This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

(application.exe) is not a valid Win32 application [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

1 week ago, i had infected by madang.b viruses. My Eset SS 8 was found it almost 1000 infected.exe files. I hope it was surely removed from my laptop now. but after of all, some of my application (office, nitro pdf, corel, photoshop, etc) shown dialog box that told "xxxx.exe is not a valid win32 application". i had try many tutors related this issued. but never bring a bright solution for me. if could anyone help me with this, i would really appreciate it.

thanks before.
-deff

:welcome:

 

Lets run a few scans and see whats going on

 

 
[external image: 1QYkxTZ.jpg] Please download aswMBR to your desktop.
 
  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
  •  
    I just want to see the report….Please Do Not Fix Anything
     
    ============================================================================
     
     
     
     
    Please download Farbar Recovery Scan Tool and save it to your desktop.
     
    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
     
    How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
    A simple way to check your system: Start –> Computer (right click) –> Properties
     
    [external image: FRST_zps5d956a1a.jpg]
     
     
    • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
    • Please make sure All Users is checked
    • Just keep the defaults as in the picture checkmarked
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
    • Thanks Ken for replied. I really appreciate it.
      I have done the scans and your instructions, this is the logs.

      Thank you
      -Deff

       

      Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015 02
      Ran by [removed] (administrator) on DEF-PC on 15-04-2015 21:19:56
      Running from C:\Users\[removed]\Desktop
      [removed]
      Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
      Internet Explorer Version 11 (Default browser: IE)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
       
      ==================== Processes (Whitelisted) =================
       
      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
       
      (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
      (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
      (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\AsLdrSrv.exe
      (ASUS) C:\Program Files (x86)\Asus\ATK Package\ATKGFNEX\GFNEXSrv.exe
      (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
      (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
      (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\HControl.exe
      (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
      (ASUS) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\ATKOSD.exe
      (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\KBFiltr.exe
      (ASUS) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\WDC.exe
      (Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
      (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
      (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
      (ASUSTeK Computer Inc.) C:\Program Files (x86)\Asus\Wireless Console 3\wcourier.exe
      (Bitsum LLC) C:\Program Files\Process Lasso\ProcessGovernor.exe
      (Bitsum LLC) C:\Program Files\Process Lasso\ProcessLasso.exe
      (Smadsoft) C:\Program Files (x86)\SMADAV\SMΔRTP.exe
      (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\USBChargerPlus\USBChargerPlus.exe
      (ASUS) C:\Program Files (x86)\Asus\ASUS InstantOn\InsOnSrv.exe
      (cFos Software GmbH) C:\Program Files\cFosSpeed\spd.exe
      (ASUS) C:\Program Files (x86)\Asus\ASUS InstantOn\InsOnWMI.exe
      (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
      (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
      (Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
      (Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
      (ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
      (Intel Corporation) C:\Windows\System32\igfxtray.exe
      (Intel Corporation) C:\Windows\System32\hkcmd.exe
      (Intel Corporation) C:\Windows\System32\igfxpers.exe
      (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
      (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
      (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
      (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
      (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
      (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
      (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
      () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
      (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
      (Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe
      () C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe
      (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
      (Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
      (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
      (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
      (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
      (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
      (arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
      (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
      (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
      (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
      (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
      (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
      (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\ATK Package\ATKOSD2\ATKOSD2.exe
      (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
      () C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd\2.0.0_0\Plugin\SPNativeMessage.exe
      (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
      (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
      (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
      (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
      (AIMP DevTeam) C:\Program Files\AIMP3\AIMP3.exe
      (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
      (EJIE Technology) C:\Program Files (x86)\Clover\clover.exe
      () C:\Program Files\Cyborg Telkomsel Mobile Broadband\App.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (IObit) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
       
       
      ==================== Registry (Whitelisted) ==================
       
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
       
      HKLM\…\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\btvstack.exe [1023104 2012-08-10] (Atheros Commnucations)
      HKLM\…\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\athbttray.exe [801920 2012-08-10] (Atheros Commnucations)
      HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585928 2015-01-16] (NVIDIA Corporation)
      HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [479232 2012-12-15] (Adobe Systems Incorporated)
      HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
      HKLM\…\Run: [cFosSpeed] => C:\Program Files\cFosSpeed\cFosSpeed.exe [1591744 2015-01-19] (cFos Software GmbH)
      HKLM\…\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5581888 2014-02-24] (ESET)
      HKLM-x32\…\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [377368 2013-10-23] (Power Software Ltd)
      HKLM-x32\…\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [1802240 2014-10-13] (IObit)
      Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
      HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [GoogleChromeAutoLaunch_A9AC9B5C6255D671A633D32EA1A22B00] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [809472 2015-03-31] (Google Inc.)
      HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3890768 2015-04-13] (Tonec Inc.)
      HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7451928 2015-03-13] (Piriform Ltd)
      HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673088 2013-03-14] (Disc Soft Ltd)
      HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Policies\Explorer: [] 
      AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174856 2014-09-14] (NVIDIA Corporation)
      AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156840 2014-09-14] (NVIDIA Corporation)
      ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
      ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)
      ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
      ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
      BootExecute: RegistryDefragBootTime.exeautocheck autochk * 
       
      ==================== Internet (Whitelisted) ====================
       
      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
       
      HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
      HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
      HKU\S-1-5-21-3901189400-636743289-3933302658-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
      HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
      HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
      HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
      SearchScopes: HKU\S-1-5-21-3901189400-636743289-3933302658-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear
      BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-02-21] (Internet Download Manager, Tonec Inc.)
      BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-01-09] (IObit)
      BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
      BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
      BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
      BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
      BHO: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> C:\Program Files (x86)\Clover\TabHelper64.dll [2014-01-23] (EJIE Technology)
      BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-02-21] (Internet Download Manager, Tonec Inc.)
      BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
      BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
      BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
      Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll [2015-02-20] (Microsoft Corporation)
      Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll [2015-02-20] (Microsoft Corporation)
      Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
      Tcpip\..\Interfaces\{16069F89-842A-43F8-BE08-AAEEDB44675E}: [NameServer] 114.5.5.77 114.5.5.5
      Tcpip\..\Interfaces\{2E385CBD-E7DB-4717-B418-9B593B66AADC}: [NameServer] 8.26.56.26,8.20.247.20
      Tcpip\..\Interfaces\{2EE81293-715E-4B59-B7EF-634063A4DE30}: [NameServer] 8.26.56.26,8.20.247.20
      Tcpip\..\Interfaces\{762575E4-6EED-446D-B604-9F528B812946}: [NameServer] 8.26.56.26,8.20.247.20
       
      FireFox:
      ========
      FF ProfilePath: C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default
      FF NetworkProxy: "gopher", ""
      FF NetworkProxy: "gopher_port", 0
      FF NetworkProxy: "share_proxy_settings", true
      FF NetworkProxy: "type", 0
      FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-15] ()
      FF Plugin: @microsoft.com/GENUINE -> disabled No File
      FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
      FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-12-15] (Adobe Systems)
      FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-15] ()
      FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll [2015-01-09] (Adobe Systems, Inc.)
      FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
      FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-08] (Google)
      FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)
      FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
      FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
      FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)
      FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2014-05-22] (Nitro PDF)
      FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
      FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
      FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
      FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
      FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-12-15] (Adobe Systems)
      FF user.js: detected! => C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\user.js [2015-04-12]
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-01-20] (Apple Inc.)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-01-20] (Apple Inc.)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-01-20] (Apple Inc.)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-01-20] (Apple Inc.)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-01-20] (Apple Inc.)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2014-01-20] (Apple Inc.)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2014-01-20] (Apple Inc.)
      FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\Extensions\[removed] [2015-01-09]
      FF Extension: Auto Hide IP - C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\Extensions\[removed] [2014-07-20]
      FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-15]
      FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-15]
      FF HKLM\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
      FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2015-04-13]
      FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
      FF HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5
      FF Extension: IDM CC - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5 [2015-04-13]
      FF HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5
       
      Chrome: 
      =======
      CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.703\_platform_specific\win_x86\widevinecdmadapter.dll No File
      CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.118\PepperFlash\pepflashplayer.dll ()
      CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
      CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.118\internal-nacl-plugin No File
      CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.118\pdf.dll ()
      CHR Plugin: (Internet Download Manager Plugin) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn\6.21.16_0\IDMGCExt.dll No File
      CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
      CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
      CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
      CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
      CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
      CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
      CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
      CHR Plugin: (Nero Kwik Media Helper) - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
      CHR Plugin: (Microsoft Office 2013) - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
      CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
      CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
      CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
      CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
      CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
      CHR Plugin: (Microsoft Office 2013) - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
      CHR Plugin: (Nitro PDF plugin for Firefox and Chrome) - C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF)
      CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
      CHR Profile: C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default
      CHR Extension: (Google Translate) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2014-10-23]
      CHR Extension: (Xmarks Bookmark Sync) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajpgkpeckebdhofmmjfgcjjiiejpodla [2013-12-16]
      CHR Extension: (From Dust) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\anelkojiepicmcldgnmkplocifmegpfj [2013-12-16]
      CHR Extension: (Google Docs) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-20]
      CHR Extension: (Google Drive) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-20]
      CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd [2015-04-12]
      CHR Extension: (WOT) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2013-11-20]
      CHR Extension: (YouTube) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-20]
      CHR Extension: (Adblock Plus) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-20]
      CHR Extension: (Google Search) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-20]
      CHR Extension: (Tampermonkey) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-12-16]
      CHR Extension: (Photo Zoom for Facebook) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2013-11-20]
      CHR Extension: (AdBlock) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-11-20]
      CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-07]
      CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-02]
      CHR Extension: (IDM Integration Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-04-13]
      CHR Extension: (Google Wallet) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-20]
      CHR Extension: (Checker Plus for Gmail™) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2013-11-20]
      CHR Extension: (Gmail) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-20]
      CHR HKLM\…\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]
      CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]
      CHR HKU\S-1-5-21-3901189400-636743289-3933302658-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
      CHR HKLM-x32\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]
       
      ==================== Services (Whitelisted) =================
       
      (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
       
      R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [598016 2014-09-04] (Autodesk Inc.) [File not signed]
      R2 AdvancedSystemCareService8; C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [815392 2014-11-04] (IObit)
      R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
      S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [216906 2012-08-10] (Atheros Commnucations) [File not signed]
      S4 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [32768 2014-02-07] (Autodesk, Inc.) [File not signed]
      S4 CDROM_Detect; C:\Program Files\Cyborg Telkomsel Mobile Broadband\WCDMA_Eject.exe [325632 2013-06-08] () [File not signed]
      R2 cFosSpeedS; C:\Program Files\cFosSpeed\spd.exe [500672 2015-01-19] (cFos Software GmbH)
      R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [117704 2015-01-09] (Intel Corporation)
      R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116680 2015-01-09] (Intel Corporation)
      R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1343408 2014-02-24] (ESET)
      S4 EMP_UDSA; C:\Program Files (x86)\EPSON Projector\Epson USB Display V1.5\EMP_UDSA.exe [98304 2011-01-06] (SEIKO EPSON CORPORATION) [File not signed]
      S4 FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [1362426 2014-10-02] (Flexera Software LLC) [File not signed]
      R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2015-01-16] (NVIDIA Corporation)
      R2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116736 2013-11-20] (Google Inc.) [File not signed]
      S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116736 2013-11-20] (Google Inc.) [File not signed]
      S3 gusvc; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [136192 2011-05-10] (Google) [File not signed]
      R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
      R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [344896 2014-09-30] (IObit)
      S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2630656 2014-11-04] (IObit) [File not signed]
      S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
      R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
      S3 MozillaMaintenance; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [115200 2014-12-15] (Mozilla Foundation) [File not signed]
      S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [278010 2012-08-23] () [File not signed]
      R2 NitroDriverReadSpool9; C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe [230920 2014-05-22] (Nitro PDF Software)
      R2 NitroUpdateService; C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe [417800 2014-05-22] ()
      R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706312 2015-01-16] (NVIDIA Corporation)
      S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21838866 2015-01-16] (NVIDIA Corporation) [File not signed]
      S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1903616 2014-12-18] (Electronic Arts) [File not signed]
      S4 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-11-26] ()
      R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2013-09-13] (arvato digital services llc)
      S4 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275264 2013-10-09] (Skype Technologies S.A.) [File not signed]
      R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2014-12-02] (Western Digital Technologies, Inc.)
      R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [296312 2014-06-02] (Western Digital Technologies, Inc.)
      R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
      S4 ZAtheros Bt&Wlan; Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [327680 2012-08-10] (Atheros) [File not signed]
      S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3347962 2012-08-23] (Intel® Corporation) [File not signed]
       
      ==================== Drivers (Whitelisted) ====================
       
      (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
       
      S3 ampa; C:\Windows\system32\ampa.sys [15288 2011-12-26] () [File not signed]
      S3 ampa; C:\Windows\SysWOW64\ampa.sys [12728 2011-12-26] () [File not signed]
      R3 ATP; C:\Windows\System32\DRIVERS\AsusTP.sys [70416 2015-01-09] (ASUS Corporation)
      R3 CT_QUALCOMM_U_drv; C:\Windows\System32\DRIVERS\CT_QUALCOMM_U_drv.sys [118016 2009-04-27] (QUALCOMM Incorporated)
      R3 DptfDevDram; C:\Windows\System32\DRIVERS\DptfDevDram.sys [145640 2015-01-09] (Intel Corporation)
      R3 DptfDevFan; C:\Windows\System32\DRIVERS\DptfDevFan.sys [50640 2015-01-09] (Intel Corporation)
      R3 DptfDevGen; C:\Windows\System32\DRIVERS\DptfDevGen.sys [78504 2015-01-09] (Intel Corporation)
      R3 DptfDevProc; C:\Windows\System32\DRIVERS\DptfDevProc.sys [289744 2015-01-09] (Intel Corporation)
      R3 DptfManager; C:\Windows\System32\DRIVERS\DptfManager.sys [494296 2015-01-09] (Intel Corporation)
      R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-11-03] (DT Soft Ltd)
      R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
      U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET)
      R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
      R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [30752 2014-04-07] (EldoS Corporation)
      R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET)
      R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)
      R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET)
      R3 eppvad_simple; C:\Windows\System32\drivers\EMP_UDAU.sys [23040 2011-01-06] (SEIKO EPSON CORPORATION)
      S3 esgiguard; C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [14872 2014-01-07] ()
      R3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2013-03-23] (IObit)
      R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-01-03] (REALiX™)
      R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-12-18] (Intel Corporation)
      R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [17280 2012-08-05] ( )
      R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
      S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-04-15] (Malwarebytes Corporation)
      R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
      R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [129312 2015-03-23] (Intel Corporation)
      S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19784 2015-01-16] (NVIDIA Corporation)
      R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
      S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
      S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
      R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2013-11-19] (IObit.com)
      S3 REN2CAP_DRIVER; C:\Windows\System32\drivers\ren2cap.sys [46728 2011-11-07] ()
      S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [74240 2015-01-09] (Research In Motion Limited)
      S3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [455240 2013-03-05] (RTS Corporation)
      R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
      R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-12-09] (Duplex Secure Ltd.)
      U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-04-12] ()
      R3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2013-11-19] (IObit.com)
      U3 azbz9zfj; C:\Windows\System32\Drivers\azbz9zfj.sys [0 ] (Intel Corporation) <==== ATTENTION (zero size file/folder)
      S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X]
      S3 catchme; \??\C:\Worksnow\catchme.sys [X]
      S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X]
      S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
      S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
      S3 PCFApiUtil; \??\C:\Program Files (x86)\Baidu Security\PC Faster\PCFApiUtil64.sys [X]
      S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
      S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
      S3 VGPU; System32\drivers\rdvgkmd.sys [X]
      S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
      S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
      U3 aswMBR; \??\C:\Users\Defhawk\AppData\Local\Temp\aswMBR.sys [X]
      U3 aswVmm; \??\C:\Users\Defhawk\AppData\Local\Temp\aswVmm.sys [X]
       
      ==================== NetSvcs (Whitelisted) ===================
       
      (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
       
       
      ==================== One Month Created Files and Folders ========
       
      (If an entry is included in the fixlist, the file\folder will be moved.)
       
      2015-04-15 21:19 - 2015-04-15 21:20 - 00038695 _____ () C:\Users\Defhawk\Desktop\FRST.txt
      2015-04-15 21:19 - 2015-04-15 21:20 - 00000000 ____D () C:\FRST
      2015-04-15 21:19 - 2015-04-15 21:18 - 02097152 _____ (Farbar) C:\Users\Defhawk\Desktop\FRST64.exe
      2015-04-15 21:17 - 2015-04-15 21:17 - 00001447 _____ () C:\Users\Defhawk\Desktop\aswMBR.txt
      2015-04-15 21:17 - 2015-04-15 21:17 - 00000512 _____ () C:\Users\Defhawk\Desktop\MBR.dat
      2015-04-15 21:15 - 2015-04-15 21:15 - 05198336 _____ (AVAST Software) C:\Users\Defhawk\Desktop\aswMBR.exe
      2015-04-15 19:36 - 2015-04-15 19:38 - 00001131 _____ () C:\Users\Defhawk\Desktop\PTE.lnk
      2015-04-15 19:20 - 2015-04-15 19:46 - 00000000 ____D () C:\Program Files (x86)\Pro Evolution Soccer 2015
      2015-04-15 19:20 - 2015-04-15 19:20 - 00000902 _____ () C:\Users\Public\Desktop\Pro Evolution Soccer 2015.lnk
      2015-04-15 10:08 - 2015-04-15 10:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
      2015-04-15 10:01 - 2015-04-15 10:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
      2015-04-14 23:05 - 2015-04-14 23:05 - 00001228 _____ () C:\Users\Public\Desktop\IObit Uninstaller.lnk
      2015-04-14 23:01 - 2015-04-15 10:05 - 00000000 ____D () C:\Program Files\Microsoft Office
      2015-04-14 18:17 - 2015-04-14 18:17 - 00000000 __RHD () C:\MSOCache
      2015-04-14 18:06 - 2015-04-14 18:06 - 00019570 _____ () C:\Users\Defhawk\Documents\140415.reg
      2015-04-14 11:59 - 2015-04-15 13:04 - 00004410 _____ () C:\Windows\setupact.log
      2015-04-14 11:59 - 2015-04-14 11:59 - 00000000 _____ () C:\Windows\setuperr.log
      2015-04-14 11:58 - 2015-04-15 10:29 - 00020594 _____ () C:\Windows\PFRO.log
      2015-04-14 01:26 - 2015-04-14 01:26 - 00486050 _____ () C:\Users\Defhawk\Documents\UninstallKey01.reg
      2015-04-14 01:24 - 2015-04-14 01:24 - 00869656 _____ () C:\Users\Defhawk\Documents\DeletedKey01.reg
      2015-04-14 00:50 - 2015-04-14 00:50 - 00020224 _____ () C:\Users\Defhawk\Documents\install.txt
      2015-04-14 00:50 - 2015-04-14 00:50 - 00000282 _____ () C:\Windows\Tasks\Uninstaller_SkipUac_Defhawk.job
      2015-04-14 00:45 - 2015-04-14 00:45 - 00000000 ____D () C:\Users\Default\AppData\Roaming\IObit
      2015-04-14 00:45 - 2015-04-14 00:45 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\IObit
      2015-04-14 00:17 - 2015-04-14 00:17 - 00001932 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Pro 9.lnk
      2015-04-14 00:17 - 2015-04-14 00:17 - 00001920 _____ () C:\Users\Public\Desktop\Nitro Pro 9.lnk
      2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files\Nitro
      2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files\Common Files\Nitro
      2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files (x86)\Nitro
      2015-04-14 00:17 - 2014-05-22 14:05 - 00029704 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalmon9.dll
      2015-04-14 00:17 - 2014-05-22 14:05 - 00017928 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalui9.dll
      2015-04-13 23:49 - 2015-04-13 23:49 - 00000000 ___SD () C:\Windows\system32\CompatTel
      2015-04-13 23:49 - 2015-04-13 23:49 - 00000000 ____D () C:\Windows\system32\appraiser
      2015-04-13 23:44 - 2015-04-13 23:44 - 00001077 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
      2015-04-13 23:44 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
      2015-04-13 23:14 - 2013-10-02 09:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
      2015-04-13 23:14 - 2013-10-02 09:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
      2015-04-13 23:14 - 2013-10-02 09:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
      2015-04-13 23:14 - 2013-10-02 08:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
      2015-04-13 23:14 - 2013-10-02 08:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
      2015-04-13 23:14 - 2013-10-02 08:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
      2015-04-13 23:14 - 2013-10-02 08:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
      2015-04-13 23:14 - 2013-10-02 07:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
      2015-04-13 23:14 - 2013-10-02 07:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
      2015-04-13 23:14 - 2013-10-02 07:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
      2015-04-13 23:14 - 2013-10-02 07:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
      2015-04-13 23:14 - 2013-10-02 07:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
      2015-04-13 23:14 - 2013-10-02 06:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
      2015-04-13 23:14 - 2013-10-02 06:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
      2015-04-13 23:14 - 2013-10-02 06:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
      2015-04-13 23:14 - 2013-10-02 05:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
      2015-04-13 23:14 - 2013-10-02 03:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
      2015-04-13 23:14 - 2013-10-02 03:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
      2015-04-13 23:13 - 2015-03-25 10:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
      2015-04-13 23:13 - 2015-03-25 10:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
      2015-04-13 23:13 - 2015-03-25 10:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
      2015-04-13 23:13 - 2015-03-25 10:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
      2015-04-13 23:13 - 2015-03-25 10:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
      2015-04-13 23:13 - 2015-03-25 10:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
      2015-04-13 23:13 - 2015-03-25 10:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
      2015-04-13 23:13 - 2015-03-25 10:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
      2015-04-13 23:13 - 2015-03-25 10:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
      2015-04-13 23:13 - 2015-03-25 10:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
      2015-04-13 23:13 - 2015-03-25 10:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
      2015-04-13 23:13 - 2015-03-25 10:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
      2015-04-13 23:13 - 2015-03-25 10:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
      2015-04-13 23:13 - 2015-03-25 10:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
      2015-04-13 23:13 - 2015-03-25 10:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
      2015-04-13 23:13 - 2015-03-25 10:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
      2015-04-13 23:12 - 2015-03-23 10:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
      2015-04-13 23:12 - 2015-03-23 10:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
      2015-04-13 23:12 - 2015-03-23 10:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
      2015-04-13 23:12 - 2015-03-23 10:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
      2015-04-13 23:12 - 2015-03-23 10:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
      2015-04-13 23:12 - 2015-03-23 10:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
      2015-04-13 23:12 - 2015-03-23 10:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
      2015-04-13 23:12 - 2015-03-23 10:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
      2015-04-13 23:12 - 2015-01-28 06:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
      2015-04-13 22:51 - 2015-04-13 22:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
      2015-04-13 22:38 - 2015-04-13 22:38 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
      2015-04-13 22:38 - 2015-04-13 22:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
      2015-04-13 22:26 - 2015-04-13 22:26 - 00000000 ____D () C:\ProgramData\ESET
      2015-04-13 22:19 - 2015-04-13 22:19 - 00055680 _____ () C:\Users\Defhawk\Documents\cc_20150413_221934.reg
      2015-04-13 20:27 - 2015-04-13 20:27 - 00000812 _____ () C:\Users\Public\Desktop\PowerISO.lnk
      2015-04-13 20:27 - 2015-04-13 20:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
      2015-04-13 20:20 - 2015-04-13 20:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
      2015-04-13 20:20 - 2015-04-13 20:20 - 00000000 ____D () C:\Program Files (x86)\K-Lite Codec Pack
      2015-04-13 20:20 - 2013-10-26 01:00 - 00127488 _____ () C:\Windows\system32\ff_vfw.dll
      2015-04-13 20:20 - 2013-10-26 01:00 - 00112640 _____ () C:\Windows\SysWOW64\ff_vfw.dll
      2015-04-13 20:20 - 2013-03-18 00:22 - 03554304 _____ (x264vfw project) C:\Windows\system32\x264vfw64.dll
      2015-04-13 20:20 - 2013-03-17 23:21 - 03649536 _____ (x264vfw project) C:\Windows\SysWOW64\x264vfw.dll
      2015-04-13 20:20 - 2012-07-21 17:54 - 00122880 _____ (fccHandler) C:\Windows\SysWOW64\ac3acm.acm
      2015-04-13 20:20 - 2011-12-08 00:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll
      2015-04-13 20:20 - 2011-12-08 00:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\lagarith.dll
      2015-04-13 20:20 - 2011-06-24 21:45 - 00258560 _____ () C:\Windows\system32\xvidvfw.dll
      2015-04-13 20:20 - 2011-06-24 21:44 - 00243200 _____ () C:\Windows\SysWOW64\xvidvfw.dll
      2015-04-12 23:52 - 2015-04-12 23:52 - 00001860 _____ () C:\Users\Defhawk\Desktop\mbam120415.txt
      2015-04-12 20:53 - 2015-04-12 20:53 - 00000000 ____D () C:\ProgramData\KONAMI
      2015-04-12 18:38 - 2015-04-12 18:39 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files
      2015-04-12 18:30 - 2015-04-12 18:30 - 00045107 _____ () C:\ComboFix.txt
      2015-04-12 18:02 - 2011-06-26 13:45 - 00256000 _____ () C:\Windows\PEV.exe
      2015-04-12 18:02 - 2010-11-08 00:20 - 00208896 _____ () C:\Windows\MBR.exe
      2015-04-12 18:02 - 2009-04-20 11:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
      2015-04-12 18:02 - 2000-08-31 07:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
      2015-04-12 18:02 - 2000-08-31 07:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
      2015-04-12 18:02 - 2000-08-31 07:00 - 00098816 _____ () C:\Windows\sed.exe
      2015-04-12 18:02 - 2000-08-31 07:00 - 00080412 _____ () C:\Windows\grep.exe
      2015-04-12 18:02 - 2000-08-31 07:00 - 00068096 _____ () C:\Windows\zip.exe
      2015-04-12 17:58 - 2015-04-12 18:30 - 00000000 ____D () C:\Qoobox
      2015-04-12 17:58 - 2015-04-12 18:27 - 00000000 ____D () C:\Windows\erdnt
      2015-04-12 17:49 - 2015-04-12 17:50 - 05617275 ____R (Swearware) C:\Users\Defhawk\Desktop\Worksnow.com
      2015-04-12 17:07 - 2015-04-12 17:08 - 00448512 _____ (OldTimer Tools) C:\Users\Defhawk\Downloads\TFC.exe
      2015-04-12 17:05 - 2015-04-12 17:06 - 00294400 _____ () C:\Users\Defhawk\Desktop\exeHelper.com
      2015-04-12 16:50 - 2015-04-12 16:50 - 00001072 _____ () C:\Users\Public\Desktop\SMADΔV.lnk
      2015-04-12 14:46 - 2015-04-12 14:46 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DEF-PC-Windows-7-Ultimate-(64-bit).dat
      2015-04-12 14:45 - 2015-04-12 14:45 - 00003652 _____ () C:\Windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
      2015-04-12 14:45 - 2015-04-12 14:45 - 00002159 _____ () C:\Users\Defhawk\Desktop\Tweaking.com - Windows Repair.lnk
      2015-04-12 14:39 - 2015-04-12 14:42 - 12849664 _____ () C:\Users\Defhawk\Downloads\tweaking.com_windows_repair_aio_setup.exe
      2015-04-12 14:34 - 2015-04-12 14:34 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
      2015-04-12 14:34 - 2015-04-12 14:34 - 00000000 ___SD () C:\Windows\system32\GWX
      2015-04-12 14:04 - 2015-04-12 15:51 - 00318769 _____ () C:\Users\Defhawk\Desktop\MGlogs.zip
      2015-04-12 13:55 - 2015-04-12 15:51 - 00318769 _____ () C:\MGlogs.zip
      2015-04-12 13:55 - 2015-04-12 15:51 - 00000000 ____D () C:\MGtools
      2015-04-12 13:55 - 2015-04-12 13:55 - 00000000 ____D () C:\ProgramData\HitmanPro
      2015-04-12 13:14 - 2015-04-12 13:14 - 00002643 _____ () C:\Users\Defhawk\Desktop\RKreport_SCN_04122015_131010.log
      2015-04-12 13:02 - 2015-04-12 13:34 - 00000000 ____D () C:\ProgramData\RogueKiller
      2015-04-12 13:02 - 2015-04-12 13:02 - 00035064 _____ () C:\Windows\system32\Drivers\TrueSight.sys
      2015-04-12 13:01 - 2015-04-12 21:40 - 01994752 _____ () C:\Users\Defhawk\Desktop\MGtools.exe
      2015-04-12 13:01 - 2015-04-12 12:58 - 10109952 _____ (SurfRight B.V.) C:\Users\Defhawk\Desktop\HitmanPro.exe
      2015-04-12 13:00 - 2015-04-12 13:00 - 01994752 _____ () C:\Users\Defhawk\Downloads\MGtools.exe
      2015-04-12 12:54 - 2015-04-12 12:58 - 10109952 _____ (SurfRight B.V.) C:\Users\Defhawk\Downloads\HitmanPro.exe
      2015-04-12 12:50 - 2015-04-12 12:49 - 04197376 _____ (Kaspersky Lab ZAO) C:\Users\Defhawk\Downloads\tdsskiller.exe
      2015-04-12 12:50 - 2015-04-12 12:40 - 16849920 _____ () C:\Users\Defhawk\Downloads\RogueKiller.exe
      2015-04-12 12:47 - 2015-04-12 12:49 - 04197376 _____ (Kaspersky Lab ZAO) C:\Users\Defhawk\Desktop\tdsskiller.exe
      2015-04-12 12:41 - 2015-04-12 12:41 - 00454551 _____ () C:\Users\Defhawk\Downloads\(every program) is not a valid win32 application - MajorGeeks Support Forums.html
      2015-04-12 12:41 - 2015-04-12 12:41 - 00000000 ____D () C:\Users\Defhawk\Downloads\(every program) is not a valid win32 application - MajorGeeks Support Forums_files
      2015-04-12 12:34 - 2015-04-12 12:38 - 01990828 _____ () C:\Users\Defhawk\Downloads\Unconfirmed 964814.crdownload
      2015-04-12 12:33 - 2015-04-12 12:40 - 16849920 _____ () C:\Users\Defhawk\Desktop\RogueKiller.exe
      2015-04-12 11:32 - 2015-04-12 11:32 - 00000000 ____D () C:\Users\Defhawk\Desktop\rkill
      2015-04-12 03:12 - 2015-04-12 03:12 - 00000416 _____ () C:\Users\Defhawk\120415backup.reg
      2015-04-12 03:06 - 2015-04-12 11:36 - 00002528 _____ () C:\Users\Defhawk\Desktop\Rkill.txt
      2015-04-12 01:08 - 2015-04-12 01:08 - 00001646 _____ () C:\Users\Defhawk\Documents\cc_20150412_010800.reg
      2015-04-12 00:44 - 2011-06-11 05:15 - 05601616 _____ (Microsoft Corporation) C:\Windows\system32\mfc100u.dll
      2015-04-12 00:44 - 2011-06-11 05:15 - 05574984 _____ (Microsoft Corporation) C:\Windows\system32\mfc100.dll
      2015-04-12 00:14 - 2010-03-18 19:27 - 00827744 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll
      2015-04-11 16:46 - 2015-04-11 16:49 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\WCDMA_General
      2015-04-11 16:46 - 2015-04-11 16:46 - 00000916 _____ () C:\Users\Public\Desktop\Cyborg Telkomsel Mobile Broadband.lnk
      2015-04-11 16:46 - 2015-04-11 16:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cyborg Telkomsel Mobile Broadband
      2015-04-11 16:46 - 2015-04-11 16:46 - 00000000 ____D () C:\Program Files\Cyborg Telkomsel Mobile Broadband
      2015-04-11 16:46 - 2009-04-27 16:33 - 00118016 _____ (QUALCOMM Incorporated) C:\Windows\system32\Drivers\CT_QUALCOMM_U_drv.sys
      2015-04-11 13:05 - 2015-04-11 13:14 - 45473792 _____ () C:\Windows\system32\config\components.old
      2015-04-08 20:55 - 2015-04-08 21:13 - 00002274 _____ () C:\Users\Defhawk\Desktop\FixExec.txt
      2015-04-05 13:46 - 2015-04-05 13:47 - 45473792 _____ () C:\Windows\system32\config\COMPONENTS.iobit
      2015-04-05 01:19 - 2015-04-05 01:19 - 00003342 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup
      2015-04-05 01:19 - 2015-04-05 01:19 - 00002248 _____ () C:\Users\Defhawk\Desktop\SpyHunter.lnk
      2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
      2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\sh4ldr
      2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group
      2015-04-05 00:10 - 2015-04-05 00:10 - 76125026 _____ () C:\Users\Defhawk\Downloads\Tomorrowland 2014 - official aftermovie - YouTube.MKV
      2015-04-03 13:26 - 2015-04-03 13:26 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DEF-PC-Microsoft-Windows-7-Ultimate-(64-bit).dat
      2015-04-03 13:26 - 2015-04-03 13:26 - 00000000 ____D () C:\RegBackup
      2015-04-02 21:41 - 2015-04-15 19:20 - 00000914 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro Evolution Soccer 2015.lnk
      2015-04-01 19:10 - 2013-10-18 15:01 - 00285747 _____ () C:\shldr
      2015-04-01 19:10 - 2013-10-18 15:01 - 00008192 _____ () C:\shldr.mbr
      2015-04-01 00:33 - 2015-04-15 11:29 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
      2015-04-01 00:33 - 2015-04-01 00:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
      2015-04-01 00:33 - 2015-04-01 00:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
      2015-04-01 00:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
      2015-04-01 00:33 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
      2015-03-31 22:39 - 2015-03-31 22:39 - 00000000 _____ () C:\autoexec.bat
      2015-03-31 21:37 - 2015-04-01 00:33 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
      2015-03-31 21:37 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
      2015-03-23 22:46 - 2015-03-23 22:46 - 00001058 _____ () C:\Users\Public\Desktop\Smart Defrag 4.lnk
      2015-03-23 22:46 - 2015-03-23 22:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 4
      2015-03-23 22:46 - 2015-01-10 15:32 - 00128288 _____ (IObit) C:\Windows\system32\IObitSmartDefragExtension.dll
      2015-03-23 22:46 - 2014-06-04 15:17 - 00034080 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe
      2015-03-23 22:46 - 2014-06-04 15:17 - 00021184 _____ (IObit) C:\Windows\system32\Drivers\SmartDefragDriver.sys
      2015-03-23 22:40 - 2015-03-23 22:40 - 00943832 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
      2015-03-23 22:40 - 2015-03-23 22:40 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
      2015-03-23 22:39 - 2015-03-23 22:39 - 00129312 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys
      2015-03-17 20:08 - 2015-03-17 19:53 - 00189912 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys
       
      ==================== One Month Modified Files and Folders =======
       
      (If an entry is included in the fixlist, the file\folder will be moved.)
       
