I'll definitely take your advice. Here are the two updated logs. Due to the time difference I might not be checking in for a while, just in case it looks like I abandoned the thread.
FRST updated:
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\SmartSetting.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\MovieColorEnhancer.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\WifiManager.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Eco Mode\SmartEco.exe
(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Gretech Corp.) C:\Program Files (x86)\GRETECH\GomPlayer\GOM.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11895400 2011-06-25] (Realtek Semiconductor)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2588968 2010-11-13] (ELAN Microelectronics Corp.)
HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-09] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [ctfmon] => C:\windows\system32\ctfmon.exe [9728 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [Spybot-S&D; Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\MountPoints2: {9a7c915e-34b5-11e2-bdd9-806e6f6e6963} - E:\PLAY.EXE "playlist.m3u"
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\MountPoints2: {b02a9a3b-7a26-11e2-b71f-50b7c307cd39} - F:\LGAutoRun.exe
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Bubbles.scr [899584 2010-11-21] (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.samsung.com/sec
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-02-10] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-02-10] (Microsoft Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-02-10] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler-x32: s-http - {D37E6C5F-1C0F-47C0-A3B6-403EEC555402} - C:\Program Files (x86)\Initech\SHTTP\InitechSHTTPInterface.11014.dll [2013-02-08] (© INITECH)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{83395AC7-FE87-4186-91C3-A6BE63F9820B}: [NameServer] 168.126.63.1,168.126.63.2
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @qvod.com/QvodShare -> C:\Program Files (x86)\QvodPlayer\npShareModule_x64.dll No File
FF Plugin-x32: @ahnlab.com/asp/npaosmgr.1 -> C:\Program Files (x86)\AhnLab\ASP\Components\aosmgr\npaosmgr.dll [2014-08-05] (AhnLab, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-25] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-07-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @softforum.com/npxwebplugins -> C:\Program Files (x86)\SoftForum\XecureWeb\ActiveX\npxwebplugin.dll [2009-05-28] (SoftForum)
FF Plugin-x32: @softforum.com/npxwebplugins_file -> C:\Program Files (x86)\SoftForum\XecureWeb\ActiveX\npxwebplugin_file.dll [2009-05-28] (SoftForum Co., Ltd.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2015-01-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2015-01-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-10-16] (VideoLAN)
FF Plugin-x32: @wizvera.com/npVeraport20 -> C:\Program Files (x86)\Wizvera\Veraport20\npveraport20.dll [2013-11-15] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @iniline.com/npCrossWeb -> C:\Users\SS\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0AB9084F-0EF8-499a-A461-DE46D3C4A45B}\plugins\npCrossWeb.dll [2014-12-05] (INITECH Co., Ltd.)
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @initech.com/npSandBox -> C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.10052.dll [2014-11-27] (Initech Co., Ltd.)
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @qvod.com/QvodInsert -> C:\Program Files (x86)\QvodPlayer\npQvodInsert.dll No File
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\SS\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2014-10-29] (Google)
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @talk.google.com/O1DPlugin -> C:\Users\SS\AppData\Roaming\Mozilla\plugins\npo1d.dll [2014-10-29] (Google)
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @tools.google.com/Google Update;version=3 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin HKU\S-1-5-21-3476611405-1961159229-2615470741-1001: @tools.google.com/Google Update;version=9 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin ProgramFiles/Appdata: C:\Users\SS\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2014-10-29] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\SS\AppData\Roaming\mozilla\plugins\npo1d.dll [2014-10-29] (Google)
FF Extension: INISAFE CrossWeb - C:\Users\SS\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0AB9084F-0EF8-499a-A461-DE46D3C4A45B} [2015-01-30]
FF HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.xpi
FF Extension: INISAFE SandBox - C:\Program Files (x86)\initech\INISAFE SandBox V1\npSandBox.xpi [2014-11-27]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Drive) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-15]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-15]
CHR Extension: (Chromebleed) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eeoekjnjgppnaegdjbcafdggilajhpic [2015-01-15]
CHR Extension: (AdBlock) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-15]
CHR Extension: (ActiveMail) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmbjhlidpnohinigphldbcffhikcill [2015-02-27]
CHR Extension: (StayFocusd) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2015-01-15]
CHR Extension: (Skype Click to Call) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-01-13]
CHR Extension: (Youtube Preview Is it worth watching) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nacgopecogaedhhjdfondlcobjofdhap [2015-02-27]
CHR Extension: (Google Wallet) - C:\Users\SS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-15]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2714800 2015-02-10] (Microsoft Corporation)
R2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [498688 2011-11-21] (Red Bend Ltd.) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-03-17] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] ()
S3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [986112 2011-11-21] (Intel(R) Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 AMonTDLH; C:\windows\system32\Drivers\AMonTDLH.sys [118072 2012-09-14] (AhnLab, Inc.)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2011-09-06] (Google Inc)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2011-09-06] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [35840 2011-09-06] (LG Electronics Inc.)
S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93184 2011-09-16] (LG Electronics Inc.)
S3 CdmDrvNt; C:\windows\system32\Drivers\CdmDrvNt.sys [25656 2009-07-21] (AhnLab, Inc.)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-03-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
S3 MfFWEnt; C:\Program Files\AhnLab\ASP\MyFirewall 4.0\MfFWEnt.sys [127224 2014-07-16] (AhnLab, Inc.)
