32 - 2015-03-03 17:32 - 00291312 _____ (Avast Software s.r.o.) C:\windows\system32\aswBoot.exe
    2015-03-03 17:32 - 2015-03-03 17:32 - 00206976 _____ () C:\windows\system32\Drivers\aswVmm.sys
    2015-03-03 17:32 - 2015-03-03 17:32 - 00106912 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswStm.sys
    2015-03-03 17:32 - 2015-03-03 17:32 - 00081728 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswRdr2.sys
    2015-03-03 17:32 - 2015-03-03 17:32 - 00073440 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswMonFlt.sys
    2015-03-03 17:32 - 2015-03-03 17:32 - 00049904 _____ () C:\windows\system32\Drivers\aswRvrt.sys
    2015-03-03 17:32 - 2015-03-03 17:32 - 00043112 _____ (Avast Software s.r.o.) C:\windows\avastSS.scr
    2015-03-03 17:32 - 2015-03-03 17:32 - 00024144 _____ () C:\windows\system32\Drivers\aswHwid.sys
    2015-03-03 17:32 - 2015-03-03 17:32 - 00002075 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
    2015-03-03 17:32 - 2015-03-03 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
    2015-03-03 17:28 - 2015-03-03 17:28 - 00000000 ____D () C:\Program Files\AVAST Software
    2015-03-03 17:27 - 2015-03-03 17:27 - 05475064 _____ (Avast Software s.r.o.) C:\Users\iselba\Downloads\avast_free_antivirus_setup_online.exe
    2015-03-03 17:27 - 2015-03-03 17:27 - 00000000 ____D () C:\ProgramData\AVAST Software
    2015-02-25 16:05 - 2015-02-25 16:05 - 00003766 _____ () C:\Users\iselba\Documents\20150225.reg
    2015-02-25 15:06 - 2015-02-25 15:06 - 00002678 _____ () C:\Users\iselba\Documents\cc_20150225_150637.reg
    2015-02-25 15:01 - 2015-01-08 19:48 - 00635904 _____ (Microsoft Corporation) C:\windows\system32\perftrack.dll
    2015-02-25 15:01 - 2015-01-08 19:48 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\wdi.dll
    2015-02-25 15:01 - 2015-01-08 19:48 - 00027136 _____ (Microsoft Corporation) C:\windows\system32\powertracker.dll
    2015-02-24 23:27 - 2015-01-08 16:44 - 00419936 _____ () C:\windows\system32\locale.nls
    2015-02-24 20:20 - 2015-02-24 20:20 - 00000104 _____ () C:\Users\iselba\Desktop\Panel de control - Acceso directo.lnk
    2015-02-18 17:42 - 2015-02-18 17:42 - 00004904 _____ () C:\Users\iselba\Documents\cc_20150218_174224.reg
    2015-02-18 13:30 - 2015-02-18 13:29 - 00450771 ____R () C:\windows\system32\Drivers\etc\hosts.20150218-133030.backup
    2015-02-18 12:16 - 2015-02-18 12:16 - 00002163 _____ () C:\Users\iselba\Desktop\HP Support Assistant.lnk
    2015-02-18 12:16 - 2015-02-18 12:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
    2015-02-18 12:07 - 2015-02-18 12:07 - 00000000 ____D () C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
    2015-02-14 20:44 - 2015-03-07 07:48 - 00607736 _____ () C:\windows\WindowsUpdate.log
    2015-02-14 19:30 - 2015-02-14 19:29 - 00450771 ____R () C:\windows\system32\Drivers\etc\hosts.20150214-193003.backup
    2015-02-14 19:29 - 2009-06-10 14:39 - 00000824 _____ () C:\windows\system32\Drivers\etc\hosts.20150214-192928.backup
    2015-02-14 18:58 - 2015-02-14 20:00 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
    2015-02-14 18:58 - 2015-02-14 18:58 - 00002131 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
    2015-02-14 18:58 - 2015-02-14 18:58 - 00002119 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    2015-02-14 18:58 - 2015-02-14 18:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    2015-02-14 18:58 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\windows\system32\sdnclean.exe
    2015-02-14 18:57 - 2015-02-14 19:10 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
    2015-02-14 18:42 - 2015-02-14 18:42 - 00021448 _____ () C:\Users\iselba\Documents\cc_20150214_184216.reg
    2015-02-14 18:39 - 2015-02-14 18:39 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk
    2015-02-14 14:08 - 2015-02-14 14:08 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
    2015-02-14 14:07 - 2015-02-14 14:08 - 00000000 ____D () C:\Program Files\XTab
    2015-02-14 14:06 - 2015-02-14 14:06 - 00000000 ____D () C:\Users\iselba\AppData\Roaming\key-find
    2015-02-14 14:04 - 2015-02-14 14:04 - 00000000 ____D () C:\Program Files\PhraseFinder_1.10.0.9
    2015-02-14 13:43 - 2015-02-14 13:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
    2015-02-14 13:43 - 2015-02-14 13:43 - 00000000 ____D () C:\Program Files\Recuva
    2015-02-14 13:42 - 2015-02-14 13:42 - 04210920 _____ (Piriform Ltd) C:\Users\iselba\Downloads\rcsetup151.exe
    2015-02-13 21:42 - 2015-01-15 00:46 - 00136640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
    2015-02-13 21:42 - 2015-01-15 00:46 - 00067520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
    2015-02-13 21:42 - 2015-01-15 00:43 - 00100352 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
    2015-02-13 21:42 - 2015-01-15 00:43 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
    2015-02-13 21:42 - 2015-01-15 00:42 - 01061376 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
    2015-02-13 21:42 - 2015-01-15 00:42 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
    2015-02-13 21:42 - 2015-01-15 00:42 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
    2015-02-13 21:42 - 2015-01-15 00:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
    2015-02-13 21:42 - 2015-01-15 00:39 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
    2015-02-13 21:42 - 2015-01-15 00:39 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
    2015-02-13 21:42 - 2015-01-15 00:37 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
    2015-02-13 21:42 - 2015-01-14 21:21 - 00369968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
    2015-02-13 21:42 - 2015-01-08 18:45 - 02380288 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
    2015-02-13 21:41 - 2015-02-03 19:54 - 00482304 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
    2015-02-13 21:41 - 2015-02-03 19:53 - 00767488 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
    2015-02-13 21:41 - 2015-02-03 19:53 - 00621056 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
    2015-02-13 21:41 - 2015-02-03 19:53 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
    2015-02-13 21:41 - 2015-02-03 19:53 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
    2015-02-13 21:41 - 2015-02-03 19:53 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
    2015-02-13 21:41 - 2015-02-03 19:49 - 00886784 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
    2015-02-13 21:41 - 2015-01-27 16:36 - 01167520 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
    2015-02-13 21:41 - 2015-01-13 22:44 - 03972544 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
    2015-02-13 21:41 - 2015-01-13 22:44 - 03917760 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
    2015-02-13 21:41 - 2015-01-09 23:27 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
    2015-02-13 21:41 - 2015-01-09 23:27 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
    2015-02-13 21:41 - 2015-01-09 23:27 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
    2015-02-13 21:41 - 2015-01-09 23:27 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
    2015-02-13 21:41 - 2015-01-09 23:27 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
    2015-02-13 21:41 - 2015-01-09 23:27 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
    2015-02-13 21:41 - 2015-01-09 23:27 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
    2015-02-13 21:41 - 2014-11-25 20:32 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
    2015-02-13 21:41 - 2014-10-03 18:42 - 03221504 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
    2015-02-13 21:41 - 2014-10-03 18:42 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\aaclient.dll
    2015-02-13 21:40 - 2015-01-13 22:09 - 00342712 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
    2015-02-13 21:40 - 2015-01-11 19:25 - 19740160 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
    2015-02-13 21:40 - 2015-01-11 19:21 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
    2015-02-13 21:40 - 2015-01-11 19:21 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
    2015-02-13 21:40 - 2015-01-11 19:08 - 00503296 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
    2015-02-13 21:40 - 2015-01-11 19:07 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
    2015-02-13 21:40 - 2015-01-11 19:07 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
    2015-02-13 21:40 - 2015-01-11 19:05 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
    2015-02-13 21:40 - 2015-01-11 19:02 - 02277888 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
    2015-02-13 21:40 - 2015-01-11 19:00 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
    2015-02-13 21:40 - 2015-01-11 18:59 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
    2015-02-13 21:40 - 2015-01-11 18:57 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
    2015-02-13 21:40 - 2015-01-11 18:55 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
    2015-02-13 21:40 - 2015-01-11 18:55 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
    2015-02-13 21:40 - 2015-01-11 18:48 - 00667648 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
    2015-02-13 21:40 - 2015-01-11 18:45 - 00418304 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
    2015-02-13 21:40 - 2015-01-11 18:40 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
    2015-02-13 21:40 - 2015-01-11 18:36 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
    2015-02-13 21:40 - 2015-01-11 18:35 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
    2015-02-13 21:40 - 2015-01-11 18:33 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
    2015-02-13 21:40 - 2015-01-11 18:23 - 02052608 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
    2015-02-13 21:40 - 2015-01-11 18:23 - 00688640 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
    2015-02-13 21:40 - 2015-01-11 18:23 - 00684544 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
    2015-02-13 21:40 - 2015-01-11 18:22 - 01155072 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
    2015-02-13 21:40 - 2015-01-11 18:14 - 12829184 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
    2015-02-13 21:40 - 2015-01-11 18:00 - 01888256 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
    2015-02-13 21:40 - 2015-01-11 17:56 - 01307136 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
    2015-02-13 21:40 - 2015-01-11 17:55 - 00710144 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
    2015-02-13 21:39 - 2014-12-11 22:07 - 01174528 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
    2015-02-13 21:34 - 2015-01-12 19:49 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
    2015-02-13 21:34 - 2014-12-07 19:46 - 00308224 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll
    2015-02-13 18:51 - 2015-02-14 18:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
    2015-02-13 18:51 - 2015-01-22 20:43 - 00620032 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
    2015-02-13 18:51 - 2015-01-22 20:17 - 04300800 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
    2015-02-13 18:42 - 2015-02-13 18:42 - 00000000 ____D () C:\windows\Tasks\ImCleanDisabled
    2015-02-08 10:08 - 2015-02-08 10:08 - 00322399 _____ () C:\Users\iselba\Downloads\Paquetes Vacacionales y Hoteles Todo Incluido Vedeviaje.com.html
    2015-02-08 10:08 - 2015-02-08 10:08 - 00000000 ____D () C:\Users\iselba\Downloads\Paquetes Vacacionales y Hoteles Todo Incluido Vedeviaje.com_files
    2015-02-06 13:01 - 2015-02-06 13:01 - 00052728 _____ (Phrase Finder) C:\windows\system32\Drivers\pfnfd_1_10_0_9.sys

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-03-07 07:51 - 2013-06-08 10:31 - 00000350 _____ () C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job
    2015-03-07 07:51 - 2013-06-03 17:49 - 00000350 _____ () C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
    2015-03-07 07:51 - 2012-01-26 20:31 - 00001084 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-03-07 07:51 - 2009-07-13 21:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
    2015-03-07 07:49 - 2012-09-04 17:29 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
    2015-03-07 07:46 - 2009-07-13 21:34 - 00016160 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-03-07 07:46 - 2009-07-13 21:34 - 00016160 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-03-07 00:08 - 2011-08-10 13:35 - 00001112 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002UA.job
    2015-03-06 23:58 - 2011-08-09 13:43 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002UA.job
    2015-03-06 23:41 - 2012-01-26 20:31 - 00001088 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-03-06 23:32 - 2012-05-29 19:01 - 00000838 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
    2015-03-06 23:17 - 2013-12-14 23:26 - 00000000 ____D () C:\ProgramData\Oracle
    2015-03-06 23:16 - 2013-12-14 23:24 - 00000000 ____D () C:\Program Files\Java
    2015-03-06 20:57 - 2011-07-02 23:13 - 00005642 ___SH () C:\ProgramData\KGyGaAvL.sys
    2015-03-06 18:42 - 2009-07-13 19:37 - 00000000 ___RD () C:\Users\Public
    2015-03-06 18:12 - 2014-11-16 20:39 - 00000000 ____D () C:\Users\iselba\AppData\Local\Cuevana
    2015-03-06 17:59 - 2011-08-10 13:35 - 00001090 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002Core.job
    2015-03-06 17:59 - 2011-08-09 13:43 - 00001054 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002Core.job
    2015-03-04 09:05 - 2014-07-22 20:07 - 00000324 _____ () C:\windows\Tasks\HPCeeScheduleForiselba.job
    2015-03-03 22:43 - 2010-09-17 20:39 - 00000000 ____D () C:\ProgramData\PDFC
    2015-03-03 20:46 - 2011-02-01 16:02 - 00000052 _____ () C:\windows\system32\DOErrors.log
    2015-03-03 17:22 - 2014-10-16 21:37 - 00000000 ____D () C:\ProgramData\AVG2015
    2015-03-03 17:22 - 2011-02-01 16:15 - 00000000 ____D () C:\Program Files\AVG
    2015-03-03 17:22 - 2011-02-01 15:46 - 00000000 ____D () C:\ProgramData\MFAData
    2015-03-03 17:20 - 2014-10-16 21:20 - 00000000 ____D () C:\Users\iselba\AppData\Local\Avg2015
    2015-03-03 17:19 - 2011-04-02 17:20 - 00000000 ___HD () C:\$AVG
    2015-02-25 17:31 - 2009-07-13 19:04 - 00450771 ____R () C:\windows\system32\Drivers\etc\hosts.20150304-090349.backup
    2015-02-25 16:29 - 2010-09-17 20:22 - 01687830 _____ () C:\windows\system32\PerfStringBackup.INI
    2015-02-25 15:26 - 2009-07-13 19:37 - 00000000 ____D () C:\windows\tracing
    2015-02-24 03:23 - 2011-02-01 16:01 - 00246920 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
    2015-02-20 11:48 - 2013-11-30 18:15 - 00002127 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2015-02-18 13:30 - 2009-07-13 19:04 - 00450771 ____R () C:\windows\system32\Drivers\etc\hosts.20150225-173110.backup
    2015-02-18 12:17 - 2010-09-17 20:31 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
    2015-02-18 12:16 - 2009-07-13 19:37 - 00000000 ____D () C:\windows\Help
    2015-02-18 12:10 - 2010-09-17 20:11 - 00000000 ____D () C:\Program Files\Hewlett-Packard
    2015-02-18 12:08 - 2011-01-30 06:29 - 00000000 ____D () C:\Users\iselba\AppData\Roaming\hpqLog
    2015-02-18 12:06 - 2010-09-17 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
    2015-02-18 12:05 - 2010-09-17 20:20 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
    2015-02-14 22:27 - 2009-07-13 19:37 - 00000000 ____D () C:\windows\rescache
    2015-02-14 19:30 - 2009-07-13 19:04 - 00450771 ____R () C:\windows\system32\Drivers\etc\hosts.20150218-132952.backup
    2015-02-14 18:39 - 2013-09-01 20:14 - 00000000 ____D () C:\Program Files\CCleaner
    2015-02-14 14:05 - 2014-11-16 20:37 - 30932961 _____ (Cuevana ) C:\Users\iselba\Downloads\cuevana-storm-0.3b2-setup.exe
    2015-02-14 13:29 - 2009-07-13 21:33 - 00434312 _____ () C:\windows\system32\FNTCACHE.DAT
    2015-02-14 13:26 - 2014-12-09 22:31 - 00000000 ____D () C:\windows\system32\appraiser
    2015-02-14 13:26 - 2014-05-06 19:01 - 00000000 ___SD () C:\windows\system32\CompatTel
    2015-02-13 23:28 - 2013-08-14 22:05 - 00000000 ____D () C:\windows\system32\MRT
    2015-02-13 23:21 - 2011-03-05 12:07 - 113756392 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
    2015-02-13 23:19 - 2011-02-01 15:48 - 00000000 ____D () C:\ProgramData\Microsoft Help
    2015-02-13 21:13 - 2009-07-13 21:53 - 00032518 _____ () C:\windows\Tasks\SCHEDLGU.TXT
    2015-02-13 21:12 - 2013-08-25 21:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    2015-02-13 21:12 - 2010-12-13 22:30 - 00000000 ____D () C:\ProgramData\FLEXnet
    2015-02-13 21:12 - 2009-07-13 19:37 - 00000000 ____D () C:\windows\system32\wfp
    2015-02-13 21:10 - 2015-02-03 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pipo
    2015-02-13 21:10 - 2015-02-03 19:07 - 00000000 ____D () C:\Users\iselba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PIPO
    2015-02-13 21:10 - 2015-02-03 18:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2
    2015-02-13 21:10 - 2015-02-03 18:10 - 00000000 ____D () C:\ProgramData\IObit
    2015-02-13 21:10 - 2015-02-03 18:10 - 00000000 ____D () C:\Program Files\IObit
    2015-02-13 21:10 - 2014-11-16 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cuevana Storm
    2015-02-13 21:10 - 2014-11-16 20:38 - 00000000 ____D () C:\Program Files\Cuevana Storm
    2015-02-13 21:10 - 2013-09-01 20:14 - 00000000 ____D () C:\Users\iselba\Desktop\CCleaner
    2015-02-13 21:10 - 2013-08-25 21:10 - 00000000 ____D () C:\Users\iselba\AppData\Roaming\Malwarebytes
    2015-02-13 21:10 - 2013-08-25 21:10 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2015-02-13 21:10 - 2013-08-25 21:10 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
    2015-02-13 21:10 - 2011-12-14 19:08 - 00000000 ____D () C:\Program Files\Common Files\AVG Secure Search
    2015-02-13 21:10 - 2011-01-30 06:28 - 00000000 ____D () C:\Users\iselba
    2015-02-13 21:10 - 2009-07-13 19:37 - 00000000 ____D () C:\windows\AppCompat
    2015-02-13 21:10 - 2009-07-13 19:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
    2015-02-13 21:09 - 2009-07-13 19:37 - 00000000 ____D () C:\windows\registration
    2015-02-08 11:52 - 2015-02-03 19:56 - 00000266 _____ () C:\windows\Pipo.INI
    2015-02-05 22:59 - 2009-07-13 19:37 - 00000000 ____D () C:\windows\Microsoft.NET
    2015-02-05 22:32 - 2012-05-29 19:01 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
    2015-02-05 22:32 - 2012-01-26 20:30 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl

    ==================== Files in the root of some directories =======

    2013-05-20 17:20 - 2014-06-22 15:50 - 0003728 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
    2011-10-02 21:37 - 2014-08-03 18:35 - 0005120 _____ () C:\Users\iselba\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2011-03-10 19:21 - 2011-03-10 22:18 - 0001534 _____ () C:\Users\iselba\AppData\Local\mbt-actwiz.log
    2011-07-02 23:13 - 2012-05-26 20:40 - 0000088 __RSH () C:\ProgramData\42DC50AF2F.sys
    2011-07-31 12:41 - 2011-07-31 12:41 - 0000048 ____H () C:\ProgramData\ezsidmv.dat
    2010-09-17 21:07 - 2010-09-17 21:07 - 0000191 _____ () C:\ProgramData\HPWALog.txt
    2013-08-25 09:36 - 2013-08-25 09:44 - 0000356 _____ () C:\ProgramData\hpzinstall.log
    2011-07-02 23:13 - 2015-03-06 20:57 - 0005642 ___SH () C:\ProgramData\KGyGaAvL.sys

    Some content of TEMP:
    ====================
    C:\Users\iselba\AppData\Local\Temp\Foxit Updater.exe
    C:\Users\iselba\AppData\Local\Temp\jre-8u40-windows-au.exe
    C:\Users\iselba\AppData\Local\Temp\{89F7059C-822E-4647-8729-9561BA0FCB19}-GoogleToolbarInstaller_updater_signed.exe


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\windows\explorer.exe => File is digitally signed
    C:\windows\system32\winlogon.exe => File is digitally signed
    C:\windows\system32\wininit.exe => File is digitally signed
    C:\windows\system32\svchost.exe => File is digitally signed
    C:\windows\system32\services.exe => File is digitally signed
    C:\windows\system32\User32.dll => File is digitally signed
    C:\windows\system32\userinit.exe => File is digitally signed
    C:\windows\system32\rpcss.dll => File is digitally signed
    C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-03-06 19:40

    ==================== End Of Log ============================

    Additional scan result of Farbar Recovery Scan Tool (x86) Version: 07-03-2015
    Ran by iselba at 2015-03-07 08:07:55
    Running from C:\Users\iselba\Desktop
    Boot Mode: Safe Mode (with Networking)
    ==========================================================


    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
    AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    32 Bit HP CIO Components Installer (Version: 6.1.2 - Hewlett-Packard) Hidden
    Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
    Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
    aTube Catcher (HKLM\...\aTube Catcher) (Version: 3.1.1324 - DsNET Corp)
    aTube Catcher versión 3.8 (HKLM\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
    Avast Free Antivirus (HKLM\...\Avast) (Version: 10.2.2214 - AVAST Software)
    AVG Security Toolbar (HKLM\...\AVG Secure Search) (Version: 18.1.9.799 - AVG Technologies)
    Bing Rewards Client Installer (Version: 16.0.345.0 - Microsoft Corporation) Hidden
    CCleaner (HKLM\...\CCleaner) (Version: 5.02 - Piriform)
    Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Corel Home Office - CS Templates (Version: 5.6 - 公司名称) Hidden
    Corel Home Office - CT Templates (Version: 5.6 - 您的公司名稱) Hidden
    Corel Home Office - IPM (Version: 5.6 - Corel Corporation) Hidden
    Corel Home Office - JP Templates (Version: 5.6 - 会社名) Hidden
    Corel Home Office - KR Templates (Version: 5.6 - 회사명) Hidden
    Corel Home Office - Launcher (Version: 5.6 - Corel Corporation) Hidden
    Corel Home Office - Templates RU (Version: 5.6 - Название организации) Hidden
    Corel Home Office - Templates1 (Version: 5.6 - Your Company Name) Hidden
    Corel Home Office (HKLM\...\_{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}) (Version: 5.0.85.588 - Corel Corporation)
    Corel Home Office (Version: 5.6 - Corel Corporation) Hidden
    Cuevana Storm versión 0.3b (HKLM\...\{2AFB4518-E1D7-4D74-B4FC-C65AE00E531D}_is1) (Version: 0.3b - Cuevana)
    D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
    Defraggler (HKLM\...\Defraggler) (Version: 2.18 - Piriform)
    DJ_SF_06_D1600_SW_Min (Version: 140.0.690.000 - Hewlett-Packard) Hidden
    Driver Booster 2.1 (HKLM\...\Driver Booster_is1) (Version: 2.1 - IObit)
    Energy Star Digital Logo (HKLM\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
    Epson Easy Photo Print 2 (HKLM\...\{87C2248A-C7DD-49ED-9BCD-B312A9D0819E}) (Version: 2.1.0.0 - SEIKO EPSON CORPORATION)
    Epson Event Manager (HKLM\...\{48F22622-1CC2-4A83-9C1E-644DD96F832D}) (Version: 2.20.00 - SEIKO EPSON Corporation)
    EPSON NX210 Series Printer Uninstall (HKLM\...\EPSON NX210 Series) (Version: - SEIKO EPSON Corporation)
    EPSON Scan (HKLM\...\EPSON Scanner) (Version: - )
    Facebook Video Calling 1.2.0.287 (HKLM\...\{B92C5909-1D37-4C51-8397-A28BB28E5DC3}) (Version: 1.2.287 - Skype Limited)
    FastStone Image Viewer 4.6 (HKLM\...\FastStone Image Viewer) (Version: 4.6 - FastStone Soft)
    Foxit Cloud (HKLM\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 2.3.25.1124 - Foxit Software Inc.)
    Foxit Reader (HKLM\...\Foxit Reader_is1) (Version: 7.0.6.1126 - Foxit Software Inc.)
    Galería fotográfica de Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Google Chrome (HKLM\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.)
    Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
    Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
    Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
    Hacer clic y ejecutar de Microsoft Office 2010 (HKLM\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Hacer clic y ejecutar de Microsoft Office 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
    Hewlett-Packard ACLM.NET v1.2.2.3 (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
    HP Advisor (HKLM\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.4.10262.3295 - Hewlett-Packard)
    HP Deskjet D1600 Printer Driver 14.0 Rel. 6 (HKLM\...\{96178C0A-BAF9-4E49-A2A5-CDE76722105B}) (Version: 14.0 - HP)
    HP Documentation (HKLM\...\{C1DE827D-8A61-4A77-9CCF-31AD84CC1FB6}) (Version: 1.5.1.0 - Hewlett-Packard)
    HP ESU for Microsoft Windows 7 (HKLM\...\{206E1EEB-027A-4FC0-B4ED-6E48203BD49A}) (Version: 1.1.1.1 - Hewlett-Packard Company)
    HP HotKey Support (HKLM\...\{4BBA5224-C5B1-4B8C-AAA4-68DA6654B9C1}) (Version: 3.5.15.1 - Hewlett-Packard Company)
    HP Setup (HKLM\...\{1E6219D4-027E-47EE-AB83-DD2F26E31A32}) (Version: 1.2.3557.3169 - Hewlett-Packard)
    HP SoftPaq Download Manager (HKLM\...\{2DA697D7-FED3-4DE2-A174-92A2A12F9688}) (Version: 3.0.5.0 - Hewlett-Packard Company)
    HP Software Framework (HKLM\...\{9CD3BB19-993E-469D-9E1F-B57A175C1411}) (Version: 4.0.51.1 - Hewlett-Packard Company)
    HP Software Setup (HKLM\...\{04801E42-B1A6-4C52-9F3D-CADB5A050433}) (Version: 7.0.1.6 - Hewlett-Packard Company)
    HP Support Assistant (HKLM\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
    HP Webcam (HKLM\...\{1D61E881-43CD-447B-9E6B-D2C6138B2862}) (Version: 1.0.19.6 - Roxio)
    HP Webcam Driver (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.50014.0 - Sonix)
    HP Wireless Assistant (HKLM\...\{1061DF04-CF33-40B0-8360-D07C9BBEB122}) (Version: 3.50.10.1 - Hewlett-Packard)
    IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6268.0 - IDT)
    Intel(R) Graphics Media Accelerator Driver (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2057 - Intel Corporation)
    Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
    InterVideo WinDVD 8 (HKLM\...\InstallShield_{5FEBF468-5AC2-4C66-AD80-DF85C085AA73}) (Version: 8.5.10.54 - InterVideo Inc.)
    InterVideo WinDVD 8 (Version: 8.5.10.54 - InterVideo Inc.) Hidden
    Java 7 Update 76 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217076FF}) (Version: 7.0.760 - Oracle)
    Java 8 Update 40 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
    key-find uninstall (HKLM\...\key-find uninstall) (Version: - key-find) <==== ATTENTION!
    LightScribe System Software (HKLM\...\{FA8BFB25-BF48-4F8B-8859-B30810745190}) (Version: 1.18.11.1 - LightScribe)
    LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.98 - LSI Corporation)
    Malwarebytes Anti-Malware versión 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
    Messenger Companion (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4.5.1 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
    Microsoft Encarta 2009 Biblioteca Premium (HKLM\...\{09140081-2C94-4A67-8E55-8483C019C7D2}) (Version: 2009 - Microsoft Corporation)
    Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
    Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
    Microsoft Office Outlook Connector (HKLM\...\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
    Microsoft Office Outlook Connector (HKLM\...\{95140000-007A-0C0A-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Mouse Setting Software 4.0 (HKLM\...\Mouse Setting Software_is1) (Version: - )
    Mozilla Firefox 37.0 (x86 en-US) (HKLM\...\Mozilla Firefox 37.0 (x86 en-US)) (Version: 37.0 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 36.0 - Mozilla)
    MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    PDF Complete Special Edition (HKLM\...\PDF Complete) (Version: 3.5.116 - PDF Complete, Inc)
    Phrase Finder 1.10.0.9 (HKLM\...\PhraseFinder_1.10.0.9) (Version: 1.10.0.9 - Phrase Finder)
    Ralink Motorola BC4 Bluetooth 3.0+HS Adapter (HKLM\...\Ralink Motorola BC4 Bluetooth 3.0+HS Adapter_is1) (Version: 3.0.41.262 - Motorola, Inc.)
    Ralink RT3090 802.11b/g/n WiFi Adapter (HKLM\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}) (Version: 1.2.0.27 - Ralink)
    Realtek Ethernet Controller All-In-One Windows Driver (HKLM\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 1.12.0011 - Realtek)
    Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
    Roxio Creator Business (HKLM\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3.56.21 - Roxio)
    Skype™ 6.3 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.3.105 - Skype Technologies S.A.)
    Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
    Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.4.0 - Synaptics Incorporated)
    Toolbox (Version: 140.0.428.000 - Hewlett-Packard) Hidden
    Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
    Veetle TV (HKLM\...\Veetle TV) (Version: 0.9.19 - Veetle, Inc)
    Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    Windows 7 Default Setting (HKLM\...\{5BF8E079-D6E2-4323-B794-75152371122A}) (Version: 1.0.1.6 - Hewlett-Packard Company)
    Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
    Windows Movie Maker 2.6 (HKLM\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
    WinZip 14.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}) (Version: 14.5.9095 - WinZip Computing, S.L. )

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

    CustomCLSID: HKU\S-1-5-21-808547686-2828976095-2913112375-1001_Classes\CLSID\{93a3111f-4f74-4ed8-895e-d9708497629e}\InprocServer32 -> C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll (MindSpark)

    ==================== Restore Points =========================

    18-02-2015 12:07:43 Installed HP Support Assistant
    18-02-2015 12:13:44 Instalador de Módulos de Windows
    18-02-2015 12:15:24 Instalador de Módulos de Windows
    24-02-2015 21:37:56 Removed Norton Online Backup
    24-02-2015 23:27:05 Windows Update
    25-02-2015 15:22:56 Windows Update
    03-03-2015 17:16:43 Removed AVG 2015
    03-03-2015 17:20:00 Removed AVG 2015
    03-03-2015 17:28:40 avast! antivirus system restore point
    04-03-2015 13:47:29 Windows Update

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-13 19:04 - 2015-03-04 09:03 - 00450771 ____R C:\windows\system32\Drivers\etc\hosts
    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com
    127.0.0.1 www.0scan.com
    127.0.0.1 0scan.com
    127.0.0.1 1000gratisproben.com
    127.0.0.1 www.1000gratisproben.com
    127.0.0.1 1001namen.com
    127.0.0.1 www.1001namen.com
    127.0.0.1 100888290cs.com
    127.0.0.1 www.100888290cs.com
    127.0.0.1 www.100sexlinks.com
    127.0.0.1 100sexlinks.com
    127.0.0.1 10sek.com
    127.0.0.1 www.10sek.com
    127.0.0.1 www.1-2005-search.com
    127.0.0.1 1-2005-search.com
    127.0.0.1 123fporn.info
    127.0.0.1 www.123fporn.info
    127.0.0.1 123haustiereundmehr.com
    127.0.0.1 www.123haustiereundmehr.com
    127.0.0.1 123moviedownload.com

    There are 1000 more lines.


    ==================== Scheduled Tasks (whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

    Task: {06E487BC-9E96-4094-849C-2DD2E7FC0CF1} - System32\Tasks\{3871DE69-2604-4563-B44A-8DCF4C5C222B} => pcalua.exe -a D:\unInstaller.exe -d D:\
    Task: {0B0E078C-1E5F-4D06-9510-58E002788BA8} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
    Task: {0CF3EEE5-80B2-4E1E-9246-FAE721D9278C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002Core => C:\Users\ALEX\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: {0E5377A6-3420-4657-9A07-E7E23C961773} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-23] (Google Inc.)
    Task: {11EFBE93-978E-496E-9765-DDFE8C838BE1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-01-20] (Piriform Ltd)
    Task: {13C65136-6CB5-40E9-B836-A3BC8914B369} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {16F3227B-3B18-4CED-8F94-1DBCCB08D276} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002Core => C:\Users\ALEX\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: {1E8CD17F-590E-4E48-A4D3-CC8D8209D53A} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\windows\TEMP\{F5EE06BD-F259-4577-AD02-5F7167E926D6}.exe
    Task: {2192BAC0-0650-4EB3-9EED-6DCDC76E6A01} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
    Task: {33C8A4EB-7A5D-4418-B36C-0A5377E3162A} - System32\Tasks\HPCeeScheduleForiselba => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard)
    Task: {3863397E-BA67-43D8-B6A7-049003EE9C4A} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated)
    Task: {4E636430-508D-4A8C-85C2-99DE0B554522} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => C:\windows\TEMP\{B9925420-31C5-45F1-95DF-B0F4A9D01B9A}.exe
    Task: {5F113F37-0E44-407B-94CF-084E98E29D86} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-23] (Google Inc.)
    Task: {639E8954-3659-4AF9-8F1F-97F6B5D01D69} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002UA => C:\Users\ALEX\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: {6C443A3F-7F26-40A2-8436-3778B463B523} - System32\Tasks\Driver Booster SkipUAC (iselba) => C:\Program Files\IObit\Driver Booster\DriverBooster.exe [2015-01-07] (IObit)
    Task: {6E1D785A-1B12-45A9-94D7-44C360C658A8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search &amp; Destroy 2\SDScan.exe
    Task: {73795BF9-B4C1-4447-9E8C-7B3D5D92B61B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search &amp; Destroy 2\SDImmunize.exe
    Task: {808E0CE6-886E-4212-B594-06C25648C8CD} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search &amp; Destroy 2\SDUpdate.exe
    Task: {858AE255-1B9F-4F9C-996A-C2E7EC0CA1DE} - System32\Tasks\{AD50F3CC-A8D1-47C7-9BFF-546AC2AE597C} => pcalua.exe -a G:\Autorun.exe -d G:\
    Task: {944FFB94-3871-48C0-B533-04A46331CE5B} - System32\Tasks\Driver Booster Update => C:\Program Files\IObit\Driver Booster\AutoUpdate.exe [2014-12-09] (IObit)
    Task: {9E874AE5-14D2-44A9-B46B-D2A6F25A769A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002UA => C:\Users\ALEX\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: {C669525F-C913-46D7-966F-54DC850FAB75} - System32\Tasks\Driver Booster Scan => C:\Program Files\IObit\Driver Booster\Scheduler.exe [2014-12-17] (IObit)
    Task: {D1C9AB6D-F670-43EA-98BF-CE3E2179042D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {F3CE7210-6246-4252-A13A-C9761776BEB6} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-03-03] (Avast Software s.r.o.)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\windows\TEMP\{B9925420-31C5-45F1-95DF-B0F4A9D01B9A}.exe <==== ATTENTION
    Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\windows\TEMP\{F5EE06BD-F259-4577-AD02-5F7167E926D6}.exe <==== ATTENTION
    Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002Core.job => C:\Users\ALEX\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002UA.job => C:\Users\ALEX\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002Core.job => C:\Users\ALEX\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-808547686-2828976095-2913112375-1002UA.job => C:\Users\ALEX\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\HPCeeScheduleForiselba.job => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe

    ==================== Loaded Modules (whitelisted) ==============

    2015-02-20 11:48 - 2015-02-17 15:44 - 09171272 _____ () C:\Program Files\Google\Chrome\Application\40.0.2214.115\pdf.dll

    ==================== Alternate Data Streams (whitelisted) =========

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

    ==================== EXE Association (whitelisted) ===============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Control Panel\Desktop\\Wallpaper -> %windir%\web\wallpaper\windows\img0.jpg
    DNS Servers: 192.168.1.1

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    MSCONFIG\startupreg: EEventManager => C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
    MSCONFIG\startupreg: EPSON NX210 Series => C:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIFDA.EXE /FU "C:\windows\TEMP\E_SE502.tmp" /EF "HKCU"
    MSCONFIG\startupreg: HPAdvisorDock => C:\Program Files\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
    MSCONFIG\startupreg: NortonOnlineBackup => C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe
    MSCONFIG\startupreg: PDF Complete => C:\Program Files\PDF Complete\pdfsty.exe
    MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

    ==================== Accounts: =============================

    Administrador (S-1-5-21-808547686-2828976095-2913112375-500 - Administrator - Disabled)
    Invitado (S-1-5-21-808547686-2828976095-2913112375-501 - Limited - Disabled)
    iselba (S-1-5-21-808547686-2828976095-2913112375-1001 - Administrator - Enabled) => C:\Users\iselba

    ==================== Faulty Device Manager Devices =============

    Name: avast! VM Monitor
    Description: avast! VM Monitor
    Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Manufacturer:
    Service: aswVmm
    Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
    Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
    Devices stay in this state if they have been prepared for removal.
    After you remove the device, this error disappears.Remove the device, and this error should be resolved.

    Name: Security Processor Loader Driver
    Description: Security Processor Loader Driver
    Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Manufacturer:
    Service: spldr
    Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
    Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
    Devices stay in this state if they have been prepared for removal.
    After you remove the device, this error disappears.Remove the device, and this error should be resolved.

    Name: Ralink Motorola BC4 Bluetooth 3.0+HS Adapter
    Description: Ralink Motorola BC4 Bluetooth 3.0+HS Adapter
    Class Guid: {a173b237-6a34-4bb5-aa63-2561160fa200}
    Manufacturer: Motorola, Inc.
    Service: BTMUSB
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

    Name: avast! Revert
    Description: avast! Revert
    Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Manufacturer:
    Service: aswRvrt
    Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
    Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
    Devices stay in this state if they have been prepared for removal.
    After you remove the device, this error disappears.Remove the device, and this error should be resolved.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (03/06/2015 08:03:45 PM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Error al generar el contexto de activación para "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    No se encontró el ensamblado dependiente Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
    Use sxstrace.exe para obtener un diagnóstico detallado.

    Error: (03/06/2015 07:40:26 PM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Error al generar el contexto de activación para "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    No se encontró el ensamblado dependiente Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
    Use sxstrace.exe para obtener un diagnóstico detallado.

    Error: (03/04/2015 00:25:49 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Error al generar el contexto de activación para "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    No se encontró el ensamblado dependiente Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
    Use sxstrace.exe para obtener un diagnóstico detallado.

    Error: (03/03/2015 08:21:37 PM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Error al generar el contexto de activación para "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    No se encontró el ensamblado dependiente Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
    Use sxstrace.exe para obtener un diagnóstico detallado.

    Error: (03/03/2015 05:28:39 PM) (Source: VSS) (EventID: 8194) (User: )
    Description: Error del Servicio de instantáneas de volumen: error inesperado al consultar la interfaz IVssWriterCallback. HR = 0x80070005, Acceso denegado.
    .
    A menudo ocurre por una configuración de seguridad incorrecta en el proceso de escritura o de solicitud.


    Operación:
    Recopilando datos del escritor

    Contexto:
    Id. de clase del escritor: {e8132975-6f93-4464-a53e-1050253ae220}
    Nombre del escritor: System Writer
    Id. de instancia del escritor: {ee9f7338-dbbe-4668-82cf-129e8344dba2}

    Error: (03/03/2015 05:20:31 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Nombre de la aplicación con errores: cmdshell.exe, versión: 4.0.1.1716, marca de tiempo: 0x54b75bdb
    Nombre del módulo con errores: ole32.DLL, versión: 6.1.7601.17514, marca de tiempo: 0x4ce7b96f
    Código de excepción: 0xc0000005
    Desplazamiento de errores: 0x00039342
    Id. del proceso con errores: 0x11a4
    Hora de inicio de la aplicación con errores: 0xcmdshell.exe0
    Ruta de acceso de la aplicación con errores: cmdshell.exe1
    Ruta de acceso del módulo con errores: cmdshell.exe2
    Id. del informe: cmdshell.exe3

    Error: (02/25/2015 05:18:24 PM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Error al generar el contexto de activación para "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    No se encontró el ensamblado dependiente Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
    Use sxstrace.exe para obtener un diagnóstico detallado.

    Error: (02/25/2015 04:00:27 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Nombre de la aplicación con errores: cmdshell.exe, versión: 4.0.1.1716, marca de tiempo: 0x54b75bdb
    Nombre del módulo con errores: unknown, versión: 0.0.0.0, marca de tiempo: 0x00000000
    Código de excepción: 0xc0000005
    Desplazamiento de errores: 0xf1eef1ee
    Id. del proceso con errores: 0x16c4
    Hora de inicio de la aplicación con errores: 0xcmdshell.exe0
    Ruta de acceso de la aplicación con errores: cmdshell.exe1
    Ruta de acceso del módulo con errores: cmdshell.exe2
    Id. del informe: cmdshell.exe3

    Error: (02/24/2015 07:58:16 PM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Error al generar el contexto de activación para "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    No se encontró el ensamblado dependiente Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
    Use sxstrace.exe para obtener un diagnóstico detallado.

    Error: (02/24/2015 07:53:39 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Nombre de la aplicación con errores: cmdshell.exe, versión: 4.0.1.1716, marca de tiempo: 0x54b75bdb
    Nombre del módulo con errores: ole32.DLL, versión: 6.1.7601.17514, marca de tiempo: 0x4ce7b96f
    Código de excepción: 0xc0000005
    Desplazamiento de errores: 0x00039342
    Id. del proceso con errores: 0x11bc
    Hora de inicio de la aplicación con errores: 0xcmdshell.exe0
    Ruta de acceso de la aplicación con errores: cmdshell.exe1
    Ruta de acceso del módulo con errores: cmdshell.exe2
    Id. del informe: cmdshell.exe3


    System errors:
    =============
    Error: (03/07/2015 08:07:58 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: El servicio Examinador de equipos depende del servicio Servidor, el cual no pudo iniciarse debido al siguiente error:
    %%1068

    Error: (03/07/2015 08:07:58 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: El servicio Examinador de equipos depende del servicio Servidor, el cual no pudo iniciarse debido al siguiente error:
    %%1068

    Error: (03/07/2015 08:07:58 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: El servicio Examinador de equipos depende del servicio Servidor, el cual no pudo iniciarse debido al siguiente error:
    %%1068

    Error: (03/07/2015 08:05:56 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: El servicio Examinador de equipos depende del servicio Servidor, el cual no pudo iniciarse debido al siguiente error:
    %%1068

    Error: (03/07/2015 08:05:56 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: El servicio Examinador de equipos depende del servicio Servidor, el cual no pudo iniciarse debido al siguiente error:
    %%1068

    Error: (03/07/2015 08:05:56 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: El servicio Examinador de equipos depende del servicio Servidor, el cual no pudo iniciarse debido al siguiente error:
    %%1068

    Error: (03/07/2015 08:05:56 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: El servicio Examinador de equipos depende del servicio Servidor, el cual no pudo iniciarse debido al siguiente error:
    %%1068

    Error: (03/07/2015 08:05:56 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: El servicio Examinador de equipos depende del servicio Servidor, el cual no pudo iniciarse debido al siguiente error:
    %%1068

    Error: (03/07/2015 08:05:56 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: El servicio Examinador de equipos depende del servicio Servidor, el cual no pudo iniciarse debido al siguiente error:
    %%1068

    Error: (03/07/2015 08:03:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: El servicio Examinador de equipos depende del servicio Servidor, el cual no pudo iniciarse debido al siguiente error:
    %%1068


    Microsoft Office Sessions:
    =========================
    Error: (01/29/2015 11:09:02 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6712.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 10473 seconds with 1440 seconds of active time. This session ended with a crash.

    Error: (12/29/2014 08:54:41 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6712.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5188 seconds with 1020 seconds of active time. This session ended with a crash.

    Error: (11/27/2014 05:20:07 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 103 seconds with 0 seconds of active time. This session ended with a crash.

    Error: (06/01/2014 04:35:27 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 3353 seconds with 1440 seconds of active time. This session ended with a crash.

    Error: (02/23/2014 09:09:07 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 7055 seconds with 2280 seconds of active time. This session ended with a crash.

    Error: (02/01/2014 08:59:48 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash.

    Error: (01/19/2014 04:46:39 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 111 seconds with 60 seconds of active time. This session ended with a crash.

    Error: (01/13/2014 08:58:16 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 5612 seconds with 2040 seconds of active time. This session ended with a crash.

    Error: (01/07/2014 08:18:59 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 4 seconds with 0 seconds of active time. This session ended with a crash.

    Error: (12/09/2013 09:08:10 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
    Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 2055 seconds with 780 seconds of active time. This session ended with a crash.


    ==================== Memory info ===========================

    Processor: Pentium(R) Dual-Core CPU T4500 @ 2.30GHz
    Percentage of memory in use: 40%
    Total physical RAM: 1976.27 MB
    Available physical RAM: 1178.18 MB
    Total Pagefile: 3952.53 MB
    Available Pagefile: 3156.34 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1890.16 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:280.79 GB) (Free:223.18 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive f: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.98 GB) FAT32

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: AC465C4C)
    Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=280.8 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=2 GB) - (Type=0C)

    ==================== End Of Log ============================
     
  8. DanoNH

    DanoNH Malware Specialist

    Joined:
    Dec 31, 1969
    Messages:
    106
    First Name:
    Dan
    Hi, and thanks for the logs. I'm glad you got FRST to run. Your system is capable of running 64-bit Windows, but you do have a 32-bit version installed.

    It will take me a little while to sort out the logs and gat my proposed reply approved. Please don't make any changes to the computer until after I tell you the system is clean. ;)

    I'll be back.

    Sent from my Oneplus One using Tapatalk
     
  9. DanoNH

    DanoNH Malware Specialist

    Joined:
    Dec 31, 1969
    Messages:
    106
    First Name:
    Dan
    Hello quenosabe. Are you ready to go? Please make sure to read and follow all the steps in order and as directed. If you have ANY questions along the way or get stuck, please STOP and post back here to let me know. ;)

    Let's get started:

    First
    Please go to your Control Panel > Uninstall a program or Control Panel > Programs and Features and uninstall the following programs:
    1. AVG Security Toolbar
    2. Driver Booster 2.1
    3. Java 7 Update 76
    4. key-find uninstall
    Optionally, I recommend that you uninstall Spybot - Search & Destroy in that list as well.

    Reboot if your are prompted to.

    Second
    Run a FRST Fix

    Download the attached fixlist.txt file and save it to the DESKTOP.

    (NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.)

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.

    Run FRST/FRST64 from your Desktop and press the Fix button just once and wait.

    If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.

    When finished FRST will generate a log on the Desktop named Fixlog.txt. Please post the contents of that log file into your next reply.

    Third
    Run Junkware Removal Tool:

    Please download Junkware Removal Tool to your DESKTOP.


    • Shut down your protection software now to avoid potential conflicts. See here for more information.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.


    Finally
    Please make sure to copy/paste the contents of the following logs in your next reply:
    1. FRST fixlog.txt
    2. JRT log
    And tell me how your computer is doing.
     

    Attached Files:

  10. quenosabe

    quenosabe Thread Starter

    Joined:
    Apr 17, 2012
    Messages:
    39
    Hi Dan, could not remove avg security toolbar, driver booster shows up on programs list but cant find uninstall file.

    Key find is no longer on programs list but shows up on chrome.

    Unwanted windows still popping up.

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-03-2015
    Ran by iselba at 2015-03-07 15:40:41 Run:1
    Running from C:\Users\iselba\Desktop
    Loaded Profiles: iselba (Available profiles: iselba)
    Boot Mode: Normal

    ==============================================

    Content of fixlist:
    *****************
    start
    CreateRestorePoint:
    HKLM\...\Run: [vProt] => C:\Program Files\AVG Secure Search\vprot.exe [2640408 2014-08-26] ()
    HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
    Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\...\Policies\system: [LogonHoursAction] 2
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\...\MountPoints2: {2be8b766-5f2f-11e0-b685-1cc1deb8d26d} - D:\LaunchU3.exe -a
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\...\MountPoints2: {b043abf2-91d3-11e2-bb49-1cc1deb8d26d} - D:\iStudio.exe
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hp&ts=...BNC08EYKWK90SX
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=d...r&uid=HitachiXHTS545032B9A300_101026PBNC08EYK WK90SX&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hp&ts=...BNC08EYKWK90SX
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=d...r&uid=HitachiXHTS545032B9A300_101026PBNC08EYK WK90SX&q={searchTerms}
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hp&ts=...BNC08EYKWK90SX
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hp&ts=...BNC08EYKWK90SX
    URLSearchHook: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 - (No Name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File
    URLSearchHook: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 - (No Name) - {93a3111f-4f74-4ed8-895e-d9708497629e} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll (MindSpark)
    URLSearchHook: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=d...r&uid=HitachiXHTS545032B9A300_101026PBNC08EYK WK90SX&q={searchTerms}
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=d...r&uid=HitachiXHTS545032B9A300_101026PBNC08EYK WK90SX&q={searchTerms}
    SearchScopes: HKLM -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm072^YYA^mx&si=pconverter&ptb=0B1FDA34-96E2-4E81-B1AE-12874FB91B62&ind=2013092818&n=77fd5bd2&psa=&st=sb&searchfor={searchTerms}
    SearchScopes: HKU\.DEFAULT -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
    SearchScopes: HKU\.DEFAULT -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL =
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=defa ult&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=defa ult&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=defa ult&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=defa ult&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=defa ult&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {AA74C1E3-044F-4DEE-9963-9FED50D139A3} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=defa ult&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=defa ult&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=defa ult&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=defa ult&q={searchTerms}
    BHO: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files\XTab\SupTab.dll [2015-01-16] (Thinknice Co. Limited)
    BHO: No Name -> {84FF7BD6-B47F-46F8-9130-01B2696B36CB} -> No File
    BHO: AVG Security Toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Secure Search\18.1.9.799\AVG Secure Search_toolbar.dll [2014-08-26] (AVG Secure Search)
    BHO: Search Assistant BHO -> {c547c6c2-561b-4169-a2a5-20ba771ca93b} -> C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll [2013-09-28] (MindSpark)
    Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
    Toolbar: HKLM - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\18.1.9.799\AVG Secure Search_toolbar.dll [2014-08-26] (AVG Secure Search)
    Toolbar: HKU\.DEFAULT -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    Toolbar: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    Toolbar: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
    Toolbar: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
    Toolbar: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File []
    Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File []
    Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File []
    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll [2014-08-11] (AVG Secure Search)
    FF DefaultSearchEngine: key-find
    FF SelectedSearchEngine: key-find
    FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File
    FF Plugin: @ei.RadioRage_4j.com/Plugin -> C:\Program Files\RadioRage_4jEI\Installr\1.bin\NP4jEISB.dll No File
    FF Plugin: @ei.Zwinky_5q.com/Plugin -> C:\Program Files\Zwinky_5qEI\Installr\1.bin\NP5qEISB.dll No File
    FF Plugin: @VideoDownloadConverter_4z.com/Plugin -> C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll No File
    FF user.js: detected! => C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\u ser.js [2015-03-07]
    FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml [2014-06-22]
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\ProgramData\AVG Secure Search\FireFoxExt\18.1.9.799
    FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\18.1.9.799 [2014-08-25]
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\e xtensions\[email protected]
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\e xtensions\[email protected]
    CHR HomePage: Default -> hxxp://www.key-find.com/?type=hp&ts=1423947936&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYK WK90SX
    CHR DefaultSearchKeyword: Default -> key-find
    CHR DefaultSuggestURL: Default ->
    CHR HKLM\...\Chrome\Extension: [aaaaojmikegpiepcfdkkjaplodkpfmlo] - C:\Users\iselba\AppData\Local\APN\GoogleCRXs\apnorjtoolbar.crx [Not Found]
    S2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
    S2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
    S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
    S2 VideoDownloadConverter_4zService; C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe [42504 2013-09-28] (COMPANYVERS_NAME)
    S2 vToolbarUpdater18.1.9; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-11] (AVG Secure Search)
    R1 avgtp; C:\windows\system32\drivers\avgtpx86.sys [42784 2014-08-11] (AVG Technologies)
    R1 pfnfd_1_10_0_9; C:\windows\System32\drivers\pfnfd_1_10_0_9.sys [52728 2015-02-06] (Phrase Finder)
    2015-02-13 18:42 - 2015-02-13 18:42 - 00000000 ____D () C:\windows\Tasks\ImCleanDisabled
    2015-03-07 07:51 - 2013-06-08 10:31 - 00000350 _____ () C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job
    2015-03-07 07:51 - 2013-06-03 17:49 - 00000350 _____ () C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
    2015-03-06 20:57 - 2011-07-02 23:13 - 00005642 ___SH () C:\ProgramData\KGyGaAvL.sys
    2015-03-03 17:22 - 2014-10-16 21:37 - 00000000 ____D () C:\ProgramData\AVG2015
    2015-03-03 17:22 - 2011-02-01 16:15 - 00000000 ____D () C:\Program Files\AVG
    2015-03-03 17:20 - 2014-10-16 21:20 - 00000000 ____D () C:\Users\iselba\AppData\Local\Avg2015
    2015-03-03 17:19 - 2011-04-02 17:20 - 00000000 ___HD () C:\$AVG
    2013-05-20 17:20 - 2014-06-22 15:50 - 0003728 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
    2011-07-02 23:13 - 2012-05-26 20:40 - 0000088 __RSH () C:\ProgramData\42DC50AF2F.sys
    CustomCLSID: HKU\S-1-5-21-808547686-2828976095-2913112375-1001_Classes\CLSID\{93a3111f-4f74-4ed8-895e-d9708497629e}\InprocServer32 -> C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll (MindSpark)
    Task: {06E487BC-9E96-4094-849C-2DD2E7FC0CF1} - System32\Tasks\{3871DE69-2604-4563-B44A-8DCF4C5C222B} => pcalua.exe -a D:\unInstaller.exe -d D:\
    Task: {1E8CD17F-590E-4E48-A4D3-CC8D8209D53A} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\windows\TEMP\{F5EE06BD-F259-4577-AD02-5F7167E926D6}.exe
    Task: {858AE255-1B9F-4F9C-996A-C2E7EC0CA1DE} - System32\Tasks\{AD50F3CC-A8D1-47C7-9BFF-546AC2AE597C} => pcalua.exe -a G:\Autorun.exe -d G:\
    Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\windows\TEMP\{B9925420-31C5-45F1-95DF-B0F4A9D01B9A}.exe <==== ATTENTION
    Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\windows\TEMP\{F5EE06BD-F259-4577-AD02-5F7167E926D6}.exe <==== ATTENTION
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
    Hosts:
    cmd: ipconfig /flushdns
    cmd: netsh advfirewall reset
    cmd: netsh advfirewall set allprofiles state on
    cmd: bitsadmin /reset /allusers
    EmptyTemp:
    end
    *****************

    Restore point was successfully created.
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\vProt => value deleted successfully.
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SDTray => Value not found.
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\LogonHoursAction => value deleted successfully.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DontDisplayLogonHoursWarnings => value deleted successfully.
    "HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2be8b766-5f2f-11e0-b685-1cc1deb8d26d}" => Key deleted successfully.
    HKCR\CLSID\{2be8b766-5f2f-11e0-b685-1cc1deb8d26d} => Key not found.
    "HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b043abf2-91d3-11e2-bb49-1cc1deb8d26d}" => Key deleted successfully.
    HKCR\CLSID\{b043abf2-91d3-11e2-bb49-1cc1deb8d26d} => Key not found.
    HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
    HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
    HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
    HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} => value deleted successfully.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{93a3111f-4f74-4ed8-895e-d9708497629e} => value deleted successfully.
    "HKCR\CLSID\{93a3111f-4f74-4ed8-895e-d9708497629e}" => Key deleted successfully.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{84FF7BD6-B47F-46F8-9130-01B2696B36CB} => value deleted successfully.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
    "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
    HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.
    HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.
    "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}" => Key deleted successfully.
    HKCR\CLSID\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key not found.
    HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
    "HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}" => Key deleted successfully.
    HKCR\CLSID\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
    "HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
    HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
    "HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" => Key deleted successfully.
    HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => Key not found.
    "HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully.
    HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
    "HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully.
    "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully.
    "HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA74C1E3-044F-4DEE-9963-9FED50D139A3}" => Key deleted successfully.
    HKCR\CLSID\{AA74C1E3-044F-4DEE-9963-9FED50D139A3} => Key not found.
    "HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}" => Key deleted successfully.
    HKCR\CLSID\{C04B7D22-5AEC-4561-8F49-27F6269208F6} => Key not found.
    "HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}" => Key deleted successfully.
    HKCR\CLSID\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key not found.
    "HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}" => Key deleted successfully.
    HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => Key not found.
    "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully.
    "HKCR\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}" => Key deleted successfully.
    HKCR\CLSID\{84FF7BD6-B47F-46F8-9130-01B2696B36CB} => Key not found.
    "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully.
    HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found.
    "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c547c6c2-561b-4169-a2a5-20ba771ca93b}" => Key deleted successfully.
    "HKCR\CLSID\{c547c6c2-561b-4169-a2a5-20ba771ca93b}" => Key deleted successfully.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => value deleted successfully.
    HKCR\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Key not found.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} => value deleted successfully.
    HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found.
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => value deleted successfully.
    HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => value deleted successfully.
    HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => value deleted successfully.
    HKCR\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => value deleted successfully.
    "HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}" => Key deleted successfully.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} => value deleted successfully.
    HKCR\CLSID\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} => Key not found.
    "HKCR\PROTOCOLS\Handler\linkscanner" => Key deleted successfully.
    HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => Key not found.
    "HKCR\PROTOCOLS\Handler\livecall" => Key deleted successfully.
    HKCR\CLSID\{828030A1-22C1-4009-854F-8E305202313F} => Key not found.
    "HKCR\PROTOCOLS\Handler\msnim" => Key deleted successfully.
    HKCR\CLSID\{828030A1-22C1-4009-854F-8E305202313F} => Key not found.
    "HKCR\PROTOCOLS\Handler\viprotocol" => Key deleted successfully.
    "HKCR\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}" => Key deleted successfully.
    Firefox DefaultSearchEngine deleted successfully.
    Firefox SelectedSearchEngine deleted successfully.
    "HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin" => Key deleted successfully.
    "HKLM\Software\MozillaPlugins\@ei.RadioRage_4j.com/Plugin" => Key deleted successfully.
    "HKLM\Software\MozillaPlugins\@ei.Zwinky_5q.com/Plugin" => Key deleted successfully.
    "HKLM\Software\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin" => Key deleted successfully.
    C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\u ser.js => not found.
    C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml => Moved successfully.
    HKLM\Software\Mozilla\Firefox\Extensions\\[email protected] => value deleted successfully.
    C:\ProgramData\AVG Secure Search\FireFoxExt\18.1.9.799 => Moved successfully.
    HKLM\Software\Mozilla\Firefox\Extensions\\[email protected] => value deleted successfully.
    HKLM\Software\Mozilla\Firefox\Extensions\\[email protected] => value deleted successfully.
    Chrome HomePage deleted successfully.
    Chrome DefaultSearchKeyword deleted successfully.
    Chrome DefaultSuggestURL deleted successfully.
    "HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo" => Key deleted successfully.
    SDScannerService => Service not found.
    SDUpdateService => Service not found.
    SDWSCService => Service not found.
    VideoDownloadConverter_4zService => Service deleted successfully.
    vToolbarUpdater18.1.9 => Service stopped successfully.
    vToolbarUpdater18.1.9 => Service deleted successfully.
    avgtp => Service stopped successfully.
    avgtp => Service deleted successfully.
    pfnfd_1_10_0_9 => Unable to stop service
    pfnfd_1_10_0_9 => Service deleted successfully.
    C:\windows\Tasks\ImCleanDisabled => Moved successfully.
    C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => Moved successfully.
    C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully.
    C:\ProgramData\KGyGaAvL.sys => Moved successfully.
    C:\ProgramData\AVG2015 => Moved successfully.
    C:\Program Files\AVG => Moved successfully.
    C:\Users\iselba\AppData\Local\Avg2015 => Moved successfully.
    C:\$AVG => Moved successfully.
    C:\Program Files\Mozilla Firefoxavg-secure-search.xml => Moved successfully.
    C:\ProgramData\42DC50AF2F.sys => Moved successfully.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001_Classes\CLSID\{93a3111f-4f74-4ed8-895e-d9708497629e} => Key not found.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{06E487BC-9E96-4094-849C-2DD2E7FC0CF1}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06E487BC-9E96-4094-849C-2DD2E7FC0CF1}" => Key deleted successfully.
    C:\Windows\System32\Tasks\{3871DE69-2604-4563-B44A-8DCF4C5C222B} => Moved successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3871DE69-2604-4563-B44A-8DCF4C5C222B}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1E8CD17F-590E-4E48-A4D3-CC8D8209D53A}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E8CD17F-590E-4E48-A4D3-CC8D8209D53A}" => Key deleted successfully.
    C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{858AE255-1B9F-4F9C-996A-C2E7EC0CA1DE}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{858AE255-1B9F-4F9C-996A-C2E7EC0CA1DE}" => Key deleted successfully.
    C:\Windows\System32\Tasks\{AD50F3CC-A8D1-47C7-9BFF-546AC2AE597C} => Moved successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AD50F3CC-A8D1-47C7-9BFF-546AC2AE597C}" => Key deleted successfully.
    C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job not found.
    C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job not found.
    C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
    Hosts was reset successfully.

    ========= ipconfig /flushdns =========


    Configuraci&#65533;n IP de Windows

    Se vaci&#65533; correctamente la cach&#65533; de resoluci&#65533;n de DNS.

    ========= End of CMD: =========


    ========= netsh advfirewall reset =========

    Aceptar


    ========= End of CMD: =========


    ========= netsh advfirewall set allprofiles state on =========

    Aceptar


    ========= End of CMD: =========


    ========= bitsadmin /reset /allusers =========


    BITSADMIN version 3.0 [ 7.5.7601 ]
    BITS administration utility.
    (C) Copyright 2000-2006 Microsoft Corp.

    BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
    Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

    Unable to cancel {363CBF9F-48FD-41C2-984F-68CA5F23D8CA}.
    Unable to cancel {F13007D1-BA2C-426A-9BE4-D77A087B08A6}.
    {C507F8A9-00A8-4054-8F04-0DC0CAD5C9D6} canceled.
    {98AB62F0-5EEF-41ED-AE80-A5F3623D1E95} canceled.
    {1A95576F-17C1-4AB7-B937-461F95A80ACA} canceled.
    3 out of 5 jobs canceled.

    ========= End of CMD: =========

    EmptyTemp: => Removed 339.6 MB temporary data.


    The system needed a reboot.

    ==== End of Fixlog 15:42:50 ====

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.4.3 (03.01.2015:1)
    OS: Windows 7 Starter x86
    Ran by iselba on 07/03/2015 at 15:53:59.90
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values

    Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
    Suspicious HKLM\..\Run entries found. Trojan:JS/Medfos.B?

    Value Name Type Value Data
    ========================================================================================
    BTMTrayAgent REG_SZ rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp




    ~~~ Registry Keys

    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.DynamicBarButton
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.DynamicBarButton.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.FeedManager
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.FeedManager.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLMenu
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLMenu.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLPanel
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLPanel.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.MultipleButton
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.MultipleButton.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.PseudoTransparentPlugin
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.PseudoTransparentPlugin.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.Radio
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.Radio.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.RadioSettings
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.RadioSettings.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ScriptButton
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ScriptButton.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.SettingsPlugin
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.SettingsPlugin.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.SkinLauncher
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.SkinLauncher.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.SkinLauncherSettings
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.SkinLauncherSettings.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ThirdPartyInstaller
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ThirdPartyInstaller.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ToolbarProtector
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ToolbarProtector.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.UrlAlertButton
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.UrlAlertButton.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.XMLSessionPlugin
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.XMLSessionPlugin.1
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ApnStub_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ApnStub_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\APN_ATU3__RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\APN_ATU3__RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskPartnerCobrandingTool_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskPartnerCobrandingTool_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_atube-catcher[1]_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_atube-catcher[1]_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_para_atube-catcher_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_para_atube-catcher_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_para_windows-movie-maker_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_para_windows-movie-maker_RASMANCS
    Successfully deleted: [Registry Key] "hkey_current_user\software\pip"
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}



    ~~~ Files

    Successfully deleted: [File] C:\windows\System32\Tasks\Driver Booster Scan
    Successfully deleted: [File] C:\windows\System32\Tasks\Driver Booster SkipUAC (iselba)
    Successfully deleted: [File] C:\windows\System32\Tasks\Driver Booster Update
    Successfully deleted: [File] "C:\windows\wininit.ini"



    ~~~ Folders

    Successfully deleted: [Folder] "C:\Users\iselba\appdata\locallow\iac"
    Successfully deleted: [Folder] "C:\Users\iselba\appdata\locallow\videodownloadconverter_4z"
    Successfully deleted: [Folder] "C:\Users\iselba\appdata\locallow\zwinky_5qei"
    Successfully deleted: [Folder] "C:\Program Files\radiorage_4jei"
    Successfully deleted: [Folder] "C:\Program Files\video download converter"
    Successfully deleted: [Folder] "C:\Program Files\videodownloadconverter_4z"
    Successfully deleted: [Folder] "C:\Program Files\zwinky_5qei"
    Successfully deleted: [Folder] "C:\ProgramData\ask"
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{00E9C7DB-8494-4D3F-A5A2-BE7C607EB2D2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{00EFFBCA-29EA-4875-BDB1-870DBA7AC648}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{02699695-14F7-4F89-9A4D-F713AE20C036}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{028021BA-8FCC-4C89-A6A9-7E5C06E5675E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{02851D09-8512-4F18-AD72-F56003CFDAEE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{02DD3991-CEEC-453E-986F-A8DC9527FDE7}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{03C30F78-C1E6-44D9-BFB7-DBA038D49DF1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{040965FC-DFAD-451C-BE88-2887F4A28219}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{040BD99D-0F8B-4324-B70D-F0A73F52956C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{040FF8C5-7536-49EE-B0BC-1D32E999D49A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{04E8B9E1-9484-429B-AB17-87D0EC0E5196}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{050BE486-1ED7-4484-95B3-80D6EE5653BC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0534930E-53BD-4B41-A9C4-8C4B988ECE7B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{067FD1F0-FDC9-493D-BA98-C4623A7985C0}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{070FA93D-5298-4D00-AD0C-EC8E92A65741}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{07847D7F-4089-4E58-9FD0-C435ECD1D4DA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{078C85ED-F8E5-4B5C-A2F1-DB582A6B24F2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{07DC3B40-829B-489F-846E-96770C741982}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{08204A05-F60D-4CC9-9B9A-D52192535431}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{085EB82B-75C7-4983-BD36-1BFB73145F2B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{08D0BF44-6E46-4BCC-9E11-0804BBB88DCC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0A62A557-B23A-4347-9E73-CEB1BA042838}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0A694B27-5440-49B4-AC80-037E16223F19}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0A94E1C2-7B27-4754-857C-3F0860BAB329}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0B099FEF-A755-4577-A5AD-F65EA118532E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0D171EB0-DE64-4B48-B764-B79CAEF38821}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0D528415-DA11-475D-B921-5C27E1F4EDAF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0D61392B-3E24-42E6-B4D8-0AC95FB5B062}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0E7C5EC5-7515-4DF9-B820-EEBDB658F1A8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0ED51417-BF87-4192-B96E-360B471ED164}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0F7EDB3D-5350-4EC8-ACC9-30E62A1ADD9E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{0F80A4D8-45F5-4836-9DAC-DADF997AB11F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{10397240-6F30-45FB-BB2D-716255C4B873}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1058FAFE-5C63-4C31-8CE6-359A38E142CA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{10A00FE9-41E7-40F0-B1F8-E1FA6A343CC1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{11475D5D-2E41-4680-9691-75F86084484F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{116D7257-A016-4589-AD15-51688E06390C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{12D8C710-AF85-4BEC-8CDC-C7B914E4650E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{13D089A6-A433-45C1-88B8-7426A5C648CB}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{154C4920-906B-46FE-926F-419F43CA7678}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1739DB5D-14FD-4AD0-82AA-83D153629418}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{175AA364-AC02-4B34-920F-78537B6E5582}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{17BD6E6C-D022-4632-9DA2-F25B9FBA4326}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{17F03F37-DA00-47F2-81C0-8E797B04607B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1822646B-FDB6-4DF5-87A0-6208BD09F474}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1864B4F6-0D18-4F63-A915-A0062DE75B4A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{187656CF-2AE1-4CAA-9291-6C8CDB447F87}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{18D91E99-9861-4C84-B000-828052C9C345}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{194C19F7-4BCA-4B10-9C40-A7C73E6D6C55}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1A01B9C6-47AC-450C-8FFE-FA54EC2ED7E6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1A152273-E409-434E-A080-F389AF8D8BF1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1A4D79FE-FEFA-42C1-9615-24376A3E6C7E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1A77B09D-A84F-4753-A4D1-80395D489F9C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1AFCEB62-0E74-42C0-8808-1338E0914596}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1C63774F-DDE2-4AB3-90E0-EC170628603B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1D497A32-91CB-4266-8A74-2BB076DFFBE9}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1D51B2CE-7942-40B7-AE77-E7A0612F22BC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1D9AD9F2-9115-4217-9432-58E241FC2AC7}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1E00560B-8B93-4233-855F-4A7179AEADB2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1E7B903E-A87A-47E4-BA4C-B4FD14C0B410}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1F0BD083-AE9E-49BC-85CB-62D7ABFE0FE8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1F186B8D-C150-4853-9D6B-53FA077E86CD}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1F341175-5869-4337-ABDD-8F2C927BF2AE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1F5C5F38-6643-4417-A13F-97E409239C27}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1FC82E88-BC14-4551-B3A0-62E720FC784C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1FD7145E-CED6-4BEB-A735-10619CCD96C6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1FE1E82F-EA79-4F31-B104-9FE706405B7B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{1FF944C2-B8F9-4573-8B4B-9600846552CC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{204E7314-E9B0-4260-B944-4DB5607D5DAC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{21A50DC9-8279-42B7-86CF-6DBAABC90E20}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{21A798EF-00F0-4234-B841-3BCAAC659010}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2308B819-1002-43AD-920C-B0B439BF6EF2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{236ACF7E-891E-496E-B8AD-F36BC638AB7C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{246B0E68-E717-4CE7-8988-4123FF23AB46}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{24820AE1-FC48-4B3C-9237-1AE8E72ECCB4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{25212183-5781-44AC-9EF3-8A16075B0FFC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{260E20A3-D39A-416D-A4C2-D0A11825D061}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{265578A9-DE06-44B1-A366-0EE51C36223E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{26879474-0A6F-42FE-BE06-7AA3BD3DD5CF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{27142001-36D4-4ACE-BDD6-863F013A0731}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{280D00C0-D52F-4D5F-ADFA-1EC62B7720D0}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{286D2B9E-56A7-4F1F-864B-B85F48A1F536}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{29EAE82D-BCA1-4BE7-82D5-0F06499C3817}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{29FF5C7A-8ADE-4B08-AE77-D03C8E058590}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2A045EB2-6CB1-429F-9681-4343BF479C84}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2A5029FB-DD92-418F-A2DF-82D0E78FD722}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2A809C04-0DD6-4440-B549-C808AD85D852}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2A814202-79F3-4C9F-9B67-CD8B6ED493F7}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2B49D10F-EAF3-44D7-B3CD-1C529FB17B74}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2B7CDCE7-A1D2-42C7-8120-234BBAFA0017}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2C9F2294-2D93-4F62-B917-FBB29CEB0E57}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2CBAFF84-D117-422D-A27C-6DF6176AE2D8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2CE130BB-F7B6-4E6A-B4EC-6FAEF7CCB480}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2D3A32AF-E394-4A5C-8664-2BB169ECD3FF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2D92084D-411B-42CD-AE30-4F4E15C8A161}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2E5E53E5-F10B-4915-92CE-DF89CD34EE9F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2EC6293A-8BB5-4841-9648-560F8E43F344}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{2F77BCAE-4A23-4CCE-9553-61AD90BE2C86}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3020C131-FF45-4E87-875D-F1B85D82C820}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{308B7D93-9CD0-4652-8A32-608A3F782191}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{30D8119E-C304-49D5-948B-29764583C0F0}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{31072A95-8668-4285-B58D-748E10918130}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{31F27089-0A37-4E39-95A0-C63BFD0C95A3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{326AFEEB-C439-43ED-AFBC-E7D2226C8A25}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{32DE9A7F-20F3-453C-BD2A-C42E10367406}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{34ED93E5-CA53-43E8-A5C1-691443A4FB4D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{357E89F3-1479-43E4-ACEA-BB8A83084EDB}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{359FE925-0B7A-4163-9048-8BF846E92F7B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3654EFF7-1B1D-441A-AC44-F98F9D40AEB9}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{36A32AC1-026D-4CCF-942B-360E5A114972}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{37226BA0-3212-4780-89A1-E26D41F21D0A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{374EC071-5C1E-4C12-AE61-976D9D6C070D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{378F81EC-9A98-4C3B-959A-6CD5DD7BA9B6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{37D50D08-0EC7-4598-BB9E-C75516430E7F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3832638D-A3F6-42D9-ACA8-E2C1FA485332}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{389F97A6-8D7E-440B-8D49-25177A6E4B4B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{38D263E0-7100-40CF-9634-861B268A08C8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{394F4C59-B418-42BC-A282-E617245B876A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{39820F75-FCDB-4EA8-9F5C-6FAB8ED71F4D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3995EE67-450C-4C5A-BFF4-6693C281F4DE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3A0B3674-ABB2-4EC7-8BEF-D28938AC9C42}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3A525A94-3100-457E-876F-03959187CD21}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3BB81345-6AA5-4DA6-84D1-B701BDBF9309}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3BB829B1-E8AE-4A4F-B407-45D793EF1C1E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3BC7B423-8095-4AF1-BDD9-54C0B178255A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3BD6F393-657F-4218-81AA-1A16A71CD8CC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3BE80342-82E2-4B57-9D75-8B5E0C0D327B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3C6B9F3B-9002-4B13-9466-1E735910A820}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3CA9A10B-8997-4562-B23F-0A51D7F6AD7E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3D50867B-DB0F-491F-8052-FAAB18C28F3E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3DA043AA-E36A-4284-A95E-D1882208A2C9}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3DC935E2-2C96-43C4-B5CB-D4DC424CE8E5}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{3EA79132-7240-43A8-9744-F8E39E731446}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{40289943-CDAA-42BE-8B48-AFABF6D06F64}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{4042340C-1AA9-4AA2-BB81-4B04BACACFE8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{42FF09D2-D62C-42BA-9B2F-A058EF5C27C1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{432A2F27-817E-47A5-B783-8B317BA725C8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{436148FF-E717-4D0D-A28E-A310920D29AB}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{44B5D4BB-6ED6-48AD-B53F-3DB804183B7F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{45215555-5CAD-4E6B-88A3-AE78151313A5}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{452D4B24-8FCC-4521-BAB4-DA82098677BF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{45DAA7D9-3DD0-45DC-84E2-CBDF834D95AF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{469B8374-B2AC-4891-AE02-0C703CD077D8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{47B6CDCE-144B-4B47-B5E4-3970C64E741D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{492C85E1-C72E-4002-B69B-A28CEDE2E1B9}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{49AADDF2-C9D5-45C1-A8B6-B409D6A339FD}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{49EE8251-2EEF-4FC5-ADBC-CFDC392EF9BA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{4B3C4812-5366-4497-86DD-17C1621DD64B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{4C24E73A-4AA9-4EFF-8EE9-3CF650DEF0BD}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{4C391B8E-803E-461F-9B11-6D799D1CDAFE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{4C4A734E-C8D2-4CC4-8773-1F8FCAFCBF81}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{4D284B77-070C-4994-96E3-955B5CDCD3E5}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{4DCA44E0-EF1B-4C52-8799-0A6F2B1DDDF2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{4DD12E69-AD3C-4BDF-B7DC-8B73845F1EFC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{4DD4D7B9-3554-4DAA-8F4F-F677143F6C62}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{4E7BC0E9-4B9E-4534-8C94-42FEEB3CDC23}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{4F3E4CAB-A0EB-4EED-BC5F-A49C4D825CA5}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5001D7E9-AB3D-46FE-BADA-FD0FB5DC9F50}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{50611DCF-69FF-4131-B95E-CD39E06446A4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{50AD6E88-294F-40C2-A6F3-66D4529B6C28}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{50B5EDD6-6185-4E19-ADF6-B30A8976BF93}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{51C91EBA-0D44-4042-9646-FD1879B25057}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{51F3E2B9-01E6-4EF2-82A6-66190501C55F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{51F9A220-DFE2-42A8-B80B-EAABC6EF98DA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{52516803-5B35-4979-92B1-90CEFA325A7B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{52882FAC-28EA-4227-834A-FBEFC9D52D78}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{538DBB49-7389-441E-977D-BA30A46D61E3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{53960715-97CE-4A2E-AF31-C274E82CA576}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{53EDD397-FDDA-4675-80BD-E0BEA96CE290}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{545D8DD2-065C-47CF-91CA-F79E2BD0D0D7}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5576ACA5-BFDC-4EDD-A112-007831B424E0}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{559B3F04-D84D-4ACE-A02A-2C4A60C728A8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{55A9E532-64E7-4DCD-9A32-39AB07407C64}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{55DAC22A-266F-45C9-A920-ADEE2CA3767C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{56454426-47D4-4D0B-A7E6-0E1BA987E956}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{568CAE9C-98D2-418F-8860-E90B6D77B6B7}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{56CC9652-D63B-44E5-A593-C4934F3D2174}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{570EC697-D8B2-474A-AEC5-2F7B7982B7A1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5749C430-C124-408F-B346-0D668AC8E6DA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{581B7A7B-3614-4397-AD3F-B1AE07F79322}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{58257457-557D-4FFC-95AC-B1B0393C3250}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5850EE3A-1629-4F65-BA0D-B177C99F747A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5975C5AE-D25E-402C-9A9B-5CF32467FA04}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5984D330-DF8D-4DF4-930F-864E568D6729}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{59D7FD46-DF9F-454A-9F43-CCDA671767B0}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5A692210-6398-454E-A1C8-75066426A11F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5A8EFDEF-513C-4514-96F8-D66F831F7086}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5BB58F88-468F-4854-AB48-52EC653881C3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5C403BD6-4FBF-4E36-8767-19CB401C407E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5C6786FA-362F-4781-8BEB-C68395CC549A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5D3CA5C5-11A8-4C83-B63E-D774EBF8536E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5D3F814F-2D28-4EC3-BC61-C1F2F9AE0653}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5D6B04F7-72ED-4DA5-8029-DEBA129B6FD3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5D733C88-6D54-4F32-B85E-EF483B54F8D3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5D8E6EA3-758B-49A8-8191-172E80992B0D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5DEF6E3B-C977-42E2-867C-790F2E824DF8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{5ECB49A6-624E-4AAA-949E-26C308981241}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{60036B89-8D47-4CBD-899D-B1C7B7AF3D39}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6023B940-FCD3-4935-8C9A-358F396B951F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{60703B33-0839-4EF4-8593-0D8ED2ED0DEB}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{611447DB-42A1-499F-97BE-497B22319FE6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{619B1011-9FF2-443B-90F1-0C6DC6725C10}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{61C5CAF3-1C89-4CD1-9A27-FCD939C6209A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{61FF1C89-650F-45EA-AE70-DCA5A96A7463}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{626954CB-C4FD-4022-BAF4-F19FD865E433}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{62C9BEC7-E744-4D9C-B417-FF76DC10C7AA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{64374EEF-F877-4151-9D6E-22DAD1B69B28}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6490CB46-B3C7-439C-9588-14E095021F45}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{64E2161A-7EC8-4AA6-BD01-615E78F5BC28}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6531FF20-D21A-4EAE-A338-868ADD7420EF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{65E8C905-197E-498C-9326-0668E366D69E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6623500B-6F3A-4360-8054-E4F03DC0F365}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{666A272B-9461-4F08-94EB-6CF1EC2000AD}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{668EB436-5071-4E88-94D5-6DDBD5E45A30}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{66E16BC6-7A67-472C-9DEF-DE4FF13967FC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{678731A4-0A19-4E48-B6C4-79457EAD6022}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{67AE3C76-E624-4199-8B0C-6BE8ADAE69BD}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{67E86265-1081-4B22-9257-D6EE2C0B7206}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{68AD3679-48BD-4896-A0BC-EC66B3C71E16}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{68CB8F09-07DE-4695-B7D9-F9D1F0D7F849}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{68DD629A-65C5-4062-9C43-A990047AF6D9}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6A087641-6EAC-4996-9B3C-AB98CAB810F2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6B69BEDE-58C9-4646-BEB1-167814725A1B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6C79A7F1-12B5-4601-984D-3CBFE279E1F1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6C7D1217-3055-4FCF-8877-FEFE0E4AD9E4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6CB9CBEB-CCB4-419E-9A4B-DAF170F47ABE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6CF3E808-4F24-4EC7-A4F3-794B5E8E9620}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6CF91B7B-E850-473D-89DB-CF5BD73F92EE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6D5A4B69-BDF1-4488-87A9-09B03624756D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6D5B6052-A67D-4F7B-8268-7BAD105FE9B3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{6E61596E-29E9-4BC8-AA19-C16553CF8F9B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7091526A-BA52-4CDF-93CF-59DCF0EDA9FC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7145B9E1-0075-4AD8-BA82-4CD30B3A9D1E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{723CC853-B948-4A55-8763-E71105A2E0D3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{732D78DE-3A35-4B1F-9AAC-5C4A62821490}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{759DB97C-89B1-4F1B-A60C-71BBBB7BA90C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{75C58C8C-CD9C-4534-B765-8C2B5DC8E70E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{75DD8BCB-0411-4D00-A7AA-F69BDBE4FD88}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{76199411-461E-43FC-92D1-D44D60C300B2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{765C283F-D420-413F-B5C9-574B7A3F3D2F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{779A6305-9521-4A86-8D66-E47EEB6EBB7A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{77A30E1A-2C99-4128-B4B0-54553AE417A2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{77E053B0-9FFF-4006-8943-EFD468136EB0}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{78364A53-9DD5-4C55-84C9-7820E9143418}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7973DF28-BB92-41E7-938F-C5BC4DEF3FF3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{798D24CC-44D6-48C9-B934-FE6C846B3A2C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{79A20DC9-7441-4D88-8960-D92182DEC6F2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7AAC36DC-D3E4-482F-A3F0-9DAEA4007E81}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7AEA3509-B4A6-413D-A6DE-009FAA38054A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7B037CA1-F0FD-4676-8B19-C8CBD743725E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7B7231B9-7ED5-4F12-91A9-61AA7AFDE3BF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7BD045D6-E89F-4B33-AC11-F3E6B5BDE987}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7C0A52D1-CB38-4193-9F03-3CE99E06FA39}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7C291010-D8FE-42C6-A14B-E3BA7A106F88}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7C912EFC-EDAA-4491-8E39-A9939282E127}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7CB22C45-2B89-4250-BE3B-66B98C1C77B1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7D671ABD-DFC2-4FC3-947E-2169842A45CF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7D89F29C-FEEF-48FF-818D-2E8A7D9E981A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7EE11D42-987E-4511-8B33-009C0B243A77}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7F46B430-A908-4AC1-B764-C67E25A29C0D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7F60AE24-2B3D-4BC9-BDF9-A6C3536623F7}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7F74CC2A-75A3-4E0F-9463-D9831E966E49}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7F96134B-2695-4E3C-9155-AC5CFA16B83E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7F96A0B0-51BC-4778-B36E-6D5DCF62864E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7FCAA3C8-14D9-4F6C-8F32-1F3932DD4363}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{7FDD0FF5-8BD6-49C3-9ACE-6B87B14B4329}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8065F1B8-506D-40C6-B984-60E0CEFC94B2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{808D6510-96D6-488E-9A26-269E761E3191}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{80ABF618-399B-4EB6-ACC5-D5C7FEDBD602}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{81ABABFC-B6FD-414C-8533-4CD111A43271}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8229848F-580D-4F99-9903-4F89BFA4351C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{82A25126-81BC-4346-A04F-1B9C78924852}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8300DB87-4F0F-4ED0-924F-58C920F38314}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{832710DE-CC7E-4531-9CED-DA8309899F90}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{834C4000-4316-4198-8BBB-61B8B15B9FFD}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{83FBDBB2-679F-4D22-92D2-F3BE1B0F12FE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{849CF8CA-CE44-428F-9C2B-68A763A00A31}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{850FED10-D6CA-47D3-9A37-209AAD3B81C9}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{85625C33-8233-47CC-8A1D-CCEDA5B6A0B1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{85EAB2FB-BF79-4644-8664-F218FCBE8B4B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{85F596AC-222F-4DDA-8223-894DED2E0BFB}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{861B60A2-ED37-471E-B7FA-BC84E4395B10}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8632584E-303E-457D-BE37-EE87ABD99329}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{86FA7F31-60E4-4D59-B77D-7BE74E5A0559}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{87257622-BA3D-42D8-A6A6-4F1A8E5EAAE1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{87C0A136-59D0-4E32-AC43-CD15FE63E0D5}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{87ED1BC4-89C3-4786-BB68-6BFCF87E16A2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{88479BAC-32F2-4BF7-9C83-CAF9B3D22F7D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{884CDA33-CD65-4186-BCB1-D14DADEC3CC7}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8851C3EE-A1AF-4119-BD77-E118F0E851A3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{88A2C7C2-032E-4B92-AE3C-2CC9DC55CEF4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{898A0036-C3C7-4ADD-8DFC-234805410ED1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{89D53F14-3B23-4098-920B-014D2D89FAF2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8A550D51-2914-4E5F-B761-6DB6C5F9741C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8A6D87F0-4AF9-42C1-9947-33596CF8BB32}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8A70ADB9-F1C3-42B5-8E4A-EDBB1805B253}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8B4FF132-A4A0-4A7B-A890-D1D52D92CD7F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8B59E4E1-811C-48AB-81FA-0141476A4CE5}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8B88FD9A-2942-42CF-8964-0B4CBB1B4A35}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8BACB64A-FA75-4018-88E7-67C20A369D3B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8BE98BE2-31E5-40D1-9375-ECC4345E7993}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8C24D8B4-637D-472E-81E3-CA617BE0495A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8C31F676-DC30-4E58-B047-CBDECC2C3147}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8C6DCB45-FAB9-4457-A996-88530AF5153D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8CA67238-8866-46D1-B73D-78AFA35ECBD7}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8CF4E12D-721A-484E-905D-F0AE98D021B3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8D687F76-FBFF-4CF4-AACB-1F20D285C64F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8D8BC8BA-824C-42D1-8857-CA88505CFCA3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8EB4945A-4BDF-40E5-9029-133935C9C781}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8EEF54D5-D7F8-4863-A6F2-760CB2828094}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8EF4ADCC-38D3-44FC-9E26-C098B84DC167}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8F6975D3-4CB6-4D58-9A32-C9E76E3C674C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8FCC6B03-0C5A-43BA-8392-A99C3698254E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{8FF4879B-88C2-4F29-BDF2-CABF08356F05}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{90446502-11AE-4865-8C0D-A72DB1F9A27D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{910CB8C2-FCBD-4D5F-9A28-454A6A13700A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{91269976-81E2-41A3-9B40-C70F5BA0AE2A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{91C0AAE4-F169-42A9-B358-F23F7F9258AC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9272EDCC-B253-4EB1-A8AB-705AB8BC8801}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{92CFD46C-12EE-47C0-8AEA-15C8F9F50A78}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9328FA82-7EBC-4874-BC5A-3D13F9E3DDDE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9347D5F3-DF03-4E5D-BB9C-F457BCED80A6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{941164AF-88D7-4274-BB67-03E80A30D5C8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{94187FA4-A7DE-4631-B30F-6A3F88336EF8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{94955541-2DAC-4344-8671-FB9B24277870}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{951D3647-2123-4978-881C-E46FB305BB85}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{95672E92-C1AD-44E4-BE13-6D5B43491683}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{95774686-0452-4D96-9319-DDC27E865BC2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{964D3652-7190-4595-939C-E8D08FBEA739}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{96568F5A-F593-4381-9E83-7258AA15873D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{96A07B12-AE4B-4D32-978C-CA44C4EA4577}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{971A4DF3-E776-4445-B637-BC16234B7850}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{97814776-BBC5-48A1-93E8-0A1FD39706C2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{981604AE-D921-4BA3-89EB-E5CA661D274B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{98EA4EA3-B48B-4C94-B0E8-24EED76D4916}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{992713DE-248F-4C35-B9D3-98B25A1E3CF6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{99AB1E73-E96B-45F2-9E69-366DB2AFB4A1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{99F9C49E-3DAF-4ED8-BC74-3EDD33D262A4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9A2B0E6B-C2C6-4DBF-96C3-1046FA4D622D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9A6EA56F-8DB1-4546-8D72-445DD8BD135D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9A76ACE9-3977-4E46-B295-AC1B812989CF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9B6C0F1F-D2F9-4F54-AB51-941C331D87CA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9C01514B-6904-4628-8C15-C997304B5A8B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9C2FC8B5-57E4-40B3-BEDA-5295D7217109}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9C382B46-01AA-433A-B975-052A12AC6F9C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9C536A4C-6406-4481-A08B-DD5A3432B005}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9E01F83A-3619-416B-AA65-94D24E0AE5C2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9E4DD95B-D885-43D4-B442-7D7BE9BAD5F6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9EEAEC02-9B1F-44BF-9703-2710D0FBB511}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9FE45BEB-2CAA-47A8-94BF-BD4255C4B6AC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{9FFAF12B-87F0-4B9E-8DF5-34383D64F83B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A0279709-FA2B-4B8F-8758-BDE992744609}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A11FE0E4-2CE6-420C-BA87-0D3581D9A6EF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A12702DF-CC13-4583-8A53-7B1B8B099446}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A184AEFD-6A1C-499C-9F67-FA15B0C4EE63}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A1F17850-373D-4927-B6F8-42C0251D7290}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A20A6A6E-2DD6-42D8-833C-B1CFB9CA6320}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A23B474A-C959-4342-A45C-79A9CAF94A7D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A25F660A-4ABD-4623-A4C3-9AC6CD3F90C6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A2970D5F-BCAD-4249-A1B6-112E441E470D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A34C88ED-2F5F-4A40-A276-A414D921CAF6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A473989C-53E4-4A0F-ACE0-0043BBAB1A26}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A5577551-A98F-4819-BAE9-F00E2AADBB7A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A5E579ED-9DE9-488D-A723-FB1CF1F8D3E6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A610D9CE-52E8-43D4-AD83-9074AAA30726}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A62D0B55-889E-4B5A-A587-6962129C8DF9}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A644C166-909E-4657-B968-A981091AA11D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A6C8C3B2-56D8-40D1-9A3F-AD24E10290F3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A76139CC-4044-48EB-9BD2-7DB7809BF4DC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A78138F6-7E4D-469C-9237-602D54F272A1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A7BEB5AE-08B0-449F-9CE6-49FBFB1FF778}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A86610BD-B46C-4C06-8507-3594EE630018}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A9123D10-E399-410F-953A-AFE7F323C9E3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A982AFB1-A762-4749-B13E-498FB08E680B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A9ECAE93-D14E-454E-88AB-3EF4E2BA7C77}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{A9FE582F-9FC5-4721-8702-3D33749807E4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AA6DB8C6-FD05-40E3-8AF5-06B3C908B641}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AA8E27A5-6733-4E18-9B94-4C260E761BEA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AAB51DE6-A1C3-4A60-A4D0-A3C1F6DBC4CB}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AB12BE40-74BB-4A9D-B005-26A2786B3C7A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AB28C0B4-52B4-41FB-935C-4084156A8DFA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AB36499A-881C-4045-9090-B203A984F0FE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{ABDA03D2-2282-4806-8C6D-11234E286E30}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{ABED032D-E3A7-4D96-9DB8-01BFE41A4004}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AC016CC1-E26A-4122-B7E9-51FDC1CDA045}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AC517D60-D2AB-48C8-B749-FBA7CCB5C235}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AC82E4F4-F1A7-44D1-9E2A-B1C4E3575C6D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{ACCB1364-9D29-4A68-B6CD-46616851AC55}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{ACD5E8ED-68A1-4DD5-BB87-7CA58D9809D7}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AD6E388E-3F35-40AC-80CA-329274F8694C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AEE76F30-6B5F-4EB9-837B-2ABEBAB05CB1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{AF791A1A-FA6F-41EA-B9DB-F1FDE5F273EA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B0379971-AEDF-4459-A5AF-AC75E5725D87}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B0473DBE-C9B5-49C0-B762-95DD6A7E9E4C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B07E6F22-FFFD-4143-BC25-941B20AF094F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B0AA11C8-41DF-409D-9794-7D41554EEF05}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B1420EBF-E8FF-4E11-A8C0-79AD3C893169}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B23C0CB0-4F29-48EF-AAFD-180DCDD38757}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B2760663-57A8-4BDF-AC0A-1077E32F4B17}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B2AA6299-73DA-48A1-B566-EB8379185E22}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B304A3CB-B8B6-4CCB-81EA-CF7C537468F8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B3BDDDF1-9E1C-4BB3-8BE7-282EED7B0467}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B3E0ABF6-FEB7-4ED0-8EAA-18A676810C17}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B4449C5E-A988-4125-9575-114A4931A5A6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B4BA07EB-4750-4E6B-B0FF-86DBE2C5B467}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B50A438B-AADE-4DED-8B33-0A451482968A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B5636545-17E2-42B9-90B0-5F98A90AF4A7}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B578E7A3-BEEB-494C-A430-C098D3784448}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B5A70FA3-666A-4B75-B3E2-089437D022EE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B65817C7-D0E9-4D16-A158-14D05F125045}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B66361D9-3835-4CCE-89C4-4E9CAFE628C5}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B69B9F8F-36C0-4CF1-BC88-43B4093C0226}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B6DF88BE-4F58-4E97-88F7-03158AFAF898}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B7723CC0-1155-4C89-B40B-E3678BBD770B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B79A9E99-843B-4F16-9242-A4F57666B4AC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B7F9D378-6EC1-4E30-8CE8-F276F64F4865}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B8910326-B2CC-4B27-A548-13FC330CDCA2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B90714A1-128D-4F0C-BD57-400552E9EA59}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B93B60C4-3F86-478F-A6ED-99D817D47CD2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{B9CAE285-F586-49EC-A743-251A1FE32262}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BA97B191-815F-4F78-8757-7CBA07BF13C8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BB5F8F4A-F38B-4743-8300-8758F0B75400}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BBAFB4AE-7F4B-406F-980B-1C88FF0032B4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BBC03D0A-FF64-40DE-85A7-78BCFC6000D9}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BC2C1F76-51A7-4C74-97C4-879B669DD495}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BC4DF005-0A5E-4F28-A095-84D235C46EFA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BCBF60DA-9670-4FB2-9A7D-67B63574C267}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BCF47EB2-1FDC-4C56-B73F-9BFE2AD37A07}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BD11D092-6427-43AB-BA0C-229922CD8379}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BD1AEE6F-76D6-47BD-8D03-AEC590A54717}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BE9F2439-22BD-45FF-B572-7F5A3C64F3CE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{BEFD1F9E-FECC-4CB3-8321-161946241245}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C002A782-4211-42AC-AA72-95A228848557}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C0D566A0-DDD5-4A6A-86EF-7400B4E45987}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C0E7CBC4-2453-4BCE-B0FC-2BABED083C23}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C100795C-67BA-4873-8A48-279DEE626F29}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C14124AA-EB01-43C0-8F0C-1540B7DBB45B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C1C1104E-81A9-4D46-AF9A-DEA8BA7645B5}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C1CC4BF9-D8B3-47E4-B580-7F34039917E0}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C1F5DE1F-AB01-44A1-840C-A5181E8CCF81}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C1FDF4E7-7950-403C-A644-C891BE0848CD}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C243AE33-96A5-4B87-9DD2-E58772BAEAAF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C30C520F-6407-4206-84E3-076BA8551C3F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C387FB06-77F8-4EE0-BE44-F9C5D0501A5C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C3B8B933-ACE9-4AD1-8B46-408D91BF97B6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C3D5D965-BE88-4AE8-9229-94497DC86A88}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C4C0D5D3-FE5C-437D-AF7F-64CDB4DCE193}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C5E6FA0F-9C56-424B-AAFF-ABF62D62A319}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C60A7073-20FC-4C38-A0CC-8088EC661A7E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C68685C3-2AE0-4602-96BD-06628401454B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C6B7CC4C-A2F6-43CC-864B-6FE308EF4F10}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C6C254C0-9A21-4924-A60D-9D7F21528221}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C6FD2AF3-158B-4904-BDB4-8D195BF5CE77}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C804D7BF-C3ED-4BE4-9752-762083FE6922}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{C8168C29-CC74-4550-977A-CDE985BC32E8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{CA462EAC-43FB-47F9-91BB-E77FFD1A70E0}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{CBD68732-585C-44AA-9FE4-E6373213E9CD}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{CCEBA30E-B827-4D53-B082-41CCE23F1172}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{CE21387D-8D28-4282-9123-DE3ABC4C28A8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{CF0CE943-BD25-4A3A-BC56-47FE8A48CA3B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{CF554C29-3FDF-44FC-BEDE-41D40393A449}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{CF63DC2B-AD92-423A-AF0A-E269D0BA7D5D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{CFCAA770-E142-40AA-99CA-3E218AE40AAD}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D134550B-40FB-43D8-8421-0136B685A4D8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D24D541D-4F32-4983-952B-7B88AF4C5205}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D36044F3-9FFB-4FF0-AA4B-4A52CC3C0B37}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D4CD10E2-5CE3-4276-AA29-148A0DEF5231}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D504992B-24A9-4CA8-AE95-67AC10CAC032}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D58FF387-FB04-4B67-B579-CB872AAEEB3C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D5AA3DDE-5EA1-4ABF-ABCF-F9BAB4722BDC}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D6DB3208-3B81-49E0-B4BD-516189CAF92D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D7B044E0-D83E-4A3D-9F13-66F86B31EC3D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D7BF2A44-727B-45A1-BA22-9CFB982F7D0B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D8A4E383-A7A9-4B5E-8DCC-708A8C901BCB}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D94E7D00-02E2-428B-820C-F44F61FE15FF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{D95F767C-AC35-43B3-88AD-5B977C1B67C5}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DAB3CADD-28BC-4EAA-B5B9-01E5F4C69E95}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DABE7780-7A85-4B3C-A8CE-13B88CDE3E33}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DAFC1857-C4D8-4D16-A690-6D766824E9D4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DB430238-3F69-4EBD-81CD-232F4471DE11}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DB664EFE-FEB8-4C94-B827-47484F015C0F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DB8C4B91-3F58-447C-A5DF-8686E4E30434}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DBD9A274-A4D5-4656-950C-4A0333A59BA1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DC131ADC-D9B9-4DE8-BC05-8315D9B9DAFB}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DC5C5AA1-8DC6-46B8-AD4F-E6B0D92D133F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DCACE2D3-A2EF-4858-8008-117938F69C88}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DCC7B6F2-EF71-4B4F-B587-3505AEDCC1C2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DD167FDE-7122-44B8-AE55-954733349C27}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DD65B9A5-80A0-4318-B042-454048234EBA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DDBEB381-DE91-47E8-90FC-A1735F2F23D0}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DDD18E2B-F2A4-49A6-A426-BEFA0A20BC21}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DE02ED12-CE75-46BE-86A3-5F6E85541306}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DE81213F-1FA5-448E-8FCF-FA7460F0224A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DE9BEA7D-7E73-47F1-B55D-1EE7BE21F38C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DF2EC7C8-0189-4AD1-B101-7C31EC7061F1}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{DF3F2B00-8E98-445A-A310-A97C8A64D9B3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E0773C10-F64F-41AF-A7DF-FE790B9CE56F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E0B2943D-E10E-47BA-8AE0-57E22DEC0A8A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E1052C45-7969-42FD-858A-81D04B11A0E6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E14EBE0B-E17B-452F-9508-D05A9CD02DBE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E1A3F4B6-8139-45D5-A555-B81770829516}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E1C8F968-CB58-4119-B6F9-F63F0339212B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E24C0C4D-B5D7-4375-9A04-68A3D19F8D27}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E27DF6C4-A55D-4999-BAF7-4D215409F9D3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E297EE0E-EB18-4403-A0FA-6FBC2CD893C4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E2C01443-B36B-479A-BA39-2625899B7445}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E2CECF1C-B3BA-4396-AB86-788613C501DA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E303B0A5-C3DF-416F-84A0-CB4ED4E7EC38}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E3927D6D-177D-4AEF-B64C-FCBF7669B949}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E3D67583-11E0-4437-843A-5E67E0E1A08A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E4DD4C97-CB9F-4C8A-8F29-64C284751C1E}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E51F2585-E2B4-450B-BCA1-AB8FAAEF5621}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E60064A3-E932-4313-8A66-587E3E9D7E61}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E6580051-96E3-4C88-9710-910776BBC265}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E685DFDA-32E6-4C39-ACA6-C9BE1F23A67A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E68F7ED3-6265-494B-B6C5-598F7478A01D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E706EFE1-9B14-439D-B937-051260F6D8B2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E7D08938-6B54-48B1-B30B-F3201AD8D485}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E7D59D08-17CF-4F5D-9D0A-B66DDA0FC8AA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E7E1F10D-A1F2-4C51-A9A2-CD17D7116FA2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E7FC54C2-3208-479F-B69A-CA16DCA82E9C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E84169E4-29B0-45D9-AD88-89555D512A79}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E8C93436-FF63-41E6-81C9-40068D089C27}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{E8E63096-223F-491D-9017-F664324E205D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EABAB3A6-B8AA-4C30-AAB5-3A4912B4D596}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EAE0CAB7-C6AA-4AFE-BADC-285AB5C43E7B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EB2F5309-D8B3-476F-AEC7-4FF8F360C9C8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EB99F967-1E70-4BFF-B9C4-D51837D85C0F}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EBC88A2F-3577-4653-9228-61A8BFF99F3B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EBE55C01-4447-45D4-8096-6AA1320E8E98}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EC3CD574-D937-4D26-B0AA-8862225386F6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EC660C6E-B765-49EC-A890-EA49326FBEC2}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{ED247AA9-F341-4AE7-BFB2-9FE0F1A387F4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{ED6C7229-2CC2-4506-B2F5-E1E29142E25B}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EDA9029E-B863-43E2-ABE8-D0679176DFDD}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EE090B92-F7FA-4A5B-AA1A-DCDF1891BB86}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EE458CC9-C898-4ACC-9EC4-434DBFFAA7EF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EE6B3623-F370-4C7A-9D8A-F51B0693E4F8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EE96FEE8-58BB-4DFF-9D54-BA721F5E40B4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EEE2D4C7-C47A-41EF-A2C7-67615B2522A9}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{EFA5EB7D-B727-4376-B2E1-9182A7CDA342}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F0131749-4C37-4C74-B34D-2B2D51C228AF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F107449D-0425-417D-BDDA-83E4E6525E27}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F1196DD9-00ED-4C7E-9AB4-0FD343EB7544}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F16B640F-896F-407B-8743-F326F1BC6AB8}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F1A31437-FA8C-4FD8-8E84-4B7D0CF37198}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F270D465-A539-4878-8519-AD958658380A}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F2F42075-A2DF-4CFC-8BB8-B1D83D80B957}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F3B500C6-EA64-4407-88E9-5E89651D064C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F419CB87-B1D8-429F-8C84-8F0C7ED85582}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F6A1930E-5EFB-4AAD-AF5D-63B2353E4FC3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F6B80EB0-D02E-4729-8170-3EDC4F53EBB6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F6FE7F33-8575-4A1B-8478-2A07AC1F5C32}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F7133616-30C5-424F-A70E-692B2D4865EF}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F724CE01-17AA-48B9-9531-28670266F2A5}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F829F977-7EF5-40A4-B244-794905008A8C}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F843A129-31F1-4946-A6F6-9002A3DC1CCE}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F8FACD73-FF05-4DC5-A8B1-F9611B39B948}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F9ED209B-3CB9-4C6E-A453-E143A3D00CC3}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F9EE3432-5DB3-4882-AF51-41F305BA2ECA}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{F9F9674F-FDDE-43FC-B63A-24E2D149C218}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FA72FD9F-5F7F-44C3-88AF-1596C6C793D7}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FA8D90B1-90B1-408A-9D9B-109E8E890BA5}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FABC3E32-966A-42F8-9D79-B6D3F0577697}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FB07B94B-799D-47E8-AF1B-C0085E0F3594}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FCB61E70-CC48-4B0A-AFCE-F518A960F816}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FD06A6B9-7D25-4E7E-8E31-6F6C7E54EAD6}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FE144D08-3D7C-4060-8C9E-107E1C48F14D}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FE647661-C07A-40A7-82DF-C173F94E5076}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FEF55C70-204B-4A34-9D21-12E46560C805}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FF362C33-8C75-42F5-BA3D-724FA574B446}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FF60FD57-CC68-47B6-817D-553CDA213427}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FF61A755-8D14-40BA-8620-67CF6ED85BB4}
    Successfully deleted: [Empty Folder] C:\Users\iselba\appdata\local\{FFC5F6D8-1AE4-4965-964C-9E556CDD175B}



    ~~~ FireFox

    Successfully deleted: [File] C:\Users\iselba\AppData\Roaming\mozilla\firefox\profiles\gnw8ay56.default\user.js
    Successfully deleted: [File] C:\Users\iselba\AppData\Roaming\mozilla\firefox\profiles\gnw8ay56.default\searchplugins\askcom.xml
    Successfully deleted: [File] C:\Users\iselba\AppData\Roaming\mozilla\firefox\profiles\gnw8ay56.default\searchplugins\iminent.xml
    Successfully deleted the following from C:\Users\iselba\AppData\Roaming\mozilla\firefox\profiles\gnw8ay56.default\prefs.js

    user_pref("browser.search.defaultengine", "Ask.com");
    user_pref("browser.search.hiddenOneOffs", "Yahoo,Bing,Ask.com,DuckDuckGo,eBay");
    user_pref("browser.search.searchengine.alias", "key-find");
    user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine");
    user_pref("browser.search.searchengine.iconURL", "hxxp://www.key-find.com/web/favicon.ico");
    user_pref("browser.search.searchengine.name", "key-find");
    user_pref("browser.search.searchengine.ptid", "cor");
    user_pref("browser.search.searchengine.uid", "HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX");
    user_pref("browser.search.searchengine.url", "hxxp://www.key-find.com/web/?type=dspp&ts=1423948004&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&q={searchTerms}")
    user_pref("browser.startup.homepage", "hxxp://www.key-find.com/?type=hppp&ts=1423948004&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX");
    user_pref("extensions.iminent.admin", false);
    user_pref("extensions.iminent.aflt", "orgnl");
    user_pref("extensions.iminent.appId", "{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}");
    user_pref("extensions.iminent.autoRvrt", "false");
    user_pref("extensions.iminent.dfltLng", "");
    user_pref("extensions.iminent.excTlbr", false);
    user_pref("extensions.iminent.ffxUnstlRst", false);
    user_pref("extensions.iminent.id", "0c44f5f4000000000000e02a821d29ba");
    user_pref("extensions.iminent.instlDay", "16072");
    user_pref("extensions.iminent.instlRef", "");
    user_pref("extensions.iminent.newTab", false);
    user_pref("extensions.iminent.prdct", "iminent");
    user_pref("extensions.iminent.prtnrId", "iminent");
    user_pref("extensions.iminent.rvrt", "false");
    user_pref("extensions.iminent.smplGrp", "none");
    user_pref("extensions.iminent.tlbrId", "YBCPCSTIPO");
    user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q=");
    user_pref("extensions.iminent.vrsn", "1.8.28.3");
    user_pref("extensions.iminent.vrsnTs", "1.8.28.318:13:30");
    user_pref("extensions.iminent.vrsni", "1.8.28.3");
    user_pref("[email protected]", true);
    user_pref("iminent.enabledAds", "false");
    Emptied folder: C:\Users\iselba\AppData\Roaming\mozilla\firefox\profiles\gnw8ay56.default\minidumps [135 files]



    ~~~ Chrome

    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof



    ~~~ Event Viewer Logs were cleared





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 07/03/2015 at 15:57:51.93
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     
  11. DanoNH

    DanoNH Malware Specialist

    Joined:
    Dec 31, 1969
    Messages:
    106
    First Name:
    Dan
    Hello quenosabe,

    Lets see if we can clear up the programs and your Chrome Key Finder extension, and I'll have you run another FRST fix for some items that didn't process correctly.


    First
    We need to totally uninstall some programs using the Revo Uninstaller.

    Download and run the free version of Revo Uninstaller. The FREE version download prompt may take a few seconds, so please wait for it.

    Select the following programs and click Uninstall.
    • AVG Security Toolbar
    • Driver Booster 2.1
    • key-find uninstal

    Set it to 'Advanced' and click Scan.

    Revo will do this:

    Step 1. Create restore point.

    Step 2. Run the official program uninstallers.

    Step 3. When the process finishes, click Scan in Revo and it will search for remnants. Delete everything found (Select All, Delete All).

    Reboot if asked to.


    Second
    Uninstall a Google Chrome extension to remove it completely from the browser:


    1. Click the Chrome menu [​IMG] on the browser toolbar.
    2. Click Tools.
    3. Select Extensions.
    4. Click the trash can icon [​IMG] by the extension you'd like to completely remove. (Look for key finder).
    5. A confirmation dialog appears, click Remove.


    Third
    Run a FRST Fix

    Download the attached fixlist.txt file and save it to the DESKTOP.

    (NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.)

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.

    Run FRST/FRST64 from your Desktop and press the Fix button just once and wait.

    If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.

    When finished FRST will generate a log on the Desktop named Fixlog.txt. Please post the contents of that log file into your next reply.
     

    Attached Files:

  12. quenosabe

    quenosabe Thread Starter

    Joined:
    Apr 17, 2012
    Messages:
    39
    Hi Dan, got rid of avg and driver booster, key find was no longer on the programs list, has not apeared on chrome.

    I just noticed that when i run the mouse over almost any link on a web page a small window pops up at the link, it tries to get me to download "utility pc repair", of course I have never tried to download the stuff, i just close the window thwt pops up afterward.

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 08-03-2015 03
    Ran by iselba at 2015-03-08 21:14:49 Run:2
    Running from C:\Users\iselba\Desktop
    Loaded Profiles: iselba (Available profiles: iselba)
    Boot Mode: Normal

    ==============================================

    Content of fixlist:
    *****************
    start
    CreateRestorePoint:
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=ds&ts=1423947936&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=ds&ts=1423947936&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&q={searchTerms}
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=ds&ts=1423947936&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&q={searchTerms}
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=ds&ts=1423947936&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {AA74C1E3-044F-4DEE-9963-9FED50D139A3} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-808547686-2828976095-2913112375-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.key-find.com/web/?utm_so...tm_campaign=install_ie&utm_content=ds&from=co r&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX&ts=1423948025&type=default&q={searchTerms}
    C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\user.js => not found.
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\extensions\[email protected]
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\extensions\[email protected]
    CHR HomePage: Default -> hxxp://www.key-find.com/?type=hp&ts=1423947936&from=cor&uid=HitachiXHTS545032B9A300_101026PBNC08EYKWK90SX
    end
    *****************

    Restore point was successfully created.
    HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
    HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.
    HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
    HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => Key not found.
    HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
    HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found.
    HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found.
    "HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA74C1E3-044F-4DEE-9963-9FED50D139A3}" => Key deleted successfully.
    HKCR\CLSID\{AA74C1E3-044F-4DEE-9963-9FED50D139A3} => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6} => Key not found.
    HKCR\CLSID\{C04B7D22-5AEC-4561-8F49-27F6269208F6} => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key not found.
    HKCR\CLSID\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key not found.
    HKU\S-1-5-21-808547686-2828976095-2913112375-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => Key not found.
    HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => Key not found.
    "C:\Users\iselba\AppData\Roaming\Mozilla\Firefox\Profiles\gnw8ay56.default\user.js => not found." => File/Directory not found.
    HKLM\Software\Mozilla\Firefox\Extensions\\[email protected] => Value not found.
    HKLM\Software\Mozilla\Firefox\Extensions\\[email protected] => Value not found.
    Chrome HomePage not detected.

    ==== End of Fixlog 21:15:03 ====
     
  13. DanoNH

    DanoNH Malware Specialist

    Joined:
    Dec 31, 1969
    Messages:
    106
    First Name:
    Dan
    Hello quenosabe,

    We are making progress here. :)

    Regarding the pop-up windows, can you please answer my questions below?

    1. In your original post in this thread, were the pop-ups you were getting only in Firefox, only in Chrome, in both, or you aren't sure?
    2. Regarding the pop-up you describe most recently, you mentioned Chrome. Is it happening also in Firefox?
    3. In Chrome, is it a small box inside the web page, or does it open a new window?
    I'll return later with our next steps. Thanks for your patience.
     
  14. quenosabe

    quenosabe Thread Starter

    Joined:
    Apr 17, 2012
    Messages:
    39
    1- I checked, it happens on both chrome and firefox

    2- It is a small box on the web page (I am not too computer literate maybe it is called a balloon...) doesnt matter where I click outside the balloon, it opens a new window redirecting to various sites, Then I close the window and can proceed normally.

    When I pressed the "reply" buton to answer this post it popped up another window, so I just closed it (i know there is nothing wrong with your website).

    By the way, same thing happens on internet explorer.
     
  15. DanoNH

    DanoNH Malware Specialist

    Joined:
    Dec 31, 1969
    Messages:
    106
    First Name:
    Dan
    Hi quenosabe,

    Here are our next steps to get rid of the PC Repair trojan:


    First
    Run AdwCleaner

    Download AdwCleaner from here or from here. Save the file to the DESKTOP.

    NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

    1. Close all open windows and browsers.
    2. Double click the AdwCleaner icon to run AdwCleaner. (Vista and 7 users) Right click the AdwCleaner icon, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    3. Click the Scan button and wait for the scan to complete.
      [​IMG]
    4. When the Scan has finished the Scan button will be grayed out and the Cleaning button will be activated.
    5. Click the Cleaning button.
      [​IMG]
    6. Everything checked will be deleted.
    7. When the program has finished cleaning a report appears.
    8. Once done it will ask to reboot, allow this
      [​IMG]
    9. On reboot a log will be produced please copy / paste that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[S0].txt




    Second
    Clean and Re-Install Malwarebytes


    • Download and run mbam-clean.exe from here

    • It will ask to restart your computer, please allow it to do so very important

    • After the computer restarts, temporarily disable your Anti-Virus and install the latest version of Malwarebytes' from Here or Here

    • Double Click mbam-setup.exe to install the application.

    • Make sure to UNCHECK Enable free trial of Malwarebytes Anti-Malware PRO, and Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware are both CHECKED, then click Finish.
      [​IMG]

    • If an update is found, it will download and install the latest version.

    • Open it, select the Update tab, and click the Check for Updates button:
      [​IMG]

    • If an update is available, it will prompt you. Install any updates it offers.

    • Please reboot if you are asked to.
    • Now select the Settings tab, and check the box next to Scan for rootkits:
      [​IMG]

    • Go back to the Dashboard tab, and click the Scan Now button:
      [​IMG]

    • The scan may take some time to finish,so please be patient.
      [​IMG]

    • When the scan is complete, it will show you the results. (This one is clean):
      [​IMG]

    • Make sure that everything is checked, and click Quarantine All (or similar).

    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note below) If the log doesn't open, select View detailed log in the Scan tab:
      [​IMG]

    • The log is automatically saved by MBAM and can be viewed by going to the History tab and clicking on Application Logs:
      [​IMG]

    • Choose the latest Scan Log, and click on the View button:
      [​IMG]

    • In the bottom of the Scanning History Log window that opens, you can click on Export > Save to Text file (*.txt). Save the report to your Desktop.
      [​IMG]

    • Copy & Paste the entire contents of the report log in your next reply.



    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

    *** In your next reply, I need you to Copy&Paste the contents of the MBAM log file.



    Third
    Reset your web browsers:

    Internet Explorer

    • Open Internet Explorer
    • Goto the Gear icon in the top right corner
    • Select Internet Options
    • Goto the Advanced tab
    • Select the Reset button
    • Enable "Delete personal Settings"
    • Click the Reset button
    • Restart Internet Explorer



    Firefox

    • Open Firefox
    • Goto the three stripes icon in the upper right corner, which looks like this: [​IMG]
    • In the bottom right of the menu that opens, click on the Blue question mark
    • Select Troubleshooting Information in the menu
    • Click the Reset Firefox button
    • Confirm Reset Firefox again at the prompt
    • Note: Old data from Firefox will be placed on your Windows Desktop in a folder called “Old Firefox data”. Delete this folder.



    Chrome

    • Open Chrome
    • Goto the Menu icon [​IMG]
    • Select Settings
    • Scroll down the page and look for + Show advanced settings
    • Scroll down to the end of the page and click the Reset browser settings button
    • Click Reset once more
    • Restart Chrome



    Finally
    In your next reply, please copy and paste the contents of the following logs:
    • AdwCleaner log
    • Malwarebytes Anti-Malware log

    You can post them individually following each reboot if you like.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1144328

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice