For about a week or so I have been getting terrible pop ups and redirects on my clicks that will open new tabs that I didn't even open. My home page has also been altered and I am unable to reliably use the computer unless it is in safe mode.
Any help is greatly appreciated to help fix this problem!
Here are the logs from the two scanning programs:
aswMBR
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-02-21 12:42:08
—————————–
12:42:08.888 OS Version: Windows x64 6.3.9600
12:42:08.888 Number of processors: 8 586 0x3C03
12:42:08.889 ComputerName: NATHAN UserName:
12:42:10.506 Initialize success
12:47:10.355 AVAST engine defs: 15022100
12:47:37.934 The log file has been saved successfully to "C:\Users\nathanw\Desktop\aswMBR.txt"
12:48:44.025 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000003e
12:48:44.026 Disk 0 Vendor: HGST_HTS721010A9E630 JB0OA3J0 Size: 953869MB BusType: 11
12:48:44.216 Disk 0 MBR read successfully
12:48:44.218 Disk 0 MBR scan
12:48:44.236 Disk 0 unknown MBR code
12:48:44.244 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
12:48:44.387 Disk 0 scanning C:\Windows\system32\drivers
12:48:55.435 Service scanning
12:49:09.913 Service serverca C:\Users\nathanw\AppData\Local\ConvertAd\CASrv.exe **INFECTED** Win32:Rootkit-gen [Rtk]
12:49:09.975 Service serverig C:\Users\nathanw\AppData\Local\igs\IGSrv.exe **INFECTED** Win32:Rootkit-gen [Rtk]
12:49:10.076 Service serversu C:\Users\nathanw\AppData\Roaming\SoftwareUpdater\SUsrv.exe **INFECTED** Win32:Rootkit-gen [Rtk]
12:49:16.546 Modules scanning
12:49:16.550 Disk 0 trace - called modules:
12:49:16.565 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll iaStorA.sys
12:49:16.568 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe00025ae5060]
12:49:16.570 3 CLASSPNP.SYS[fffff800b431727b] -> nt!IofCallDriver -> [0xffffe00023425e50]
12:49:16.572 5 ACPI.sys[fffff800b40ea7aa] -> nt!IofCallDriver -> \Device\0000003e[0xffffe00023423060]
12:49:18.439 AVAST engine scan C:\Windows
12:49:20.105 AVAST engine scan C:\Windows\system32
12:51:22.369 AVAST engine scan C:\Windows\system32\drivers
12:51:35.470 AVAST engine scan C:\Users\nathanw
12:51:36.398 File: C:\Users\nathanw\AppData\Local\ConvertAd\carunasu.exe **INFECTED** Win32:Malware-gen
12:51:36.425 File: C:\Users\nathanw\AppData\Local\ConvertAd\CASrv.exe **INFECTED** Win32:Rootkit-gen [Rtk]
12:52:47.402 File: C:\Users\nathanw\AppData\Local\igs\igs.exe **INFECTED** Win32:Dropper-gen [Drp]
12:52:47.440 File: C:\Users\nathanw\AppData\Local\igs\IGSrv.exe **INFECTED** Win32:Rootkit-gen [Rtk]
12:53:04.244 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\2PXWKNAU\dl[1].htm **INFECTED** Win32:Adware-gen [Adw]
12:53:25.521 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\BA4B78XG\dl[1].htm **INFECTED** Win32:Adware-gen [Adw]
12:53:35.202 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\BBGWMW46\dl[1].htm **INFECTED** Win32:Rootkit-gen [Rtk]
12:53:39.102 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\BBGWMW46\Setup[1].exe **INFECTED** Win32:Malware-gen
12:53:39.195 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\BBGWMW46\Setup[2].exe **INFECTED** Win32:Malware-gen
12:53:55.629 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\OD0H28WA\dl[2].htm **INFECTED** Win32:Rootkit-gen [Rtk]
12:54:03.607 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\PK09Y7LZ\carunasu[1].exe **INFECTED** Win32:Malware-gen
12:54:23.225 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\SLBT3JQL\ConvertAdSetup[1].exe **INFECTED** Win32:Adware-gen [Adw]
12:54:27.444 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\SLBT3JQL\VOPackage[1].exe **INFECTED** Win32:Dropper-gen [Drp]
12:54:30.590 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\WZ32XHW5\count_wp_ign[1].htm **INFECTED** Win32:Dropper-gen [Drp]
12:54:38.376 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\ZEFNFT72\CASrv[1].exe **INFECTED** Win32:Rootkit-gen [Rtk]
12:54:43.424 File: C:\Users\nathanw\AppData\Local\Microsoft\Windows\INetCache\IE\ZEFNFT72\WinCheckSetup[1].exe **INFECTED** Win32:Dropper-gen [Drp]
12:56:46.124 File: C:\Users\nathanw\AppData\Local\Temp\5E138365-D139-D924-E7D3-05D364FB07C1.exe **INFECTED** Win32:Adware-gen [Adw]
12:57:00.005 File: C:\Users\nathanw\AppData\Local\Temp\ICReinstall_nsmB328.tmp **INFECTED** Win32:Malware-gen
12:57:00.394 File: C:\Users\nathanw\AppData\Local\Temp\is45637729\74847631_stp\Generic_vo.exe **INFECTED** Win32:Dropper-gen [Drp]
12:57:02.319 File: C:\Users\nathanw\AppData\Local\Temp\n4028\VOPackage.exe **INFECTED** Win32:Dropper-gen [Drp]
12:57:03.975 File: C:\Users\nathanw\AppData\Local\Temp\nsa8472.tmp **INFECTED** Win32:Dropper-gen [Drp]
12:57:04.140 File: C:\Users\nathanw\AppData\Local\Temp\nsiD5.tmp **INFECTED** Win32:Malware-gen
12:57:04.193 File: C:\Users\nathanw\AppData\Local\Temp\nsmB328.tmp **INFECTED** Win32:Malware-gen
12:57:04.397 File: C:\Users\nathanw\AppData\Local\Temp\nsoF5FD.tmp **INFECTED** Win32:Malware-gen
12:57:04.453 File: C:\Users\nathanw\AppData\Local\Temp\nsoF5FE.tmp **INFECTED** Win32:Dropper-gen [Drp]
12:57:04.828 File: C:\Users\nathanw\AppData\Local\Temp\nsxDD4B.tmp **INFECTED** Win32:Adware-gen [Adw]
12:57:04.881 File: C:\Users\nathanw\AppData\Local\Temp\nsy37B8.tmp **INFECTED** Win32:Dropper-gen [Drp]
12:58:43.892 File: C:\Users\nathanw\AppData\Local\Temp\TDIR542F7706\SI.exe **INFECTED** Win32:Adware-gen [Adw]
12:58:43.983 File: C:\Users\nathanw\AppData\Local\Temp\TDIR542F7740\SI.exe **INFECTED** Win32:Adware-gen [Adw]
12:58:44.185 File: C:\Users\nathanw\AppData\Local\Temp\TDIR542F7751\SI.exe **INFECTED** Win32:Adware-gen [Adw]
12:59:01.771 File: C:\Users\nathanw\AppData\Local\wincheck\Uninstall.exe **INFECTED** Win32:Adware-gen [Adw]
12:59:01.820 File: C:\Users\nathanw\AppData\Local\wincheck\wincheck.exe **INFECTED** Win32:Adware-gen [Adw]
13:00:56.214 File: C:\Users\nathanw\AppData\Roaming\SoftwareUpdater\SUsrv.exe **INFECTED** Win32:Rootkit-gen [Rtk]
13:00:56.267 File: C:\Users\nathanw\AppData\Roaming\SoftwareUpdater\UpdateNotifier.exe **INFECTED** Win32:Adware-gen [Adw]
13:01:01.089 File: C:\Users\nathanw\AppData\Roaming\VOPackage\VOPackage.exe **INFECTED** Win32:Dropper-gen [Drp]
13:01:01.133 File: C:\Users\nathanw\AppData\Roaming\VOPackage\VOsrv.exe **INFECTED** Win32:Adware-gen [Adw]
13:01:01.632 File: C:\Users\nathanw\AppData\Roaming\WSE_Vosteran\UpdateProc\UpdateTask.exe **INFECTED** Win32:Dropper-gen [Drp]
13:01:11.331 File: C:\Users\nathanw\Downloads\Adobe_Reader_Setup.exe **INFECTED** Win32:Adware-gen [Adw]
13:01:20.867 File: C:\Users\nathanw\Downloads\Setup.exe **INFECTED** Win32:SoftPulse-DC [Adw]
13:01:29.827 AVAST engine scan C:\ProgramData
13:04:01.109 Disk 0 statistics 4498395/0/0 @ 2.93 MB/s
13:04:01.113 Scan finished successfully
13:13:00.724 Disk 0 MBR has been saved successfully to "C:\Users\nathanw\Desktop\MBR.dat"
13:13:00.727 The log file has been saved successfully to "C:\Users\nathanw\Desktop\aswMBR.txt"
FRST64
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-02-2015
Ran by [removed] (administrator) on NATHAN on 21-02-2015 13:17:18
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(OptimizerMonitor Inc.) C:\Program Files (x86)\IGS\OptimizerMonitor.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-04-23] (Realtek Semiconductor)
HKLM\…\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2014-04-23] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-30] (Intel Corporation)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891568 2014-04-23] (ELAN Microelectronics Corp.)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\…\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2014-01-02] (MSI)
HKLM\…\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [407720 2014-01-02] (MSI)
HKLM\…\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM-x32\…\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2013-08-16] (Creative Technology Ltd)
HKLM-x32\…\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\…\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\…\Run: [SUPER CHARGER] => C:\Program Files (x86)\MSI\SUPER CHARGER\SUPER CHARGER.exe [1047536 2014-02-21] (MSI)
HKLM-x32\…\Run: [PerforMax Cleaner] => C:\Program Files (x86)\PerforMax Cleaner\PerforMax Cleaner.exe [1490944 2014-09-08] ()
HKLM-x32\…\Run: [BService] => C:\Program Files (x86)\Bench\BService\1.1\bservice.exe
HKLM-x32\…\Run: [BService64] => C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe
HKLM-x32\…\Run: [Wd] => C:\Program Files (x86)\Bench\Wd\wd.exe
HKLM-x32\…\Run: [Bench Communicator Watcher] => C:\Program Files (x86)\Bench\Proxy\pwdg.exe
HKLM-x32\…\Run: [Bench Settings Cleaner] => C:\Program Files (x86)\Bench\Proxy\cl.exe
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\…\Run: [gmsd_us_163] => C:\Program Files (x86)\gmsd_us_163\gmsd_us_163.exe [3977576 2015-01-30] ()
HKLM-x32\…\Run: [WinCheck] => C:\Users\nathanw\AppData\Local\wincheck\wincheck.exe [415744 2015-01-31] ()
HKLM-x32\…\Run: [gmsd_us_165] => C:\Program Files (x86)\gmsd_us_165\gmsd_us_165.exe [3978088 2015-01-31] ()
HKLM-x32\…\Run: [SmartWeb] => C:\Users\nathanw\AppData\Local\SmartWeb\SmartWebHelper.exe [270696 2014-12-31] (SoftBrain Technologies Ltd.)
HKLM-x32\…\RunOnce: [upgmsd_us_163.exe] => C:\Users\nathanw\AppData\Local\gmsd_us_163\upgmsd_us_163.exe [3306464 2015-01-30] ()
HKLM-x32\…\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\nathanw\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat"
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [SteelSeries Engine] => C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe [249856 2014-01-23] (SteelSeries ApS)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [CyberGhost] => C:\Program Files\CyberGhost 5\CyberGhost.EXE [404080 2014-06-12] (CyberGhost S.R.L.)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [Driver Support] => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [5673824 2014-08-07] (PC Drivers Headquarters)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [Gameo] => C:\Users\nathanw\AppData\Roaming\Gameo\gameo.exe [42482176 2015-01-18] ()
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [SpeedTray] => C:\Users\nathanw\AppData\Roaming\SpeedTray\speedtray.exe [725518 2014-12-25] ()
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [TheAnswerFinder] => C:\Users\nathanw\AppData\Roaming\TheAnswerFinder\TheAnswerFinder.exe [1786312 2015-01-31] (Mime Ventures)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.38\OptProLauncher.exe [148024 2015-01-29] (PC Utilities Software Limited)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Run: [GoogleChromeAutoLaunch_E51A917143CE60DF87C6800984BEEDC2] => C:\Users\nathanw\AppData\Local\Vosteran\Application\vosteran.exe [1014272 2015-01-24] ()
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\nathanw\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat"
AppInit_DLLs-x32: C:/PROGRA~3/{A6374~1/191~1.1/dota.dll => C:/PROGRA~3/{A6374~1/191~1.1/dota.dll [964608 2015-02-01] ()
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [188224 2014-11-10] (Search Protect)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{29CDA0F1-A6DA-44CC-9ABB-131A7D3D77AE}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SafeConnect.lnk
ShortcutTarget: SafeConnect.lnk -> C:\Program Files (x86)\SafeConnect\SCClient.exe (Impulse Point, LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe ()
Startup: C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
Startup: C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OptimizerProInstaller.lnk
ShortcutTarget: OptimizerProInstaller.lnk -> C:\ProgramData\{2b6e2981-fd67-657c-2b6e-e2981fd6a607}\OptimizerProInstaller.exe (PC Utilities Software Limited)
Startup: C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
ShortcutTarget: SmartWeb.lnk -> C:\Users\nathanw\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.protectedio.com
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msi13.msn.com
SearchScopes: HKLM -> DefaultScope {AEAA03CB-A063-46DD-8F9D-9C73CB30B790} URL = http://astromenda.com/results.php?f=4&q;={searchTerms}&a;=ast_dnldstr_14_40_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtDtDyCtN1L2XzutAtFyDtFtCtFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FtA0DtD0EtB0BtG0BtC0B0FtG0AyDtC0AtGyD0E0EzztGyE0F0A0DzzyD0BzytA0FzzyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0DyCyEyE0AyEzztG0CyBtCzytGyE0D0F0BtGzytD0AyDtGtD0D0FyC0Ezzzy0DtA0FzzyE2Q&cr;=1440908205&ir;=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
SearchScopes: HKLM -> {AEAA03CB-A063-46DD-8F9D-9C73CB30B790} URL = http://astromenda.com/results.php?f=4&q;={searchTerms}&a;=ast_dnldstr_14_40_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtDtDyCtN1L2XzutAtFyDtFtCtFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FtA0DtD0EtB0BtG0BtC0B0FtG0AyDtC0AtGyD0E0EzztGyE0F0A0DzzyD0BzytA0FzzyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0DyCyEyE0AyEzztG0CyBtCzytGyE0D0F0BtGzytD0AyDtGtD0D0FyC0Ezzzy0DtA0FzzyE2Q&cr;=1440908205&ir;=
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid;=CT3330557&octid;=EB_ORIGINAL_CTID&ISID;=M05A97C27-B11B-4A1F-9195-35A3807ABEA1&SearchSource;=58&CUI;=&UM;=6&UP;=SP96CAD07F-DE2B-40FD-A8F7-F76C24BCEE5C&q;={searchTerms}&SSPV;=
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL =
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> {AEAA03CB-A063-46DD-8F9D-9C73CB30B790} URL = http://astromenda.com/results.php?f=4&q;={searchTerms}&a;=ast_dnldstr_14_40_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtDtDyCtN1L2XzutAtFyDtFtCtFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FtA0DtD0EtB0BtG0BtC0B0FtG0AyDtC0AtGyD0E0EzztGyE0F0A0DzzyD0BzytA0FzzyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0DyCyEyE0AyEzztG0CyBtCzytGyE0D0F0BtGzytD0AyDtGtD0D0FyC0Ezzzy0DtA0FzzyE2Q&cr;=1440908205&ir;=
SearchScopes: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = http://www.bing.com/search?FORM=U270DF&PC;=U270&q;={searchTerms}&src;=IE-SearchBox
BHO: Browser Warden BHO -> {2C09954F-CDA8-4BD1-8794-1D543E050378} -> C:\Program Files (x86)\Browser Warden\FrameworkBHO64.dll ()
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: SpeedChecker -> {3D9400B3-E14A-2220-608E-DE76BDA6A3AB} -> C:\Program Files (x86)\ver0SpeedChecker\187_x64.dll ()
BHO: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\dca-bho.dll (Compete, Inc.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Browser Warden BHO -> {2C09954F-CDA8-4BD1-8794-1D543E050378} -> C:\Program Files (x86)\Browser Warden\FrameworkBHO.dll No File
BHO-x32: SpeedChecker -> {3D9400B3-E14A-2220-608E-DE76BDA6A3AB} -> C:\Program Files (x86)\ver0SpeedChecker\187.dll ()
BHO-x32: Dolphin Deals -> {7c1ec179-be4e-4bee-b5a7-4596884bbc8d} -> C:\Program Files (x86)\Dolphin Deals\DolphinDealsbho.dll (Dolphin Deals)
BHO-x32: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-bho.dll (Compete, Inc.)
BHO-x32: SecureWebBHO Class -> {D3C24E2B-C820-4492-9B69-11BF7163F998} -> C:\Program Files (x86)\Jelbrus Secure Web\jsie.dll (Jelbrus)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Winsock: Catalog9 01 C:\Windows\SysWOW64\OptimizerMonitor.dll [301152] (OptimizerMonitor Inc.)
Winsock: Catalog9 02 C:\Windows\SysWOW64\OptimizerMonitor.dll [301152] (OptimizerMonitor Inc.)
Winsock: Catalog9 03 C:\Windows\SysWOW64\OptimizerMonitor.dll [301152] (OptimizerMonitor Inc.)
Winsock: Catalog9 04 C:\Windows\SysWOW64\OptimizerMonitor.dll [301152] (OptimizerMonitor Inc.)
Winsock: Catalog9 16 C:\Windows\SysWOW64\OptimizerMonitor.dll [301152] (OptimizerMonitor Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] [removed] [removed] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\nathanw\AppData\Roaming\Mozilla\Firefox\Profiles\frc79gxm.default
FF Homepage: search.protectedio.com
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\nathanw\AppData\Roaming\Mozilla\Firefox\Profiles\frc79gxm.default\user.js
FF Extension: Firefox Helper - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\52f49536d77819bae6f4abd24dce4dfb [2015-02-07]
FF HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Firefox\Extensions: [{57FC8B03-13E5-70AC-4016-0DB57BA53BDF}] - C:\Program Files (x86)\ver0SpeedChecker\187.xpi
FF Extension: SpeedChecker - C:\Program Files (x86)\ver0SpeedChecker\187.xpi [2015-01-31]
FF HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Firefox\Extensions: [ConsumerInput@Compete] - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12099.xpi
FF Extension: Consumer Input - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12099.xpi [2015-01-21]
FF HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://vosteran.com/?f=1&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
CHR StartupUrls: Default -> "hxxp://vosteran.com/?f=7&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=", "hxxp://www.trovi.com/?gd=&ctid;=CT3330557&octid;=EB_ORIGINAL_CTID&ISID;=M05A97C27-B11B-4A1F-9195-35A3807ABEA1&SearchSource;=55&CUI;=&UM;=6&UP;=SP96CAD07F-DE2B-40FD-A8F7-F76C24BCEE5C&SSPV;="
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://vosteran.com/results.php?f=4&q;={searchTerms}&a;=vst_cmi_15_05_ch&cd;=2XzuyEtN2Y1L1QzuyEyEzz0AyD0ByEyCtA0D0DtDyCtByCtDtN0D0Tzu0StCtCtByBtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StCyB0F0CyE0C0C0EtG0DtA0FyBtGtB0EyEtDtG0A0CyB0BtGyBzytC0B0FzzyBtAyCtBzyyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0ByByEtC0AzytDyBtGyCtD0DzytGyEtAyD0AtG0B0AtAzztGtBzzyByEzyzzzyyCyByByCyB2Q&cr;=379893325&ir;=
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR Profile: C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-01]
CHR Extension: (Adblock Plus) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-08]
CHR Extension: (Google Wallet) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-01]
CHR Extension: (oaepeijninfcgjdnighjnlgdkkgpnaen) - C:\Users\nathanw\AppData\Local\Google\Chrome\User Data\Default\Extensions\oaepeijninfcgjdnighjnlgdkkgpnaen [2015-02-08]
CHR HKLM\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [pfkfdlcdbajamklbneflfbcmfgddmpae] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [pfkfdlcdbajamklbneflfbcmfgddmpae] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [pfkfdlcdbajamklbneflfbcmfgddmpae] - https://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 4ef60154; c:\Program Files (x86)\Optimizer Pro 3.38\OptProMon.dll [1633848 2015-01-31] ()
S2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64624 2014-06-12] (CyberGhost S.R.L)
S2 ChromeEnhancer; C:\Program Files\ChromeEnhancer\ChromeEnhancer.exe [44544 2015-01-28] () [File not signed]
S2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
S2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [3056960 2014-11-10] (Search Protect)
S2 consumerinput_update; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [106296 2015-02-03] (ConsumerInput)
S3 consumerinput_updatem; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [106296 2015-02-03] (ConsumerInput)
S2 CrUwvroQ; C:\ProgramData\UDDNuLHc\CrUwvroQ.exe [2734864 2015-01-31] (Mathematical Applications)
S2 ETDService; C:\Program Files\Elantech\ETDService.exe [101680 2014-04-23] (ELAN Microelectronics Corp.)
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-01-31] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-01-31] (globalUpdate) [File not signed]
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-30] (Intel Corporation)
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-04-23] (Intel Corporation)
S2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
S2 itsvc_1.10.0.8; C:\Program Files (x86)\IntelliTerm_1.10.0.8\Service\itsvc.exe [278608 2015-01-21] (Intelli Term)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
S2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2014-01-02] (Micro-Star International Co., Ltd.) [File not signed]
S2 MSI_SuperCharger; C:\Program Files (x86)\MSI\SUPER CHARGER\ChargeService.exe [162800 2014-02-21] (MSI)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-10-11] ()
S2 NAT; C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\NAT.exe [232424 2013-10-11] (Symantec Corporation)
S2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4362056 2014-11-18] (Symantec Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2014-04-23] (NVIDIA Corporation)
R2 OptimizerMonitor; C:\Program Files (x86)\IGS\OptimizerMonitor.exe [1820240 2015-01-29] (OptimizerMonitor Inc.) [File not signed]
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-10-28] ()
S2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [344576 2014-03-04] (Qualcomm Atheros) [File not signed]
S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-04-23] (Realtek Semiconductor)
S2 SCManager; C:\Program Files (x86)\SafeConnect\scManager.sys [176520 2012-11-19] (Impulse Point, LLC)
S2 serverca; C:\Users\nathanw\AppData\Local\ConvertAd\CASrv.exe [93184 2015-02-01] () [File not signed]
S2 serverig; C:\Users\nathanw\AppData\Local\igs\IGSrv.exe [93696 2015-02-01] () [File not signed]
S2 serversu; C:\Users\nathanw\AppData\Roaming\SoftwareUpdater\SUsrv.exe [120832 2015-01-31] () [File not signed]
S2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [126568 2015-02-01] (RaMMicHaeL)
S2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [179200 2014-09-13] (Company) [File not signed]
S2 Wajam Web Enhancer; C:\Program Files\Wajam Web Enhancer\wajam_64.exe [2486272 2015-01-28] (Wajam_Internet Technologies Inc.) [File not signed] <==== ATTENTION
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-21] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-21] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3671792 2013-10-11] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [81072 2014-02-20] (Qualcomm Atheros, Inc.)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [63488 2014-04-24] (Microsoft Corporation) [File not signed]
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-11-07] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1411384 2013-11-07] (Motorola Solutions, Inc.)
S3 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0405000.009\ccSetx64.sys [150104 2013-07-29] (Symantec Corporation)
S1 ccSet_NAT; C:\Windows\system32\drivers\NATx64\010A000.009\ccSetx64.sys [150104 2013-07-29] (Symantec Corporation)
S3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [160464 2014-04-23] (Intel Corporation)
R1 itnfd_1_10_0_8; C:\Windows\System32\drivers\itnfd_1_10_0_8.sys [58232 2015-01-21] (Intelli Term)
R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [163536 2013-03-20] (Qualcomm Atheros, Inc.)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3607520 2013-10-14] (Intel Corporation)
S3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\SUPER CHARGER\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
S3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2014-04-23] (NVIDIA Corporation)
S3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [466648 2014-04-23] (Realsil Semiconductor Corporation)
S3 SAlphamBth; C:\Windows\System32\drivers\SAlphabt64.sys [31232 2012-10-16] (SteelSeries Corporation)
S3 SAlphamHid; C:\Windows\System32\drivers\SAlpham64.sys [38016 2013-05-31] (SteelSeries Corporation)
R3 SAlphaPS2; C:\Windows\System32\drivers\SAlphaPS264.sys [26496 2013-12-12] (SteelSeries Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-21] (Microsoft Corporation)
S3 WINIO; C:\Program Files (x86)\MSI\Dragon Gaming Center\winio64.sys [15160 2010-06-07] ()
S3 SPPD; \??\C:\Windows\system32\drivers\SPPD.sys [X]
U3 aswMBR; \??\C:\Users\nathanw\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\nathanw\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-21 13:17 - 2015-02-21 13:17 - 00029662 _____ () C:\Users\nathanw\Desktop\FRST.txt
2015-02-21 13:15 - 2015-02-21 13:17 - 00000000 ____D () C:\FRST
2015-02-21 13:15 - 2015-02-21 13:15 - 00000000 ____D () C:\Users\nathanw\Desktop\FRST-OlderVersion
2015-02-21 13:13 - 2015-02-21 13:13 - 00007124 _____ () C:\Users\nathanw\Desktop\aswMBR.txt
2015-02-21 13:13 - 2015-02-21 13:13 - 00000512 _____ () C:\Users\nathanw\Desktop\MBR.dat
2015-02-21 12:40 - 2015-02-21 13:15 - 02086912 _____ (Farbar) C:\Users\nathanw\Desktop\FRST64.exe
2015-02-21 12:39 - 2015-02-21 12:40 - 05198336 _____ (AVAST Software) C:\Users\nathanw\Desktop\aswMBR.exe
2015-02-15 15:40 - 2015-02-15 15:40 - 00002068 _____ () C:\Windows\SysWOW64\errordetails.xml
2015-02-13 13:27 - 2015-02-15 17:49 - 00000000 ____D () C:\Windows\pss
2015-02-12 15:32 - 2015-01-19 13:42 - 01487976 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2015-02-12 15:31 - 2015-02-03 18:38 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-12 15:31 - 2015-02-03 18:08 - 00761856 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-12 15:31 - 2015-02-03 18:08 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-12 15:31 - 2015-02-02 18:11 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-12 15:31 - 2015-02-02 18:11 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-12 15:31 - 2015-02-02 18:11 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-11 22:42 - 2015-01-10 03:22 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-10 17:29 - 2015-02-10 17:30 - 00015907 _____ () C:\Users\nathanw\Documents\nutritionlog.nathanwatts.xlsx
2015-02-10 17:29 - 2015-02-10 17:29 - 00081920 _____ () C:\Users\nathanw\Documents\nutrientreport.nathanwatts.xls
2015-02-09 21:39 - 2015-02-09 21:40 - 00081920 _____ () C:\Users\nathanw\Downloads\NutrientsReport.xls
2015-02-09 19:08 - 2015-02-09 21:39 - 00015877 _____ () C:\Users\nathanw\Documents\nutrition log.xlsx
2015-02-06 14:51 - 2015-02-07 15:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-06 14:51 - 2015-02-06 14:51 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-06 14:51 - 2015-02-06 14:51 - 00001173 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Mozilla
2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Mozilla
2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\ProgramData\Mozilla
2015-02-06 14:51 - 2015-02-06 14:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-06 14:50 - 2015-02-06 14:50 - 00243440 _____ () C:\Users\nathanw\Downloads\Firefox Setup Stub 35.0.1.exe
2015-02-05 01:27 - 2015-02-05 01:27 - 01246384 _____ () C:\Users\nathanw\Downloads\Installation.exe
2015-02-03 18:59 - 2015-02-03 18:59 - 00000000 ____D () C:\ProgramData\Browser
2015-02-03 18:53 - 2015-02-15 17:49 - 00000378 _____ () C:\Windows\Tasks\CIMT_S-1-5-21-3104748373-4178966826-1034322177-1002.job
2015-02-03 18:53 - 2015-02-12 18:53 - 00000412 _____ () C:\Windows\Tasks\CIMT_daily_S-1-5-21-3104748373-4178966826-1034322177-1002.job
2015-02-03 18:53 - 2015-02-03 18:53 - 00003384 _____ () C:\Windows\System32\Tasks\CIMT_daily_S-1-5-21-3104748373-4178966826-1034322177-1002
2015-02-03 18:53 - 2015-02-03 18:53 - 00003274 _____ () C:\Windows\System32\Tasks\CIMT_S-1-5-21-3104748373-4178966826-1034322177-1002
2015-02-03 18:53 - 2015-02-03 18:53 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Compete
2015-02-03 18:52 - 2015-02-15 17:47 - 00000982 _____ () C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job
2015-02-03 18:52 - 2015-02-13 14:57 - 00000986 _____ () C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job
2015-02-03 18:52 - 2015-02-03 18:53 - 00000000 ____D () C:\Program Files (x86)\Consumer Input
2015-02-03 18:52 - 2015-02-03 18:52 - 00003856 _____ () C:\Windows\System32\Tasks\ConsumerInputUpdateTaskMachineUA
2015-02-03 18:52 - 2015-02-03 18:52 - 00003620 _____ () C:\Windows\System32\Tasks\ConsumerInputUpdateTaskMachineCore
2015-02-03 18:52 - 2015-02-03 18:52 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Consumer Input
2015-02-01 18:23 - 2015-02-15 17:48 - 00383280 _____ () C:\Windows\system32\errordetails.xml
2015-02-01 00:21 - 2015-02-01 00:21 - 00000000 ____D () C:\BreakingNewsAlert
2015-02-01 00:06 - 2015-02-01 17:15 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vosteran
2015-02-01 00:06 - 2015-02-01 00:06 - 00000000 ____D () C:\Users\nathanw\AppData\Local\SmartWeb
2015-02-01 00:06 - 2015-02-01 00:06 - 00000000 ____D () C:\Users\nathanw\AppData\Local\gmsd_us_165
2015-02-01 00:06 - 2015-02-01 00:06 - 00000000 ____D () C:\Program Files (x86)\gmsd_us_165
2015-02-01 00:05 - 2015-02-13 15:06 - 00000314 _____ () C:\Windows\Tasks\WSE_Vosteran.job
2015-02-01 00:05 - 2015-02-13 13:34 - 00004904 _____ () C:\Windows\SysWOW64\OptimizerMonitor.ini
2015-02-01 00:05 - 2015-02-13 13:34 - 00002688 _____ () C:\Windows\SysWOW64\OptimizerMonitorOff.ini
2015-02-01 00:05 - 2015-02-13 13:34 - 00002688 _____ () C:\Windows\system32\OptimizerMonitorOff.ini
2015-02-01 00:05 - 2015-02-01 00:06 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Vosteran
2015-02-01 00:05 - 2015-02-01 00:05 - 00002652 _____ () C:\Windows\System32\Tasks\WSE_Vosteran
2015-02-01 00:05 - 2015-02-01 00:05 - 00000000 ____D () C:\Program Files (x86)\IGS
2015-02-01 00:05 - 2015-01-29 08:22 - 00301152 _____ (OptimizerMonitor Inc.) C:\Windows\SysWOW64\OptimizerMonitor.dll
2015-02-01 00:04 - 2015-02-13 15:04 - 00000782 _____ () C:\Windows\Tasks\Vosteran dota.job
2015-02-01 00:04 - 2015-02-01 17:16 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pirates
2015-02-01 00:04 - 2015-02-01 00:05 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\WSE_Vosteran
2015-02-01 00:04 - 2015-02-01 00:05 - 00000000 ____D () C:\Program Files (x86)\WSE_Vosteran
2015-02-01 00:04 - 2015-02-01 00:04 - 00003788 _____ () C:\Windows\System32\Tasks\Vosteran dota
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Pirates854
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Pirates
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Users\nathanw\AppData\Local\igs
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\ProgramData\Unchecky
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\ProgramData\{A6374EF4-F6B5-9F72-4733-EFF097B13C7E}
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Program Files (x86)\Unchecky
2015-02-01 00:04 - 2015-02-01 00:04 - 00000000 ____D () C:\Program Files (x86)\IntelliTerm_1.10.0.8
2015-01-31 23:58 - 2015-02-15 15:49 - 00003258 _____ () C:\Windows\System32\Tasks\Optimizer Pro Schedule
2015-01-31 23:58 - 2015-01-31 23:58 - 00000000 ____D () C:\Users\nathanw\Documents\Optimizer Pro
2015-01-31 23:58 - 2015-01-31 23:58 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Optimizer Pro
2015-01-31 23:56 - 2015-02-12 23:57 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\SoftwareUpdater
2015-01-31 23:56 - 2015-02-01 00:07 - 00000000 ____D () C:\Users\nathanw\AppData\Local\ConvertAd
2015-01-31 23:54 - 2015-02-15 17:47 - 00002466 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5_user.job
2015-01-31 23:54 - 2015-02-15 17:47 - 00002466 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5.job
2015-01-31 23:54 - 2015-02-11 22:59 - 00000000 ____D () C:\Users\nathanw\AppData\Local\BreakingNewsAlert
2015-01-31 23:54 - 2015-01-31 23:54 - 00005470 _____ () C:\Windows\System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5
2015-01-31 23:53 - 2015-02-15 17:47 - 00003494 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7.job
2015-01-31 23:53 - 2015-02-15 17:47 - 00003158 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6.job
2015-01-31 23:53 - 2015-02-01 00:07 - 00000000 ____D () C:\Users\nathanw\AppData\Local\wincheck
2015-01-31 23:53 - 2015-01-31 23:53 - 00006498 _____ () C:\Windows\System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7
2015-01-31 23:53 - 2015-01-31 23:53 - 00006162 _____ () C:\Windows\System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6
2015-01-31 23:52 - 2015-02-15 17:49 - 00002132 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-10_user.job
2015-01-31 23:52 - 2015-02-15 17:49 - 00000442 _____ () C:\Windows\Tasks\SpeedChecker Update.job
2015-01-31 23:52 - 2015-02-15 17:47 - 00005538 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-7.job
2015-01-31 23:52 - 2015-02-15 17:47 - 00005538 _____ () C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-6.job
2015-01-31 23:52 - 2015-02-15 17:47 - 00001018 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-01-31 23:52 - 2015-02-15 17:47 - 00000000 ____D () C:\Users\nathanw\AppData\Local\gmsd_us_163
2015-01-31 23:52 - 2015-02-13 13:32 - 00002085 _____ () C:\Windows\patsearch.bin
2015-01-31 23:52 - 2015-02-12 23:57 - 00001022 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-01-31 23:52 - 2015-02-03 18:46 - 00000000 ____D () C:\ProgramData\{2b6e2981-fd67-657c-2b6e-e2981fd6a607}
2015-01-31 23:52 - 2015-01-31 23:54 - 00000000 ____D () C:\ProgramData\UDDNuLHc
2015-01-31 23:52 - 2015-01-31 23:54 - 00000000 ____D () C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01
2015-01-31 23:52 - 2015-01-31 23:53 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\VOPackage
2015-01-31 23:52 - 2015-01-31 23:53 - 00000000 ____D () C:\Program Files (x86)\7d294cc7-8e3e-446e-9a9d-234f73b47a8d
2015-01-31 23:52 - 2015-01-31 23:52 - 00008542 _____ () C:\Windows\System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-7
2015-01-31 23:52 - 2015-01-31 23:52 - 00008542 _____ () C:\Windows\System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-6
2015-01-31 23:52 - 2015-01-31 23:52 - 00003994 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2015-01-31 23:52 - 2015-01-31 23:52 - 00003758 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2015-01-31 23:52 - 2015-01-31 23:52 - 00003086 _____ () C:\Windows\System32\Tasks\SpeedChecker Update
2015-01-31 23:52 - 2015-01-31 23:52 - 00003078 _____ () C:\Windows\System32\Tasks\RPC
2015-01-31 23:52 - 2015-01-31 23:52 - 00001125 _____ () C:\Users\nathanw\Desktop\Optimizer Pro.lnk
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNHKT_01009.Wdf
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GU Player
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Users\nathanw\AppData\Local\globalUpdate
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\ProgramData\BreakingNewsAlert
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Program Files (x86)\ver0SpeedChecker
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 3.38
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Program Files (x86)\GU Player
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Program Files (x86)\gmsd_us_163
2015-01-31 23:52 - 2015-01-31 23:52 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2015-01-31 23:51 - 2015-02-01 18:23 - 00000000 ____D () C:\Program Files (x86)\Regprocleaner
2015-01-31 23:51 - 2015-01-31 23:54 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\TheAnswerFinder
2015-01-31 23:51 - 2015-01-31 23:51 - 00001197 _____ () C:\Users\Public\Desktop\Reg Pro Cleaner.lnk
2015-01-31 23:51 - 2015-01-31 23:51 - 00001179 _____ () C:\Users\Public\Desktop\Regprocleaner.lnk
2015-01-31 23:51 - 2015-01-31 23:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Regprocleaner
2015-01-31 23:51 - 2015-01-31 23:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reg Pro Cleaner
2015-01-31 23:51 - 2015-01-31 23:51 - 00000000 ____D () C:\Program Files (x86)\Reg Pro Cleaner
2015-01-31 15:48 - 2015-01-31 15:48 - 00000001 _____ () C:\Users\Public\Documents\dgc.txt
2015-01-31 00:09 - 2015-01-31 00:09 - 00000000 ____D () C:\Program Files (x86)\Dolphin Deals
2015-01-31 00:06 - 2015-02-12 22:37 - 00003278 _____ () C:\Windows\System32\Tasks\Jelbrus Secure Web Task
2015-01-28 23:28 - 2015-01-28 23:28 - 00000000 ____D () C:\Program Files\ChromeEnhancer
2015-01-24 22:23 - 2015-01-24 22:23 - 00000000 ____D () C:\Users\nathanw\Desktop\New folder
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-21 12:47 - 2014-06-17 00:51 - 01126066 _____ () C:\Windows\WindowsUpdate.log
2015-02-21 12:29 - 2014-07-25 18:04 - 00000000 ____D () C:\Users\nathanw
2015-02-15 19:42 - 2013-11-13 12:03 - 00865408 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-15 19:41 - 2014-07-28 11:13 - 00000000 ____D () C:\Users\nathanw\AppData\Local\CrashDumps
2015-02-15 17:49 - 2013-08-22 09:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-15 17:47 - 2014-07-25 18:19 - 00000916 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-15 17:47 - 2013-08-22 09:46 - 00039837 _____ () C:\Windows\setupact.log
2015-02-15 15:49 - 2014-10-02 23:06 - 00003090 _____ () C:\Windows\System32\Tasks\RegClean Pro
2015-02-15 15:36 - 2014-07-25 18:19 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-13 15:25 - 2014-07-25 18:12 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3104748373-4178966826-1034322177-1002
2015-02-13 15:12 - 2014-10-02 23:07 - 00000314 _____ () C:\Windows\Tasks\UpdaterEX.job
2015-02-13 15:03 - 2014-10-02 23:10 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Gameo
2015-02-13 15:02 - 2014-10-02 23:06 - 00000276 _____ () C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2015-02-13 13:41 - 2013-08-22 10:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-02-13 13:39 - 2013-11-13 15:06 - 00000000 ____D () C:\ProgramData\boost_interprocess
2015-02-13 13:34 - 2014-10-05 01:36 - 00073728 _____ () C:\Windows\SysWOW64\tasks.dll
2015-02-13 00:01 - 2014-11-02 00:50 - 00000362 _____ () C:\Windows\Tasks\bench-S-1-5-21-3104748373-4178966826-1034322177-1002.job
2015-02-12 22:56 - 2013-08-22 09:44 - 00481880 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-12 22:55 - 2013-08-22 08:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-02-12 22:54 - 2014-12-14 16:33 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-12 22:54 - 2014-07-31 07:11 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-12 22:54 - 2014-07-28 11:16 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-12 22:54 - 2014-04-24 15:48 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-12 22:47 - 2014-07-28 11:16 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-12 22:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-02-12 22:38 - 2014-07-25 18:17 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{62839BE3-D084-47BD-A73F-8EB4F8423EF9}
2015-02-12 16:05 - 2014-10-03 00:06 - 00000079 _____ () C:\Users\nathanw\AppData\Roaming\WB.CFG
2015-02-12 15:13 - 2014-08-15 15:31 - 00000000 ____D () C:\Program Files (x86)\SafeConnect
2015-02-10 17:52 - 2014-07-25 18:39 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-10 17:44 - 2014-07-25 18:05 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Packages
2015-02-09 16:43 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-02-03 18:45 - 2014-09-25 22:41 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Skype
2015-02-03 14:31 - 2014-08-02 10:51 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-03 14:31 - 2014-08-02 10:51 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-01 18:20 - 2013-11-13 11:53 - 01195148 _____ () C:\Windows\PFRO.log
2015-02-01 00:03 - 2014-09-09 16:40 - 00000000 ____D () C:\Users\nathanw\AppData\Local\Adobe
2015-01-31 23:53 - 2014-07-26 09:26 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2015-01-31 00:05 - 2014-07-25 18:19 - 00002285 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-28 23:06 - 2014-10-02 23:06 - 00000284 _____ () C:\Windows\Tasks\RegClean Pro_UPDATES.job
2015-01-28 15:44 - 2014-09-25 22:38 - 00000000 ____D () C:\Program Files\Wajam Web Enhancer
2015-01-24 22:16 - 2014-10-02 23:10 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Gameo
2015-01-22 21:18 - 2014-07-25 18:06 - 00000000 ____D () C:\Users\nathanw\AppData\Roaming\Adobe
==================== Files in the root of some directories =======
2014-10-03 00:06 - 2015-02-12 16:05 - 0000079 _____ () C:\Users\nathanw\AppData\Roaming\WB.CFG
2014-11-02 20:31 - 2014-12-27 14:47 - 0000003 _____ () C:\Users\nathanw\AppData\Local\proxy.log
2014-09-01 22:04 - 2014-09-01 22:04 - 0000000 _____ () C:\Users\nathanw\AppData\Local\{C03E1153-99E9-4E26-8BFE-471025ABE5FF}
Some content of TEMP:
====================
C:\Users\nathanw\AppData\Local\Temp\5E138365-D139-D924-E7D3-05D364FB07C1.dll
C:\Users\nathanw\AppData\Local\Temp\5E138365-D139-D924-E7D3-05D364FB07C1.exe
C:\Users\nathanw\AppData\Local\Temp\7675_.exe
C:\Users\nathanw\AppData\Local\Temp\8658_.exe
C:\Users\nathanw\AppData\Local\Temp\9686FB06-6AC9-7F61-45F2-378B0915C505.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup0216__7675.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup2481__7675.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup4018__7675.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup4390__8658.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup5092__7675.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup5140__8658.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup5683__9288.exe
C:\Users\nathanw\AppData\Local\Temp\amisetup5731__7675.exe
C:\Users\nathanw\AppData\Local\Temp\CloudBackup83.exe
C:\Users\nathanw\AppData\Local\Temp\ConsumerInputSetup.exe
C:\Users\nathanw\AppData\Local\Temp\cubfmglb.0eo.exe
C:\Users\nathanw\AppData\Local\Temp\hotzenplotz.exe
C:\Users\nathanw\AppData\Local\Temp\nsf2140.exe
C:\Users\nathanw\AppData\Local\Temp\optprosetup.exe
C:\Users\nathanw\AppData\Local\Temp\SpOrder.dll
C:\Users\nathanw\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-12 23:30
==================== End Of Log ============================
Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-02-2015
Ran by [removed] at 2015-02-21 13:17:57
Running from C:\Users\[removed]\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\uTorrent) (Version: 3.4.2.36802 - BitTorrent Inc.)
Adobe Reader XI (11.0.10) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Battery Calibration (HKLM-x32\…\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.1402.2101 - Micro-Star International Co., Ltd.)
BioShock Infinite (HKLM-x32\…\Steam App 8870) (Version: - Irrational Games)
Bitcoin Core (64-bit) (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Bitcoin Core (64-bit)) (Version: 0.9.2 - Bitcoin Core project)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Boot Configure (HKLM\…\{5DEFD958-7239-4FA0-8B4E-3B532D7A14BF}) (Version: 10.014.02075 - Application)
Browser Warden (HKLM-x32\…\39012_Browser Warden) (Version: 1.0 - Gratifying Apps) <==== ATTENTION
BurnRecovery (HKLM-x32\…\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 4.0.1309.301 - )
Chivalry: Medieval Warfare (HKLM-x32\…\Steam App 219640) (Version: - Torn Banner Studios)
CinPlus-Pro 2.5pV31.01 (HKLM-x32\…\CinPlus-Pro 2.5pV31.01) (Version: 1.36.01.22 - CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Consumer Input (remove only) (HKLM-x32\…\Consumer Input Installer) (Version: - Compete Inc.) <==== ATTENTION
ConvertAd (HKLM-x32\…\ConvertAd) (Version: 1.0.0.0 - ConvertAd) <==== ATTENTION
Counter-Strike: Global Offensive (HKLM-x32\…\Steam App 730) (Version: - Valve)
CyberGhost 5 (HKLM\…\CyberGhost 5_is1) (Version: - CyberGhost S.R.L.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5509.52 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dolphin Deals (HKLM\…\Dolphin Deals) (Version: 2014.08.12.215047 - Dolphin Deals) <==== ATTENTION
download-free-soft bundle uninstaller (HKLM-x32\…\download-free-soft bundle uninstaller) (Version: 2.0.1.0 - download-free-soft)
Dragon Gaming Center (HKLM-x32\…\InstallShield_{965B16C7-0778-4C45-B7D1-83A59E6FBBCB}) (Version: 1.0.1403.0501 - Micro-Star International Co., Ltd.)
Dragon Gaming Center (x32 Version: 1.0.1403.0501 - Micro-Star International Co., Ltd.) Hidden
Driver Support (HKLM-x32\…\{597FB4A5-DD86-4316-A410-7E8074CC2CCE}) (Version: 9.1.4.4 - PC Drivers Headquarters, LP)
ETDWare PS/2-X64 11.13.6.2_WHQL (HKLM\…\Elantech) (Version: 11.13.6.2 - ELAN Microelectronic Corp.)
Extended Update (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\UpdaterEX) (Version: - Extended Update) <==== ATTENTION
FlacSquisher 1.3.4 (HKLM-x32\…\FlacSquisher) (Version: 1.3.4 - FlacSquisher)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galeria de Fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Gameo (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Gameo) (Version: 0.10.5 - Fried Cookie Software) <==== ATTENTION!
GamesDesktop 025.163 (HKLM-x32\…\gmsd_us_163_is1) (Version: - GAMESDESKTOP) <==== ATTENTION
GamesDesktop 025.165 (HKLM-x32\…\gmsd_us_165_is1) (Version: - GAMESDESKTOP) <==== ATTENTION
GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 40.0.2214.94 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
GU Player (remove only) (HKLM-x32\…\GU Player) (Version: - )
Hitman: Absolution (HKLM-x32\…\Steam App 203140) (Version: - IO Interactive)
IGS (HKLM-x32\…\IGS) (Version: - ) <==== ATTENTION!
igsc (HKLM-x32\…\igsc) (Version: 1.0.0.0 - igs) <==== ATTENTION!
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\…\{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}) (Version: 1.1.0.36960 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 17.0.1405.3) (HKLM\…\{302600C1-6BDF-4FD1-1312-148929CC1385}) (Version: 17.0.1312.0414 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.2.1000 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{105fa5c4-72e1-41f2-a82c-884d8aa4b381}) (Version: 16.6.0 - Intel Corporation)
Intelli Term 1.10.0.8 (HKLM-x32\…\IntelliTerm_1.10.0.8) (Version: 1.10.0.8 - Intelli Term)
iTunes (HKLM\…\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Just Cause 2 (HKLM-x32\…\Steam App 8190) (Version: - Avalanche Studios)
Just Cause 2: Multiplayer Mod (HKLM-x32\…\Steam App 259080) (Version: - Avalanche Studios)
KB9X Radio Switch Driver (HKLM\…\5AADE1068CF70DD983F763B20CF2CAAB72883915) (Version: 1.1.0.0 - ENE TECHNOLOGY INC.)
K-Lite Codec Pack 10.6.5 Basic (HKLM-x32\…\KLiteCodecPack_is1) (Version: 10.6.5 - )
Left 4 Dead 2 (HKLM-x32\…\Steam App 550) (Version: - Valve)
MAGIX MX Suite (HKLM-x32\…\MAGIX_{43136332-880B-458A-966C-900C18752B66}) (Version: 1.13.0.121 - MAGIX AG)
MAGIX MX Suite (Version: 1.13.0.121 - MAGIX AG) Hidden
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\…\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
Microsoft Office 365 - en-us (HKLM\…\O365HomePremRetail - en-us) (Version: 15.0.4675.1003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 35.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla)
MSI Remind Manager (HKLM-x32\…\InstallShield_{3E23F267-3E35-40F9-B6BF-BC034D214717}) (Version: 1.0.1404.1101 - Micro-Star International Co., Ltd.)
MSI Remind Manager (x32 Version: 1.0.1404.1101 - Micro-Star International Co., Ltd.) Hidden
MSI Social Media Collection (HKLM-x32\…\{7ADEC426-BE95-48EF-84D4-086BD0F4D331}) (Version: 1.14.2251 - Micro-Star International Co., Ltd.)
MyPC Backup (HKLM\…\MyPC Backup) (Version: - JDi Backup Ltd) <==== ATTENTION
News Alert (HKLM-x32\…\BreakingNewsAlert) (Version: 2.7.56 - Mathematical Applications)
Norton Anti-Theft (HKLM-x32\…\NAT) (Version: 1.10.0.9 - Symantec Corporation)
Norton Online Backup (HKLM-x32\…\{652C1CDF-C61D-4525-9348-8C272CC2DB24}) (Version: 2.10.1.3 - Symantec Corporation)
Norton Online Backup (x32 Version: 4.5.0.9 - Symantec Corporation) Hidden
NVIDIA GeForce Experience 1.7.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.7.1 - NVIDIA Corporation)
NVIDIA Graphics Driver 332.35 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.35 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\…\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA Virtual Audio 1.2.9 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.9 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Optimizer Pro v3.2 (HKLM-x32\…\Optimizer Pro_is1) (Version: 3.2.0.3 - PC Utilities Software Limited) <==== ATTENTION
PAYDAY 2 (HKLM-x32\…\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.)
PerforMax Cleaner (HKLM-x32\…\{e37dc69e-51a7-48de-bbc9-d0f300dbe5e0}) (Version: 1.0.0.0 - OneBit IT)
PerforMax Cleaner (x32 Version: 1.0.0.0 - OneBit IT) Hidden
Pirates (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Pirates) (Version: - Pirates) <==== ATTENTION!
Popcorn Time (HKLM-x32\…\Popcorn Time_is1) (Version: Beta 4.3 - Popcorn Time)
PunkBuster Services (HKLM-x32\…\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
Qualcomm Atheros Bandwidth Control Filter Driver (Version: 1.1.41.1283 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer E220x Drivers (Version: 1.1.41.1283 - Qualcomm Atheros) Hidden
Qualcomm Atheros Network Manager (Version: 1.1.41.1283 - Qualcomm Atheros) Hidden
Qualcomm Atheros Performance Suite (HKLM-x32\…\{68DD86DD-8E02-4921-926B-B358D51EAF3A}) (Version: 1.1.41.1283 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21249 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7179 - Realtek Semiconductor Corp.)
RegClean-Pro (HKLM-x32\…\RegClean-Pro_is1) (Version: 6.21 - Systweak Inc) <==== ATTENTION
Regprocleaner version 2.0 (HKLM-x32\…\{6406DF9F-E9C8-4C2E-AB48-80352BDF5099}_is1) (Version: 2.0 - Regprocleaner)
Remote Desktop Access (VuuPC) (HKLM-x32\…\VOPackage) (Version: 1.0.0.0 - CMI Limited) <==== ATTENTION
Rising Storm/Red Orchestra 2 Multiplayer (HKLM-x32\…\Steam App 35450) (Version: - Tripwire Interactive)
SafeConnect (HKLM-x32\…\SafeConnect) (Version: - )
SCM (HKLM\…\{6692DCAF-A445-4C6B-AF31-3DD85FC06FBA}) (Version: 13.014.01026 - Application)
Search Protect (HKLM-x32\…\SearchProtect) (Version: 2.18.20.209 - Search Protect) <==== ATTENTION
SHIELD Streaming (Version: 1.6.53 - NVIDIA Corporation) Hidden
Skype™ 6.21 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
SmartWeb (HKLM-x32\…\SmartWeb) (Version: 8.0.6 - SoftBrain Technologies Ltd.) <==== ATTENTION
Sniper Elite V2 (HKLM-x32\…\Steam App 63380) (Version: - Rebellion)
Software Updater (HKLM-x32\…\SoftwareUpdater) (Version: 1.0.0.0 - Software Updater Ltd)
Sophos Virus Removal Tool (HKLM-x32\…\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.3 - Sophos Limited)
Sound Blaster Cinema (HKLM-x32\…\{8801CA65-921A-4CCC-9D63-879D1D0BAA97}) (Version: 1.00.05 - Creative Technology Limited)
SpeedChecker (HKLM-x32\…\04B239F6-D435-4A0C-F65E-9F1C99811569) (Version: - SpeedChecker-software) <==== ATTENTION
Steam (HKLM-x32\…\Steam) (Version: - Valve Corporation)
SteelSeries Engine (HKLM\…\SteelSeries Engine) (Version: 2.8.417.28061 - SteelSeries)
SteelSeries Engine 3.2.6 (HKLM\…\SteelSeries Engine 3) (Version: 3.2.6 - SteelSeries ApS)
SUPER CHARGER (HKLM-x32\…\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.024 - MSI)
TAP-Windows 9.9.2 (HKLM\…\TAP-Windows) (Version: 9.9.2 - )
TheAnswerFinder (HKLM\…\TheAnswerFinder) (Version: 1.0.7 - TheAnswerFinder)
Unchecky v0.3.6 (HKLM-x32\…\Unchecky) (Version: 0.3.6 - RaMMicHaeL)
Vosteran (HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\…\Vosteran) (Version: 31.0.1650.23 - Vosteran) <==== ATTENTION!
Wajam (HKLM-x32\…\Wajam Web Enhancer) (Version: 1.0.6.38 (i1.0) - Wajam) <==== ATTENTION
WinCheck (HKLM-x32\…\wincheck) (Version: 1.0.0.0 - WinCheck) <==== ATTENTION!
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinZip 17.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DD}) (Version: 17.5.10562 - WinZip Computing, S.L. )
WSE_Astromenda (HKLM-x32\…\WSE_Astromenda) (Version: - WSE_Astromenda) <==== ATTENTION!
WSE_Vosteran (HKLM-x32\…\WSE_Vosteran) (Version: - WSE_Vosteran) <==== ATTENTION!
XSplit Gamecaster (HKLM-x32\…\{9C3D0D0D-3983-4C18-91EE-C6976D5AA349}) (Version: 1.5.1403.1907 - SplitMediaLabs)
フォト ギャラリー (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
معرض الصور (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
사진 갤러리 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
影像中心 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
照片库 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-3104748373-4178966826-1034322177-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\nathanw\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation)
==================== Restore Points =========================
10-01-2015 13:20:58 Scheduled Checkpoint
15-01-2015 17:11:02 Windows Update
23-01-2015 16:25:18 Windows Update
27-01-2015 14:22:22 Windows Update
08-02-2015 02:44:12 Windows Update
12-02-2015 22:46:25 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 08:25 - 2015-02-13 13:32 - 00002034 ____A C:\Windows\system32\Drivers\etc\hosts
0.0.0.0 .psf
0.0.0.0 psf
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
0.0.0.0 cdn.appround.biz
There are 6 more lines.
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {01837989-FBD1-4B28-9DB4-B919FD74211D} - System32\Tasks\Driver Support-RTMUpdater => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {0A149050-CB32-4D8F-B30C-F6EBB0DD48B7} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {0D149001-107B-426A-B29D-652D7F68E53E} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-08-29] () <==== ATTENTION
Task: {1148FEDC-2318-4CE0-B90A-1D8A08101811} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-11-04] (Microsoft Corporation)
Task: {21360565-4733-4D63-93D2-C480E8948889} - System32\Tasks\gameo_update => C:\Users\nathanw\AppData\Roaming\Gameo\gameo.exe [2015-01-18] ()
Task: {221BCF22-52D9-40FB-80E7-59972D7D690A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-25] (Google Inc.)
Task: {27902362-EB83-4D3D-A103-522639358B67} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {2C4C7E11-034E-4C87-A73F-5BAA2A50817F} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-7 => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-7.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {33751216-1BFC-4DBC-8F1C-5FBE754275FD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {33D088CC-A6F3-49A3-B1E2-9F5A631F3C01} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-11-11] (Microsoft Corporation)
Task: {3AA138B5-2D43-4CCF-B530-AA2BE0364E46} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {3CCC02E7-A999-41B8-B111-65B81F7FB907} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-08-29] () <==== ATTENTION
Task: {3CEA15DE-E282-446C-93E4-12AAECAA30E8} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-01-31] (globalUpdate) <==== ATTENTION
Task: {42FF6DEB-DB25-445D-ACE8-946FC119E710} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7 => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {4B2A101F-F713-4145-AF2D-14B52C40F02C} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-6 => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-6.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {5B3FA51C-0D53-486D-8077-2D67E97B2BE8} - System32\Tasks\Optimum_LogOn => C:\Program Files (x86)\Optimum PC Boost\OptimumPCBoost.exe <==== ATTENTION
Task: {60B406F7-0FF1-4EAD-904D-A915A8D63734} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro 3.38\OptProLauncher.exe [2015-01-29] (PC Utilities Software Limited) <==== ATTENTION
Task: {6AF3C44A-B687-4298-BA15-C041A9EE5D7C} - System32\Tasks\ConsumerInputUpdateTaskMachineUA => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2015-02-03] (ConsumerInput) <==== ATTENTION
Task: {6B36B481-0B04-4132-8F67-A468A957B017} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6 => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {6BB4F7C5-4D82-4704-873D-60122B8F9C8E} - System32\Tasks\ConsumerInputUpdateTaskMachineCore => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2015-02-03] (ConsumerInput) <==== ATTENTION
Task: {6EC4FC81-6C4A-4002-AC2A-F0DA1CBBC6E5} - System32\Tasks\SpeedChecker Update => C:\Program Files (x86)\ver0SpeedChecker\s5SpeedCheckerI55.exe [2015-01-31] () <==== ATTENTION
Task: {76E2425C-A76D-474B-849F-A0559AF55CEC} - System32\Tasks\MSI_Reminder => C:\Program Files (x86)\MSI\MSI Remind Manager\MSI Reminder.exe [2014-04-09] ()
Task: {791B7F10-DCBF-4F2A-B026-735AF13704B9} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5_user => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-5.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {7A748A39-6A0C-4183-8156-DDAE70169665} - System32\Tasks\MSI_Dragon Gaming Center => C:\Program Files (x86)\MSI\Dragon Gaming Center\mDispatch.exe [2014-01-23] (TODO: <公司名稱>)
Task: {7A9873FE-94CC-4F5E-BC45-EB736D672BF9} - System32\Tasks\Optimum_Daily => C:\Program Files (x86)\Optimum PC Boost\OptimumPCBoost.exe <==== ATTENTION
Task: {7CAB2EFE-2186-46C1-A3CE-97EF4BD8545A} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\SymErr.exe [2013-08-01] (Symantec Corporation)
Task: {873D1A12-5B57-4F11-B9E1-B6F4D9E7B361} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5 => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-5.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {88A5AFC4-DC21-4E20-89E3-98A157FBEAC1} - System32\Tasks\Vosteran dota => Wscript.exe "C:\ProgramData\{A6374EF4-F6B5-9F72-4733-EFF097B13C7E}\1.9.1.1\fiber.js" "433a2f50726f6772616d446174612f7b41363337344546342d463642352d394637322d343733332d4546463039374231334337457d2f312e392e312e312f646f74612e646c6c" "687474703a2f2f73616f2e766f7367722e636f6d2f" "–IsErIk" <==== ATTENTION
Task: {890E34F8-EA5D-4682-9E70-A6DF41CD48DC} - System32\Tasks\Driver Support-RTMRules => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {919C7BC8-ECD6-43B9-992C-F773CD90DD4C} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.10.0.9\SymErr.exe [2013-08-01] (Symantec Corporation)
Task: {91DE0F2C-1E27-4DF4-8DE1-7610BDC96319} - System32\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-10_user => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-10.exe [2015-01-31] (CinPlus-Pro 2.5pV31.01) <==== ATTENTION
Task: {96E4EE60-C87A-4CCE-BB71-262D540089FD} - System32\Tasks\WSE_Vosteran => C:\Users\nathanw\AppData\Roaming\WSE_Vosteran\UpdateProc\UpdateTask.exe [2015-02-01] () <==== ATTENTION
Task: {A794D80B-4551-461A-B1A4-B6F820D9221E} - System32\Tasks\CIMT_daily_S-1-5-21-3104748373-4178966826-1034322177-1002 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe [2015-01-19] () <==== ATTENTION
Task: {B3F4C5ED-7D51-4CE2-8982-ACEDA14BB5D8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-02-12] (Microsoft Corporation)
Task: {B64F17F9-AF2D-4B1F-A85F-F7ACAE2354C2} - System32\Tasks\GPUP => C:\Program Files (x86)\GetPrivate\gpup.exe [2014-10-03] () <==== ATTENTION
Task: {BF34D6C7-3234-4712-B542-FA825002455A} - System32\Tasks\Driver Support-RTMScan => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-08-07] (PC Drivers Headquarters)
Task: {C7662A70-7764-4CF7-B866-F5B2306DC242} - System32\Tasks\Jelbrus Secure Web Task => C:\Program Files (x86)\Jelbrus Secure Web\jswtask.exe [2014-11-12] (Jelbrus)
Task: {CFCA9BE6-17E8-41A4-96E5-411ADBABFB4C} - System32\Tasks\CIMT_S-1-5-21-3104748373-4178966826-1034322177-1002 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe [2015-01-19] () <==== ATTENTION
Task: {D069AC4D-3961-45D9-91A7-663AD5EF9DBF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-25] (Google Inc.)
Task: {D2099157-2EFE-4715-893A-18FAC41D294D} - System32\Tasks\RPC => C:\Program Files (x86)\Regprocleaner\Regprocleaner.exe [2015-01-22] ()
Task: {E3D2EB48-2F88-4B4F-906D-C0D87A7CEA6D} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-01-31] (globalUpdate) <==== ATTENTION
Task: {E755D892-7CF4-425C-83B9-0E69CE2FF3A1} - System32\Tasks\UpdaterEX => C:\Users\nathanw\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {FA114C47-16F5-4EA9-BA09-99233431A606} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-08-29] () <==== ATTENTION
Task: {FDB10BD5-63D5-499D-8F5B-9F1C39533065} - System32\Tasks\bench-S-1-5-21-3104748373-4178966826-1034322177-1002 => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: {FF72D8AC-2CB8-4CDA-8C41-73EC2C1FD75D} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-3104748373-4178966826-1034322177-1002 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-10_user.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-5_user.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-6.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\846bb3df-d697-4cbc-b53f-963ee89ca784-7.job => C:\Program Files (x86)\CinPlus-Pro 2.5pV31.01\846bb3df-d697-4cbc-b53f-963ee89ca784-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-S-1-5-21-3104748373-4178966826-1034322177-1002.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_daily_S-1-5-21-3104748373-4178966826-1034322177-1002.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_S-1-5-21-3104748373-4178966826-1034322177-1002.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\SpeedChecker Update.job => C:\Program Files (x86)\ver0SpeedChecker\s5SpeedCheckerI55.exe <==== ATTENTION
Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\nathanw\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE/CheckNathan\nathanw0Ò¥< <==== ATTENTION
Task: C:\Windows\Tasks\Vosteran dota.job => Wscript.exe C:\ProgramData\{A6374EF4-F6B5-9F72-4733-EFF097B13C7E}\1.9.1.1\fiber.js <==== ATTENTION
Task: C:\Windows\Tasks\WSE_Vosteran.job => C:\Users\nathanw\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE/CheckNathan\nathanw0Ö ¥< <==== ATTENTION
==================== Loaded Modules (whitelisted) ==============
2014-11-21 23:40 - 2014-09-23 08:36 - 08897696 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-02-06 14:51 - 2015-01-23 05:37 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\OptimizerMonitor => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3104748373-4178966826-1034322177-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\nathanw\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
DNS Servers: [removed] - [removed]
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-3104748373-4178966826-1034322177-500 - Administrator - Disabled)
Guest (S-1-5-21-3104748373-4178966826-1034322177-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3104748373-4178966826-1034322177-1004 - Limited - Enabled)
nathanw (S-1-5-21-3104748373-4178966826-1034322177-1002 - Administrator - Enabled) => C:\Users\nathanw
UpdatusUser (S-1-5-21-3104748373-4178966826-1034322177-1001 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Faulty Device Manager Devices =============
Name: Radio Switch Device
Description: Radio Switch Device
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: ENE TECHNOLOGY INC.
Service: mshidumdf
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/15/2015 07:40:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Explorer.EXE, version: 6.3.9600.17284, time stamp: 0x53f816dc
Faulting module name: ntdll.dll, version: 6.3.9600.17278, time stamp: 0x53eebd22
Exception code: 0xc0000005
Fault offset: 0x0000000000038299
Faulting process id: 0x420
Faulting application start time: 0xExplorer.EXE0
Faulting application path: Explorer.EXE1
Faulting module path: Explorer.EXE2
Report Id: Explorer.EXE3
Faulting package full name: Explorer.EXE4
Faulting package-relative application ID: Explorer.EXE5
Error: (02/13/2015 01:33:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program s5SpeedCheckerI55.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 1314
Start Time: 01d047bb640ba655
Termination Time: 0
Application Path: C:\Program Files (x86)\ver0SpeedChecker\s5SpeedCheckerI55.exe
Report Id: b89470e5-b3ae-11e4-8298-303a6412db7f
Faulting package full name:
Faulting package-relative application ID:
Error: (02/12/2015 11:18:54 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcFailed to kill already running streamer. [6]
Error: (02/12/2015 11:18:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: nvstreamsvc.exe, version: 1.6.53.0, time stamp: 0x527cf301
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17278, time stamp: 0x53eebd22
Exception code: 0xc0000142
Fault offset: 0x00000000000ec0b4
Faulting process id: 0x1ed0
Faulting application start time: 0xnvstreamsvc.exe0
Faulting application path: nvstreamsvc.exe1
Faulting module path: nvstreamsvc.exe2
Report Id: nvstreamsvc.exe3
Faulting package full name: nvstreamsvc.exe4
Faulting package-relative application ID: nvstreamsvc.exe5
Error: (02/12/2015 10:54:30 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8
Error: (02/12/2015 03:18:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: gpup.exe, version: 0.0.0.0, time stamp: 0x541ffff6
Faulting module name: tasks.dll, version: 0.0.0.0, time stamp: 0x541fffca
Exception code: 0xc0000005
Fault offset: 0x000010ad
Faulting process id: 0x92c4
Faulting application start time: 0xgpup.exe0
Faulting application path: gpup.exe1
Faulting module path: gpup.exe2
Report Id: gpup.exe3
Faulting package full name: gpup.exe4
Faulting package-relative application ID: gpup.exe5
Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8719
Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8719
Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/11/2015 11:17:48 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7625
System errors:
=============
Error: (02/21/2015 01:18:05 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (02/21/2015 01:18:05 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (02/21/2015 01:18:04 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (02/21/2015 01:18:04 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (02/21/2015 01:18:00 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (02/21/2015 01:18:00 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (02/21/2015 01:17:58 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (02/21/2015 01:17:58 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (02/21/2015 01:17:55 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (02/21/2015 01:17:55 PM) (Source: DCOM) (EventID: 10005) (User: Nathan)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Microsoft Office Sessions:
=========================
Error: (02/15/2015 07:40:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.3.9600.1728453f816dcntdll.dll6.3.9600.1727853eebd22c0000005000000000003829942001d04971ca78ecf0C:\Windows\Explorer.EXEC:\Windows\SYSTEM32\ntdll.dll6fe2a889-b574-11e4-82a0-97886234adad
Error: (02/13/2015 01:33:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: s5SpeedCheckerI55.exe0.0.0.0131401d047bb640ba6550C:\Program Files (x86)\ver0SpeedChecker\s5SpeedCheckerI55.exeb89470e5-b3ae-11e4-8298-303a6412db7f
Error: (02/12/2015 11:18:54 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcFailed to kill already running streamer. [6]
Error: (02/12/2015 11:18:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nvstreamsvc.exe1.6.53.0527cf301KERNELBASE.dll6.3.9600.1727853eebd22c000014200000000000ec0b41ed001d047442d1d2ef2C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeKERNELBASE.dll6ae3fbab-b337-11e4-8294-303a6412db7f
Error: (02/12/2015 10:54:30 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8
Error: (02/12/2015 03:18:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: gpup.exe0.0.0.0541ffff6tasks.dll0.0.0.0541fffcac0000005000010ad92c401d04700c290ddc7C:\Program Files (x86)\GetPrivate\gpup.exeC:\Program Files (x86)\GetPrivate\tasks.dll4ab2ba4e-b2f4-11e4-8291-303a6412db7f
Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8719
Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8719
Error: (02/11/2015 11:17:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/11/2015 11:17:48 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7625
CodeIntegrity Errors:
===================================
Date: 2015-02-12 23:32:20.312
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-02-12 19:28:05.730
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-02-12 19:28:05.623
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-02-12 19:28:05.515
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-02-12 19:28:04.571
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-02-12 19:28:04.408
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-02-12 19:28:04.262
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-02-12 19:28:04.118
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-02-12 19:28:03.973
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-02-12 19:28:03.785
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4710HQ CPU @ 2.50GHz
Percentage of memory in use: 28%
Total physical RAM: 8111.19 MB
Available physical RAM: 5836.1 MB
Total Pagefile: 10287.19 MB
Available Pagefile: 8125.87 MB
Total Virtual: 131072 MB
Available Virtual: 131071.83 MB
==================== Drives ================================
Drive c: (OS_Install) (Fixed) (Total:580.74 GB) (Free:378.85 GB) NTFS
Drive d: (Data) (Fixed) (Total:334.57 GB) (Free:293.13 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: BF003083)
Partition: GPT Partition Type.
==================== End Of Log ============================