S3 MfIPSEnt; C:\Program Files\AhnLab\ASP\MyFirewall 4.0\MfIPSEnt.sys [156408 2014-07-16] (AhnLab, Inc.)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-11-23] (Windows (R) 2003 DDK 3790 provider)
S3 scsk5; C:\Windows\SysWow64\drivers\scsk5.sys [50608 2015-01-30] ()
S3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2013-05-29] (Spotflux, Inc.)
S3 AhnFlt2K; \??\C:\windows\system32\drivers\AhnFlt2K.sys [X]
S3 AhnRec2K; \??\C:\windows\system32\drivers\AhnRec2K.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-24 22:39 - 2015-03-24 22:39 - 00000127 _____ () C:\Users\SS\Desktop\ckfiles.txt
2015-03-24 21:11 - 2015-03-24 21:12 - 00026340 _____ () C:\Users\SS\Desktop\Addition.txt
2015-03-24 20:56 - 2015-03-24 20:56 - 00468480 _____ () C:\Users\SS\Desktop\CKScanner.exe
2015-03-24 18:41 - 2015-03-25 01:10 - 00136408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-24 18:40 - 2015-03-24 18:40 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\SS\Downloads\mbam-setup-2.1.4.1018.exe
2015-03-24 18:40 - 2015-03-24 18:40 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-24 18:40 - 2015-03-24 18:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-24 18:40 - 2015-03-24 18:40 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-24 18:40 - 2015-03-24 18:40 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-24 18:40 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-03-24 18:40 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-03-24 18:40 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-03-24 18:38 - 2015-03-24 18:38 - 00001192 _____ () C:\Users\SS\Desktop\JRT.txt
2015-03-24 18:31 - 2015-03-24 18:31 - 01388782 _____ (Thisisu) C:\Users\SS\Desktop\JRT.exe
2015-03-24 18:29 - 2015-03-24 18:29 - 00014203 _____ () C:\Users\SS\Desktop\AdwCleaner[S0].txt
2015-03-24 18:21 - 2015-03-24 18:27 - 00000000 ____D () C:\AdwCleaner
2015-03-24 18:20 - 2015-03-24 18:20 - 02168320 _____ () C:\Users\SS\Desktop\AdwCleaner.exe
2015-03-23 18:34 - 2015-03-25 01:16 - 00021277 _____ () C:\Users\SS\Desktop\FRST.txt
2015-03-23 18:31 - 2015-03-23 18:33 - 00034329 _____ () C:\Users\SS\Downloads\Addition.txt
2015-03-23 18:29 - 2015-03-23 18:33 - 00058279 _____ () C:\Users\SS\Downloads\FRST.txt
2015-03-23 18:28 - 2015-03-25 01:16 - 00000000 ____D () C:\FRST
2015-03-23 18:27 - 2015-03-23 18:27 - 02095616 _____ (Farbar) C:\Users\SS\Desktop\FRST64.exe
2015-03-23 18:25 - 2015-03-23 18:34 - 00001169 _____ () C:\Users\SS\Desktop\aswMBR.txt
2015-03-23 18:24 - 2015-03-23 18:24 - 05198336 _____ (AVAST Software) C:\Users\SS\Downloads\aswMBR.exe
2015-03-23 18:20 - 2015-03-23 18:20 - 00013540 _____ () C:\Users\SS\Downloads\hijackthis.log
2015-03-23 18:19 - 2015-03-23 18:19 - 00388608 _____ (Trend Micro Inc.) C:\Users\SS\Downloads\HijackThis.exe
2015-03-19 00:39 - 2015-03-19 00:39 - 00000000 ____D () C:\Users\SS\Downloads\BlowjobFridays - Yurizan Beltran - Dick Sucking at Its Finestt 720p [.mp4]
2015-03-18 18:38 - 2015-03-18 19:03 - 1010408247 _____ () C:\Users\SS\Downloads\chanel_preston_TT_1_JD_1080p_stream.mp4
2015-03-17 23:49 - 2015-03-18 17:26 - 272288145 _____ () C:\Users\SS\Downloads\BRAZZERS - Doctor Adventures - Doctors Without Bras - Kendra Lust - Rachel Starr [SM128].mkv
2015-03-17 18:44 - 2015-03-17 18:44 - 00000000 ____D () C:\Users\SS\Downloads\HardX - Mia Malkova (Massive Anal Action) [.mp4]
2015-03-17 18:22 - 2015-03-17 18:22 - 00000000 ____D () C:\Users\SS\Downloads\Blowjob Friday - Capri Cavanni (Serious BJ skills)
2015-03-16 18:51 - 2015-03-16 18:51 - 00000000 ____D () C:\Users\SS\AppData\Roaming\LavasoftStatistics
2015-03-16 18:46 - 2015-03-16 18:46 - 02057008 _____ () C:\Users\SS\Downloads\Adaware_Installer.exe
2015-03-14 11:49 - 2015-03-14 12:21 - 00000000 ____D () C:\Users\SS\Downloads\The Last Naruto The Movie 2014 720p HDCAM ENG SUBS x264 Pimp4003
2015-03-12 23:31 - 2015-03-12 23:58 - 480362658 _____ () C:\Users\SS\Downloads\t4k.dillion.harper.excited.little.slut.12.03.15_480.mp4
2015-03-12 23:31 - 2015-03-12 23:44 - 481824046 _____ () C:\Users\SS\Downloads\Digital_Playground_ge_34601_The_Fuck_Shop_480p_1500.mp4
2015-03-12 22:35 - 2015-03-12 22:37 - 339871297 _____ () C:\Users\SS\Downloads\BabyGotBoobs - Shawna Lenee - Up Close And Personal With Shawnas Tits NEW (BRAZZERS February 11, 2015) NEW.mp4
2015-03-12 21:15 - 2015-03-12 21:56 - 658123518 _____ () C:\Users\SS\Downloads\HotAndMean - Carter Cruise, Maddy Oreilly_480p.mp4
2015-03-11 21:27 - 2015-03-11 21:27 - 03471514 _____ () C:\Users\SS\Downloads\Introclass (1).pptx
2015-03-11 21:27 - 2015-03-11 21:27 - 00958942 _____ () C:\Users\SS\Downloads\Country Bingo.pptx
2015-03-11 18:28 - 2015-03-11 18:43 - 00000000 ____D () C:\Users\SS\Downloads\Sheena_Shaw_Wide_Open
2015-03-11 18:08 - 2015-02-20 13:41 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-03-11 18:08 - 2015-02-20 13:40 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-03-11 18:08 - 2015-02-20 13:40 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-03-11 18:08 - 2015-02-20 13:40 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-03-11 18:08 - 2015-02-20 13:13 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2015-03-11 18:08 - 2015-02-20 13:13 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-03-11 18:08 - 2015-02-20 13:13 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2015-03-11 18:08 - 2015-02-20 13:12 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2015-03-11 18:08 - 2015-02-20 12:29 - 00372224 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-03-11 18:08 - 2015-02-20 12:09 - 00299008 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-03-11 18:08 - 2015-02-03 12:34 - 05554104 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-03-11 18:08 - 2015-02-03 12:34 - 00094656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-03-11 18:08 - 2015-02-03 12:33 - 00616360 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2015-03-11 18:08 - 2015-02-03 12:31 - 14632960 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2015-03-11 18:08 - 2015-02-03 12:31 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2015-03-11 18:08 - 2015-02-03 12:31 - 01574400 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2015-03-11 18:08 - 2015-02-03 12:30 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-03-11 18:08 - 2015-02-03 12:30 - 01202176 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2015-03-11 18:08 - 2015-02-03 12:16 - 03973048 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-03-11 18:08 - 2015-02-03 12:16 - 03917760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-03-11 18:08 - 2015-02-03 12:12 - 11411968 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2015-03-11 18:08 - 2015-02-03 12:12 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2015-03-11 18:08 - 2015-02-03 12:12 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2015-03-11 18:08 - 2015-02-03 12:12 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2015-03-11 18:07 - 2015-02-03 12:34 - 00693176 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2015-03-11 18:07 - 2015-02-03 12:31 - 00782848 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00641024 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00432128 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00188416 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2015-03-11 18:07 - 2015-02-03 12:31 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2015-03-11 18:07 - 2015-02-03 12:31 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2015-03-11 18:07 - 2015-02-03 12:30 - 01069056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00842240 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00680960 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00146944 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00126464 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2015-03-11 18:07 - 2015-02-03 12:30 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe
2015-03-11 18:07 - 2015-02-03 12:30 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
2015-03-11 18:07 - 2015-02-03 12:29 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
2015-03-11 18:07 - 2015-02-03 12:28 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-03-11 18:07 - 2015-02-03 12:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2015-03-11 18:07 - 2015-02-03 12:19 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2015-03-11 18:07 - 2015-02-03 12:12 - 01005056 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptui.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00988160 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmv2clt.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00744960 _____ (Microsoft Corporation) C:\windows\SysWOW64\blackbox.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00617984 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmdrmsdk.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscp.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00406016 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmmgrtn.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msnetobj.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00081408 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsp.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2015-03-11 18:07 - 2015-02-03 12:12 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2015-03-11 18:07 - 2015-02-03 12:12 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2015-03-11 18:07 - 2015-02-03 12:11 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2015-03-11 18:07 - 2015-02-03 12:11 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2015-03-11 18:07 - 2015-02-03 12:11 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2015-03-11 18:07 - 2015-02-03 12:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2015-03-11 18:07 - 2015-02-03 12:08 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-03-11 18:07 - 2015-02-03 11:32 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2015-03-11 18:07 - 2014-11-01 07:24 - 00619056 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2015-03-11 18:06 - 2015-02-13 14:26 - 12875264 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-03-11 18:06 - 2015-02-13 14:22 - 14177280 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-03-11 18:06 - 2015-02-03 12:31 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
2015-03-11 18:06 - 2015-02-03 12:12 - 00171520 _____ (Microsoft Corporation) C:\windows\SysWOW64\ubpm.dll
2015-03-11 18:05 - 2015-03-06 14:56 - 00155576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-03-11 18:05 - 2015-03-06 14:56 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-03-11 18:05 - 2015-03-06 14:42 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-03-11 18:05 - 2015-03-06 14:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-03-11 18:05 - 2015-03-06 14:41 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-03-11 18:05 - 2015-03-06 14:41 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-03-11 18:05 - 2015-03-06 14:39 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-03-11 18:05 - 2015-03-06 14:38 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-03-11 18:05 - 2015-03-06 14:36 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-03-11 18:05 - 2015-03-06 14:10 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-03-11 18:05 - 2015-03-06 14:09 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-03-11 18:05 - 2015-03-06 14:09 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-03-11 18:05 - 2015-03-06 14:07 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-03-11 18:05 - 2015-03-06 14:07 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-03-11 18:05 - 2015-03-06 14:06 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-03-11 18:05 - 2015-02-26 12:25 - 03204096 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-03-11 18:05 - 2015-02-24 12:15 - 00389800 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-03-11 18:05 - 2015-02-24 11:32 - 00342696 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-03-11 18:05 - 2015-02-21 10:16 - 25021440 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-03-11 18:05 - 2015-02-21 09:41 - 12827648 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-03-11 18:05 - 2015-02-21 09:27 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-03-11 18:05 - 2015-02-21 09:27 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-03-11 18:05 - 2015-02-21 09:25 - 19720192 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-03-11 18:05 - 2015-02-21 08:58 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-03-11 18:05 - 2015-02-21 08:32 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-03-11 18:05 - 2015-02-20 12:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-03-11 18:05 - 2015-02-20 12:05 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-03-11 18:05 - 2015-02-20 11:50 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-03-11 18:05 - 2015-02-20 11:49 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-03-11 18:05 - 2015-02-20 11:49 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-03-11 18:05 - 2015-02-20 11:48 - 02886144 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-03-11 18:05 - 2015-02-20 11:47 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-03-11 18:05 - 2015-02-20 11:41 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-03-11 18:05 - 2015-02-20 11:40 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-03-11 18:05 - 2015-02-20 11:36 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-03-11 18:05 - 2015-02-20 11:35 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-03-11 18:05 - 2015-02-20 11:35 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-03-11 18:05 - 2015-02-20 11:34 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-03-11 18:05 - 2015-02-20 11:32 - 06035456 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-03-11 18:05 - 2015-02-20 11:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-03-11 18:05 - 2015-02-20 11:22 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-03-11 18:05 - 2015-02-20 11:22 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-03-11 18:05 - 2015-02-20 11:13 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 18:05 - 2015-02-20 11:09 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-03-11 18:05 - 2015-02-20 11:08 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-03-11 18:05 - 2015-02-20 11:08 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-03-11 18:05 - 2015-02-20 11:08 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-03-11 18:05 - 2015-02-20 11:06 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-03-11 18:05 - 2015-02-20 11:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-03-11 18:05 - 2015-02-20 11:03 - 02278400 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-03-11 18:05 - 2015-02-20 11:01 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-03-11 18:05 - 2015-02-20 11:00 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-03-11 18:05 - 2015-02-20 10:58 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-03-11 18:05 - 2015-02-20 10:56 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-03-11 18:05 - 2015-02-20 10:56 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-03-11 18:05 - 2015-02-20 10:49 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-03-11 18:05 - 2015-02-20 10:49 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-03-11 18:05 - 2015-02-20 10:47 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-03-11 18:05 - 2015-02-20 10:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-03-11 18:05 - 2015-02-20 10:43 - 14398976 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-03-11 18:05 - 2015-02-20 10:41 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-11 18:05 - 2015-02-20 10:37 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-03-11 18:05 - 2015-02-20 10:30 - 04300288 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-03-11 18:05 - 2015-02-20 10:28 - 02358784 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-03-11 18:05 - 2015-02-20 10:24 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-03-11 18:05 - 2015-02-20 10:24 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-03-11 18:05 - 2015-02-20 10:23 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-03-11 18:05 - 2015-02-20 10:16 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-03-11 18:05 - 2015-02-20 10:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-03-11 18:05 - 2015-02-20 10:01 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-03-11 18:05 - 2015-02-20 09:57 - 01311232 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-03-11 18:05 - 2015-02-20 09:55 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-03-11 18:05 - 2015-02-04 12:16 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2015-03-11 18:05 - 2015-02-04 11:54 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2015-03-11 18:05 - 2015-02-03 12:31 - 01424896 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-03-11 18:05 - 2015-02-03 12:12 - 01230848 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2015-03-11 18:05 - 2015-01-31 08:56 - 00459336 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-03-11 18:05 - 2015-01-17 11:48 - 01067520 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2015-03-11 18:05 - 2015-01-17 11:30 - 00828928 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2015-03-11 00:34 - 2015-03-11 00:34 - 00000000 ____D () C:\Users\SS\Downloads\[FuckedHard18] Morgan Layne [SD] [.wmv]
2015-03-08 20:59 - 2015-03-08 20:59 - 00147471 _____ () C:\Users\SS\Desktop\jim_aparo___batman_a_death_in_the_family_by_superman8193-d5tlylg-ben-affleck-as-batman-death-red-hood-arkham-asylum-and-hush-52c68877-489e-4ce1-a7c6-b0d2e04e2ed4.jpeg
2015-03-08 16:40 - 2015-03-08 16:40 - 00000000 ____D () C:\Users\SS\Downloads\EvilAngel.Kalina.Ryu.Sperm.Diet.mp4
2015-03-08 12:26 - 2015-03-08 23:20 - 2003577517 _____ () C:\Users\SS\Downloads\Saya_Song.mp4
2015-03-08 11:40 - 2015-03-08 11:40 - 00000000 ____D () C:\Users\SS\Downloads\[GFRevenge] Dillion Harper (Track star)[PornLeech]
2015-03-07 14:24 - 2015-03-07 14:24 - 00000000 ____D () C:\Users\SS\Downloads\James Deen - JESSIE ROGERS - Assfucked Til She Squirts [.mp4]
2015-03-07 14:22 - 2015-03-07 14:22 - 00000000 ____D () C:\Users\SS\Downloads\[Private] Tina Hot [Anal Introductions][1080p] [.mp4][PornLeech]
2015-03-06 14:14 - 2015-03-06 14:18 - 00000000 ____D () C:\Users\SS\Downloads\BangBros - Big Mouthfuls - Simply 18 w Emma Mae HD 720p
2015-03-05 13:47 - 2015-03-05 13:47 - 00000000 ____D () C:\Users\SS\Downloads\[DigitalPlayground] Janice Griffith (50 Ways To Fuck) [.mp4]
2015-03-04 23:39 - 2015-03-04 23:48 - 03461639 _____ () C:\Users\SS\Downloads\Introclass.pptx
2015-02-27 14:34 - 2015-02-27 14:34 - 00000000 ____D () C:\Program Files (x86)\ActiveMail
2015-02-27 12:12 - 2015-02-27 12:12 - 00000000 ____D () C:\Program Files (x86)\Youtube Preview Is it worth watching
2015-02-27 11:12 - 2015-02-27 11:12 - 00000000 ____D () C:\Program Files (x86)\coinsaove
2015-02-26 09:59 - 2015-02-26 09:59 - 00000000 ____D () C:\Program Files (x86)\Renren Album Downloader
2015-02-26 09:19 - 2015-01-09 08:44 - 00419936 _____ () C:\windows\SysWOW64\locale.nls
2015-02-26 09:19 - 2015-01-09 08:43 - 00419936 _____ () C:\windows\system32\locale.nls
2015-02-23 17:37 - 2015-02-23 17:40 - 00000000 ____D () C:\Users\SS\Downloads\BaDoink.15.02.20.Marica.Haze.Mirrors.Edge.An.XXX.Parody.XXX.1080p.MP4.KTR
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-25 00:34 - 2014-10-08 07:46 - 00000890 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-25 00:34 - 2014-10-08 07:46 - 00000886 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-25 00:26 - 2012-04-21 21:43 - 01364280 _____ () C:\windows\WindowsUpdate.log
2015-03-25 00:20 - 2014-01-11 10:20 - 00000896 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA.job
2015-03-24 22:17 - 2012-12-05 23:05 - 00000000 ____D () C:\Users\SS\Desktop\Unused
2015-03-24 22:10 - 2012-12-05 23:35 - 00000000 ____D () C:\Users\SS\AppData\Roaming\BitTorrent
2015-03-24 18:36 - 2009-07-14 13:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-24 18:36 - 2009-07-14 13:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-24 18:28 - 2010-11-21 12:47 - 00667664 _____ () C:\windows\PFRO.log
2015-03-24 18:28 - 2009-07-14 14:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-24 18:28 - 2009-07-14 13:51 - 00155324 _____ () C:\windows\setupact.log
2015-03-24 17:47 - 2014-01-11 10:20 - 00000844 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core.job
2015-03-23 23:58 - 2012-12-16 13:12 - 00000000 ____D () C:\Users\SS\AppData\Roaming\vlc
2015-03-23 18:19 - 2012-12-05 21:28 - 00000000 ____D () C:\Users\SS\AppData\Local\VirtualStore
2015-03-23 17:40 - 2015-02-04 17:26 - 00000020 _____ () C:\Users\SS\AppData\Roaming\appdataFr3.bin
2015-03-22 22:14 - 2012-12-07 08:50 - 00000000 ____D () C:\Users\SS\AppData\Roaming\Skype
2015-03-20 06:19 - 2013-02-19 23:00 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-03-14 01:40 - 2013-02-19 08:57 - 00000000 ____D () C:\Users\SS\Desktop\CARLOS
2015-03-12 15:41 - 2014-03-16 22:04 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-03-12 15:40 - 2012-04-21 06:13 - 00000000 ____D () C:\ProgramData\Skype
2015-03-12 15:35 - 2009-07-14 13:45 - 00370488 _____ () C:\windows\system32\FNTCACHE.DAT
2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\SysWOW64\tr-TR
2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\system32\tr-TR
2015-03-12 15:31 - 2009-07-14 12:20 - 00000000 ____D () C:\windows\system32\Dism
2015-03-12 14:16 - 2013-12-09 22:51 - 00000000 ____D () C:\windows\system32\MRT
2015-03-12 14:02 - 2013-12-09 22:51 - 122905848 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-03-11 22:22 - 2012-12-05 22:00 - 00656980 _____ () C:\windows\system32\perfh01F.dat
2015-03-11 22:22 - 2012-12-05 22:00 - 00140326 _____ () C:\windows\system32\perfc01F.dat
2015-03-11 22:22 - 2012-04-21 21:15 - 00428722 _____ () C:\windows\system32\perfh012.dat
2015-03-11 22:22 - 2012-04-21 21:15 - 00120710 _____ () C:\windows\system32\perfc012.dat
2015-03-11 22:22 - 2009-07-14 14:13 - 02111596 _____ () C:\windows\system32\PerfStringBackup.INI
2015-03-11 21:29 - 2012-12-25 23:46 - 00000000 ____D () C:\Users\SS\AppData\Local\CrashDumps
2015-03-11 18:46 - 2012-12-19 23:09 - 00001173 _____ () C:\Users\SS\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2015-03-11 18:46 - 2012-12-19 23:09 - 00001149 _____ () C:\Users\Public\Desktop\GOM Player.lnk
2015-03-11 17:38 - 2015-02-06 16:05 - 00000000 ____D () C:\ProgramData\3045395222265742798
2015-02-26 10:02 - 2014-12-29 16:21 - 00000258 __RSH () C:\ProgramData\ntuser.pol
==================== Files in the root of some directories =======
2015-02-04 17:26 - 2015-03-23 17:40 - 0000020 _____ () C:\Users\SS\AppData\Roaming\appdataFr3.bin
2013-08-20 00:12 - 2014-04-22 00:27 - 0000954 _____ () C:\Users\SS\AppData\Roaming\coreavc.ini
2012-04-21 06:07 - 2012-04-21 06:08 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2012-04-21 06:02 - 2012-04-21 06:02 - 0000113 _____ () C:\ProgramData\{34FBC7C4-CD31-4D93-A428-0E524EAC4586}.log
2012-04-21 06:05 - 2012-04-21 06:05 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2012-04-21 06:02 - 2012-04-21 06:05 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log
2012-04-21 06:05 - 2012-04-21 06:07 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
Some content of TEMP:
====================
C:\Users\SS\AppData\Local\Temp\Quarantine.exe
C:\Users\SS\AppData\Local\Temp\SkypeSetup.exe
C:\Users\SS\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-15 12:54
==================== End Of Log ============================
Addition updated:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by [removed] at 2015-03-25 01:18:05
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
ActiveMail (HKLM-x32\…\{89AE616B-E500-0C2D-D0D2-F444CEEB4619}) (Version: - "")
Adobe Flash Player 10 ActiveX (HKLM-x32\…\{48DB5914-8772-472D-B8DF-E2092BE598F6}) (Version: 10.3.181.34 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 - Korean (HKLM-x32\…\{AC76BA86-7AD7-1042-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
AhnLab Online Security (HKLM-x32\…\AhnLab Online Security) (Version: - AhnLab, Inc)
Audacity 2.0.5 (HKLM-x32\…\Audacity_is1) (Version: 2.0.5 - Audacity Team)
calibre (HKLM-x32\…\{4BF56EFD-2F39-40F2-89BB-CF9D3550A806}) (Version: 2.17.0 - Kovid Goyal)
coinsaove (HKLM-x32\…\{C8AAF59A-6BAA-F68B-9470-A856460A8093}) (Version: - "") <==== ATTENTION
CyberLink Media Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink Corp.)
CyberLink Media+ Player10 (HKLM-x32\…\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 - CyberLink Corp.)
CyberLink MediaShow (HKLM-x32\…\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1130a - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.)
CyberLink PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3306 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4417 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Easy Content Share (HKLM-x32\…\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD)
Easy Migration (HKLM-x32\…\{AD86049C-3D9C-43E1-BE73-643F57D83D50}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
EasyFileShare (HKLM-x32\…\{16880765-677F-440B-B16A-BFD9B9C00012}) (Version: 1.0.12 - Samsung)
Eco Mode (HKLM-x32\…\{9A8E4762-3331-4EDB-8E1F-B11179DDBC00}) (Version: 1.0.0.11 - Samsung Electronics Co., Ltd.)
E-POP (HKLM-x32\…\{75282161-8CAC-4071-A225-EBC95E43C7F3}) (Version: 1.00.0000 - Samsung)
ETDWare PS/2-X64 8.0.7.2_WHQL (HKLM\…\Elantech) (Version: 8.0.7.2 - ELAN Microelectronic Corp.)
GOM Player (HKLM-x32\…\GOM Player) (Version: 2.2.67.5221 - Gretech Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 39.0.2171.99 - Google Inc.)
Google Talk Plugin (HKLM-x32\…\{0C5C1177-94C5-3EFB-A8BE-3F6AF1AF887F}) (Version: 5.38.6.0 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Hanword HWP document converter for Microsoft Word (x64) (HKLM\…\{90150000-2009-0409-1000-0000000FF1CE}) (Version: 15.0.4454.1506 - Microsoft Corporation)
Hanword HWP document converter for Microsoft Word (x86) (HKLM-x32\…\{90150000-2009-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1506 - Microsoft Corporation)
INISAFE SandBox 1.0 (HKLM-x32\…\INISAFE SandBox) (Version: 1.0 - Initech, Inc.)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2266 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\…\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel)
Intel(R) WiDi (HKLM-x32\…\{E1B934BB-6AFA-429F-98E4-76F9CBC72BF6}) (Version: 2.2.14.0 - Intel Corporation)
Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - )
Interactive Guide (HKLM-x32\…\{CB383BE9-7518-4ABD-826E-8FC4695F7D52}) (Version: 1.1 - )
Java 7 Update 67 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.670 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
KakaoTalk (HKLM-x32\…\KakaoTalk) (Version: 2.0.4.786 - Kakao)
LG United Mobile Drivers (HKLM-x32\…\{C2944BE7-9BFF-4EF0-A362-CB3281B7C50D}) (Version: 3.6.0.0 - LG Electronics)
Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Media Center 한글 입력기 (HKLM-x32\…\{BB9A1C85-8841-4755-A4D3-E3EEC3EFD3F0}) (Version: 3.1.5.0 - Samsung Electronics Co., LTD)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Home and Student 2013 - en-us (HKLM\…\HomeStudentRetail - en-us) (Version: 15.0.4701.1002 - Microsoft Corporation)
Microsoft Office 언어 교정 도구 2013 - 한국어 (HKLM-x32\…\{90150000-001F-0412-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\…\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Multimedia POP (HKLM-x32\…\{331ECF61-69AF-4F57-AC35-AFED610231C3}) (Version: 1.2 - )
NVIDIA 그래픽 드라이버 267.54 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.54 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
PhoneShare (HKLM-x32\…\{3F50512F-53DF-46B1-8CCB-6C7E638CADD6}) (Version: 9.1.4 - Samsung)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6400 - Realtek Semiconductor Corp.)
Renren Album Downloader (HKLM-x32\…\{AF992111-52BE-832B-5882-8477E4A3C99A}) (Version: - "") <==== ATTENTION
Samsung AnyWeb Print (HKLM-x32\…\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 2.0.67.1 - Samsung Electronics Co., Ltd.)
Samsung Control Center (HKLM-x32\…\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM-x32\…\Samsung Printer Live Update) (Version: - Samsung Electronics Co., Ltd.)
Samsung Recovery Solution 5 (HKLM-x32\…\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.1.3 - Samsung)
Samsung Support Center (HKLM-x32\…\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.26 - Samsung)
Samsung Universal Print Driver (HKLM-x32\…\Samsung Universal Print Driver) (Version: 2.02.05.00:27 - Samsung Electronics Co., Ltd.)
Samsung Universal Scan Driver (HKLM-x32\…\Samsung Universal Scan Driver) (Version: 1.2.5.0 - Samsung Electronics Co., Ltd.)
Samsung Update Plus (HKLM-x32\…\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.0.17 - Samsung Electronics Co., Ltd.)
SISShortcut (HKLM-x32\…\{FDAE128F-A355-42B1-8422-1AF3ACEE34F4}) (Version: 1.00.000 - Samsung)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.1 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
User Guide (HKLM-x32\…\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.3 - )
Veraport20(Security module management) - 2,5,6,1 (HKLM-x32\…\{2D992E01-604B-472C-A883-1DDA105A24D5}_is1) (Version: 2,5,6,1 - Wizvera)
VLC media player 2.0.4 (HKLM-x32\…\VLC media player) (Version: 2.0.4 - VideoLAN)
Vuze Remote Toolbar (HKLM-x32\…\Vuze_Remote Toolbar) (Version: 6.9.0.16 - Vuze Remote) <==== ATTENTION
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WordCaptureX Pro (HKLM-x32\…\{139C1D95-9037-3AB3-F5F4-4A79BF6831EC}) (Version: 4.0.0 - Deskperience)
XecureWeb Control (HKLM-x32\…\XecureWeb Control) (Version: - )
Youtube Preview Is it worth watching (HKLM-x32\…\{CDFBAC3A-2FE1-0B77-34C9-065BBCC8B77C}) (Version: - "") <==== ATTENTION
원격 연결을 위한 Windows Live Mesh ActiveX 컨트롤 (HKLM-x32\…\{61920449-0393-4707-B7DD-E6C0013C8B2C}) (Version: 15.4.5722.2 - Microsoft Corporation)
인텔(R) PROSet/무선 WiMAX 소프트웨어 (HKLM\…\{5C1DA3D9-F590-4317-A4FB-274F658E504B}) (Version: 6.05.0001 - Intel Corporation)
인텔® PROSet/무선 WiFi 소프트웨어 (HKLM\…\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\SS\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3476611405-1961159229-2615470741-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\SS\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
==================== Restore Points =========================
16-03-2015 18:46:22 AA11
23-03-2015 17:32:33 AA11
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 11:34 - 2015-03-03 20:25 - 00450892 ____R C:\windows\system32\Drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 www.123fporn.info
127.0.0.1 123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
There are 1000 more lines.
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {03A10DB7-9071-4EEF-B9CB-F411EA94735C} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Samsung Control Center\SmartSetting.exe [2011-06-04] (Samsung Electronics Co., Ltd.)
Task: {0A384BD9-2CAB-42DF-8601-6D380A53BFEB} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Samsung Control Center\SCCSpeedBoot.exe [2011-05-18] (Samsung Electronics Co., Ltd.)
Task: {0CFBF115-D843-433D-8B12-14C46A4A3BDA} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2011-03-29] (SEC)
Task: {1645AE87-AC06-4F79-9291-63F734344ECA} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-08-17] (CyberLink)
Task: {28A63C7E-40C7-4D78-9EBE-60FB6CE6E95B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
Task: {2D03498A-F669-4E65-8297-264723A0C017} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2011-04-17] (SAMSUNG Electronics)
Task: {2DB56CE1-EAD1-4215-9D66-960A74B181F9} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {2F5C19D8-2F72-434D-9A4B-551DBD945E72} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {3468239E-CD89-4747-90F5-DCCB45BA2FCB} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {398E535C-CC80-4CF3-9698-34C0F76AD90A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {3F7881E2-661E-42EB-8913-ABFD71584BC0} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
Task: {4A805CAE-69C4-4139-A3D2-995EC8A4FEA1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-15] (Google Inc.)
Task: {6AB036E6-C87E-4750-9D49-01D6931EFB37} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Samsung Control Center\MovieColorEnhancer.exe [2011-02-17] (Samsung Electronics Co., Ltd.)
Task: {76BC4D0C-1132-487C-85F2-7120F1BF7473} - System32\Tasks\Microsoft Office 15 Sync Maintenance for SS-PC-SS SS-PC => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation)
Task: {7E430DF2-7F3D-45FC-A8E6-757D48DAC111} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe [2010-08-27] (Samsung Electronics)
Task: {A0618927-0C2F-4AB6-B49A-AECA2955850A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-15] (Google Inc.)
Task: {A957AD76-D965-4019-82E7-04133BD83B27} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Samsung Control Center\WifiManager.exe [2012-03-08] (Samsung Electronics Co., Ltd.)
Task: {BB1B4464-B9EC-4474-8C84-31A56602CAE2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {C7519AC8-6F25-4BAD-BAFE-E7D925D18572} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Samsung Control Center\dmhkcore.exe [2011-06-15] (Samsung Electronics Co., Ltd.)
Task: {DE28C41A-1C1E-46B7-9DE8-7E610E5C2B14} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Samsung Control Center\EBM\EasyBatteryMgr4.exe [2011-07-02] (SAMSUNG Electronics co., LTD.)
Task: {E924E8DA-3600-4ED2-82A9-AB458CDC5AF9} - System32\Tasks\EcoMode => C:\Program Files (x86)\Samsung\Eco Mode\SmartEco.exe [2011-06-06] (Samsung Electronics)
Task: {E937FD97-F248-4672-85D2-684AEA989A33} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {EB02381F-D652-4B1C-894A-712498C62C51} - \Microsoft\Windows\MUI\LPRemove No Task File <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001Core.job => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3476611405-1961159229-2615470741-1001UA.job => C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2012-04-21 21:01 - 2008-06-05 08:53 - 00027648 _____ () C:\windows\System32\spd__l.dll
2014-03-21 17:29 - 2014-05-20 08:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2012-04-21 20:59 - 2010-12-17 10:37 - 00094208 _____ () C:\windows\system32\IccLibDll_x64.dll
2012-04-21 21:01 - 2010-10-22 03:22 - 00709632 _____ () C:\windows\system32\SnMinDrv.dll
2015-03-20 06:17 - 2015-01-28 00:29 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-12-29 16:28 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-12-29 16:28 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-12-29 16:28 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2014-12-29 16:28 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2014-12-29 16:28 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2012-04-21 06:14 - 2011-02-17 00:03 - 00203776 _____ () C:\Program Files (x86)\Samsung\Samsung Control Center\WinCRT.dll
2012-04-21 06:14 - 2006-08-12 11:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Samsung Control Center\HookDllPS2.dll
2009-11-02 14:20 - 2009-11-02 14:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 14:23 - 2009-11-02 14:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2012-04-21 06:15 - 2010-05-07 23:22 - 01636864 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
2015-01-15 00:29 - 2015-01-09 09:35 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libglesv2.dll
2015-01-15 00:29 - 2015-01-09 09:35 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\libegl.dll
2015-01-15 00:29 - 2015-01-09 09:35 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\pdf.dll
2015-01-15 00:29 - 2015-01-09 09:35 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\ffmpegsumo.dll
2015-01-15 00:29 - 2015-01-09 09:35 - 14913352 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.99\PepperFlash\pepflashplayer.dll
2014-01-31 12:28 - 2014-01-31 12:28 - 00421520 _____ () C:\Program Files (x86)\GRETECH\GomPlayer\GomTVStrm.dll
2014-12-19 10:08 - 2014-12-19 10:08 - 01193984 _____ () C:\Program Files (x86)\GRETECH\GomPlayer\libass.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3476611405-1961159229-2615470741-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\SS\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: [removed] - [removed]
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-3476611405-1961159229-2615470741-500 - Administrator - Disabled)
Guest (S-1-5-21-3476611405-1961159229-2615470741-501 - Limited - Disabled)
SS (S-1-5-21-3476611405-1961159229-2615470741-1001 - Administrator - Enabled) => C:\Users\SS
UpdatusUser (S-1-5-21-3476611405-1961159229-2615470741-1000 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (03/24/2015 10:19:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.0.32.0, time stamp: 0x54ff42f1
Faulting module name: mbamcore.dll, version: 1.1.67.0, time stamp: 0x54ff372a
Exception code: 0xc0000005
Fault offset: 0x000cf363
Faulting process id: 0x14dc
Faulting application start time: 0xmbamservice.exe0
Faulting application path: mbamservice.exe1
Faulting module path: mbamservice.exe2
Report Id: mbamservice.exe3
System errors:
=============
Error: (03/24/2015 10:20:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The MBAMService service terminated unexpectedly. It has done this 1 time(s).
Microsoft Office Sessions:
=========================
Error: (03/24/2015 10:19:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: mbamservice.exe3.0.32.054ff42f1mbamcore.dll1.1.67.054ff372ac0000005000cf36314dc01d06616ac4e454aC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exeC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamcore.dll5eca50d7-d228-11e4-96ad-50b7c307cd39
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz
Percentage of memory in use: 68%
Total physical RAM: 4009.55 MB
Available physical RAM: 1245.05 MB
Total Pagefile: 8017.28 MB
Available Pagefile: 4225.14 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:179 GB) (Free:53.44 GB) NTFS
Drive d: () (Fixed) (Total:266.57 GB) (Free:253.66 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: A80DEEF6)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=179 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=266.6 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=20.1 GB) - (Type=27)
==================== End Of Log ============================