      2015-04-15 21:17 - 2015-02-05 18:12 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57.job
      2015-04-15 21:17 - 2014-04-01 05:10 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6.job
      2015-04-15 21:14 - 2014-03-31 11:30 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\IDM
      2015-04-15 21:12 - 2014-04-09 22:55 - 00000000 ____D () C:\ProgramData\ProductData
      2015-04-15 21:12 - 2009-07-14 12:13 - 00776420 _____ () C:\Windows\system32\PerfStringBackup.INI
      2015-04-15 21:11 - 2015-01-03 04:36 - 00002858 _____ () C:\Windows\System32\Tasks\Driver Booster SkipUAC (Defhawk)
      2015-04-15 21:09 - 2013-11-20 00:11 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
      2015-04-15 20:27 - 2015-01-09 17:37 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
      2015-04-15 20:14 - 2009-07-14 11:45 - 00021200 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
      2015-04-15 20:14 - 2009-07-14 11:45 - 00021200 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
      2015-04-15 19:45 - 2013-11-05 15:39 - 00000000 ____D () C:\Program Files (x86)\Steam
      2015-04-15 19:37 - 2013-11-04 00:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\AIMP3
      2015-04-15 19:26 - 2013-11-07 01:32 - 01301481 _____ () C:\Windows\WindowsUpdate.log
      2015-04-15 19:05 - 2013-11-04 18:00 - 00000000 ____D () C:\Users\Defhawk\Documents\Bluetooth Folder
      2015-04-15 18:40 - 2014-03-30 02:51 - 00000000 ____D () C:\Program Files\Corel
      2015-04-15 18:40 - 2013-11-04 17:40 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Corel
      2015-04-15 18:40 - 2013-11-04 17:30 - 00000000 ____D () C:\ProgramData\Corel
      2015-04-15 18:37 - 2014-03-30 02:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)
      2015-04-15 18:17 - 2015-02-05 18:12 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5.job
      2015-04-15 18:17 - 2014-04-01 05:10 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d.job
      2015-04-15 13:15 - 2014-12-02 01:16 - 00000000 ____D () C:\Users\Defhawk\Documents\SnowFox Total Video Converter
      2015-04-15 13:15 - 2014-05-24 20:49 - 00000000 ____D () C:\Users\Defhawk\Documents\Scanned
      2015-04-15 12:59 - 2014-03-18 14:56 - 00000000 ____D () C:\Program Files (x86)\SMADAV
      2015-04-15 12:58 - 2009-07-14 12:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
      2015-04-15 12:55 - 2013-11-03 15:05 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\DMCache
      2015-04-15 10:34 - 2009-07-14 11:45 - 05979304 _____ () C:\Windows\system32\FNTCACHE.DAT
      2015-04-15 10:31 - 2013-11-03 12:30 - 00490216 _____ () C:\Users\Defhawk\AppData\Local\GDIPFONTCACHEV1.DAT
      2015-04-15 10:09 - 2013-11-04 16:03 - 00000000 ____D () C:\ProgramData\Microsoft Help
      2015-04-15 10:07 - 2014-05-11 14:29 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\vlc
      2015-04-15 10:03 - 2009-07-14 09:34 - 00000514 _____ () C:\Windows\win.ini
      2015-04-15 10:01 - 2009-07-14 10:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
      2015-04-15 01:26 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\AppCompat
      2015-04-15 00:25 - 2009-07-14 14:46 - 00000000 ____D () C:\Windows\CSC
      2015-04-15 00:20 - 2013-11-04 00:36 - 00003160 _____ () C:\Windows\System32\Tasks\SidebarExecute
      2015-04-15 00:12 - 2013-11-03 12:33 - 00776420 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
      2015-04-14 23:09 - 2013-11-05 03:31 - 00000000 ____D () C:\Users\Defhawk\AppData\Local\CrashDumps
      2015-04-14 06:48 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\rescache
      2015-04-14 01:15 - 2013-11-03 19:08 - 00000000 ____D () C:\ProgramData\USBChargerPlus
      2015-04-14 01:04 - 2014-05-02 23:18 - 00000000 ____D () C:\Users\Defhawk\AppData\Local\VMware
      2015-04-14 01:04 - 2013-11-03 10:54 - 00000000 ____D () C:\Users\Defhawk
      2015-04-14 01:04 - 2009-07-14 10:20 - 00000000 ___RD () C:\Users\Default
      2015-04-13 23:53 - 2009-07-14 10:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
      2015-04-13 23:44 - 2014-10-05 00:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
      2015-04-13 23:44 - 2014-10-05 00:33 - 00000000 ____D () C:\Program Files\VS Revo Group
      2015-04-13 22:43 - 2014-06-16 16:13 - 00008192 _____ () C:\Windows\SysWOW64\WDPABKP.dat
      2015-04-13 22:40 - 2013-11-03 13:05 - 00000000 ____D () C:\Program Files\WinRAR
      2015-04-13 22:26 - 2014-12-18 01:40 - 00000000 ____D () C:\Program Files\ESET
      2015-04-13 22:18 - 2013-11-03 23:35 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
      2015-04-13 22:18 - 2013-11-03 23:34 - 00000000 ____D () C:\Program Files\CCleaner
      2015-04-13 21:12 - 2015-01-03 04:35 - 00002104 _____ () C:\Users\Public\Desktop\Driver Booster 2.lnk
      2015-04-13 21:06 - 2014-03-31 11:30 - 00000000 ____D () C:\Program Files (x86)\Internet Download Manager
      2015-04-13 21:06 - 2013-11-04 18:29 - 00000000 ____D () C:\Program Files\PowerISO
      2015-04-13 20:42 - 2013-11-03 10:59 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\DAEMON Tools Lite
      2015-04-13 20:39 - 2013-11-03 15:05 - 00001009 _____ () C:\Users\Defhawk\Desktop\Internet Download Manager.lnk
      2015-04-13 20:34 - 2013-11-04 18:31 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\PowerISO
      2015-04-13 19:29 - 2013-11-04 01:47 - 00000000 ____D () C:\Windows\Panther
      2015-04-12 21:44 - 2014-11-30 03:17 - 00000000 ____D () C:\Users\Defhawk\Downloads\Compressed
      2015-04-12 21:34 - 2014-11-03 01:34 - 00000000 ____D () C:\Users\Defhawk\Downloads\MWD
      2015-04-12 21:34 - 2014-10-25 03:09 - 00000000 ____D () C:\Users\Defhawk\Downloads\Lamaran
      2015-04-12 21:34 - 2014-10-16 02:13 - 00000000 ____D () C:\Users\Defhawk\Downloads\Defraggler Professional Edition v2.18 Final - SceneDL
      2015-04-12 21:34 - 2014-10-03 03:03 - 00000000 ____D () C:\Users\Defhawk\Documents\KONAMI
      2015-04-12 21:34 - 2014-09-24 03:56 - 00000000 ____D () C:\Users\Defhawk\Desktop\Tor Browser
      2015-04-12 20:27 - 2014-03-18 14:56 - 00000000 ____D () C:\[Smad-Cage]
      2015-04-12 18:46 - 2013-11-04 19:58 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\uTorrent
      2015-04-12 18:26 - 2013-11-05 16:27 - 00000000 ____D () C:\ProgramData\TEMP
      2015-04-12 18:23 - 2009-07-14 09:34 - 00000215 _____ () C:\Windows\system.ini
      2015-04-12 18:22 - 2009-07-14 09:34 - 00000027 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_134
      2015-04-12 18:19 - 2009-07-14 09:34 - 41680896 _____ () C:\Windows\system32\config\SYSTEM.bak
      2015-04-12 18:19 - 2009-07-14 09:34 - 103915520 _____ () C:\Windows\system32\config\SOFTWARE.bak
      2015-04-12 18:19 - 2009-07-14 09:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
      2015-04-12 18:19 - 2009-07-14 09:34 - 00065536 _____ () C:\Windows\system32\config\SAM.bak
      2015-04-12 18:19 - 2009-07-14 09:34 - 00028672 _____ () C:\Windows\system32\config\SECURITY.bak
      2015-04-12 16:50 - 2014-12-17 00:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus
      2015-04-12 15:49 - 2013-11-04 20:36 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Nitro PDF
      2015-04-12 11:47 - 2015-01-09 07:52 - 00002141 _____ () C:\Users\Public\Desktop\Advanced SystemCare 8.lnk
      2015-04-12 11:10 - 2013-11-09 13:35 - 00000000 ____D () C:\Windows\MSSecurityNS
      2015-04-12 02:01 - 2009-07-14 11:54 - 00000749 ____R () C:\Windows\WindowsShell.Manifest
      2015-04-12 02:01 - 2009-07-14 10:20 - 00000000 ___RD () C:\Users\Public\Libraries
      2015-04-12 01:05 - 2013-12-01 23:04 - 00000000 ___RD () C:\Users\Defhawk\Dropbox
      2015-04-12 01:05 - 2013-12-01 23:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Dropbox
      2015-04-12 01:04 - 2014-10-31 17:13 - 00000000 ___RD () C:\Users\Defhawk\Google Drive
      2015-04-12 00:55 - 2014-07-20 22:55 - 00000038 _____ () C:\Windows\sysreg.dat
      2015-04-12 00:55 - 2008-03-05 07:47 - 00000072 _____ () C:\Windows\anticrash.dat
      2015-04-12 00:55 - 2008-03-05 07:46 - 00000067 _____ () C:\Windows\hare.dat
      2015-04-12 00:55 - 2001-10-13 13:11 - 00000084 _____ () C:\Windows\battery.dat
      2015-04-11 23:44 - 2009-07-14 11:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
      2015-04-11 23:28 - 2009-07-14 12:08 - 00032582 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
      2015-04-11 20:04 - 2013-12-01 23:04 - 00001021 _____ () C:\Users\Defhawk\Desktop\Dropbox.lnk
      2015-04-11 20:04 - 2013-12-01 23:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
      2015-04-11 16:57 - 2009-07-14 09:34 - 00000883 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_868
      2015-04-11 13:14 - 2009-07-14 09:34 - 41680896 _____ () C:\Windows\system32\config\system.old
      2015-04-11 13:14 - 2009-07-14 09:34 - 103931904 _____ () C:\Windows\system32\config\software.old
      2015-04-11 13:14 - 2009-07-14 09:34 - 00524288 _____ () C:\Windows\system32\config\default.old
      2015-04-11 13:14 - 2009-07-14 09:34 - 00065536 _____ () C:\Windows\system32\config\sam.old
      2015-04-11 13:14 - 2009-07-14 09:34 - 00028672 _____ () C:\Windows\system32\config\security.old
      2015-04-10 09:44 - 2015-01-09 07:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8
      2015-04-10 09:44 - 2014-10-02 21:30 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Autodesk
      2015-04-10 09:44 - 2013-11-17 21:36 - 00000000 ____D () C:\Windows\SysWOW64\My Vaults
      2015-04-10 09:44 - 2013-11-04 18:04 - 00000000 ____D () C:\ProgramData\Atheros
      2015-04-10 09:44 - 2013-11-04 00:36 - 00000000 ____D () C:\ProgramData\P4G
      2015-04-09 18:48 - 2008-03-04 19:57 - 00000338 _____ () C:\Windows\winshell.dat
      2015-04-08 11:55 - 2013-11-03 10:53 - 00000000 ____D () C:\Recovery
      2015-04-08 11:55 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\system32\Msdtc
      2015-04-07 21:54 - 2014-07-20 02:22 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\FirefoxToolbar
      2015-04-07 21:00 - 2009-07-14 12:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
      2015-04-05 19:00 - 2009-07-14 14:45 - 00000000 ___RD () C:\Users\Public\Recorded TV
      2015-04-05 13:12 - 2009-07-14 09:34 - 00000855 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_89
      2015-04-05 12:38 - 2014-04-13 15:06 - 103931904 _____ () C:\Windows\system32\config\SOFTWARE.iodefrag.bak
      2015-04-05 12:38 - 2014-04-13 15:06 - 00446464 _____ () C:\Windows\system32\config\DEFAULT.iodefrag.bak
      2015-04-05 12:38 - 2014-04-13 15:06 - 00065536 _____ () C:\Windows\system32\config\SAM.iodefrag.bak
      2015-04-05 12:38 - 2014-04-13 15:06 - 00028672 _____ () C:\Windows\system32\config\SECURITY.iodefrag.bak
      2015-04-05 12:37 - 2013-11-09 13:35 - 00000000 ____D () C:\Windows\MSSecurityNi
      2015-04-05 01:13 - 2009-07-14 09:34 - 00001117 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_839
      2015-04-04 12:23 - 2013-11-20 00:25 - 00002143 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
      2015-04-01 22:09 - 2013-11-03 17:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
      2015-04-01 19:10 - 2013-11-04 18:00 - 00000000 ____D () C:\Program Files (x86)\Bluetooth Suite
      2015-04-01 06:52 - 2014-09-06 02:46 - 00001908 _____ () C:\Windows\diagwrn.xml
      2015-04-01 06:52 - 2014-09-06 02:46 - 00001908 _____ () C:\Windows\diagerr.xml
      2015-04-01 00:33 - 2013-11-05 16:41 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Malwarebytes
      2015-03-31 18:59 - 2014-07-20 22:58 - 00000000 ____D () C:\Windows\pss
      2015-03-23 22:46 - 2014-04-09 22:55 - 00000000 ____D () C:\Program Files (x86)\IObit
      2015-03-23 22:46 - 2014-04-09 22:53 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\IObit
      2015-03-23 22:40 - 2013-11-03 11:03 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
      2015-03-19 18:15 - 2013-11-24 23:57 - 00000000 ____D () C:\ProgramData\CanonIJPLM
       
      ==================== Files in the root of some directories =======
       
      2013-02-17 10:27 - 2013-02-17 10:27 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
      2014-04-12 23:59 - 2015-02-02 20:46 - 0000132 _____ () C:\Users\Defhawk\AppData\Roaming\Adobe PNG Format CC Prefs
      2013-11-05 02:24 - 2014-01-20 20:07 - 0000132 _____ () C:\Users\Defhawk\AppData\Roaming\Adobe PNG Format CS6 Prefs
      2014-06-20 19:04 - 2014-06-20 19:04 - 0000024 _____ () C:\Users\Defhawk\AppData\Roaming\temp.ini
      2014-01-24 21:49 - 2014-01-24 21:49 - 142848334 _____ () C:\Users\Defhawk\AppData\Local\ACCCx2_3_0_322.zip.aamdownload
      2014-01-24 21:49 - 2014-01-24 21:49 - 0001796 _____ () C:\Users\Defhawk\AppData\Local\ACCCx2_3_0_322.zip.aamdownload.aamd
      2014-01-20 16:57 - 2014-01-20 17:00 - 0001456 _____ () C:\Users\Defhawk\AppData\Local\Adobe Save for Web 13.0 Prefs
      2013-11-07 19:53 - 2013-11-07 19:53 - 0000001 _____ () C:\Users\Defhawk\AppData\Local\llftool.4.30.agreement
      2014-03-18 23:11 - 2014-06-24 23:08 - 0007607 _____ () C:\Users\Defhawk\AppData\Local\Resmon.ResmonCfg
      2013-11-03 12:51 - 2013-11-03 12:52 - 0009486 _____ () C:\Users\Defhawk\AppData\Local\WiDiSetupLog.20131103.125137.txt
      2013-11-04 01:00 - 2013-11-04 01:00 - 0010023 _____ () C:\Users\Defhawk\AppData\Local\WiDiSetupLog.20131104.010029.txt
      2014-03-14 18:49 - 2014-03-14 18:49 - 0000000 _____ () C:\ProgramData\DP45977C.lfl
      2014-10-02 21:45 - 2014-10-02 21:45 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
       
      Files to move or delete:
      ====================
      C:\Users\Defhawk\120415backup.reg
      C:\Users\Defhawk\200714.reg
       
       
      Some content of TEMP:
      ====================
      C:\Users\Defhawk\AppData\Local\Temp\PidGenX.dll
       
       
      ==================== Bamital & volsnap Check =================
       
      (There is no automatic fix for files that do not pass verification.)
       
      C:\Windows\System32\winlogon.exe => File is digitally signed
      C:\Windows\System32\wininit.exe => File is digitally signed
      C:\Windows\SysWOW64\wininit.exe => File is digitally signed
      C:\Windows\explorer.exe => File is digitally signed
      C:\Windows\SysWOW64\explorer.exe => File is digitally signed
      C:\Windows\System32\svchost.exe => File is digitally signed
      C:\Windows\SysWOW64\svchost.exe => File is digitally signed
      C:\Windows\System32\services.exe => File is digitally signed
      C:\Windows\System32\User32.dll => File is digitally signed
      C:\Windows\SysWOW64\User32.dll => File is digitally signed
      C:\Windows\System32\userinit.exe => File is digitally signed
      C:\Windows\SysWOW64\userinit.exe => File is digitally signed
      C:\Windows\System32\rpcss.dll => File is digitally signed
      C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
       
       
      nointegritychecks: ==> Integrity Checks is disabled <===== ATTENTION!
       
       
      LastRegBack: 2015-04-14 06:20
       
      ==================== End Of Log ============================
       
       
       
       
      Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-04-2015 02
      Ran by [removed] at 2015-04-15 21:21:30
      Running from C:\Users\[removed]\Desktop
      Boot Mode: Normal
      ==========================================================
       
       
      ==================== Security Center ========================
       
      (If an entry is included in the fixlist, it will be removed.)
       
      AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
      FW: ESET Personal firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
       
      ==================== Installed Programs ======================
       
      (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
       
      µTorrent (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)
      Akamai NetSession Interface (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Akamai) (Version:  - Akamai Technologies, Inc)
      ASUS Power4Gear Hybrid (HKLM\…\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.2 - ASUS)
      ASUS Screen Saver (HKLM\…\{0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2}) (Version: 1.0.1 - ASUS)
      Atheros Bluetooth Suite (64) (HKLM\…\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.150 - Atheros)
      Atheros Outlook Addin 2010 (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\BB108A893815B64BF41C4574C3324FB7371AA244) (Version: 1.0.0.0 - Microsoft)
      AutoCAD MEP 2015 - English (Version: 7.7.49.0 - Autodesk) Hidden
      AutoCAD MEP 2015 Language Pack - English (Version: 7.7.49.0 - Autodesk) Hidden
      Autodesk 360 (HKLM\…\{556966D9-F7F6-421B-9707-D07901604DDF}) (Version: 5.2.3.1000 - Autodesk)
      Autodesk AutoCAD MEP 2015 - English (HKLM\…\AutoCAD MEP 2015 - English) (Version: 7.7.49.0 - Autodesk)
      Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit (HKLM\…\{9D589081-AFC2-4932-9071-AC585AC1EA83}) (Version: 3.32.3004 - Autodesk)
      Autodesk ReCap (HKLM\…\Autodesk ReCap) (Version: 1.3.1.39 - Autodesk)
      Autodesk ReCap (Version: 1.3.1.39 - Autodesk) Hidden
      Canon iP2700 series Printer Driver (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2700_series) (Version:  - )
      Canon MP230 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP230_series) (Version: 1.00 - Canon Inc.)
      CCleaner (HKLM\…\CCleaner) (Version: 5.04 - Piriform)
      cFosSpeed v10.00 (HKLM\…\cFosSpeed) (Version: 10.00 - cFos Software GmbH, Bonn)
      CGS17_Setup_x64 (Version: 17.0 - Corel Corporation) Hidden
      Corel Graphics - Windows Shell Extension (HKLM\…\_{4AB916EE-ABA8-4079-9889-745798B6D809}) (Version: 17.0.0.491 - Corel Corporation)
      Corel Graphics - Windows Shell Extension (Version: 17.0.491 - Corel Corporation) Hidden
      Corel Graphics - Windows Shell Extension 32 Bit (Version: 17.0.491 - Corel Corporation) Hidden
      Corel Graphics - Windows Shell Extension 64 Bit (Version: 16.1.843 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - Capture (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - Common (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - Connect (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - Custom Data (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - Draw (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - EN (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - Filters (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - FontNav (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - IPM Content (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - PHOTO-PAINT (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - Photozoom Plugin (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - Redist (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - Setup Files (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - VBA (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - VideoBrowser (x64) (Version: 17.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X7 - Writing Tools (x64) (Version: 17.0 -  Corel Corporation) Hidden
      CPUID CPU-Z 1.67.1 (HKLM\…\CPUID CPU-Z_is1) (Version:  - )
      CPUID HWMonitor Pro 1.16 (HKLM\…\CPUID HWMonitorPro_is1) (Version:  - )
      Cyborg Telkomsel Mobile Broadband (HKLM\…\Cyborg Telkomsel Mobile Broadband_is1) (Version:  - )
      Defraggler (HKLM\…\Defraggler) (Version: 2.18 - Piriform)
      Dropbox (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Dropbox) (Version: 3.4.3 - Dropbox, Inc.)
      ESET Smart Security (HKLM\…\{5E6F6CE8-1A35-4629-A550-376D4FF74F9B}) (Version: 7.0.317.4 - ESET, spol s r. o.)
      Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\…\{90F00673-A276-4A58-B675-B426D39D1E09}) (Version: 15.3.0.0398 - Intel Corporation)
      Intel® PROSet/Wireless WiFi Software (HKLM\…\{ECE5B218-A086-4E18-A362-D11181681457}) (Version: 15.03.1000.1637 - Intel Corporation)
      IObit Uninstaller (HKLM-x32\…\IObitUninstall) (Version: 4.1.5.24 - IObit)
      Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
      Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
      Nitro Pro 9 (HKLM\…\{8C386164-8794-4684-8921-2218199E1020}) (Version: 9.5.1.12 - Nitro)
      NVIDIA GeForce Experience 2.2.2 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)
      NVIDIA Graphics Driver 344.11 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.11 - NVIDIA Corporation)
      NVIDIA HD Audio Driver 1.3.32.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
      NVIDIA PhysX System Software 9.14.0702 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
      Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
      Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (Version: 11.0.51108 - Microsoft Corporation) Hidden
      Pro Evolution Soccer 2015 (HKLM-x32\…\UHJvRXZvbHV0aW9uU29jY2VyMjAxNQ==_is1) (Version: 1 - )
      Revo Uninstaller Pro 3.1.2 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)
      SanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19755 - Gemalto N.V.)
      Share64 (Version: 14.1.0.150 - Corel Corporation) Hidden
      SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden
      SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden
      TeraCopy 2.3 (HKLM\…\TeraCopy_is1) (Version:  - Code Sector)
      WD SmartWare (HKLM\…\{7AE43D6C-B3F1-448D-AD84-1CDC7AC6EBC7}) (Version: 2.4.6.3 - Western Digital Technologies, Inc.)
      Windows Driver Package - ASUS (ATP) Mouse  (01/10/2013 1.0.0.170) (HKLM\…\4A9DE1E9EBC800B7F01739D4DE7363EF6751BDF5) (Version: 01/10/2013 1.0.0.170 - ASUS)
      WinRAR 5.01 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
      Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (Version: 11.0.51108 - Microsoft Corporation) Hidden
       
      ==================== Custom CLSID (selected items): ==========================
       
      (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
       
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2015\acad.exe (Autodesk, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2015\acad.exe (Autodesk, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2015\en-US\acadficn.dll (Autodesk, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
       
      ==================== Restore Points  =========================
       
      14-04-2015 19:01:12 Removed Microsoft Office 32-bit Components 2013
      14-04-2015 19:01:56 Removed Microsoft Office Professional Plus 2013
      14-04-2015 19:02:16 Removed Microsoft Office Professional Plus 2013
      14-04-2015 19:02:48 Removed Microsoft Publisher MUI (English) 2013
      14-04-2015 19:04:39 Removed Microsoft Access MUI (English) 2013
      14-04-2015 22:19:55 Installed Microsoft Office Professional Plus 2013
      14-04-2015 22:20:14 PROPLUS
      14-04-2015 22:36:28 Removed Microsoft Word MUI (English) 2013
      14-04-2015 22:57:44 Installed Microsoft Office Professional Plus 2013
      14-04-2015 22:59:40 Installed Microsoft Office Professional Plus 2013
      14-04-2015 22:59:56 PROPLUS
      14-04-2015 23:07:15 Installed Microsoft Fix it 50850
      14-04-2015 23:24:09 Installed Microsoft Office Professional Plus 2013
      15-04-2015 10:00:07 Installed Microsoft Office Professional Plus 2013
      15-04-2015 10:00:46 PROPLUS
      15-04-2015 18:30:50 Revo Uninstaller Pro's restore point - CorelDRAW Graphics Suite X7 (64-Bit)
      15-04-2015 21:15:07 Driver Booster : Qualcomm Command Control Port (COM5)
       
      ==================== Hosts content: ==========================
       
      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
       
      2009-07-14 09:34 - 2015-04-15 00:17 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts
      127.0.0.1       localhost
       
      ==================== Scheduled Tasks (whitelisted) =============
       
      (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
       
      Task: {009BBECF-4D78-4564-8F1E-F0F759E7D98F} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
      Task: {028F0BEA-2EB0-4634-9C5A-C742BBEB76F4} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-04-16] (AsusTek)
      Task: {04CBF69D-AA8B-4CE9-B1B3-9BD20D0FE348} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)
      Task: {0D9DE9B0-CAA3-4E98-A370-E4B4E42DA95A} - System32\Tasks\Uninstaller_SkipUac_Defhawk => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-11-04] (IObit)
      Task: {1296B0D2-42C3-4623-B9A1-4E90505D4046} - System32\Tasks\{D355A25F-ECA9-4762-B764-3F20E3109E6E} => Firefox.exe http://ui.skype.com/ui/0/6.5.0.158/en/go/help.faq.installer?LastError=1618
      Task: {1823FA51-0467-43BB-8134-F66123521DBB} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
      Task: {21969B38-4960-4D24-9C8E-D4FC7923C0E0} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-05-17] (ASUSTeK Computer Inc.)
      Task: {2323B362-6072-4667-9F6D-03380EA0698A} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-11-04] (IObit)
      Task: {23CB1AB5-EA73-4F6C-B3B1-AC2D73B58A47} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
      Task: {2446A911-78EE-45E8-B33B-A1A2AB6ECBE7} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
      Task: {24EA35E8-6BD4-44F2-A43A-04EF083397C4} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2014-07-21] (Nero AG)
      Task: {28650E00-EF3E-4295-9668-766B94B05A1B} - System32\Tasks\{5C4A58BA-8354-4A6C-B5BA-5563FB8E2CFF} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P7.3 Self-installer.exe" -d C:\Users\Defhawk\Downloads
      Task: {29A3E160-1D0F-4F1E-AC63-92F8DE11939C} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
      Task: {36B05A08-31B2-47D7-A8E7-487C2F605BAF} - System32\Tasks\cFosSpeedTR => C:\Program Files\cFosSpeed\CFSTR.exe [2014-04-30] (BB)
      Task: {3868AD23-3468-4E2D-869F-21217684C3C0} - System32\Tasks\{CB9212D3-94DB-4220-81D8-6F30C28ADE44} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.0 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDM
      Task: {3B22EFFE-7D8F-4879-A2C8-14794A75819D} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2014-12-17] (IObit)
      Task: {3BB2B98A-6C8A-402A-97F7-435C3A506140} - System32\Tasks\{56885AD1-C12F-47A4-8D23-F8D89DE66A2E} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.4 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDM
      Task: {3C9E538E-F64A-4668-A4F9-63D0DE563553} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
      Task: {4643B852-23FB-409E-80AB-552789036A2A} - System32\Tasks\{3C92213F-4502-4D35-8B46-1A4E32F4BA49} => C:\Program Files (x86)\Nero\Nero 12\Nero ControlCenter\NCC.exe
      Task: {49A25C2A-9F8D-4CA2-A1BE-39B1F43EB723} - System32\Tasks\ASC8_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe [2014-11-07] (IObit)
      Task: {4D38440B-AF7B-4872-AA8F-FD15E3657395} - System32\Tasks\Process Lasso Core Engine Only => C:\Program Files\Process Lasso\processgovernor.exe [2014-09-22] (Bitsum LLC)
      Task: {59E0D626-4AD0-49A6-AA7D-F049B405F411} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-05-15] (ASUS)
      Task: {6310B5CD-0E05-4887-AF03-74012DE53E7C} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2014-12-09] (IObit)
      Task: {6A250B61-775C-4CE8-BB6C-C72F660B0A41} - System32\Tasks\ASUS InstantOn Config => C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [2012-09-24] (ASUS)
      Task: {7398C9F1-B7EE-485B-8232-331BDAD10A40} - System32\Tasks\{DFF6302E-B746-47CD-8BEE-51B20017A14D} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\Nero\Nero 12\Nero ControlCenter\NCC.exe"
      Task: {7830917E-F467-40BF-A4CC-28C5876001B1} - System32\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
      Task: {7A19FF40-4CB2-4564-B657-91566652CAD0} - System32\Tasks\Process Lasso Management Console (GUI) => C:\Program Files\Process Lasso\processlasso.exe [2014-09-22] (Bitsum LLC)
      Task: {7BC53F15-B01F-48BE-B2F2-98BD572CE49D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
      Task: {8ADC19A6-0DEF-4A99-95F0-47C63D9D103B} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-09-14] (ASUSTek Computer Inc.)
      Task: {91A3D505-22C3-4B90-B99B-C85C38D2E449} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-12] (Tweaking.com)
      Task: {A41D758C-732B-41C6-92AE-7DFC80D9AC0F} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2013-10-26] ()
      Task: {AAFF357B-3E9E-4420-A97D-4FCE425EB44A} - System32\Tasks\{A7CF406F-E389-4603-A99D-96DF4CF8E9F4} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.5 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDM
      Task: {B76D7C3A-0FC8-489A-8A0C-5ECB84B303D7} - System32\Tasks\smadav => C:\Program Files (x86)\Smadav\SMΔRTP.exe [2015-02-11] (Smadsoft)
      Task: {BD5CF776-01FC-4EDB-9D03-4CCC4F138181} - System32\Tasks\{6575FDB1-B2CA-4592-9E2A-89BF71F18C0E} => pcalua.exe -a C:\Users\Defhawk\AppData\Local\Temp\NeroInstallFiles\NERO20120813121238302\setup.exe -d C:\Users\Defhawk\AppData\Local\Temp\NeroInstallFiles\NERO20120813121238302
      Task: {C237C350-8497-403A-8D80-95FE0FD944D2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd)
      Task: {C5D6C676-CC24-4621-AD7B-9732B7B680F0} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.)
      Task: {CA07F7AC-6FE1-4499-98FE-154040652706} - System32\Tasks\{3681AD73-36EC-4764-AE5B-C1F3F90EA6EC} => pcalua.exe -a I:\INSTALL.EXE -d I:\
      Task: {CBDB467C-BCF1-4935-8BF8-067D5726872E} - \Microsoft Office 15 Sync Maintenance for Def-PC-Defhawk Def-PC No Task File <==== ATTENTION
      Task: {CBFCB5FC-B3D6-4376-9A81-66CD907AD0F2} - System32\Tasks\{CB8B5CF1-985B-4406-ADAD-51EFADEEF487} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P6.4 Self-installer.exe" -d C:\Users\Defhawk\Downloads
      Task: {CC088725-91F5-4E53-A0F8-03C294D4A9B7} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-01-09] (Realtek Semiconductor)
      Task: {CFCBA695-6977-4705-BD56-3C34EB5C2074} - System32\Tasks\AutoKMSCustom => C:\Windows\AutoKMS\AutoKMS.exe [2014-01-09] ()
      Task: {D4E9AFF7-C3F6-4145-BD58-3C00BE01063A} - System32\Tasks\Driver Booster SkipUAC (Defhawk) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2014-12-17] (IObit)
      Task: {D74126FC-77A0-46A8-8C0D-C932B95015EB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
      Task: {DC3EA95E-CB26-4403-8692-EFCCE0BBFB71} - System32\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
      Task: {E64DE4BA-F797-4301-AF38-6D92BEEEC84E} - System32\Tasks\ASC8_SkipUac_Defhawk => C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe [2014-11-07] (IObit)
      Task: {E9B0D633-DE94-4608-9BAE-16CF90AD732F} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
      Task: {F26FA818-8742-4E5E-A115-0AE9166E1AF6} - System32\Tasks\{A4D3F862-ECA0-4659-A604-FA6A3813E901} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P7.1 Self-installer.exe" -d C:\Users\Defhawk\Downloads
      Task: {F45E28EE-2421-428B-B21B-C618B93C8E09} - System32\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
      Task: {FA724455-DB75-41AB-B4C5-FE1150360F34} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-15] (Adobe Systems Incorporated)
      Task: {FBE9499D-F4DD-437E-A393-C21B10C9B005} - System32\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
      Task: {FD95CA08-B3DD-4638-81DA-01076FFF67CE} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
      Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
      Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
      Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
      Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
      Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
      Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
      Task: C:\Windows\Tasks\Uninstaller_SkipUac_Defhawk.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
       
      ==================== Loaded Modules (whitelisted) ==============
       
      2013-11-03 12:29 - 2014-09-14 04:53 - 00116880 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
      2012-10-01 20:36 - 2012-10-01 20:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
      2010-07-14 16:11 - 2010-07-14 16:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
      2013-07-10 11:18 - 2013-07-10 11:18 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
      2013-11-24 23:57 - 2012-03-28 19:49 - 00140456 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
      2014-05-22 14:06 - 2014-05-22 14:06 - 00417800 _____ () C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe
      2015-04-12 12:19 - 2014-08-11 20:35 - 01009952 _____ () C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd\2.0.0_0\Plugin\SPNativeMessage.exe
      2015-04-11 16:46 - 2014-09-05 09:58 - 01935872 _____ () C:\Program Files\Cyborg Telkomsel Mobile Broadband\App.exe
      2013-11-17 00:47 - 2012-01-29 16:55 - 00657920 _____ () C:\Program Files\TeraCopy\TeraCopy64.dll
      2013-11-17 00:47 - 2012-01-20 14:55 - 00678400 _____ () C:\Program Files\TeraCopy\TeraCopyExt64.dll
      2015-01-09 07:51 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\sqlite3.dll
      2013-11-03 11:05 - 2014-09-14 06:48 - 00012104 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
      2014-10-02 22:05 - 2014-09-04 10:41 - 00047496 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
      2014-10-02 22:05 - 2014-09-04 10:41 - 00104328 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
      2015-01-09 07:52 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madExcept_.bpl
      2015-01-09 07:52 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madBasic_.bpl
      2015-01-09 07:52 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madDisAsm_.bpl
      2015-01-09 07:51 - 2014-10-16 10:26 - 00622880 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\ProductStatistics.dll
      2012-01-31 09:25 - 2012-01-31 09:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
      2012-03-15 10:48 - 2012-03-15 10:48 - 00221184 _____ () C:\Program Files (x86)\ASUS\VirtualCamera\virtualCamera.ax
      2012-10-01 20:37 - 2012-10-01 20:37 - 06522480 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
      2015-04-04 12:23 - 2015-03-31 04:07 - 01174856 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.118\libglesv2.dll
      2015-04-04 12:23 - 2015-03-31 04:07 - 00080200 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.118\libegl.dll
      2015-04-04 12:23 - 2015-03-31 04:07 - 09279304 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.118\pdf.dll
      2015-01-12 07:18 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\madExcept_.bpl
      2015-01-12 07:18 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\madBasic_.bpl
      2015-01-12 07:18 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\madDisAsm_.bpl
      2015-01-12 07:18 - 2013-12-12 18:46 - 08001344 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\WebUI.dll
      2015-01-12 07:18 - 2013-05-16 19:26 - 00182080 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\unrar.dll
      2015-01-12 07:18 - 2013-10-16 22:17 - 00185168 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\libcurl-4.dll
      2015-01-12 07:18 - 2013-05-16 19:26 - 00145216 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\zlibwapi.dll
      2015-01-27 00:02 - 2015-01-27 00:02 - 00218112 _____ () C:\Program Files\AIMP3\System\libsoxr.dll
      2015-01-27 00:02 - 2015-01-27 00:02 - 00220672 _____ () C:\Program Files\AIMP3\System\Encoders\MACDll.dll
      2015-01-27 00:02 - 2015-01-27 00:02 - 00435200 _____ () C:\Program Files\AIMP3\System\Encoders\libFLAC.dll
      2015-01-27 00:02 - 2015-01-27 00:02 - 01733120 _____ () C:\Program Files\AIMP3\System\Encoders\aimp_libvorbis.dll
      2015-01-27 00:02 - 2015-01-27 00:02 - 00100424 _____ () C:\Program Files\AIMP3\Plugins\aimp_cdda\aimp_cdda.dll
      2015-01-27 00:02 - 2015-01-27 00:02 - 00159232 _____ () C:\Program Files\AIMP3\Plugins\aimp_sacd\libsacd.dll
      2015-01-27 00:02 - 2015-01-27 00:02 - 00026624 _____ () C:\Program Files\AIMP3\Plugins\Aorta\Aorta.dll
      2015-01-27 00:02 - 2015-01-27 00:02 - 00237568 _____ () C:\Program Files\AIMP3\Plugins\OptimFROG\OptimFROG.dll
      2015-01-27 00:02 - 2015-01-27 00:02 - 00152648 _____ () C:\Program Files\AIMP3\Plugins\PandemicAnalogMeter\PandemicAnalogMeter.dll
      2015-04-11 16:46 - 2013-05-22 10:56 - 00186368 _____ () C:\Program Files\Cyborg Telkomsel Mobile Broadband\RasDial.dll
      2015-04-11 16:46 - 2013-05-22 10:56 - 00324608 _____ () C:\Program Files\Cyborg Telkomsel Mobile Broadband\pcmWave.dll
      2015-04-11 16:46 - 2013-07-19 11:12 - 00368640 _____ () C:\Program Files\Cyborg Telkomsel Mobile Broadband\ATManager.dll
      2015-04-11 16:46 - 2013-05-22 10:56 - 00264704 _____ () C:\Program Files\Cyborg Telkomsel Mobile Broadband\log.dll
      2015-01-03 04:35 - 2014-10-08 15:51 - 00348992 _____ () C:\Program Files (x86)\IObit\Driver Booster\madExcept_.bpl
      2015-01-03 04:35 - 2014-10-08 15:50 - 00183616 _____ () C:\Program Files (x86)\IObit\Driver Booster\madBasic_.bpl
      2015-01-03 04:35 - 2014-10-08 15:50 - 00051008 _____ () C:\Program Files (x86)\IObit\Driver Booster\madDisAsm_.bpl
      2015-01-03 04:35 - 2014-08-22 15:19 - 00893248 _____ () C:\Program Files (x86)\IObit\Driver Booster\webres.dll
      2015-01-03 04:35 - 2012-02-16 10:16 - 00516440 _____ () C:\Program Files (x86)\IObit\Driver Booster\sqlite3.dll
       
      ==================== Alternate Data Streams (whitelisted) =========
       
      (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
       
      AlternateDataStreams: C:\Windows:nlsPreferences
      AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51
       
      ==================== Safe Mode (whitelisted) ===================
       
      (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
       
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service"
       
      ==================== EXE Association (whitelisted) ===============
       
      (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
       
      HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION!
       
      ==================== Other Areas ============================
       
      (Currently there is no automatic fix for this section.)
       
      HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
      DNS Servers: [removed] - [removed]
       
      ==================== MSCONFIG/TASK MANAGER disabled items ==
       
      (Currently there is no automatic fix for this section.)
       
      MSCONFIG\Services: eventlog => 2
      MSCONFIG\Services: Wecsvc => 3
      MSCONFIG\startupreg: EPSON_UD_START => 
      MSCONFIG\startupreg: Lync => 
       
      ==================== Accounts: =============================
       
      Administrator (S-1-5-21-3901189400-636743289-3933302658-500 - Administrator - Disabled)
      Defhawk (S-1-5-21-3901189400-636743289-3933302658-1000 - Administrator - Enabled) => C:\Users\Defhawk
      Guest (S-1-5-21-3901189400-636743289-3933302658-501 - Limited - Disabled)
      HomeGroupUser$ (S-1-5-21-3901189400-636743289-3933302658-1002 - Limited - Enabled)
       
      ==================== Faulty Device Manager Devices =============
       
       
      ==================== Event log errors: =========================
       
      Application errors:
      ==================
      Error: (04/15/2015 07:59:19 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
      Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe because this image is not a valid Win32 application.
       
      Error: (04/15/2015 07:15:55 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
      Description: Failed to schedule Software Protection service for re-start at 2015-05-15T11:25:55Z. Error Code: 0x80041321.
       
      Error: (04/15/2015 06:33:01 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
      Description: Failed to schedule Software Protection service for re-start at 2015-05-15T11:26:01Z. Error Code: 0x80041321.
       
      Error: (04/15/2015 01:16:44 PM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
      Description: Product: Nero Update – Error 1921.Service Nero Update (NAUpdate) could not be stopped.  Verify that you have sufficient privileges to stop system services.
       
      Error: (04/15/2015 01:13:17 PM) (Source: Office Software Protection Platform Service) (EventID: 1014) (User: )
      Description: Acquisition of End User License failed. hr=0x80072EE7
      Sku Id=2b88c4f2-ea8f-43cd-805e-4d41346e18a7
       
      Error: (04/15/2015 01:13:17 PM) (Source: Office Software Protection Platform Service) (EventID: 8200) (User: )
      Description: License acquisition failure details. 
      hr=0x80072EE7
       
      Error: (04/15/2015 01:12:51 PM) (Source: Office Software Protection Platform Service) (EventID: 1014) (User: )
      Description: Acquisition of End User License failed. hr=0x80072EE7
      Sku Id=2b88c4f2-ea8f-43cd-805e-4d41346e18a7
       
      Error: (04/15/2015 01:12:51 PM) (Source: Office Software Protection Platform Service) (EventID: 8200) (User: )
      Description: License acquisition failure details. 
      hr=0x80072EE7
       
      Error: (04/15/2015 01:08:33 PM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
      Description: Product: Nero Update – Error 1921.Service Nero Update (NAUpdate) could not be stopped.  Verify that you have sufficient privileges to stop system services.
       
      Error: (04/15/2015 00:56:28 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
      Description: The handle is invalid
       
       
      System errors:
      =============
      Error: (04/15/2015 06:15:56 PM) (Source: Disk) (EventID: 11) (User: )
      Description: The driver detected a controller error on \Device\Harddisk1\DR5.
       
      Error: (04/15/2015 06:15:55 PM) (Source: Disk) (EventID: 11) (User: )
      Description: The driver detected a controller error on \Device\Harddisk1\DR5.
       
      Error: (04/15/2015 06:15:55 PM) (Source: Disk) (EventID: 11) (User: )
      Description: The driver detected a controller error on \Device\Harddisk1\DR5.
       
      Error: (04/15/2015 06:15:54 PM) (Source: Disk) (EventID: 11) (User: )
      Description: The driver detected a controller error on \Device\Harddisk1\DR5.
       
      Error: (04/15/2015 06:15:54 PM) (Source: Disk) (EventID: 11) (User: )
      Description: The driver detected a controller error on \Device\Harddisk1\DR5.
       
      Error: (04/15/2015 01:02:15 PM) (Source: DCOM) (EventID: 10001) (User: )
      Description: "C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe" -Embedding193{5DC4F9AD-3A2B-4DF4-AC39-3FF5A19FCF4C}
       
      Error: (04/15/2015 01:02:12 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
      Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80070420'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
       
      Error: (04/15/2015 01:01:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: The Intel(R) PROSet/Wireless Zero Configuration Service service failed to start due to the following error: 
      %%193
       
      Error: (04/15/2015 01:00:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: The MBAMScheduler service failed to start due to the following error: 
      %%1053
       
      Error: (04/15/2015 01:00:42 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
      Description: A timeout was reached (30000 milliseconds) while waiting for the MBAMScheduler service to connect.
       
       
      Microsoft Office Sessions:
      =========================
      Error: (04/15/2015 07:59:19 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
      Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe because this image is not a valid Win32 application.
      C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe
       
      Error: (04/15/2015 07:15:55 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
      Description: 0x800413212015-05-15T11:25:55Z
       
      Error: (04/15/2015 06:33:01 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
      Description: 0x800413212015-05-15T11:26:01Z
       
      Error: (04/15/2015 01:16:44 PM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
      Description: Product: Nero Update – Error 1921.Service Nero Update (NAUpdate) could not be stopped.  Verify that you have sufficient privileges to stop system services.(NULL)(NULL)(NULL)(NULL)(NULL)
       
      Error: (04/15/2015 01:13:17 PM) (Source: Office Software Protection Platform Service) (EventID: 1014) (User: )
      Description: hr=0x80072EE72b88c4f2-ea8f-43cd-805e-4d41346e18a7
       
      Error: (04/15/2015 01:13:17 PM) (Source: Office Software Protection Platform Service) (EventID: 8200) (User: )
      00020001(0x00000000, 13:13:17:210)
      00030001(0x00000000, 13:13:17:216 - https://activation.sls.microsoft.com)
      00030002(0x00000000, 13:13:17:216 - 0)
      00040001(0x00000000, 13:13:17:216 - https://activation.sls.microsoft.com)
      00040002(0x00000000, 13:13:17:220 - 0, , , )
      00040006(0x00000000, 13:13:17:220 - 1, https://activation.sls.microsoft.com, , )
      00020005(0x00000000, 13:13:17:220 - 0)
      00020008(0x80072EE7, 13:13:17:226 - SOAPAction: "http://microsoft.com/SL/ProductActivationService/IssueToken"
      Content-Type: text/xml; charset=utf-8
      , xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenc="http://schemas.xmlsoap.org/soap/encoding/"> xmlns="http://schemas.xmlsoap.org/ws/2004/04/security/trust">ProductActivationhttp://schemas.xmlsoap.org/ws/2004/04/security/trust/Issue xmlns:q1="http://schemas.xmlsoap.org/ws/2004/04/security/trust" soapenc:arrayType="q1:TokenEntry[1]">PublishLicensexmlns:sl="http://www.microsoft.com/DRM/XrML2/SL/v2" xmlns:tm="http://www.microsoft.com/DRM/XrML2/TM/v2">Office 15 Publishing License (Public)/sl:productId/sl:pidxmlns="http://www.w3.org/2000/09/xmldsig#">uzDfZ3WsHY4/UKthrglDqsLw4BqrlOWlNdLBnLD/5sdAUXnv+2kB9jJJPK2TYkbkQ5bfK4QfS8h050WPtpN/NGL7batTKnEjNnRNrenM8+YAT9Ne7K7xCwgJdb08rOZyMqQPKtPr1p6FCwPY7zBvOmtNdvVs0psxwEuq2DmFz1g8+WJw9zGgqI4qkYA7P/yaN0lbQpvH3p1v68DogX7BLd6Z+Z+3MNG1Lh+k11kmd+lM8RaLq74zT8OSZDJ9McD9i/4JaB0kJfdV5oGb0ZbWvW/3Z8pQVf7tA5s3J1Tpp3/nrvV5WtZMZ3nGemTFRP5dxbH5y4YSBoKFGOYCyQH3pQ==AQAB varName="application">editionId[@value="" or @value="OfficeProPlusVL_MAK"]xmlns="http://www.w3.org/2000/09/xmldsig#">lAi6wXhcWOjn1rN1aIy6z4YBcYlkdrxP9EEw7iiD0tg6i0aVOgZ/FS6IxiOgZXYwTgK/BHA7QN6/lvxnecZ2cETT7w7ZRByGUN1zTQKFwXdyQz/xdp5kZ81bmI3EQWLJBT6iW5K8HZr0qRsQRlExUrWZSOI449+Br2QgOMcBMS3FEMBS8XCBPgZ3z/V9ydztWjhopBB0ZngebWEjqwtlrXEB1M+WOPWUcljdJlp5pXNkiqCrJEzenMJ+tfTfD/8zv08LdhhIAmx1VLViItRqO9OD7l313X7bVyfTWTxGmf7D9YS5Sa0UCiOXM0qVZCVuQ5CzjLRLa13FaJurQ6SBhQ==AQAB xmlns="http://www.w3.org/2000/09/xmldsig#">ptV5l33YkYwdOV/Ru16t2VcbVg92rhNO1ng3kIn/AY/c/HlfUuVxwR4F4F3JoxbDQ4wiNf1QwQaAJdl/1pHy0iY3Hb60KLMuqOb4/C2EsICU2cOuhVxgVIoM+aqEkkFHyUx1E6+TbCSAvv0PQR7ns6h9CLlXPHZ6w6P8s0L/rAs=AQAB varRef="appid"/>xmlns:sl="http://www.microsoft.com/DRM/XrML2/SL/v2">400 name="Security-SPP-Reserved-ProductUniquenessGroupID">8EA85E20-E9D5-4651-A4AF-A69DFB2F9DC0OfficeProPlusVL_MAKxmlns:sl="http://www.microsoft.com/DRM/XrML2/SL/v2"> varRef="binding"/>xmlns:sl="http://www.microsoft.com/DRM/XrML2/SL/v2"> xmlns="http://www.w3.org/2000/09/xmldsig#"> Algorithm="http://www.microsoft.com/xrml/lwc14n"/> Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> Algorithm="urn:mpeg:mpeg21:2003:01-REL-R-NS:licenseTransform"/>Algorithm="http://www.microsoft.com/xrml/lwc14n"/> Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>QAJpwtbV/tQFh4LqogxFqCb32Vc=QMmRAPGgexuqxPZnzA4O3A1S4B5OCzNGHudEhqm48c4cBHHi+wpUnNWNzJ53Igo0IueB3lRmD4t7hEGLLYLOZRnB+1yS1+JmrpkJ6uamr1fXLI+FpXp8LmvdnarP0PL93Gxdculch4znpJzErCXpscmMi6woqWl+TVHpAKleJCLN92+pAl69RpNBfSMVsskQRpTEgzd+ZoTHjoAQ3lDAaD4MWdzIh330X90r2JhesvAIW5Pgvtw7n7p3UUVef279BP4WP32z28MW8C0dDbvB2Ovr/7t7HXvfnsMpRNWReOVzwUfP/zC7gdOuOzImWgDzQLKAJNsHWmtQgRbtqT/82A==lAi6wXhcWOjn1rN1aIy6z4YBcYlkdrxP9EEw7iiD0tg6i0aVOgZ/FS6IxiOgZXYwTgK/BHA7QN6/lvxnecZ2cETT7w7ZRByGUN1zTQKFwXdyQz/xdp5kZ81bmI3EQWLJBT6iW5K8HZr0qRsQRlExUrWZSOI449+Br2QgOMcBMS3FEMBS8XCBPgZ3z/V9ydztWjhopBB0ZngebWEjqwtlrXEB1M+WOPWUcljdJlp5pXNkiqCrJEzenMJ+tfTfD/8zv08LdhhIAmx1VLViItRqO9OD7l313X7bVyfTWTxGmf7D9YS5Sa0UCiOXM0qVZCVuQ5CzjLRLa13FaJurQ6SBhQ==AQAB2012-09-29T15:55:01Z xmlns:r="urn:mpeg:mpeg21:2003:01-REL-R-NS">xmlns:tm="http://www.microsoft.com/DRM/XrML2/TM/v2"> tag="#global">msft:sl/PL/GENERIC/PUBLIC2.0name="licensorUrl">http://licensing.microsoft.com name="licenseCategory">msft:sl/PL/GENERIC/PUBLIC{2B88C4F2-EA8F-43CD-805E-4D41346E18A7}{7959ced6-a417-48b4-894f-44e2b645938a}{0ff1ce15-a989-479d-af46-f275c6370663}Office 15, OfficeProPlusVL_MAK editionOfficeProPlusVL_MAKMicrosoft CorporationOffice 15{CE939C0E-53F7-4011-A286-78B6975FA5F0}3trueReferralId=000000;PartnerId=00000000-0000-0000-0000-000000000000xmlns:sl="http://www.microsoft.com/DRM/XrML2/SL/v2" xmlns:tm="http://www.microsoft.com/DRM/XrML2/TM/v2">Office 15 Publishing License (Private)xmlns="http://www.w3.org/2000/09/xmldsig#">uzDfZ3WsHY4/UKthrglDqsLw4BqrlOWlNdLBnLD/5sdAUXnv+2kB9jJJPK2TYkbkQ5bfK4QfS8h050WPtpN/NGL7batTKnEjNnRNrenM8+YAT9Ne7K7xCwgJdb08rOZyMqQPKtPr1p6FCwPY7zBvOmtNdvVs0psxwEuq2DmFz1g8+WJw9zGgqI4qkYA7P/yaN0lbQpvH3p1v68DogX7BLd6Z+Z+3MNG1Lh+k11kmd+lM8RaLq74zT8OSZDJ9McD9i/4JaB0kJfdV5oGb0ZbWvW/3Z8pQVf7tA5s3J1Tpp3/nrvV5WtZMZ3nGemTFRP5dxbH5y4YSBoKFGOYCyQH3pQ==AQAB varName="anyRight">xmlns="http://www.w3.org/2000/09/xmldsig#">ptV5l33YkYwdOV/Ru16t2VcbVg92rhNO1ng3kIn/AY/c/HlfUuVxwR4F4F3JoxbDQ4wiNf1QwQaAJdl/1pHy0iY3Hb60KLMuqOb4/C2EsICU2cOuhVxgVIoM+aqEkkFHyUx1E6+TbCSAvv0PQR7ns6h9CLlXPHZ6w6P8s0L/rAs=AQAB size="16">AAAAAAAAAAAAAAAAAAAAAA==xmlns="http://www.w3.org/2000/09/xmldsig#">ptV5l33YkYwdOV/Ru16t2VcbVg92rhNO1ng3kIn/AY/c/HlfUuVxwR4F4F3JoxbDQ4wiNf1QwQaAJdl/1pHy0iY3Hb60KLMuqOb4/C2EsICU2cOuhVxgVIoM+aqEkkFHyUx1E6+TbCSAvv0PQR7ns6h9CLlXPHZ6w6P8s0L/rAs=AQAB varRef="anyRight"/>xmlns="http://www.w3.org/2000/09/xmldsig#">uzDfZ3WsHY4/UKthrglDqsLw4BqrlOWlNdLBnLD/5sdAUXnv+2kB9jJJPK2TYkbkQ5bfK4QfS8h050WPtpN/NGL7batTKnEjNnRNrenM8+YAT9Ne7K7xCwgJdb08rOZyMqQPKtPr1p6FCwPY7zBvOmtNdvVs0psxwEuq2DmFz1g8+WJw9zGgqI4qkYA7P/yaN0lbQpvH3p1v68DogX7BLd6Z+Z+3MNG1Lh+k11kmd+lM8RaLq74zT8OSZDJ9McD9i/4JaB0kJfdV5oGb0ZbWvW/3Z8pQVf7tA5s3J1Tpp3/nrvV5WtZMZ3nGemTFRP5dxbH5y4YSBoKFGOYCyQH3pQ==AQAB xmlns="http://www.w3.org/2000/09/xmldsig#"> Algorithm="http://www.microsoft.com/xrml/lwc14n"/> Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> Algorithm="urn:mpeg:mpeg21:2003:01-REL-R-NS:licenseTransform"/>Algorithm="http://www.microsoft.com/xrml/lwc14n"/> Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>iVsN92uYcbd0Nj+Tz0AeQxO6jpY=Srx5gCw84/Cetb56UHWNVbcaIbV+YZ4YF9I1hKxGeFn4OptrIAotkXe6xukm9pc6zOLVAgUvpw1ZmPRPSN/8OnSgeojsBMJS34F6JyXG2v747g3MhF/XwfOvTyx+2Dqw/LzNVyxPBGjvjeNg2ijvsn0Qq0GkxE/68CAyKFfD+oK7HSjlDLuDTJXaORBjFBfhZwhEDp+ay+G7qowN3BWe00lDoZSSVlCfdqZQiuSa1JXSfgfaL2WD/2vQt1MiqOpGEVPjJ5u7Ma8Y3NeSJY3vYVZPzHFT11Ziv8Fd2z9C+v3JXleIngFsLYTZAhD/WqrRGP7wqTYODO50qlk2Fp9z6g==lAi6wXhcWOjn1rN1aIy6z4YBcYlkdrxP9EEw7iiD0tg6i0aVOgZ/FS6IxiOgZXYwTgK/BHA7QN6/lvxnecZ2cETT7w7ZRByGUN1zTQKFwXdyQz/xdp5kZ81bmI3EQWLJBT6iW5K8HZr0qRsQRlExUrWZSOI449+Br2QgOMcBMS3FEMBS8XCBPgZ3z/V9ydztWjhopBB0ZngebWEjqwtlrXEB1M+WOPWUcljdJlp5pXNkiqCrJEzenMJ+tfTfD/8zv08LdhhIAmx1VLViItRqO9OD7l313X7bVyfTWTxGmf7D9YS5Sa0UCiOXM0qVZCVuQ5CzjLRLa13FaJurQ6SBhQ==AQAB2012-09-29T15:55:01Z xmlns:r="urn:mpeg:mpeg21:2003:01-REL-R-NS">xmlns:tm="http://www.microsoft.com/DRM/XrML2/TM/v2"> tag="#global">msft:sl/PL/GENERIC/PRIVATE2.0name="licensorUrl">http://licensing.microsoft.com name="licenseCategory">msft:sl/PL/GENERIC/PRIVATE{c0cfb665-b96c-4f22-af71-ba9e2f880975}{CE939C0E-53F7-4011-A286-78B6975FA5F0}3truexmlns:q1="http://schemas.xmlsoap.org/ws/2004/04/security/trust" soapenc:arrayType="q1:TokenEntry[14]">BindingTypemsft:rm/algorithm/hwid/4.0BindingOAAAAAIAAQABAAIAAQACAAAABAABAAEAlitYJmX9RlxY3f53epjUKuPg1jhyKZRw7mjS8tT2lKY=ProductKeyRXMWX-WKNYY-T9QGD-MPWVP-9P8QHProductKeyTypemsft:rm/algorithm/pkey/2009ProductKeyActConfigIdmsft2009:2b88c4f2-ea8f-43cd-805e-4d41346e18a7&om4PiToEQOKsGGeWZg;==otherInfoPublic.licenseCategorymsft:sl/EUL/ACTIVATED/PUBLICotherInfoPrivate.licenseCategorymsft:sl/EUL/ACTIVATED/PRIVATEotherInfoPublic.sysprepActionrearmotherInfoPrivate.sysprepActionrearmClientInformationSystemUILanguageId=1033;UserUILanguageId=1033;GeoId=244ClientSystemTime2015-04-15T06:13:17ZClientSystemTimeUtc2015-04-15T06:13:17ZotherInfoPublic.secureStoreId5f7fb011-ee1a-4784-91d5-60509aaa6c95otherInfoPrivate.secureStoreId5f7fb011-ee1a-4784-91d5-60509aaa6c95)
      00010002(0x80072EE7, 13:13:17:230 - )
      00010003(0x80072EE7, 13:13:17:230)
       
      Error: (04/15/2015 01:12:51 PM) (Source: Office Software Protection Platform Service) (EventID: 1014) (User: )
      Description: hr=0x80072EE72b88c4f2-ea8f-43cd-805e-4d41346e18a7
       
      Error: (04/15/2015 01:12:51 PM) (Source: Office Software Protection Platform Service) (EventID: 8200) (User: )
      00020001(0x00000000, 13:12:51:929)
      00030001(0x00000000, 13:12:51:935 - https://activation.sls.microsoft.com)
      00030002(0x00000000, 13:12:51:935 - 0)
      00040001(0x00000000, 13:12:51:935 - https://activation.sls.microsoft.com)
      00040002(0x00000000, 13:12:51:939 - 0, , , )
      00040006(0x00000000, 13:12:51:939 - 1, https://activation.sls.microsoft.com, , )
      00020005(0x00000000, 13:12:51:939 - 0)
      00020008(0x80072EE7, 13:12:51:945 - SOAPAction: "http://microsoft.com/SL/ProductActivationService/IssueToken"
      Content-Type: text/xml; charset=utf-8
      , xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenc="http://schemas.xmlsoap.org/soap/encoding/"> xmlns="http://schemas.xmlsoap.org/ws/2004/04/security/trust">ProductActivationhttp://schemas.xmlsoap.org/ws/2004/04/security/trust/Issue xmlns:q1="http://schemas.xmlsoap.org/ws/2004/04/security/trust" soapenc:arrayType="q1:TokenEntry[1]">PublishLicensexmlns:sl="http://www.microsoft.com/DRM/XrML2/SL/v2" xmlns:tm="http://www.microsoft.com/DRM/XrML2/TM/v2">Office 15 Publishing License (Public)/sl:productId/sl:pidxmlns="http://www.w3.org/2000/09/xmldsig#">uzDfZ3WsHY4/UKthrglDqsLw4BqrlOWlNdLBnLD/5sdAUXnv+2kB9jJJPK2TYkbkQ5bfK4QfS8h050WPtpN/NGL7batTKnEjNnRNrenM8+YAT9Ne7K7xCwgJdb08rOZyMqQPKtPr1p6FCwPY7zBvOmtNdvVs0psxwEuq2DmFz1g8+WJw9zGgqI4qkYA7P/yaN0lbQpvH3p1v68DogX7BLd6Z+Z+3MNG1Lh+k11kmd+lM8RaLq74zT8OSZDJ9McD9i/4JaB0kJfdV5oGb0ZbWvW/3Z8pQVf7tA5s3J1Tpp3/nrvV5WtZMZ3nGemTFRP5dxbH5y4YSBoKFGOYCyQH3pQ==AQAB varName="application">editionId[@value="" or @value="OfficeProPlusVL_MAK"]xmlns="http://www.w3.org/2000/09/xmldsig#">lAi6wXhcWOjn1rN1aIy6z4YBcYlkdrxP9EEw7iiD0tg6i0aVOgZ/FS6IxiOgZXYwTgK/BHA7QN6/lvxnecZ2cETT7w7ZRByGUN1zTQKFwXdyQz/xdp5kZ81bmI3EQWLJBT6iW5K8HZr0qRsQRlExUrWZSOI449+Br2QgOMcBMS3FEMBS8XCBPgZ3z/V9ydztWjhopBB0ZngebWEjqwtlrXEB1M+WOPWUcljdJlp5pXNkiqCrJEzenMJ+tfTfD/8zv08LdhhIAmx1VLViItRqO9OD7l313X7bVyfTWTxGmf7D9YS5Sa0UCiOXM0qVZCVuQ5CzjLRLa13FaJurQ6SBhQ==AQAB xmlns="http://www.w3.org/2000/09/xmldsig#">ptV5l33YkYwdOV/Ru16t2VcbVg92rhNO1ng3kIn/AY/c/HlfUuVxwR4F4F3JoxbDQ4wiNf1QwQaAJdl/1pHy0iY3Hb60KLMuqOb4/C2EsICU2cOuhVxgVIoM+aqEkkFHyUx1E6+TbCSAvv0PQR7ns6h9CLlXPHZ6w6P8s0L/rAs=AQAB varRef="appid"/>xmlns:sl="http://www.microsoft.com/DRM/XrML2/SL/v2">400 name="Security-SPP-Reserved-ProductUniquenessGroupID">8EA85E20-E9D5-4651-A4AF-A69DFB2F9DC0OfficeProPlusVL_MAKxmlns:sl="http://www.microsoft.com/DRM/XrML2/SL/v2"> varRef="binding"/>xmlns:sl="http://www.microsoft.com/DRM/XrML2/SL/v2"> xmlns="http://www.w3.org/2000/09/xmldsig#"> Algorithm="http://www.microsoft.com/xrml/lwc14n"/> Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> Algorithm="urn:mpeg:mpeg21:2003:01-REL-R-NS:licenseTransform"/>Algorithm="http://www.microsoft.com/xrml/lwc14n"/> Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>QAJpwtbV/tQFh4LqogxFqCb32Vc=QMmRAPGgexuqxPZnzA4O3A1S4B5OCzNGHudEhqm48c4cBHHi+wpUnNWNzJ53Igo0IueB3lRmD4t7hEGLLYLOZRnB+1yS1+JmrpkJ6uamr1fXLI+FpXp8LmvdnarP0PL93Gxdculch4znpJzErCXpscmMi6woqWl+TVHpAKleJCLN92+pAl69RpNBfSMVsskQRpTEgzd+ZoTHjoAQ3lDAaD4MWdzIh330X90r2JhesvAIW5Pgvtw7n7p3UUVef279BP4WP32z28MW8C0dDbvB2Ovr/7t7HXvfnsMpRNWReOVzwUfP/zC7gdOuOzImWgDzQLKAJNsHWmtQgRbtqT/82A==lAi6wXhcWOjn1rN1aIy6z4YBcYlkdrxP9EEw7iiD0tg6i0aVOgZ/FS6IxiOgZXYwTgK/BHA7QN6/lvxnecZ2cETT7w7ZRByGUN1zTQKFwXdyQz/xdp5kZ81bmI3EQWLJBT6iW5K8HZr0qRsQRlExUrWZSOI449+Br2QgOMcBMS3FEMBS8XCBPgZ3z/V9ydztWjhopBB0ZngebWEjqwtlrXEB1M+WOPWUcljdJlp5pXNkiqCrJEzenMJ+tfTfD/8zv08LdhhIAmx1VLViItRqO9OD7l313X7bVyfTWTxGmf7D9YS5Sa0UCiOXM0qVZCVuQ5CzjLRLa13FaJurQ6SBhQ==AQAB2012-09-29T15:55:01Z xmlns:r="urn:mpeg:mpeg21:2003:01-REL-R-NS">xmlns:tm="http://www.microsoft.com/DRM/XrML2/TM/v2"> tag="#global">msft:sl/PL/GENERIC/PUBLIC2.0name="licensorUrl">http://licensing.microsoft.com name="licenseCategory">msft:sl/PL/GENERIC/PUBLIC{2B88C4F2-EA8F-43CD-805E-4D41346E18A7}{7959ced6-a417-48b4-894f-44e2b645938a}{0ff1ce15-a989-479d-af46-f275c6370663}Office 15, OfficeProPlusVL_MAK editionOfficeProPlusVL_MAKMicrosoft CorporationOffice 15{CE939C0E-53F7-4011-A286-78B6975FA5F0}3trueReferralId=000000;PartnerId=00000000-0000-0000-0000-000000000000xmlns:sl="http://www.microsoft.com/DRM/XrML2/SL/v2" xmlns:tm="http://www.microsoft.com/DRM/XrML2/TM/v2">Office 15 Publishing License (Private)xmlns="http://www.w3.org/2000/09/xmldsig#">uzDfZ3WsHY4/UKthrglDqsLw4BqrlOWlNdLBnLD/5sdAUXnv+2kB9jJJPK2TYkbkQ5bfK4QfS8h050WPtpN/NGL7batTKnEjNnRNrenM8+YAT9Ne7K7xCwgJdb08rOZyMqQPKtPr1p6FCwPY7zBvOmtNdvVs0psxwEuq2DmFz1g8+WJw9zGgqI4qkYA7P/yaN0lbQpvH3p1v68DogX7BLd6Z+Z+3MNG1Lh+k11kmd+lM8RaLq74zT8OSZDJ9McD9i/4JaB0kJfdV5oGb0ZbWvW/3Z8pQVf7tA5s3J1Tpp3/nrvV5WtZMZ3nGemTFRP5dxbH5y4YSBoKFGOYCyQH3pQ==AQAB varName="anyRight">xmlns="http://www.w3.org/2000/09/xmldsig#">ptV5l33YkYwdOV/Ru16t2VcbVg92rhNO1ng3kIn/AY/c/HlfUuVxwR4F4F3JoxbDQ4wiNf1QwQaAJdl/1pHy0iY3Hb60KLMuqOb4/C2EsICU2cOuhVxgVIoM+aqEkkFHyUx1E6+TbCSAvv0PQR7ns6h9CLlXPHZ6w6P8s0L/rAs=AQAB size="16">AAAAAAAAAAAAAAAAAAAAAA==xmlns="http://www.w3.org/2000/09/xmldsig#">ptV5l33YkYwdOV/Ru16t2VcbVg92rhNO1ng3kIn/AY/c/HlfUuVxwR4F4F3JoxbDQ4wiNf1QwQaAJdl/1pHy0iY3Hb60KLMuqOb4/C2EsICU2cOuhVxgVIoM+aqEkkFHyUx1E6+TbCSAvv0PQR7ns6h9CLlXPHZ6w6P8s0L/rAs=AQAB varRef="anyRight"/>xmlns="http://www.w3.org/2000/09/xmldsig#">uzDfZ3WsHY4/UKthrglDqsLw4BqrlOWlNdLBnLD/5sdAUXnv+2kB9jJJPK2TYkbkQ5bfK4QfS8h050WPtpN/NGL7batTKnEjNnRNrenM8+YAT9Ne7K7xCwgJdb08rOZyMqQPKtPr1p6FCwPY7zBvOmtNdvVs0psxwEuq2DmFz1g8+WJw9zGgqI4qkYA7P/yaN0lbQpvH3p1v68DogX7BLd6Z+Z+3MNG1Lh+k11kmd+lM8RaLq74zT8OSZDJ9McD9i/4JaB0kJfdV5oGb0ZbWvW/3Z8pQVf7tA5s3J1Tpp3/nrvV5WtZMZ3nGemTFRP5dxbH5y4YSBoKFGOYCyQH3pQ==AQAB xmlns="http://www.w3.org/2000/09/xmldsig#"> Algorithm="http://www.microsoft.com/xrml/lwc14n"/> Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> Algorithm="urn:mpeg:mpeg21:2003:01-REL-R-NS:licenseTransform"/>Algorithm="http://www.microsoft.com/xrml/lwc14n"/> Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>iVsN92uYcbd0Nj+Tz0AeQxO6jpY=Srx5gCw84/Cetb56UHWNVbcaIbV+YZ4YF9I1hKxGeFn4OptrIAotkXe6xukm9pc6zOLVAgUvpw1ZmPRPSN/8OnSgeojsBMJS34F6JyXG2v747g3MhF/XwfOvTyx+2Dqw/LzNVyxPBGjvjeNg2ijvsn0Qq0GkxE/68CAyKFfD+oK7HSjlDLuDTJXaORBjFBfhZwhEDp+ay+G7qowN3BWe00lDoZSSVlCfdqZQiuSa1JXSfgfaL2WD/2vQt1MiqOpGEVPjJ5u7Ma8Y3NeSJY3vYVZPzHFT11Ziv8Fd2z9C+v3JXleIngFsLYTZAhD/WqrRGP7wqTYODO50qlk2Fp9z6g==lAi6wXhcWOjn1rN1aIy6z4YBcYlkdrxP9EEw7iiD0tg6i0aVOgZ/FS6IxiOgZXYwTgK/BHA7QN6/lvxnecZ2cETT7w7ZRByGUN1zTQKFwXdyQz/xdp5kZ81bmI3EQWLJBT6iW5K8HZr0qRsQRlExUrWZSOI449+Br2QgOMcBMS3FEMBS8XCBPgZ3z/V9ydztWjhopBB0ZngebWEjqwtlrXEB1M+WOPWUcljdJlp5pXNkiqCrJEzenMJ+tfTfD/8zv08LdhhIAmx1VLViItRqO9OD7l313X7bVyfTWTxGmf7D9YS5Sa0UCiOXM0qVZCVuQ5CzjLRLa13FaJurQ6SBhQ==AQAB2012-09-29T15:55:01Z xmlns:r="urn:mpeg:mpeg21:2003:01-REL-R-NS">xmlns:tm="http://www.microsoft.com/DRM/XrML2/TM/v2"> tag="#global">msft:sl/PL/GENERIC/PRIVATE2.0name="licensorUrl">http://licensing.microsoft.com name="licenseCategory">msft:sl/PL/GENERIC/PRIVATE{c0cfb665-b96c-4f22-af71-ba9e2f880975}{CE939C0E-53F7-4011-A286-78B6975FA5F0}3truexmlns:q1="http://schemas.xmlsoap.org/ws/2004/04/security/trust" soapenc:arrayType="q1:TokenEntry[14]">BindingTypemsft:rm/algorithm/hwid/4.0BindingOAAAAAIAAQABAAIAAQACAAAABAABAAEAlitYJmX9RlxY3f53epjUKuPg1jhyKZRw7mjS8tT2lKY=ProductKeyRXMWX-WKNYY-T9QGD-MPWVP-9P8QHProductKeyTypemsft:rm/algorithm/pkey/2009ProductKeyActConfigIdmsft2009:2b88c4f2-ea8f-43cd-805e-4d41346e18a7&om4PiToEQOKsGGeWZg;==otherInfoPublic.licenseCategorymsft:sl/EUL/ACTIVATED/PUBLICotherInfoPrivate.licenseCategorymsft:sl/EUL/ACTIVATED/PRIVATEotherInfoPublic.sysprepActionrearmotherInfoPrivate.sysprepActionrearmClientInformationSystemUILanguageId=1033;UserUILanguageId=1033;GeoId=244ClientSystemTime2015-04-15T06:12:51ZClientSystemTimeUtc2015-04-15T06:12:51ZotherInfoPublic.secureStoreId5f7fb011-ee1a-4784-91d5-60509aaa6c95otherInfoPrivate.secureStoreId5f7fb011-ee1a-4784-91d5-60509aaa6c95)
      00010002(0x80072EE7, 13:12:51:949 - )
      00010003(0x80072EE7, 13:12:51:949)
       
      Error: (04/15/2015 01:08:33 PM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
      Description: Product: Nero Update – Error 1921.Service Nero Update (NAUpdate) could not be stopped.  Verify that you have sufficient privileges to stop system services.(NULL)(NULL)(NULL)(NULL)(NULL)
       
      Error: (04/15/2015 00:56:28 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
      Description: The handle is invalid
       
       
      CodeIntegrity Errors:
      ===================================
        Date: 2015-04-12 18:17:22.761
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
       
        Date: 2015-04-12 18:17:22.714
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
       
        Date: 2015-04-12 18:17:22.683
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
       
        Date: 2015-04-12 18:17:22.636
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
       
        Date: 2015-04-12 18:06:22.402
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
       
        Date: 2015-04-12 18:06:22.356
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
       
       
      ==================== Memory info =========================== 
       
      Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHz
      Percentage of memory in use: 76%
      Total physical RAM: 3981.59 MB
      Available physical RAM: 932.46 MB
      Total Pagefile: 7961.37 MB
      Available Pagefile: 4081.78 MB
      Total Virtual: 8192 MB
      Available Virtual: 8191.81 MB
       
      ==================== Drives ================================
       
      Drive c: () (Fixed) (Total:202.89 GB) (Free:37.85 GB) NTFS
      Drive d: (Hitam) (Fixed) (Total:202.67 GB) (Free:54.09 GB) NTFS
      Drive e: (Putih) (Fixed) (Total:60.1 GB) (Free:23.73 GB) NTFS
       
      ==================== MBR & Partition Table ==================
       
      ========================================================
      Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 16E7DD24)
      Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=202.9 GB) - (Type=07 NTFS)
      Partition 3: (Not Active) - (Size=202.7 GB) - (Type=07 NTFS)
      Partition 4: (Not Active) - (Size=60.1 GB) - (Type=07 NTFS)
       
      ==================== End Of Log ============================

      Just a few things to go over.

       

      Its easier for me to evaluate the logs if you just copy and paste them in in lieu of attaching them

       

      IObit
       
      I want to give you a heads up on IObit , its a program from China and not recommended. The Chinese company behind this product was found to be stealing Malwarebytes database. I would like you to uninstall it as there are better program out there,   why use one from from a questional company with unethical business practices.
       
      http://blogs.computerworld.com/15026/iobit_accused_of_stealing_from_malwarebytes
       
       
       
       
      Download CKScanner by askey127 from Here & save it to your Desktop.
      • Doubleclick CKScanner.exe then click Search For Files
      • When the cursor hourglass disappears, click Save List To File
      • A message box will verify the file saved
      • Please Run this program only once
      • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
      • Whooa..I just know that things. Its so really bad to keep it up. Thanks anyway for your suggestion. 
        Well, this is the log and sorry for the inconvenience. Seems to many crack on the log ya  :wall:

         

        ======================================================
         

        CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
        c:\program files\poweriso\keygen.exe
        c:\program files (x86)\asus\atk package\atk hotkey\atkmsgctrl.exe
        c:\qoobox\quarantine\registry_backups\service_service kmseldi.reg.dat
        c:\users\defhawk\appdata\local\vs revo group\revo uninstaller pro\backupsdata\kmspico v9.0.5.20131110 (rc)-14042015-003434\regdata.dat
        c:\users\defhawk\appdata\roaming\utorrent\bigfish games - burger rush + adnan_boy 2008 + precracked.torrent
        c:\users\defhawk\appdata\roaming\utorrent\burger shop-precracked-bigfish-reflexive-hivbaby.rar.1.torrent
        c:\users\defhawk\appdata\roaming\utorrent\burger shop-precracked-bigfish-reflexive-hivbaby.rar.torrent
        c:\users\defhawk\appdata\roaming\utorrent\crack.torrent
        c:\users\defhawk\appdata\roaming\utorrent\xilisoft video converter ultimate 7.8.5.20141031 incl. keygen-brd [atom].torrent
        c:\users\defhawk\appdata\roaming\utorrent\xilisoft.video.converter.ultimate.v7.7.2.20130217.incl.keygen-brd.torrent
        c:\users\defhawk\downloads\compressed\connectify 9.0.3 pro\patch\crack.exe
        c:\users\defhawk\pictures\rome total war\rtw\crack\rometw.exe
        c:\windows\autokms\autokms.exe
        scanner sequence 3.EH.11.VANAEZ
         —– EOF —– 
        You have illegal software on your system, this is how you infected your computer, besides it being illegal,  cracked/keygens are one of the fastest ways of infecting your system,  100% of Cracked/KeyGen software contains some form of malicious code. This forum as well as most of the other malware removal forums do not support the use of illegal software, if I was to continue helping you it could be construed in the eyes of the law as aiding and abetting a crime.  In using the crack, the 'cracker' has broken the 'End User Licence Agreement' (EULA) of the product concerned. The distribution and use of cracked software is illegal in almost every developed country.  They are also one of the biggest causes of infection. This applies to Cracks, Keygens and Warez
         
        In the future I strongly suggest you stay away from using cracks and/or Keygens. If you you want to continue, what I need you to do is to look through the CKScanner log and uninstall all the illegal software that you have downloaded and installed . After you uninstall them all, run CKScanner again and post a new log.  If I dont hear back from you in 24 hours this thread will be closed and no more help will be offered.

        I've done as your suggest about that crack and/or keygen. I realized that was my fault. Thanks for your words Ken. Hopefully, you can help me on these.
        Then, this is the log after all :

         

        CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
        scanner sequence 3.RP.11.JPCPO0
         —– EOF —– 

        Thanks for understanding. With the latest threats going around and the damage they do along with stealing personal data using the torrents or any File Sharing is really very dangerous, along with that free program you think your getting. There appears to be an issue with activating Microsoft Office, it it was obtained illegally then that needs to go as well

         

         

         
        -AdwCleaner-by Xplode
         
        Click on this link to download : ADWCleaner
        Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
        Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
         
         
        Do not click on any links in the top Advertisment.
         
        • Close all open programs and internet browsers.
        • Double click on AdwCleaner.exe to run the tool.
        • Click on Scan.
        • After the scan is complete click on "Clean"
        • Confirm each time with Ok.
        • Your computer will be rebooted automatically. A text file will open after the restart.
        • Please post the content of that logfile with your next reply.
        • You can find the logfile at C:\AdwCleaner[S1].txt as well.
        •  
           
          ===============================================================================
           
           
          [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
          • Shut down your protection software now to avoid potential conflicts.
          • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
          • The tool will open and start scanning your system.
          • Please be patient as this can take a while to complete depending on your system's specifications.
          • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
          • Post the contents of JRT.txt into your next message.
          •  
             
             
            ===============================================================================
             
            Download Malwarebytes' Anti-Malware  to your desktop. 
             
            • Windows XP : Double click on the icon to run it.
            • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
            •  
              [external image: MBAMDashboard_zpsddef9b5f.gif]
               
              • On the Dashboard click on Update Now
              • Go to the Setting Tab
              • Under Setting go to Detection and Protection
              • Under PUP and PUM make sure both are set to show Treat Detections as Malware
              • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
              • Then on the Dashboard click on Scan
              • Make sure to select THREAT SCAN
              • Then click on Scan
              • When the scan is finished and the log pops up…select Copy to Clipboard
              • Please paste the log back into this thread for review
              • Exit Malwarebytes
              • That must be my thank to you. I always ignore the pottential unwanted program as i needed it, and it changes my point of view now. As you are the trusted one of Malware hunter, i believe in yours. Next time in the future i would be more concern on these. Thanks again.

                 

                Whooa, Win32 invalid application doesnt appear at all. Have i fully secure now? What do you think?

                 

                From logs, I think i've fully removed Pokki, Mobogenie, and Baidu like in past times, but the logs answer it at all. 

                here is the logs :

                 

                AdwCleaner log

                 

                # AdwCleaner v4.201 - Logfile created 16/04/2015 at 19:31:57

                # Updated 08/04/2015 by Xplode
                # Database : 2015-04-15.1 [Server]
                # Operating system : Windows 7 Ultimate Service Pack 1 (x64)
                # Username : Defhawk - DEF-PC
                # Running from : C:\Users\Defhawk\Desktop\adwcleaner_4.201.exe
                # Option : Cleaning
                 
                ***** [ Services ] *****
                 
                 
                ***** [ Files / Folders ] *****
                 
                Folder Deleted : C:\Users\Defhawk\AppData\Local\pokki
                Folder Deleted : C:\Users\Defhawk\AppData\Roaming\FirefoxToolbar
                Folder Deleted : C:\Users\Defhawk\AppData\Roaming\RHEng
                Folder Deleted : C:\Users\Defhawk\Documents\Mobogenie
                Folder Deleted : C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd
                File Deleted : C:\Users\Defhawk\daemonprocess.txt
                File Deleted : C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\user.js
                 
                ***** [ Scheduled tasks ] *****
                 
                 
                ***** [ Shortcuts ] *****
                 
                 
                ***** [ Registry ] *****
                 
                Key Deleted : HKCU\Software\Classes\pokki
                Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
                Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
                Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}
                 
                ***** [ Web browsers ] *****
                 
                -\\ Internet Explorer v11.0.9600.17689
                 
                 
                -\\ Mozilla Firefox v34.0.5 (x86 en-GB)
                 
                 
                -\\ Google Chrome v42.0.2311.90
                 
                 
                -\\ Chromium v
                 
                 
                *************************
                 
                AdwCleaner[R0].txt - [1798 bytes] - [16/04/2015 19:14:27]
                AdwCleaner[S0].txt - [1628 bytes] - [16/04/2015 19:31:57]
                 
                ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1687  bytes] ##########
                 
                JRT log :
                 
                ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
                Junkware Removal Tool (JRT) by Thisisu
                Version: 6.5.5 (04.15.2015:1)
                OS: Windows 7 Ultimate x64
                Ran by [removed] on 16-Apr-15 at 19:37:59.05
                ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
                 
                 
                 
                 
                ~~~ Services
                 
                 
                 
                ~~~ Tasks
                 
                 
                 
                ~~~ Registry Values
                 
                Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
                 
                 
                 
                ~~~ Registry Keys
                 
                Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
                Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}
                Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}
                 
                 
                 
                ~~~ Files
                 
                 
                 
                ~~~ Folders
                 
                Successfully deleted: [Folder] C:\Users\Defhawk\AppData\Roaming\baidu security
                 
                 
                 
                 
                 
                ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
                Scan was completed on 16-Apr-15 at 19:42:13.84
                End of JRT log
                ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
                 
                Malwarebytes Anti-Malware log :

                 

                Malwarebytes Anti-Malware
                www.malwarebytes.org
                 
                Scan Date: 16-Apr-15
                Scan Time: 7:58:41 PM
                Logfile: 
                Administrator: Yes
                 
                Version: 2.00.4.1028
                Malware Database: v2015.04.16.03
                Rootkit Database: v2015.03.31.01
                License: Premium
                Malware Protection: Enabled
                Malicious Website Protection: Enabled
                Self-protection: Enabled
                 
                OS: Windows 7 Service Pack 1
                CPU: x64
                File System: NTFS
                User: Defhawk
                 
                Scan Type: Threat Scan
                Result: Completed
                Objects Scanned: 380574
                Time Elapsed: 18 min, 41 sec
                 
                Memory: Enabled
                Startup: Enabled
                Filesystem: Enabled
                Archives: Enabled
                Rootkits: Enabled
                Deep Rootkit Scan: Enabled
                Heuristics: Enabled
                PUP: Enabled
                PUM: Enabled
                 
                Processes: 0
                (No malicious items detected)
                 
                Modules: 0
                (No malicious items detected)
                 
                Registry Keys: 0
                (No malicious items detected)
                 
                Registry Values: 0
                (No malicious items detected)
                 
                Registry Data: 0
                (No malicious items detected)
                 
                Folders: 0
                (No malicious items detected)
                 
                Files: 0
                (No malicious items detected)
                 
                Physical Sectors: 0
                (No malicious items detected)
                 
                 
                (end)

                 

                Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015 04
                Ran by [removed] (administrator) on DEF-PC on 16-04-2015 22:44:08
                Running from C:\Users\[removed]\Desktop
                [removed]
                Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
                Internet Explorer Version 11 (Default browser: IE)
                Boot Mode: Normal
                Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
                 
                ==================== Processes (Whitelisted) =================
                 
                (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
                 
                (Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
                (Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
                (ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
                (Intel Corporation) C:\Windows\System32\hkcmd.exe
                () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
                (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
                (Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe
                (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
                (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
                (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
                (cFos Software GmbH) C:\Program Files\cFosSpeed\spd.exe
                (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
                (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
                (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
                (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
                (Microsoft Corporation) C:\Windows\System32\dllhost.exe
                (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
                (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
                (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
                (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
                (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
                (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
                (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
                (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
                (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
                (AIMP DevTeam) C:\Program Files\AIMP3\AIMP3.exe
                (VS Revo Group) C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe
                (Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\POWERPNT.EXE
                 
                 
                ==================== Registry (Whitelisted) ==================
                 
                (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
                 
                HKLM\…\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\btvstack.exe [1023104 2012-08-10] (Atheros Commnucations)
                HKLM\…\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\athbttray.exe [801920 2012-08-10] (Atheros Commnucations)
                HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585928 2015-01-16] (NVIDIA Corporation)
                HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [479232 2012-12-15] (Adobe Systems Incorporated)
                HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
                HKLM\…\Run: [cFosSpeed] => C:\Program Files\cFosSpeed\cFosSpeed.exe [1591744 2015-01-19] (cFos Software GmbH)
                HKLM\…\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5581888 2014-02-24] (ESET)
                Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [GoogleChromeAutoLaunch_A9AC9B5C6255D671A633D32EA1A22B00] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [812872 2015-04-14] (Google Inc.)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3890768 2015-04-13] (Tonec Inc.)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7451928 2015-03-13] (Piriform Ltd)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673088 2013-03-14] (Disc Soft Ltd)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [uTorrent] => C:\Users\Defhawk\AppData\Roaming\uTorrent\uTorrent.exe [1378304 2015-01-23] (BitTorrent Inc.)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Policies\Explorer: [] 
                AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174856 2014-09-14] (NVIDIA Corporation)
                AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156840 2014-09-14] (NVIDIA Corporation)
                ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
                ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                BootExecute: RegistryDefragBootTime.exeautocheck autochk * 
                 
                ==================== Internet (Whitelisted) ====================
                 
                (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
                 
                HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
                HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
                HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
                HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
                SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
                SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
                SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
                SearchScopes: HKU\S-1-5-21-3901189400-636743289-3933302658-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear
                BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-02-21] (Internet Download Manager, Tonec Inc.)
                BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll No File
                BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
                BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
                BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
                BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
                BHO: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> C:\Program Files (x86)\Clover\TabHelper64.dll [2014-01-23] (EJIE Technology)
                BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
                BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
                BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
                Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll [2015-02-20] (Microsoft Corporation)
                Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll [2015-02-20] (Microsoft Corporation)
                Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
                Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
                Tcpip\..\Interfaces\{2E385CBD-E7DB-4717-B418-9B593B66AADC}: [NameServer] 8.26.56.26,8.20.247.20
                Tcpip\..\Interfaces\{2EE81293-715E-4B59-B7EF-634063A4DE30}: [NameServer] 8.26.56.26,8.20.247.20
                 
                FireFox:
                ========
                FF ProfilePath: C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default
                FF NetworkProxy: "gopher", ""
                FF NetworkProxy: "gopher_port", 0
                FF NetworkProxy: "share_proxy_settings", true
                FF NetworkProxy: "type", 0
                FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
                FF Plugin: @microsoft.com/GENUINE -> disabled No File
                FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
                FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-12-15] (Adobe Systems)
                FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
                FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll [2015-01-09] (Adobe Systems, Inc.)
                FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
                FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-08] (Google)
                FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)
                FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
                FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
                FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
                FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)
                FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2014-05-22] (Nitro PDF)
                FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
                FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
                FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
                FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
                FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-12-15] (Adobe Systems)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2014-01-20] (Apple Inc.)
                FF Extension: Auto Hide IP - C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\Extensions\[removed] [2014-07-20]
                FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-15]
                FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-15]
                FF HKLM\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
                FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2015-04-13]
                FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
                FF HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5
                FF Extension: IDM CC - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5 [2015-04-13]
                FF HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5
                FF Extension: No Name - C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\extensions\[removed] [Not Found]
                 
                Chrome: 
                =======
                CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.703\_platform_specific\win_x86\widevinecdmadapter.dll No File
                CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\PepperFlash\pepflashplayer.dll ()
                CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
                CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\internal-nacl-plugin No File
                CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\pdf.dll No File
                CHR Plugin: (Internet Download Manager Plugin) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn\6.21.16_0\IDMGCExt.dll No File
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
                CHR Plugin: (Nero Kwik Media Helper) - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
                CHR Plugin: (Microsoft Office 2013) - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
                CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
                CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
                CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
                CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
                CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
                CHR Plugin: (Microsoft Office 2013) - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
                CHR Plugin: (Nitro PDF plugin for Firefox and Chrome) - C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF)
                CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
                CHR Profile: C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default
                CHR Extension: (Google Translate) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2014-10-23]
                CHR Extension: (Xmarks Bookmark Sync) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajpgkpeckebdhofmmjfgcjjiiejpodla [2013-12-16]
                CHR Extension: (From Dust) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\anelkojiepicmcldgnmkplocifmegpfj [2013-12-16]
                CHR Extension: (Google Docs) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-20]
                CHR Extension: (Google Drive) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-20]
                CHR Extension: (WOT) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2013-11-20]
                CHR Extension: (YouTube) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-20]
                CHR Extension: (Adblock Plus) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-20]
                CHR Extension: (Google Search) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-20]
                CHR Extension: (Tampermonkey) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-12-16]
                CHR Extension: (Photo Zoom for Facebook) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2013-11-20]
                CHR Extension: (AdBlock) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-11-20]
                CHR Extension: (Bookmark Manager) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-16]
                CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-07]
                CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-02]
                CHR Extension: (IDM Integration Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-04-13]
                CHR Extension: (Google Wallet) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-20]
                CHR Extension: (Checker Plus for Gmail™) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2013-11-20]
                CHR Extension: (Gmail) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-20]
                CHR HKLM\…\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]
                CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]
                CHR HKU\S-1-5-21-3901189400-636743289-3933302658-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
                CHR HKLM-x32\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]
                 
                ==================== Services (Whitelisted) =================
                 
                (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
                 
                S2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
                S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [216906 2012-08-10] (Atheros Commnucations) [File not signed]
                S4 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [32768 2014-02-07] (Autodesk, Inc.) [File not signed]
                S4 CDROM_Detect; C:\Program Files\Cyborg Telkomsel Mobile Broadband\WCDMA_Eject.exe [325632 2013-06-08] () [File not signed]
                R2 cFosSpeedS; C:\Program Files\cFosSpeed\spd.exe [500672 2015-01-19] (cFos Software GmbH)
                R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [117704 2015-01-09] (Intel Corporation)
                R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116680 2015-01-09] (Intel Corporation)
                R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1343408 2014-02-24] (ESET)
                S4 EMP_UDSA; C:\Program Files (x86)\EPSON Projector\Epson USB Display V1.5\EMP_UDSA.exe [98304 2011-01-06] (SEIKO EPSON CORPORATION) [File not signed]
                S4 FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [1362426 2014-10-02] (Flexera Software LLC) [File not signed]
                S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2015-01-16] (NVIDIA Corporation)
                S2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116736 2013-11-20] (Google Inc.) [File not signed]
                S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116736 2013-11-20] (Google Inc.) [File not signed]
                S3 gusvc; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [136192 2011-05-10] (Google) [File not signed]
                R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
                R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
                R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
                S3 MozillaMaintenance; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [115200 2014-12-15] (Mozilla Foundation) [File not signed]
                S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [278010 2012-08-23] () [File not signed]
                R2 NitroDriverReadSpool9; C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe [230920 2014-05-22] (Nitro PDF Software)
                S2 NitroUpdateService; C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe [417800 2014-05-22] ()
                R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706312 2015-01-16] (NVIDIA Corporation)
                S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21838866 2015-01-16] (NVIDIA Corporation) [File not signed]
                S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1903616 2014-12-18] (Electronic Arts) [File not signed]
                S4 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-11-26] ()
                S2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2013-09-13] (arvato digital services llc)
                S4 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275264 2013-10-09] (Skype Technologies S.A.) [File not signed]
                R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2014-12-02] (Western Digital Technologies, Inc.)
                R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [296312 2014-06-02] (Western Digital Technologies, Inc.)
                R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
                S4 ZAtheros Bt&Wlan; Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [327680 2012-08-10] (Atheros) [File not signed]
                S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3347962 2012-08-23] (Intel® Corporation) [File not signed]
                 
                ==================== Drivers (Whitelisted) ====================
                 
                (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
                 
                S3 ampa; C:\Windows\system32\ampa.sys [15288 2011-12-26] () [File not signed]
                S3 ampa; C:\Windows\SysWOW64\ampa.sys [12728 2011-12-26] () [File not signed]
                R3 ATP; C:\Windows\System32\DRIVERS\AsusTP.sys [70416 2015-01-09] (ASUS Corporation)
                S3 CT_QUALCOMM_U_drv; C:\Windows\System32\DRIVERS\CT_QUALCOMM_U_drv.sys [118016 2009-04-27] (QUALCOMM Incorporated)
                R3 DptfDevDram; C:\Windows\System32\DRIVERS\DptfDevDram.sys [145640 2015-01-09] (Intel Corporation)
                R3 DptfDevFan; C:\Windows\System32\DRIVERS\DptfDevFan.sys [50640 2015-01-09] (Intel Corporation)
                R3 DptfDevGen; C:\Windows\System32\DRIVERS\DptfDevGen.sys [78504 2015-01-09] (Intel Corporation)
                R3 DptfDevProc; C:\Windows\System32\DRIVERS\DptfDevProc.sys [289744 2015-01-09] (Intel Corporation)
                R3 DptfManager; C:\Windows\System32\DRIVERS\DptfManager.sys [494296 2015-01-09] (Intel Corporation)
                R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-11-03] (DT Soft Ltd)
                R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
                U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET)
                R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
                R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [30752 2014-04-07] (EldoS Corporation)
                R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET)
                R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)
                R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET)
                R3 eppvad_simple; C:\Windows\System32\drivers\EMP_UDAU.sys [23040 2011-01-06] (SEIKO EPSON CORPORATION)
                S3 esgiguard; C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [14872 2014-01-07] ()
                R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-01-03] (REALiX™)
                R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-12-18] (Intel Corporation)
                R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [17280 2012-08-05] ( )
                R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
                R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-04-16] (Malwarebytes Corporation)
                R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
                R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [129312 2015-03-23] (Intel Corporation)
                S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19784 2015-01-16] (NVIDIA Corporation)
                R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
                S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
                S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
                S3 REN2CAP_DRIVER; C:\Windows\System32\drivers\ren2cap.sys [46728 2011-11-07] ()
                S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [74240 2015-01-09] (Research In Motion Limited)
                S3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [455240 2013-03-05] (RTS Corporation)
                R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
                R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-12-09] (Duplex Secure Ltd.)
                U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-04-12] ()
                U3 avce1f1u; C:\Windows\System32\Drivers\avce1f1u.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero size file/folder)
                S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X]
                S3 catchme; \??\C:\Worksnow\catchme.sys [X]
                S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X]
                S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
                S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
                S3 PCFApiUtil; \??\C:\Program Files (x86)\Baidu Security\PC Faster\PCFApiUtil64.sys [X]
                S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
                S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
                S3 VGPU; System32\drivers\rdvgkmd.sys [X]
                S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
                S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
                 
                ==================== NetSvcs (Whitelisted) ===================
                 
                (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
                 
                 
                ==================== One Month Created Files and Folders ========
                 
                (If an entry is included in the fixlist, the file\folder will be moved.)
                 
                2015-04-16 20:24 - 2015-04-16 20:24 - 00001079 _____ () C:\Users\Defhawk\Desktop\Mbam.txt
                2015-04-16 20:24 - 2015-04-16 19:32 - 00001771 _____ () C:\Users\Defhawk\Desktop\AdwCleaner[S0].txt
                2015-04-16 19:42 - 2015-04-16 19:42 - 00001267 _____ () C:\Users\Defhawk\Desktop\JRT.txt
                2015-04-16 19:14 - 2015-04-16 19:32 - 00000000 ____D () C:\AdwCleaner
                2015-04-16 19:10 - 2015-04-16 19:09 - 02686088 _____ (Thisisu) C:\Users\Defhawk\Desktop\JRT.exe
                2015-04-16 19:10 - 2015-04-16 19:04 - 02217984 _____ () C:\Users\Defhawk\Desktop\adwcleaner_4.201.exe
                2015-04-16 17:48 - 2015-04-16 17:48 - 00000127 _____ () C:\Users\Defhawk\Desktop\ckfiles.txt
                2015-04-16 17:30 - 2015-04-16 17:30 - 00003262 _____ () C:\Windows\System32\Tasks\{1744B18A-8492-42F2-9C76-0E8897CEDBA8}
                2015-04-15 22:19 - 2015-04-15 22:19 - 00468480 _____ () C:\Users\Defhawk\Desktop\CKScanner.exe
                2015-04-15 22:10 - 2015-04-15 22:10 - 00107520 ___SH () C:\Users\Defhawk\Documents\Thumbs.db
                2015-04-15 22:09 - 2015-04-15 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
                2015-04-15 21:21 - 2015-04-16 21:17 - 00038039 _____ () C:\Users\Defhawk\Desktop\Addition.txt
                2015-04-15 21:19 - 2015-04-16 22:45 - 00034007 _____ () C:\Users\Defhawk\Desktop\FRST.txt
                2015-04-15 21:19 - 2015-04-16 22:44 - 00000000 ____D () C:\FRST
                2015-04-15 21:19 - 2015-04-16 21:13 - 02097664 _____ (Farbar) C:\Users\Defhawk\Desktop\FRST64.exe
                2015-04-15 21:17 - 2015-04-15 21:17 - 00001447 _____ () C:\Users\Defhawk\Desktop\aswMBR.txt
                2015-04-15 21:17 - 2015-04-15 21:17 - 00000512 _____ () C:\Users\Defhawk\Desktop\MBR.dat
                2015-04-15 21:15 - 2015-04-15 21:15 - 05198336 _____ (AVAST Software) C:\Users\Defhawk\Desktop\aswMBR.exe
                2015-04-15 19:36 - 2015-04-15 19:38 - 00001131 _____ () C:\Users\Defhawk\Desktop\PTE.lnk
                2015-04-15 19:20 - 2015-04-15 19:46 - 00000000 ____D () C:\Program Files (x86)\Pro Evolution Soccer 2015
                2015-04-15 19:20 - 2015-04-15 19:20 - 00000902 _____ () C:\Users\Public\Desktop\Pro Evolution Soccer 2015.lnk
                2015-04-15 10:08 - 2015-04-15 10:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
                2015-04-15 10:01 - 2015-04-15 10:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
                2015-04-14 23:01 - 2015-04-15 10:05 - 00000000 ____D () C:\Program Files\Microsoft Office
                2015-04-14 18:17 - 2015-04-14 18:17 - 00000000 __RHD () C:\MSOCache
                2015-04-14 18:06 - 2015-04-14 18:06 - 00019570 _____ () C:\Users\Defhawk\Documents\140415.reg
                2015-04-14 11:59 - 2015-04-16 19:33 - 00004690 _____ () C:\Windows\setupact.log
                2015-04-14 11:59 - 2015-04-14 11:59 - 00000000 _____ () C:\Windows\setuperr.log
                2015-04-14 11:58 - 2015-04-16 19:33 - 00024084 _____ () C:\Windows\PFRO.log
                2015-04-14 01:26 - 2015-04-14 01:26 - 00486050 _____ () C:\Users\Defhawk\Documents\UninstallKey01.reg
                2015-04-14 01:24 - 2015-04-14 01:24 - 00869656 _____ () C:\Users\Defhawk\Documents\DeletedKey01.reg
                2015-04-14 00:50 - 2015-04-14 00:50 - 00020224 _____ () C:\Users\Defhawk\Documents\install.txt
                2015-04-14 00:45 - 2015-04-14 00:45 - 00000000 ____D () C:\Users\Default\AppData\Roaming\IObit
                2015-04-14 00:45 - 2015-04-14 00:45 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\IObit
                2015-04-14 00:17 - 2015-04-14 00:17 - 00001932 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Pro 9.lnk
                2015-04-14 00:17 - 2015-04-14 00:17 - 00001920 _____ () C:\Users\Public\Desktop\Nitro Pro 9.lnk
                2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files\Nitro
                2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files\Common Files\Nitro
                2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files (x86)\Nitro
                2015-04-14 00:17 - 2014-05-22 14:05 - 00029704 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalmon9.dll
                2015-04-14 00:17 - 2014-05-22 14:05 - 00017928 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalui9.dll
                2015-04-13 23:49 - 2015-04-13 23:49 - 00000000 ___SD () C:\Windows\system32\CompatTel
                2015-04-13 23:49 - 2015-04-13 23:49 - 00000000 ____D () C:\Windows\system32\appraiser
                2015-04-13 23:44 - 2015-04-13 23:44 - 00001077 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
                2015-04-13 23:44 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
                2015-04-13 23:14 - 2013-10-02 09:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
                2015-04-13 23:14 - 2013-10-02 09:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
                2015-04-13 23:14 - 2013-10-02 09:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
                2015-04-13 23:14 - 2013-10-02 08:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
                2015-04-13 23:14 - 2013-10-02 08:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
                2015-04-13 23:14 - 2013-10-02 08:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
                2015-04-13 23:14 - 2013-10-02 08:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
                2015-04-13 23:14 - 2013-10-02 07:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
                2015-04-13 23:14 - 2013-10-02 07:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
                2015-04-13 23:14 - 2013-10-02 07:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
                2015-04-13 23:14 - 2013-10-02 07:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
                2015-04-13 23:14 - 2013-10-02 07:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
                2015-04-13 23:14 - 2013-10-02 06:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
                2015-04-13 23:14 - 2013-10-02 06:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
                2015-04-13 23:14 - 2013-10-02 06:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
                2015-04-13 23:14 - 2013-10-02 05:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
                2015-04-13 23:14 - 2013-10-02 03:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
                2015-04-13 23:14 - 2013-10-02 03:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
                2015-04-13 23:13 - 2015-03-25 10:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
                2015-04-13 23:13 - 2015-03-25 10:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
                2015-04-13 23:13 - 2015-03-25 10:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
                2015-04-13 23:13 - 2015-03-25 10:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
                2015-04-13 23:13 - 2015-03-25 10:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
                2015-04-13 23:13 - 2015-03-25 10:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
                2015-04-13 23:13 - 2015-03-25 10:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
                2015-04-13 23:13 - 2015-03-25 10:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
                2015-04-13 23:12 - 2015-03-23 10:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
                2015-04-13 23:12 - 2015-03-23 10:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
                2015-04-13 23:12 - 2015-03-23 10:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
                2015-04-13 23:12 - 2015-03-23 10:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
                2015-04-13 23:12 - 2015-03-23 10:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
                2015-04-13 23:12 - 2015-03-23 10:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
                2015-04-13 23:12 - 2015-03-23 10:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
                2015-04-13 23:12 - 2015-03-23 10:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
                2015-04-13 23:12 - 2015-01-28 06:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
                2015-04-13 22:51 - 2015-04-13 22:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
                2015-04-13 22:38 - 2015-04-13 22:38 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
                2015-04-13 22:38 - 2015-04-13 22:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
                2015-04-13 22:26 - 2015-04-13 22:26 - 00000000 ____D () C:\ProgramData\ESET
                2015-04-13 22:19 - 2015-04-13 22:19 - 00055680 _____ () C:\Users\Defhawk\Documents\cc_20150413_221934.reg
                2015-04-13 20:20 - 2015-04-13 20:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
                2015-04-13 20:20 - 2015-04-13 20:20 - 00000000 ____D () C:\Program Files (x86)\K-Lite Codec Pack
                2015-04-13 20:20 - 2013-10-26 01:00 - 00127488 _____ () C:\Windows\system32\ff_vfw.dll
                2015-04-13 20:20 - 2013-10-26 01:00 - 00112640 _____ () C:\Windows\SysWOW64\ff_vfw.dll
                2015-04-13 20:20 - 2013-03-18 00:22 - 03554304 _____ (x264vfw project) C:\Windows\system32\x264vfw64.dll
                2015-04-13 20:20 - 2013-03-17 23:21 - 03649536 _____ (x264vfw project) C:\Windows\SysWOW64\x264vfw.dll
                2015-04-13 20:20 - 2012-07-21 17:54 - 00122880 _____ (fccHandler) C:\Windows\SysWOW64\ac3acm.acm
                2015-04-13 20:20 - 2011-12-08 00:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll
                2015-04-13 20:20 - 2011-12-08 00:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\lagarith.dll
                2015-04-13 20:20 - 2011-06-24 21:45 - 00258560 _____ () C:\Windows\system32\xvidvfw.dll
                2015-04-13 20:20 - 2011-06-24 21:44 - 00243200 _____ () C:\Windows\SysWOW64\xvidvfw.dll
                2015-04-12 20:53 - 2015-04-12 20:53 - 00000000 ____D () C:\ProgramData\KONAMI
                2015-04-12 18:38 - 2015-04-12 18:39 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files
                2015-04-12 18:30 - 2015-04-12 18:30 - 00045107 _____ () C:\ComboFix.txt
                2015-04-12 17:58 - 2015-04-15 22:49 - 00000000 ____D () C:\Windows\erdnt
                2015-04-12 16:50 - 2015-04-12 16:50 - 00001072 _____ () C:\Users\Public\Desktop\SMADΔV.lnk
                2015-04-12 14:46 - 2015-04-12 14:46 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DEF-PC-Windows-7-Ultimate-(64-bit).dat
                2015-04-12 14:45 - 2015-04-12 14:45 - 00003652 _____ () C:\Windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
                2015-04-12 14:45 - 2015-04-12 14:45 - 00002159 _____ () C:\Users\Defhawk\Desktop\Tweaking.com - Windows Repair.lnk
                2015-04-12 14:39 - 2015-04-12 14:42 - 12849664 _____ () C:\Users\Defhawk\Downloads\tweaking.com_windows_repair_aio_setup.exe
                2015-04-12 14:34 - 2015-04-12 14:34 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
                2015-04-12 14:34 - 2015-04-12 14:34 - 00000000 ___SD () C:\Windows\system32\GWX
                2015-04-12 13:55 - 2015-04-12 15:51 - 00318769 _____ () C:\MGlogs.zip
                2015-04-12 13:55 - 2015-04-12 13:55 - 00000000 ____D () C:\ProgramData\HitmanPro
                2015-04-12 13:02 - 2015-04-12 13:34 - 00000000 ____D () C:\ProgramData\RogueKiller
                2015-04-12 13:02 - 2015-04-12 13:02 - 00035064 _____ () C:\Windows\system32\Drivers\TrueSight.sys
                2015-04-12 03:12 - 2015-04-12 03:12 - 00000416 _____ () C:\Users\Defhawk\120415backup.reg
                2015-04-12 01:08 - 2015-04-12 01:08 - 00001646 _____ () C:\Users\Defhawk\Documents\cc_20150412_010800.reg
                2015-04-12 00:44 - 2011-06-11 05:15 - 05601616 _____ (Microsoft Corporation) C:\Windows\system32\mfc100u.dll
                2015-04-12 00:44 - 2011-06-11 05:15 - 05574984 _____ (Microsoft Corporation) C:\Windows\system32\mfc100.dll
                2015-04-12 00:14 - 2010-03-18 19:27 - 00827744 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll
                2015-04-11 16:46 - 2015-04-11 16:49 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\WCDMA_General
                2015-04-11 16:46 - 2015-04-11 16:46 - 00000916 _____ () C:\Users\Public\Desktop\Cyborg Telkomsel Mobile Broadband.lnk
                2015-04-11 16:46 - 2015-04-11 16:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cyborg Telkomsel Mobile Broadband
                2015-04-11 16:46 - 2015-04-11 16:46 - 00000000 ____D () C:\Program Files\Cyborg Telkomsel Mobile Broadband
                2015-04-11 16:46 - 2009-04-27 16:33 - 00118016 _____ (QUALCOMM Incorporated) C:\Windows\system32\Drivers\CT_QUALCOMM_U_drv.sys
                2015-04-11 13:05 - 2015-04-11 13:14 - 45473792 _____ () C:\Windows\system32\config\components.old
                2015-04-05 13:46 - 2015-04-05 13:47 - 45473792 _____ () C:\Windows\system32\config\COMPONENTS.iobit
                2015-04-05 01:19 - 2015-04-05 01:19 - 00003342 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup
                2015-04-05 01:19 - 2015-04-05 01:19 - 00002248 _____ () C:\Users\Defhawk\Desktop\SpyHunter.lnk
                2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
                2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\sh4ldr
                2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group
                2015-04-05 00:10 - 2015-04-05 00:10 - 76125026 _____ () C:\Users\Defhawk\Downloads\Tomorrowland 2014 - official aftermovie - YouTube.MKV
                2015-04-03 13:26 - 2015-04-03 13:26 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DEF-PC-Microsoft-Windows-7-Ultimate-(64-bit).dat
                2015-04-03 13:26 - 2015-04-03 13:26 - 00000000 ____D () C:\RegBackup
                2015-04-02 21:41 - 2015-04-15 19:20 - 00000914 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro Evolution Soccer 2015.lnk
                2015-04-01 19:10 - 2013-10-18 15:01 - 00285747 _____ () C:\shldr
                2015-04-01 19:10 - 2013-10-18 15:01 - 00008192 _____ () C:\shldr.mbr
                2015-04-01 00:33 - 2015-04-16 22:24 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
                2015-04-01 00:33 - 2015-04-01 00:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
                2015-04-01 00:33 - 2015-04-01 00:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
                2015-04-01 00:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
                2015-04-01 00:33 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
                2015-03-31 22:39 - 2015-03-31 22:39 - 00000000 _____ () C:\autoexec.bat
                2015-03-31 21:37 - 2015-04-01 00:33 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
                2015-03-31 21:37 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
                2015-03-23 22:46 - 2015-01-10 15:32 - 00128288 _____ (IObit) C:\Windows\system32\IObitSmartDefragExtension.dll
                2015-03-23 22:46 - 2014-06-04 15:17 - 00034080 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe
                2015-03-23 22:46 - 2014-06-04 15:17 - 00021184 _____ (IObit) C:\Windows\system32\Drivers\SmartDefragDriver.sys
                2015-03-23 22:40 - 2015-03-23 22:40 - 00943832 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
                2015-03-23 22:40 - 2015-03-23 22:40 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
                2015-03-23 22:39 - 2015-03-23 22:39 - 00129312 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys
                2015-03-17 20:08 - 2015-03-17 19:53 - 00189912 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys
                 
                ==================== One Month Modified Files and Folders =======
                 
                (If an entry is included in the fixlist, the file\folder will be moved.)
                 
                2015-04-16 22:42 - 2013-11-04 00:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\AIMP3
                2015-04-16 22:39 - 2014-04-09 22:53 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\IObit
                2015-04-16 22:27 - 2015-01-09 17:37 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
                2015-04-16 22:23 - 2014-10-02 21:36 - 00000000 ____D () C:\Program Files\Autodesk
                2015-04-16 22:23 - 2014-10-02 21:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
                2015-04-16 22:23 - 2014-10-02 21:30 - 00000000 ____D () C:\ProgramData\Autodesk
                2015-04-16 22:17 - 2015-02-05 18:12 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57.job
                2015-04-16 22:17 - 2014-04-01 05:10 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6.job
                2015-04-16 22:15 - 2014-03-30 02:51 - 00000000 ____D () C:\Program Files\Corel
                2015-04-16 22:09 - 2013-11-20 00:11 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
                2015-04-16 21:59 - 2014-10-02 21:30 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Autodesk
                2015-04-16 21:55 - 2013-11-05 03:31 - 00000000 ____D () C:\Users\Defhawk\AppData\Local\CrashDumps
                2015-04-16 21:51 - 2014-10-02 21:36 - 00000000 ____D () C:\Program Files\Common Files\Autodesk Shared
                2015-04-16 21:39 - 2009-07-14 11:45 - 00021200 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
                2015-04-16 21:39 - 2009-07-14 11:45 - 00021200 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
                2015-04-16 21:15 - 2013-11-07 01:32 - 01373211 _____ () C:\Windows\WindowsUpdate.log
                2015-04-16 20:19 - 2009-07-14 12:13 - 00776420 _____ () C:\Windows\system32\PerfStringBackup.INI
                2015-04-16 19:36 - 2014-06-16 16:13 - 00008192 _____ () C:\Windows\SysWOW64\WDPABKP.dat
                2015-04-16 19:35 - 2013-11-04 19:58 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\uTorrent
                2015-04-16 19:34 - 2015-02-05 18:12 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5.job
                2015-04-16 19:34 - 2014-04-01 05:10 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d.job
                2015-04-16 19:34 - 2014-03-18 14:56 - 00000000 ____D () C:\Program Files (x86)\SMADAV
                2015-04-16 19:33 - 2013-11-04 18:29 - 00000000 ____D () C:\Program Files\PowerISO
                2015-04-16 19:33 - 2009-07-14 12:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
                2015-04-16 19:31 - 2013-11-03 10:54 - 00000000 ____D () C:\Users\Defhawk
                2015-04-16 17:32 - 2014-11-30 03:17 - 00000000 ____D () C:\Users\Defhawk\Downloads\Compressed
                2015-04-16 12:59 - 2013-11-03 15:05 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\DMCache
                2015-04-16 07:09 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\Speech
                2015-04-15 22:55 - 2013-11-04 20:36 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Nitro PDF
                2015-04-15 22:32 - 2014-04-09 22:55 - 00000000 ____D () C:\ProgramData\IObit
                2015-04-15 22:29 - 2015-01-09 17:37 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
                2015-04-15 22:29 - 2013-11-03 14:20 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
                2015-04-15 22:29 - 2013-11-03 14:20 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
                2015-04-15 22:18 - 2014-03-31 11:30 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\IDM
                2015-04-15 22:09 - 2015-01-27 00:03 - 00000722 _____ () C:\Users\Public\Desktop\AIMP3.lnk
                2015-04-15 22:08 - 2013-11-04 00:02 - 00000000 ____D () C:\Program Files\AIMP3
                2015-04-15 22:03 - 2015-01-03 04:36 - 00002858 _____ () C:\Windows\System32\Tasks\Driver Booster SkipUAC (Defhawk)
                2015-04-15 21:46 - 2013-11-20 00:25 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
                2015-04-15 21:12 - 2014-04-09 22:55 - 00000000 ____D () C:\ProgramData\ProductData
                2015-04-15 19:45 - 2013-11-05 15:39 - 00000000 ____D () C:\Program Files (x86)\Steam
                2015-04-15 19:05 - 2013-11-04 18:00 - 00000000 ____D () C:\Users\Defhawk\Documents\Bluetooth Folder
                2015-04-15 18:40 - 2013-11-04 17:40 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Corel
                2015-04-15 18:40 - 2013-11-04 17:30 - 00000000 ____D () C:\ProgramData\Corel
                2015-04-15 18:37 - 2014-03-30 02:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)
                2015-04-15 13:15 - 2014-12-02 01:16 - 00000000 ____D () C:\Users\Defhawk\Documents\SnowFox Total Video Converter
                2015-04-15 13:15 - 2014-05-24 20:49 - 00000000 ____D () C:\Users\Defhawk\Documents\Scanned
                2015-04-15 10:34 - 2009-07-14 11:45 - 05979304 _____ () C:\Windows\system32\FNTCACHE.DAT
                2015-04-15 10:31 - 2013-11-03 12:30 - 00490216 _____ () C:\Users\Defhawk\AppData\Local\GDIPFONTCACHEV1.DAT
                2015-04-15 10:09 - 2013-11-04 16:03 - 00000000 ____D () C:\ProgramData\Microsoft Help
                2015-04-15 10:07 - 2014-05-11 14:29 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\vlc
                2015-04-15 10:03 - 2009-07-14 09:34 - 00000514 _____ () C:\Windows\win.ini
                2015-04-15 10:01 - 2009-07-14 10:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
                2015-04-15 01:26 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\AppCompat
                2015-04-15 00:25 - 2009-07-14 14:46 - 00000000 ____D () C:\Windows\CSC
                2015-04-15 00:20 - 2013-11-04 00:36 - 00003160 _____ () C:\Windows\System32\Tasks\SidebarExecute
                2015-04-15 00:12 - 2013-11-03 12:33 - 00776420 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
                2015-04-14 06:48 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\rescache
                2015-04-14 01:15 - 2013-11-03 19:08 - 00000000 ____D () C:\ProgramData\USBChargerPlus
                2015-04-14 01:04 - 2014-05-02 23:18 - 00000000 ____D () C:\Users\Defhawk\AppData\Local\VMware
                2015-04-14 01:04 - 2009-07-14 10:20 - 00000000 ___RD () C:\Users\Default
                2015-04-13 23:53 - 2009-07-14 10:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
                2015-04-13 23:44 - 2014-10-05 00:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
                2015-04-13 23:44 - 2014-10-05 00:33 - 00000000 ____D () C:\Program Files\VS Revo Group
                2015-04-13 22:40 - 2013-11-03 13:05 - 00000000 ____D () C:\Program Files\WinRAR
                2015-04-13 22:26 - 2014-12-18 01:40 - 00000000 ____D () C:\Program Files\ESET
                2015-04-13 22:18 - 2013-11-03 23:35 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
                2015-04-13 22:18 - 2013-11-03 23:34 - 00000000 ____D () C:\Program Files\CCleaner
                2015-04-13 21:06 - 2014-03-31 11:30 - 00000000 ____D () C:\Program Files (x86)\Internet Download Manager
                2015-04-13 20:42 - 2013-11-03 10:59 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\DAEMON Tools Lite
                2015-04-13 20:39 - 2013-11-03 15:05 - 00001009 _____ () C:\Users\Defhawk\Desktop\Internet Download Manager.lnk
                2015-04-13 20:34 - 2013-11-04 18:31 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\PowerISO
                2015-04-13 19:29 - 2013-11-04 01:47 - 00000000 ____D () C:\Windows\Panther
                2015-04-12 21:34 - 2014-10-25 03:09 - 00000000 ____D () C:\Users\Defhawk\Downloads\Lamaran
                2015-04-12 21:34 - 2014-10-16 02:13 - 00000000 ____D () C:\Users\Defhawk\Downloads\Defraggler Professional Edition v2.18 Final - SceneDL
                2015-04-12 21:34 - 2014-10-03 03:03 - 00000000 ____D () C:\Users\Defhawk\Documents\KONAMI
                2015-04-12 21:34 - 2014-09-24 03:56 - 00000000 ____D () C:\Users\Defhawk\Desktop\Tor Browser
                2015-04-12 20:27 - 2014-03-18 14:56 - 00000000 ____D () C:\[Smad-Cage]
                2015-04-12 18:26 - 2013-11-05 16:27 - 00000000 ____D () C:\ProgramData\TEMP
                2015-04-12 18:23 - 2009-07-14 09:34 - 00000215 _____ () C:\Windows\system.ini
                2015-04-12 18:22 - 2009-07-14 09:34 - 00000027 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_134
                2015-04-12 18:19 - 2009-07-14 09:34 - 41680896 _____ () C:\Windows\system32\config\SYSTEM.bak
                2015-04-12 18:19 - 2009-07-14 09:34 - 103915520 _____ () C:\Windows\system32\config\SOFTWARE.bak
                2015-04-12 18:19 - 2009-07-14 09:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
                2015-04-12 18:19 - 2009-07-14 09:34 - 00065536 _____ () C:\Windows\system32\config\SAM.bak
                2015-04-12 18:19 - 2009-07-14 09:34 - 00028672 _____ () C:\Windows\system32\config\SECURITY.bak
                2015-04-12 16:50 - 2014-12-17 00:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus
                2015-04-12 11:10 - 2013-11-09 13:35 - 00000000 ____D () C:\Windows\MSSecurityNS
                2015-04-12 02:01 - 2009-07-14 11:54 - 00000749 ____R () C:\Windows\WindowsShell.Manifest
                2015-04-12 02:01 - 2009-07-14 10:20 - 00000000 ___RD () C:\Users\Public\Libraries
                2015-04-12 01:05 - 2013-12-01 23:04 - 00000000 ___RD () C:\Users\Defhawk\Dropbox
                2015-04-12 01:05 - 2013-12-01 23:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Dropbox
                2015-04-12 01:04 - 2014-10-31 17:13 - 00000000 ___RD () C:\Users\Defhawk\Google Drive
                2015-04-12 00:55 - 2014-07-20 22:55 - 00000038 _____ () C:\Windows\sysreg.dat
                2015-04-12 00:55 - 2008-03-05 07:47 - 00000072 _____ () C:\Windows\anticrash.dat
                2015-04-12 00:55 - 2008-03-05 07:46 - 00000067 _____ () C:\Windows\hare.dat
                2015-04-12 00:55 - 2001-10-13 13:11 - 00000084 _____ () C:\Windows\battery.dat
                2015-04-11 23:44 - 2009-07-14 11:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
                2015-04-11 23:28 - 2009-07-14 12:08 - 00032582 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
                2015-04-11 20:04 - 2013-12-01 23:04 - 00001021 _____ () C:\Users\Defhawk\Desktop\Dropbox.lnk
                2015-04-11 20:04 - 2013-12-01 23:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
                2015-04-11 16:57 - 2009-07-14 09:34 - 00000883 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_868
                2015-04-11 13:14 - 2009-07-14 09:34 - 41680896 _____ () C:\Windows\system32\config\system.old
                2015-04-11 13:14 - 2009-07-14 09:34 - 103931904 _____ () C:\Windows\system32\config\software.old
                2015-04-11 13:14 - 2009-07-14 09:34 - 00524288 _____ () C:\Windows\system32\config\default.old
                2015-04-11 13:14 - 2009-07-14 09:34 - 00065536 _____ () C:\Windows\system32\config\sam.old
                2015-04-11 13:14 - 2009-07-14 09:34 - 00028672 _____ () C:\Windows\system32\config\security.old
                2015-04-10 09:44 - 2013-11-17 21:36 - 00000000 ____D () C:\Windows\SysWOW64\My Vaults
                2015-04-10 09:44 - 2013-11-04 18:04 - 00000000 ____D () C:\ProgramData\Atheros
                2015-04-10 09:44 - 2013-11-04 00:36 - 00000000 ____D () C:\ProgramData\P4G
                2015-04-09 18:48 - 2008-03-04 19:57 - 00000338 _____ () C:\Windows\winshell.dat
                2015-04-08 11:55 - 2013-11-03 10:53 - 00000000 ____D () C:\Recovery
                2015-04-08 11:55 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\system32\Msdtc
                2015-04-07 21:00 - 2009-07-14 12:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
                2015-04-05 19:00 - 2009-07-14 14:45 - 00000000 ___RD () C:\Users\Public\Recorded TV
                2015-04-05 13:12 - 2009-07-14 09:34 - 00000855 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_89
                2015-04-05 12:38 - 2014-04-13 15:06 - 103931904 _____ () C:\Windows\system32\config\SOFTWARE.iodefrag.bak
                2015-04-05 12:38 - 2014-04-13 15:06 - 00446464 _____ () C:\Windows\system32\config\DEFAULT.iodefrag.bak
                2015-04-05 12:38 - 2014-04-13 15:06 - 00065536 _____ () C:\Windows\system32\config\SAM.iodefrag.bak
                2015-04-05 12:38 - 2014-04-13 15:06 - 00028672 _____ () C:\Windows\system32\config\SECURITY.iodefrag.bak
                2015-04-05 12:37 - 2013-11-09 13:35 - 00000000 ____D () C:\Windows\MSSecurityNi
                2015-04-05 01:13 - 2009-07-14 09:34 - 00001117 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_839
                2015-04-01 22:09 - 2013-11-03 17:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
                2015-04-01 19:10 - 2013-11-04 18:00 - 00000000 ____D () C:\Program Files (x86)\Bluetooth Suite
                2015-04-01 06:52 - 2014-09-06 02:46 - 00001908 _____ () C:\Windows\diagwrn.xml
                2015-04-01 06:52 - 2014-09-06 02:46 - 00001908 _____ () C:\Windows\diagerr.xml
                2015-04-01 00:33 - 2013-11-05 16:41 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Malwarebytes
                2015-03-31 18:59 - 2014-07-20 22:58 - 00000000 ____D () C:\Windows\pss
                2015-03-23 22:40 - 2013-11-03 11:03 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
                2015-03-19 18:15 - 2013-11-24 23:57 - 00000000 ____D () C:\ProgramData\CanonIJPLM
                 
                ==================== Files in the root of some directories =======
                 
                2013-02-17 10:27 - 2013-02-17 10:27 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
                2014-04-12 23:59 - 2015-02-02 20:46 - 0000132 _____ () C:\Users\Defhawk\AppData\Roaming\Adobe PNG Format CC Prefs
                2013-11-05 02:24 - 2014-01-20 20:07 - 0000132 _____ () C:\Users\Defhawk\AppData\Roaming\Adobe PNG Format CS6 Prefs
                2014-06-20 19:04 - 2014-06-20 19:04 - 0000024 _____ () C:\Users\Defhawk\AppData\Roaming\temp.ini
                2014-01-24 21:49 - 2014-01-24 21:49 - 142848334 _____ () C:\Users\Defhawk\AppData\Local\ACCCx2_3_0_322.zip.aamdownload
                2014-01-24 21:49 - 2014-01-24 21:49 - 0001796 _____ () C:\Users\Defhawk\AppData\Local\ACCCx2_3_0_322.zip.aamdownload.aamd
                2014-01-20 16:57 - 2014-01-20 17:00 - 0001456 _____ () C:\Users\Defhawk\AppData\Local\Adobe Save for Web 13.0 Prefs
                2013-11-07 19:53 - 2013-11-07 19:53 - 0000001 _____ () C:\Users\Defhawk\AppData\Local\llftool.4.30.agreement
                2014-03-18 23:11 - 2014-06-24 23:08 - 0007607 _____ () C:\Users\Defhawk\AppData\Local\Resmon.ResmonCfg
                2013-11-03 12:51 - 2013-11-03 12:52 - 0009486 _____ () C:\Users\Defhawk\AppData\Local\WiDiSetupLog.20131103.125137.txt
                2013-11-04 01:00 - 2013-11-04 01:00 - 0010023 _____ () C:\Users\Defhawk\AppData\Local\WiDiSetupLog.20131104.010029.txt
                2014-03-14 18:49 - 2014-03-14 18:49 - 0000000 _____ () C:\ProgramData\DP45977C.lfl
                2014-10-02 21:45 - 2014-10-02 21:45 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
                 
                Files to move or delete:
                ====================
                C:\Users\Defhawk\120415backup.reg
                C:\Users\Defhawk\200714.reg
                 
                 
                Some content of TEMP:
                ====================
                C:\Users\Defhawk\AppData\Local\Temp\PidGenX.dll
                C:\Users\Defhawk\AppData\Local\Temp\Quarantine.exe
                C:\Users\Defhawk\AppData\Local\Temp\sqlite3.dll
                 
                 
                ==================== Bamital & volsnap Check =================
                 
                (There is no automatic fix for files that do not pass verification.)
                 
                C:\Windows\System32\winlogon.exe => File is digitally signed
                C:\Windows\System32\wininit.exe => File is digitally signed
                C:\Windows\SysWOW64\wininit.exe => File is digitally signed
                C:\Windows\explorer.exe => File is digitally signed
                C:\Windows\SysWOW64\explorer.exe => File is digitally signed
                C:\Windows\System32\svchost.exe => File is digitally signed
                C:\Windows\SysWOW64\svchost.exe => File is digitally signed
                C:\Windows\System32\services.exe => File is digitally signed
                C:\Windows\System32\User32.dll => File is digitally signed
                C:\Windows\SysWOW64\User32.dll => File is digitally signed
                C:\Windows\System32\userinit.exe => File is digitally signed
                C:\Windows\SysWOW64\userinit.exe => File is digitally signed
                C:\Windows\System32\rpcss.dll => File is digitally signed
                C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
                 
                 
                nointegritychecks: ==> Integrity Checks is disabled <===== ATTENTION!
                 
                 
                LastRegBack: 2015-04-14 06:20
                 
                ==================== End Of Log ============================

                 

                 

                Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-04-2015 04
                Ran by [removed] at 2015-04-16 22:45:40
                Running from C:\Users\[removed]\Desktop
                Boot Mode: Normal
                ==========================================================
                 
                 
                ==================== Security Center ========================
                 
                (If an entry is included in the fixlist, it will be removed.)
                 
                AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
                FW: ESET Personal firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
                 
                ==================== Installed Programs ======================
                 
                (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
                 
                µTorrent (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)
                Adobe Flash Player 17 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
                Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
                AIMP3 (HKLM-x32\…\AIMP3) (Version: v3.60.1483, 27.02.2015 - AIMP DevTeam)
                Akamai NetSession Interface (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Akamai) (Version:  - Akamai Technologies, Inc)
                ASUS Power4Gear Hybrid (HKLM\…\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.2 - ASUS)
                ASUS Screen Saver (HKLM\…\{0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2}) (Version: 1.0.1 - ASUS)
                Atheros Bluetooth Suite (64) (HKLM\…\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.150 - Atheros)
                Atheros Outlook Addin 2010 (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\BB108A893815B64BF41C4574C3324FB7371AA244) (Version: 1.0.0.0 - Microsoft)
                AutoCAD MEP 2015 Language Pack - English (Version: 7.7.49.0 - Autodesk) Hidden
                Canon iP2700 series Printer Driver (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2700_series) (Version:  - )
                Canon MP230 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP230_series) (Version: 1.00 - Canon Inc.)
                CCleaner (HKLM\…\CCleaner) (Version: 5.04 - Piriform)
                cFosSpeed v10.00 (HKLM\…\cFosSpeed) (Version: 10.00 - cFos Software GmbH, Bonn)
                CGS17_Setup_x64 (Version: 17.0 - Corel Corporation) Hidden
                Corel Graphics - Windows Shell Extension (HKLM\…\_{4AB916EE-ABA8-4079-9889-745798B6D809}) (Version: 17.0.0.491 - Corel Corporation)
                Corel Graphics - Windows Shell Extension (Version: 17.0.491 - Corel Corporation) Hidden
                Corel Graphics - Windows Shell Extension 32 Bit (Version: 17.0.491 - Corel Corporation) Hidden
                Corel Graphics - Windows Shell Extension 64 Bit (Version: 16.1.843 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Capture (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Common (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Connect (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Custom Data (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Draw (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - EN (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Filters (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - FontNav (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - IPM Content (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - PHOTO-PAINT (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Photozoom Plugin (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Redist (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Setup Files (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - VBA (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - VideoBrowser (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Writing Tools (x64) (Version: 17.0 -  Corel Corporation) Hidden
                CPUID CPU-Z 1.67.1 (HKLM\…\CPUID CPU-Z_is1) (Version:  - )
                CPUID HWMonitor Pro 1.16 (HKLM\…\CPUID HWMonitorPro_is1) (Version:  - )
                Cyborg Telkomsel Mobile Broadband (HKLM\…\Cyborg Telkomsel Mobile Broadband_is1) (Version:  - )
                Defraggler (HKLM\…\Defraggler) (Version: 2.18 - Piriform)
                Dropbox (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Dropbox) (Version: 3.4.3 - Dropbox, Inc.)
                ESET Smart Security (HKLM\…\{5E6F6CE8-1A35-4629-A550-376D4FF74F9B}) (Version: 7.0.317.4 - ESET, spol s r. o.)
                Google Chrome (HKLM-x32\…\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
                Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\…\{90F00673-A276-4A58-B675-B426D39D1E09}) (Version: 15.3.0.0398 - Intel Corporation)
                Intel® PROSet/Wireless WiFi Software (HKLM\…\{ECE5B218-A086-4E18-A362-D11181681457}) (Version: 15.03.1000.1637 - Intel Corporation)
                Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
                Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
                Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
                Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
                Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
                Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
                Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
                Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
                Nitro Pro 9 (HKLM\…\{8C386164-8794-4684-8921-2218199E1020}) (Version: 9.5.1.12 - Nitro)
                NVIDIA GeForce Experience 2.2.2 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)
                NVIDIA Graphics Driver 344.11 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.11 - NVIDIA Corporation)
                NVIDIA HD Audio Driver 1.3.32.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
                NVIDIA PhysX System Software 9.14.0702 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
                Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
                Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (Version: 11.0.51108 - Microsoft Corporation) Hidden
                Pro Evolution Soccer 2015 (HKLM-x32\…\UHJvRXZvbHV0aW9uU29jY2VyMjAxNQ==_is1) (Version: 1 - )
                Revo Uninstaller Pro 3.1.2 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)
                SanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19755 - Gemalto N.V.)
                Share64 (Version: 14.1.0.150 - Corel Corporation) Hidden
                SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden
                SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden
                TeraCopy 2.3 (HKLM\…\TeraCopy_is1) (Version:  - Code Sector)
                WD SmartWare (HKLM\…\{7AE43D6C-B3F1-448D-AD84-1CDC7AC6EBC7}) (Version: 2.4.6.3 - Western Digital Technologies, Inc.)
                Windows Driver Package - ASUS (ATP) Mouse  (01/10/2013 1.0.0.170) (HKLM\…\4A9DE1E9EBC800B7F01739D4DE7363EF6751BDF5) (Version: 01/10/2013 1.0.0.170 - ASUS)
                WinRAR 5.01 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
                Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (Version: 11.0.51108 - Microsoft Corporation) Hidden
                 
                ==================== Custom CLSID (selected items): ==========================
                 
                (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
                 
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                 
                ==================== Restore Points  =========================
                 
                15-04-2015 23:06:58 Revo Uninstaller Pro's restore point - Mirillis
                 
                 
                ==================== Hosts content: ==========================
                 
                (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
                 
                2009-07-14 09:34 - 2015-04-15 00:17 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts
                127.0.0.1       localhost
                 
                ==================== Scheduled Tasks (whitelisted) =============
                 
                (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
                 
                Task: {009BBECF-4D78-4564-8F1E-F0F759E7D98F} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
                Task: {028F0BEA-2EB0-4634-9C5A-C742BBEB76F4} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-04-16] (AsusTek)
                Task: {04CBF69D-AA8B-4CE9-B1B3-9BD20D0FE348} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)
                Task: {1296B0D2-42C3-4623-B9A1-4E90505D4046} - System32\Tasks\{D355A25F-ECA9-4762-B764-3F20E3109E6E} => Firefox.exe http://ui.skype.com/ui/0/6.5.0.158/en/go/help.faq.installer?LastError=1618
                Task: {1823FA51-0467-43BB-8134-F66123521DBB} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
                Task: {21969B38-4960-4D24-9C8E-D4FC7923C0E0} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-05-17] (ASUSTeK Computer Inc.)
                Task: {2323B362-6072-4667-9F6D-03380EA0698A} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
                Task: {23CB1AB5-EA73-4F6C-B3B1-AC2D73B58A47} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
                Task: {2446A911-78EE-45E8-B33B-A1A2AB6ECBE7} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
                Task: {24EA35E8-6BD4-44F2-A43A-04EF083397C4} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2014-07-21] (Nero AG)
                Task: {28650E00-EF3E-4295-9668-766B94B05A1B} - System32\Tasks\{5C4A58BA-8354-4A6C-B5BA-5563FB8E2CFF} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P7.3 Self-installer.exe" -d C:\Users\Defhawk\Downloads
                Task: {29A3E160-1D0F-4F1E-AC63-92F8DE11939C} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
                Task: {36B05A08-31B2-47D7-A8E7-487C2F605BAF} - System32\Tasks\cFosSpeedTR => C:\Program Files\cFosSpeed\CFSTR.exe [2014-04-30] (BB)
                Task: {3868AD23-3468-4E2D-869F-21217684C3C0} - System32\Tasks\{CB9212D3-94DB-4220-81D8-6F30C28ADE44} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.0 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDM
                Task: {3BB2B98A-6C8A-402A-97F7-435C3A506140} - System32\Tasks\{56885AD1-C12F-47A4-8D23-F8D89DE66A2E} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.4 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDM
                Task: {3C9E538E-F64A-4668-A4F9-63D0DE563553} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
                Task: {4643B852-23FB-409E-80AB-552789036A2A} - System32\Tasks\{3C92213F-4502-4D35-8B46-1A4E32F4BA49} => C:\Program Files (x86)\Nero\Nero 12\Nero ControlCenter\NCC.exe
                Task: {4D38440B-AF7B-4872-AA8F-FD15E3657395} - System32\Tasks\Process Lasso Core Engine Only => C:\Program Files\Process Lasso\processgovernor.exe [2014-09-22] (Bitsum LLC)
                Task: {59E0D626-4AD0-49A6-AA7D-F049B405F411} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-05-15] (ASUS)
                Task: {6A250B61-775C-4CE8-BB6C-C72F660B0A41} - System32\Tasks\ASUS InstantOn Config => C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [2012-09-24] (ASUS)
                Task: {7398C9F1-B7EE-485B-8232-331BDAD10A40} - System32\Tasks\{DFF6302E-B746-47CD-8BEE-51B20017A14D} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\Nero\Nero 12\Nero ControlCenter\NCC.exe"
                Task: {7830917E-F467-40BF-A4CC-28C5876001B1} - System32\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
                Task: {7A19FF40-4CB2-4564-B657-91566652CAD0} - System32\Tasks\Process Lasso Management Console (GUI) => C:\Program Files\Process Lasso\processlasso.exe [2014-09-22] (Bitsum LLC)
                Task: {7BC53F15-B01F-48BE-B2F2-98BD572CE49D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
                Task: {8ADC19A6-0DEF-4A99-95F0-47C63D9D103B} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-09-14] (ASUSTek Computer Inc.)
                Task: {91A3D505-22C3-4B90-B99B-C85C38D2E449} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-12] (Tweaking.com)
                Task: {A41D758C-732B-41C6-92AE-7DFC80D9AC0F} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2013-10-26] ()
                Task: {AAFF357B-3E9E-4420-A97D-4FCE425EB44A} - System32\Tasks\{A7CF406F-E389-4603-A99D-96DF4CF8E9F4} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.5 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDM
                Task: {B76D7C3A-0FC8-489A-8A0C-5ECB84B303D7} - System32\Tasks\smadav => C:\Program Files (x86)\Smadav\SMΔRTP.exe [2015-02-11] (Smadsoft)
                Task: {BD5CF776-01FC-4EDB-9D03-4CCC4F138181} - System32\Tasks\{6575FDB1-B2CA-4592-9E2A-89BF71F18C0E} => pcalua.exe -a C:\Users\Defhawk\AppData\Local\Temp\NeroInstallFiles\NERO20120813121238302\setup.exe -d C:\Users\Defhawk\AppData\Local\Temp\NeroInstallFiles\NERO20120813121238302
                Task: {C237C350-8497-403A-8D80-95FE0FD944D2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd)
                Task: {C5D6C676-CC24-4621-AD7B-9732B7B680F0} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.)
                Task: {CA07F7AC-6FE1-4499-98FE-154040652706} - System32\Tasks\{3681AD73-36EC-4764-AE5B-C1F3F90EA6EC} => pcalua.exe -a I:\INSTALL.EXE -d I:\
                Task: {CBDB467C-BCF1-4935-8BF8-067D5726872E} - \Microsoft Office 15 Sync Maintenance for Def-PC-Defhawk Def-PC No Task File <==== ATTENTION
                Task: {CBFCB5FC-B3D6-4376-9A81-66CD907AD0F2} - System32\Tasks\{CB8B5CF1-985B-4406-ADAD-51EFADEEF487} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P6.4 Self-installer.exe" -d C:\Users\Defhawk\Downloads
                Task: {CC088725-91F5-4E53-A0F8-03C294D4A9B7} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-01-09] (Realtek Semiconductor)
                Task: {CFCBA695-6977-4705-BD56-3C34EB5C2074} - System32\Tasks\AutoKMSCustom => C:\Windows\AutoKMS\AutoKMS.exe
                Task: {D4E9AFF7-C3F6-4145-BD58-3C00BE01063A} - System32\Tasks\Driver Booster SkipUAC (Defhawk) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
                Task: {D74126FC-77A0-46A8-8C0D-C932B95015EB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
                Task: {DC3EA95E-CB26-4403-8692-EFCCE0BBFB71} - System32\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
                Task: {E9B0D633-DE94-4608-9BAE-16CF90AD732F} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
                Task: {F26FA818-8742-4E5E-A115-0AE9166E1AF6} - System32\Tasks\{A4D3F862-ECA0-4659-A604-FA6A3813E901} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P7.1 Self-installer.exe" -d C:\Users\Defhawk\Downloads
                Task: {F45E28EE-2421-428B-B21B-C618B93C8E09} - System32\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
                Task: {F4D0D822-F7C1-4193-A131-9CF4CE2E2BFA} - System32\Tasks\{1744B18A-8492-42F2-9C76-0E8897CEDBA8} => pcalua.exe -a "C:\Program Files (x86)\Xilisoft\Video Converter Ultimate\Uninstall.exe" -d "C:\Program Files (x86)\Xilisoft\Video Converter Ultimate"
                Task: {FA724455-DB75-41AB-B4C5-FE1150360F34} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
                Task: {FBE9499D-F4DD-437E-A393-C21B10C9B005} - System32\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
                Task: {FD95CA08-B3DD-4638-81DA-01076FFF67CE} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
                Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
                Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                 
                ==================== Loaded Modules (whitelisted) ==============
                 
                2012-10-01 20:36 - 2012-10-01 20:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
                2013-11-17 00:47 - 2012-01-20 14:55 - 00678400 _____ () C:\Program Files\TeraCopy\TeraCopyExt64.dll
                2013-11-24 23:57 - 2012-03-28 19:49 - 00140456 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
                2013-11-03 12:29 - 2014-09-14 04:53 - 00116880 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
                2012-10-01 20:36 - 2012-10-01 20:36 - 01286272 _____ () C:\Program Files\Microsoft Office\Office15\PPRESOURCES.DLL
                2012-10-01 18:56 - 2012-10-01 18:56 - 00240256 _____ () C:\Program Files\Microsoft Office\Office15\IEAWSDC.DLL
                2013-11-03 11:05 - 2014-09-14 06:48 - 00012104 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
                2012-10-01 20:37 - 2012-10-01 20:37 - 06522480 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
                2012-03-15 10:48 - 2012-03-15 10:48 - 00221184 _____ () C:\Program Files (x86)\ASUS\VirtualCamera\virtualCamera.ax
                2015-04-15 21:46 - 2015-04-14 04:55 - 01252680 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\libglesv2.dll
                2015-04-15 21:46 - 2015-04-14 04:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\libegl.dll
                2015-04-15 22:08 - 2015-04-15 22:08 - 00218112 _____ () C:\Program Files\AIMP3\System\libsoxr.dll
                2015-04-15 22:08 - 2015-04-15 22:08 - 00467968 _____ () C:\Program Files\AIMP3\System\Encoders\libFLAC.dll
                2015-04-15 22:08 - 2015-04-15 22:08 - 01733120 _____ () C:\Program Files\AIMP3\System\Encoders\aimp_libvorbis.dll
                2015-04-15 22:08 - 2015-04-15 22:08 - 00160840 _____ () C:\Program Files\AIMP3\Plugins\aimp_cdda\aimp_cdda.dll
                2015-04-15 22:08 - 2015-04-15 22:08 - 00159232 _____ () C:\Program Files\AIMP3\Plugins\aimp_sacd\libsacd.dll
                2015-04-15 22:08 - 2015-04-15 22:08 - 00026624 _____ () C:\Program Files\AIMP3\Plugins\Aorta\Aorta.dll
                2015-04-15 22:08 - 2015-04-15 22:08 - 00237568 _____ () C:\Program Files\AIMP3\Plugins\OptimFROG\OptimFROG.dll
                2015-04-15 22:08 - 2015-04-15 22:08 - 00152648 _____ () C:\Program Files\AIMP3\Plugins\PandemicAnalogMeter\PandemicAnalogMeter.dll
                 
                ==================== Alternate Data Streams (whitelisted) =========
                 
                (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
                 
                AlternateDataStreams: C:\Windows:nlsPreferences
                AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51
                 
                ==================== Safe Mode (whitelisted) ===================
                 
                (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
                 
                 
                ==================== EXE Association (whitelisted) ===============
                 
                (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
                 
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION!
                 
                ==================== Other Areas ============================
                 
                (Currently there is no automatic fix for this section.)
                 
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
                DNS Servers: 192.168.43.1
                 
                ==================== MSCONFIG/TASK MANAGER disabled items ==
                 
                (Currently there is no automatic fix for this section.)
                 
                MSCONFIG\Services: eventlog => 2
                MSCONFIG\Services: Wecsvc => 3
                MSCONFIG\startupreg: EPSON_UD_START => 
                MSCONFIG\startupreg: Lync => 
                 
                ==================== Accounts: =============================
                 
                Administrator (S-1-5-21-3901189400-636743289-3933302658-500 - Administrator - Disabled)
                Defhawk (S-1-5-21-3901189400-636743289-3933302658-1000 - Administrator - Enabled) => C:\Users\Defhawk
                Guest (S-1-5-21-3901189400-636743289-3933302658-501 - Limited - Disabled)
                HomeGroupUser$ (S-1-5-21-3901189400-636743289-3933302658-1002 - Limited - Enabled)
                 
                ==================== Faulty Device Manager Devices =============
                 
                 
                ==================== Event log errors: =========================
                 
                Application errors:
                ==================
                Error: (04/16/2015 10:33:41 PM) (Source: MsiInstaller) (EventID: 11316) (User: Def-PC)
                Description: Product: Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit – Error 1316. The specified account already exists.
                 
                Error: (04/16/2015 10:15:06 PM) (Source: MsiInstaller) (EventID: 11706) (User: Def-PC)
                Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1706.No valid source could be found for product CorelDRAW Graphics Suite X7 - Draw (x64).  The Windows Installer cannot continue.
                 
                Error: (04/16/2015 10:08:48 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:34:48Z. Error Code: 0x80041321.
                 
                Error: (04/16/2015 09:55:23 PM) (Source: Application Error) (EventID: 1000) (User: )
                Description: Faulting application name: NitroPDF.exe, version: 9.5.1.12, time stamp: 0x537e324c
                Faulting module name: NitroPDF.exe, version: 9.5.1.12, time stamp: 0x537e324c
                Exception code: 0xc0000005
                Fault offset: 0x00000000000d2e19
                Faulting process id: 0xbf4
                Faulting application start time: 0xNitroPDF.exe0
                Faulting application path: NitroPDF.exe1
                Faulting module path: NitroPDF.exe2
                Report Id: NitroPDF.exe3
                 
                Error: (04/16/2015 09:15:07 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:35:07Z. Error Code: 0x80041321.
                 
                Error: (04/16/2015 08:39:14 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:34:14Z. Error Code: 0x80041321.
                 
                Error: (04/16/2015 08:20:32 PM) (Source: MsiInstaller) (EventID: 11706) (User: Def-PC)
                Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1706.No valid source could be found for product CorelDRAW Graphics Suite X7 - Draw (x64).  The Windows Installer cannot continue.
                 
                Error: (04/16/2015 08:19:22 PM) (Source: MsiInstaller) (EventID: 11704) (User: Def-PC)
                Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1704.An installation for Nero Update is currently suspended.  You must undo the changes made by that installation to continue.  Do you want to undo those changes?
                 
                Error: (04/16/2015 07:39:59 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:34:59Z. Error Code: 0x80041321.
                 
                Error: (04/16/2015 06:56:46 PM) (Source: Application Error) (EventID: 1000) (User: )
                Description: Faulting application name: PES2015.exe, version: 1.0.0.0, time stamp: 0x5450aba2
                Faulting module name: PES2015.exe, version: 1.0.0.0, time stamp: 0x5450aba2
                Exception code: 0xc0000005
                Fault offset: 0x0132b0b6
                Faulting process id: 0x148
                Faulting application start time: 0xPES2015.exe0
                Faulting application path: PES2015.exe1
                Faulting module path: PES2015.exe2
                Report Id: PES2015.exe3
                 
                 
                System errors:
                =============
                Error: (04/16/2015 09:18:47 PM) (Source: DCOM) (EventID: 10001) (User: )
                Description: "C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe" -Embedding193{5DC4F9AD-3A2B-4DF4-AC39-3FF5A19FCF4C}
                 
                Error: (04/16/2015 07:40:55 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
                Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Software Protection service, but this action failed with the following error: 
                %%1056
                 
                Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
                Description: The Windows Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
                 
                Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
                Description: The Nero Update service terminated unexpectedly.  It has done this 1 time(s).
                 
                Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
                Description: The Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
                 
                Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
                Description: The Intel® Centrino® Wireless Bluetooth® + High Speed Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
                 
                Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
                Description: The Intel(R) Integrated Clock Controller Service - Intel(R) ICCS service terminated unexpectedly.  It has done this 1 time(s).
                 
                Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
                Description: The WD Backup service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.
                 
                Error: (04/16/2015 07:38:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
                Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
                 
                Error: (04/16/2015 07:38:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
                Description: The WD Drive Manager service terminated unexpectedly.  It has done this 1 time(s).
                 
                 
                Microsoft Office Sessions:
                =========================
                Error: (04/16/2015 10:33:41 PM) (Source: MsiInstaller) (EventID: 11316) (User: Def-PC)
                Description: Product: Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit – Error 1316. The specified account already exists.
                (NULL)(NULL)(NULL)(NULL)(NULL)
                 
                Error: (04/16/2015 10:15:06 PM) (Source: MsiInstaller) (EventID: 11706) (User: Def-PC)
                Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1706.No valid source could be found for product CorelDRAW Graphics Suite X7 - Draw (x64).  The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)
                 
                Error: (04/16/2015 10:08:48 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: 0x800413212015-05-15T16:34:48Z
                 
                Error: (04/16/2015 09:55:23 PM) (Source: Application Error) (EventID: 1000) (User: )
                Description: NitroPDF.exe9.5.1.12537e324cNitroPDF.exe9.5.1.12537e324cc000000500000000000d2e19bf401d078554ddc427aC:\PROGRA~1\Nitro\PRO9~1\NitroPDF.exeC:\PROGRA~1\Nitro\PRO9~1\NitroPDF.exe9b6834c3-e448-11e4-848f-2cd05ae83598
                 
                Error: (04/16/2015 09:15:07 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: 0x800413212015-05-15T16:35:07Z
                 
                Error: (04/16/2015 08:39:14 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: 0x800413212015-05-15T16:34:14Z
                 
                Error: (04/16/2015 08:20:32 PM) (Source: MsiInstaller) (EventID: 11706) (User: Def-PC)
                Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1706.No valid source could be found for product CorelDRAW Graphics Suite X7 - Draw (x64).  The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)
                 
                Error: (04/16/2015 08:19:22 PM) (Source: MsiInstaller) (EventID: 11704) (User: Def-PC)
                Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1704.An installation for Nero Update is currently suspended.  You must undo the changes made by that installation to continue.  Do you want to undo those changes?(NULL)(NULL)(NULL)(NULL)(NULL)
                 
                Error: (04/16/2015 07:39:59 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: 0x800413212015-05-15T16:34:59Z
                 
                Error: (04/16/2015 06:56:46 PM) (Source: Application Error) (EventID: 1000) (User: )
                Description: PES2015.exe1.0.0.05450aba2PES2015.exe1.0.0.05450aba2c00000050132b0b614801d0783910ac1c74C:\Program Files (x86)\Pro Evolution Soccer 2015\PES2015.exeC:\Program Files (x86)\Pro Evolution Soccer 2015\PES2015.exea7b80b74-e42f-11e4-8f32-74d02b7463ad
                 
                 
                CodeIntegrity Errors:
                ===================================
                  Date: 2015-04-12 18:17:22.761
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                  Date: 2015-04-12 18:17:22.714
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                  Date: 2015-04-12 18:17:22.683
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                  Date: 2015-04-12 18:17:22.636
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                  Date: 2015-04-12 18:06:22.402
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                  Date: 2015-04-12 18:06:22.356
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                 
                ==================== Memory info =========================== 
                 
                Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHz
                Percentage of memory in use: 62%
                Total physical RAM: 3981.59 MB
                Available physical RAM: 1480.73 MB
                Total Pagefile: 7961.37 MB
                Available Pagefile: 5125.6 MB
                Total Virtual: 8192 MB
                Available Virtual: 8191.84 MB
                 
                ==================== Drives ================================
                 
                Drive c: () (Fixed) (Total:202.89 GB) (Free:44.29 GB) NTFS
                Drive d: (Hitam) (Fixed) (Total:202.67 GB) (Free:54.09 GB) NTFS
                Drive e: (Putih) (Fixed) (Total:60.1 GB) (Free:23.73 GB) NTFS
                Drive h: (Defrino) (Fixed) (Total:802.48 GB) (Free:178.88 GB) NTFS
                Drive k: (Gionaldo) (Fixed) (Total:129 GB) (Free:117.51 GB) NTFS
                 
                ==================== MBR & Partition Table ==================
                 
                ========================================================
                Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 16E7DD24)
                Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
                Partition 2: (Not Active) - (Size=202.9 GB) - (Type=07 NTFS)
                Partition 3: (Not Active) - (Size=202.7 GB) - (Type=07 NTFS)
                Partition 4: (Not Active) - (Size=60.1 GB) - (Type=07 NTFS)
                 
                ========================================================
                Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 59DD4884)
                Partition 1: (Not Active) - (Size=802.5 GB) - (Type=07 NTFS)
                Partition 2: (Not Active) - (Size=129 GB) - (Type=07 NTFS)
                 
                ==================== End Of Log ============================

                 

                 

                Download MiniToolBox and save it to your desktop,  right click on it and select RUN AS ADMINISTRATOR
                 
                Checkmark the following boxes:
                •  
                • Flush DNS 
                • Reset IE Proxy Settings 
                • Reset FF Proxy Settings
                 
                 
                Click Go and post the result (Result.txt) that pops up. A copy of result.txt will be saved in the same directory the tool is run.
                 
                 
                 
                I am attaching a FIXLIST file, you need to download it to your desktop where you now have FRST64 or the fix wont work, use your mouse to drag FIXLIST right next to FRST64, either above or below it but not right on top of it, after its downloaded open up FRST64 and click on FIX (Not Scan) it wont take long, after your computer reboots you will find a FIXLOG file on your desktop, post it please and let me know how your system is behaving now

                Attachments:

                Hi Ken, sorry for late post. 

                Here are the logs :

                 

                MiniToolBox by Farbar  Version: 14-04-2015
                Ran by [removed] (administrator) on 17-04-2015 at 20:09:47
                Running from "C:\Users\Defhawk\Desktop"
                Microsoft Windows 7 Ultimate  Service Pack 1 (X64)
                Model: K46CB Manufacturer: ASUSTeK COMPUTER INC.
                Boot Mode: Normal
                ***************************************************************************
                 
                ========================= Flush DNS: ===================================
                 
                Windows IP Configuration
                 
                Successfully flushed the DNS Resolver Cache.
                 
                "Reset IE Proxy Settings": IE Proxy Settings were reset.
                 
                "Reset FF Proxy Settings": Firefox Proxy settings were reset.
                 
                 
                **** End of log ****

                 

                 

                Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-04-2015 04
                Ran by [removed] at 2015-04-17 20:11:19 Run:1
                Running from C:\Users\[removed]\Desktop
                [removed]
                Boot Mode: Normal
                ==============================================
                 
                Content of fixlist:
                *****************
                Start
                CreateRestorePoint: 
                CloseProcesses:
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [uTorrent] => C:\Users\Defhawk\AppData\Roaming\uTorrent\uTorrent.exe [1378304 2015-01-23] (BitTorrent Inc.)
                HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
                SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
                SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
                SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
                FF Extension: No Name - C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\extensions\[removed] [Not Found]
                2015-04-14 00:45 - 2015-04-14 00:45 - 00000000 ____D () C:\Users\Default\AppData\Roaming\IObit
                2015-04-14 00:45 - 2015-04-14 00:45 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\IObit
                2015-03-23 22:46 - 2015-01-10 15:32 - 00128288 _____ (IObit) C:\Windows\system32\IObitSmartDefragExtension.dll
                2015-03-23 22:46 - 2014-06-04 15:17 - 00034080 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe
                2015-03-23 22:46 - 2014-06-04 15:17 - 00021184 _____ (IObit) C:\Windows\system32\Drivers\SmartDefragDriver.sys
                2015-04-16 19:35 - 2013-11-04 19:58 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\uTorrent
                (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
                C:\Program Files (x86)\IObit
                Task: {0D9DE9B0-CAA3-4E98-A370-E4B4E42DA95A} - System32\Tasks\Uninstaller_SkipUac_Defhawk => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-11-04] (IObit)
                Task: {2323B362-6072-4667-9F6D-03380EA0698A} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-11-04] (IObit)
                Task: {3B22EFFE-7D8F-4879-A2C8-14794A75819D} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2014-12-17] (IObit)
                Task: {49A25C2A-9F8D-4CA2-A1BE-39B1F43EB723} - System32\Tasks\ASC8_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe [2014-11-07] (IObit)
                Task: {6310B5CD-0E05-4887-AF03-74012DE53E7C} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2014-12-09] (IObit)
                Task: C:\Windows\Tasks\Uninstaller_SkipUac_Defhawk.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
                CMD: ipconfig /flushdns
                Hosts:
                EmptyTemp:
                End
                 
                 
                 
                 
                 
                 
                 
                 
                 
                 
                *****************
                 
                Restore point was successfully created.
                Processes closed successfully.
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => value deleted successfully.
                "HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
                "HKU\S-1-5-21-3901189400-636743289-3933302658-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
                HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
                HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
                HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
                C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\extensions\[removed] not found.
                C:\Users\Default\AppData\Roaming\IObit => Moved successfully.
                "C:\Users\Default User\AppData\Roaming\IObit" => File/Directory not found.
                C:\Windows\system32\IObitSmartDefragExtension.dll => Moved successfully.
                C:\Windows\system32\SmartDefragBootTime.exe => Moved successfully.
                C:\Windows\system32\Drivers\SmartDefragDriver.sys => Moved successfully.
                C:\Users\Defhawk\AppData\Roaming\uTorrent => Moved successfully.
                C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe => No running process found
                "C:\Program Files (x86)\IObit" => File/Directory not found.
                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D9DE9B0-CAA3-4E98-A370-E4B4E42DA95A} => Key not found. 
                C:\Windows\System32\Tasks\Uninstaller_SkipUac_Defhawk not found.
                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Defhawk => Key not found. 
                "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2323B362-6072-4667-9F6D-03380EA0698A}" => Key deleted successfully.
                "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2323B362-6072-4667-9F6D-03380EA0698A}" => Key deleted successfully.
                C:\Windows\System32\Tasks\Uninstaller_SkipUac_Administrator => Moved successfully.
                "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Administrator" => Key deleted successfully.
                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B22EFFE-7D8F-4879-A2C8-14794A75819D} => Key not found. 
                C:\Windows\System32\Tasks\Driver Booster Scan not found.
                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scan => Key not found. 
                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{49A25C2A-9F8D-4CA2-A1BE-39B1F43EB723} => Key not found. 
                C:\Windows\System32\Tasks\ASC8_PerformanceMonitor not found.
                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASC8_PerformanceMonitor => Key not found. 
                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6310B5CD-0E05-4887-AF03-74012DE53E7C} => Key not found. 
                C:\Windows\System32\Tasks\Driver Booster Update not found.
                HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Update => Key not found. 
                C:\Windows\Tasks\Uninstaller_SkipUac_Defhawk.job not found.
                 
                =========  ipconfig /flushdns =========
                 
                 
                Windows IP Configuration
                 
                Successfully flushed the DNS Resolver Cache.
                 
                ========= End of CMD: =========
                 
                C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
                Hosts was reset successfully.
                EmptyTemp: => Removed 165.8 MB temporary data.
                 
                 
                The system needed a reboot. 
                 
                ==== End of Fixlog 20:12:29 ====

                 

                 

                Thank you for helping me out.

                - Deff

                Great, no need to quote the logs you post, it makes them look smaller and these old eyes need all the help they can get :)

                 

                Go ahead and open FRST, checkmark Additions , run a new scan and post the logs and let me take one final look

                So sorry. Just want to make you easier to take a look. 
                Well, here they are :
                 

                Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015 04
                Ran by [removed] (administrator) on DEF-PC on 17-04-2015 20:59:22
                Running from C:\Users\[removed]\Desktop
                [removed]
                Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
                Internet Explorer Version 11 (Default browser: IE)
                Boot Mode: Normal
                Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
                 
                ==================== Processes (Whitelisted) =================
                 
                (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
                 
                (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
                (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
                (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
                (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\AsLdrSrv.exe
                (ASUS) C:\Program Files (x86)\Asus\ATK Package\ATKGFNEX\GFNEXSrv.exe
                (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\HControl.exe
                (ASUS) C:\Program Files (x86)\Asus\ASUS InstantOn\InsOnSrv.exe
                (cFos Software GmbH) C:\Program Files\cFosSpeed\spd.exe
                (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
                (ASUSTeK Computer Inc.) C:\Program Files (x86)\Asus\Wireless Console 3\wcourier.exe
                (Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
                (Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
                (Smadsoft) C:\Program Files (x86)\SMADAV\SMΔRTP.exe
                (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\USBChargerPlus\USBChargerPlus.exe
                (ASUS) C:\Program Files (x86)\Asus\ASUS InstantOn\InsOnWMI.exe
                (Bitsum LLC) C:\Program Files\Process Lasso\ProcessLasso.exe
                (ASUS) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\ATKOSD.exe
                (ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
                (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\KBFiltr.exe
                (ASUS) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\WDC.exe
                (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
                (Bitsum LLC) C:\Program Files\Process Lasso\ProcessGovernor.exe
                (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
                () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
                (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
                (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
                (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
                (cFos Software GmbH) C:\Program Files\cFosSpeed\cfosspeed.exe
                (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
                (Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe
                () C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe
                (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
                (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
                (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
                (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
                (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
                (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
                (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
                (arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
                (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
                (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
                (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
                (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\ATK Package\ATKOSD2\ATKOSD2.exe
                (Intel Corporation) C:\Windows\System32\igfxtray.exe
                (Intel Corporation) C:\Windows\System32\hkcmd.exe
                (Intel Corporation) C:\Windows\System32\igfxpers.exe
                (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
                (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
                (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
                (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
                (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
                (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
                (Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
                (BitTorrent Inc.) C:\FRST\Quarantine\C\Users\Defhawk\AppData\Roaming\uTorrent\uTorrent.exe
                () C:\Program Files\Cyborg Telkomsel Mobile Broadband\App.exe
                (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
                (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
                (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
                (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                (EJIE Technology) C:\Program Files (x86)\Clover\clover.exe
                (Microsoft Corporation) C:\Windows\System32\msiexec.exe
                 
                 
                ==================== Registry (Whitelisted) ==================
                 
                (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
                 
                HKLM\…\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\btvstack.exe [1023104 2012-08-10] (Atheros Commnucations)
                HKLM\…\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\athbttray.exe [801920 2012-08-10] (Atheros Commnucations)
                HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585928 2015-01-16] (NVIDIA Corporation)
                HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [479232 2012-12-15] (Adobe Systems Incorporated)
                HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
                HKLM\…\Run: [cFosSpeed] => C:\Program Files\cFosSpeed\cFosSpeed.exe [1591744 2015-01-19] (cFos Software GmbH)
                HKLM\…\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595336 2014-10-01] (ESET)
                Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [GoogleChromeAutoLaunch_A9AC9B5C6255D671A633D32EA1A22B00] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [812872 2015-04-14] (Google Inc.)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3890768 2015-04-13] (Tonec Inc.)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7451928 2015-03-13] (Piriform Ltd)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673088 2013-03-14] (Disc Soft Ltd)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [uTorrent] => C:\FRST\Quarantine\C\Users\Defhawk\AppData\Roaming\uTorrent\uTorrent.exe [1378304 2015-01-23] (BitTorrent Inc.)
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Policies\Explorer: [] 
                AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174856 2014-09-14] (NVIDIA Corporation)
                AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156840 2014-09-14] (NVIDIA Corporation)
                ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
                ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
                BootExecute: RegistryDefragBootTime.exeautocheck autochk * 
                 
                ==================== Internet (Whitelisted) ====================
                 
                (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
                 
                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
                HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
                HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
                HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
                HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
                SearchScopes: HKU\S-1-5-21-3901189400-636743289-3933302658-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear
                BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-02-21] (Internet Download Manager, Tonec Inc.)
                BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll No File
                BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
                BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
                BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
                BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
                BHO: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> C:\Program Files (x86)\Clover\TabHelper64.dll [2014-01-23] (EJIE Technology)
                BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-02-21] (Internet Download Manager, Tonec Inc.)
                BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
                BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
                BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
                Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll [2015-02-20] (Microsoft Corporation)
                Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll [2015-02-20] (Microsoft Corporation)
                Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
                Tcpip\..\Interfaces\{16069F89-842A-43F8-BE08-AAEEDB44675E}: [NameServer] 114.5.5.5 114.5.5.77
                Tcpip\..\Interfaces\{2E385CBD-E7DB-4717-B418-9B593B66AADC}: [NameServer] 8.26.56.26,8.20.247.20
                Tcpip\..\Interfaces\{2EE81293-715E-4B59-B7EF-634063A4DE30}: [NameServer] 8.26.56.26,8.20.247.20
                 
                FireFox:
                ========
                FF ProfilePath: C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default
                FF NetworkProxy: "gopher", ""
                FF NetworkProxy: "gopher_port", 0
                FF NetworkProxy: "share_proxy_settings", true
                FF NetworkProxy: "type", 0
                FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
                FF Plugin: @microsoft.com/GENUINE -> disabled No File
                FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
                FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-12-15] (Adobe Systems)
                FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
                FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll [2015-01-09] (Adobe Systems, Inc.)
                FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
                FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-08] (Google)
                FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)
                FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
                FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
                FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
                FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)
                FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2014-05-22] (Nitro PDF)
                FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
                FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
                FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
                FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
                FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-12-15] (Adobe Systems)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2014-01-20] (Apple Inc.)
                FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2014-01-20] (Apple Inc.)
                FF Extension: Auto Hide IP - C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\Extensions\[removed] [2014-07-20]
                FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-15]
                FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-15]
                FF HKLM\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
                FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
                FF HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5
                FF Extension: IDM CC - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5 [2015-04-13]
                FF HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5
                FF Extension: No Name - C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\extensions\[removed] [Not Found]
                 
                Chrome: 
                =======
                CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.703\_platform_specific\win_x86\widevinecdmadapter.dll No File
                CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\PepperFlash\pepflashplayer.dll ()
                CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
                CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\internal-nacl-plugin No File
                CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\pdf.dll No File
                CHR Plugin: (Internet Download Manager Plugin) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn\6.21.16_0\IDMGCExt.dll No File
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
                CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
                CHR Plugin: (Nero Kwik Media Helper) - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
                CHR Plugin: (Microsoft Office 2013) - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
                CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
                CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
                CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
                CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
                CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
                CHR Plugin: (Microsoft Office 2013) - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
                CHR Plugin: (Nitro PDF plugin for Firefox and Chrome) - C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF)
                CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
                CHR Profile: C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default
                CHR Extension: (Google Translate) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2014-10-23]
                CHR Extension: (Xmarks Bookmark Sync) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajpgkpeckebdhofmmjfgcjjiiejpodla [2013-12-16]
                CHR Extension: (From Dust) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\anelkojiepicmcldgnmkplocifmegpfj [2013-12-16]
                CHR Extension: (Google Docs) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-20]
                CHR Extension: (Google Drive) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-20]
                CHR Extension: (WOT) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2013-11-20]
                CHR Extension: (YouTube) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-20]
                CHR Extension: (Adblock Plus) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-20]
                CHR Extension: (Google Search) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-20]
                CHR Extension: (Tampermonkey) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-12-16]
                CHR Extension: (Photo Zoom for Facebook) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2013-11-20]
                CHR Extension: (AdBlock) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-11-20]
                CHR Extension: (Bookmark Manager) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-16]
                CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-07]
                CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-02]
                CHR Extension: (IDM Integration Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-04-13]
                CHR Extension: (Google Wallet) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-20]
                CHR Extension: (Checker Plus for Gmail™) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2013-11-20]
                CHR Extension: (Gmail) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-20]
                CHR HKLM\…\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]
                CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]
                CHR HKU\S-1-5-21-3901189400-636743289-3933302658-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
                CHR HKLM-x32\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]
                 
                ==================== Services (Whitelisted) =================
                 
                (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
                 
                R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
                S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [216906 2012-08-10] (Atheros Commnucations) [File not signed]
                S4 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [32768 2014-02-07] (Autodesk, Inc.) [File not signed]
                S4 CDROM_Detect; C:\Program Files\Cyborg Telkomsel Mobile Broadband\WCDMA_Eject.exe [325632 2013-06-08] () [File not signed]
                R2 cFosSpeedS; C:\Program Files\cFosSpeed\spd.exe [500672 2015-01-19] (cFos Software GmbH)
                R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [117704 2015-01-09] (Intel Corporation)
                R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116680 2015-01-09] (Intel Corporation)
                R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1349576 2014-10-01] (ESET)
                S4 EMP_UDSA; C:\Program Files (x86)\EPSON Projector\Epson USB Display V1.5\EMP_UDSA.exe [98304 2011-01-06] (SEIKO EPSON CORPORATION) [File not signed]
                S4 FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [1362426 2014-10-02] (Flexera Software LLC) [File not signed]
                R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2015-01-16] (NVIDIA Corporation)
                S2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116736 2013-11-20] (Google Inc.) [File not signed]
                S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116736 2013-11-20] (Google Inc.) [File not signed]
                S3 gusvc; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [136192 2011-05-10] (Google) [File not signed]
                R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
                R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
                R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
                S3 MozillaMaintenance; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [115200 2014-12-15] (Mozilla Foundation) [File not signed]
                S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [278010 2012-08-23] () [File not signed]
                R2 NitroDriverReadSpool9; C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe [230920 2014-05-22] (Nitro PDF Software)
                R2 NitroUpdateService; C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe [417800 2014-05-22] ()
                R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706312 2015-01-16] (NVIDIA Corporation)
                S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21838866 2015-01-16] (NVIDIA Corporation) [File not signed]
                S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1903616 2014-12-18] (Electronic Arts) [File not signed]
                S4 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-11-26] ()
                R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2013-09-13] (arvato digital services llc)
                S4 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275264 2013-10-09] (Skype Technologies S.A.) [File not signed]
                R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2014-12-02] (Western Digital Technologies, Inc.)
                R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [296312 2014-06-02] (Western Digital Technologies, Inc.)
                R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
                S4 ZAtheros Bt&Wlan; Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [327680 2012-08-10] (Atheros) [File not signed]
                S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3347962 2012-08-23] (Intel® Corporation) [File not signed]
                 
                ==================== Drivers (Whitelisted) ====================
                 
                (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
                 
                S3 ampa; C:\Windows\system32\ampa.sys [15288 2011-12-26] () [File not signed]
                S3 ampa; C:\Windows\SysWOW64\ampa.sys [12728 2011-12-26] () [File not signed]
                R3 ATP; C:\Windows\System32\DRIVERS\AsusTP.sys [70416 2015-01-09] (ASUS Corporation)
                R3 CT_QUALCOMM_U_drv; C:\Windows\System32\DRIVERS\CT_QUALCOMM_U_drv.sys [118016 2009-04-27] (QUALCOMM Incorporated)
                R3 DptfDevDram; C:\Windows\System32\DRIVERS\DptfDevDram.sys [145640 2015-01-09] (Intel Corporation)
                R3 DptfDevFan; C:\Windows\System32\DRIVERS\DptfDevFan.sys [50640 2015-01-09] (Intel Corporation)
                R3 DptfDevGen; C:\Windows\System32\DRIVERS\DptfDevGen.sys [78504 2015-01-09] (Intel Corporation)
                R3 DptfDevProc; C:\Windows\System32\DRIVERS\DptfDevProc.sys [289744 2015-01-09] (Intel Corporation)
                R3 DptfManager; C:\Windows\System32\DRIVERS\DptfManager.sys [494296 2015-01-09] (Intel Corporation)
                R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-11-03] (DT Soft Ltd)
                R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-08-18] (ESET)
                U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [241368 2014-08-18] (ESET)
                R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-08-18] (ESET)
                R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [30752 2014-04-07] (EldoS Corporation)
                R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [222280 2014-08-18] (ESET)
                R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44632 2014-08-18] (ESET)
                R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [63160 2014-09-18] (ESET)
                R3 eppvad_simple; C:\Windows\System32\drivers\EMP_UDAU.sys [23040 2011-01-06] (SEIKO EPSON CORPORATION)
                S3 esgiguard; C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [14872 2014-01-07] ()
                R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-01-03] (REALiX™)
                R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-12-18] (Intel Corporation)
                R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [17280 2012-08-05] ( )
                R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
                R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-04-17] (Malwarebytes Corporation)
                R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
                R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [129312 2015-03-23] (Intel Corporation)
                S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19784 2015-01-16] (NVIDIA Corporation)
                R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
                S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
                S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
                S3 REN2CAP_DRIVER; C:\Windows\System32\drivers\ren2cap.sys [46728 2011-11-07] ()
                S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [74240 2015-01-09] (Research In Motion Limited)
                S3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [455240 2013-03-05] (RTS Corporation)
                R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-12-09] (Duplex Secure Ltd.)
                U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-04-12] ()
                U3 aaljikum; C:\Windows\System32\Drivers\aaljikum.sys [0 ] (Intel Corporation) <==== ATTENTION (zero size file/folder)
                S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X]
                S3 catchme; \??\C:\Worksnow\catchme.sys [X]
                S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X]
                S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
                S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
                S3 PCFApiUtil; \??\C:\Program Files (x86)\Baidu Security\PC Faster\PCFApiUtil64.sys [X]
                S0 SmartDefragDriver; System32\Drivers\SmartDefragDriver.sys [X]
                S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
                S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
                S3 VGPU; System32\drivers\rdvgkmd.sys [X]
                S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
                S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
                 
                ==================== NetSvcs (Whitelisted) ===================
                 
                (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
                 
                 
                ==================== One Month Created Files and Folders ========
                 
                (If an entry is included in the fixlist, the file\folder will be moved.)
                 
                2015-04-17 20:09 - 2015-04-17 20:10 - 00000647 _____ () C:\Users\Defhawk\Desktop\Result.txt
                2015-04-17 20:06 - 2015-04-17 20:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
                2015-04-17 20:06 - 2015-04-17 20:06 - 00000000 ____D () C:\ProgramData\ESET
                2015-04-17 20:06 - 2015-04-17 20:06 - 00000000 ____D () C:\Program Files\ESET
                2015-04-17 19:58 - 2015-04-17 19:58 - 00002677 _____ () C:\Users\Defhawk\Downloads\Fixlist.txt
                2015-04-17 19:58 - 2015-04-17 19:56 - 00402944 _____ (Farbar) C:\Users\Defhawk\Desktop\MiniToolBox.exe
                2015-04-16 21:13 - 2015-04-16 21:13 - 00000000 ____D () C:\Users\Defhawk\Desktop\FRST-OlderVersion
                2015-04-16 20:24 - 2015-04-16 20:24 - 00001079 _____ () C:\Users\Defhawk\Desktop\Mbam.txt
                2015-04-16 20:24 - 2015-04-16 19:32 - 00001771 _____ () C:\Users\Defhawk\Desktop\AdwCleaner[S0].txt
                2015-04-16 19:42 - 2015-04-16 19:42 - 00001267 _____ () C:\Users\Defhawk\Desktop\JRT.txt
                2015-04-16 19:14 - 2015-04-16 19:32 - 00000000 ____D () C:\AdwCleaner
                2015-04-16 19:10 - 2015-04-16 19:09 - 02686088 _____ (Thisisu) C:\Users\Defhawk\Desktop\JRT.exe
                2015-04-16 19:10 - 2015-04-16 19:04 - 02217984 _____ () C:\Users\Defhawk\Desktop\adwcleaner_4.201.exe
                2015-04-16 17:48 - 2015-04-16 17:48 - 00000127 _____ () C:\Users\Defhawk\Desktop\ckfiles.txt
                2015-04-16 17:30 - 2015-04-16 17:30 - 00003262 _____ () C:\Windows\System32\Tasks\{1744B18A-8492-42F2-9C76-0E8897CEDBA8}
                2015-04-15 22:19 - 2015-04-15 22:19 - 00468480 _____ () C:\Users\Defhawk\Desktop\CKScanner.exe
                2015-04-15 22:10 - 2015-04-15 22:10 - 00107520 ___SH () C:\Users\Defhawk\Documents\Thumbs.db
                2015-04-15 22:09 - 2015-04-15 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
                2015-04-15 21:21 - 2015-04-16 23:06 - 00037208 _____ () C:\Users\Defhawk\Desktop\Addition.txt
                2015-04-15 21:19 - 2015-04-17 21:00 - 00036326 _____ () C:\Users\Defhawk\Desktop\FRST.txt
                2015-04-15 21:19 - 2015-04-17 20:59 - 00000000 ____D () C:\FRST
                2015-04-15 21:19 - 2015-04-16 21:13 - 02097664 _____ (Farbar) C:\Users\Defhawk\Desktop\FRST64.exe
                2015-04-15 21:17 - 2015-04-15 21:17 - 00001447 _____ () C:\Users\Defhawk\Desktop\aswMBR.txt
                2015-04-15 21:17 - 2015-04-15 21:17 - 00000512 _____ () C:\Users\Defhawk\Desktop\MBR.dat
                2015-04-15 21:15 - 2015-04-15 21:15 - 05198336 _____ (AVAST Software) C:\Users\Defhawk\Desktop\aswMBR.exe
                2015-04-15 19:36 - 2015-04-15 19:38 - 00001131 _____ () C:\Users\Defhawk\Desktop\PTE.lnk
                2015-04-15 19:20 - 2015-04-15 19:46 - 00000000 ____D () C:\Program Files (x86)\Pro Evolution Soccer 2015
                2015-04-15 19:20 - 2015-04-15 19:20 - 00000902 _____ () C:\Users\Public\Desktop\Pro Evolution Soccer 2015.lnk
                2015-04-15 10:08 - 2015-04-15 10:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
                2015-04-15 10:01 - 2015-04-15 10:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
                2015-04-14 23:01 - 2015-04-15 10:05 - 00000000 ____D () C:\Program Files\Microsoft Office
                2015-04-14 18:17 - 2015-04-14 18:17 - 00000000 __RHD () C:\MSOCache
                2015-04-14 18:06 - 2015-04-14 18:06 - 00019570 _____ () C:\Users\Defhawk\Documents\140415.reg
                2015-04-14 11:59 - 2015-04-17 20:14 - 00004802 _____ () C:\Windows\setupact.log
                2015-04-14 11:59 - 2015-04-14 11:59 - 00000000 _____ () C:\Windows\setuperr.log
                2015-04-14 11:58 - 2015-04-17 19:00 - 00024500 _____ () C:\Windows\PFRO.log
                2015-04-14 01:26 - 2015-04-14 01:26 - 00486050 _____ () C:\Users\Defhawk\Documents\UninstallKey01.reg
                2015-04-14 01:24 - 2015-04-14 01:24 - 00869656 _____ () C:\Users\Defhawk\Documents\DeletedKey01.reg
                2015-04-14 00:50 - 2015-04-14 00:50 - 00020224 _____ () C:\Users\Defhawk\Documents\install.txt
                2015-04-14 00:17 - 2015-04-14 00:17 - 00001932 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Pro 9.lnk
                2015-04-14 00:17 - 2015-04-14 00:17 - 00001920 _____ () C:\Users\Public\Desktop\Nitro Pro 9.lnk
                2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files\Nitro
                2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files\Common Files\Nitro
                2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files (x86)\Nitro
                2015-04-14 00:17 - 2014-05-22 14:05 - 00029704 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalmon9.dll
                2015-04-14 00:17 - 2014-05-22 14:05 - 00017928 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalui9.dll
                2015-04-13 23:49 - 2015-04-13 23:49 - 00000000 ___SD () C:\Windows\system32\CompatTel
                2015-04-13 23:49 - 2015-04-13 23:49 - 00000000 ____D () C:\Windows\system32\appraiser
                2015-04-13 23:44 - 2015-04-13 23:44 - 00001077 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
                2015-04-13 23:44 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
                2015-04-13 23:14 - 2013-10-02 09:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
                2015-04-13 23:14 - 2013-10-02 09:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
                2015-04-13 23:14 - 2013-10-02 09:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
                2015-04-13 23:14 - 2013-10-02 08:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
                2015-04-13 23:14 - 2013-10-02 08:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
                2015-04-13 23:14 - 2013-10-02 08:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
                2015-04-13 23:14 - 2013-10-02 08:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
                2015-04-13 23:14 - 2013-10-02 07:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
                2015-04-13 23:14 - 2013-10-02 07:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
                2015-04-13 23:14 - 2013-10-02 07:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
                2015-04-13 23:14 - 2013-10-02 07:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
                2015-04-13 23:14 - 2013-10-02 07:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
                2015-04-13 23:14 - 2013-10-02 06:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
                2015-04-13 23:14 - 2013-10-02 06:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
                2015-04-13 23:14 - 2013-10-02 06:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
                2015-04-13 23:14 - 2013-10-02 05:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
                2015-04-13 23:14 - 2013-10-02 03:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
                2015-04-13 23:14 - 2013-10-02 03:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
                2015-04-13 23:13 - 2015-03-25 10:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
                2015-04-13 23:13 - 2015-03-25 10:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
                2015-04-13 23:13 - 2015-03-25 10:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
                2015-04-13 23:13 - 2015-03-25 10:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
                2015-04-13 23:13 - 2015-03-25 10:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
                2015-04-13 23:13 - 2015-03-25 10:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
                2015-04-13 23:13 - 2015-03-25 10:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
                2015-04-13 23:13 - 2015-03-25 10:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
                2015-04-13 23:13 - 2015-03-25 10:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
                2015-04-13 23:12 - 2015-03-23 10:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
                2015-04-13 23:12 - 2015-03-23 10:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
                2015-04-13 23:12 - 2015-03-23 10:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
                2015-04-13 23:12 - 2015-03-23 10:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
                2015-04-13 23:12 - 2015-03-23 10:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
                2015-04-13 23:12 - 2015-03-23 10:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
                2015-04-13 23:12 - 2015-03-23 10:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
                2015-04-13 23:12 - 2015-03-23 10:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
                2015-04-13 23:12 - 2015-01-28 06:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
                2015-04-13 22:38 - 2015-04-13 22:38 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
                2015-04-13 22:38 - 2015-04-13 22:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
                2015-04-13 22:19 - 2015-04-13 22:19 - 00055680 _____ () C:\Users\Defhawk\Documents\cc_20150413_221934.reg
                2015-04-13 20:20 - 2015-04-13 20:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
                2015-04-13 20:20 - 2015-04-13 20:20 - 00000000 ____D () C:\Program Files (x86)\K-Lite Codec Pack
                2015-04-13 20:20 - 2013-10-26 01:00 - 00127488 _____ () C:\Windows\system32\ff_vfw.dll
                2015-04-13 20:20 - 2013-10-26 01:00 - 00112640 _____ () C:\Windows\SysWOW64\ff_vfw.dll
                2015-04-13 20:20 - 2013-03-18 00:22 - 03554304 _____ (x264vfw project) C:\Windows\system32\x264vfw64.dll
                2015-04-13 20:20 - 2013-03-17 23:21 - 03649536 _____ (x264vfw project) C:\Windows\SysWOW64\x264vfw.dll
                2015-04-13 20:20 - 2012-07-21 17:54 - 00122880 _____ (fccHandler) C:\Windows\SysWOW64\ac3acm.acm
                2015-04-13 20:20 - 2011-12-08 00:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll
                2015-04-13 20:20 - 2011-12-08 00:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\lagarith.dll
                2015-04-13 20:20 - 2011-06-24 21:45 - 00258560 _____ () C:\Windows\system32\xvidvfw.dll
                2015-04-13 20:20 - 2011-06-24 21:44 - 00243200 _____ () C:\Windows\SysWOW64\xvidvfw.dll
                2015-04-12 20:53 - 2015-04-12 20:53 - 00000000 ____D () C:\ProgramData\KONAMI
                2015-04-12 18:38 - 2015-04-12 18:39 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files
                2015-04-12 18:30 - 2015-04-12 18:30 - 00045107 _____ () C:\ComboFix.txt
                2015-04-12 17:58 - 2015-04-15 22:49 - 00000000 ____D () C:\Windows\erdnt
                2015-04-12 16:50 - 2015-04-12 16:50 - 00001072 _____ () C:\Users\Public\Desktop\SMADΔV.lnk
                2015-04-12 14:46 - 2015-04-12 14:46 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DEF-PC-Windows-7-Ultimate-(64-bit).dat
                2015-04-12 14:45 - 2015-04-12 14:45 - 00003652 _____ () C:\Windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
                2015-04-12 14:45 - 2015-04-12 14:45 - 00002159 _____ () C:\Users\Defhawk\Desktop\Tweaking.com - Windows Repair.lnk
                2015-04-12 14:39 - 2015-04-12 14:42 - 12849664 _____ () C:\Users\Defhawk\Downloads\tweaking.com_windows_repair_aio_setup.exe
                2015-04-12 14:34 - 2015-04-12 14:34 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
                2015-04-12 14:34 - 2015-04-12 14:34 - 00000000 ___SD () C:\Windows\system32\GWX
                2015-04-12 13:55 - 2015-04-12 15:51 - 00318769 _____ () C:\MGlogs.zip
                2015-04-12 13:55 - 2015-04-12 13:55 - 00000000 ____D () C:\ProgramData\HitmanPro
                2015-04-12 13:02 - 2015-04-12 13:34 - 00000000 ____D () C:\ProgramData\RogueKiller
                2015-04-12 13:02 - 2015-04-12 13:02 - 00035064 _____ () C:\Windows\system32\Drivers\TrueSight.sys
                2015-04-12 03:12 - 2015-04-12 03:12 - 00000416 _____ () C:\Users\Defhawk\120415backup.reg
                2015-04-12 01:08 - 2015-04-12 01:08 - 00001646 _____ () C:\Users\Defhawk\Documents\cc_20150412_010800.reg
                2015-04-12 00:44 - 2011-06-11 05:15 - 05601616 _____ (Microsoft Corporation) C:\Windows\system32\mfc100u.dll
                2015-04-12 00:44 - 2011-06-11 05:15 - 05574984 _____ (Microsoft Corporation) C:\Windows\system32\mfc100.dll
                2015-04-12 00:14 - 2010-03-18 19:27 - 00827744 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll
                2015-04-11 16:46 - 2015-04-11 16:49 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\WCDMA_General
                2015-04-11 16:46 - 2015-04-11 16:46 - 00000916 _____ () C:\Users\Public\Desktop\Cyborg Telkomsel Mobile Broadband.lnk
                2015-04-11 16:46 - 2015-04-11 16:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cyborg Telkomsel Mobile Broadband
                2015-04-11 16:46 - 2015-04-11 16:46 - 00000000 ____D () C:\Program Files\Cyborg Telkomsel Mobile Broadband
                2015-04-11 16:46 - 2009-04-27 16:33 - 00118016 _____ (QUALCOMM Incorporated) C:\Windows\system32\Drivers\CT_QUALCOMM_U_drv.sys
                2015-04-11 13:05 - 2015-04-11 13:14 - 45473792 _____ () C:\Windows\system32\config\components.old
                2015-04-05 13:46 - 2015-04-05 13:47 - 45473792 _____ () C:\Windows\system32\config\COMPONENTS.iobit
                2015-04-05 01:19 - 2015-04-05 01:19 - 00003342 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup
                2015-04-05 01:19 - 2015-04-05 01:19 - 00002248 _____ () C:\Users\Defhawk\Desktop\SpyHunter.lnk
                2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
                2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\sh4ldr
                2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group
                2015-04-05 00:10 - 2015-04-05 00:10 - 76125026 _____ () C:\Users\Defhawk\Downloads\Tomorrowland 2014 - official aftermovie - YouTube.MKV
                2015-04-03 13:26 - 2015-04-03 13:26 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DEF-PC-Microsoft-Windows-7-Ultimate-(64-bit).dat
                2015-04-03 13:26 - 2015-04-03 13:26 - 00000000 ____D () C:\RegBackup
                2015-04-02 21:41 - 2015-04-15 19:20 - 00000914 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro Evolution Soccer 2015.lnk
                2015-04-01 19:10 - 2013-10-18 15:01 - 00285747 _____ () C:\shldr
                2015-04-01 19:10 - 2013-10-18 15:01 - 00008192 _____ () C:\shldr.mbr
                2015-04-01 00:33 - 2015-04-17 20:23 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
                2015-04-01 00:33 - 2015-04-01 00:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
                2015-04-01 00:33 - 2015-04-01 00:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
                2015-04-01 00:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
                2015-04-01 00:33 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
                2015-03-31 22:39 - 2015-03-31 22:39 - 00000000 _____ () C:\autoexec.bat
                2015-03-31 21:37 - 2015-04-01 00:33 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
                2015-03-31 21:37 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
                2015-03-23 22:40 - 2015-03-23 22:40 - 00943832 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
                2015-03-23 22:40 - 2015-03-23 22:40 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
                2015-03-23 22:39 - 2015-03-23 22:39 - 00129312 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys
                 
                ==================== One Month Modified Files and Folders =======
                 
                (If an entry is included in the fixlist, the file\folder will be moved.)
                 
                2015-04-17 20:29 - 2013-11-07 01:32 - 01765098 _____ () C:\Windows\WindowsUpdate.log
                2015-04-17 20:27 - 2015-01-09 17:37 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
                2015-04-17 20:17 - 2015-02-05 18:12 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57.job
                2015-04-17 20:17 - 2014-04-01 05:10 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6.job
                2015-04-17 20:14 - 2015-02-05 18:12 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5.job
                2015-04-17 20:14 - 2014-04-01 05:10 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d.job
                2015-04-17 20:14 - 2014-03-18 14:56 - 00000000 ____D () C:\Program Files (x86)\SMADAV
                2015-04-17 20:14 - 2009-07-14 12:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
                2015-04-17 20:12 - 2014-06-16 16:13 - 00008192 _____ () C:\Windows\SysWOW64\WDPABKP.dat
                2015-04-17 20:11 - 2009-07-14 11:45 - 00021200 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
                2015-04-17 20:11 - 2009-07-14 11:45 - 00021200 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
                2015-04-17 20:10 - 2013-11-20 00:11 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
                2015-04-17 20:08 - 2013-11-05 03:31 - 00000000 ____D () C:\Users\Defhawk\AppData\Local\CrashDumps
                2015-04-17 19:58 - 2009-07-14 12:13 - 00776420 _____ () C:\Windows\system32\PerfStringBackup.INI
                2015-04-16 23:07 - 2013-11-04 00:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\AIMP3
                2015-04-16 22:39 - 2014-04-09 22:53 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\IObit
                2015-04-16 22:23 - 2014-10-02 21:36 - 00000000 ____D () C:\Program Files\Autodesk
                2015-04-16 22:23 - 2014-10-02 21:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
                2015-04-16 22:23 - 2014-10-02 21:30 - 00000000 ____D () C:\ProgramData\Autodesk
                2015-04-16 22:15 - 2014-03-30 02:51 - 00000000 ____D () C:\Program Files\Corel
                2015-04-16 21:59 - 2014-10-02 21:30 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Autodesk
                2015-04-16 21:51 - 2014-10-02 21:36 - 00000000 ____D () C:\Program Files\Common Files\Autodesk Shared
                2015-04-16 19:33 - 2013-11-04 18:29 - 00000000 ____D () C:\Program Files\PowerISO
                2015-04-16 19:31 - 2013-11-03 10:54 - 00000000 ____D () C:\Users\Defhawk
                2015-04-16 17:32 - 2014-11-30 03:17 - 00000000 ____D () C:\Users\Defhawk\Downloads\Compressed
                2015-04-16 12:59 - 2013-11-03 15:05 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\DMCache
                2015-04-16 07:09 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\Speech
                2015-04-15 22:55 - 2013-11-04 20:36 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Nitro PDF
                2015-04-15 22:32 - 2014-04-09 22:55 - 00000000 ____D () C:\ProgramData\IObit
                2015-04-15 22:29 - 2015-01-09 17:37 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
                2015-04-15 22:29 - 2013-11-03 14:20 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
                2015-04-15 22:29 - 2013-11-03 14:20 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
                2015-04-15 22:18 - 2014-03-31 11:30 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\IDM
                2015-04-15 22:09 - 2015-01-27 00:03 - 00000722 _____ () C:\Users\Public\Desktop\AIMP3.lnk
                2015-04-15 22:08 - 2013-11-04 00:02 - 00000000 ____D () C:\Program Files\AIMP3
                2015-04-15 22:03 - 2015-01-03 04:36 - 00002858 _____ () C:\Windows\System32\Tasks\Driver Booster SkipUAC (Defhawk)
                2015-04-15 21:46 - 2013-11-20 00:25 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
                2015-04-15 21:12 - 2014-04-09 22:55 - 00000000 ____D () C:\ProgramData\ProductData
                2015-04-15 19:45 - 2013-11-05 15:39 - 00000000 ____D () C:\Program Files (x86)\Steam
                2015-04-15 19:05 - 2013-11-04 18:00 - 00000000 ____D () C:\Users\Defhawk\Documents\Bluetooth Folder
                2015-04-15 18:40 - 2013-11-04 17:40 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Corel
                2015-04-15 18:40 - 2013-11-04 17:30 - 00000000 ____D () C:\ProgramData\Corel
                2015-04-15 18:37 - 2014-03-30 02:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)
                2015-04-15 13:15 - 2014-12-02 01:16 - 00000000 ____D () C:\Users\Defhawk\Documents\SnowFox Total Video Converter
                2015-04-15 13:15 - 2014-05-24 20:49 - 00000000 ____D () C:\Users\Defhawk\Documents\Scanned
                2015-04-15 10:34 - 2009-07-14 11:45 - 05979304 _____ () C:\Windows\system32\FNTCACHE.DAT
                2015-04-15 10:31 - 2013-11-03 12:30 - 00490216 _____ () C:\Users\Defhawk\AppData\Local\GDIPFONTCACHEV1.DAT
                2015-04-15 10:09 - 2013-11-04 16:03 - 00000000 ____D () C:\ProgramData\Microsoft Help
                2015-04-15 10:07 - 2014-05-11 14:29 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\vlc
                2015-04-15 10:03 - 2009-07-14 09:34 - 00000514 _____ () C:\Windows\win.ini
                2015-04-15 10:01 - 2009-07-14 10:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
                2015-04-15 01:26 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\AppCompat
                2015-04-15 00:25 - 2009-07-14 14:46 - 00000000 ____D () C:\Windows\CSC
                2015-04-15 00:20 - 2013-11-04 00:36 - 00003160 _____ () C:\Windows\System32\Tasks\SidebarExecute
                2015-04-15 00:12 - 2013-11-03 12:33 - 00776420 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
                2015-04-14 06:48 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\rescache
                2015-04-14 01:15 - 2013-11-03 19:08 - 00000000 ____D () C:\ProgramData\USBChargerPlus
                2015-04-14 01:04 - 2014-05-02 23:18 - 00000000 ____D () C:\Users\Defhawk\AppData\Local\VMware
                2015-04-14 01:04 - 2009-07-14 10:20 - 00000000 ___RD () C:\Users\Default
                2015-04-13 23:53 - 2009-07-14 10:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
                2015-04-13 23:44 - 2014-10-05 00:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
                2015-04-13 23:44 - 2014-10-05 00:33 - 00000000 ____D () C:\Program Files\VS Revo Group
                2015-04-13 22:40 - 2013-11-03 13:05 - 00000000 ____D () C:\Program Files\WinRAR
                2015-04-13 22:18 - 2013-11-03 23:35 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
                2015-04-13 22:18 - 2013-11-03 23:34 - 00000000 ____D () C:\Program Files\CCleaner
                2015-04-13 21:06 - 2014-03-31 11:30 - 00000000 ____D () C:\Program Files (x86)\Internet Download Manager
                2015-04-13 20:42 - 2013-11-03 10:59 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\DAEMON Tools Lite
                2015-04-13 20:39 - 2013-11-03 15:05 - 00001009 _____ () C:\Users\Defhawk\Desktop\Internet Download Manager.lnk
                2015-04-13 20:34 - 2013-11-04 18:31 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\PowerISO
                2015-04-13 19:29 - 2013-11-04 01:47 - 00000000 ____D () C:\Windows\Panther
                2015-04-12 21:34 - 2014-10-25 03:09 - 00000000 ____D () C:\Users\Defhawk\Downloads\Lamaran
                2015-04-12 21:34 - 2014-10-16 02:13 - 00000000 ____D () C:\Users\Defhawk\Downloads\Defraggler Professional Edition v2.18 Final - SceneDL
                2015-04-12 21:34 - 2014-10-03 03:03 - 00000000 ____D () C:\Users\Defhawk\Documents\KONAMI
                2015-04-12 21:34 - 2014-09-24 03:56 - 00000000 ____D () C:\Users\Defhawk\Desktop\Tor Browser
                2015-04-12 20:27 - 2014-03-18 14:56 - 00000000 ____D () C:\[Smad-Cage]
                2015-04-12 18:26 - 2013-11-05 16:27 - 00000000 ____D () C:\ProgramData\TEMP
                2015-04-12 18:23 - 2009-07-14 09:34 - 00000215 _____ () C:\Windows\system.ini
                2015-04-12 18:22 - 2009-07-14 09:34 - 00000027 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_134
                2015-04-12 18:19 - 2009-07-14 09:34 - 41680896 _____ () C:\Windows\system32\config\SYSTEM.bak
                2015-04-12 18:19 - 2009-07-14 09:34 - 103915520 _____ () C:\Windows\system32\config\SOFTWARE.bak
                2015-04-12 18:19 - 2009-07-14 09:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
                2015-04-12 18:19 - 2009-07-14 09:34 - 00065536 _____ () C:\Windows\system32\config\SAM.bak
                2015-04-12 18:19 - 2009-07-14 09:34 - 00028672 _____ () C:\Windows\system32\config\SECURITY.bak
                2015-04-12 16:50 - 2014-12-17 00:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus
                2015-04-12 11:10 - 2013-11-09 13:35 - 00000000 ____D () C:\Windows\MSSecurityNS
                2015-04-12 02:01 - 2009-07-14 11:54 - 00000749 ____R () C:\Windows\WindowsShell.Manifest
                2015-04-12 02:01 - 2009-07-14 10:20 - 00000000 ___RD () C:\Users\Public\Libraries
                2015-04-12 01:05 - 2013-12-01 23:04 - 00000000 ___RD () C:\Users\Defhawk\Dropbox
                2015-04-12 01:05 - 2013-12-01 23:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Dropbox
                2015-04-12 01:04 - 2014-10-31 17:13 - 00000000 ___RD () C:\Users\Defhawk\Google Drive
                2015-04-12 00:55 - 2014-07-20 22:55 - 00000038 _____ () C:\Windows\sysreg.dat
                2015-04-12 00:55 - 2008-03-05 07:47 - 00000072 _____ () C:\Windows\anticrash.dat
                2015-04-12 00:55 - 2008-03-05 07:46 - 00000067 _____ () C:\Windows\hare.dat
                2015-04-12 00:55 - 2001-10-13 13:11 - 00000084 _____ () C:\Windows\battery.dat
                2015-04-11 23:44 - 2009-07-14 11:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
                2015-04-11 23:28 - 2009-07-14 12:08 - 00032582 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
                2015-04-11 20:04 - 2013-12-01 23:04 - 00001021 _____ () C:\Users\Defhawk\Desktop\Dropbox.lnk
                2015-04-11 20:04 - 2013-12-01 23:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
                2015-04-11 16:57 - 2009-07-14 09:34 - 00000883 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_868
                2015-04-11 13:14 - 2009-07-14 09:34 - 41680896 _____ () C:\Windows\system32\config\system.old
                2015-04-11 13:14 - 2009-07-14 09:34 - 103931904 _____ () C:\Windows\system32\config\software.old
                2015-04-11 13:14 - 2009-07-14 09:34 - 00524288 _____ () C:\Windows\system32\config\default.old
                2015-04-11 13:14 - 2009-07-14 09:34 - 00065536 _____ () C:\Windows\system32\config\sam.old
                2015-04-11 13:14 - 2009-07-14 09:34 - 00028672 _____ () C:\Windows\system32\config\security.old
                2015-04-10 09:44 - 2013-11-17 21:36 - 00000000 ____D () C:\Windows\SysWOW64\My Vaults
                2015-04-10 09:44 - 2013-11-04 18:04 - 00000000 ____D () C:\ProgramData\Atheros
                2015-04-10 09:44 - 2013-11-04 00:36 - 00000000 ____D () C:\ProgramData\P4G
                2015-04-09 18:48 - 2008-03-04 19:57 - 00000338 _____ () C:\Windows\winshell.dat
                2015-04-08 11:55 - 2013-11-03 10:53 - 00000000 ____D () C:\Recovery
                2015-04-08 11:55 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\system32\Msdtc
                2015-04-07 21:00 - 2009-07-14 12:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
                2015-04-05 19:00 - 2009-07-14 14:45 - 00000000 ___RD () C:\Users\Public\Recorded TV
                2015-04-05 13:12 - 2009-07-14 09:34 - 00000855 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_89
                2015-04-05 12:38 - 2014-04-13 15:06 - 103931904 _____ () C:\Windows\system32\config\SOFTWARE.iodefrag.bak
                2015-04-05 12:38 - 2014-04-13 15:06 - 00446464 _____ () C:\Windows\system32\config\DEFAULT.iodefrag.bak
                2015-04-05 12:38 - 2014-04-13 15:06 - 00065536 _____ () C:\Windows\system32\config\SAM.iodefrag.bak
                2015-04-05 12:38 - 2014-04-13 15:06 - 00028672 _____ () C:\Windows\system32\config\SECURITY.iodefrag.bak
                2015-04-05 12:37 - 2013-11-09 13:35 - 00000000 ____D () C:\Windows\MSSecurityNi
                2015-04-05 01:13 - 2009-07-14 09:34 - 00001117 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_839
                2015-04-01 22:09 - 2013-11-03 17:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
                2015-04-01 19:10 - 2013-11-04 18:00 - 00000000 ____D () C:\Program Files (x86)\Bluetooth Suite
                2015-04-01 06:52 - 2014-09-06 02:46 - 00001908 _____ () C:\Windows\diagwrn.xml
                2015-04-01 06:52 - 2014-09-06 02:46 - 00001908 _____ () C:\Windows\diagerr.xml
                2015-04-01 00:33 - 2013-11-05 16:41 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Malwarebytes
                2015-03-31 18:59 - 2014-07-20 22:58 - 00000000 ____D () C:\Windows\pss
                2015-03-23 22:40 - 2013-11-03 11:03 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
                2015-03-19 18:15 - 2013-11-24 23:57 - 00000000 ____D () C:\ProgramData\CanonIJPLM
                 
                ==================== Files in the root of some directories =======
                 
                2013-02-17 10:27 - 2013-02-17 10:27 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
                2014-04-12 23:59 - 2015-02-02 20:46 - 0000132 _____ () C:\Users\Defhawk\AppData\Roaming\Adobe PNG Format CC Prefs
                2013-11-05 02:24 - 2014-01-20 20:07 - 0000132 _____ () C:\Users\Defhawk\AppData\Roaming\Adobe PNG Format CS6 Prefs
                2014-06-20 19:04 - 2014-06-20 19:04 - 0000024 _____ () C:\Users\Defhawk\AppData\Roaming\temp.ini
                2014-01-24 21:49 - 2014-01-24 21:49 - 142848334 _____ () C:\Users\Defhawk\AppData\Local\ACCCx2_3_0_322.zip.aamdownload
                2014-01-24 21:49 - 2014-01-24 21:49 - 0001796 _____ () C:\Users\Defhawk\AppData\Local\ACCCx2_3_0_322.zip.aamdownload.aamd
                2014-01-20 16:57 - 2014-01-20 17:00 - 0001456 _____ () C:\Users\Defhawk\AppData\Local\Adobe Save for Web 13.0 Prefs
                2013-11-07 19:53 - 2013-11-07 19:53 - 0000001 _____ () C:\Users\Defhawk\AppData\Local\llftool.4.30.agreement
                2014-03-18 23:11 - 2014-06-24 23:08 - 0007607 _____ () C:\Users\Defhawk\AppData\Local\Resmon.ResmonCfg
                2013-11-03 12:51 - 2013-11-03 12:52 - 0009486 _____ () C:\Users\Defhawk\AppData\Local\WiDiSetupLog.20131103.125137.txt
                2013-11-04 01:00 - 2013-11-04 01:00 - 0010023 _____ () C:\Users\Defhawk\AppData\Local\WiDiSetupLog.20131104.010029.txt
                2014-03-14 18:49 - 2014-03-14 18:49 - 0000000 _____ () C:\ProgramData\DP45977C.lfl
                2014-10-02 21:45 - 2014-10-02 21:45 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
                 
                Files to move or delete:
                ====================
                C:\Users\Defhawk\120415backup.reg
                C:\Users\Defhawk\200714.reg
                 
                 
                ==================== Bamital & volsnap Check =================
                 
                (There is no automatic fix for files that do not pass verification.)
                 
                C:\Windows\System32\winlogon.exe => File is digitally signed
                C:\Windows\System32\wininit.exe => File is digitally signed
                C:\Windows\SysWOW64\wininit.exe => File is digitally signed
                C:\Windows\explorer.exe => File is digitally signed
                C:\Windows\SysWOW64\explorer.exe => File is digitally signed
                C:\Windows\System32\svchost.exe => File is digitally signed
                C:\Windows\SysWOW64\svchost.exe => File is digitally signed
                C:\Windows\System32\services.exe => File is digitally signed
                C:\Windows\System32\User32.dll => File is digitally signed
                C:\Windows\SysWOW64\User32.dll => File is digitally signed
                C:\Windows\System32\userinit.exe => File is digitally signed
                C:\Windows\SysWOW64\userinit.exe => File is digitally signed
                C:\Windows\System32\rpcss.dll => File is digitally signed
                C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
                 
                 
                nointegritychecks: ==> Integrity Checks is disabled <===== ATTENTION!
                 
                 
                LastRegBack: 2015-04-14 06:20
                 
                ==================== End Of Log ============================
                 
                Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-04-2015 04
                Ran by [removed] at 2015-04-17 21:00:34
                Running from C:\Users\[removed]\Desktop
                Boot Mode: Normal
                ==========================================================
                 
                 
                ==================== Security Center ========================
                 
                (If an entry is included in the fixlist, it will be removed.)
                 
                AV: ESET Smart Security 8.0 (Disabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
                AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                AS: ESET Smart Security 8.0 (Disabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
                FW: ESET Personal firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
                 
                ==================== Installed Programs ======================
                 
                (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
                 
                µTorrent (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)
                Adobe Flash Player 17 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
                Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
                AIMP3 (HKLM-x32\…\AIMP3) (Version: v3.60.1483, 27.02.2015 - AIMP DevTeam)
                Akamai NetSession Interface (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Akamai) (Version:  - Akamai Technologies, Inc)
                ASUS Power4Gear Hybrid (HKLM\…\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.2 - ASUS)
                ASUS Screen Saver (HKLM\…\{0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2}) (Version: 1.0.1 - ASUS)
                Atheros Bluetooth Suite (64) (HKLM\…\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.150 - Atheros)
                Atheros Outlook Addin 2010 (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\BB108A893815B64BF41C4574C3324FB7371AA244) (Version: 1.0.0.0 - Microsoft)
                AutoCAD MEP 2015 Language Pack - English (Version: 7.7.49.0 - Autodesk) Hidden
                Canon iP2700 series Printer Driver (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2700_series) (Version:  - )
                Canon MP230 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP230_series) (Version: 1.00 - Canon Inc.)
                CCleaner (HKLM\…\CCleaner) (Version: 5.04 - Piriform)
                cFosSpeed v10.00 (HKLM\…\cFosSpeed) (Version: 10.00 - cFos Software GmbH, Bonn)
                CGS17_Setup_x64 (Version: 17.0 - Corel Corporation) Hidden
                Corel Graphics - Windows Shell Extension (HKLM\…\_{4AB916EE-ABA8-4079-9889-745798B6D809}) (Version: 17.0.0.491 - Corel Corporation)
                Corel Graphics - Windows Shell Extension (Version: 17.0.491 - Corel Corporation) Hidden
                Corel Graphics - Windows Shell Extension 32 Bit (Version: 17.0.491 - Corel Corporation) Hidden
                Corel Graphics - Windows Shell Extension 64 Bit (Version: 16.1.843 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Capture (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Common (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Connect (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Custom Data (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Draw (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - EN (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Filters (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - FontNav (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - IPM Content (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - PHOTO-PAINT (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Photozoom Plugin (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Redist (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Setup Files (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - VBA (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - VideoBrowser (x64) (Version: 17.0 - Corel Corporation) Hidden
                CorelDRAW Graphics Suite X7 - Writing Tools (x64) (Version: 17.0 -  Corel Corporation) Hidden
                CPUID CPU-Z 1.67.1 (HKLM\…\CPUID CPU-Z_is1) (Version:  - )
                CPUID HWMonitor Pro 1.16 (HKLM\…\CPUID HWMonitorPro_is1) (Version:  - )
                Cyborg Telkomsel Mobile Broadband (HKLM\…\Cyborg Telkomsel Mobile Broadband_is1) (Version:  - )
                Defraggler (HKLM\…\Defraggler) (Version: 2.18 - Piriform)
                Dropbox (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Dropbox) (Version: 3.4.3 - Dropbox, Inc.)
                ESET Smart Security (HKLM\…\{C082CDB9-D173-4740-AE0E-C685E6F44850}) (Version: 8.0.304.0 - ESET, spol s r. o.)
                Google Chrome (HKLM-x32\…\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
                Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\…\{90F00673-A276-4A58-B675-B426D39D1E09}) (Version: 15.3.0.0398 - Intel Corporation)
                Intel® PROSet/Wireless WiFi Software (HKLM\…\{ECE5B218-A086-4E18-A362-D11181681457}) (Version: 15.03.1000.1637 - Intel Corporation)
                Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
                Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
                Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
                Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
                Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
                Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
                Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
                Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
                Nitro Pro 9 (HKLM\…\{8C386164-8794-4684-8921-2218199E1020}) (Version: 9.5.1.12 - Nitro)
                NVIDIA GeForce Experience 2.2.2 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)
                NVIDIA Graphics Driver 344.11 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.11 - NVIDIA Corporation)
                NVIDIA HD Audio Driver 1.3.32.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
                NVIDIA PhysX System Software 9.14.0702 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
                Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
                Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (Version: 11.0.51108 - Microsoft Corporation) Hidden
                Pro Evolution Soccer 2015 (HKLM-x32\…\UHJvRXZvbHV0aW9uU29jY2VyMjAxNQ==_is1) (Version: 1 - )
                Revo Uninstaller Pro 3.1.2 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)
                SanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19755 - Gemalto N.V.)
                Share64 (Version: 14.1.0.150 - Corel Corporation) Hidden
                SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden
                SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden
                TeraCopy 2.3 (HKLM\…\TeraCopy_is1) (Version:  - Code Sector)
                WD SmartWare (HKLM\…\{7AE43D6C-B3F1-448D-AD84-1CDC7AC6EBC7}) (Version: 2.4.6.3 - Western Digital Technologies, Inc.)
                Windows Driver Package - ASUS (ATP) Mouse  (01/10/2013 1.0.0.170) (HKLM\…\4A9DE1E9EBC800B7F01739D4DE7363EF6751BDF5) (Version: 01/10/2013 1.0.0.170 - ASUS)
                WinRAR 5.01 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
                Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (Version: 11.0.51108 - Microsoft Corporation) Hidden
                 
                ==================== Custom CLSID (selected items): ==========================
                 
                (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
                 
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
                 
                ==================== Restore Points  =========================
                 
                16-04-2015 21:54:26 Removed Autodesk App Manager.
                16-04-2015 21:59:54 Revo Uninstaller Pro's restore point - Autodesk Material Library 2015
                16-04-2015 22:17:42 Revo Uninstaller Pro's restore point - Autodesk Material Library Base Resolution Image Library 2015
                16-04-2015 22:21:08 Revo Uninstaller Pro's restore point - Autodesk ReCap
                16-04-2015 22:24:04 Revo Uninstaller Pro's restore point - Autodesk Featured Apps
                16-04-2015 22:26:15 Removed Autodesk Featured Apps.
                16-04-2015 22:32:05 Revo Uninstaller Pro's restore point - Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit
                16-04-2015 22:33:15 Removed Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit
                17-04-2015 20:03:44 Installed ESET Smart Security
                17-04-2015 20:11:26 Restore Point Created by FRST
                 
                ==================== Hosts content: ==========================
                 
                (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
                 
                2009-07-14 09:34 - 2015-04-17 20:12 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
                 
                ==================== Scheduled Tasks (whitelisted) =============
                 
                (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
                 
                Task: {009BBECF-4D78-4564-8F1E-F0F759E7D98F} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
                Task: {028F0BEA-2EB0-4634-9C5A-C742BBEB76F4} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-04-16] (AsusTek)
                Task: {04CBF69D-AA8B-4CE9-B1B3-9BD20D0FE348} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)
                Task: {1296B0D2-42C3-4623-B9A1-4E90505D4046} - System32\Tasks\{D355A25F-ECA9-4762-B764-3F20E3109E6E} => Firefox.exe http://ui.skype.com/ui/0/6.5.0.158/en/go/help.faq.installer?LastError=1618
                Task: {1823FA51-0467-43BB-8134-F66123521DBB} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
                Task: {21969B38-4960-4D24-9C8E-D4FC7923C0E0} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-05-17] (ASUSTeK Computer Inc.)
                Task: {23CB1AB5-EA73-4F6C-B3B1-AC2D73B58A47} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
                Task: {2446A911-78EE-45E8-B33B-A1A2AB6ECBE7} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
                Task: {24EA35E8-6BD4-44F2-A43A-04EF083397C4} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2014-07-21] (Nero AG)
                Task: {28650E00-EF3E-4295-9668-766B94B05A1B} - System32\Tasks\{5C4A58BA-8354-4A6C-B5BA-5563FB8E2CFF} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P7.3 Self-installer.exe" -d C:\Users\Defhawk\Downloads
                Task: {29A3E160-1D0F-4F1E-AC63-92F8DE11939C} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
                Task: {36B05A08-31B2-47D7-A8E7-487C2F605BAF} - System32\Tasks\cFosSpeedTR => C:\Program Files\cFosSpeed\CFSTR.exe [2014-04-30] (BB)
                Task: {3868AD23-3468-4E2D-869F-21217684C3C0} - System32\Tasks\{CB9212D3-94DB-4220-81D8-6F30C28ADE44} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.0 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDM
                Task: {3BB2B98A-6C8A-402A-97F7-435C3A506140} - System32\Tasks\{56885AD1-C12F-47A4-8D23-F8D89DE66A2E} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.4 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDM
                Task: {3C9E538E-F64A-4668-A4F9-63D0DE563553} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
                Task: {4643B852-23FB-409E-80AB-552789036A2A} - System32\Tasks\{3C92213F-4502-4D35-8B46-1A4E32F4BA49} => C:\Program Files (x86)\Nero\Nero 12\Nero ControlCenter\NCC.exe
                Task: {4D38440B-AF7B-4872-AA8F-FD15E3657395} - System32\Tasks\Process Lasso Core Engine Only => C:\Program Files\Process Lasso\processgovernor.exe [2014-09-22] (Bitsum LLC)
                Task: {59E0D626-4AD0-49A6-AA7D-F049B405F411} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-05-15] (ASUS)
                Task: {6A250B61-775C-4CE8-BB6C-C72F660B0A41} - System32\Tasks\ASUS InstantOn Config => C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [2012-09-24] (ASUS)
                Task: {7398C9F1-B7EE-485B-8232-331BDAD10A40} - System32\Tasks\{DFF6302E-B746-47CD-8BEE-51B20017A14D} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\Nero\Nero 12\Nero ControlCenter\NCC.exe"
                Task: {7830917E-F467-40BF-A4CC-28C5876001B1} - System32\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
                Task: {7A19FF40-4CB2-4564-B657-91566652CAD0} - System32\Tasks\Process Lasso Management Console (GUI) => C:\Program Files\Process Lasso\processlasso.exe [2014-09-22] (Bitsum LLC)
                Task: {7BC53F15-B01F-48BE-B2F2-98BD572CE49D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
                Task: {8ADC19A6-0DEF-4A99-95F0-47C63D9D103B} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-09-14] (ASUSTek Computer Inc.)
                Task: {91A3D505-22C3-4B90-B99B-C85C38D2E449} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-12] (Tweaking.com)
                Task: {A41D758C-732B-41C6-92AE-7DFC80D9AC0F} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2013-10-26] ()
                Task: {AAFF357B-3E9E-4420-A97D-4FCE425EB44A} - System32\Tasks\{A7CF406F-E389-4603-A99D-96DF4CF8E9F4} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.5 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDM
                Task: {B76D7C3A-0FC8-489A-8A0C-5ECB84B303D7} - System32\Tasks\smadav => C:\Program Files (x86)\Smadav\SMΔRTP.exe [2015-02-11] (Smadsoft)
                Task: {BD5CF776-01FC-4EDB-9D03-4CCC4F138181} - System32\Tasks\{6575FDB1-B2CA-4592-9E2A-89BF71F18C0E} => pcalua.exe -a C:\Users\Defhawk\AppData\Local\Temp\NeroInstallFiles\NERO20120813121238302\setup.exe -d C:\Users\Defhawk\AppData\Local\Temp\NeroInstallFiles\NERO20120813121238302
                Task: {C237C350-8497-403A-8D80-95FE0FD944D2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd)
                Task: {C5D6C676-CC24-4621-AD7B-9732B7B680F0} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.)
                Task: {CA07F7AC-6FE1-4499-98FE-154040652706} - System32\Tasks\{3681AD73-36EC-4764-AE5B-C1F3F90EA6EC} => pcalua.exe -a I:\INSTALL.EXE -d I:\
                Task: {CBDB467C-BCF1-4935-8BF8-067D5726872E} - \Microsoft Office 15 Sync Maintenance for Def-PC-Defhawk Def-PC No Task File <==== ATTENTION
                Task: {CBFCB5FC-B3D6-4376-9A81-66CD907AD0F2} - System32\Tasks\{CB8B5CF1-985B-4406-ADAD-51EFADEEF487} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P6.4 Self-installer.exe" -d C:\Users\Defhawk\Downloads
                Task: {CC088725-91F5-4E53-A0F8-03C294D4A9B7} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-01-09] (Realtek Semiconductor)
                Task: {CFCBA695-6977-4705-BD56-3C34EB5C2074} - System32\Tasks\AutoKMSCustom => C:\Windows\AutoKMS\AutoKMS.exe
                Task: {D4E9AFF7-C3F6-4145-BD58-3C00BE01063A} - System32\Tasks\Driver Booster SkipUAC (Defhawk) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
                Task: {D74126FC-77A0-46A8-8C0D-C932B95015EB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
                Task: {DC3EA95E-CB26-4403-8692-EFCCE0BBFB71} - System32\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
                Task: {E9B0D633-DE94-4608-9BAE-16CF90AD732F} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
                Task: {F26FA818-8742-4E5E-A115-0AE9166E1AF6} - System32\Tasks\{A4D3F862-ECA0-4659-A604-FA6A3813E901} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P7.1 Self-installer.exe" -d C:\Users\Defhawk\Downloads
                Task: {F45E28EE-2421-428B-B21B-C618B93C8E09} - System32\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
                Task: {F4D0D822-F7C1-4193-A131-9CF4CE2E2BFA} - System32\Tasks\{1744B18A-8492-42F2-9C76-0E8897CEDBA8} => pcalua.exe -a "C:\Program Files (x86)\Xilisoft\Video Converter Ultimate\Uninstall.exe" -d "C:\Program Files (x86)\Xilisoft\Video Converter Ultimate"
                Task: {FA724455-DB75-41AB-B4C5-FE1150360F34} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
                Task: {FBE9499D-F4DD-437E-A393-C21B10C9B005} - System32\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)
                Task: {FD95CA08-B3DD-4638-81DA-01076FFF67CE} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
                Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
                Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                 
                ==================== Loaded Modules (whitelisted) ==============
                 
                2013-11-03 12:29 - 2014-09-14 04:53 - 00116880 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
                2012-10-01 20:36 - 2012-10-01 20:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
                2013-11-17 00:47 - 2012-01-20 14:55 - 00678400 _____ () C:\Program Files\TeraCopy\TeraCopyExt64.dll
                2010-07-14 16:11 - 2010-07-14 16:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
                2013-11-24 23:57 - 2012-03-28 19:49 - 00140456 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
                2014-05-22 14:06 - 2014-05-22 14:06 - 00417800 _____ () C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe
                2013-07-10 11:18 - 2013-07-10 11:18 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
                2015-04-11 16:46 - 2014-09-05 09:58 - 01935872 _____ () C:\Program Files\Cyborg Telkomsel Mobile Broadband\App.exe
                2013-11-03 11:05 - 2014-09-14 06:48 - 00012104 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
                2012-01-31 09:25 - 2012-01-31 09:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
                2012-03-15 10:48 - 2012-03-15 10:48 - 00221184 _____ () C:\Program Files (x86)\ASUS\VirtualCamera\virtualCamera.ax
                2012-10-01 20:37 - 2012-10-01 20:37 - 06522480 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
                2015-04-15 21:46 - 2015-04-14 04:55 - 01252680 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\libglesv2.dll
                2015-04-15 21:46 - 2015-04-14 04:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\libegl.dll
                2015-04-11 16:46 - 2013-05-22 10:56 - 00186368 _____ () C:\Program Files\Cyborg Telkomsel Mobile Broadband\RasDial.dll
                2015-04-11 16:46 - 2013-05-22 10:56 - 00324608 _____ () C:\Program Files\Cyborg Telkomsel Mobile Broadband\pcmWave.dll
                2015-04-11 16:46 - 2013-07-19 11:12 - 00368640 _____ () C:\Program Files\Cyborg Telkomsel Mobile Broadband\ATManager.dll
                2015-04-11 16:46 - 2013-05-22 10:56 - 00264704 _____ () C:\Program Files\Cyborg Telkomsel Mobile Broadband\log.dll
                 
                ==================== Alternate Data Streams (whitelisted) =========
                 
                (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
                 
                AlternateDataStreams: C:\Windows:nlsPreferences
                AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51
                 
                ==================== Safe Mode (whitelisted) ===================
                 
                (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
                 
                 
                ==================== EXE Association (whitelisted) ===============
                 
                (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
                 
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION!
                 
                ==================== Other Areas ============================
                 
                (Currently there is no automatic fix for this section.)
                 
                HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
                DNS Servers: [removed] - [removed]
                 
                ==================== MSCONFIG/TASK MANAGER disabled items ==
                 
                (Currently there is no automatic fix for this section.)
                 
                MSCONFIG\Services: eventlog => 2
                MSCONFIG\Services: Wecsvc => 3
                MSCONFIG\startupreg: EPSON_UD_START => 
                MSCONFIG\startupreg: Lync => 
                 
                ==================== Accounts: =============================
                 
                Administrator (S-1-5-21-3901189400-636743289-3933302658-500 - Administrator - Disabled)
                Defhawk (S-1-5-21-3901189400-636743289-3933302658-1000 - Administrator - Enabled) => C:\Users\Defhawk
                Guest (S-1-5-21-3901189400-636743289-3933302658-501 - Limited - Disabled)
                HomeGroupUser$ (S-1-5-21-3901189400-636743289-3933302658-1002 - Limited - Enabled)
                 
                ==================== Faulty Device Manager Devices =============
                 
                 
                ==================== Event log errors: =========================
                 
                Application errors:
                ==================
                Error: (04/17/2015 08:22:39 PM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
                Description: Product: Nero Update – Error 1921.Service Nero Update (NAUpdate) could not be stopped.  Verify that you have sufficient privileges to stop system services.
                 
                Error: (04/17/2015 08:20:44 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:34:44Z. Error Code: 0x80041321.
                 
                Error: (04/17/2015 08:08:06 PM) (Source: Application Error) (EventID: 1000) (User: )
                Description: Faulting application name: egui.exe, version: 8.0.304.0, time stamp: 0x542bf51f
                Faulting module name: mfc110u.dll, version: 11.0.60610.1, time stamp: 0x51b4fcce
                Exception code: 0xc000041d
                Fault offset: 0x0000000000263204
                Faulting process id: 0x1460
                Faulting application start time: 0xegui.exe0
                Faulting application path: egui.exe1
                Faulting module path: egui.exe2
                Report Id: egui.exe3
                 
                Error: (04/17/2015 08:07:34 PM) (Source: Application Error) (EventID: 1000) (User: )
                Description: Faulting application name: egui.exe, version: 8.0.304.0, time stamp: 0x542bf51f
                Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521eaf24
                Exception code: 0xc0000374
                Fault offset: 0x00000000000c4102
                Faulting process id: 0x1cf8
                Faulting application start time: 0xegui.exe0
                Faulting application path: egui.exe1
                Faulting module path: egui.exe2
                Report Id: egui.exe3
                 
                Error: (04/17/2015 07:09:41 PM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
                Description: Product: Nero Update – Error 1921.Service Nero Update (NAUpdate) could not be stopped.  Verify that you have sufficient privileges to stop system services.
                 
                Error: (04/17/2015 07:07:54 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:34:54Z. Error Code: 0x80041321.
                 
                Error: (04/16/2015 10:47:31 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:34:31Z. Error Code: 0x80041321.
                 
                Error: (04/16/2015 10:33:41 PM) (Source: MsiInstaller) (EventID: 11316) (User: Def-PC)
                Description: Product: Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit – Error 1316. The specified account already exists.
                 
                Error: (04/16/2015 10:15:06 PM) (Source: MsiInstaller) (EventID: 11706) (User: Def-PC)
                Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1706.No valid source could be found for product CorelDRAW Graphics Suite X7 - Draw (x64).  The Windows Installer cannot continue.
                 
                Error: (04/16/2015 10:08:48 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:34:48Z. Error Code: 0x80041321.
                 
                 
                System errors:
                =============
                Error: (04/17/2015 08:16:13 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
                Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
                 
                Error: (04/17/2015 08:16:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
                Description: The Intel(R) PROSet/Wireless Zero Configuration Service service failed to start due to the following error: 
                %%193
                 
                Error: (04/17/2015 08:14:40 PM) (Source: NETLOGON) (EventID: 3095) (User: )
                Description: This computer is configured as a member of a workgroup, not as
                a member of a domain. The Netlogon service does not need to run in this
                configuration.
                 
                Error: (04/17/2015 08:12:36 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
                Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
                %%1056
                 
                Error: (04/17/2015 08:12:26 PM) (Source: DCOM) (EventID: 10010) (User: )
                Description: {9E175B6D-F52A-11D8-B9A5-505054503030}
                 
                Error: (04/17/2015 08:12:23 PM) (Source: DCOM) (EventID: 10010) (User: )
                Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
                 
                Error: (04/17/2015 08:12:05 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
                Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
                 
                Error: (04/17/2015 08:12:05 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
                Description: The Software Protection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
                 
                Error: (04/17/2015 08:12:05 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
                Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
                 
                Error: (04/17/2015 08:11:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
                Description: The WD Backup service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.
                 
                 
                Microsoft Office Sessions:
                =========================
                Error: (04/17/2015 08:22:39 PM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
                Description: Product: Nero Update – Error 1921.Service Nero Update (NAUpdate) could not be stopped.  Verify that you have sufficient privileges to stop system services.(NULL)(NULL)(NULL)(NULL)(NULL)
                 
                Error: (04/17/2015 08:20:44 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: 0x800413212015-05-15T16:34:44Z
                 
                Error: (04/17/2015 08:08:06 PM) (Source: Application Error) (EventID: 1000) (User: )
                Description: egui.exe8.0.304.0542bf51fmfc110u.dll11.0.60610.151b4fccec000041d0000000000263204146001d0790f87f02296C:\Program Files\ESET\ESET Smart Security\egui.exeC:\Program Files\ESET\ESET Smart Security\mfc110u.dllc9114abf-e502-11e4-b23a-74d02b7463ad
                 
                Error: (04/17/2015 08:07:34 PM) (Source: Application Error) (EventID: 1000) (User: )
                Description: egui.exe8.0.304.0542bf51fntdll.dll6.1.7601.18247521eaf24c000037400000000000c41021cf801d0790f72bd5667C:\Program Files\ESET\ESET Smart Security\egui.exeC:\Windows\SYSTEM32\ntdll.dllb5fb9265-e502-11e4-b23a-74d02b7463ad
                 
                Error: (04/17/2015 07:09:41 PM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
                Description: Product: Nero Update – Error 1921.Service Nero Update (NAUpdate) could not be stopped.  Verify that you have sufficient privileges to stop system services.(NULL)(NULL)(NULL)(NULL)(NULL)
                 
                Error: (04/17/2015 07:07:54 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: 0x800413212015-05-15T16:34:54Z
                 
                Error: (04/16/2015 10:47:31 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: 0x800413212015-05-15T16:34:31Z
                 
                Error: (04/16/2015 10:33:41 PM) (Source: MsiInstaller) (EventID: 11316) (User: Def-PC)
                Description: Product: Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit – Error 1316. The specified account already exists.
                (NULL)(NULL)(NULL)(NULL)(NULL)
                 
                Error: (04/16/2015 10:15:06 PM) (Source: MsiInstaller) (EventID: 11706) (User: Def-PC)
                Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1706.No valid source could be found for product CorelDRAW Graphics Suite X7 - Draw (x64).  The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)
                 
                Error: (04/16/2015 10:08:48 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
                Description: 0x800413212015-05-15T16:34:48Z
                 
                 
                CodeIntegrity Errors:
                ===================================
                  Date: 2015-04-12 18:17:22.761
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                  Date: 2015-04-12 18:17:22.714
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                  Date: 2015-04-12 18:17:22.683
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                  Date: 2015-04-12 18:17:22.636
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                  Date: 2015-04-12 18:06:22.402
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                  Date: 2015-04-12 18:06:22.356
                  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
                 
                 
                ==================== Memory info =========================== 
                 
                Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHz
                Percentage of memory in use: 69%
                Total physical RAM: 3981.59 MB
                Available physical RAM: 1213.91 MB
                Total Pagefile: 7961.37 MB
                Available Pagefile: 4643.8 MB
                Total Virtual: 8192 MB
                Available Virtual: 8191.84 MB
                 
                ==================== Drives ================================
                 
                Drive c: () (Fixed) (Total:202.89 GB) (Free:41.9 GB) NTFS
                Drive d: (Hitam) (Fixed) (Total:202.67 GB) (Free:54.09 GB) NTFS
                Drive e: (Putih) (Fixed) (Total:60.1 GB) (Free:23.73 GB) NTFS
                 
                ==================== MBR & Partition Table ==================
                 
                ========================================================
                Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 16E7DD24)
                Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
                Partition 2: (Not Active) - (Size=202.9 GB) - (Type=07 NTFS)
                Partition 3: (Not Active) - (Size=202.7 GB) - (Type=07 NTFS)
                Partition 4: (Not Active) - (Size=60.1 GB) - (Type=07 NTFS)
                 
                ==================== End Of Log ============================

                Ask AI

                AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

                Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI