This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CleanerPro and PC Mechanic [Solved]

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi!

 

My 12 year old son tried to download a WoW client on his computer and has managed to download some malware with it.  Afterwards when he started his computer PC Mechanic would run automatically, and then a pop-up for CleanerPro would appear.  When he closed the CleanerPro window PC Mechanic popped up again briefly and then the screen turned black.  Nothing else happened.

 

I was able to use f8 to start the computer in safe mode and uninstall PC Mechanic (as if it were a regular program).  Still can't get rid of Cleaner Pro that way and discovered that he also has something called Vosteron installed, a browser hijacker.  At restart in normal mode Cleaner Pro automatically starts and once again we can't get past the starting pop up.

 

I've forbidden him from downloading anything from here on out, granted this is a bit like closing the gate after the horse got out.  But in the meantime, we would appreaciate any and all help.  Thanks in advance,

 

Tim and Isaac

 

 

 

Hi Svinlesha,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

Since booting in Normal Mode prompts the Cleaner Pro program to load, boot in Safe Mode w/ Networking and download the following tools and run the scans requested.

=========================

[external image: bullseye_zpse9eaf36e.gif] aswMBR

Download aswMBR.exe and save it to your desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

=========================

[external image: bullseye_zpse9eaf36e.gif] Download Farbar Recovery Scan Tool and save to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right click and select "Run as Administrator" to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply

=========================

In your next post please provide the following:

  • aswMBR.txt
  • attach MBR.zip
  • FRST.txt
  • Addition.txt

Hi OCD!

 

1) Thank you very much for taking out the time to help us!

 

2) I'm posting this now from my son's computer in safemode.  Note that we are in Sweden and that some of the items in the logs may be in Swedish.

 

Here is the text of the aswMBR log:

____

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-01-27 17:40:21
—————————–
17:40:21.866    OS Version: Windows x64 6.1.7601 Service Pack 1
17:40:21.866    Number of processors: 4 586 0x1E05
17:40:21.866    ComputerName: INET  UserName: Tim
17:40:22.710    Initialize success
17:40:24.471    AVAST engine defs: 15012700
17:41:03.448    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-8
17:41:03.449    Disk 0 Vendor: ST1000DM003-1CH162 CC47 Size: 953869MB BusType: 11
17:41:03.540    Disk 0 MBR read successfully
17:41:03.541    Disk 0 MBR scan
17:41:03.838    Disk 0 Windows 7 default MBR code
17:41:03.840    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       953867 MB offset 2048
17:41:03.843    Disk 0 Boot: NTFS     code=1
17:41:03.940    Disk 0 scanning C:\Windows\system32\drivers
17:41:10.964    Service scanning
17:41:22.917    Modules scanning
17:41:22.922    Disk 0 trace - called modules:
17:41:22.933    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
17:41:22.936    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800476a060]
17:41:22.939    3 CLASSPNP.SYS[fffff880018c143f] -> nt!IofCallDriver -> [0xfffffa80044cd090]
17:41:22.943    5 ACPI.sys[fffff88000f9f7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP4T0L0-8[0xfffffa8004491060]
17:41:23.591    AVAST engine scan C:\Windows
17:41:25.341    AVAST engine scan C:\Windows\system32
17:43:25.819    AVAST engine scan C:\Windows\system32\drivers
17:43:34.373    AVAST engine scan C:\Users\Tim
17:52:49.582    AVAST engine scan C:\ProgramData
17:53:38.882    File: C:\ProgramData\Surf annd ekeEp\B1zeEWuh.exe  **INFECTED** Win32:Malware-gen
17:53:38.956    File: C:\ProgramData\surff annd kkeep\ymcZgDCvy.exe  **INFECTED** Win32:Malware-gen
17:53:48.073    Disk 0 statistics 5057526/0/0 @ 4,36 MB/s
17:53:48.078    Scan finished successfully
18:00:54.597    Disk 0 MBR has been saved successfully to "C:\Users\Tim\Desktop\MBR.dat"
18:00:54.600    The log file has been saved successfully to "C:\Users\Tim\Desktop\aswMBR.txt"
________

 

Here is the text of the FRST log:

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01
Ran by [removed] (administrator) on INET on 27-01-2015 18:04:27
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Svenska (Sverige)
Internet Explorer Version 11 (Default browser: Vosteran)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-09] (AVAST Software)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\…\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Tim\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat"
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Run: [GoogleChromeAutoLaunch_77DB27ED30D96DC6FB2B344658AE2828] => C:\Users\Tim\AppData\Local\Vosteran\Application\vosteran.exe [1014272 2015-01-15] ()
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Tim\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat"
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_117_Plugin.exe [829832 2013-10-22] (Adobe Systems Incorporated)
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: E - E:\AutoRun.exe
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: {5480bd08-e76f-11e3-a348-00241dc449fa} - E:\AutoRun.exe
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: {5b757370-e676-11e3-ba8d-00241dc449fa} - E:\AutoRun.exe
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: {5b757384-e676-11e3-ba8d-00241dc449fa} - E:\AutoRun.exe
AppInit_DLLs-x32: C:/PROGRA~3/{C6092~1/190~1.1/rati.dll => C:/PROGRA~3/{C6092~1/190~1.1/rati.dll [966144 2015-01-24] ()
Startup: C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://vosteran.com/?f=1&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.inet.se
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.inet.se
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
SearchScopes: HKU\S-1-5-21-3767168050-546541148-904736753-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
SearchScopes: HKU\S-1-5-21-3767168050-546541148-904736753-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
BHO: No Name -> {73CF76E3-40B6-C299-001B-0B0C06AB79F5} ->  No File
BHO: No Name -> {764E787A-518C-E931-F013-BD3BA3F0F7A3} ->  No File
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: No Name -> {BAC79AB2-0EEE-C9A4-1577-7355E883D4F8} ->  No File
BHO-x32: ace race 1.0.0.6 -> {68182220-3c75-49d9-a9c4-4093d3986279} -> C:\Program Files (x86)\ace race\aceracebho.dll (ace race)
BHO-x32: No Name -> {73CF76E3-40B6-C299-001B-0B0C06AB79F5} ->  No File
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: No Name -> {764E787A-518C-E931-F013-BD3BA3F0F7A3} ->  No File
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: No Name -> {BAC79AB2-0EEE-C9A4-1577-7355E883D4F8} ->  No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default
FF DefaultSearchEngine: Vosteran
FF DefaultSearchUrl: https://se.search.yahoo.com/yhs/search
FF SearchEngineOrder.1: Yahoo! (Avast)
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Vosteran
FF Homepage: hxxp://vosteran.com/?f=1&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
FF Keyword.URL: https://se.search.yahoo.com/yhs/search
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Tim\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF user.js: detected! => C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\user.js
FF SearchPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\ask-search.xml
FF SearchPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\bingp.xml
FF SearchPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\Vosteran.xml
FF SearchPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\yahoo-avast.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\allaannonser-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\prisjakt-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\tyda-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-sv-SE.xml
FF Extension: ace race 1.0.1 - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\Extensions\{4a90d0b9-0668-4ad5-92c2-d78786884485}.xpi [2015-01-24]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-12-02]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-22]
StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome:
=======
CHR HomePage: Default -> hxxp://vosteran.com/?f=1&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
CHR StartupUrls: Default -> "hxxp://vosteran.com/?f=7&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=", "https://se.yahoo.com/?fr=hp-avast&type;=avastbcl"
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR Profile: C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Dokument) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-08]
CHR Extension: (Google Drive) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-08]
CHR Extension: (YouTube) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-08]
CHR Extension: (Battlefield Heroes) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2015-01-09]
CHR Extension: (Sök på Google) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-08]
CHR Extension: (ace race) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiknpkdjaijoilnmlcmkgcelkafbnpbl [2015-01-25]
CHR Extension: (Avast Online Security) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-08]
CHR Extension: (Google Wallet) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-08]
CHR Extension: (Vosteran New Tab) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce [2015-01-24]
CHR Extension: (Gmail) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-08]
CHR HKLM\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-04]
CHR HKLM-x32\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
StartMenuInternet: Google Chrome - chrome.exe

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-04] (AVAST Software)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-12-04] (Avast Software)
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [53832 2014-11-25] (Just Develop It) <==== ATTENTION
S2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
S2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-28] (Hi-Rez Studios) [File not signed]
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-01-09] ()
S2 Update ace race; C:\Program Files (x86)\ace race\updateacerace.exe [664816 2015-01-25] ()
S2 Util ace race; C:\Program Files (x86)\ace race\bin\utilacerace.exe [681200 2015-01-27] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-04] ()
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-04] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-04] ()
S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-04] (AVAST Software)
S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-04] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-04] (AVAST Software)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [243200 2009-10-21] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
S3 IAMTVE; C:\Windows\system32\drivers\IAMTVE.sys [43416 2010-11-30] (Intel Corporation)
S3 IAMTXPE; C:\Windows\system32\drivers\IAMTXPE.sys [51096 2010-11-30] (Intel Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [15416 2009-05-14] ()
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-12-04] (Avast Software)
R1 {4a90d0b9-0668-4ad5-92c2-d78786884485}Gw64; C:\Windows\System32\drivers\{4a90d0b9-0668-4ad5-92c2-d78786884485}Gw64.sys [48784 2015-01-24] (StdLib)
R1 {56db9de0-c769-4563-8e82-7e39885bf1ad}Gw64; C:\Windows\System32\drivers\{56db9de0-c769-4563-8e82-7e39885bf1ad}Gw64.sys [48784 2015-01-25] (StdLib)
S3 aswVmm; \??\C:\Users\Tim\AppData\Local\Temp\aswVmm.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va029; \??\C:\Windows\SysWOW64\Drivers\X6va029 [X]
U3 aswMBR; \??\C:\Users\Tim\AppData\Local\Temp\aswMBR.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-27 18:04 - 2015-01-27 18:04 - 00020598 _____ () C:\Users\Tim\Desktop\FRST.txt
2015-01-27 18:04 - 2015-01-27 18:04 - 00000000 ____D () C:\FRST
2015-01-27 18:02 - 2015-01-27 18:02 - 02129920 _____ (Farbar) C:\Users\Tim\Desktop\FRST64.exe
2015-01-27 18:01 - 2015-01-27 18:01 - 00000544 _____ () C:\Users\Tim\Desktop\MBR.zip
2015-01-27 18:00 - 2015-01-27 18:00 - 00002137 _____ () C:\Users\Tim\Desktop\aswMBR.txt
2015-01-27 18:00 - 2015-01-27 18:00 - 00000512 _____ () C:\Users\Tim\Desktop\MBR.dat
2015-01-27 17:37 - 2015-01-27 17:37 - 05198336 _____ (AVAST Software) C:\Users\Tim\Desktop\aswMBR.exe
2015-01-27 17:28 - 2015-01-27 17:28 - 00000197 _____ () C:\Windows\system32\2015-01-27-16-28-06.013-AvastVBoxSVC.exe-2452.log
2015-01-25 17:05 - 2015-01-25 17:05 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-05-46.072-AvastVBoxSVC.exe-2384.log
2015-01-25 17:00 - 2015-01-25 17:00 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-00-29.011-AvastVBoxSVC.exe-1428.log
2015-01-25 16:18 - 2015-01-25 16:18 - 00000197 _____ () C:\Windows\system32\2015-01-25-15-18-00.026-AvastVBoxSVC.exe-2732.log
2015-01-25 16:18 - 2015-01-25 05:46 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{56db9de0-c769-4563-8e82-7e39885bf1ad}Gw64.sys
2015-01-25 09:39 - 2015-01-25 09:39 - 00000197 _____ () C:\Windows\system32\2015-01-25-08-39-04.097-AvastVBoxSVC.exe-3736.log
2015-01-25 09:36 - 2015-01-25 09:36 - 00000254 __RSH () C:\ProgramData\ntuser.pol
2015-01-24 18:35 - 2015-01-25 17:35 - 00000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2015-01-24 17:57 - 2015-01-24 17:57 - 00001238 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2015-01-24 17:57 - 2015-01-24 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2015-01-24 17:55 - 2015-01-24 21:47 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2015-01-24 17:51 - 2015-01-24 17:51 - 02942368 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\World-of-Warcraft-Setup-enGB.exe
2015-01-24 17:45 - 2015-01-24 03:40 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{4a90d0b9-0668-4ad5-92c2-d78786884485}Gw64.sys
2015-01-24 17:38 - 2015-01-25 00:06 - 00000000 ____D () C:\Users\Tim\AppData\Local\Battle.net
2015-01-24 17:38 - 2015-01-24 17:55 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Battle.net
2015-01-24 17:38 - 2015-01-24 17:38 - 00000000 ____D () C:\Users\Tim\AppData\Local\Blizzard Entertainment
2015-01-24 17:37 - 2015-01-24 17:38 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates WW2
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates WW1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates W1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003532 _____ () C:\Windows\System32\Tasks\GoodGameEmpire W1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003532 _____ () C:\Windows\System32\Tasks\GoodGameEmpire NextW2
2015-01-24 17:36 - 2015-01-24 17:36 - 00003532 _____ () C:\Windows\System32\Tasks\GoodGameEmpire NextW1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003440 _____ () C:\Windows\System32\Tasks\WOT WWED1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003440 _____ () C:\Windows\System32\Tasks\WOT WW2
2015-01-24 17:36 - 2015-01-24 17:36 - 00003440 _____ () C:\Windows\System32\Tasks\WOT WW1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003440 _____ () C:\Windows\System32\Tasks\WOT WTUE1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003440 _____ () C:\Windows\System32\Tasks\WOT WTHUR1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003440 _____ () C:\Windows\System32\Tasks\WOT WFRI1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003440 _____ () C:\Windows\System32\Tasks\WOT W1
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Pirates946
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vosteran
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pirates
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\GGEmpire441
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\GGEmpire
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\ProgramData\Battle.net
2015-01-24 17:35 - 2015-01-27 17:28 - 00000000 ____D () C:\Program Files (x86)\ace race
2015-01-24 17:35 - 2015-01-25 17:35 - 00000284 _____ () C:\Windows\Tasks\WSE_Vosteran.job
2015-01-24 17:35 - 2015-01-25 17:06 - 00003438 _____ () C:\Windows\System32\Tasks\CleanerPro_Popup
2015-01-24 17:35 - 2015-01-25 17:06 - 00000000 ____D () C:\Users\Tim\Documents\CleanerPro
2015-01-24 17:35 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\Vosteran
2015-01-24 17:35 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\Pirates
2015-01-24 17:35 - 2015-01-24 17:35 - 123231216 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\WorldOfWarCraftSetup.exe
2015-01-24 17:35 - 2015-01-24 17:35 - 00004086 _____ () C:\Windows\System32\Tasks\Vosteran rati
2015-01-24 17:35 - 2015-01-24 17:35 - 00003212 _____ () C:\Windows\System32\Tasks\WSE_Vosteran
2015-01-24 17:35 - 2015-01-24 17:35 - 00003174 _____ () C:\Windows\System32\Tasks\CleanerPro_Start
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\WSE_Vosteran
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Users\Tim\AppData\Local\CleanerPro
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cleaner Pro
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\ProgramData\{C6092ECA-968B-FF4C-270D-8FCEF78F5C40}
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Program Files (x86)\WSE_Vosteran
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Program Files (x86)\Cleaner Pro
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall W1
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall TW2
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall TW1
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Cleaner Pro
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Local\StormFall
2015-01-24 17:33 - 2015-01-24 17:34 - 00819816 _____ (%VENDOR%) C:\Users\Tim\Downloads\WorldofWarCraft_Setup.exe
2015-01-24 13:47 - 2015-01-24 13:48 - 00000197 _____ () C:\Windows\system32\2015-01-24-12-47-40.045-AvastVBoxSVC.exe-3452.log
2015-01-24 08:41 - 2015-01-24 08:41 - 00000197 _____ () C:\Windows\system32\2015-01-24-07-41-44.020-AvastVBoxSVC.exe-4040.log
2015-01-23 21:40 - 2015-01-23 21:40 - 00000197 _____ () C:\Windows\system32\2015-01-23-20-40-03.016-AvastVBoxSVC.exe-4508.log
2015-01-23 16:57 - 2015-01-23 16:58 - 00000197 _____ () C:\Windows\system32\2015-01-23-15-57-47.063-AvastVBoxSVC.exe-3636.log
2015-01-23 07:35 - 2015-01-23 07:36 - 00000197 _____ () C:\Windows\system32\2015-01-23-06-35-43.037-AvastVBoxSVC.exe-3552.log
2015-01-22 15:05 - 2015-01-22 15:06 - 00000197 _____ () C:\Windows\system32\2015-01-22-14-05-49.099-AvastVBoxSVC.exe-3720.log
2015-01-22 07:32 - 2015-01-22 07:32 - 00000197 _____ () C:\Windows\system32\2015-01-22-06-32-43.034-AvastVBoxSVC.exe-3040.log
2015-01-21 19:31 - 2015-01-21 19:32 - 00000000 ____D () C:\Users\Tim\Downloads\Slender_v0_9_7 (1)
2015-01-21 19:31 - 2015-01-21 19:31 - 00000000 ____D () C:\Users\Tim\Desktop\Slender v0.9.7
2015-01-21 19:23 - 2015-01-21 19:30 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7 (1).zip
2015-01-21 19:13 - 2015-01-21 19:13 - 00004002 _____ () C:\Windows\System32\Tasks\LaunchSignup
2015-01-21 19:13 - 2015-01-21 19:13 - 00001971 _____ () C:\Users\Tim\Desktop\Sync Folder.lnk
2015-01-21 19:12 - 2015-01-22 07:29 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup
2015-01-21 19:12 - 2015-01-21 19:12 - 01060200 _____ (Uniblue Systems Limited ) C:\Users\Tim\Downloads\pcmechanicpm.exe
2015-01-21 19:12 - 2015-01-21 19:12 - 00003200 _____ () C:\Windows\System32\Tasks\PC-Mechanic Maintenance
2015-01-21 19:12 - 2015-01-21 19:12 - 00002488 _____ () C:\Windows\System32\Tasks\PC-Mechanic Startup
2015-01-21 19:12 - 2015-01-21 19:12 - 00001071 _____ () C:\Users\Tim\Desktop\MyPC Backup.lnk
2015-01-21 19:12 - 2015-01-21 19:12 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2015-01-21 19:08 - 2015-01-21 19:09 - 00000197 _____ () C:\Windows\system32\2015-01-21-18-08-51.048-AvastVBoxSVC.exe-3480.log
2015-01-21 19:01 - 2015-01-21 19:01 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7.zip
2015-01-21 14:27 - 2015-01-21 14:27 - 00000197 _____ () C:\Windows\system32\2015-01-21-13-27-01.087-AvastVBoxSVC.exe-2708.log
2015-01-21 06:17 - 2015-01-21 06:18 - 00000197 _____ () C:\Windows\system32\2015-01-21-05-17-40.013-AvastVBoxSVC.exe-3284.log
2015-01-21 05:32 - 2015-01-21 05:32 - 00000197 _____ () C:\Windows\system32\2015-01-21-04-32-11.025-AvastVBoxSVC.exe-2500.log
2015-01-20 15:42 - 2015-01-20 15:43 - 00000197 _____ () C:\Windows\system32\2015-01-20-14-42-54.082-AvastVBoxSVC.exe-3380.log
2015-01-20 07:21 - 2015-01-20 07:21 - 00000197 _____ () C:\Windows\system32\2015-01-20-06-21-05.091-AvastVBoxSVC.exe-3240.log
2015-01-19 13:43 - 2015-01-19 13:44 - 00000197 _____ () C:\Windows\system32\2015-01-19-12-43-55.039-AvastVBoxSVC.exe-3832.log
2015-01-19 07:27 - 2015-01-19 07:27 - 00000197 _____ () C:\Windows\system32\2015-01-19-06-27-12.003-AvastVBoxSVC.exe-3452.log
2015-01-18 09:31 - 2015-01-18 09:31 - 00000197 _____ () C:\Windows\system32\2015-01-18-08-31-40.030-AvastVBoxSVC.exe-3352.log
2015-01-17 09:13 - 2015-01-17 09:13 - 00000197 _____ () C:\Windows\system32\2015-01-17-08-13-20.071-AvastVBoxSVC.exe-3536.log
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieUserList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieSiteList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieBrowserModeList
2015-01-16 18:34 - 2015-01-16 18:34 - 00000222 _____ () C:\Users\Tim\Desktop\MicroVolts Surge.url
2015-01-16 17:58 - 2015-01-16 17:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-16-58-01.044-AvastVBoxSVC.exe-3048.log
2015-01-16 11:45 - 2015-01-16 11:45 - 00000197 _____ () C:\Windows\system32\2015-01-16-10-45-04.007-AvastVBoxSVC.exe-3160.log
2015-01-16 07:57 - 2015-01-16 07:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-06-57-44.044-AvastVBoxSVC.exe-3596.log
2015-01-15 15:19 - 2015-01-15 15:19 - 00000197 _____ () C:\Windows\system32\2015-01-15-14-19-09.002-AvastVBoxSVC.exe-2148.log
2015-01-15 06:46 - 2015-01-15 06:46 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-46-18.056-AvastVBoxSVC.exe-3440.log
2015-01-15 06:42 - 2015-01-15 06:42 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-42-40.094-AvastVBoxSVC.exe-2848.log
2015-01-14 16:29 - 2015-01-14 16:29 - 00000197 _____ () C:\Windows\system32\2015-01-14-15-29-36.005-AvastVBoxSVC.exe-3388.log
2015-01-14 14:43 - 2015-01-14 14:44 - 00000197 _____ () C:\Windows\system32\2015-01-14-13-43-43.031-AvastVBoxSVC.exe-2500.log
2015-01-14 07:51 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 07:51 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 07:51 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 07:51 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 07:51 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 07:51 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 07:51 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 07:51 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 07:48 - 2015-01-14 07:48 - 00000197 _____ () C:\Windows\system32\2015-01-14-06-48-14.075-AvastVBoxSVC.exe-1388.log
2015-01-13 14:37 - 2015-01-13 14:38 - 00000197 _____ () C:\Windows\system32\2015-01-13-13-37-39.065-AvastVBoxSVC.exe-3848.log
2015-01-13 07:54 - 2015-01-13 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-13-06-54-26.047-AvastVBoxSVC.exe-2908.log
2015-01-12 13:45 - 2015-01-12 13:45 - 00000197 _____ () C:\Windows\system32\2015-01-12-12-45-02.016-AvastVBoxSVC.exe-3228.log
2015-01-12 07:55 - 2015-01-12 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-12-06-55-17.056-AvastVBoxSVC.exe-2700.log
2015-01-11 10:10 - 2015-01-11 10:10 - 00000197 _____ () C:\Windows\system32\2015-01-11-09-10-12.019-AvastVBoxSVC.exe-2992.log
2015-01-10 17:56 - 2015-01-10 17:56 - 08229276 _____ () C:\Users\Tim\Downloads\1964_11.rar
2015-01-10 17:54 - 2015-01-10 17:54 - 00065552 _____ () C:\Users\Tim\Downloads\Zelda_1.zip
2015-01-10 17:53 - 2015-01-10 17:53 - 03029593 _____ () C:\Users\Tim\Downloads\fceux-2.2.2-win32.zip
2015-01-10 17:14 - 2015-01-10 17:14 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Unity
2015-01-10 15:36 - 2015-01-10 15:36 - 00000197 _____ () C:\Windows\system32\2015-01-10-14-36-08.039-AvastVBoxSVC.exe-3096.log
2015-01-10 09:54 - 2015-01-10 09:55 - 00000197 _____ () C:\Windows\system32\2015-01-10-08-54-54.090-AvastVBoxSVC.exe-2936.log
2015-01-09 21:01 - 2015-01-10 12:43 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-01-09 21:00 - 2015-01-09 21:00 - 00000000 ____D () C:\Users\Tim\AppData\Local\PunkBuster
2015-01-09 19:26 - 2015-01-09 21:38 - 00000000 ____D () C:\Users\Tim\Documents\Battlefield Heroes
2015-01-09 19:25 - 2015-01-10 12:43 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-01-09 19:25 - 2015-01-10 10:12 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-01-09 19:25 - 2015-01-09 21:07 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-01-09 19:25 - 2015-01-09 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games
2015-01-09 19:23 - 2015-01-09 19:23 - 00000000 ____D () C:\Program Files (x86)\EA Games
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Users\Tim\AppData\Local\Ubisoft Game Launcher
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2015-01-09 15:13 - 2015-01-09 15:13 - 00000197 _____ () C:\Windows\system32\2015-01-09-14-13-11.016-AvastVBoxSVC.exe-3340.log
2015-01-09 11:45 - 2015-01-09 11:46 - 00000197 _____ () C:\Windows\system32\2015-01-09-10-45-23.092-AvastVBoxSVC.exe-3372.log
2015-01-09 07:47 - 2015-01-09 07:47 - 00000197 _____ () C:\Windows\system32\2015-01-09-06-47-16.002-AvastVBoxSVC.exe-3136.log
2015-01-08 15:07 - 2015-01-08 15:08 - 00000197 _____ () C:\Windows\system32\2015-01-08-14-07-54.027-AvastVBoxSVC.exe-3892.log
2015-01-08 07:33 - 2015-01-08 07:33 - 00000197 _____ () C:\Windows\system32\2015-01-08-06-33-12.020-AvastVBoxSVC.exe-2848.log
2015-01-07 10:19 - 2015-01-07 10:20 - 00000197 _____ () C:\Windows\system32\2015-01-07-09-19-56.023-AvastVBoxSVC.exe-2908.log
2015-01-06 12:11 - 2015-01-06 12:12 - 00000197 _____ () C:\Windows\system32\2015-01-06-11-11-48.071-AvastVBoxSVC.exe-2448.log
2015-01-05 07:53 - 2015-01-05 07:53 - 00000197 _____ () C:\Windows\system32\2015-01-05-06-53-36.086-AvastVBoxSVC.exe-3104.log
2015-01-04 17:51 - 2015-01-04 17:51 - 00000197 _____ () C:\Windows\system32\2015-01-04-16-51-18.021-AvastVBoxSVC.exe-3220.log
2015-01-03 00:50 - 2015-01-03 00:50 - 00003262 _____ () C:\Windows\System32\Tasks\avastBCLRestartS-1-5-21-3767168050-546541148-904736753-1000
2015-01-02 18:00 - 2015-01-02 18:00 - 00000197 _____ () C:\Windows\system32\2015-01-02-17-00-10.085-AvastVBoxSVC.exe-1404.log
2015-01-02 14:06 - 2015-01-02 14:06 - 00000197 _____ () C:\Windows\system32\2015-01-02-13-06-19.086-AvastVBoxSVC.exe-2344.log
2015-01-02 13:58 - 2015-01-02 13:58 - 00086398 _____ () C:\Users\Tim\Downloads\[1-7-2]_Lucky_Block_v5-0-0.jar
2015-01-02 13:49 - 2015-01-02 13:49 - 00000000 ____D () C:\Users\Tim\AppData\Local\Mindspark_Interactive_Net
2015-01-02 13:48 - 2015-01-02 13:48 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Elite Unzip
2015-01-02 13:48 - 2015-01-02 13:48 - 00000000 ____D () C:\Program Files (x86)\EliteUnzip
2015-01-02 13:47 - 2015-01-02 13:48 - 04161288 _____ (Mindspark Interactive Network) C:\Users\Tim\Downloads\EliteUnzipSetup.EliteUnzip_aa.gafhhbahpojnjfhpepjjfjojbphnogmn.ch.exe
2015-01-02 12:02 - 2015-01-02 12:03 - 00000197 _____ () C:\Windows\system32\2015-01-02-11-02-31.002-AvastVBoxSVC.exe-2616.log
2015-01-01 14:53 - 2015-01-01 14:53 - 00000197 _____ () C:\Windows\system32\2015-01-01-13-53-14.082-AvastVBoxSVC.exe-3504.log
2014-12-31 16:21 - 2014-12-31 16:21 - 00000197 _____ () C:\Windows\system32\2014-12-31-15-21-48.034-AvastVBoxSVC.exe-708.log
2014-12-31 10:31 - 2014-12-31 10:32 - 00000197 _____ () C:\Windows\system32\2014-12-31-09-31-21.063-AvastVBoxSVC.exe-3084.log
2014-12-30 10:14 - 2014-12-30 10:15 - 00000197 _____ () C:\Windows\system32\2014-12-30-09-14-36.048-AvastVBoxSVC.exe-2212.log
2014-12-29 17:50 - 2014-12-29 17:50 - 00000197 _____ () C:\Windows\system32\2014-12-29-16-50-58.090-AvastVBoxSVC.exe-2600.log
2014-12-29 11:01 - 2014-12-29 11:01 - 00000197 _____ () C:\Windows\system32\2014-12-29-10-01-13.002-AvastVBoxSVC.exe-3084.log
2014-12-28 20:53 - 2014-12-28 20:54 - 00000000 ____D () C:\Users\Tim\Documents\Shadow Warrior
2014-12-28 20:14 - 2014-12-28 20:14 - 00000222 _____ () C:\Users\Tim\Desktop\Shadow Warrior.url
2014-12-28 17:22 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2014-12-28 17:22 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2014-12-28 17:22 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2014-12-28 17:22 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2014-12-28 17:22 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2014-12-28 17:22 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2014-12-28 17:22 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2014-12-28 17:22 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2014-12-28 17:22 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2014-12-28 17:22 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2014-12-28 17:21 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2014-12-28 17:21 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2014-12-28 17:21 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2014-12-28 17:21 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2014-12-28 17:21 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2014-12-28 17:21 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2014-12-28 17:21 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2014-12-28 17:21 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2014-12-28 17:21 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2014-12-28 17:21 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2014-12-28 17:21 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2014-12-28 17:21 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2014-12-28 17:21 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2014-12-28 17:21 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2014-12-28 17:21 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2014-12-28 17:21 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2014-12-28 17:21 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2014-12-28 17:21 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2014-12-28 17:21 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2014-12-28 17:21 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2014-12-28 17:21 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2014-12-28 17:21 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2014-12-28 17:21 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2014-12-28 17:21 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2014-12-28 17:21 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2014-12-28 17:21 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2014-12-28 17:21 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2014-12-28 17:21 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2014-12-28 17:21 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2014-12-28 17:21 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2014-12-28 17:21 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2014-12-28 17:09 - 2014-12-28 17:09 - 00000222 _____ () C:\Users\Tim\Desktop\Castle Crashers.url
2014-12-28 16:28 - 2014-12-28 16:28 - 00000197 _____ () C:\Windows\system32\2014-12-28-15-28-52.077-AvastVBoxSVC.exe-3820.log
2014-12-28 10:33 - 2014-12-28 10:33 - 00000197 _____ () C:\Windows\system32\2014-12-28-09-33-25.088-AvastVBoxSVC.exe-2900.log

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-27 17:33 - 2010-11-21 12:38 - 00670622 _____ () C:\Windows\system32\perfh01D.dat
2015-01-27 17:33 - 2010-11-21 12:38 - 00146498 _____ () C:\Windows\system32\perfc01D.dat
2015-01-27 17:33 - 2009-07-14 06:13 - 01602714 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-27 17:28 - 2009-07-14 03:34 - 00000505 _____ () C:\Windows\win.ini
2015-01-27 17:27 - 2014-08-08 10:43 - 00000990 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-27 17:27 - 2009-07-14 05:51 - 00165825 _____ () C:\Windows\setupact.log
2015-01-27 17:26 - 2013-09-30 14:53 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-01-27 17:26 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-25 17:38 - 2013-09-30 14:37 - 01792190 _____ () C:\Windows\WindowsUpdate.log
2015-01-25 17:11 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-25 17:11 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-25 16:41 - 2013-12-02 16:51 - 00000000 ____D () C:\ProgramData\Surf annd ekeEp
2015-01-25 16:40 - 2014-08-08 10:43 - 00000994 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-25 16:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
2015-01-25 09:34 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2015-01-25 09:27 - 2010-11-21 04:47 - 00101736 _____ () C:\Windows\PFRO.log
2015-01-24 17:35 - 2014-08-08 10:44 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-24 17:35 - 2013-10-22 09:18 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-24 17:17 - 2013-10-22 09:51 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\.minecraft
2015-01-24 15:45 - 2013-10-23 08:34 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-24 13:47 - 2013-11-13 07:41 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-01-20 19:01 - 2013-12-02 16:47 - 00000000 ____D () C:\ProgramData\YoutubeAdblocker
2015-01-16 19:34 - 2014-05-29 07:50 - 00000000 ____D () C:\Users\Tim\AppData\Local\Microsoft Games
2015-01-16 18:34 - 2013-10-23 09:01 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-01-14 08:28 - 2013-09-30 15:30 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 08:24 - 2013-09-30 15:30 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-09 18:07 - 2013-10-27 12:27 - 00267107 _____ () C:\Windows\DirectX.log
2015-01-09 17:53 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-06 04:36 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-05 18:16 - 2013-10-22 10:01 - 22764208 _____ () C:\Users\Tim\Desktop\TechnicLauncher.exe
2015-01-05 18:16 - 2013-10-22 10:01 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\.technic
2015-01-03 00:50 - 2013-10-22 09:18 - 00001137 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-02 17:41 - 2014-06-09 15:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Skype
2015-01-02 16:32 - 2014-06-09 15:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-02 16:32 - 2014-06-09 15:34 - 00000000 ____D () C:\ProgramData\Skype
2015-01-02 12:01 - 2009-07-14 06:08 - 00032514 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-30 23:55 - 2014-10-18 07:25 - 00000000 ____D () C:\Users\Tim\AppData\Local\CSO

==================== Files in the root of some directories =======

2015-01-24 18:35 - 2015-01-25 17:35 - 0000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2013-11-28 18:17 - 2013-11-28 18:17 - 0000091 _____ () C:\Users\Tim\AppData\Local\fusioncache.dat
2014-10-04 13:14 - 2014-10-04 13:14 - 0000000 _____ () C:\Users\Tim\AppData\Local\{26F9D811-A740-4CF8-B01D-202083068605}

Some content of TEMP:
====================
C:\Users\Tim\AppData\Local\Temp\APNSetup.exe
C:\Users\Tim\AppData\Local\Temp\CloudBackup3885.exe
C:\Users\Tim\AppData\Local\Temp\DataCard_Setup64.exe
C:\Users\Tim\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\Tim\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\MobileCM.exe
C:\Users\Tim\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Tim\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Tim\AppData\Local\Temp\nvStInst.exe
C:\Users\Tim\AppData\Local\Temp\pcspeedup.exe
C:\Users\Tim\AppData\Local\Temp\ResetDevice.exe
C:\Users\Tim\AppData\Local\Temp\SimBundD.exe
C:\Users\Tim\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Tim\AppData\Local\Temp\vcredist_x64.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-24 16:08

==================== End Of Log ============================

 

 

 

I've attached the MBR.dat zip and the Addition txt as per your instructions.  I was a bit uncertain if you wanted addition.txt as an attachment or not.  Please let me know if I got anything wrong!

 

:)

 

 

(PS: By the way, I didn't receive a message to download the lastest avast! virus definitions when I ran aswMBR.  Could be because we already have avast! installed.)

Hi Svinlesha,
 

Note that we are in Sweden and that some of the items in the logs may be in Swedish.


Thanks for that information. Should I need anything translated I will be sure to ask. :thumbup:

=========================

Please run this first script in Safe Mode (probably the only way you can boot at the moment). After completing this first step try and boot in Normal Mode, then continue on with the steps. If you still cannot boot in Normal Mode then go back to Safe Mode w/ Networking to complete the steps.

=========================

[external image: bullseye_zpse9eaf36e.gif] FRST Fix Script

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the desktop as fixlist.txt
 

Start
CloseProcesses:
Folder: C:\ProgramData\Surf annd ekeEp
Folder: C:\ProgramData\surff annd kkeep
HKLM-x32\…\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Tim\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat"
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Tim\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat"
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: E - E:\AutoRun.exe
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: {5480bd08-e76f-11e3-a348-00241dc449fa} - E:\AutoRun.exe
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: {5b757370-e676-11e3-ba8d-00241dc449fa} - E:\AutoRun.exe
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: {5b757384-e676-11e3-ba8d-00241dc449fa} - E:\AutoRun.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://vosteran.com/…r=668876811&ir=
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/…r=668876811&ir=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/…r=668876811&ir=
SearchScopes: HKU\S-1-5-21-3767168050-546541148-904736753-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/…r=668876811&ir=
SearchScopes: HKU\S-1-5-21-3767168050-546541148-904736753-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/…r=668876811&ir=
BHO: No Name -> {73CF76E3-40B6-C299-001B-0B0C06AB79F5} ->  No File
BHO: No Name -> {764E787A-518C-E931-F013-BD3BA3F0F7A3} ->  No File
BHO: No Name -> {BAC79AB2-0EEE-C9A4-1577-7355E883D4F8} ->  No File
BHO-x32: ace race 1.0.0.6 -> {68182220-3c75-49d9-a9c4-4093d3986279} -> C:\Program Files (x86)\ace race\aceracebho.dll (ace race)
BHO-x32: No Name -> {73CF76E3-40B6-C299-001B-0B0C06AB79F5} ->  No File
BHO-x32: No Name -> {764E787A-518C-E931-F013-BD3BA3F0F7A3} ->  No File
BHO-x32: No Name -> {BAC79AB2-0EEE-C9A4-1577-7355E883D4F8} ->  No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
FF DefaultSearchEngine: Vosteran
FF DefaultSearchUrl: https://se.search.yahoo.com/yhs/search
FF SelectedSearchEngine: Vosteran
FF Homepage: hxxp://vosteran.com/?f=1&a=vst_ggbg_15_04_ff&cd=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr=668876811&ir=
FF Keyword.URL: https://se.search.yahoo.com/yhs/search
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\ask-search.xml
FF SearchPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\Vosteran.xml
FF Extension: ace race 1.0.1 - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\Extensions\{4a90d0b9-0668-4ad5-92c2-d78786884485}.xpi [2015-01-24]
CHR HomePage: Default -> hxxp://vosteran.com/?f=1&a=vst_ggbg_15_04_ff&cd=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr=668876811&ir=
CHR StartupUrls: Default -> "hxxp://vosteran.com/?f=7&a=vst_ggbg_15_04_ff&cd=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr=668876811&ir=", "https://se.yahoo.com…&type=avastbcl"
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://vosteran.com/…r=668876811&ir=
CHR Extension: (ace race) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiknpkdjaijoilnmlcmkgcelkafbnpbl [2015-01-25]
CHR Extension: (Vosteran New Tab) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce [2015-01-24]
CHR HKLM\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKLM-x32\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
S2 BackupStack;C:\Program Files (x86)\MyPC Backup\BackupStack.exe [53832 2014-11-25] (Just Develop It) <==== ATTENTION
Startup: C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
S2 Update ace race; C:\Program Files (x86)\ace race\updateacerace.exe [664816 2015-01-25] ()
S2 Util ace race; C:\Program Files (x86)\ace race\bin\utilacerace.exe [681200 2015-01-27] ()
2015-01-24 17:35 - 2015-01-25 17:35 - 00000284 _____ () C:\Windows\Tasks\WSE_Vosteran.job
2015-01-24 17:35 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\Vosteran
2015-01-24 17:35 - 2015-01-27 17:28 - 00000000 ____D () C:\Program Files (x86)\ace race
2015-01-24 17:35 - 2015-01-25 17:35 - 00000284 _____ () C:\Windows\Tasks\WSE_Vosteran.job
2015-01-24 17:35 - 2015-01-25 17:06 - 00003438 _____ () C:\Windows\System32\Tasks\CleanerPro_Popup
2015-01-24 17:35 - 2015-01-25 17:06 - 00000000 ____D () C:\Users\Tim\Documents\CleanerPro
2015-01-24 17:35 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\Vosteran
2015-01-24 17:35 - 2015-01-24 17:35 - 00004086 _____ () C:\Windows\System32\Tasks\Vosteran rati
2015-01-24 17:35 - 2015-01-24 17:35 - 00003212 _____ () C:\Windows\System32\Tasks\WSE_Vosteran
2015-01-24 17:35 - 2015-01-24 17:35 - 00003174 _____ () C:\Windows\System32\Tasks\CleanerPro_Start
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\WSE_Vosteran
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Users\Tim\AppData\Local\CleanerPro
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cleaner Pro
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\ProgramData\{C6092ECA-968B-FF4C-270D-8FCEF78F5C40}
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Program Files (x86)\WSE_Vosteran
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Program Files (x86)\Cleaner Pro
2015-01-21 19:12 - 2015-01-22 07:29 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup
2015-01-21 19:12 - 2015-01-21 19:12 - 01060200 _____ (Uniblue Systems Limited ) C:\Users\Tim\Downloads\pcmechanicpm.exe
2015-01-21 19:12 - 2015-01-21 19:12 - 00003200 _____ () C:\Windows\System32\Tasks\PC-Mechanic Maintenance
2015-01-21 19:12 - 2015-01-21 19:12 - 00002488 _____ () C:\Windows\System32\Tasks\PC-Mechanic Startup
2015-01-21 19:12 - 2015-01-21 19:12 - 00001071 _____ () C:\Users\Tim\Desktop\MyPC Backup.lnk
2015-01-25 16:41 - 2013-12-02 16:51 - 00000000 ____D () C:\ProgramData\Surf annd ekeEp
C:\Users\Tim\AppData\Local\Temp\APNSetup.exe
C:\Users\Tim\AppData\Local\Temp\CloudBackup3885.exe
C:\Users\Tim\AppData\Local\Temp\DataCard_Setup64.exe
C:\Users\Tim\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\Tim\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\MobileCM.exe
C:\Users\Tim\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Tim\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Tim\AppData\Local\Temp\nvStInst.exe
C:\Users\Tim\AppData\Local\Temp\pcspeedup.exe
C:\Users\Tim\AppData\Local\Temp\ResetDevice.exe
C:\Users\Tim\AppData\Local\Temp\SimBundD.exe
C:\Users\Tim\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Tim\AppData\Local\Temp\vcredist_x64.exe
ace race (HKLM\…\ace race) (Version: 2015.01.24.132342 - ace race) <==== ATTENTION!
GoodGameEmpire (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\GoodGameEmpire) (Version:  - GoodGameEmpire) <==== ATTENTION!
MyPC Backup  (HKLM\…\MyPC Backup) (Version:  - JDi Backup Ltd) <==== ATTENTION
Pirates (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Pirates) (Version:  - Pirates) <==== ATTENTION!
Ryzom (HKLM-x32\…\Ryzom) (Version:  - Ryzom) <==== ATTENTION!
SK.Enhancer (HKLM-x32\…\S-161304646) (Version: 1.1.0.1444 - PremiumSoft) <==== ATTENTION
StormFall (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\StormFall) (Version:  - StormFall) <==== ATTENTION!
Surf annd ekeEp (HKLM-x32\…\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}) (Version: 3.0.0.1080 - suRf anDD keepo) <==== ATTENTION
World Of WarCraft Packages (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\World Of WarCraft Packages) (Version:  - ) <==== ATTENTION
WorldofTanks (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\WorldofTanks) (Version:  - WorldofTanks) <==== ATTENTION!
Vosteran (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Vosteran) (Version: 31.0.1650.23 - Vosteran) <==== ATTENTION!
WSE_Vosteran (HKLM-x32\…\WSE_Vosteran) (Version:  - WSE_Vosteran) <==== ATTENTION!
YoutubeAdblocker (HKLM-x32\…\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version: 1.1.0.1227 - YoutubeAdblocker) <==== ATTENTION
Task: {0054B32A-9A08-4880-B781-1A0144D02163} - System32\Tasks\WOT WTUE1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {1A8E4D96-B77B-42E2-9032-DE0842EBF59C} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files (x86)\PC Speed Up\PCSUSD.exe <==== ATTENTION
Task: {4F65FDC1-CE4B-4547-878D-1F940CC69919} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe [2014-11-25] (MyPC Backup) <==== ATTENTION
Task: {531EACD5-1D26-4083-89DA-AA81134C14ED} - System32\Tasks\Vosteran rati => C:\ProgramData\{C6092ECA-968B-FF4C-270D-8FCEF78F5C40}\1.9.0.1\f <==== ATTENTION
Task: {591EB1BA-19E3-4379-A9EB-107166A00CE0} - System32\Tasks\WOT WFRI1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {5F997847-8013-40F0-8FBF-BB2C27ED4C08} - System32\Tasks\GoodGameEmpire NextW2 => Chrome.exe –app=http://a2g-secure.com/?E=bwsPamg0MAiwFF%2bnM1a0Fg%3d%3d&s1= –app-window-size=1440,900 <==== ATTENTION
Task: {60738156-F346-4BC0-914E-804846C4D2D7} - System32\Tasks\GoodGameEmpire NextW1 => Chrome.exe –app=http://a2g-secure.com/?E=bwsPamg0MAiwFF%2bnM1a0Fg%3d%3d&s1= –app-window-size=1440,900 <==== ATTENTION
Task: {85A9F0D6-47C9-44E7-B76B-27612BCCB044} - System32\Tasks\WOT W1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {B14D944C-8ADA-47AA-A2AB-B35C6C5DF3E1} - System32\Tasks\WOT WW1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {C6DE6D19-4CF0-415F-889C-CF050AA36C29} - System32\Tasks\WSE_Vosteran => C:\Users\Tim\AppData\Roaming\WSE_Vosteran\UpdateProc\UpdateTask.exe [2015-01-24] () <==== ATTENTION
Task: {C8C2EBB5-1778-4517-86CB-2DA25C933965} - System32\Tasks\WOT WTHUR1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {E3FA7E52-4FB0-4BD9-AEBD-8C05F3BE2F8D} - System32\Tasks\WOT WW2 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {EB4DFD11-4059-4241-A212-EE714CD8AFEC} - System32\Tasks\WOT WWED1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {F136AE5F-C6BF-4882-AC89-3B662C25EAF9} - System32\Tasks\GoodGameEmpire W1 => Chrome.exe –app=http://a2g-secure.com/?E=bwsPamg0MAiwFF%2bnM1a0Fg%3d%3d&s1= –app-window-size=1440,900 <==== ATTENTION
Task: C:\Windows\Tasks\WSE_Vosteran.job => C:\Users\Tim\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
EmptyTemp:
Hosts:
CMD: ipconfig /flushdns
End

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST and press the Fix button just once and wait.
The tool will make a log (Fixlog.txt) please post it to your reply.

=========================

[external image: bullseye_zpse9eaf36e.gif] Reboot in Normal Mode (if possible)

=========================

[external image: bullseye_zpse9eaf36e.gif] AdwCleaner v3: Scan & Clean

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished…
  • Click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a log file report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that log file in your next reply.
  • A copy of that log file will also be saved in the C:\AdwCleaner folder.

=========================

[external image: bullseye_zpse9eaf36e.gif] Junkware Removal Tool

Download Junkware Removal Tool to your desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Shut down your protection software now to avoid potential conflicts.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

=========================

[external image: bullseye_zpse9eaf36e.gif] Reboot

=========================

[external image: bullseye_zpse9eaf36e.gif] Re-run Farbar Recovery Scan Tool it should be on your desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the tool opens click Yes to disclaimer.
  • Select the Addition box
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • It will also make (Addition.txt). Please attach it to your reply

=========================

In your next post please provide the following:

  • Fixlog.txt
  • AdwCleaner[S0].txt
  • JRT.txt
  • new FRST.txt
  • new Addition.txt

Hiya OCD!

 

Here are the logs per your request:

 

FIXLOG.TXT:

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-01-2015 01
Ran by [removed] at 2015-01-28 11:58:36 Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Safe Mode (with Networking)
==============================================
 
Content of fixlist:
*****************
Start
CloseProcesses:
Folder: C:\ProgramData\Surf annd ekeEp
Folder: C:\ProgramData\surff annd kkeep
HKLM-x32\…\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Tim\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat"
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\Tim\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat"
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: E - E:\AutoRun.exe
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: {5480bd08-e76f-11e3-a348-00241dc449fa} - E:\AutoRun.exe
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: {5b757370-e676-11e3-ba8d-00241dc449fa} - E:\AutoRun.exe
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\MountPoints2: {5b757384-e676-11e3-ba8d-00241dc449fa} - E:\AutoRun.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://vosteran.com/…r=668876811&ir;=
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/…r=668876811&ir;=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/…r=668876811&ir;=
SearchScopes: HKU\S-1-5-21-3767168050-546541148-904736753-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/…r=668876811&ir;=
SearchScopes: HKU\S-1-5-21-3767168050-546541148-904736753-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/…r=668876811&ir;=
BHO: No Name -> {73CF76E3-40B6-C299-001B-0B0C06AB79F5} ->  No File
BHO: No Name -> {764E787A-518C-E931-F013-BD3BA3F0F7A3} ->  No File
BHO: No Name -> {BAC79AB2-0EEE-C9A4-1577-7355E883D4F8} ->  No File
BHO-x32: ace race 1.0.0.6 -> {68182220-3c75-49d9-a9c4-4093d3986279} -> C:\Program Files (x86)\ace race\aceracebho.dll (ace race)
BHO-x32: No Name -> {73CF76E3-40B6-C299-001B-0B0C06AB79F5} ->  No File
BHO-x32: No Name -> {764E787A-518C-E931-F013-BD3BA3F0F7A3} ->  No File
BHO-x32: No Name -> {BAC79AB2-0EEE-C9A4-1577-7355E883D4F8} ->  No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
FF DefaultSearchEngine: Vosteran
FF DefaultSearchUrl: https://se.search.yahoo.com/yhs/search
FF SelectedSearchEngine: Vosteran
FF Homepage: hxxp://vosteran.com/?f=1&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
FF Keyword.URL: https://se.search.yahoo.com/yhs/search
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\ask-search.xml
FF SearchPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\Vosteran.xml
FF Extension: ace race 1.0.1 - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\Extensions\{4a90d0b9-0668-4ad5-92c2-d78786884485}.xpi [2015-01-24]
CHR HomePage: Default -> hxxp://vosteran.com/?f=1&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
CHR StartupUrls: Default -> "hxxp://vosteran.com/?f=7&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=", "https://se.yahoo.com…&type;=avastbcl"
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://vosteran.com/…r=668876811&ir;=
CHR Extension: (ace race) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiknpkdjaijoilnmlcmkgcelkafbnpbl [2015-01-25]
CHR Extension: (Vosteran New Tab) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce [2015-01-24]
CHR HKLM\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKLM-x32\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
S2 BackupStack;C:\Program Files (x86)\MyPC Backup\BackupStack.exe [53832 2014-11-25] (Just Develop It) <==== ATTENTION
Startup: C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
S2 Update ace race; C:\Program Files (x86)\ace race\updateacerace.exe [664816 2015-01-25] ()
S2 Util ace race; C:\Program Files (x86)\ace race\bin\utilacerace.exe [681200 2015-01-27] ()
2015-01-24 17:35 - 2015-01-25 17:35 - 00000284 _____ () C:\Windows\Tasks\WSE_Vosteran.job
2015-01-24 17:35 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\Vosteran
2015-01-24 17:35 - 2015-01-27 17:28 - 00000000 ____D () C:\Program Files (x86)\ace race
2015-01-24 17:35 - 2015-01-25 17:35 - 00000284 _____ () C:\Windows\Tasks\WSE_Vosteran.job
2015-01-24 17:35 - 2015-01-25 17:06 - 00003438 _____ () C:\Windows\System32\Tasks\CleanerPro_Popup
2015-01-24 17:35 - 2015-01-25 17:06 - 00000000 ____D () C:\Users\Tim\Documents\CleanerPro
2015-01-24 17:35 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\Vosteran
2015-01-24 17:35 - 2015-01-24 17:35 - 00004086 _____ () C:\Windows\System32\Tasks\Vosteran rati
2015-01-24 17:35 - 2015-01-24 17:35 - 00003212 _____ () C:\Windows\System32\Tasks\WSE_Vosteran
2015-01-24 17:35 - 2015-01-24 17:35 - 00003174 _____ () C:\Windows\System32\Tasks\CleanerPro_Start
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\WSE_Vosteran
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Users\Tim\AppData\Local\CleanerPro
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cleaner Pro
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\ProgramData\{C6092ECA-968B-FF4C-270D-8FCEF78F5C40}
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Program Files (x86)\WSE_Vosteran
2015-01-24 17:35 - 2015-01-24 17:35 - 00000000 ____D () C:\Program Files (x86)\Cleaner Pro
2015-01-21 19:12 - 2015-01-22 07:29 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup
2015-01-21 19:12 - 2015-01-21 19:12 - 01060200 _____ (Uniblue Systems Limited ) C:\Users\Tim\Downloads\pcmechanicpm.exe
2015-01-21 19:12 - 2015-01-21 19:12 - 00003200 _____ () C:\Windows\System32\Tasks\PC-Mechanic Maintenance
2015-01-21 19:12 - 2015-01-21 19:12 - 00002488 _____ () C:\Windows\System32\Tasks\PC-Mechanic Startup
2015-01-21 19:12 - 2015-01-21 19:12 - 00001071 _____ () C:\Users\Tim\Desktop\MyPC Backup.lnk
2015-01-25 16:41 - 2013-12-02 16:51 - 00000000 ____D () C:\ProgramData\Surf annd ekeEp
C:\Users\Tim\AppData\Local\Temp\APNSetup.exe
C:\Users\Tim\AppData\Local\Temp\CloudBackup3885.exe
C:\Users\Tim\AppData\Local\Temp\DataCard_Setup64.exe
C:\Users\Tim\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\Tim\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Tim\AppData\Local\Temp\MobileCM.exe
C:\Users\Tim\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Tim\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Tim\AppData\Local\Temp\nvStInst.exe
C:\Users\Tim\AppData\Local\Temp\pcspeedup.exe
C:\Users\Tim\AppData\Local\Temp\ResetDevice.exe
C:\Users\Tim\AppData\Local\Temp\SimBundD.exe
C:\Users\Tim\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Tim\AppData\Local\Temp\vcredist_x64.exe
ace race (HKLM\…\ace race) (Version: 2015.01.24.132342 - ace race) <==== ATTENTION!
GoodGameEmpire (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\GoodGameEmpire) (Version:  - GoodGameEmpire) <==== ATTENTION!
MyPC Backup  (HKLM\…\MyPC Backup) (Version:  - JDi Backup Ltd) <==== ATTENTION
Pirates (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Pirates) (Version:  - Pirates) <==== ATTENTION!
Ryzom (HKLM-x32\…\Ryzom) (Version:  - Ryzom) <==== ATTENTION!
SK.Enhancer (HKLM-x32\…\S-161304646) (Version: 1.1.0.1444 - PremiumSoft) <==== ATTENTION
StormFall (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\StormFall) (Version:  - StormFall) <==== ATTENTION!
Surf annd ekeEp (HKLM-x32\…\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}) (Version: 3.0.0.1080 - suRf anDD keepo) <==== ATTENTION
World Of WarCraft Packages (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\World Of WarCraft Packages) (Version:  - ) <==== ATTENTION
WorldofTanks (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\WorldofTanks) (Version:  - WorldofTanks) <==== ATTENTION!
Vosteran (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Vosteran) (Version: 31.0.1650.23 - Vosteran) <==== ATTENTION!
WSE_Vosteran (HKLM-x32\…\WSE_Vosteran) (Version:  - WSE_Vosteran) <==== ATTENTION!
YoutubeAdblocker (HKLM-x32\…\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version: 1.1.0.1227 - YoutubeAdblocker) <==== ATTENTION
Task: {0054B32A-9A08-4880-B781-1A0144D02163} - System32\Tasks\WOT WTUE1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {1A8E4D96-B77B-42E2-9032-DE0842EBF59C} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files (x86)\PC Speed Up\PCSUSD.exe <==== ATTENTION
Task: {4F65FDC1-CE4B-4547-878D-1F940CC69919} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe [2014-11-25] (MyPC Backup) <==== ATTENTION
Task: {531EACD5-1D26-4083-89DA-AA81134C14ED} - System32\Tasks\Vosteran rati => C:\ProgramData\{C6092ECA-968B-FF4C-270D-8FCEF78F5C40}\1.9.0.1\f <==== ATTENTION
Task: {591EB1BA-19E3-4379-A9EB-107166A00CE0} - System32\Tasks\WOT WFRI1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {5F997847-8013-40F0-8FBF-BB2C27ED4C08} - System32\Tasks\GoodGameEmpire NextW2 => Chrome.exe –app=http://a2g-secure.com/?E=bwsPamg0MAiwFF%2bnM1a0Fg%3d%3d&s1;= –app-window-size=1440,900 <==== ATTENTION
Task: {60738156-F346-4BC0-914E-804846C4D2D7} - System32\Tasks\GoodGameEmpire NextW1 => Chrome.exe –app=http://a2g-secure.com/?E=bwsPamg0MAiwFF%2bnM1a0Fg%3d%3d&s1;= –app-window-size=1440,900 <==== ATTENTION
Task: {85A9F0D6-47C9-44E7-B76B-27612BCCB044} - System32\Tasks\WOT W1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {B14D944C-8ADA-47AA-A2AB-B35C6C5DF3E1} - System32\Tasks\WOT WW1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {C6DE6D19-4CF0-415F-889C-CF050AA36C29} - System32\Tasks\WSE_Vosteran => C:\Users\Tim\AppData\Roaming\WSE_Vosteran\UpdateProc\UpdateTask.exe [2015-01-24] () <==== ATTENTION
Task: {C8C2EBB5-1778-4517-86CB-2DA25C933965} - System32\Tasks\WOT WTHUR1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {E3FA7E52-4FB0-4BD9-AEBD-8C05F3BE2F8D} - System32\Tasks\WOT WW2 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {EB4DFD11-4059-4241-A212-EE714CD8AFEC} - System32\Tasks\WOT WWED1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ <==== ATTENTION
Task: {F136AE5F-C6BF-4882-AC89-3B662C25EAF9} - System32\Tasks\GoodGameEmpire W1 => Chrome.exe –app=http://a2g-secure.com/?E=bwsPamg0MAiwFF%2bnM1a0Fg%3d%3d&s1;= –app-window-size=1440,900 <==== ATTENTION
Task: C:\Windows\Tasks\WSE_Vosteran.job => C:\Users\Tim\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
EmptyTemp:
Hosts:
CMD: ipconfig /flushdns
End
*****************
 
Processes closed successfully.
 
========================= Folder: C:\ProgramData\Surf annd ekeEp ========================
 
2013-12-02 16:51 - 2013-12-02 16:51 - 0003950 _____ () C:\ProgramData\Surf annd ekeEp\B1zeEWuh.dat
2013-12-02 16:51 - 2013-12-02 16:51 - 0494080 _____ (Setup) C:\ProgramData\Surf annd ekeEp\B1zeEWuh.exe
 
====== End of Folder: ======
 
 
========================= Folder: C:\ProgramData\surff annd kkeep ========================
 
2013-12-02 16:47 - 2013-12-02 16:47 - 0003418 _____ () C:\ProgramData\surff annd kkeep\ymcZgDCvy.dat
2012-12-02 16:47 - 2012-12-02 16:47 - 0494080 _____ (Setup) C:\ProgramData\surff annd kkeep\ymcZgDCvy.exe
 
====== End of Folder: ======
 
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\WSE_Vosteran => value deleted successfully.
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\WSE_Vosteran => value deleted successfully.
"HKU\S-1-5-21-3767168050-546541148-904736753-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E" => Key deleted successfully.
"HKU\S-1-5-21-3767168050-546541148-904736753-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5480bd08-e76f-11e3-a348-00241dc449fa}" => Key deleted successfully.
HKCR\CLSID\{5480bd08-e76f-11e3-a348-00241dc449fa} => Key not found. 
"HKU\S-1-5-21-3767168050-546541148-904736753-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b757370-e676-11e3-ba8d-00241dc449fa}" => Key deleted successfully.
HKCR\CLSID\{5b757370-e676-11e3-ba8d-00241dc449fa} => Key not found. 
"HKU\S-1-5-21-3767168050-546541148-904736753-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b757384-e676-11e3-ba8d-00241dc449fa}" => Key deleted successfully.
HKCR\CLSID\{5b757384-e676-11e3-ba8d-00241dc449fa} => Key not found. 
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. 
HKU\S-1-5-21-3767168050-546541148-904736753-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-3767168050-546541148-904736753-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73CF76E3-40B6-C299-001B-0B0C06AB79F5}" => Key deleted successfully.
HKCR\CLSID\{73CF76E3-40B6-C299-001B-0B0C06AB79F5} => Key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{764E787A-518C-E931-F013-BD3BA3F0F7A3}" => Key deleted successfully.
HKCR\CLSID\{764E787A-518C-E931-F013-BD3BA3F0F7A3} => Key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAC79AB2-0EEE-C9A4-1577-7355E883D4F8}" => Key deleted successfully.
HKCR\CLSID\{BAC79AB2-0EEE-C9A4-1577-7355E883D4F8} => Key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68182220-3c75-49d9-a9c4-4093d3986279}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{68182220-3c75-49d9-a9c4-4093d3986279}" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73CF76E3-40B6-C299-001B-0B0C06AB79F5}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{73CF76E3-40B6-C299-001B-0B0C06AB79F5} => Key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{764E787A-518C-E931-F013-BD3BA3F0F7A3}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{764E787A-518C-E931-F013-BD3BA3F0F7A3} => Key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAC79AB2-0EEE-C9A4-1577-7355E883D4F8}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{BAC79AB2-0EEE-C9A4-1577-7355E883D4F8} => Key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully.
HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully.
HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Key not found. 
Firefox DefaultSearchEngine deleted successfully.
Firefox DefaultSearchUrl deleted successfully.
Firefox SelectedSearchEngine deleted successfully.
Firefox homepage deleted successfully.
Firefox Keyword.URL deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin" => Key deleted successfully.
C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll => Moved successfully.
"HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin" => Key deleted successfully.
C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll not found.
C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\ask-search.xml => Moved successfully.
C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\Vosteran.xml => Moved successfully.
C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\Extensions\{4a90d0b9-0668-4ad5-92c2-d78786884485}.xpi => Moved successfully.
Chrome HomePage deleted successfully.
Chrome StartupUrls deleted successfully.
Chrome DefaultSearchKeyword deleted successfully.
Chrome DefaultSearchURL deleted successfully.
C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiknpkdjaijoilnmlcmkgcelkafbnpbl => Moved successfully.
C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce => Moved successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce" => Key deleted successfully.
"HKU\S-1-5-21-3767168050-546541148-904736753-1000\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce" => Key deleted successfully.
BackupStack => Service deleted successfully.
C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk => Moved successfully.
C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe => Moved successfully.
Update ace race => Service deleted successfully.
Util ace race => Service deleted successfully.
C:\Windows\Tasks\WSE_Vosteran.job => Moved successfully.
C:\Users\Tim\AppData\Local\Vosteran => Moved successfully.
C:\Program Files (x86)\ace race => Moved successfully.
"C:\Windows\Tasks\WSE_Vosteran.job" => File/Directory not found.
C:\Windows\System32\Tasks\CleanerPro_Popup => Moved successfully.
C:\Users\Tim\Documents\CleanerPro => Moved successfully.
"C:\Users\Tim\AppData\Local\Vosteran" => File/Directory not found.
C:\Windows\System32\Tasks\Vosteran rati => Moved successfully.
C:\Windows\System32\Tasks\WSE_Vosteran => Moved successfully.
C:\Windows\System32\Tasks\CleanerPro_Start => Moved successfully.
C:\Users\Tim\AppData\Roaming\WSE_Vosteran => Moved successfully.
C:\Users\Tim\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z => Moved successfully.
C:\Users\Tim\AppData\Local\CleanerPro => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cleaner Pro => Moved successfully.
C:\ProgramData\{C6092ECA-968B-FF4C-270D-8FCEF78F5C40} => Moved successfully.
C:\Program Files (x86)\WSE_Vosteran => Moved successfully.
C:\Program Files (x86)\Cleaner Pro => Moved successfully.
C:\Program Files (x86)\MyPC Backup => Moved successfully.
C:\Users\Tim\Downloads\pcmechanicpm.exe => Moved successfully.
C:\Windows\System32\Tasks\PC-Mechanic Maintenance => Moved successfully.
C:\Windows\System32\Tasks\PC-Mechanic Startup => Moved successfully.
C:\Users\Tim\Desktop\MyPC Backup.lnk => Moved successfully.
C:\ProgramData\Surf annd ekeEp => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\APNSetup.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\CloudBackup3885.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\DataCard_Setup64.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\fp_pl_pfs_installer-1.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\fp_pl_pfs_installer.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\MobileCM.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\nvSCPAPI.dll => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\nvSCPAPI64.dll => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\nvStInst.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\pcspeedup.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\ResetDevice.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\SimBundD.exe => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\swt-win32-3349.dll => Moved successfully.
C:\Users\Tim\AppData\Local\Temp\vcredist_x64.exe => Moved successfully.
ace race (HKLM\…\ace race) (Version: 2015.01.24.132342 - ace race) <==== ATTENTION! => Error: No automatic fix found for this entry.
GoodGameEmpire (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\GoodGameEmpire) (Version:  - GoodGameEmpire) <==== ATTENTION! => Error: No automatic fix found for this entry.
MyPC Backup  (HKLM\…\MyPC Backup) (Version:  - JDi Backup Ltd) <==== ATTENTION => Error: No automatic fix found for this entry.
Pirates (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Pirates) (Version:  - Pirates) <==== ATTENTION! => Error: No automatic fix found for this entry.
Ryzom (HKLM-x32\…\Ryzom) (Version:  - Ryzom) <==== ATTENTION! => Error: No automatic fix found for this entry.
SK.Enhancer (HKLM-x32\…\S-161304646) (Version: 1.1.0.1444 - PremiumSoft) <==== ATTENTION => Error: No automatic fix found for this entry.
StormFall (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\StormFall) (Version:  - StormFall) <==== ATTENTION! => Error: No automatic fix found for this entry.
Surf annd ekeEp (HKLM-x32\…\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}) (Version: 3.0.0.1080 - suRf anDD keepo) <==== ATTENTION => Error: No automatic fix found for this entry.
World Of WarCraft Packages (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\World Of WarCraft Packages) (Version:  - ) <==== ATTENTION => Error: No automatic fix found for this entry.
WorldofTanks (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\WorldofTanks) (Version:  - WorldofTanks) <==== ATTENTION! => Error: No automatic fix found for this entry.
Vosteran (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Vosteran) (Version: 31.0.1650.23 - Vosteran) <==== ATTENTION! => Error: No automatic fix found for this entry.
WSE_Vosteran (HKLM-x32\…\WSE_Vosteran) (Version:  - WSE_Vosteran) <==== ATTENTION! => Error: No automatic fix found for this entry.
YoutubeAdblocker (HKLM-x32\…\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version: 1.1.0.1227 - YoutubeAdblocker) <==== ATTENTION => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0054B32A-9A08-4880-B781-1A0144D02163}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0054B32A-9A08-4880-B781-1A0144D02163}" => Key deleted successfully.
C:\Windows\System32\Tasks\WOT WTUE1 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WTUE1" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1A8E4D96-B77B-42E2-9032-DE0842EBF59C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A8E4D96-B77B-42E2-9032-DE0842EBF59C}" => Key deleted successfully.
C:\Windows\System32\Tasks\PC SpeedUp Service Deactivator => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC SpeedUp Service Deactivator" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4F65FDC1-CE4B-4547-878D-1F940CC69919}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F65FDC1-CE4B-4547-878D-1F940CC69919}" => Key deleted successfully.
C:\Windows\System32\Tasks\LaunchSignup => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchSignup" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{531EACD5-1D26-4083-89DA-AA81134C14ED}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{531EACD5-1D26-4083-89DA-AA81134C14ED}" => Key deleted successfully.
C:\Windows\System32\Tasks\Vosteran rati not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Vosteran rati" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{591EB1BA-19E3-4379-A9EB-107166A00CE0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{591EB1BA-19E3-4379-A9EB-107166A00CE0}" => Key deleted successfully.
C:\Windows\System32\Tasks\WOT WFRI1 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WFRI1" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5F997847-8013-40F0-8FBF-BB2C27ED4C08}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F997847-8013-40F0-8FBF-BB2C27ED4C08}" => Key deleted successfully.
C:\Windows\System32\Tasks\GoodGameEmpire NextW2 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoodGameEmpire NextW2" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{60738156-F346-4BC0-914E-804846C4D2D7}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{60738156-F346-4BC0-914E-804846C4D2D7}" => Key deleted successfully.
C:\Windows\System32\Tasks\GoodGameEmpire NextW1 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoodGameEmpire NextW1" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{85A9F0D6-47C9-44E7-B76B-27612BCCB044}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85A9F0D6-47C9-44E7-B76B-27612BCCB044}" => Key deleted successfully.
C:\Windows\System32\Tasks\WOT W1 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT W1" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B14D944C-8ADA-47AA-A2AB-B35C6C5DF3E1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B14D944C-8ADA-47AA-A2AB-B35C6C5DF3E1}" => Key deleted successfully.
C:\Windows\System32\Tasks\WOT WW1 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WW1" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C6DE6D19-4CF0-415F-889C-CF050AA36C29}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6DE6D19-4CF0-415F-889C-CF050AA36C29}" => Key deleted successfully.
C:\Windows\System32\Tasks\WSE_Vosteran not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WSE_Vosteran" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C8C2EBB5-1778-4517-86CB-2DA25C933965}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8C2EBB5-1778-4517-86CB-2DA25C933965}" => Key deleted successfully.
C:\Windows\System32\Tasks\WOT WTHUR1 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WTHUR1" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E3FA7E52-4FB0-4BD9-AEBD-8C05F3BE2F8D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3FA7E52-4FB0-4BD9-AEBD-8C05F3BE2F8D}" => Key deleted successfully.
C:\Windows\System32\Tasks\WOT WW2 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WW2" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB4DFD11-4059-4241-A212-EE714CD8AFEC}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB4DFD11-4059-4241-A212-EE714CD8AFEC}" => Key deleted successfully.
C:\Windows\System32\Tasks\WOT WWED1 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WWED1" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F136AE5F-C6BF-4882-AC89-3B662C25EAF9}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F136AE5F-C6BF-4882-AC89-3B662C25EAF9}" => Key deleted successfully.
C:\Windows\System32\Tasks\GoodGameEmpire W1 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoodGameEmpire W1" => Key deleted successfully.
C:\Windows\Tasks\WSE_Vosteran.job not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
 
=========  ipconfig /flushdns =========
 
 
IP-konfiguration f�r Windows
 
DNS-matcharens cacheminne har rensats.
 
========= End of CMD: =========
 
EmptyTemp: => Removed 4.4 GB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 11:59:44 ====
 
 
  • AdwCleaner[S0].txt:

# AdwCleaner v4.109 - Report created 28/01/2015 at 12:21:34

# Updated 24/01/2015 by Xplode
# Database : 2015-01-26.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Tim - INET
# Running from : C:\Users\Tim\Desktop\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
Service Deleted : {4a90d0b9-0668-4ad5-92c2-d78786884485}Gw64
Service Deleted : {56db9de0-c769-4563-8e82-7e39885bf1ad}Gw64
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\QuickSet
Folder Deleted : C:\ProgramData\surff annd kkeep
Folder Deleted : C:\ProgramData\YoutubeAdblocker
Folder Deleted : C:\ProgramData\d96b0b4e1ec89f20
Folder Deleted : C:\Program Files (x86)\EliteUnzip
Folder Deleted : C:\Program Files (x86)\surff annd kkeep
Folder Deleted : C:\Program Files (x86)\YoutubeAdblocker
Folder Deleted : C:\Program Files (x86)\Surf annd ekeEp
Folder Deleted : C:\Users\Tim\AppData\Local\Vosteran
Folder Deleted : C:\Users\Tim\AppData\Local\Mindspark_Interactive_Net
Folder Deleted : C:\Users\Tim\AppData\Roaming\WebExtend
Folder Deleted : C:\Users\Tim\AppData\Roaming\Cleaner Pro
Folder Deleted : C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Deleted : C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Elite Unzip
Folder Deleted : C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vosteran
File Deleted : C:\Windows\System32\drivers\{4a90d0b9-0668-4ad5-92c2-d78786884485}Gw64.sys
File Deleted : C:\Windows\System32\drivers\{56db9de0-c769-4563-8e82-7e39885bf1ad}Gw64.sys
File Deleted : C:\Users\Tim\Desktop\Sync Folder.lnk
File Deleted : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\bingp.xml
File Deleted : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\user.js
File Deleted : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
File Deleted : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_eliteunzip.dl.tb.ask.com_0.localstorage
 
***** [ Scheduled Tasks ] *****
 
Task Deleted : WOT WMON1
Task Deleted : WOT W2
Task Deleted : WOT T
Task Deleted : WOT N
Task Deleted : PC-Mechanic Startup
Task Deleted : PC-Mechanic Maintenance
Task Deleted : GoodGameEmpire W2
 
***** [ Shortcuts ] *****
 
Shortcut Disinfected : C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks\WorldofTanks.lnk
Shortcut Disinfected : C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire\GoodGameEmpire.lnk
Shortcut Disinfected : C:\Users\Tim\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GoodGameEmpire.lnk
Shortcut Disinfected : C:\Users\Tim\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WorldofTanks.lnk
 
***** [ Registry ] *****
 
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Deleted : HKLM\SOFTWARE\Classes\and
Key Deleted : HKLM\SOFTWARE\Classes\surf
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-161304646
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Vosteran Browser
Key Deleted : HKCU\Software\WSE_Vosteran
Key Deleted : HKCU\Software\Vosteran
Key Deleted : HKLM\SOFTWARE\Uniblue
Key Deleted : HKLM\SOFTWARE\SK.Enhancer
Key Deleted : HKLM\SOFTWARE\Mindspark
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WorldofTanks
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WSE_Vosteran
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17496
 
 
-\\ Mozilla Firefox v35.0.1 (x86 sv-SE)
 
[trq1irq0.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.hmpgUrl", "hxxp://vosteran.com/?f=1&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1[…]
[trq1irq0.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.newTabUrl", "hxxp://vosteran.com/?f=2&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDy[…]
[trq1irq0.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.prtnrId", "WSE_Vosteran");
[trq1irq0.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.srchPrvdr", "Vosteran");
[trq1irq0.default\prefs.js] - Line Deleted : user_pref("extensions.srchvstrn.tlbrSrchUrl", "hxxp://vosteran.com/?f=3&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzyt[…]
[trq1irq0.default\prefs.js] - Line Deleted : user_pref("[removed]-event-fired", true);
 
-\\ Google Chrome v40.0.2214.91
 
[C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
[C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
 
-\\ Chromium v
 
[C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
[C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_ggbg_15_04_ff&cd;=2XzuyEtN2Y1L1QzutDtDtByEtC0D0CyEyEzy0F0AtDtByD0EtN0D0Tzu0StCtCtCzytN1L2XzutAtFyBtFtAtFtBtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0F0A0FyCtDtCyBtGzztCyB0AtG0C0D0AyDtGzytB0D0FtGtA0CyEyEtAtDtC0EzyyCtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0D0EtAtBtA0EtAtGtByB0A0FtGyE0BzztDtGzzzzzzyDtGyBtB0Azzzy0EyCyByC0A0ByE2Q&cr;=668876811&ir;=
 
*************************
 
AdwCleaner[R0].txt - [8477 octets] - [28/01/2015 12:08:18]
AdwCleaner[S0].txt - [9261 octets] - [28/01/2015 12:21:34]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9321 octets] ##########
 
 
 
JRT.TXT:
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on 2015-01-28 at 12:32:39,86
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
 
 
 
~~~ FireFox
 
Emptied folder: C:\Users\Tim\AppData\Roaming\mozilla\firefox\profiles\trq1irq0.default\minidumps [102 files]
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2015-01-28 at 12:36:00,47
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
NEW FRST.TXT:
 
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01
Ran by [removed] (administrator) on INET on 28-01-2015 12:52:25
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Svenska (Sverige)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-28] (AVAST Software)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Run: [GoogleChromeAutoLaunch_77DB27ED30D96DC6FB2B344658AE2828] => "C:\Users\Tim\AppData\Local\Vosteran\Application\vosteran.exe" –no-startup-window –auto-launch-at-startup –profile-directory="Default"
AppInit_DLLs-x32: C:/PROGRA~3/{C6092~1/190~1.1/rati.dll => "C:/PROGRA~3/{C6092~1/190~1.1/rati.dll" File Not Found
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.inet.se
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.inet.se
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF ProfilePath: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default
FF SearchEngineOrder.1: Yahoo! (Avast)
FF SearchEngineOrder.3: Bing 
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Tim\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF SearchPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\trq1irq0.default\searchplugins\yahoo-avast.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\allaannonser-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\prisjakt-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\tyda-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-sv-SE.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-27]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-22]
 
Chrome: 
=======
CHR Profile: C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Dokument) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-08]
CHR Extension: (Google Drive) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-08]
CHR Extension: (YouTube) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-08]
CHR Extension: (Battlefield Heroes) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2015-01-09]
CHR Extension: (Sök på Google) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-08]
CHR Extension: (Avast Online Security) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-08]
CHR Extension: (Google Wallet) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-08]
CHR Extension: (Gmail) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-08]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-04]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-04] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-12-04] (Avast Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-28] (Hi-Rez Studios) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-01-09] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-04] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-04] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-04] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-04] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-04] (AVAST Software)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [243200 2009-10-21] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
S3 IAMTVE; C:\Windows\system32\drivers\IAMTVE.sys [43416 2010-11-30] (Intel Corporation)
S3 IAMTXPE; C:\Windows\system32\drivers\IAMTXPE.sys [51096 2010-11-30] (Intel Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [15416 2009-05-14] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-12-04] (Avast Software)
S3 aswVmm; \??\C:\Users\Tim\AppData\Local\Temp\aswVmm.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va029; \??\C:\Windows\SysWOW64\Drivers\X6va029 [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-01-28 12:52 - 2015-01-28 12:52 - 00013630 _____ () C:\Users\Tim\Desktop\FRST.txt
2015-01-28 12:48 - 2015-01-28 12:48 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-48-37.047-AvastVBoxSVC.exe-3220.log
2015-01-28 12:36 - 2015-01-28 12:36 - 00000824 _____ () C:\Users\Tim\Desktop\JRT.txt
2015-01-28 12:32 - 2015-01-28 12:32 - 00000000 ____D () C:\Windows\ERUNT
2015-01-28 12:30 - 2015-01-28 12:30 - 01707939 _____ (Thisisu) C:\Users\Tim\Desktop\JRT.exe
2015-01-28 12:27 - 2015-01-28 12:27 - 00009433 _____ () C:\Users\Tim\Desktop\AdwCleaner[S0].txt
2015-01-28 12:26 - 2015-01-28 12:26 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-26-05.093-AvastVBoxSVC.exe-3520.log
2015-01-28 12:08 - 2015-01-28 12:21 - 00000000 ____D () C:\AdwCleaner
2015-01-28 12:06 - 2015-01-28 12:06 - 02194432 _____ () C:\Users\Tim\Desktop\AdwCleaner.exe
2015-01-28 12:02 - 2015-01-28 12:03 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-02-45.051-AvastVBoxSVC.exe-1584.log
2015-01-27 18:40 - 2015-01-27 18:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-27 18:04 - 2015-01-28 12:52 - 00000000 ____D () C:\FRST
2015-01-27 18:02 - 2015-01-27 18:02 - 02129920 _____ (Farbar) C:\Users\Tim\Desktop\FRST64.exe
2015-01-27 17:37 - 2015-01-27 17:37 - 05198336 _____ (AVAST Software) C:\Users\Tim\Desktop\aswMBR.exe
2015-01-27 17:28 - 2015-01-27 17:28 - 00000197 _____ () C:\Windows\system32\2015-01-27-16-28-06.013-AvastVBoxSVC.exe-2452.log
2015-01-25 17:05 - 2015-01-25 17:05 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-05-46.072-AvastVBoxSVC.exe-2384.log
2015-01-25 17:00 - 2015-01-25 17:00 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-00-29.011-AvastVBoxSVC.exe-1428.log
2015-01-25 16:18 - 2015-01-25 16:18 - 00000197 _____ () C:\Windows\system32\2015-01-25-15-18-00.026-AvastVBoxSVC.exe-2732.log
2015-01-25 09:39 - 2015-01-25 09:39 - 00000197 _____ () C:\Windows\system32\2015-01-25-08-39-04.097-AvastVBoxSVC.exe-3736.log
2015-01-25 09:36 - 2015-01-28 12:01 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-01-24 18:35 - 2015-01-25 17:35 - 00000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2015-01-24 17:57 - 2015-01-24 17:57 - 00001238 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2015-01-24 17:57 - 2015-01-24 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2015-01-24 17:55 - 2015-01-24 21:47 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2015-01-24 17:51 - 2015-01-24 17:51 - 02942368 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\World-of-Warcraft-Setup-enGB.exe
2015-01-24 17:38 - 2015-01-25 00:06 - 00000000 ____D () C:\Users\Tim\AppData\Local\Battle.net
2015-01-24 17:38 - 2015-01-24 17:55 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Battle.net
2015-01-24 17:38 - 2015-01-24 17:38 - 00000000 ____D () C:\Users\Tim\AppData\Local\Blizzard Entertainment
2015-01-24 17:37 - 2015-01-24 17:38 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2015-01-24 17:36 - 2015-01-28 12:21 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks
2015-01-24 17:36 - 2015-01-28 12:21 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates WW2
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates WW1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates W1
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Pirates946
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pirates
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\GGEmpire441
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\GGEmpire
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\ProgramData\Battle.net
2015-01-24 17:35 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\Pirates
2015-01-24 17:35 - 2015-01-24 17:35 - 123231216 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\WorldOfWarCraftSetup.exe
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall W1
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall TW2
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall TW1
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Local\StormFall
2015-01-24 17:33 - 2015-01-24 17:34 - 00819816 _____ (%VENDOR%) C:\Users\Tim\Downloads\WorldofWarCraft_Setup.exe
2015-01-24 13:47 - 2015-01-24 13:48 - 00000197 _____ () C:\Windows\system32\2015-01-24-12-47-40.045-AvastVBoxSVC.exe-3452.log
2015-01-24 08:41 - 2015-01-24 08:41 - 00000197 _____ () C:\Windows\system32\2015-01-24-07-41-44.020-AvastVBoxSVC.exe-4040.log
2015-01-23 21:40 - 2015-01-23 21:40 - 00000197 _____ () C:\Windows\system32\2015-01-23-20-40-03.016-AvastVBoxSVC.exe-4508.log
2015-01-23 16:57 - 2015-01-23 16:58 - 00000197 _____ () C:\Windows\system32\2015-01-23-15-57-47.063-AvastVBoxSVC.exe-3636.log
2015-01-23 07:35 - 2015-01-23 07:36 - 00000197 _____ () C:\Windows\system32\2015-01-23-06-35-43.037-AvastVBoxSVC.exe-3552.log
2015-01-22 15:05 - 2015-01-22 15:06 - 00000197 _____ () C:\Windows\system32\2015-01-22-14-05-49.099-AvastVBoxSVC.exe-3720.log
2015-01-22 07:32 - 2015-01-22 07:32 - 00000197 _____ () C:\Windows\system32\2015-01-22-06-32-43.034-AvastVBoxSVC.exe-3040.log
2015-01-21 19:31 - 2015-01-21 19:32 - 00000000 ____D () C:\Users\Tim\Downloads\Slender_v0_9_7 (1)
2015-01-21 19:31 - 2015-01-21 19:31 - 00000000 ____D () C:\Users\Tim\Desktop\Slender v0.9.7
2015-01-21 19:23 - 2015-01-21 19:30 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7 (1).zip
2015-01-21 19:08 - 2015-01-21 19:09 - 00000197 _____ () C:\Windows\system32\2015-01-21-18-08-51.048-AvastVBoxSVC.exe-3480.log
2015-01-21 19:01 - 2015-01-21 19:01 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7.zip
2015-01-21 14:27 - 2015-01-21 14:27 - 00000197 _____ () C:\Windows\system32\2015-01-21-13-27-01.087-AvastVBoxSVC.exe-2708.log
2015-01-21 06:17 - 2015-01-21 06:18 - 00000197 _____ () C:\Windows\system32\2015-01-21-05-17-40.013-AvastVBoxSVC.exe-3284.log
2015-01-21 05:32 - 2015-01-21 05:32 - 00000197 _____ () C:\Windows\system32\2015-01-21-04-32-11.025-AvastVBoxSVC.exe-2500.log
2015-01-20 15:42 - 2015-01-20 15:43 - 00000197 _____ () C:\Windows\system32\2015-01-20-14-42-54.082-AvastVBoxSVC.exe-3380.log
2015-01-20 07:21 - 2015-01-20 07:21 - 00000197 _____ () C:\Windows\system32\2015-01-20-06-21-05.091-AvastVBoxSVC.exe-3240.log
2015-01-19 13:43 - 2015-01-19 13:44 - 00000197 _____ () C:\Windows\system32\2015-01-19-12-43-55.039-AvastVBoxSVC.exe-3832.log
2015-01-19 07:27 - 2015-01-19 07:27 - 00000197 _____ () C:\Windows\system32\2015-01-19-06-27-12.003-AvastVBoxSVC.exe-3452.log
2015-01-18 09:31 - 2015-01-18 09:31 - 00000197 _____ () C:\Windows\system32\2015-01-18-08-31-40.030-AvastVBoxSVC.exe-3352.log
2015-01-17 09:13 - 2015-01-17 09:13 - 00000197 _____ () C:\Windows\system32\2015-01-17-08-13-20.071-AvastVBoxSVC.exe-3536.log
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieUserList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieSiteList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieBrowserModeList
2015-01-16 18:34 - 2015-01-16 18:34 - 00000222 _____ () C:\Users\Tim\Desktop\MicroVolts Surge.url
2015-01-16 17:58 - 2015-01-16 17:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-16-58-01.044-AvastVBoxSVC.exe-3048.log
2015-01-16 11:45 - 2015-01-16 11:45 - 00000197 _____ () C:\Windows\system32\2015-01-16-10-45-04.007-AvastVBoxSVC.exe-3160.log
2015-01-16 07:57 - 2015-01-16 07:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-06-57-44.044-AvastVBoxSVC.exe-3596.log
2015-01-15 15:19 - 2015-01-15 15:19 - 00000197 _____ () C:\Windows\system32\2015-01-15-14-19-09.002-AvastVBoxSVC.exe-2148.log
2015-01-15 06:46 - 2015-01-15 06:46 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-46-18.056-AvastVBoxSVC.exe-3440.log
2015-01-15 06:42 - 2015-01-15 06:42 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-42-40.094-AvastVBoxSVC.exe-2848.log
2015-01-14 16:29 - 2015-01-14 16:29 - 00000197 _____ () C:\Windows\system32\2015-01-14-15-29-36.005-AvastVBoxSVC.exe-3388.log
2015-01-14 14:43 - 2015-01-14 14:44 - 00000197 _____ () C:\Windows\system32\2015-01-14-13-43-43.031-AvastVBoxSVC.exe-2500.log
2015-01-14 07:51 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 07:51 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 07:51 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 07:51 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 07:51 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 07:51 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 07:51 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 07:51 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 07:48 - 2015-01-14 07:48 - 00000197 _____ () C:\Windows\system32\2015-01-14-06-48-14.075-AvastVBoxSVC.exe-1388.log
2015-01-13 14:37 - 2015-01-13 14:38 - 00000197 _____ () C:\Windows\system32\2015-01-13-13-37-39.065-AvastVBoxSVC.exe-3848.log
2015-01-13 07:54 - 2015-01-13 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-13-06-54-26.047-AvastVBoxSVC.exe-2908.log
2015-01-12 13:45 - 2015-01-12 13:45 - 00000197 _____ () C:\Windows\system32\2015-01-12-12-45-02.016-AvastVBoxSVC.exe-3228.log
2015-01-12 07:55 - 2015-01-12 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-12-06-55-17.056-AvastVBoxSVC.exe-2700.log
2015-01-11 10:10 - 2015-01-11 10:10 - 00000197 _____ () C:\Windows\system32\2015-01-11-09-10-12.019-AvastVBoxSVC.exe-2992.log
2015-01-10 17:56 - 2015-01-10 17:56 - 08229276 _____ () C:\Users\Tim\Downloads\1964_11.rar
2015-01-10 17:54 - 2015-01-10 17:54 - 00065552 _____ () C:\Users\Tim\Downloads\Zelda_1.zip
2015-01-10 17:53 - 2015-01-10 17:53 - 03029593 _____ () C:\Users\Tim\Downloads\fceux-2.2.2-win32.zip
2015-01-10 17:14 - 2015-01-10 17:14 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Unity
2015-01-10 15:36 - 2015-01-10 15:36 - 00000197 _____ () C:\Windows\system32\2015-01-10-14-36-08.039-AvastVBoxSVC.exe-3096.log
2015-01-10 09:54 - 2015-01-10 09:55 - 00000197 _____ () C:\Windows\system32\2015-01-10-08-54-54.090-AvastVBoxSVC.exe-2936.log
2015-01-09 21:01 - 2015-01-10 12:43 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-01-09 21:00 - 2015-01-09 21:00 - 00000000 ____D () C:\Users\Tim\AppData\Local\PunkBuster
2015-01-09 19:26 - 2015-01-09 21:38 - 00000000 ____D () C:\Users\Tim\Documents\Battlefield Heroes
2015-01-09 19:25 - 2015-01-10 12:43 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-01-09 19:25 - 2015-01-10 10:12 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-01-09 19:25 - 2015-01-09 21:07 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-01-09 19:25 - 2015-01-09 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games
2015-01-09 19:23 - 2015-01-09 19:23 - 00000000 ____D () C:\Program Files (x86)\EA Games
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Users\Tim\AppData\Local\Ubisoft Game Launcher
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2015-01-09 15:13 - 2015-01-09 15:13 - 00000197 _____ () C:\Windows\system32\2015-01-09-14-13-11.016-AvastVBoxSVC.exe-3340.log
2015-01-09 11:45 - 2015-01-09 11:46 - 00000197 _____ () C:\Windows\system32\2015-01-09-10-45-23.092-AvastVBoxSVC.exe-3372.log
2015-01-09 07:47 - 2015-01-09 07:47 - 00000197 _____ () C:\Windows\system32\2015-01-09-06-47-16.002-AvastVBoxSVC.exe-3136.log
2015-01-08 15:07 - 2015-01-08 15:08 - 00000197 _____ () C:\Windows\system32\2015-01-08-14-07-54.027-AvastVBoxSVC.exe-3892.log
2015-01-08 07:33 - 2015-01-08 07:33 - 00000197 _____ () C:\Windows\system32\2015-01-08-06-33-12.020-AvastVBoxSVC.exe-2848.log
2015-01-07 10:19 - 2015-01-07 10:20 - 00000197 _____ () C:\Windows\system32\2015-01-07-09-19-56.023-AvastVBoxSVC.exe-2908.log
2015-01-06 12:11 - 2015-01-06 12:12 - 00000197 _____ () C:\Windows\system32\2015-01-06-11-11-48.071-AvastVBoxSVC.exe-2448.log
2015-01-05 07:53 - 2015-01-05 07:53 - 00000197 _____ () C:\Windows\system32\2015-01-05-06-53-36.086-AvastVBoxSVC.exe-3104.log
2015-01-04 17:51 - 2015-01-04 17:51 - 00000197 _____ () C:\Windows\system32\2015-01-04-16-51-18.021-AvastVBoxSVC.exe-3220.log
2015-01-03 00:50 - 2015-01-03 00:50 - 00003262 _____ () C:\Windows\System32\Tasks\avastBCLRestartS-1-5-21-3767168050-546541148-904736753-1000
2015-01-02 18:00 - 2015-01-02 18:00 - 00000197 _____ () C:\Windows\system32\2015-01-02-17-00-10.085-AvastVBoxSVC.exe-1404.log
2015-01-02 14:06 - 2015-01-02 14:06 - 00000197 _____ () C:\Windows\system32\2015-01-02-13-06-19.086-AvastVBoxSVC.exe-2344.log
2015-01-02 13:58 - 2015-01-02 13:58 - 00086398 _____ () C:\Users\Tim\Downloads\[1-7-2]_Lucky_Block_v5-0-0.jar
2015-01-02 13:47 - 2015-01-02 13:48 - 04161288 _____ (Mindspark Interactive Network) C:\Users\Tim\Downloads\EliteUnzipSetup.EliteUnzip_aa.gafhhbahpojnjfhpepjjfjojbphnogmn.ch.exe
2015-01-02 12:02 - 2015-01-02 12:03 - 00000197 _____ () C:\Windows\system32\2015-01-02-11-02-31.002-AvastVBoxSVC.exe-2616.log
2015-01-01 14:53 - 2015-01-01 14:53 - 00000197 _____ () C:\Windows\system32\2015-01-01-13-53-14.082-AvastVBoxSVC.exe-3504.log
2014-12-31 16:21 - 2014-12-31 16:21 - 00000197 _____ () C:\Windows\system32\2014-12-31-15-21-48.034-AvastVBoxSVC.exe-708.log
2014-12-31 10:31 - 2014-12-31 10:32 - 00000197 _____ () C:\Windows\system32\2014-12-31-09-31-21.063-AvastVBoxSVC.exe-3084.log
2014-12-30 10:14 - 2014-12-30 10:15 - 00000197 _____ () C:\Windows\system32\2014-12-30-09-14-36.048-AvastVBoxSVC.exe-2212.log
2014-12-29 17:50 - 2014-12-29 17:50 - 00000197 _____ () C:\Windows\system32\2014-12-29-16-50-58.090-AvastVBoxSVC.exe-2600.log
2014-12-29 11:01 - 2014-12-29 11:01 - 00000197 _____ () C:\Windows\system32\2014-12-29-10-01-13.002-AvastVBoxSVC.exe-3084.log
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-01-28 12:49 - 2013-09-30 14:37 - 01856158 _____ () C:\Windows\WindowsUpdate.log
2015-01-28 12:46 - 2009-07-14 05:51 - 00166329 _____ () C:\Windows\setupact.log
2015-01-28 12:45 - 2014-08-08 10:43 - 00000990 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-28 12:45 - 2013-09-30 14:53 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-01-28 12:45 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-28 12:41 - 2014-08-08 10:44 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-28 12:41 - 2014-08-08 10:43 - 00000994 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-28 12:31 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-28 12:31 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-28 12:30 - 2010-11-21 12:38 - 00670622 _____ () C:\Windows\system32\perfh01D.dat
2015-01-28 12:30 - 2010-11-21 12:38 - 00146498 _____ () C:\Windows\system32\perfc01D.dat
2015-01-28 12:30 - 2009-07-14 06:13 - 01602714 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-28 12:23 - 2013-11-13 07:41 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-01-28 12:23 - 2010-11-21 04:47 - 00102046 _____ () C:\Windows\PFRO.log
2015-01-28 12:00 - 2013-10-22 09:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-28 11:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2015-01-27 17:28 - 2009-07-14 03:34 - 00000505 _____ () C:\Windows\win.ini
2015-01-25 16:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
2015-01-24 17:35 - 2013-10-22 09:18 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-24 17:17 - 2013-10-22 09:51 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\.minecraft
2015-01-24 15:45 - 2013-10-23 08:34 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-16 19:34 - 2014-05-29 07:50 - 00000000 ____D () C:\Users\Tim\AppData\Local\Microsoft Games
2015-01-16 18:34 - 2013-10-23 09:01 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-01-14 08:28 - 2013-09-30 15:30 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 08:24 - 2013-09-30 15:30 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-09 18:07 - 2013-10-27 12:27 - 00267107 _____ () C:\Windows\DirectX.log
2015-01-09 17:53 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-06 04:36 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-05 18:16 - 2013-10-22 10:01 - 22764208 _____ () C:\Users\Tim\Desktop\TechnicLauncher.exe
2015-01-05 18:16 - 2013-10-22 10:01 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\.technic
2015-01-03 00:50 - 2013-10-22 09:18 - 00001137 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-02 17:41 - 2014-06-09 15:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Skype
2015-01-02 16:32 - 2014-06-09 15:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-02 16:32 - 2014-06-09 15:34 - 00000000 ____D () C:\ProgramData\Skype
2015-01-02 12:01 - 2009-07-14 06:08 - 00032514 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-30 23:55 - 2014-10-18 07:25 - 00000000 ____D () C:\Users\Tim\AppData\Local\CSO
 
==================== Files in the root of some directories =======
 
2015-01-24 18:35 - 2015-01-25 17:35 - 0000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2013-11-28 18:17 - 2013-11-28 18:17 - 0000091 _____ () C:\Users\Tim\AppData\Local\fusioncache.dat
2014-10-04 13:14 - 2014-10-04 13:14 - 0000000 _____ () C:\Users\Tim\AppData\Local\{26F9D811-A740-4CF8-B01D-202083068605}
 
Some content of TEMP:
====================
C:\Users\Tim\AppData\Local\Temp\Quarantine.exe
C:\Users\Tim\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-01-24 16:08
 
==================== End Of Log ============================
 
 
I was able to reboot in normal mode after the first fix.  Feels much better now, thanks.   :)  My son wants me to thank you for your help as well.  (I'm making him help me do this to learn more about his computer.) 
 
 
Firefox doesn't want to connect to the net anymore, however, it seems to think everything is unverified.  I've got no problem with simply uninstalling and reinstalling it though, if that is the easiest solution to the problem.  Or it might be connected to fact that the Firefox avast plugin is disabled atm.
 
Finally, please find the addition.txt file enclosed as an attachment.
 
Thanks again, see you soon!

 

Attachments:

Hi Svinlesha,

Both you and your son are quite welcome. And I think it's a great idea for him to be sitting in on the fixing of the computer. We all have to learn somtime, let's just be thankful it wasn't one of the more severe infections out there.

[external image: bullseye_zpse9eaf36e.gif] Reset Firefox to its default state
  • At the top of the Firefox window, click the Firefox button, go over to the Help sub-menu
    (on Windows XP, click the Help menu at the top of the Firefox window) and select Troubleshooting Information.
    [external image: restfirefox1.png]
  • Click the Reset Firefox button in the upper-right corner of the Troubleshooting Information page.
    [external image: resetfirefox2.png]
  • To continue, click Reset Firefox in the confirmation window that opens.
  • Firefox will close and be reset. When it's done, a window will list the information that was imported. Click Finish and Firefox will open.
=========================

[external image: bullseye_zpse9eaf36e.gif] Uninstall via Programs and Features

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • ace race
  • Cleaner Pro
  • GoodGameEmpire
  • Pirates
  • Ryzom
  • StormFall
  • World Of WarCraft Packages
=========================

[external image: bullseye_zpse9eaf36e.gif] FRST Fix Script

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the desktop as fixlist.txt



Start
CloseProcesses:
C:\Users\Tim\AppData\Local\Vosteran
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST and press the Fix button just once and wait.
The tool will make a log (Fixlog.txt) please post it to your reply.

=========================

[external image: bullseye_zpse9eaf36e.gif] Re-run Farbar Recovery Scan Tool it should be on your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
=========================

In your next post please provide the following:
  • Fixlog.txt
  • new FRST.txt

Hi OCD!

 

Well, before we continue: we could not uninstall ace race (a message said it was already unintalled, but we continue getting a warning from Avast about it every time we start up a browser), and the Cleaner Pro uninstaller didn't work because of a missing DLL.  Continuing, the control panel claims that Good Game Empire is "maybe" already unintalled, as well as Stormfall and WoW Packages.  So we've been unable to uninstall any program, and I thought I better check back with you before continuing.

 

Should I go ahead and run your fixscript?

Hi Svinlesha,

Yes, please continue with the outlined steps. We will address those items down the road.

I'm headed out the door for work so I will have to pick back up later tonight (or morning for you).

Hello OCD

 

 

here is the fixlogtext

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-01-2015
Ran by [removed] at 2015-01-29 18:24:34 Run:2
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
Start
CloseProcesses:
C:\Users\Tim\AppData\Local\Vosteran
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
EmptyTemp:
End
*****************
 
Processes closed successfully.
"C:\Users\Tim\AppData\Local\Vosteran" => File/Directory not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
EmptyTemp: => Removed 51.8 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 18:24:42 ====
 
here is the new frst text
 
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by [removed] (administrator) on INET on 29-01-2015 18:29:43
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Svenska (Sverige)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-28] (AVAST Software)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Run: [GoogleChromeAutoLaunch_77DB27ED30D96DC6FB2B344658AE2828] => "C:\Users\Tim\AppData\Local\Vosteran\Application\vosteran.exe" –no-startup-window –auto-launch-at-startup –profile-directory="Default"
AppInit_DLLs-x32: C:/PROGRA~3/{C6092~1/190~1.1/rati.dll => "C:/PROGRA~3/{C6092~1/190~1.1/rati.dll" File Not Found
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.inet.se
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.inet.se
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF ProfilePath: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\40hu7roo.default-1422549441719
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Tim\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\allaannonser-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\prisjakt-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\tyda-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-sv-SE.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-27]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-22]
 
Chrome: 
=======
CHR Profile: C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Dokument) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-08]
CHR Extension: (Google Drive) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-08]
CHR Extension: (YouTube) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-08]
CHR Extension: (Battlefield Heroes) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2015-01-09]
CHR Extension: (Sök på Google) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-08]
CHR Extension: (Avast Online Security) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-08]
CHR Extension: (Google Wallet) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-08]
CHR Extension: (Gmail) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-08]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-04]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-04] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-12-04] (Avast Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-28] (Hi-Rez Studios) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-01-09] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-04] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-04] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-04] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-04] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-04] (AVAST Software)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [243200 2009-10-21] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
S3 IAMTVE; C:\Windows\system32\drivers\IAMTVE.sys [43416 2010-11-30] (Intel Corporation)
S3 IAMTXPE; C:\Windows\system32\drivers\IAMTXPE.sys [51096 2010-11-30] (Intel Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [15416 2009-05-14] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-12-04] (Avast Software)
S3 aswVmm; \??\C:\Users\Tim\AppData\Local\Temp\aswVmm.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va029; \??\C:\Windows\SysWOW64\Drivers\X6va029 [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-01-29 18:29 - 2015-01-29 18:30 - 00012987 _____ () C:\Users\Tim\Desktop\FRST.txt
2015-01-29 18:25 - 2015-01-29 18:26 - 00000197 _____ () C:\Windows\system32\2015-01-29-17-25-57.087-AvastVBoxSVC.exe-3236.log
2015-01-29 18:24 - 2015-01-29 18:24 - 00000000 ____D () C:\Users\Tim\Desktop\FRST-OlderVersion
2015-01-29 18:17 - 2015-01-29 18:17 - 00000197 _____ () C:\Windows\system32\2015-01-29-17-17-03.025-AvastVBoxSVC.exe-2268.log
2015-01-29 17:37 - 2015-01-29 17:37 - 00000000 ____D () C:\Users\Tim\Desktop\Gammal Firefox-data
2015-01-29 17:10 - 2015-01-29 17:10 - 00000197 _____ () C:\Windows\system32\2015-01-29-16-10-08.084-AvastVBoxSVC.exe-2996.log
2015-01-28 12:48 - 2015-01-28 12:48 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-48-37.047-AvastVBoxSVC.exe-3220.log
2015-01-28 12:32 - 2015-01-28 12:32 - 00000000 ____D () C:\Windows\ERUNT
2015-01-28 12:30 - 2015-01-28 12:30 - 01707939 _____ (Thisisu) C:\Users\Tim\Desktop\JRT.exe
2015-01-28 12:26 - 2015-01-28 12:26 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-26-05.093-AvastVBoxSVC.exe-3520.log
2015-01-28 12:08 - 2015-01-28 12:21 - 00000000 ____D () C:\AdwCleaner
2015-01-28 12:06 - 2015-01-28 12:06 - 02194432 _____ () C:\Users\Tim\Desktop\AdwCleaner.exe
2015-01-28 12:02 - 2015-01-28 12:03 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-02-45.051-AvastVBoxSVC.exe-1584.log
2015-01-27 18:40 - 2015-01-27 18:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-27 18:04 - 2015-01-29 18:29 - 00000000 ____D () C:\FRST
2015-01-27 18:02 - 2015-01-29 18:24 - 02130432 _____ (Farbar) C:\Users\Tim\Desktop\FRST64.exe
2015-01-27 17:37 - 2015-01-27 17:37 - 05198336 _____ (AVAST Software) C:\Users\Tim\Desktop\aswMBR.exe
2015-01-27 17:28 - 2015-01-27 17:28 - 00000197 _____ () C:\Windows\system32\2015-01-27-16-28-06.013-AvastVBoxSVC.exe-2452.log
2015-01-25 17:05 - 2015-01-25 17:05 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-05-46.072-AvastVBoxSVC.exe-2384.log
2015-01-25 17:00 - 2015-01-25 17:00 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-00-29.011-AvastVBoxSVC.exe-1428.log
2015-01-25 16:18 - 2015-01-25 16:18 - 00000197 _____ () C:\Windows\system32\2015-01-25-15-18-00.026-AvastVBoxSVC.exe-2732.log
2015-01-25 09:39 - 2015-01-25 09:39 - 00000197 _____ () C:\Windows\system32\2015-01-25-08-39-04.097-AvastVBoxSVC.exe-3736.log
2015-01-25 09:36 - 2015-01-28 12:01 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-01-24 18:35 - 2015-01-25 17:35 - 00000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2015-01-24 17:57 - 2015-01-24 17:57 - 00001238 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2015-01-24 17:57 - 2015-01-24 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2015-01-24 17:55 - 2015-01-24 21:47 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2015-01-24 17:51 - 2015-01-24 17:51 - 02942368 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\World-of-Warcraft-Setup-enGB.exe
2015-01-24 17:38 - 2015-01-25 00:06 - 00000000 ____D () C:\Users\Tim\AppData\Local\Battle.net
2015-01-24 17:38 - 2015-01-24 17:55 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Battle.net
2015-01-24 17:38 - 2015-01-24 17:38 - 00000000 ____D () C:\Users\Tim\AppData\Local\Blizzard Entertainment
2015-01-24 17:37 - 2015-01-24 17:38 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2015-01-24 17:36 - 2015-01-28 12:21 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks
2015-01-24 17:36 - 2015-01-28 12:21 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates WW2
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates WW1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates W1
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Pirates946
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pirates
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\GGEmpire441
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\GGEmpire
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\ProgramData\Battle.net
2015-01-24 17:35 - 2015-01-29 17:23 - 00000000 ____D () C:\Users\Tim\AppData\Local\Pirates
2015-01-24 17:35 - 2015-01-24 17:35 - 123231216 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\WorldOfWarCraftSetup.exe
2015-01-24 17:34 - 2015-01-29 17:25 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall W1
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall TW2
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall TW1
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Local\StormFall
2015-01-24 17:33 - 2015-01-24 17:34 - 00819816 _____ (%VENDOR%) C:\Users\Tim\Downloads\WorldofWarCraft_Setup.exe
2015-01-24 13:47 - 2015-01-24 13:48 - 00000197 _____ () C:\Windows\system32\2015-01-24-12-47-40.045-AvastVBoxSVC.exe-3452.log
2015-01-24 08:41 - 2015-01-24 08:41 - 00000197 _____ () C:\Windows\system32\2015-01-24-07-41-44.020-AvastVBoxSVC.exe-4040.log
2015-01-23 21:40 - 2015-01-23 21:40 - 00000197 _____ () C:\Windows\system32\2015-01-23-20-40-03.016-AvastVBoxSVC.exe-4508.log
2015-01-23 16:57 - 2015-01-23 16:58 - 00000197 _____ () C:\Windows\system32\2015-01-23-15-57-47.063-AvastVBoxSVC.exe-3636.log
2015-01-23 07:35 - 2015-01-23 07:36 - 00000197 _____ () C:\Windows\system32\2015-01-23-06-35-43.037-AvastVBoxSVC.exe-3552.log
2015-01-22 15:05 - 2015-01-22 15:06 - 00000197 _____ () C:\Windows\system32\2015-01-22-14-05-49.099-AvastVBoxSVC.exe-3720.log
2015-01-22 07:32 - 2015-01-22 07:32 - 00000197 _____ () C:\Windows\system32\2015-01-22-06-32-43.034-AvastVBoxSVC.exe-3040.log
2015-01-21 19:31 - 2015-01-21 19:32 - 00000000 ____D () C:\Users\Tim\Downloads\Slender_v0_9_7 (1)
2015-01-21 19:31 - 2015-01-21 19:31 - 00000000 ____D () C:\Users\Tim\Desktop\Slender v0.9.7
2015-01-21 19:23 - 2015-01-21 19:30 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7 (1).zip
2015-01-21 19:08 - 2015-01-21 19:09 - 00000197 _____ () C:\Windows\system32\2015-01-21-18-08-51.048-AvastVBoxSVC.exe-3480.log
2015-01-21 19:01 - 2015-01-21 19:01 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7.zip
2015-01-21 14:27 - 2015-01-21 14:27 - 00000197 _____ () C:\Windows\system32\2015-01-21-13-27-01.087-AvastVBoxSVC.exe-2708.log
2015-01-21 06:17 - 2015-01-21 06:18 - 00000197 _____ () C:\Windows\system32\2015-01-21-05-17-40.013-AvastVBoxSVC.exe-3284.log
2015-01-21 05:32 - 2015-01-21 05:32 - 00000197 _____ () C:\Windows\system32\2015-01-21-04-32-11.025-AvastVBoxSVC.exe-2500.log
2015-01-20 15:42 - 2015-01-20 15:43 - 00000197 _____ () C:\Windows\system32\2015-01-20-14-42-54.082-AvastVBoxSVC.exe-3380.log
2015-01-20 07:21 - 2015-01-20 07:21 - 00000197 _____ () C:\Windows\system32\2015-01-20-06-21-05.091-AvastVBoxSVC.exe-3240.log
2015-01-19 13:43 - 2015-01-19 13:44 - 00000197 _____ () C:\Windows\system32\2015-01-19-12-43-55.039-AvastVBoxSVC.exe-3832.log
2015-01-19 07:27 - 2015-01-19 07:27 - 00000197 _____ () C:\Windows\system32\2015-01-19-06-27-12.003-AvastVBoxSVC.exe-3452.log
2015-01-18 09:31 - 2015-01-18 09:31 - 00000197 _____ () C:\Windows\system32\2015-01-18-08-31-40.030-AvastVBoxSVC.exe-3352.log
2015-01-17 09:13 - 2015-01-17 09:13 - 00000197 _____ () C:\Windows\system32\2015-01-17-08-13-20.071-AvastVBoxSVC.exe-3536.log
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieUserList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieSiteList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieBrowserModeList
2015-01-16 18:34 - 2015-01-16 18:34 - 00000222 _____ () C:\Users\Tim\Desktop\MicroVolts Surge.url
2015-01-16 17:58 - 2015-01-16 17:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-16-58-01.044-AvastVBoxSVC.exe-3048.log
2015-01-16 11:45 - 2015-01-16 11:45 - 00000197 _____ () C:\Windows\system32\2015-01-16-10-45-04.007-AvastVBoxSVC.exe-3160.log
2015-01-16 07:57 - 2015-01-16 07:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-06-57-44.044-AvastVBoxSVC.exe-3596.log
2015-01-15 15:19 - 2015-01-15 15:19 - 00000197 _____ () C:\Windows\system32\2015-01-15-14-19-09.002-AvastVBoxSVC.exe-2148.log
2015-01-15 06:46 - 2015-01-15 06:46 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-46-18.056-AvastVBoxSVC.exe-3440.log
2015-01-15 06:42 - 2015-01-15 06:42 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-42-40.094-AvastVBoxSVC.exe-2848.log
2015-01-14 16:29 - 2015-01-14 16:29 - 00000197 _____ () C:\Windows\system32\2015-01-14-15-29-36.005-AvastVBoxSVC.exe-3388.log
2015-01-14 14:43 - 2015-01-14 14:44 - 00000197 _____ () C:\Windows\system32\2015-01-14-13-43-43.031-AvastVBoxSVC.exe-2500.log
2015-01-14 07:51 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 07:51 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 07:51 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 07:51 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 07:51 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 07:51 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 07:51 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 07:51 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 07:48 - 2015-01-14 07:48 - 00000197 _____ () C:\Windows\system32\2015-01-14-06-48-14.075-AvastVBoxSVC.exe-1388.log
2015-01-13 14:37 - 2015-01-13 14:38 - 00000197 _____ () C:\Windows\system32\2015-01-13-13-37-39.065-AvastVBoxSVC.exe-3848.log
2015-01-13 07:54 - 2015-01-13 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-13-06-54-26.047-AvastVBoxSVC.exe-2908.log
2015-01-12 13:45 - 2015-01-12 13:45 - 00000197 _____ () C:\Windows\system32\2015-01-12-12-45-02.016-AvastVBoxSVC.exe-3228.log
2015-01-12 07:55 - 2015-01-12 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-12-06-55-17.056-AvastVBoxSVC.exe-2700.log
2015-01-11 10:10 - 2015-01-11 10:10 - 00000197 _____ () C:\Windows\system32\2015-01-11-09-10-12.019-AvastVBoxSVC.exe-2992.log
2015-01-10 17:56 - 2015-01-10 17:56 - 08229276 _____ () C:\Users\Tim\Downloads\1964_11.rar
2015-01-10 17:54 - 2015-01-10 17:54 - 00065552 _____ () C:\Users\Tim\Downloads\Zelda_1.zip
2015-01-10 17:53 - 2015-01-10 17:53 - 03029593 _____ () C:\Users\Tim\Downloads\fceux-2.2.2-win32.zip
2015-01-10 17:14 - 2015-01-10 17:14 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Unity
2015-01-10 15:36 - 2015-01-10 15:36 - 00000197 _____ () C:\Windows\system32\2015-01-10-14-36-08.039-AvastVBoxSVC.exe-3096.log
2015-01-10 09:54 - 2015-01-10 09:55 - 00000197 _____ () C:\Windows\system32\2015-01-10-08-54-54.090-AvastVBoxSVC.exe-2936.log
2015-01-09 21:01 - 2015-01-10 12:43 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-01-09 21:00 - 2015-01-09 21:00 - 00000000 ____D () C:\Users\Tim\AppData\Local\PunkBuster
2015-01-09 19:26 - 2015-01-09 21:38 - 00000000 ____D () C:\Users\Tim\Documents\Battlefield Heroes
2015-01-09 19:25 - 2015-01-10 12:43 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-01-09 19:25 - 2015-01-10 10:12 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-01-09 19:25 - 2015-01-09 21:07 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-01-09 19:25 - 2015-01-09 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games
2015-01-09 19:23 - 2015-01-09 19:23 - 00000000 ____D () C:\Program Files (x86)\EA Games
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Users\Tim\AppData\Local\Ubisoft Game Launcher
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2015-01-09 15:13 - 2015-01-09 15:13 - 00000197 _____ () C:\Windows\system32\2015-01-09-14-13-11.016-AvastVBoxSVC.exe-3340.log
2015-01-09 11:45 - 2015-01-09 11:46 - 00000197 _____ () C:\Windows\system32\2015-01-09-10-45-23.092-AvastVBoxSVC.exe-3372.log
2015-01-09 07:47 - 2015-01-09 07:47 - 00000197 _____ () C:\Windows\system32\2015-01-09-06-47-16.002-AvastVBoxSVC.exe-3136.log
2015-01-08 15:07 - 2015-01-08 15:08 - 00000197 _____ () C:\Windows\system32\2015-01-08-14-07-54.027-AvastVBoxSVC.exe-3892.log
2015-01-08 07:33 - 2015-01-08 07:33 - 00000197 _____ () C:\Windows\system32\2015-01-08-06-33-12.020-AvastVBoxSVC.exe-2848.log
2015-01-07 10:19 - 2015-01-07 10:20 - 00000197 _____ () C:\Windows\system32\2015-01-07-09-19-56.023-AvastVBoxSVC.exe-2908.log
2015-01-06 12:11 - 2015-01-06 12:12 - 00000197 _____ () C:\Windows\system32\2015-01-06-11-11-48.071-AvastVBoxSVC.exe-2448.log
2015-01-05 07:53 - 2015-01-05 07:53 - 00000197 _____ () C:\Windows\system32\2015-01-05-06-53-36.086-AvastVBoxSVC.exe-3104.log
2015-01-04 17:51 - 2015-01-04 17:51 - 00000197 _____ () C:\Windows\system32\2015-01-04-16-51-18.021-AvastVBoxSVC.exe-3220.log
2015-01-03 00:50 - 2015-01-03 00:50 - 00003262 _____ () C:\Windows\System32\Tasks\avastBCLRestartS-1-5-21-3767168050-546541148-904736753-1000
2015-01-02 18:00 - 2015-01-02 18:00 - 00000197 _____ () C:\Windows\system32\2015-01-02-17-00-10.085-AvastVBoxSVC.exe-1404.log
2015-01-02 14:06 - 2015-01-02 14:06 - 00000197 _____ () C:\Windows\system32\2015-01-02-13-06-19.086-AvastVBoxSVC.exe-2344.log
2015-01-02 13:58 - 2015-01-02 13:58 - 00086398 _____ () C:\Users\Tim\Downloads\[1-7-2]_Lucky_Block_v5-0-0.jar
2015-01-02 13:47 - 2015-01-02 13:48 - 04161288 _____ (Mindspark Interactive Network) C:\Users\Tim\Downloads\EliteUnzipSetup.EliteUnzip_aa.gafhhbahpojnjfhpepjjfjojbphnogmn.ch.exe
2015-01-02 12:02 - 2015-01-02 12:03 - 00000197 _____ () C:\Windows\system32\2015-01-02-11-02-31.002-AvastVBoxSVC.exe-2616.log
2015-01-01 14:53 - 2015-01-01 14:53 - 00000197 _____ () C:\Windows\system32\2015-01-01-13-53-14.082-AvastVBoxSVC.exe-3504.log
2014-12-31 16:21 - 2014-12-31 16:21 - 00000197 _____ () C:\Windows\system32\2014-12-31-15-21-48.034-AvastVBoxSVC.exe-708.log
2014-12-31 10:31 - 2014-12-31 10:32 - 00000197 _____ () C:\Windows\system32\2014-12-31-09-31-21.063-AvastVBoxSVC.exe-3084.log
2014-12-30 10:14 - 2014-12-30 10:15 - 00000197 _____ () C:\Windows\system32\2014-12-30-09-14-36.048-AvastVBoxSVC.exe-2212.log
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-01-29 18:29 - 2013-09-30 14:37 - 01909410 _____ () C:\Windows\WindowsUpdate.log
2015-01-29 18:26 - 2013-11-13 07:41 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-01-29 18:25 - 2014-08-08 10:43 - 00000990 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-29 18:25 - 2013-09-30 14:53 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-01-29 18:25 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-29 18:25 - 2009-07-14 05:51 - 00166833 _____ () C:\Windows\setupact.log
2015-01-29 18:21 - 2010-11-21 12:38 - 00670622 _____ () C:\Windows\system32\perfh01D.dat
2015-01-29 18:21 - 2010-11-21 12:38 - 00146498 _____ () C:\Windows\system32\perfc01D.dat
2015-01-29 18:21 - 2009-07-14 06:13 - 01602714 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-29 18:21 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-29 18:21 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-28 12:41 - 2014-08-08 10:44 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-28 12:41 - 2014-08-08 10:43 - 00000994 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-28 12:23 - 2010-11-21 04:47 - 00102046 _____ () C:\Windows\PFRO.log
2015-01-28 12:00 - 2013-10-22 09:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-28 11:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2015-01-27 17:28 - 2009-07-14 03:34 - 00000505 _____ () C:\Windows\win.ini
2015-01-25 16:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
2015-01-24 17:35 - 2013-10-22 09:18 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-24 17:17 - 2013-10-22 09:51 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\.minecraft
2015-01-24 15:45 - 2013-10-23 08:34 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-16 19:34 - 2014-05-29 07:50 - 00000000 ____D () C:\Users\Tim\AppData\Local\Microsoft Games
2015-01-16 18:34 - 2013-10-23 09:01 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-01-14 08:28 - 2013-09-30 15:30 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 08:24 - 2013-09-30 15:30 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-09 18:07 - 2013-10-27 12:27 - 00267107 _____ () C:\Windows\DirectX.log
2015-01-09 17:53 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-06 04:36 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-05 18:16 - 2013-10-22 10:01 - 22764208 _____ () C:\Users\Tim\Desktop\TechnicLauncher.exe
2015-01-05 18:16 - 2013-10-22 10:01 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\.technic
2015-01-03 00:50 - 2013-10-22 09:18 - 00001137 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-02 17:41 - 2014-06-09 15:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Skype
2015-01-02 16:32 - 2014-06-09 15:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-02 16:32 - 2014-06-09 15:34 - 00000000 ____D () C:\ProgramData\Skype
2015-01-02 12:01 - 2009-07-14 06:08 - 00032514 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-30 23:55 - 2014-10-18 07:25 - 00000000 ____D () C:\Users\Tim\AppData\Local\CSO
 
==================== Files in the root of some directories =======
 
2015-01-24 18:35 - 2015-01-25 17:35 - 0000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2013-11-28 18:17 - 2013-11-28 18:17 - 0000091 _____ () C:\Users\Tim\AppData\Local\fusioncache.dat
2014-10-04 13:14 - 2014-10-04 13:14 - 0000000 _____ () C:\Users\Tim\AppData\Local\{26F9D811-A740-4CF8-B01D-202083068605}
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-01-24 16:08
 
==================== End Of Log ============================
 
 
thanks again 
 
isaac

 

Hi Svinlesha,

Sometimes when you try and remove a program and don't get all the parts it becomes difficult to remove it completely. Revo is usually able to get all the remnants, so let's give it a try.

Since there are multiple programs we are trying to remove, you will have to complete the removal process for each program then move onto the next one on the list until you have finished.

[external image: bullseye_zpse9eaf36e.gif] Revo Uninstaller Pro

Please download Revo Uninstaller Pro and save it to your desktop.
(This version is a fully functional, 30 day free trial)
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • From the list of programs click on
    ace race
    Cleaner Pro
    GoodGameEmpire
    Pirates
    Ryzom
    StormFall
    World Of WarCraft Packages
  • Chose "Uninstall". When prompted click Yes.
  • Make sure the advanced option is checked… then click Next.
  • The program will run, when prompted… click Yes… then Next.
  • Once the program has searched for leftovers click Next.
  • Check ONLY the bolded items on the list then… click Next… then Yes.
  • When done click Finish.
=========================

[external image: bullseye_zpse9eaf36e.gif] Reboot

=========================

[external image: bullseye_zpse9eaf36e.gif] Re-run Farbar Recovery Scan Tool it should be on your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the tool opens click Yes to disclaimer.
  • Select the Addition box
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • It will also make (Addition.txt). Please attach it to your reply
=========================

In your next post please provide the following:
  • FRST.txt
  • Addition.txt

Hi again OCD!

 

Good old Revo uninstaller!  I haven't used it since i migrated to Windows 7 years ago.   :)

 

Sorry to say, we had similar problems with Revo that we had when we tried to uninstall through the controlpanel.  

 

ace race: Revo couldn't find it.

Cleaner Pro: A missing DLL from the "Window installer package" stopped the uninstall process.  Scanned and found a large number of registry items we can delete, though.

Good Games Empire: the uninstaller failed, but we could scan for and remaining items in the registry.  It found a lot of items in the registry to delete, including chrome.exe.  Should we just delete the registry items?

Ryzom: uninstalled previously.

Stormfall: Revo couldn't find it.

World of Warcraft packages: Revo couldn't find it.

 

Since we haven't done anything yet i'm guessing the FRST and addition logs are unchanged, but here you go (just to be certain):

 

 

FRST:

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by [removed] (administrator) on INET on 31-01-2015 11:42:26
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Svenska (Sverige)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-28] (AVAST Software)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Run: [GoogleChromeAutoLaunch_77DB27ED30D96DC6FB2B344658AE2828] => "C:\Users\Tim\AppData\Local\Vosteran\Application\vosteran.exe" –no-startup-window –auto-launch-at-startup –profile-directory="Default"
AppInit_DLLs-x32: C:/PROGRA~3/{C6092~1/190~1.1/rati.dll => "C:/PROGRA~3/{C6092~1/190~1.1/rati.dll" File Not Found
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.inet.se
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.inet.se
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF ProfilePath: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\40hu7roo.default-1422549441719
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Tim\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\allaannonser-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\prisjakt-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\tyda-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-sv-SE.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-27]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-22]
 
Chrome: 
=======
CHR Profile: C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Dokument) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-08]
CHR Extension: (Google Drive) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-08]
CHR Extension: (YouTube) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-08]
CHR Extension: (Battlefield Heroes) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2015-01-09]
CHR Extension: (Sök på Google) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-08]
CHR Extension: (Avast Online Security) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-08]
CHR Extension: (Google Wallet) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-08]
CHR Extension: (Gmail) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-08]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-04]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-04] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-12-04] (Avast Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-28] (Hi-Rez Studios) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-01-09] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-04] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-04] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-04] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-04] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-04] (AVAST Software)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [243200 2009-10-21] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
S3 IAMTVE; C:\Windows\system32\drivers\IAMTVE.sys [43416 2010-11-30] (Intel Corporation)
S3 IAMTXPE; C:\Windows\system32\drivers\IAMTXPE.sys [51096 2010-11-30] (Intel Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [15416 2009-05-14] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-12-04] (Avast Software)
S3 aswVmm; \??\C:\Users\Tim\AppData\Local\Temp\aswVmm.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va029; \??\C:\Windows\SysWOW64\Drivers\X6va029 [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-01-31 11:30 - 2015-01-31 11:30 - 00001039 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\Users\Tim\AppData\Local\VS Revo Group
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\ProgramData\VS Revo Group
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-01-31 11:30 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2015-01-31 11:29 - 2015-01-31 11:28 - 10801480 _____ (VS Revo Group ) C:\Users\Tim\Desktop\RevoUninProSetup.exe
2015-01-31 11:28 - 2015-01-31 11:28 - 10801480 _____ (VS Revo Group ) C:\Users\Tim\Downloads\RevoUninProSetup.exe
2015-01-31 11:23 - 2015-01-31 11:24 - 00000197 _____ () C:\Windows\system32\2015-01-31-10-23-26.018-AvastVBoxSVC.exe-3036.log
2015-01-29 18:29 - 2015-01-31 11:42 - 00013044 _____ () C:\Users\Tim\Desktop\FRST.txt
2015-01-29 18:25 - 2015-01-29 18:26 - 00000197 _____ () C:\Windows\system32\2015-01-29-17-25-57.087-AvastVBoxSVC.exe-3236.log
2015-01-29 18:24 - 2015-01-29 18:24 - 00000000 ____D () C:\Users\Tim\Desktop\FRST-OlderVersion
2015-01-29 18:17 - 2015-01-29 18:17 - 00000197 _____ () C:\Windows\system32\2015-01-29-17-17-03.025-AvastVBoxSVC.exe-2268.log
2015-01-29 17:37 - 2015-01-29 17:37 - 00000000 ____D () C:\Users\Tim\Desktop\Gammal Firefox-data
2015-01-29 17:10 - 2015-01-29 17:10 - 00000197 _____ () C:\Windows\system32\2015-01-29-16-10-08.084-AvastVBoxSVC.exe-2996.log
2015-01-28 12:48 - 2015-01-28 12:48 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-48-37.047-AvastVBoxSVC.exe-3220.log
2015-01-28 12:32 - 2015-01-28 12:32 - 00000000 ____D () C:\Windows\ERUNT
2015-01-28 12:30 - 2015-01-28 12:30 - 01707939 _____ (Thisisu) C:\Users\Tim\Desktop\JRT.exe
2015-01-28 12:26 - 2015-01-28 12:26 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-26-05.093-AvastVBoxSVC.exe-3520.log
2015-01-28 12:08 - 2015-01-28 12:21 - 00000000 ____D () C:\AdwCleaner
2015-01-28 12:06 - 2015-01-28 12:06 - 02194432 _____ () C:\Users\Tim\Desktop\AdwCleaner.exe
2015-01-28 12:02 - 2015-01-28 12:03 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-02-45.051-AvastVBoxSVC.exe-1584.log
2015-01-27 18:40 - 2015-01-27 18:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-27 18:04 - 2015-01-31 11:42 - 00000000 ____D () C:\FRST
2015-01-27 18:02 - 2015-01-29 18:24 - 02130432 _____ (Farbar) C:\Users\Tim\Desktop\FRST64.exe
2015-01-27 17:37 - 2015-01-27 17:37 - 05198336 _____ (AVAST Software) C:\Users\Tim\Desktop\aswMBR.exe
2015-01-27 17:28 - 2015-01-27 17:28 - 00000197 _____ () C:\Windows\system32\2015-01-27-16-28-06.013-AvastVBoxSVC.exe-2452.log
2015-01-25 17:05 - 2015-01-25 17:05 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-05-46.072-AvastVBoxSVC.exe-2384.log
2015-01-25 17:00 - 2015-01-25 17:00 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-00-29.011-AvastVBoxSVC.exe-1428.log
2015-01-25 16:18 - 2015-01-25 16:18 - 00000197 _____ () C:\Windows\system32\2015-01-25-15-18-00.026-AvastVBoxSVC.exe-2732.log
2015-01-25 09:39 - 2015-01-25 09:39 - 00000197 _____ () C:\Windows\system32\2015-01-25-08-39-04.097-AvastVBoxSVC.exe-3736.log
2015-01-25 09:36 - 2015-01-28 12:01 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-01-24 18:35 - 2015-01-25 17:35 - 00000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2015-01-24 17:57 - 2015-01-24 17:57 - 00001238 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2015-01-24 17:57 - 2015-01-24 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2015-01-24 17:55 - 2015-01-24 21:47 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2015-01-24 17:51 - 2015-01-24 17:51 - 02942368 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\World-of-Warcraft-Setup-enGB.exe
2015-01-24 17:38 - 2015-01-25 00:06 - 00000000 ____D () C:\Users\Tim\AppData\Local\Battle.net
2015-01-24 17:38 - 2015-01-24 17:55 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Battle.net
2015-01-24 17:38 - 2015-01-24 17:38 - 00000000 ____D () C:\Users\Tim\AppData\Local\Blizzard Entertainment
2015-01-24 17:37 - 2015-01-24 17:38 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2015-01-24 17:36 - 2015-01-28 12:21 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks
2015-01-24 17:36 - 2015-01-28 12:21 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates WW2
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates WW1
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates W1
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Pirates946
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pirates
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\GGEmpire441
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\GGEmpire
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\ProgramData\Battle.net
2015-01-24 17:35 - 2015-01-29 17:23 - 00000000 ____D () C:\Users\Tim\AppData\Local\Pirates
2015-01-24 17:35 - 2015-01-24 17:35 - 123231216 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\WorldOfWarCraftSetup.exe
2015-01-24 17:34 - 2015-01-29 17:25 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall W1
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall TW2
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall TW1
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Local\StormFall
2015-01-24 17:33 - 2015-01-24 17:34 - 00819816 _____ (%VENDOR%) C:\Users\Tim\Downloads\WorldofWarCraft_Setup.exe
2015-01-24 13:47 - 2015-01-24 13:48 - 00000197 _____ () C:\Windows\system32\2015-01-24-12-47-40.045-AvastVBoxSVC.exe-3452.log
2015-01-24 08:41 - 2015-01-24 08:41 - 00000197 _____ () C:\Windows\system32\2015-01-24-07-41-44.020-AvastVBoxSVC.exe-4040.log
2015-01-23 21:40 - 2015-01-23 21:40 - 00000197 _____ () C:\Windows\system32\2015-01-23-20-40-03.016-AvastVBoxSVC.exe-4508.log
2015-01-23 16:57 - 2015-01-23 16:58 - 00000197 _____ () C:\Windows\system32\2015-01-23-15-57-47.063-AvastVBoxSVC.exe-3636.log
2015-01-23 07:35 - 2015-01-23 07:36 - 00000197 _____ () C:\Windows\system32\2015-01-23-06-35-43.037-AvastVBoxSVC.exe-3552.log
2015-01-22 15:05 - 2015-01-22 15:06 - 00000197 _____ () C:\Windows\system32\2015-01-22-14-05-49.099-AvastVBoxSVC.exe-3720.log
2015-01-22 07:32 - 2015-01-22 07:32 - 00000197 _____ () C:\Windows\system32\2015-01-22-06-32-43.034-AvastVBoxSVC.exe-3040.log
2015-01-21 19:31 - 2015-01-21 19:32 - 00000000 ____D () C:\Users\Tim\Downloads\Slender_v0_9_7 (1)
2015-01-21 19:31 - 2015-01-21 19:31 - 00000000 ____D () C:\Users\Tim\Desktop\Slender v0.9.7
2015-01-21 19:23 - 2015-01-21 19:30 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7 (1).zip
2015-01-21 19:08 - 2015-01-21 19:09 - 00000197 _____ () C:\Windows\system32\2015-01-21-18-08-51.048-AvastVBoxSVC.exe-3480.log
2015-01-21 19:01 - 2015-01-21 19:01 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7.zip
2015-01-21 14:27 - 2015-01-21 14:27 - 00000197 _____ () C:\Windows\system32\2015-01-21-13-27-01.087-AvastVBoxSVC.exe-2708.log
2015-01-21 06:17 - 2015-01-21 06:18 - 00000197 _____ () C:\Windows\system32\2015-01-21-05-17-40.013-AvastVBoxSVC.exe-3284.log
2015-01-21 05:32 - 2015-01-21 05:32 - 00000197 _____ () C:\Windows\system32\2015-01-21-04-32-11.025-AvastVBoxSVC.exe-2500.log
2015-01-20 15:42 - 2015-01-20 15:43 - 00000197 _____ () C:\Windows\system32\2015-01-20-14-42-54.082-AvastVBoxSVC.exe-3380.log
2015-01-20 07:21 - 2015-01-20 07:21 - 00000197 _____ () C:\Windows\system32\2015-01-20-06-21-05.091-AvastVBoxSVC.exe-3240.log
2015-01-19 13:43 - 2015-01-19 13:44 - 00000197 _____ () C:\Windows\system32\2015-01-19-12-43-55.039-AvastVBoxSVC.exe-3832.log
2015-01-19 07:27 - 2015-01-19 07:27 - 00000197 _____ () C:\Windows\system32\2015-01-19-06-27-12.003-AvastVBoxSVC.exe-3452.log
2015-01-18 09:31 - 2015-01-18 09:31 - 00000197 _____ () C:\Windows\system32\2015-01-18-08-31-40.030-AvastVBoxSVC.exe-3352.log
2015-01-17 09:13 - 2015-01-17 09:13 - 00000197 _____ () C:\Windows\system32\2015-01-17-08-13-20.071-AvastVBoxSVC.exe-3536.log
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieUserList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieSiteList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieBrowserModeList
2015-01-16 18:34 - 2015-01-16 18:34 - 00000222 _____ () C:\Users\Tim\Desktop\MicroVolts Surge.url
2015-01-16 17:58 - 2015-01-16 17:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-16-58-01.044-AvastVBoxSVC.exe-3048.log
2015-01-16 11:45 - 2015-01-16 11:45 - 00000197 _____ () C:\Windows\system32\2015-01-16-10-45-04.007-AvastVBoxSVC.exe-3160.log
2015-01-16 07:57 - 2015-01-16 07:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-06-57-44.044-AvastVBoxSVC.exe-3596.log
2015-01-15 15:19 - 2015-01-15 15:19 - 00000197 _____ () C:\Windows\system32\2015-01-15-14-19-09.002-AvastVBoxSVC.exe-2148.log
2015-01-15 06:46 - 2015-01-15 06:46 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-46-18.056-AvastVBoxSVC.exe-3440.log
2015-01-15 06:42 - 2015-01-15 06:42 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-42-40.094-AvastVBoxSVC.exe-2848.log
2015-01-14 16:29 - 2015-01-14 16:29 - 00000197 _____ () C:\Windows\system32\2015-01-14-15-29-36.005-AvastVBoxSVC.exe-3388.log
2015-01-14 14:43 - 2015-01-14 14:44 - 00000197 _____ () C:\Windows\system32\2015-01-14-13-43-43.031-AvastVBoxSVC.exe-2500.log
2015-01-14 07:51 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 07:51 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 07:51 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 07:51 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 07:51 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 07:51 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 07:51 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 07:51 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 07:48 - 2015-01-14 07:48 - 00000197 _____ () C:\Windows\system32\2015-01-14-06-48-14.075-AvastVBoxSVC.exe-1388.log
2015-01-13 14:37 - 2015-01-13 14:38 - 00000197 _____ () C:\Windows\system32\2015-01-13-13-37-39.065-AvastVBoxSVC.exe-3848.log
2015-01-13 07:54 - 2015-01-13 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-13-06-54-26.047-AvastVBoxSVC.exe-2908.log
2015-01-12 13:45 - 2015-01-12 13:45 - 00000197 _____ () C:\Windows\system32\2015-01-12-12-45-02.016-AvastVBoxSVC.exe-3228.log
2015-01-12 07:55 - 2015-01-12 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-12-06-55-17.056-AvastVBoxSVC.exe-2700.log
2015-01-11 10:10 - 2015-01-11 10:10 - 00000197 _____ () C:\Windows\system32\2015-01-11-09-10-12.019-AvastVBoxSVC.exe-2992.log
2015-01-10 17:56 - 2015-01-10 17:56 - 08229276 _____ () C:\Users\Tim\Downloads\1964_11.rar
2015-01-10 17:54 - 2015-01-10 17:54 - 00065552 _____ () C:\Users\Tim\Downloads\Zelda_1.zip
2015-01-10 17:53 - 2015-01-10 17:53 - 03029593 _____ () C:\Users\Tim\Downloads\fceux-2.2.2-win32.zip
2015-01-10 17:14 - 2015-01-10 17:14 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Unity
2015-01-10 15:36 - 2015-01-10 15:36 - 00000197 _____ () C:\Windows\system32\2015-01-10-14-36-08.039-AvastVBoxSVC.exe-3096.log
2015-01-10 09:54 - 2015-01-10 09:55 - 00000197 _____ () C:\Windows\system32\2015-01-10-08-54-54.090-AvastVBoxSVC.exe-2936.log
2015-01-09 21:01 - 2015-01-10 12:43 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-01-09 21:00 - 2015-01-09 21:00 - 00000000 ____D () C:\Users\Tim\AppData\Local\PunkBuster
2015-01-09 19:26 - 2015-01-09 21:38 - 00000000 ____D () C:\Users\Tim\Documents\Battlefield Heroes
2015-01-09 19:25 - 2015-01-10 12:43 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-01-09 19:25 - 2015-01-10 10:12 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-01-09 19:25 - 2015-01-09 21:07 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-01-09 19:25 - 2015-01-09 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games
2015-01-09 19:23 - 2015-01-09 19:23 - 00000000 ____D () C:\Program Files (x86)\EA Games
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Users\Tim\AppData\Local\Ubisoft Game Launcher
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2015-01-09 15:13 - 2015-01-09 15:13 - 00000197 _____ () C:\Windows\system32\2015-01-09-14-13-11.016-AvastVBoxSVC.exe-3340.log
2015-01-09 11:45 - 2015-01-09 11:46 - 00000197 _____ () C:\Windows\system32\2015-01-09-10-45-23.092-AvastVBoxSVC.exe-3372.log
2015-01-09 07:47 - 2015-01-09 07:47 - 00000197 _____ () C:\Windows\system32\2015-01-09-06-47-16.002-AvastVBoxSVC.exe-3136.log
2015-01-08 15:07 - 2015-01-08 15:08 - 00000197 _____ () C:\Windows\system32\2015-01-08-14-07-54.027-AvastVBoxSVC.exe-3892.log
2015-01-08 07:33 - 2015-01-08 07:33 - 00000197 _____ () C:\Windows\system32\2015-01-08-06-33-12.020-AvastVBoxSVC.exe-2848.log
2015-01-07 10:19 - 2015-01-07 10:20 - 00000197 _____ () C:\Windows\system32\2015-01-07-09-19-56.023-AvastVBoxSVC.exe-2908.log
2015-01-06 12:11 - 2015-01-06 12:12 - 00000197 _____ () C:\Windows\system32\2015-01-06-11-11-48.071-AvastVBoxSVC.exe-2448.log
2015-01-05 07:53 - 2015-01-05 07:53 - 00000197 _____ () C:\Windows\system32\2015-01-05-06-53-36.086-AvastVBoxSVC.exe-3104.log
2015-01-04 17:51 - 2015-01-04 17:51 - 00000197 _____ () C:\Windows\system32\2015-01-04-16-51-18.021-AvastVBoxSVC.exe-3220.log
2015-01-03 00:50 - 2015-01-03 00:50 - 00003262 _____ () C:\Windows\System32\Tasks\avastBCLRestartS-1-5-21-3767168050-546541148-904736753-1000
2015-01-02 18:00 - 2015-01-02 18:00 - 00000197 _____ () C:\Windows\system32\2015-01-02-17-00-10.085-AvastVBoxSVC.exe-1404.log
2015-01-02 14:06 - 2015-01-02 14:06 - 00000197 _____ () C:\Windows\system32\2015-01-02-13-06-19.086-AvastVBoxSVC.exe-2344.log
2015-01-02 13:58 - 2015-01-02 13:58 - 00086398 _____ () C:\Users\Tim\Downloads\[1-7-2]_Lucky_Block_v5-0-0.jar
2015-01-02 13:47 - 2015-01-02 13:48 - 04161288 _____ (Mindspark Interactive Network) C:\Users\Tim\Downloads\EliteUnzipSetup.EliteUnzip_aa.gafhhbahpojnjfhpepjjfjojbphnogmn.ch.exe
2015-01-02 12:02 - 2015-01-02 12:03 - 00000197 _____ () C:\Windows\system32\2015-01-02-11-02-31.002-AvastVBoxSVC.exe-2616.log
2015-01-01 14:53 - 2015-01-01 14:53 - 00000197 _____ () C:\Windows\system32\2015-01-01-13-53-14.082-AvastVBoxSVC.exe-3504.log
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-01-31 11:40 - 2014-08-08 10:43 - 00000994 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-31 11:30 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-31 11:30 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-31 11:29 - 2010-11-21 12:38 - 00670622 _____ () C:\Windows\system32\perfh01D.dat
2015-01-31 11:29 - 2010-11-21 12:38 - 00146498 _____ () C:\Windows\system32\perfc01D.dat
2015-01-31 11:29 - 2009-07-14 06:13 - 01602714 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-31 11:27 - 2013-09-30 14:37 - 01955693 _____ () C:\Windows\WindowsUpdate.log
2015-01-31 11:23 - 2013-11-13 07:41 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-01-31 11:22 - 2014-08-08 10:43 - 00000990 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-31 11:22 - 2013-09-30 14:53 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-01-31 11:22 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-31 11:22 - 2009-07-14 05:51 - 00167001 _____ () C:\Windows\setupact.log
2015-01-28 12:41 - 2014-08-08 10:44 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-28 12:23 - 2010-11-21 04:47 - 00102046 _____ () C:\Windows\PFRO.log
2015-01-28 12:00 - 2013-10-22 09:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-28 11:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2015-01-27 17:28 - 2009-07-14 03:34 - 00000505 _____ () C:\Windows\win.ini
2015-01-25 16:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
2015-01-24 17:35 - 2013-10-22 09:18 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-24 17:17 - 2013-10-22 09:51 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\.minecraft
2015-01-24 15:45 - 2013-10-23 08:34 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-16 19:34 - 2014-05-29 07:50 - 00000000 ____D () C:\Users\Tim\AppData\Local\Microsoft Games
2015-01-16 18:34 - 2013-10-23 09:01 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-01-14 08:28 - 2013-09-30 15:30 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 08:24 - 2013-09-30 15:30 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-09 18:07 - 2013-10-27 12:27 - 00267107 _____ () C:\Windows\DirectX.log
2015-01-09 17:53 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-06 04:36 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-05 18:16 - 2013-10-22 10:01 - 22764208 _____ () C:\Users\Tim\Desktop\TechnicLauncher.exe
2015-01-05 18:16 - 2013-10-22 10:01 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\.technic
2015-01-03 00:50 - 2013-10-22 09:18 - 00001137 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-02 17:41 - 2014-06-09 15:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Skype
2015-01-02 16:32 - 2014-06-09 15:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-02 16:32 - 2014-06-09 15:34 - 00000000 ____D () C:\ProgramData\Skype
2015-01-02 12:01 - 2009-07-14 06:08 - 00032514 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
 
==================== Files in the root of some directories =======
 
2015-01-24 18:35 - 2015-01-25 17:35 - 0000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2013-11-28 18:17 - 2013-11-28 18:17 - 0000091 _____ () C:\Users\Tim\AppData\Local\fusioncache.dat
2014-10-04 13:14 - 2014-10-04 13:14 - 0000000 _____ () C:\Users\Tim\AppData\Local\{26F9D811-A740-4CF8-B01D-202083068605}
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-01-24 16:08
 
==================== End Of Log ============================
 
 
Addition:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-01-2015
Ran by [removed] at 2015-01-31 11:43:00
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 11 Plugin (HKLM-x32\…\Adobe Flash Player Plugin) (Version: 11.9.900.117 - Adobe Systems Incorporated)
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 10.0.2208 - AVAST Software)
Battle.net (HKLM-x32\…\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield Heroes (HKLM-x32\…\{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}) (Version:  - EA Digital illusions)
BioShock (HKLM-x32\…\Steam App 7670) (Version:  - 2K Boston)
Castle Crashers (HKLM-x32\…\Steam App 204360) (Version:  - The Behemoth)
Cleaner Pro (HKLM-x32\…\{AFC62A4A-BD08-4188-BA77-5F8BB8BCF18F}) (Version: 2.5.9 - Cleaner Pro)
Counter-Strike Nexon: Zombies (HKLM-x32\…\Steam App 273110) (Version:  - Nexon)
Counter-Strike: Source (HKLM-x32\…\Steam App 240) (Version:  - Valve)
Cry of Fear (HKLM-x32\…\Steam App 223710) (Version:  - Team Psykskallar)
Dungeons and Dragons Online (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\DDOen) (Version:  - )
F.E.A.R. Online (HKLM-x32\…\Steam App 223650) (Version:  - InPlay Interactive)
Forsaken World  (HKLM-x32\…\Steam App 36620) (Version:  - Perfect World Beijing)
Garry's Mod (HKLM-x32\…\Steam App 4000) (Version:  - Facepunch Studios)
Global Agenda (HKLM-x32\…\Steam App 17020) (Version:  - Hi-Rez Studios)
Global Agenda Live (HKLM-x32\…\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF001}) (Version: 1.5.1.5 - Hi-Rez Studios)
GoodGameEmpire (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\GoodGameEmpire) (Version:  - GoodGameEmpire) <==== ATTENTION!
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 40.0.2214.93 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Half-Life 2: Deathmatch (HKLM-x32\…\Steam App 320) (Version:  - Valve)
Half-Life 2: Lost Coast (HKLM-x32\…\Steam App 340) (Version:  - Valve)
Happy Cloud Client (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\HappyCloud) (Version: 3.41 - Happy Cloud, Inc.)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\…\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
Huawei Driver Installation (x32 Version: 1.0.0 - Huawei) Hidden
Java 7 Update 67 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
League of Legends (HKLM-x32\…\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Left 4 Dead 2 (HKLM-x32\…\Steam App 550) (Version:  - Valve)
Left 4 Dead 2 Beta (HKLM-x32\…\Steam App 223530) (Version:  - )
Microsoft .NET Framework 1.1 (HKLM-x32\…\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile Language Pack - SVE (HKLM\…\Microsoft .NET Framework 4 Client Profile SVE Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\…\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended Language Pack - SVE (HKLM\…\Microsoft .NET Framework 4 Extended SVE Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
MicroVolts Surge (HKLM-x32\…\Steam App 109400) (Version:  - NQ Games)
Mobile Broadband (x32 Version: 1.6 - Emotum) Hidden
Mozilla Firefox 35.0.1 (x86 sv-SE) (HKLM-x32\…\Mozilla Firefox 35.0.1 (x86 sv-SE)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
NVIDIA 3D Vision drivrutin 337.88 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 337.88 - NVIDIA Corporation)
NVIDIA 3D Vision drivrutin för styrenhet 337.88 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 337.88 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1 - NVIDIA Corporation)
NVIDIA Grafikdrivrutin 337.88 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation)
NVIDIA PhysX systemprogramvara 9.13.1220 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
ORION: Prelude (HKLM-x32\…\Steam App 104900) (Version:  - Spiral Game Studios)
Pando Media Booster (HKLM-x32\…\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
PunkBuster Services (HKLM-x32\…\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\…\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.34.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller Pro 3.1.2 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)
Shadow Warrior (HKLM-x32\…\Steam App 233130) (Version:  - Flying Wild Hog)
SHIELD Streaming (Version: 2.1.214 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Tactical Intervention (HKLM-x32\…\Steam App 51100) (Version:  - FIX Games)
Team Fortress 2 (HKLM-x32\…\Steam App 440) (Version:  - Valve)
Telenor Stay Connected (HKLM\…\Emotum Mobile Broadband) (Version: 1.6.3 - Emotum)
Torchlight II (HKLM-x32\…\Steam App 200710) (Version:  - Runic Games)
Torchlight II Demo (HKLM-x32\…\Steam App 219850) (Version:  - Runic Games)
Trials Fusion Demo (HKLM-x32\…\Steam App 294260) (Version:  - RedLynx, in collaboration with  Ubisoft Shanghai, Ubisoft Kiev)
Unity Web Player (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\UnityWebPlayer) (Version: 4.6.1f1 - Unity Technologies ApS)
Unturned (HKLM-x32\…\Steam App 304930) (Version:  - Nelson Sexton)
Uplay (HKLM-x32\…\Uplay) (Version: 4.3 - Ubisoft)
World of Warcraft (HKLM-x32\…\World of Warcraft) (Version:  - Blizzard Entertainment)
XCOM: Enemy Unknown Demo (HKLM-x32\…\Steam App 216690) (Version:  - Firaxis Games)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
 
==================== Restore Points  =========================
 
26-11-2014 18:43:37 Microsoft Visual C++ 2005 Redistributable (x64) installerades
26-11-2014 18:44:51 DirectX har installerats
28-11-2014 19:50:26 Windows Update
02-12-2014 10:37:28 Windows Update
04-12-2014 17:33:15 avast! antivirus system restore point
09-12-2014 07:55:41 Windows Update
10-12-2014 08:23:05 Windows Update
16-12-2014 07:52:23 Windows Update
19-12-2014 08:22:52 Windows Update
19-12-2014 23:16:14 DirectX har installerats
24-12-2014 09:44:08 Windows Update
28-12-2014 17:20:40 DirectX har installerats
30-12-2014 10:18:12 Windows Update
02-01-2015 12:05:42 Windows Update
06-01-2015 12:15:17 Windows Update
09-01-2015 17:47:10 DirectX har installerats
09-01-2015 18:06:44 DirectX har installerats
14-01-2015 07:51:12 Windows Update
14-01-2015 08:24:37 Windows Update
20-01-2015 07:24:48 Windows Update
21-01-2015 19:12:27 Uniblue PC Mechanic installation
23-01-2015 07:38:42 Windows Update
28-01-2015 12:06:02 Windows Update
31-01-2015 11:33:21 Revo Uninstaller Pro's restore point - Cleaner Pro
31-01-2015 11:34:21 Revo Uninstaller Pro's restore point - Cleaner Pro
31-01-2015 11:37:26 Revo Uninstaller Pro's restore point - GoodGameEmpire
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 03:34 - 2015-01-28 11:58 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {0954B156-7016-4593-9693-815C917DFE34} - System32\Tasks\Pirates WW1 => Chrome.exe –kiosk http://plarium.com/play/en/pirates/top/?adCampaign=42541&clickID;=tDtDtByEtC0D0CyEyEzy0F0AtDtByD0E&publisherID;=0_1_2
Task: {16171CED-4A66-46A5-8937-DF962C296E36} - System32\Tasks\Pirates WW2 => Chrome.exe –kiosk http://plarium.com/play/en/pirates/top/?adCampaign=42541&clickID;=tDtDtByEtC0D0CyEyEzy0F0AtDtByD0E&publisherID;=0_1_2
Task: {33350F8C-1068-44B9-899C-0F4AE49D866E} - System32\Tasks\Pirates W1 => Chrome.exe –kiosk http://plarium.com/play/en/pirates/top/?adCampaign=42541&clickID;=tDtDtByEtC0D0CyEyEzy0F0AtDtByD0E&publisherID;=0_1_2
Task: {4F2C2ED3-C9F8-4473-8CEE-EA2C8F8A7EC3} - System32\Tasks\StormFall TW2 => Chrome.exe –app=http://plarium.com/play/en/stormfall/dragon04?adCampaign=44120&clickID;=tDtDtByEtC0D0CyEyEzy0F0AtDtByD0E&publisherID;=1_1_2 –app-window-size=1440,900
Task: {639E9174-0A15-4DEB-8A1A-54B49BDFE36D} - System32\Tasks\avastBCLRestartS-1-5-21-3767168050-546541148-904736753-1000 => Chrome.exe 
Task: {6F667589-ED09-4487-B973-C67C90DE85DB} - System32\Tasks\StormFall W1 => Chrome.exe –app=http://plarium.com/play/en/stormfall/dragon04?adCampaign=44120&clickID;=tDtDtByEtC0D0CyEyEzy0F0AtDtByD0E&publisherID;=1_1_2 –app-window-size=1440,900
Task: {81DDFC05-7CD8-4A36-B7F9-803FEAAF25C5} - \CleanerPro_Start No Task File <==== ATTENTION
Task: {8B6E33A8-393C-4AE2-B8A1-DBDF2705F9F5} - \CleanerPro_Popup No Task File <==== ATTENTION
Task: {A575C369-FF15-421C-88C4-9F5D2FDA273C} - System32\Tasks\StormFall TW1 => Chrome.exe –app=http://plarium.com/play/en/stormfall/dragon04?adCampaign=44120&clickID;=tDtDtByEtC0D0CyEyEzy0F0AtDtByD0E&publisherID;=1_1_2 –app-window-size=1440,900
Task: {CF6900C0-2B9C-4E69-926A-43062E378EF7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-08] (Google Inc.)
Task: {D5ED21B8-3E4B-418C-9908-1B6315E656FA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-08] (Google Inc.)
Task: {FB026419-93C2-406B-8541-CE371B0C2FCA} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-12-04] (AVAST Software)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2013-09-30 14:53 - 2014-05-20 02:25 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-01-09 19:25 - 2015-01-09 21:07 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-12-04 17:34 - 2014-12-04 17:34 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2014-12-04 17:34 - 2014-12-04 17:34 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2015-01-29 17:10 - 2015-01-29 17:10 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15012900\algo.dll
2014-12-04 17:34 - 2014-12-04 17:34 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2015-01-31 11:23 - 2015-01-31 11:23 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15013100\algo.dll
2014-12-04 17:34 - 2014-12-04 17:34 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-01-28 12:41 - 2015-01-25 07:08 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\libglesv2.dll
2015-01-28 12:41 - 2015-01-25 07:08 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\libegl.dll
2015-01-28 12:41 - 2015-01-25 07:08 - 09170760 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\pdf.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: Emotum Mobile Broadband => C:\Program Files (x86)\Emotum\Mobile Broadband\Mobile.exe
MSCONFIG\startupreg: PCSpeedUp => C:\Program Files (x86)\PC Speed Up\PCSUNotifier.exe
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
 
========================= Accounts: ==========================
 
Administratör (S-1-5-21-3767168050-546541148-904736753-500 - Administrator - Disabled)
ASPNET (S-1-5-21-3767168050-546541148-904736753-1003 - Limited - Enabled)
Gäst (S-1-5-21-3767168050-546541148-904736753-501 - Limited - Disabled)
Tim (S-1-5-21-3767168050-546541148-904736753-1000 - Administrator - Enabled) => C:\Users\Tim
 
==================== Faulty Device Manager Devices =============
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (01/31/2015 11:36:39 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll
 
Error: (01/31/2015 11:33:50 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll
 
Error: (01/31/2015 11:33:21 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Fel i tjänsten Volume Shadow Copy: Oväntat fel när gränssnittet IVssWriterCallback skulle erhållas.  hr = 0x80070005, Åtkomst nekad.
.
Det orsakas ofta av inkorrekta säkerhetsinställningar i processen för antingen skrivaren eller beställaren.
 
 
Åtgärd:
   Samlar in skrivardata
 
Kontext:
   Skrivarklass-ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Skrivarnamn: System Writer
   Skrivarinstans-ID: {5ba6c00a-eecd-471f-8e96-b33fcb1045b4}
 
Error: (01/31/2015 11:22:50 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/29/2015 06:25:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/29/2015 06:15:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/29/2015 05:26:13 PM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll
 
Error: (01/29/2015 05:22:20 PM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll
 
Error: (01/29/2015 05:09:35 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/28/2015 00:46:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (01/29/2015 06:24:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Tjänsten Windows Search avslutades oväntat. Den har gjort detta 1 gång(er). Följande åtgärd kommer att utföras om 30000 millisekunder: Starta om tjänsten.
 
Error: (01/29/2015 06:24:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Tjänsten Windows Modules Installer avslutades oväntat. Den har gjort detta 1 gång(er). Följande åtgärd kommer att utföras om 120000 millisekunder: Starta om tjänsten.
 
Error: (01/29/2015 06:24:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten PnkBstrA avslutades oväntat. Detta har skett 1 gånger.
 
Error: (01/29/2015 06:24:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten NVIDIA Streamer Service avslutades oväntat. Detta har skett 1 gånger.
 
Error: (01/29/2015 06:24:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten Hi-Rez Studios Authenticate and Update Service avslutades oväntat. Detta har skett 1 gånger.
 
Error: (01/29/2015 06:24:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten NVIDIA Network Service avslutades oväntat. Detta har skett 1 gånger.
 
Error: (01/29/2015 06:24:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten Skype Click to Call PNR Service avslutades oväntat. Detta har skett 1 gånger.
 
Error: (01/29/2015 06:24:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten Skype Click to Call Updater avslutades oväntat. Detta har skett 1 gånger.
 
Error: (01/29/2015 06:24:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Tjänsten Print Spooler avslutades oväntat. Den har gjort detta 1 gång(er). Följande åtgärd kommer att utföras om 60000 millisekunder: Starta om tjänsten.
 
Error: (01/29/2015 06:24:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten NVIDIA Stereoscopic 3D Driver Service avslutades oväntat. Detta har skett 1 gånger.
 
 
Microsoft Office Sessions:
=========================
Error: (01/31/2015 11:36:39 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll (NULL)(NULL)(NULL)(NULL)(NULL)
 
Error: (01/31/2015 11:33:50 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll (NULL)(NULL)(NULL)(NULL)(NULL)
 
Error: (01/31/2015 11:33:21 AM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Åtkomst nekad.
 
 
Åtgärd:
   Samlar in skrivardata
 
Kontext:
   Skrivarklass-ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Skrivarnamn: System Writer
   Skrivarinstans-ID: {5ba6c00a-eecd-471f-8e96-b33fcb1045b4}
 
Error: (01/31/2015 11:22:50 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/29/2015 06:25:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/29/2015 06:15:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/29/2015 05:26:13 PM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll (NULL)(NULL)(NULL)(NULL)(NULL)
 
Error: (01/29/2015 05:22:20 PM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll (NULL)(NULL)(NULL)(NULL)(NULL)
 
Error: (01/29/2015 05:09:35 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/28/2015 00:46:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz
Percentage of memory in use: 40%
Total physical RAM: 4091.48 MB
Available physical RAM: 2448.09 MB
Total Pagefile: 8181.15 MB
Available Pagefile: 6511.62 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:931.51 GB) (Free:504.2 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 8E7BE50A)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================
 
(I figure you just want us to use revo to remove the registry items, but will be absolutely certain I don't do anything without your explicit say-so).
 
Thanks,
 
Tim

Hi Svinlesha,

OK, here is some good news.

ace race: Complete
Cleaner Pro: Incomplete
Good Games Empire: - Incomplete
Ryzom:  - Complete
Stormfall:  - Complete
World of Warcraft packages: - Complete

So we have made a good dent in these. Let's continue on with the malware removal process and address the two remaining programs later on.

=========================

[external image: bullseye_zpse9eaf36e.gif] Delete cache and other browser data in Chrome

  • Click the Chrome menu [external image: chromebrowsertoolbar.png] on the browser toolbar.
  • Select Tools.
  • Select Clear browsing data.
  • In the dialogue that appears, select the highlighted check-boxes for the types of information that you want to remove.
    • Clear browsing history
    • Clear download history
    • Empty the cache
    • Delete cookies and other site and plug-in data
    • Clear saved passwords
    • Clear saved Autofill form data
    • Clear data from hosted apps
    • Deauthorize content licenses
  • Use the menu at the top to select the amount of data that you want to delete. Select beginning of time to delete everything.
  • Click Clear browsing data.

=========================

Can you tell what these files are?
C:\Users\Tim\Downloads\Slender_v0_9_7 (1).zip
C:\Users\Tim\Downloads\fceux-2.2.2-win32.zip
C:\Users\Tim\Downloads\1964_11.rar


It might be helpful if your son can tell you what all he downloaded.

=========================

[external image: bullseye_zpse9eaf36e.gif] FRST Fix Script

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the desktop as fixlist.txt




Start
CloseProcesses:
[GoogleChromeAutoLaunch_77DB27ED30D96DC6FB2B344658AE2828] => "C:\Users\Tim\AppData\Local\Vosteran\Application\vosteran.exe" –no-startup-window –auto-launch-at-startup –profile-directory="Default"
C:\Users\Tim\AppData\Local\Vosteran
2015-01-02 13:47 - 2015-01-02 13:48 - 04161288 _____ (Mindspark Interactive Network) C:\Users\Tim\Downloads\EliteUnzipSetup.EliteUnzip_aa.gafhhbahpojnjfhpepjjfjojbphnogmn.ch.exe
Task: {81DDFC05-7CD8-4A36-B7F9-803FEAAF25C5} - \CleanerPro_Start No Task File <==== ATTENTION
Task: {8B6E33A8-393C-4AE2-B8A1-DBDF2705F9F5} - \CleanerPro_Popup No Task File <==== ATTENTION
C:\Program Files (x86)\PC Speed Up
EmptyTemp:
End

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST and press the Fix button just once and wait.
The tool will make a log (Fixlog.txt) please post it to your reply.

=========================

[external image: bullseye_zpse9eaf36e.gif] Re- run AdwCleaner

It should be on your desktop

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished…
  • This time, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a log file report (AdwCleaner[S1].txt) will open automatically.
  • Copy and paste the contents of that log file in your next reply.
  • A copy of that log file will also be saved in the C:\AdwCleaner folder.

=========================

[external image: bullseye_zpse9eaf36e.gif] Malwarebytes' Anti-Malware

Download Malwarebytes' Anti-Malware (save it to your desktop).

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Select Scan tab.
    [external image: MBAMDashboard_zpsddef9b5f.gif]
  • Select type of scan to perform:
    [external image: MBAMScanTab_zps2c5e74bd.gif]
    • Threat Scan < — Select this type of scan
    • Custom Scan
    • Hyper Scan
  • Next click the Scan button.
  • When the scan is complete, if no malicious items are found you can close the program.
  • If malicious items are found be sure that everything is checked, and click Quarantine .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

=========================

[external image: bullseye_zpse9eaf36e.gif] ESET Online Scanner

*Note:

  • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
  • Please don't go surfing while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.

** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notification Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Checked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.

=========================

In your next post please provide the following:

  • Fixlog.txt
  • AdwCleaner[S1].txt
  • MBAM log
  • ESET's log.txt
  • List of programs downloaded (if known).

Hiya OCD!  Hope all is well with you and yours.  

 

Regarding the files you asked about above: 

 

Slender_v0_9_7 (1).zip

 

is a game my son downloaded called "Slenderman".  The other two (fceux-2.2.2-win32.zip and 1964_11.rar) we don't recognize.

 

 

Here are the logs you requested:

 

Fixlog:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015
Ran by [removed] at 2015-02-01 15:20:53 Run:3
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
Start
CloseProcesses:
[GoogleChromeAutoLaunch_77DB27ED30D96DC6FB2B344658AE2828] => "C:\Users\Tim\AppData\Local\Vosteran\Application\vosteran.exe" –no-startup-window –auto-launch-at-startup –profile-directory="Default"
C:\Users\Tim\AppData\Local\Vosteran
2015-01-02 13:47 - 2015-01-02 13:48 - 04161288 _____ (Mindspark Interactive Network) C:\Users\Tim\Downloads\EliteUnzipSetup.EliteUnzip_aa.gafhhbahpojnjfhpepjjfjojbphnogmn.ch.exe
Task: {81DDFC05-7CD8-4A36-B7F9-803FEAAF25C5} - \CleanerPro_Start No Task File <==== ATTENTION
Task: {8B6E33A8-393C-4AE2-B8A1-DBDF2705F9F5} - \CleanerPro_Popup No Task File <==== ATTENTION
C:\Program Files (x86)\PC Speed Up
EmptyTemp:
End
*****************
 
Processes closed successfully.
[GoogleChromeAutoLaunch_77DB27ED30D96DC6FB2B344658AE2828] => "C:\Users\Tim\AppData\Local\Vosteran\Application\vosteran.exe" –no-startup-window –auto-launch-at-startup –profile-directory="Default" => Error: No automatic fix found for this entry.
"C:\Users\Tim\AppData\Local\Vosteran" => File/Directory not found.
C:\Users\Tim\Downloads\EliteUnzipSetup.EliteUnzip_aa.gafhhbahpojnjfhpepjjfjojbphnogmn.ch.exe => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{81DDFC05-7CD8-4A36-B7F9-803FEAAF25C5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81DDFC05-7CD8-4A36-B7F9-803FEAAF25C5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CleanerPro_Start" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8B6E33A8-393C-4AE2-B8A1-DBDF2705F9F5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B6E33A8-393C-4AE2-B8A1-DBDF2705F9F5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CleanerPro_Popup" => Key deleted successfully.
"C:\Program Files (x86)\PC Speed Up" => File/Directory not found.
EmptyTemp: => Removed 29.1 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 15:21:02 ====
 
 
 
adwCleaner:
 
# AdwCleaner v4.109 - Report created 01/02/2015 at 15:33:09
# Updated 24/01/2015 by Xplode
# Database : 2015-01-26.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Tim - INET
# Running from : C:\Users\Tim\Desktop\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Scheduled Tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17496
 
 
-\\ Mozilla Firefox v35.0.1 (x86 sv-SE)
 
 
-\\ Google Chrome v40.0.2214.93
 
 
-\\ Chromium v
 
 
*************************
 
AdwCleaner[R0].txt - [8477 octets] - [28/01/2015 12:08:18]
AdwCleaner[R1].txt - [921 octets] - [01/02/2015 15:30:57]
AdwCleaner[S0].txt - [9433 octets] - [28/01/2015 12:21:34]
AdwCleaner[S1].txt - [843 octets] - [01/02/2015 15:33:09]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [902 octets] ##########
 
 
 
MBAM:
 
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 2015-02-01
Scan Time: 15:39:06
Logfile: 
Administrator: Yes
 
Version: 2.00.4.1028
Malware Database: v2015.02.01.04
Rootkit Database: v2015.01.14.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Tim
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 326905
Time Elapsed: 7 min, 16 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 8
PUP.Optional.Vosteran, HKLM\SOFTWARE\CLASSES\APPID\{4CB3598A-82E8-4D1F-983F-061238AE696E}, Quarantined, [fa4e37e27317c175935ead4824de07f9], 
PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{4CB3598A-82E8-4D1F-983F-061238AE696E}, Quarantined, [fa4e37e27317c175935ead4824de07f9], 
PUP.Optional.Vosteran.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\Vosteran.WLEPV6PRAL74SKQKKKR2PIGHRQ, Quarantined, [0d3b60b9c9c1dc5a1274245de61d2bd5], 
PUP.Optional.Vosteran.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\vosteran.exe, Quarantined, [6ddb51c811793600fb400f768f7419e7], 
PUP.Optional.AceRace.A, HKLM\SOFTWARE\WOW6432NODE\ace race, Quarantined, [01472fea11796dc9e6a213719d66639d], 
PUP.Optional.Vosteran.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\Vosteran.WLEPV6PRAL74SKQKKKR2PIGHRQ, Quarantined, [c18726f3345692a48006b2cf7093b44c], 
PUP.Optional.Vosteran.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\vosteran.exe, Quarantined, [f45471a8b5d5b3832f0c8ff6659ea45c], 
PUP.Optional.AceRace.A, HKU\S-1-5-21-3767168050-546541148-904736753-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\ace race, Quarantined, [2a1eb2674743340226634143c53e8b75], 
 
Registry Values: 1
PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\WSE_Vosteran\\, Quarantined, [b197a2776a20cb6b8b81d237a3622ad6]
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 3
PUP.Optional.InstalleRex, C:\Users\Tim\Desktop\CR_Downloader_for_jnes.exe, Quarantined, [53f57a9f67236acccf8fc1979e635ba5], 
PUP.Optional.InstalleRex, C:\Users\Tim\Downloads\CR_Downloader_for_jnes.exe, Quarantined, [cd7b30e994f6fa3c89d5e57353aee21e], 
PUP.Optional.Vosteran.A, C:\Users\Tim\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Vosteran.lnk, Quarantined, [db6d58c105858caa1d1c88fd6d96d12f], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
 
Finally, ESETScan:
 
 
C:\Users\All Users\InstallMate\{1A2AA4CA-E484-4DED-AB21-4DB0B26238E8}\Custom.dll Win32/InstalleRex.L potentially unwanted application
C:\Users\All Users\InstallMate\{594DC170-1740-4BA9-AD65-BE74F1055D52}\Custom.dll Win32/InstalleRex.L potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\EliteUnzip\NativeMessagingDispatcher.dll.vir a variant of Win32/Toolbar.MyWebSearch.AO potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\EliteUnzip\Verify.dll.vir a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Surf annd ekeEp\_Z5n80M.dll.vir a variant of Win32/AdWare.MultiPlug.N application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Surf annd ekeEp\_Z5n80M.x64.dll.vir a variant of Win64/Adware.MultiPlug.A application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\surff annd kkeep\EIthAEIf.dll.vir a variant of Win32/AdWare.MultiPlug.N application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\surff annd kkeep\EIthAEIf.x64.dll.vir a variant of Win64/Adware.MultiPlug.A application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\YoutubeAdblocker\g_kyn6tJiP.dll.vir a variant of Win32/AdWare.MultiPlug.N application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\YoutubeAdblocker\g_kyn6tJiP.x64.dll.vir a variant of Win64/Adware.MultiPlug.A application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\ProgramData\surff annd kkeep\ymcZgDCvy.exe.vir a variant of Win32/AdWare.MultiPlug.K.gen application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Windows\System32\drivers\{4a90d0b9-0668-4ad5-92c2-d78786884485}Gw64.sys.vir a variant of Win64/BrowseFox.CG potentially unwanted application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Windows\System32\drivers\{56db9de0-c769-4563-8e82-7e39885bf1ad}Gw64.sys.vir a variant of Win64/BrowseFox.CG potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\plugins\acerace.BroStats.dll a variant of MSIL/BrowseFox.G potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\plugins\acerace.BrowserAdapter.dll a variant of MSIL/BrowseFox.L potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\plugins\acerace.ExpExt.dll a variant of MSIL/BrowseFox.L potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\plugins\acerace.FFUpdate.dll a variant of MSIL/BrowseFox.L potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\plugins\acerace.GCUpdate.dll a variant of MSIL/BrowseFox.L potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\plugins\acerace.IEUpdate.dll a variant of MSIL/BrowseFox.L potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\plugins\acerace.PurBrowseG.dll a variant of MSIL/BrowseFox.L potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\4a90d0b906684ad592c2.dll a variant of Win32/BrowseFox.N potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\4a90d0b906684ad592c264.dll a variant of Win64/BrowseFox.CI potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\4a90d0b906684ad592c2d78786884485.dll a variant of Win32/BrowseFox.M potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\4a90d0b906684ad592c2d7878688448564.dll a variant of Win64/BrowseFox.CH potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\56db9de0c76945638e82.dll a variant of Win32/BrowseFox.N potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\56db9de0c76945638e8264.dll a variant of Win64/BrowseFox.CI potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\56db9de0c76945638e827e39885bf1ad.dll a variant of Win32/BrowseFox.M potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\56db9de0c76945638e827e39885bf1ad64.dll a variant of Win64/BrowseFox.CH potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\acerace.BrowserAdapter.exe a variant of Win32/BrowseFox.AC potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\acerace.BrowserAdapter64.exe a variant of Win64/BrowseFox.CN potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\acerace.expext.exe a variant of Win32/BrowseFox.AA potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\acerace.expextdll.dll a variant of Win64/BrowseFox.CJ potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\acerace.PurBrowse64.exe a variant of Win64/BrowseFox.CL potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\bin\utilacerace.exe a variant of MSIL/BrowseFox.H potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\aceracebho.dll a variant of Win32/BrowseFox.O potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\aceraceUninstall.exe Win32/BrowseFox.C potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\ace race\updateacerace.exe a variant of MSIL/BrowseFox.H potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\MyPC Backup\MyPC Backup\BackupStackUI.dll a variant of MSIL/MyPCBackup.A potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\MyPC Backup\MyPC Backup\Configuration Updater.exe a variant of MSIL/RunElevated.A potentially unsafe application deleted - quarantined
C:\FRST\Quarantine\C\Program Files (x86)\MyPC Backup\MyPC Backup.exe.xBAD MSIL/MyPCBackup.E potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\ProgramData\Surf annd ekeEp\B1zeEWuh.exe a variant of Win32/AdWare.MultiPlug.K.gen application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiknpkdjaijoilnmlcmkgcelkafbnpbl\1.0.1_0\background.js Win32/BrowseFox.Q potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiknpkdjaijoilnmlcmkgcelkafbnpbl\1.0.1_0\content.js Win32/BrowseFox.Q potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\Tim\AppData\Local\Temp\APNSetup.exe.xBAD a variant of Win32/Bundled.Toolbar.Ask.E potentially unsafe application deleted - quarantined
C:\FRST\Quarantine\C\Users\Tim\AppData\Local\Temp\CloudBackup3885.exe.xBAD MSIL/MyPCBackup.D potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\Tim\AppData\Local\Temp\pcspeedup.exe.xBAD a variant of Win32/Speedchecker.B potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\Tim\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z\World Of WarCraft Packages\uninstaller.exe Win32/InstallCore.PC potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\Users\Tim\Downloads\EliteUnzipSetup.EliteUnzip_aa.gafhhbahpojnjfhpepjjfjojbphnogmn.ch.exe.xBAD a variant of Win32/Toolbar.MyWebSearch.AO potentially unwanted application deleted - quarantined
C:\ProgramData\InstallMate\{1A2AA4CA-E484-4DED-AB21-4DB0B26238E8}\Custom.dll Win32/InstalleRex.L potentially unwanted application deleted - quarantined
C:\ProgramData\InstallMate\{594DC170-1740-4BA9-AD65-BE74F1055D52}\Custom.dll Win32/InstalleRex.L potentially unwanted application deleted - quarantined
C:\Users\Tim\Downloads\WorldofWarCraft_Setup.exe a variant of Win32/InstallCore.WC potentially unwanted application deleted - quarantined
 

 

 

For what it's worth, while ESET was scanning the computer (we used explorer because it seemed easiest) two IE windows opened, one to an MMO called Pirates and another to a second MMO called Stormfall.  So at least we know what those are now.   :)  Don't know if ESET did something to trigger them or if they just oppened themselves after a period of time, since we don't ususally use IE as our standard browser.

 

So, what next?

 

:)

Hi Svinlesha,
 

one to an MMO called Pirates and another to a second MMO called Stormfall.

 

What does MMO mean?

=========================

[external image: bullseye_zpse9eaf36e.gif] Re-run Farbar Recovery Scan Tool it should be on your desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the tool opens click Yes to disclaimer.
  • Select the Addition box
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • It will also make (Addition.txt). Please attach it to your reply

=========================

In your next post please provide the following:

  • FRST.txt
  • Addition.txt
  • How is the computer running?

Hey OCD!

 

MMO = Massive Multiplayer Online, like for example World of Warcraft.  Ryzome, which we deleted earlier, is an MMO.  So ar Pirates and Stormfall, apparently.  Not all MMOs are on the up and up…some are pretty untrustworthy.  

 

FRST log:

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by [removed] (administrator) on INET on 03-02-2015 17:22:44
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Svenska (Sverige)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-28] (AVAST Software)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\Run: [GoogleChromeAutoLaunch_77DB27ED30D96DC6FB2B344658AE2828] => "C:\Users\Tim\AppData\Local\Vosteran\Application\vosteran.exe" –no-startup-window –auto-launch-at-startup –profile-directory="Default"
AppInit_DLLs-x32: C:/PROGRA~3/{C6092~1/190~1.1/rati.dll => "C:/PROGRA~3/{C6092~1/190~1.1/rati.dll" File Not Found
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.inet.se
HKU\S-1-5-21-3767168050-546541148-904736753-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.inet.se
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF ProfilePath: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\40hu7roo.default-1422549441719
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Tim\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3767168050-546541148-904736753-1000: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\allaannonser-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\prisjakt-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\tyda-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-sv-SE.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-sv-SE.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-27]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-22]
 
Chrome: 
=======
CHR Profile: C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Dokument) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-08]
CHR Extension: (Google Drive) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-08]
CHR Extension: (YouTube) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-08]
CHR Extension: (Battlefield Heroes) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2015-01-09]
CHR Extension: (Sök på Google) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-08]
CHR Extension: (Avast Online Security) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-08]
CHR Extension: (Google Wallet) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-08]
CHR Extension: (Gmail) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-08]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-04]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-04] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-12-04] (Avast Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-28] (Hi-Rez Studios) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-01-09] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-04] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-04] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-04] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-04] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-04] (AVAST Software)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [243200 2009-10-21] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
S3 IAMTVE; C:\Windows\system32\drivers\IAMTVE.sys [43416 2010-11-30] (Intel Corporation)
S3 IAMTXPE; C:\Windows\system32\drivers\IAMTXPE.sys [51096 2010-11-30] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-03] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [15416 2009-05-14] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-12-04] (Avast Software)
S3 aswVmm; \??\C:\Users\Tim\AppData\Local\Temp\aswVmm.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va029; \??\C:\Windows\SysWOW64\Drivers\X6va029 [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-03 17:22 - 2015-02-03 17:23 - 00014288 _____ () C:\Users\Tim\Desktop\FRST.txt
2015-02-03 17:20 - 2015-02-03 17:21 - 00000197 _____ () C:\Windows\system32\2015-02-03-16-20-26.044-AvastVBoxSVC.exe-3308.log
2015-02-01 15:57 - 2015-02-01 15:57 - 00000000 ____D () C:\Program Files (x86)\ESET
2015-02-01 15:54 - 2015-02-01 15:54 - 00000197 _____ () C:\Windows\system32\2015-02-01-14-54-28.088-AvastVBoxSVC.exe-3032.log
2015-02-01 15:38 - 2015-02-03 17:19 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-01 15:38 - 2015-02-01 15:38 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-01 15:38 - 2015-02-01 15:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-01 15:38 - 2015-02-01 15:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-01 15:38 - 2015-02-01 15:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-01 15:38 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-01 15:38 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-01 15:38 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-01 15:37 - 2015-02-01 15:37 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Tim\Desktop\mbam-setup-2.0.4.1028.exe
2015-02-01 15:36 - 2015-02-01 15:37 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Tim\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-01 15:36 - 2015-02-01 15:36 - 00000197 _____ () C:\Windows\system32\2015-02-01-14-36-40.026-AvastVBoxSVC.exe-3116.log
2015-02-01 15:24 - 2015-02-01 15:25 - 00000197 _____ () C:\Windows\system32\2015-02-01-14-24-43.096-AvastVBoxSVC.exe-3052.log
2015-02-01 14:47 - 2015-02-01 14:48 - 00000197 _____ () C:\Windows\system32\2015-02-01-13-47-33.049-AvastVBoxSVC.exe-3308.log
2015-01-31 11:30 - 2015-01-31 11:30 - 00001039 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\Users\Tim\AppData\Local\VS Revo Group
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\ProgramData\VS Revo Group
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2015-01-31 11:30 - 2015-01-31 11:30 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-01-31 11:30 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2015-01-31 11:29 - 2015-01-31 11:28 - 10801480 _____ (VS Revo Group ) C:\Users\Tim\Desktop\RevoUninProSetup.exe
2015-01-31 11:28 - 2015-01-31 11:28 - 10801480 _____ (VS Revo Group ) C:\Users\Tim\Downloads\RevoUninProSetup.exe
2015-01-31 11:23 - 2015-01-31 11:24 - 00000197 _____ () C:\Windows\system32\2015-01-31-10-23-26.018-AvastVBoxSVC.exe-3036.log
2015-01-29 18:25 - 2015-01-29 18:26 - 00000197 _____ () C:\Windows\system32\2015-01-29-17-25-57.087-AvastVBoxSVC.exe-3236.log
2015-01-29 18:17 - 2015-01-29 18:17 - 00000197 _____ () C:\Windows\system32\2015-01-29-17-17-03.025-AvastVBoxSVC.exe-2268.log
2015-01-29 17:37 - 2015-01-29 17:37 - 00000000 ____D () C:\Users\Tim\Desktop\Gammal Firefox-data
2015-01-29 17:10 - 2015-01-29 17:10 - 00000197 _____ () C:\Windows\system32\2015-01-29-16-10-08.084-AvastVBoxSVC.exe-2996.log
2015-01-28 12:48 - 2015-01-28 12:48 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-48-37.047-AvastVBoxSVC.exe-3220.log
2015-01-28 12:32 - 2015-01-28 12:32 - 00000000 ____D () C:\Windows\ERUNT
2015-01-28 12:30 - 2015-01-28 12:30 - 01707939 _____ (Thisisu) C:\Users\Tim\Desktop\JRT.exe
2015-01-28 12:26 - 2015-01-28 12:26 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-26-05.093-AvastVBoxSVC.exe-3520.log
2015-01-28 12:08 - 2015-02-01 15:33 - 00000000 ____D () C:\AdwCleaner
2015-01-28 12:06 - 2015-01-28 12:06 - 02194432 _____ () C:\Users\Tim\Desktop\AdwCleaner.exe
2015-01-28 12:02 - 2015-01-28 12:03 - 00000197 _____ () C:\Windows\system32\2015-01-28-11-02-45.051-AvastVBoxSVC.exe-1584.log
2015-01-27 18:40 - 2015-01-27 18:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-27 18:04 - 2015-02-03 17:22 - 00000000 ____D () C:\FRST
2015-01-27 18:02 - 2015-02-01 15:20 - 02131456 _____ (Farbar) C:\Users\Tim\Desktop\FRST64.exe
2015-01-27 17:37 - 2015-01-27 17:37 - 05198336 _____ (AVAST Software) C:\Users\Tim\Desktop\aswMBR.exe
2015-01-27 17:28 - 2015-01-27 17:28 - 00000197 _____ () C:\Windows\system32\2015-01-27-16-28-06.013-AvastVBoxSVC.exe-2452.log
2015-01-25 17:05 - 2015-01-25 17:05 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-05-46.072-AvastVBoxSVC.exe-2384.log
2015-01-25 17:00 - 2015-01-25 17:00 - 00000197 _____ () C:\Windows\system32\2015-01-25-16-00-29.011-AvastVBoxSVC.exe-1428.log
2015-01-25 16:18 - 2015-01-25 16:18 - 00000197 _____ () C:\Windows\system32\2015-01-25-15-18-00.026-AvastVBoxSVC.exe-2732.log
2015-01-25 09:39 - 2015-01-25 09:39 - 00000197 _____ () C:\Windows\system32\2015-01-25-08-39-04.097-AvastVBoxSVC.exe-3736.log
2015-01-25 09:36 - 2015-01-28 12:01 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-01-24 18:35 - 2015-01-25 17:35 - 00000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2015-01-24 17:57 - 2015-01-24 17:57 - 00001238 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2015-01-24 17:57 - 2015-01-24 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2015-01-24 17:55 - 2015-01-24 21:47 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2015-01-24 17:51 - 2015-01-24 17:51 - 02942368 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\World-of-Warcraft-Setup-enGB.exe
2015-01-24 17:38 - 2015-01-25 00:06 - 00000000 ____D () C:\Users\Tim\AppData\Local\Battle.net
2015-01-24 17:38 - 2015-01-24 17:55 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Battle.net
2015-01-24 17:38 - 2015-01-24 17:38 - 00000000 ____D () C:\Users\Tim\AppData\Local\Blizzard Entertainment
2015-01-24 17:37 - 2015-01-24 17:38 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-01-24 17:37 - 2015-01-24 17:37 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2015-01-24 17:36 - 2015-01-28 12:21 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks
2015-01-24 17:36 - 2015-01-28 12:21 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire
2015-01-24 17:36 - 2015-01-24 17:36 - 00003602 _____ () C:\Windows\System32\Tasks\Pirates WW1
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Pirates946
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pirates
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\GGEmpire441
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\WorldofTanks
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\GGEmpire
2015-01-24 17:36 - 2015-01-24 17:36 - 00000000 ____D () C:\ProgramData\Battle.net
2015-01-24 17:35 - 2015-01-29 17:23 - 00000000 ____D () C:\Users\Tim\AppData\Local\Pirates
2015-01-24 17:35 - 2015-01-24 17:35 - 123231216 _____ (Blizzard Entertainment) C:\Users\Tim\Downloads\WorldOfWarCraftSetup.exe
2015-01-24 17:34 - 2015-01-29 17:25 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00003664 _____ () C:\Windows\System32\Tasks\StormFall TW1
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2015-01-24 17:34 - 2015-01-24 17:34 - 00000000 ____D () C:\Users\Tim\AppData\Local\StormFall
2015-01-24 13:47 - 2015-01-24 13:48 - 00000197 _____ () C:\Windows\system32\2015-01-24-12-47-40.045-AvastVBoxSVC.exe-3452.log
2015-01-24 08:41 - 2015-01-24 08:41 - 00000197 _____ () C:\Windows\system32\2015-01-24-07-41-44.020-AvastVBoxSVC.exe-4040.log
2015-01-23 21:40 - 2015-01-23 21:40 - 00000197 _____ () C:\Windows\system32\2015-01-23-20-40-03.016-AvastVBoxSVC.exe-4508.log
2015-01-23 16:57 - 2015-01-23 16:58 - 00000197 _____ () C:\Windows\system32\2015-01-23-15-57-47.063-AvastVBoxSVC.exe-3636.log
2015-01-23 07:35 - 2015-01-23 07:36 - 00000197 _____ () C:\Windows\system32\2015-01-23-06-35-43.037-AvastVBoxSVC.exe-3552.log
2015-01-22 15:05 - 2015-01-22 15:06 - 00000197 _____ () C:\Windows\system32\2015-01-22-14-05-49.099-AvastVBoxSVC.exe-3720.log
2015-01-22 07:32 - 2015-01-22 07:32 - 00000197 _____ () C:\Windows\system32\2015-01-22-06-32-43.034-AvastVBoxSVC.exe-3040.log
2015-01-21 19:31 - 2015-01-21 19:32 - 00000000 ____D () C:\Users\Tim\Downloads\Slender_v0_9_7 (1)
2015-01-21 19:31 - 2015-01-21 19:31 - 00000000 ____D () C:\Users\Tim\Desktop\Slender v0.9.7
2015-01-21 19:23 - 2015-01-21 19:30 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7 (1).zip
2015-01-21 19:08 - 2015-01-21 19:09 - 00000197 _____ () C:\Windows\system32\2015-01-21-18-08-51.048-AvastVBoxSVC.exe-3480.log
2015-01-21 19:01 - 2015-01-21 19:01 - 65812970 _____ () C:\Users\Tim\Downloads\Slender_v0_9_7.zip
2015-01-21 14:27 - 2015-01-21 14:27 - 00000197 _____ () C:\Windows\system32\2015-01-21-13-27-01.087-AvastVBoxSVC.exe-2708.log
2015-01-21 06:17 - 2015-01-21 06:18 - 00000197 _____ () C:\Windows\system32\2015-01-21-05-17-40.013-AvastVBoxSVC.exe-3284.log
2015-01-21 05:32 - 2015-01-21 05:32 - 00000197 _____ () C:\Windows\system32\2015-01-21-04-32-11.025-AvastVBoxSVC.exe-2500.log
2015-01-20 15:42 - 2015-01-20 15:43 - 00000197 _____ () C:\Windows\system32\2015-01-20-14-42-54.082-AvastVBoxSVC.exe-3380.log
2015-01-20 07:21 - 2015-01-20 07:21 - 00000197 _____ () C:\Windows\system32\2015-01-20-06-21-05.091-AvastVBoxSVC.exe-3240.log
2015-01-19 13:43 - 2015-01-19 13:44 - 00000197 _____ () C:\Windows\system32\2015-01-19-12-43-55.039-AvastVBoxSVC.exe-3832.log
2015-01-19 07:27 - 2015-01-19 07:27 - 00000197 _____ () C:\Windows\system32\2015-01-19-06-27-12.003-AvastVBoxSVC.exe-3452.log
2015-01-18 09:31 - 2015-01-18 09:31 - 00000197 _____ () C:\Windows\system32\2015-01-18-08-31-40.030-AvastVBoxSVC.exe-3352.log
2015-01-17 09:13 - 2015-01-17 09:13 - 00000197 _____ () C:\Windows\system32\2015-01-17-08-13-20.071-AvastVBoxSVC.exe-3536.log
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieUserList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieSiteList
2015-01-16 18:40 - 2015-01-16 18:40 - 00000000 __SHD () C:\Users\Tim\AppData\Local\EmieBrowserModeList
2015-01-16 18:34 - 2015-01-16 18:34 - 00000222 _____ () C:\Users\Tim\Desktop\MicroVolts Surge.url
2015-01-16 17:58 - 2015-01-16 17:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-16-58-01.044-AvastVBoxSVC.exe-3048.log
2015-01-16 11:45 - 2015-01-16 11:45 - 00000197 _____ () C:\Windows\system32\2015-01-16-10-45-04.007-AvastVBoxSVC.exe-3160.log
2015-01-16 07:57 - 2015-01-16 07:58 - 00000197 _____ () C:\Windows\system32\2015-01-16-06-57-44.044-AvastVBoxSVC.exe-3596.log
2015-01-15 15:19 - 2015-01-15 15:19 - 00000197 _____ () C:\Windows\system32\2015-01-15-14-19-09.002-AvastVBoxSVC.exe-2148.log
2015-01-15 06:46 - 2015-01-15 06:46 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-46-18.056-AvastVBoxSVC.exe-3440.log
2015-01-15 06:42 - 2015-01-15 06:42 - 00000197 _____ () C:\Windows\system32\2015-01-15-05-42-40.094-AvastVBoxSVC.exe-2848.log
2015-01-14 16:29 - 2015-01-14 16:29 - 00000197 _____ () C:\Windows\system32\2015-01-14-15-29-36.005-AvastVBoxSVC.exe-3388.log
2015-01-14 14:43 - 2015-01-14 14:44 - 00000197 _____ () C:\Windows\system32\2015-01-14-13-43-43.031-AvastVBoxSVC.exe-2500.log
2015-01-14 07:51 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 07:51 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 07:51 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 07:51 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 07:51 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 07:51 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 07:51 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 07:51 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 07:51 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 07:51 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 07:51 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 07:51 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 07:48 - 2015-01-14 07:48 - 00000197 _____ () C:\Windows\system32\2015-01-14-06-48-14.075-AvastVBoxSVC.exe-1388.log
2015-01-13 14:37 - 2015-01-13 14:38 - 00000197 _____ () C:\Windows\system32\2015-01-13-13-37-39.065-AvastVBoxSVC.exe-3848.log
2015-01-13 07:54 - 2015-01-13 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-13-06-54-26.047-AvastVBoxSVC.exe-2908.log
2015-01-12 13:45 - 2015-01-12 13:45 - 00000197 _____ () C:\Windows\system32\2015-01-12-12-45-02.016-AvastVBoxSVC.exe-3228.log
2015-01-12 07:55 - 2015-01-12 07:55 - 00000197 _____ () C:\Windows\system32\2015-01-12-06-55-17.056-AvastVBoxSVC.exe-2700.log
2015-01-11 10:10 - 2015-01-11 10:10 - 00000197 _____ () C:\Windows\system32\2015-01-11-09-10-12.019-AvastVBoxSVC.exe-2992.log
2015-01-10 17:56 - 2015-01-10 17:56 - 08229276 _____ () C:\Users\Tim\Downloads\1964_11.rar
2015-01-10 17:54 - 2015-01-10 17:54 - 00065552 _____ () C:\Users\Tim\Downloads\Zelda_1.zip
2015-01-10 17:53 - 2015-01-10 17:53 - 03029593 _____ () C:\Users\Tim\Downloads\fceux-2.2.2-win32.zip
2015-01-10 17:14 - 2015-01-10 17:14 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Unity
2015-01-10 15:36 - 2015-01-10 15:36 - 00000197 _____ () C:\Windows\system32\2015-01-10-14-36-08.039-AvastVBoxSVC.exe-3096.log
2015-01-10 09:54 - 2015-01-10 09:55 - 00000197 _____ () C:\Windows\system32\2015-01-10-08-54-54.090-AvastVBoxSVC.exe-2936.log
2015-01-09 21:01 - 2015-01-10 12:43 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-01-09 21:00 - 2015-01-09 21:00 - 00000000 ____D () C:\Users\Tim\AppData\Local\PunkBuster
2015-01-09 19:26 - 2015-01-09 21:38 - 00000000 ____D () C:\Users\Tim\Documents\Battlefield Heroes
2015-01-09 19:25 - 2015-01-10 12:43 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-01-09 19:25 - 2015-01-10 10:12 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-01-09 19:25 - 2015-01-09 21:07 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-01-09 19:25 - 2015-01-09 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games
2015-01-09 19:23 - 2015-01-09 19:23 - 00000000 ____D () C:\Program Files (x86)\EA Games
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Users\Tim\AppData\Local\Ubisoft Game Launcher
2015-01-09 17:48 - 2015-01-09 17:48 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2015-01-09 15:13 - 2015-01-09 15:13 - 00000197 _____ () C:\Windows\system32\2015-01-09-14-13-11.016-AvastVBoxSVC.exe-3340.log
2015-01-09 11:45 - 2015-01-09 11:46 - 00000197 _____ () C:\Windows\system32\2015-01-09-10-45-23.092-AvastVBoxSVC.exe-3372.log
2015-01-09 07:47 - 2015-01-09 07:47 - 00000197 _____ () C:\Windows\system32\2015-01-09-06-47-16.002-AvastVBoxSVC.exe-3136.log
2015-01-08 15:07 - 2015-01-08 15:08 - 00000197 _____ () C:\Windows\system32\2015-01-08-14-07-54.027-AvastVBoxSVC.exe-3892.log
2015-01-08 07:33 - 2015-01-08 07:33 - 00000197 _____ () C:\Windows\system32\2015-01-08-06-33-12.020-AvastVBoxSVC.exe-2848.log
2015-01-07 10:19 - 2015-01-07 10:20 - 00000197 _____ () C:\Windows\system32\2015-01-07-09-19-56.023-AvastVBoxSVC.exe-2908.log
2015-01-06 12:11 - 2015-01-06 12:12 - 00000197 _____ () C:\Windows\system32\2015-01-06-11-11-48.071-AvastVBoxSVC.exe-2448.log
2015-01-05 07:53 - 2015-01-05 07:53 - 00000197 _____ () C:\Windows\system32\2015-01-05-06-53-36.086-AvastVBoxSVC.exe-3104.log
2015-01-04 17:51 - 2015-01-04 17:51 - 00000197 _____ () C:\Windows\system32\2015-01-04-16-51-18.021-AvastVBoxSVC.exe-3220.log
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-03 17:22 - 2013-09-30 14:37 - 02062749 _____ () C:\Windows\WindowsUpdate.log
2015-02-03 17:22 - 2010-11-21 12:38 - 00670622 _____ () C:\Windows\system32\perfh01D.dat
2015-02-03 17:22 - 2010-11-21 12:38 - 00146498 _____ () C:\Windows\system32\perfc01D.dat
2015-02-03 17:22 - 2009-07-14 06:13 - 01602714 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-03 17:20 - 2013-11-13 07:41 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-02-03 17:18 - 2014-08-08 10:43 - 00000990 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-03 17:18 - 2013-09-30 14:53 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-02-03 17:18 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-03 17:18 - 2009-07-14 05:51 - 00167841 _____ () C:\Windows\setupact.log
2015-02-03 17:17 - 2010-11-21 04:47 - 00103850 _____ () C:\Windows\PFRO.log
2015-02-01 17:50 - 2014-01-11 11:44 - 00000000 ____D () C:\Users\Tim\AppData\Local\PMB Files
2015-02-01 17:50 - 2014-01-11 11:44 - 00000000 ____D () C:\ProgramData\PMB Files
2015-02-01 17:40 - 2014-08-08 10:43 - 00000994 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-01 15:59 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-01 15:59 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-28 12:41 - 2014-08-08 10:44 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-28 12:00 - 2013-10-22 09:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-28 11:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2015-01-27 17:28 - 2009-07-14 03:34 - 00000505 _____ () C:\Windows\win.ini
2015-01-25 16:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
2015-01-24 17:35 - 2013-10-22 09:18 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-24 17:17 - 2013-10-22 09:51 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\.minecraft
2015-01-24 15:45 - 2013-10-23 08:34 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-16 19:34 - 2014-05-29 07:50 - 00000000 ____D () C:\Users\Tim\AppData\Local\Microsoft Games
2015-01-16 18:34 - 2013-10-23 09:01 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-01-14 08:28 - 2013-09-30 15:30 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 08:24 - 2013-09-30 15:30 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-09 18:07 - 2013-10-27 12:27 - 00267107 _____ () C:\Windows\DirectX.log
2015-01-09 17:53 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-06 04:36 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-05 18:16 - 2013-10-22 10:01 - 22764208 _____ () C:\Users\Tim\Desktop\TechnicLauncher.exe
2015-01-05 18:16 - 2013-10-22 10:01 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\.technic
 
==================== Files in the root of some directories =======
 
2015-01-24 18:35 - 2015-01-25 17:35 - 0000057 _____ () C:\Users\Tim\AppData\Roaming\WB.CFG
2013-11-28 18:17 - 2013-11-28 18:17 - 0000091 _____ () C:\Users\Tim\AppData\Local\fusioncache.dat
2014-10-04 13:14 - 2014-10-04 13:14 - 0000000 _____ () C:\Users\Tim\AppData\Local\{26F9D811-A740-4CF8-B01D-202083068605}
 
Some content of TEMP:
====================
C:\Users\Tim\AppData\Local\Temp\Quarantine.exe
C:\Users\Tim\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-01-24 16:08
 
==================== End Of Log ============================
 
 
Addition text:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015
Ran by [removed] at 2015-02-03 17:23:23
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 11 Plugin (HKLM-x32\…\Adobe Flash Player Plugin) (Version: 11.9.900.117 - Adobe Systems Incorporated)
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 10.0.2208 - AVAST Software)
Battle.net (HKLM-x32\…\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield Heroes (HKLM-x32\…\{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}) (Version:  - EA Digital illusions)
BioShock (HKLM-x32\…\Steam App 7670) (Version:  - 2K Boston)
Castle Crashers (HKLM-x32\…\Steam App 204360) (Version:  - The Behemoth)
Cleaner Pro (HKLM-x32\…\{AFC62A4A-BD08-4188-BA77-5F8BB8BCF18F}) (Version: 2.5.9 - Cleaner Pro)
Counter-Strike Nexon: Zombies (HKLM-x32\…\Steam App 273110) (Version:  - Nexon)
Counter-Strike: Source (HKLM-x32\…\Steam App 240) (Version:  - Valve)
Cry of Fear (HKLM-x32\…\Steam App 223710) (Version:  - Team Psykskallar)
Dungeons and Dragons Online (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\DDOen) (Version:  - )
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
F.E.A.R. Online (HKLM-x32\…\Steam App 223650) (Version:  - InPlay Interactive)
Forsaken World  (HKLM-x32\…\Steam App 36620) (Version:  - Perfect World Beijing)
Garry's Mod (HKLM-x32\…\Steam App 4000) (Version:  - Facepunch Studios)
Global Agenda (HKLM-x32\…\Steam App 17020) (Version:  - Hi-Rez Studios)
Global Agenda Live (HKLM-x32\…\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF001}) (Version: 1.5.1.5 - Hi-Rez Studios)
GoodGameEmpire (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\GoodGameEmpire) (Version:  - GoodGameEmpire) <==== ATTENTION!
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 40.0.2214.93 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Half-Life 2: Deathmatch (HKLM-x32\…\Steam App 320) (Version:  - Valve)
Half-Life 2: Lost Coast (HKLM-x32\…\Steam App 340) (Version:  - Valve)
Happy Cloud Client (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\HappyCloud) (Version: 3.41 - Happy Cloud, Inc.)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\…\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
Huawei Driver Installation (x32 Version: 1.0.0 - Huawei) Hidden
Java 7 Update 67 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
League of Legends (HKLM-x32\…\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Left 4 Dead 2 (HKLM-x32\…\Steam App 550) (Version:  - Valve)
Left 4 Dead 2 Beta (HKLM-x32\…\Steam App 223530) (Version:  - )
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 1.1 (HKLM-x32\…\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile Language Pack - SVE (HKLM\…\Microsoft .NET Framework 4 Client Profile SVE Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\…\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended Language Pack - SVE (HKLM\…\Microsoft .NET Framework 4 Extended SVE Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
MicroVolts Surge (HKLM-x32\…\Steam App 109400) (Version:  - NQ Games)
Mobile Broadband (x32 Version: 1.6 - Emotum) Hidden
Mozilla Firefox 35.0.1 (x86 sv-SE) (HKLM-x32\…\Mozilla Firefox 35.0.1 (x86 sv-SE)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
NVIDIA 3D Vision drivrutin 337.88 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 337.88 - NVIDIA Corporation)
NVIDIA 3D Vision drivrutin för styrenhet 337.88 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 337.88 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1 - NVIDIA Corporation)
NVIDIA Grafikdrivrutin 337.88 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation)
NVIDIA PhysX systemprogramvara 9.13.1220 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
ORION: Prelude (HKLM-x32\…\Steam App 104900) (Version:  - Spiral Game Studios)
Pando Media Booster (HKLM-x32\…\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
PunkBuster Services (HKLM-x32\…\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\…\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.34.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller Pro 3.1.2 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)
Shadow Warrior (HKLM-x32\…\Steam App 233130) (Version:  - Flying Wild Hog)
SHIELD Streaming (Version: 2.1.214 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Tactical Intervention (HKLM-x32\…\Steam App 51100) (Version:  - FIX Games)
Team Fortress 2 (HKLM-x32\…\Steam App 440) (Version:  - Valve)
Telenor Stay Connected (HKLM\…\Emotum Mobile Broadband) (Version: 1.6.3 - Emotum)
Torchlight II (HKLM-x32\…\Steam App 200710) (Version:  - Runic Games)
Torchlight II Demo (HKLM-x32\…\Steam App 219850) (Version:  - Runic Games)
Trials Fusion Demo (HKLM-x32\…\Steam App 294260) (Version:  - RedLynx, in collaboration with  Ubisoft Shanghai, Ubisoft Kiev)
Unity Web Player (HKU\S-1-5-21-3767168050-546541148-904736753-1000\…\UnityWebPlayer) (Version: 4.6.1f1 - Unity Technologies ApS)
Unturned (HKLM-x32\…\Steam App 304930) (Version:  - Nelson Sexton)
Uplay (HKLM-x32\…\Uplay) (Version: 4.3 - Ubisoft)
World of Warcraft (HKLM-x32\…\World of Warcraft) (Version:  - Blizzard Entertainment)
XCOM: Enemy Unknown Demo (HKLM-x32\…\Steam App 216690) (Version:  - Firaxis Games)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
 
==================== Restore Points  =========================
 
26-11-2014 18:43:37 Microsoft Visual C++ 2005 Redistributable (x64) installerades
26-11-2014 18:44:51 DirectX har installerats
28-11-2014 19:50:26 Windows Update
02-12-2014 10:37:28 Windows Update
04-12-2014 17:33:15 avast! antivirus system restore point
09-12-2014 07:55:41 Windows Update
10-12-2014 08:23:05 Windows Update
16-12-2014 07:52:23 Windows Update
19-12-2014 08:22:52 Windows Update
19-12-2014 23:16:14 DirectX har installerats
24-12-2014 09:44:08 Windows Update
28-12-2014 17:20:40 DirectX har installerats
30-12-2014 10:18:12 Windows Update
02-01-2015 12:05:42 Windows Update
06-01-2015 12:15:17 Windows Update
09-01-2015 17:47:10 DirectX har installerats
09-01-2015 18:06:44 DirectX har installerats
14-01-2015 07:51:12 Windows Update
14-01-2015 08:24:37 Windows Update
20-01-2015 07:24:48 Windows Update
21-01-2015 19:12:27 Uniblue PC Mechanic installation
23-01-2015 07:38:42 Windows Update
28-01-2015 12:06:02 Windows Update
31-01-2015 11:33:21 Revo Uninstaller Pro's restore point - Cleaner Pro
31-01-2015 11:34:21 Revo Uninstaller Pro's restore point - Cleaner Pro
31-01-2015 11:37:26 Revo Uninstaller Pro's restore point - GoodGameEmpire
31-01-2015 11:46:57 Revo Uninstaller Pro's restore point - GoodGameEmpire
31-01-2015 11:51:25 Revo Uninstaller Pro's restore point - Cleaner Pro
31-01-2015 11:55:38 Revo Uninstaller Pro's restore point - Cleaner Pro
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 03:34 - 2015-01-28 11:58 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {0954B156-7016-4593-9693-815C917DFE34} - System32\Tasks\Pirates WW1 => Chrome.exe –kiosk http://plarium.com/play/en/pirates/top/?adCampaign=42541&clickID;=tDtDtByEtC0D0CyEyEzy0F0AtDtByD0E&publisherID;=0_1_2
Task: {639E9174-0A15-4DEB-8A1A-54B49BDFE36D} - System32\Tasks\avastBCLRestartS-1-5-21-3767168050-546541148-904736753-1000 => Chrome.exe 
Task: {A575C369-FF15-421C-88C4-9F5D2FDA273C} - System32\Tasks\StormFall TW1 => Chrome.exe –app=http://plarium.com/play/en/stormfall/dragon04?adCampaign=44120&clickID;=tDtDtByEtC0D0CyEyEzy0F0AtDtByD0E&publisherID;=1_1_2 –app-window-size=1440,900
Task: {CF6900C0-2B9C-4E69-926A-43062E378EF7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-08] (Google Inc.)
Task: {D5ED21B8-3E4B-418C-9908-1B6315E656FA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-08] (Google Inc.)
Task: {FB026419-93C2-406B-8541-CE371B0C2FCA} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-12-04] (AVAST Software)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2013-09-30 14:53 - 2014-05-20 02:25 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-01-09 19:25 - 2015-01-09 21:07 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-12-04 17:34 - 2014-12-04 17:34 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2014-12-04 17:34 - 2014-12-04 17:34 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2015-02-01 14:47 - 2015-02-01 14:47 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15020100\algo.dll
2014-12-04 17:34 - 2014-12-04 17:34 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2015-02-03 17:20 - 2015-02-03 17:20 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15020300\algo.dll
2014-12-04 17:34 - 2014-12-04 17:34 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-01-28 12:41 - 2015-01-25 07:08 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\libglesv2.dll
2015-01-28 12:41 - 2015-01-25 07:08 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\libegl.dll
2015-01-28 12:41 - 2015-01-25 07:08 - 09170760 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\pdf.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: Emotum Mobile Broadband => C:\Program Files (x86)\Emotum\Mobile Broadband\Mobile.exe
MSCONFIG\startupreg: PCSpeedUp => C:\Program Files (x86)\PC Speed Up\PCSUNotifier.exe
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
 
========================= Accounts: ==========================
 
Administratör (S-1-5-21-3767168050-546541148-904736753-500 - Administrator - Disabled)
ASPNET (S-1-5-21-3767168050-546541148-904736753-1003 - Limited - Enabled)
Gäst (S-1-5-21-3767168050-546541148-904736753-501 - Limited - Disabled)
Tim (S-1-5-21-3767168050-546541148-904736753-1000 - Administrator - Enabled) => C:\Users\Tim
 
==================== Faulty Device Manager Devices =============
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (02/03/2015 05:19:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/01/2015 03:52:28 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/01/2015 03:34:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/01/2015 03:22:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/01/2015 02:47:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/31/2015 11:55:52 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll
 
Error: (01/31/2015 11:51:41 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll
 
Error: (01/31/2015 11:36:39 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll
 
Error: (01/31/2015 11:33:50 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll
 
Error: (01/31/2015 11:33:21 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Fel i tjänsten Volume Shadow Copy: Oväntat fel när gränssnittet IVssWriterCallback skulle erhållas.  hr = 0x80070005, Åtkomst nekad.
.
Det orsakas ofta av inkorrekta säkerhetsinställningar i processen för antingen skrivaren eller beställaren.
 
 
Åtgärd:
   Samlar in skrivardata
 
Kontext:
   Skrivarklass-ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Skrivarnamn: System Writer
   Skrivarinstans-ID: {5ba6c00a-eecd-471f-8e96-b33fcb1045b4}
 
 
System errors:
=============
Error: (02/01/2015 03:20:53 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Tjänsten Windows Search avslutades oväntat. Den har gjort detta 1 gång(er). Följande åtgärd kommer att utföras om 30000 millisekunder: Starta om tjänsten.
 
Error: (02/01/2015 03:20:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten Hi-Rez Studios Authenticate and Update Service avslutades oväntat. Detta har skett 1 gånger.
 
Error: (02/01/2015 03:20:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten PnkBstrA avslutades oväntat. Detta har skett 1 gånger.
 
Error: (02/01/2015 03:20:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten NVIDIA Streamer Service avslutades oväntat. Detta har skett 1 gånger.
 
Error: (02/01/2015 03:20:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten NVIDIA Network Service avslutades oväntat. Detta har skett 1 gånger.
 
Error: (02/01/2015 03:20:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten Skype Click to Call PNR Service avslutades oväntat. Detta har skett 1 gånger.
 
Error: (02/01/2015 03:20:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten Skype Click to Call Updater avslutades oväntat. Detta har skett 1 gånger.
 
Error: (02/01/2015 03:20:53 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Tjänsten Print Spooler avslutades oväntat. Den har gjort detta 1 gång(er). Följande åtgärd kommer att utföras om 60000 millisekunder: Starta om tjänsten.
 
Error: (02/01/2015 03:20:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten NVIDIA Stereoscopic 3D Driver Service avslutades oväntat. Detta har skett 1 gånger.
 
Error: (02/01/2015 03:20:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjänsten NVIDIA Display Driver Service avslutades oväntat. Detta har skett 1 gånger.
 
 
Microsoft Office Sessions:
=========================
Error: (02/03/2015 05:19:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/01/2015 03:52:28 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/01/2015 03:34:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/01/2015 03:22:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/01/2015 02:47:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (01/31/2015 11:55:52 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll (NULL)(NULL)(NULL)(NULL)(NULL)
 
Error: (01/31/2015 11:51:41 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll (NULL)(NULL)(NULL)(NULL)(NULL)
 
Error: (01/31/2015 11:36:39 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll (NULL)(NULL)(NULL)(NULL)(NULL)
 
Error: (01/31/2015 11:33:50 AM) (Source: MsiInstaller) (EventID: 11723) (User: Inet)
Description: Product: Cleaner Pro – Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor.  Action Uninst000.CA.dll_fix100, entry: CustomActionFix100, library: C:\Program Files (x86)\Cleaner Pro\Uninst000.CA.dll (NULL)(NULL)(NULL)(NULL)(NULL)
 
Error: (01/31/2015 11:33:21 AM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Åtkomst nekad.
 
 
Åtgärd:
   Samlar in skrivardata
 
Kontext:
   Skrivarklass-ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Skrivarnamn: System Writer
   Skrivarinstans-ID: {5ba6c00a-eecd-471f-8e96-b33fcb1045b4}
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz
Percentage of memory in use: 47%
Total physical RAM: 4091.48 MB
Available physical RAM: 2128.84 MB
Total Pagefile: 8181.15 MB
Available Pagefile: 5779.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:931.51 GB) (Free:490.7 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 8E7BE50A)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================
 
The computer seems to be running just fine – better in fact, than it has in a while.  
 
:)

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI