thanks before.
-deff
10 min read
![]()
Lets run a few scans and see whats going on
Thanks Ken for replied. I really appreciate it.
I have done the scans and your instructions, this is the logs.
Thank you
-Deff
Just a few things to go over.
Its easier for me to evaluate the logs if you just copy and paste them in in lieu of attaching them
Whooa..I just know that things. Its so really bad to keep it up. Thanks anyway for your suggestion.
Well, this is the log and sorry for the inconvenience. Seems to many crack on the log ya ![]()
======================================================
I've done as your suggest about that crack and/or keygen. I realized that was my fault. Thanks for your words Ken. Hopefully, you can help me on these.
Then, this is the log after all :
Thanks for understanding. With the latest threats going around and the damage they do along with stealing personal data using the torrents or any File Sharing is really very dangerous, along with that free program you think your getting. There appears to be an issue with activating Microsoft Office, it it was obtained illegally then that needs to go as well
That must be my thank to you. I always ignore the pottential unwanted program as i needed it, and it changes my point of view now. As you are the trusted one of Malware hunter, i believe in yours. Next time in the future i would be more concern on these. Thanks again.
Whooa, Win32 invalid application doesnt appear at all. Have i fully secure now? What do you think?
From logs, I think i've fully removed Pokki, Mobogenie, and Baidu like in past times, but the logs answer it at all.
here is the logs :
AdwCleaner log
# AdwCleaner v4.201 - Logfile created 16/04/2015 at 19:31:57
# Updated 08/04/2015 by Xplode# Database : 2015-04-15.1 [Server]# Operating system : Windows 7 Ultimate Service Pack 1 (x64)# Username : Defhawk - DEF-PC# Running from : C:\Users\Defhawk\Desktop\adwcleaner_4.201.exe# Option : Cleaning***** [ Services ] ********** [ Files / Folders ] *****Folder Deleted : C:\Users\Defhawk\AppData\Local\pokkiFolder Deleted : C:\Users\Defhawk\AppData\Roaming\FirefoxToolbarFolder Deleted : C:\Users\Defhawk\AppData\Roaming\RHEngFolder Deleted : C:\Users\Defhawk\Documents\MobogenieFolder Deleted : C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgdFile Deleted : C:\Users\Defhawk\daemonprocess.txtFile Deleted : C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\user.js***** [ Scheduled tasks ] ********** [ Shortcuts ] ********** [ Registry ] *****Key Deleted : HKCU\Software\Classes\pokkiKey Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}***** [ Web browsers ] *****-\\ Internet Explorer v11.0.9600.17689-\\ Mozilla Firefox v34.0.5 (x86 en-GB)-\\ Google Chrome v42.0.2311.90-\\ Chromium v*************************AdwCleaner[R0].txt - [1798 bytes] - [16/04/2015 19:14:27]AdwCleaner[S0].txt - [1628 bytes] - [16/04/2015 19:31:57]########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1687 bytes] ##########JRT log :~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Junkware Removal Tool (JRT) by ThisisuVersion: 6.5.5 (04.15.2015:1)OS: Windows 7 Ultimate x64Ran by [removed] on 16-Apr-15 at 19:37:59.05~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Services~~~ Tasks~~~ Registry ValuesSuccessfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL~~~ Registry KeysSuccessfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}~~~ Files~~~ FoldersSuccessfully deleted: [Folder] C:\Users\Defhawk\AppData\Roaming\baidu security~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Scan was completed on 16-Apr-15 at 19:42:13.84End of JRT log~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Malwarebytes Anti-Malware log :
Malwarebytes Anti-Malwarewww.malwarebytes.orgScan Date: 16-Apr-15Scan Time: 7:58:41 PMLogfile:Administrator: YesVersion: 2.00.4.1028Malware Database: v2015.04.16.03Rootkit Database: v2015.03.31.01License: PremiumMalware Protection: EnabledMalicious Website Protection: EnabledSelf-protection: EnabledOS: Windows 7 Service Pack 1CPU: x64File System: NTFSUser: DefhawkScan Type: Threat ScanResult: CompletedObjects Scanned: 380574Time Elapsed: 18 min, 41 secMemory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: EnabledDeep Rootkit Scan: EnabledHeuristics: EnabledPUP: EnabledPUM: EnabledProcesses: 0(No malicious items detected)Modules: 0(No malicious items detected)Registry Keys: 0(No malicious items detected)Registry Values: 0(No malicious items detected)Registry Data: 0(No malicious items detected)Folders: 0(No malicious items detected)Files: 0(No malicious items detected)Physical Sectors: 0(No malicious items detected)(end)
Go ahead and open up FRST, make sure you checkmark Additions , run a new scan and post both new logs please
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015 04Ran by [removed] (administrator) on DEF-PC on 16-04-2015 22:44:08Running from C:\Users\[removed]\Desktop[removed]Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)Internet Explorer Version 11 (Default browser: IE)Boot Mode: NormalTutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/==================== Processes (Whitelisted) =================(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)(Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe(Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe(Intel Corporation) C:\Windows\System32\hkcmd.exe() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe(Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe(cFos Software GmbH) C:\Program Files\cFosSpeed\spd.exe(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe(Microsoft Corporation) C:\Windows\System32\dllhost.exe(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe(AIMP DevTeam) C:\Program Files\AIMP3\AIMP3.exe(VS Revo Group) C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\POWERPNT.EXE==================== Registry (Whitelisted) ==================(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)HKLM\…\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\btvstack.exe [1023104 2012-08-10] (Atheros Commnucations)HKLM\…\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\athbttray.exe [801920 2012-08-10] (Atheros Commnucations)HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585928 2015-01-16] (NVIDIA Corporation)HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [479232 2012-12-15] (Adobe Systems Incorporated)HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStartHKLM\…\Run: [cFosSpeed] => C:\Program Files\cFosSpeed\cFosSpeed.exe [1591744 2015-01-19] (cFos Software GmbH)HKLM\…\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5581888 2014-02-24] (ESET)Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [GoogleChromeAutoLaunch_A9AC9B5C6255D671A633D32EA1A22B00] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [812872 2015-04-14] (Google Inc.)HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3890768 2015-04-13] (Tonec Inc.)HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7451928 2015-03-13] (Piriform Ltd)HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673088 2013-03-14] (Disc Soft Ltd)HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [uTorrent] => C:\Users\Defhawk\AppData\Roaming\uTorrent\uTorrent.exe [1378304 2015-01-23] (BitTorrent Inc.)HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Policies\Explorer: []AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174856 2014-09-14] (NVIDIA Corporation)AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156840 2014-09-14] (NVIDIA Corporation)ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)BootExecute: RegistryDefragBootTime.exeautocheck autochk *==================== Internet (Whitelisted) ====================(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTIONHKU\S-1-5-21-3901189400-636743289-3933302658-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTIONHKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.comHKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.comHKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.comHKLM\Software\Microsoft\Internet Explorer\Main,Local Page =HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearchHKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhomeHKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearchHKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ieSearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =SearchScopes: HKU\S-1-5-21-3901189400-636743289-3933302658-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searBHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-02-21] (Internet Download Manager, Tonec Inc.)BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll No FileBHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)BHO: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> C:\Program Files (x86)\Clover\TabHelper64.dll [2014-01-23] (EJIE Technology)BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll [2015-02-20] (Microsoft Corporation)Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll [2015-02-20] (Microsoft Corporation)Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)Tcpip\Parameters: [DhcpNameServer] 192.168.43.1Tcpip\..\Interfaces\{2E385CBD-E7DB-4717-B418-9B593B66AADC}: [NameServer] 8.26.56.26,8.20.247.20Tcpip\..\Interfaces\{2EE81293-715E-4B59-B7EF-634063A4DE30}: [NameServer] 8.26.56.26,8.20.247.20FireFox:========FF ProfilePath: C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.defaultFF NetworkProxy: "gopher", ""FF NetworkProxy: "gopher_port", 0FF NetworkProxy: "share_proxy_settings", trueFF NetworkProxy: "type", 0FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()FF Plugin: @microsoft.com/GENUINE -> disabled No FileFF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-12-15] (Adobe Systems)FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll [2015-01-09] (Adobe Systems, Inc.)FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-08] (Google)FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)FF Plugin-x32: @microsoft.com/GENUINE -> disabled No FileFF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2014-05-22] (Nitro PDF)FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-12-15] (Adobe Systems)FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-01-20] (Apple Inc.)FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-01-20] (Apple Inc.)FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-01-20] (Apple Inc.)FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-01-20] (Apple Inc.)FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-01-20] (Apple Inc.)FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2014-01-20] (Apple Inc.)FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2014-01-20] (Apple Inc.)FF Extension: Auto Hide IP - C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\Extensions\[removed] [2014-07-20]FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-15]FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-15]FF HKLM\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\ESET\ESET Smart Security\Mozilla ThunderbirdFF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2015-04-13]FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\ESET\ESET Smart Security\Mozilla ThunderbirdFF HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5FF Extension: IDM CC - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5 [2015-04-13]FF HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\Defhawk\AppData\Roaming\IDM\idmmzcc5FF Extension: No Name - C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\extensions\[removed] [Not Found]Chrome:=======CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.703\_platform_specific\win_x86\widevinecdmadapter.dll No FileCHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\PepperFlash\pepflashplayer.dll ()CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewerCHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\internal-nacl-plugin No FileCHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\pdf.dll No FileCHR Plugin: (Internet Download Manager Plugin) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn\6.21.16_0\IDMGCExt.dll No FileCHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)CHR Plugin: (QuickTime Plug-in 7.5.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)CHR Plugin: (Nero Kwik Media Helper) - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)CHR Plugin: (Microsoft Office 2013) - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No FileCHR Plugin: (Microsoft Office 2013) - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)CHR Plugin: (Nitro PDF plugin for Firefox and Chrome) - C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF)CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)CHR Profile: C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\DefaultCHR Extension: (Google Translate) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2014-10-23]CHR Extension: (Xmarks Bookmark Sync) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajpgkpeckebdhofmmjfgcjjiiejpodla [2013-12-16]CHR Extension: (From Dust) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\anelkojiepicmcldgnmkplocifmegpfj [2013-12-16]CHR Extension: (Google Docs) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-20]CHR Extension: (Google Drive) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-20]CHR Extension: (WOT) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2013-11-20]CHR Extension: (YouTube) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-20]CHR Extension: (Adblock Plus) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-20]CHR Extension: (Google Search) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-20]CHR Extension: (Tampermonkey) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-12-16]CHR Extension: (Photo Zoom for Facebook) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2013-11-20]CHR Extension: (AdBlock) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-11-20]CHR Extension: (Bookmark Manager) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-16]CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-07]CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-02]CHR Extension: (IDM Integration Module) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-04-13]CHR Extension: (Google Wallet) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-20]CHR Extension: (Checker Plus for Gmail™) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2013-11-20]CHR Extension: (Gmail) - C:\Users\Defhawk\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-20]CHR HKLM\…\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]CHR HKU\S-1-5-21-3901189400-636743289-3933302658-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crxCHR HKLM-x32\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-03-17]==================== Services (Whitelisted) =================(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)S2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [216906 2012-08-10] (Atheros Commnucations) [File not signed]S4 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [32768 2014-02-07] (Autodesk, Inc.) [File not signed]S4 CDROM_Detect; C:\Program Files\Cyborg Telkomsel Mobile Broadband\WCDMA_Eject.exe [325632 2013-06-08] () [File not signed]R2 cFosSpeedS; C:\Program Files\cFosSpeed\spd.exe [500672 2015-01-19] (cFos Software GmbH)R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [117704 2015-01-09] (Intel Corporation)R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116680 2015-01-09] (Intel Corporation)R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1343408 2014-02-24] (ESET)S4 EMP_UDSA; C:\Program Files (x86)\EPSON Projector\Epson USB Display V1.5\EMP_UDSA.exe [98304 2011-01-06] (SEIKO EPSON CORPORATION) [File not signed]S4 FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [1362426 2014-10-02] (Flexera Software LLC) [File not signed]S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2015-01-16] (NVIDIA Corporation)S2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116736 2013-11-20] (Google Inc.) [File not signed]S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116736 2013-11-20] (Google Inc.) [File not signed]S3 gusvc; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [136192 2011-05-10] (Google) [File not signed]R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)S3 MozillaMaintenance; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [115200 2014-12-15] (Mozilla Foundation) [File not signed]S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [278010 2012-08-23] () [File not signed]R2 NitroDriverReadSpool9; C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe [230920 2014-05-22] (Nitro PDF Software)S2 NitroUpdateService; C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe [417800 2014-05-22] ()R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706312 2015-01-16] (NVIDIA Corporation)S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21838866 2015-01-16] (NVIDIA Corporation) [File not signed]S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1903616 2014-12-18] (Electronic Arts) [File not signed]S4 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-11-26] ()S2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2013-09-13] (arvato digital services llc)S4 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275264 2013-10-09] (Skype Technologies S.A.) [File not signed]R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2014-12-02] (Western Digital Technologies, Inc.)R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [296312 2014-06-02] (Western Digital Technologies, Inc.)R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)S4 ZAtheros Bt&Wlan; Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [327680 2012-08-10] (Atheros) [File not signed]S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3347962 2012-08-23] (Intel® Corporation) [File not signed]==================== Drivers (Whitelisted) ====================(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)S3 ampa; C:\Windows\system32\ampa.sys [15288 2011-12-26] () [File not signed]S3 ampa; C:\Windows\SysWOW64\ampa.sys [12728 2011-12-26] () [File not signed]R3 ATP; C:\Windows\System32\DRIVERS\AsusTP.sys [70416 2015-01-09] (ASUS Corporation)S3 CT_QUALCOMM_U_drv; C:\Windows\System32\DRIVERS\CT_QUALCOMM_U_drv.sys [118016 2009-04-27] (QUALCOMM Incorporated)R3 DptfDevDram; C:\Windows\System32\DRIVERS\DptfDevDram.sys [145640 2015-01-09] (Intel Corporation)R3 DptfDevFan; C:\Windows\System32\DRIVERS\DptfDevFan.sys [50640 2015-01-09] (Intel Corporation)R3 DptfDevGen; C:\Windows\System32\DRIVERS\DptfDevGen.sys [78504 2015-01-09] (Intel Corporation)R3 DptfDevProc; C:\Windows\System32\DRIVERS\DptfDevProc.sys [289744 2015-01-09] (Intel Corporation)R3 DptfManager; C:\Windows\System32\DRIVERS\DptfManager.sys [494296 2015-01-09] (Intel Corporation)R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-11-03] (DT Soft Ltd)R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET)R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [30752 2014-04-07] (EldoS Corporation)R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET)R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET)R3 eppvad_simple; C:\Windows\System32\drivers\EMP_UDAU.sys [23040 2011-01-06] (SEIKO EPSON CORPORATION)S3 esgiguard; C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [14872 2014-01-07] ()R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-01-03] (REALiX™)R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-12-18] (Intel Corporation)R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [17280 2012-08-05] ( )R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-04-16] (Malwarebytes Corporation)R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [129312 2015-03-23] (Intel Corporation)S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19784 2015-01-16] (NVIDIA Corporation)R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()S3 REN2CAP_DRIVER; C:\Windows\System32\drivers\ren2cap.sys [46728 2011-11-07] ()S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [74240 2015-01-09] (Research In Motion Limited)S3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [455240 2013-03-05] (RTS Corporation)R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-12-09] (Duplex Secure Ltd.)U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-04-12] ()U3 avce1f1u; C:\Windows\System32\Drivers\avce1f1u.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero size file/folder)S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X]S3 catchme; \??\C:\Worksnow\catchme.sys [X]S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X]S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]S3 PCFApiUtil; \??\C:\Program Files (x86)\Baidu Security\PC Faster\PCFApiUtil64.sys [X]S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]S3 tsusbhub; system32\drivers\tsusbhub.sys [X]S3 VGPU; System32\drivers\rdvgkmd.sys [X]S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]==================== NetSvcs (Whitelisted) ===================(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)==================== One Month Created Files and Folders ========(If an entry is included in the fixlist, the file\folder will be moved.)2015-04-16 20:24 - 2015-04-16 20:24 - 00001079 _____ () C:\Users\Defhawk\Desktop\Mbam.txt2015-04-16 20:24 - 2015-04-16 19:32 - 00001771 _____ () C:\Users\Defhawk\Desktop\AdwCleaner[S0].txt2015-04-16 19:42 - 2015-04-16 19:42 - 00001267 _____ () C:\Users\Defhawk\Desktop\JRT.txt2015-04-16 19:14 - 2015-04-16 19:32 - 00000000 ____D () C:\AdwCleaner2015-04-16 19:10 - 2015-04-16 19:09 - 02686088 _____ (Thisisu) C:\Users\Defhawk\Desktop\JRT.exe2015-04-16 19:10 - 2015-04-16 19:04 - 02217984 _____ () C:\Users\Defhawk\Desktop\adwcleaner_4.201.exe2015-04-16 17:48 - 2015-04-16 17:48 - 00000127 _____ () C:\Users\Defhawk\Desktop\ckfiles.txt2015-04-16 17:30 - 2015-04-16 17:30 - 00003262 _____ () C:\Windows\System32\Tasks\{1744B18A-8492-42F2-9C76-0E8897CEDBA8}2015-04-15 22:19 - 2015-04-15 22:19 - 00468480 _____ () C:\Users\Defhawk\Desktop\CKScanner.exe2015-04-15 22:10 - 2015-04-15 22:10 - 00107520 ___SH () C:\Users\Defhawk\Documents\Thumbs.db2015-04-15 22:09 - 2015-04-15 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP32015-04-15 21:21 - 2015-04-16 21:17 - 00038039 _____ () C:\Users\Defhawk\Desktop\Addition.txt2015-04-15 21:19 - 2015-04-16 22:45 - 00034007 _____ () C:\Users\Defhawk\Desktop\FRST.txt2015-04-15 21:19 - 2015-04-16 22:44 - 00000000 ____D () C:\FRST2015-04-15 21:19 - 2015-04-16 21:13 - 02097664 _____ (Farbar) C:\Users\Defhawk\Desktop\FRST64.exe2015-04-15 21:17 - 2015-04-15 21:17 - 00001447 _____ () C:\Users\Defhawk\Desktop\aswMBR.txt2015-04-15 21:17 - 2015-04-15 21:17 - 00000512 _____ () C:\Users\Defhawk\Desktop\MBR.dat2015-04-15 21:15 - 2015-04-15 21:15 - 05198336 _____ (AVAST Software) C:\Users\Defhawk\Desktop\aswMBR.exe2015-04-15 19:36 - 2015-04-15 19:38 - 00001131 _____ () C:\Users\Defhawk\Desktop\PTE.lnk2015-04-15 19:20 - 2015-04-15 19:46 - 00000000 ____D () C:\Program Files (x86)\Pro Evolution Soccer 20152015-04-15 19:20 - 2015-04-15 19:20 - 00000902 _____ () C:\Users\Public\Desktop\Pro Evolution Soccer 2015.lnk2015-04-15 10:08 - 2015-04-15 10:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 20132015-04-15 10:01 - 2015-04-15 10:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office2015-04-14 23:01 - 2015-04-15 10:05 - 00000000 ____D () C:\Program Files\Microsoft Office2015-04-14 18:17 - 2015-04-14 18:17 - 00000000 __RHD () C:\MSOCache2015-04-14 18:06 - 2015-04-14 18:06 - 00019570 _____ () C:\Users\Defhawk\Documents\140415.reg2015-04-14 11:59 - 2015-04-16 19:33 - 00004690 _____ () C:\Windows\setupact.log2015-04-14 11:59 - 2015-04-14 11:59 - 00000000 _____ () C:\Windows\setuperr.log2015-04-14 11:58 - 2015-04-16 19:33 - 00024084 _____ () C:\Windows\PFRO.log2015-04-14 01:26 - 2015-04-14 01:26 - 00486050 _____ () C:\Users\Defhawk\Documents\UninstallKey01.reg2015-04-14 01:24 - 2015-04-14 01:24 - 00869656 _____ () C:\Users\Defhawk\Documents\DeletedKey01.reg2015-04-14 00:50 - 2015-04-14 00:50 - 00020224 _____ () C:\Users\Defhawk\Documents\install.txt2015-04-14 00:45 - 2015-04-14 00:45 - 00000000 ____D () C:\Users\Default\AppData\Roaming\IObit2015-04-14 00:45 - 2015-04-14 00:45 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\IObit2015-04-14 00:17 - 2015-04-14 00:17 - 00001932 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Pro 9.lnk2015-04-14 00:17 - 2015-04-14 00:17 - 00001920 _____ () C:\Users\Public\Desktop\Nitro Pro 9.lnk2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files\Nitro2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files\Common Files\Nitro2015-04-14 00:17 - 2015-04-14 00:17 - 00000000 ____D () C:\Program Files (x86)\Nitro2015-04-14 00:17 - 2014-05-22 14:05 - 00029704 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalmon9.dll2015-04-14 00:17 - 2014-05-22 14:05 - 00017928 _____ (Nitro PDF Software) C:\Windows\system32\nitrolocalui9.dll2015-04-13 23:49 - 2015-04-13 23:49 - 00000000 ___SD () C:\Windows\system32\CompatTel2015-04-13 23:49 - 2015-04-13 23:49 - 00000000 ____D () C:\Windows\system32\appraiser2015-04-13 23:44 - 2015-04-13 23:44 - 00001077 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk2015-04-13 23:44 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys2015-04-13 23:14 - 2013-10-02 09:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys2015-04-13 23:14 - 2013-10-02 09:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe2015-04-13 23:14 - 2013-10-02 09:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll2015-04-13 23:14 - 2013-10-02 08:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll2015-04-13 23:14 - 2013-10-02 08:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll2015-04-13 23:14 - 2013-10-02 08:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll2015-04-13 23:14 - 2013-10-02 08:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll2015-04-13 23:14 - 2013-10-02 07:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll2015-04-13 23:14 - 2013-10-02 07:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll2015-04-13 23:14 - 2013-10-02 07:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll2015-04-13 23:14 - 2013-10-02 07:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe2015-04-13 23:14 - 2013-10-02 07:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe2015-04-13 23:14 - 2013-10-02 06:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll2015-04-13 23:14 - 2013-10-02 06:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe2015-04-13 23:14 - 2013-10-02 06:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll2015-04-13 23:14 - 2013-10-02 05:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe2015-04-13 23:14 - 2013-10-02 03:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll2015-04-13 23:14 - 2013-10-02 03:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll2015-04-13 23:13 - 2015-03-25 10:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll2015-04-13 23:13 - 2015-03-25 10:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll2015-04-13 23:13 - 2015-03-25 10:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll2015-04-13 23:13 - 2015-03-25 10:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll2015-04-13 23:13 - 2015-03-25 10:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll2015-04-13 23:13 - 2015-03-25 10:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll2015-04-13 23:13 - 2015-03-25 10:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll2015-04-13 23:13 - 2015-03-25 10:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll2015-04-13 23:13 - 2015-03-25 10:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe2015-04-13 23:13 - 2015-03-25 10:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe2015-04-13 23:13 - 2015-03-25 10:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll2015-04-13 23:13 - 2015-03-25 10:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll2015-04-13 23:13 - 2015-03-25 10:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll2015-04-13 23:13 - 2015-03-25 10:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll2015-04-13 23:13 - 2015-03-25 10:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe2015-04-13 23:13 - 2015-03-25 10:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll2015-04-13 23:12 - 2015-03-23 10:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll2015-04-13 23:12 - 2015-03-23 10:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll2015-04-13 23:12 - 2015-03-23 10:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll2015-04-13 23:12 - 2015-03-23 10:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll2015-04-13 23:12 - 2015-03-23 10:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll2015-04-13 23:12 - 2015-03-23 10:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll2015-04-13 23:12 - 2015-03-23 10:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll2015-04-13 23:12 - 2015-03-23 10:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll2015-04-13 23:12 - 2015-01-28 06:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe2015-04-13 22:51 - 2015-04-13 22:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET2015-04-13 22:38 - 2015-04-13 22:38 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR2015-04-13 22:38 - 2015-04-13 22:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR2015-04-13 22:26 - 2015-04-13 22:26 - 00000000 ____D () C:\ProgramData\ESET2015-04-13 22:19 - 2015-04-13 22:19 - 00055680 _____ () C:\Users\Defhawk\Documents\cc_20150413_221934.reg2015-04-13 20:20 - 2015-04-13 20:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack2015-04-13 20:20 - 2015-04-13 20:20 - 00000000 ____D () C:\Program Files (x86)\K-Lite Codec Pack2015-04-13 20:20 - 2013-10-26 01:00 - 00127488 _____ () C:\Windows\system32\ff_vfw.dll2015-04-13 20:20 - 2013-10-26 01:00 - 00112640 _____ () C:\Windows\SysWOW64\ff_vfw.dll2015-04-13 20:20 - 2013-03-18 00:22 - 03554304 _____ (x264vfw project) C:\Windows\system32\x264vfw64.dll2015-04-13 20:20 - 2013-03-17 23:21 - 03649536 _____ (x264vfw project) C:\Windows\SysWOW64\x264vfw.dll2015-04-13 20:20 - 2012-07-21 17:54 - 00122880 _____ (fccHandler) C:\Windows\SysWOW64\ac3acm.acm2015-04-13 20:20 - 2011-12-08 00:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll2015-04-13 20:20 - 2011-12-08 00:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\lagarith.dll2015-04-13 20:20 - 2011-06-24 21:45 - 00258560 _____ () C:\Windows\system32\xvidvfw.dll2015-04-13 20:20 - 2011-06-24 21:44 - 00243200 _____ () C:\Windows\SysWOW64\xvidvfw.dll2015-04-12 20:53 - 2015-04-12 20:53 - 00000000 ____D () C:\ProgramData\KONAMI2015-04-12 18:38 - 2015-04-12 18:39 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files2015-04-12 18:30 - 2015-04-12 18:30 - 00045107 _____ () C:\ComboFix.txt2015-04-12 17:58 - 2015-04-15 22:49 - 00000000 ____D () C:\Windows\erdnt2015-04-12 16:50 - 2015-04-12 16:50 - 00001072 _____ () C:\Users\Public\Desktop\SMADΔV.lnk2015-04-12 14:46 - 2015-04-12 14:46 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DEF-PC-Windows-7-Ultimate-(64-bit).dat2015-04-12 14:45 - 2015-04-12 14:45 - 00003652 _____ () C:\Windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon2015-04-12 14:45 - 2015-04-12 14:45 - 00002159 _____ () C:\Users\Defhawk\Desktop\Tweaking.com - Windows Repair.lnk2015-04-12 14:39 - 2015-04-12 14:42 - 12849664 _____ () C:\Users\Defhawk\Downloads\tweaking.com_windows_repair_aio_setup.exe2015-04-12 14:34 - 2015-04-12 14:34 - 00000000 ___SD () C:\Windows\SysWOW64\GWX2015-04-12 14:34 - 2015-04-12 14:34 - 00000000 ___SD () C:\Windows\system32\GWX2015-04-12 13:55 - 2015-04-12 15:51 - 00318769 _____ () C:\MGlogs.zip2015-04-12 13:55 - 2015-04-12 13:55 - 00000000 ____D () C:\ProgramData\HitmanPro2015-04-12 13:02 - 2015-04-12 13:34 - 00000000 ____D () C:\ProgramData\RogueKiller2015-04-12 13:02 - 2015-04-12 13:02 - 00035064 _____ () C:\Windows\system32\Drivers\TrueSight.sys2015-04-12 03:12 - 2015-04-12 03:12 - 00000416 _____ () C:\Users\Defhawk\120415backup.reg2015-04-12 01:08 - 2015-04-12 01:08 - 00001646 _____ () C:\Users\Defhawk\Documents\cc_20150412_010800.reg2015-04-12 00:44 - 2011-06-11 05:15 - 05601616 _____ (Microsoft Corporation) C:\Windows\system32\mfc100u.dll2015-04-12 00:44 - 2011-06-11 05:15 - 05574984 _____ (Microsoft Corporation) C:\Windows\system32\mfc100.dll2015-04-12 00:14 - 2010-03-18 19:27 - 00827744 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll2015-04-11 16:46 - 2015-04-11 16:49 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\WCDMA_General2015-04-11 16:46 - 2015-04-11 16:46 - 00000916 _____ () C:\Users\Public\Desktop\Cyborg Telkomsel Mobile Broadband.lnk2015-04-11 16:46 - 2015-04-11 16:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cyborg Telkomsel Mobile Broadband2015-04-11 16:46 - 2015-04-11 16:46 - 00000000 ____D () C:\Program Files\Cyborg Telkomsel Mobile Broadband2015-04-11 16:46 - 2009-04-27 16:33 - 00118016 _____ (QUALCOMM Incorporated) C:\Windows\system32\Drivers\CT_QUALCOMM_U_drv.sys2015-04-11 13:05 - 2015-04-11 13:14 - 45473792 _____ () C:\Windows\system32\config\components.old2015-04-05 13:46 - 2015-04-05 13:47 - 45473792 _____ () C:\Windows\system32\config\COMPONENTS.iobit2015-04-05 01:19 - 2015-04-05 01:19 - 00003342 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup2015-04-05 01:19 - 2015-04-05 01:19 - 00002248 _____ () C:\Users\Defhawk\Desktop\SpyHunter.lnk2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\sh4ldr2015-04-05 01:19 - 2015-04-05 01:19 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group2015-04-05 00:10 - 2015-04-05 00:10 - 76125026 _____ () C:\Users\Defhawk\Downloads\Tomorrowland 2014 - official aftermovie - YouTube.MKV2015-04-03 13:26 - 2015-04-03 13:26 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DEF-PC-Microsoft-Windows-7-Ultimate-(64-bit).dat2015-04-03 13:26 - 2015-04-03 13:26 - 00000000 ____D () C:\RegBackup2015-04-02 21:41 - 2015-04-15 19:20 - 00000914 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro Evolution Soccer 2015.lnk2015-04-01 19:10 - 2013-10-18 15:01 - 00285747 _____ () C:\shldr2015-04-01 19:10 - 2013-10-18 15:01 - 00008192 _____ () C:\shldr.mbr2015-04-01 00:33 - 2015-04-16 22:24 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys2015-04-01 00:33 - 2015-04-01 00:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware2015-04-01 00:33 - 2015-04-01 00:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware2015-04-01 00:33 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys2015-04-01 00:33 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys2015-03-31 22:39 - 2015-03-31 22:39 - 00000000 _____ () C:\autoexec.bat2015-03-31 21:37 - 2015-04-01 00:33 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk2015-03-31 21:37 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys2015-03-23 22:46 - 2015-01-10 15:32 - 00128288 _____ (IObit) C:\Windows\system32\IObitSmartDefragExtension.dll2015-03-23 22:46 - 2014-06-04 15:17 - 00034080 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe2015-03-23 22:46 - 2014-06-04 15:17 - 00021184 _____ (IObit) C:\Windows\system32\Drivers\SmartDefragDriver.sys2015-03-23 22:40 - 2015-03-23 22:40 - 00943832 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys2015-03-23 22:40 - 2015-03-23 22:40 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll2015-03-23 22:39 - 2015-03-23 22:39 - 00129312 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys2015-03-17 20:08 - 2015-03-17 19:53 - 00189912 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys==================== One Month Modified Files and Folders =======(If an entry is included in the fixlist, the file\folder will be moved.)2015-04-16 22:42 - 2013-11-04 00:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\AIMP32015-04-16 22:39 - 2014-04-09 22:53 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\IObit2015-04-16 22:27 - 2015-01-09 17:37 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job2015-04-16 22:23 - 2014-10-02 21:36 - 00000000 ____D () C:\Program Files\Autodesk2015-04-16 22:23 - 2014-10-02 21:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk2015-04-16 22:23 - 2014-10-02 21:30 - 00000000 ____D () C:\ProgramData\Autodesk2015-04-16 22:17 - 2015-02-05 18:12 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57.job2015-04-16 22:17 - 2014-04-01 05:10 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6.job2015-04-16 22:15 - 2014-03-30 02:51 - 00000000 ____D () C:\Program Files\Corel2015-04-16 22:09 - 2013-11-20 00:11 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job2015-04-16 21:59 - 2014-10-02 21:30 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Autodesk2015-04-16 21:55 - 2013-11-05 03:31 - 00000000 ____D () C:\Users\Defhawk\AppData\Local\CrashDumps2015-04-16 21:51 - 2014-10-02 21:36 - 00000000 ____D () C:\Program Files\Common Files\Autodesk Shared2015-04-16 21:39 - 2009-07-14 11:45 - 00021200 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A02015-04-16 21:39 - 2009-07-14 11:45 - 00021200 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A02015-04-16 21:15 - 2013-11-07 01:32 - 01373211 _____ () C:\Windows\WindowsUpdate.log2015-04-16 20:19 - 2009-07-14 12:13 - 00776420 _____ () C:\Windows\system32\PerfStringBackup.INI2015-04-16 19:36 - 2014-06-16 16:13 - 00008192 _____ () C:\Windows\SysWOW64\WDPABKP.dat2015-04-16 19:35 - 2013-11-04 19:58 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\uTorrent2015-04-16 19:34 - 2015-02-05 18:12 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5.job2015-04-16 19:34 - 2014-04-01 05:10 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d.job2015-04-16 19:34 - 2014-03-18 14:56 - 00000000 ____D () C:\Program Files (x86)\SMADAV2015-04-16 19:33 - 2013-11-04 18:29 - 00000000 ____D () C:\Program Files\PowerISO2015-04-16 19:33 - 2009-07-14 12:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT2015-04-16 19:31 - 2013-11-03 10:54 - 00000000 ____D () C:\Users\Defhawk2015-04-16 17:32 - 2014-11-30 03:17 - 00000000 ____D () C:\Users\Defhawk\Downloads\Compressed2015-04-16 12:59 - 2013-11-03 15:05 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\DMCache2015-04-16 07:09 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\Speech2015-04-15 22:55 - 2013-11-04 20:36 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Nitro PDF2015-04-15 22:32 - 2014-04-09 22:55 - 00000000 ____D () C:\ProgramData\IObit2015-04-15 22:29 - 2015-01-09 17:37 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater2015-04-15 22:29 - 2013-11-03 14:20 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe2015-04-15 22:29 - 2013-11-03 14:20 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl2015-04-15 22:18 - 2014-03-31 11:30 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\IDM2015-04-15 22:09 - 2015-01-27 00:03 - 00000722 _____ () C:\Users\Public\Desktop\AIMP3.lnk2015-04-15 22:08 - 2013-11-04 00:02 - 00000000 ____D () C:\Program Files\AIMP32015-04-15 22:03 - 2015-01-03 04:36 - 00002858 _____ () C:\Windows\System32\Tasks\Driver Booster SkipUAC (Defhawk)2015-04-15 21:46 - 2013-11-20 00:25 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk2015-04-15 21:12 - 2014-04-09 22:55 - 00000000 ____D () C:\ProgramData\ProductData2015-04-15 19:45 - 2013-11-05 15:39 - 00000000 ____D () C:\Program Files (x86)\Steam2015-04-15 19:05 - 2013-11-04 18:00 - 00000000 ____D () C:\Users\Defhawk\Documents\Bluetooth Folder2015-04-15 18:40 - 2013-11-04 17:40 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Corel2015-04-15 18:40 - 2013-11-04 17:30 - 00000000 ____D () C:\ProgramData\Corel2015-04-15 18:37 - 2014-03-30 02:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)2015-04-15 13:15 - 2014-12-02 01:16 - 00000000 ____D () C:\Users\Defhawk\Documents\SnowFox Total Video Converter2015-04-15 13:15 - 2014-05-24 20:49 - 00000000 ____D () C:\Users\Defhawk\Documents\Scanned2015-04-15 10:34 - 2009-07-14 11:45 - 05979304 _____ () C:\Windows\system32\FNTCACHE.DAT2015-04-15 10:31 - 2013-11-03 12:30 - 00490216 _____ () C:\Users\Defhawk\AppData\Local\GDIPFONTCACHEV1.DAT2015-04-15 10:09 - 2013-11-04 16:03 - 00000000 ____D () C:\ProgramData\Microsoft Help2015-04-15 10:07 - 2014-05-11 14:29 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\vlc2015-04-15 10:03 - 2009-07-14 09:34 - 00000514 _____ () C:\Windows\win.ini2015-04-15 10:01 - 2009-07-14 10:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared2015-04-15 01:26 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\AppCompat2015-04-15 00:25 - 2009-07-14 14:46 - 00000000 ____D () C:\Windows\CSC2015-04-15 00:20 - 2013-11-04 00:36 - 00003160 _____ () C:\Windows\System32\Tasks\SidebarExecute2015-04-15 00:12 - 2013-11-03 12:33 - 00776420 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI2015-04-14 06:48 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\rescache2015-04-14 01:15 - 2013-11-03 19:08 - 00000000 ____D () C:\ProgramData\USBChargerPlus2015-04-14 01:04 - 2014-05-02 23:18 - 00000000 ____D () C:\Users\Defhawk\AppData\Local\VMware2015-04-14 01:04 - 2009-07-14 10:20 - 00000000 ___RD () C:\Users\Default2015-04-13 23:53 - 2009-07-14 10:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories2015-04-13 23:44 - 2014-10-05 00:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro2015-04-13 23:44 - 2014-10-05 00:33 - 00000000 ____D () C:\Program Files\VS Revo Group2015-04-13 22:40 - 2013-11-03 13:05 - 00000000 ____D () C:\Program Files\WinRAR2015-04-13 22:26 - 2014-12-18 01:40 - 00000000 ____D () C:\Program Files\ESET2015-04-13 22:18 - 2013-11-03 23:35 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk2015-04-13 22:18 - 2013-11-03 23:34 - 00000000 ____D () C:\Program Files\CCleaner2015-04-13 21:06 - 2014-03-31 11:30 - 00000000 ____D () C:\Program Files (x86)\Internet Download Manager2015-04-13 20:42 - 2013-11-03 10:59 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\DAEMON Tools Lite2015-04-13 20:39 - 2013-11-03 15:05 - 00001009 _____ () C:\Users\Defhawk\Desktop\Internet Download Manager.lnk2015-04-13 20:34 - 2013-11-04 18:31 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\PowerISO2015-04-13 19:29 - 2013-11-04 01:47 - 00000000 ____D () C:\Windows\Panther2015-04-12 21:34 - 2014-10-25 03:09 - 00000000 ____D () C:\Users\Defhawk\Downloads\Lamaran2015-04-12 21:34 - 2014-10-16 02:13 - 00000000 ____D () C:\Users\Defhawk\Downloads\Defraggler Professional Edition v2.18 Final - SceneDL2015-04-12 21:34 - 2014-10-03 03:03 - 00000000 ____D () C:\Users\Defhawk\Documents\KONAMI2015-04-12 21:34 - 2014-09-24 03:56 - 00000000 ____D () C:\Users\Defhawk\Desktop\Tor Browser2015-04-12 20:27 - 2014-03-18 14:56 - 00000000 ____D () C:\[Smad-Cage]2015-04-12 18:26 - 2013-11-05 16:27 - 00000000 ____D () C:\ProgramData\TEMP2015-04-12 18:23 - 2009-07-14 09:34 - 00000215 _____ () C:\Windows\system.ini2015-04-12 18:22 - 2009-07-14 09:34 - 00000027 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_1342015-04-12 18:19 - 2009-07-14 09:34 - 41680896 _____ () C:\Windows\system32\config\SYSTEM.bak2015-04-12 18:19 - 2009-07-14 09:34 - 103915520 _____ () C:\Windows\system32\config\SOFTWARE.bak2015-04-12 18:19 - 2009-07-14 09:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak2015-04-12 18:19 - 2009-07-14 09:34 - 00065536 _____ () C:\Windows\system32\config\SAM.bak2015-04-12 18:19 - 2009-07-14 09:34 - 00028672 _____ () C:\Windows\system32\config\SECURITY.bak2015-04-12 16:50 - 2014-12-17 00:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus2015-04-12 11:10 - 2013-11-09 13:35 - 00000000 ____D () C:\Windows\MSSecurityNS2015-04-12 02:01 - 2009-07-14 11:54 - 00000749 ____R () C:\Windows\WindowsShell.Manifest2015-04-12 02:01 - 2009-07-14 10:20 - 00000000 ___RD () C:\Users\Public\Libraries2015-04-12 01:05 - 2013-12-01 23:04 - 00000000 ___RD () C:\Users\Defhawk\Dropbox2015-04-12 01:05 - 2013-12-01 23:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Dropbox2015-04-12 01:04 - 2014-10-31 17:13 - 00000000 ___RD () C:\Users\Defhawk\Google Drive2015-04-12 00:55 - 2014-07-20 22:55 - 00000038 _____ () C:\Windows\sysreg.dat2015-04-12 00:55 - 2008-03-05 07:47 - 00000072 _____ () C:\Windows\anticrash.dat2015-04-12 00:55 - 2008-03-05 07:46 - 00000067 _____ () C:\Windows\hare.dat2015-04-12 00:55 - 2001-10-13 13:11 - 00000084 _____ () C:\Windows\battery.dat2015-04-11 23:44 - 2009-07-14 11:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk2015-04-11 23:28 - 2009-07-14 12:08 - 00032582 _____ () C:\Windows\Tasks\SCHEDLGU.TXT2015-04-11 20:04 - 2013-12-01 23:04 - 00001021 _____ () C:\Users\Defhawk\Desktop\Dropbox.lnk2015-04-11 20:04 - 2013-12-01 23:02 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox2015-04-11 16:57 - 2009-07-14 09:34 - 00000883 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_8682015-04-11 13:14 - 2009-07-14 09:34 - 41680896 _____ () C:\Windows\system32\config\system.old2015-04-11 13:14 - 2009-07-14 09:34 - 103931904 _____ () C:\Windows\system32\config\software.old2015-04-11 13:14 - 2009-07-14 09:34 - 00524288 _____ () C:\Windows\system32\config\default.old2015-04-11 13:14 - 2009-07-14 09:34 - 00065536 _____ () C:\Windows\system32\config\sam.old2015-04-11 13:14 - 2009-07-14 09:34 - 00028672 _____ () C:\Windows\system32\config\security.old2015-04-10 09:44 - 2013-11-17 21:36 - 00000000 ____D () C:\Windows\SysWOW64\My Vaults2015-04-10 09:44 - 2013-11-04 18:04 - 00000000 ____D () C:\ProgramData\Atheros2015-04-10 09:44 - 2013-11-04 00:36 - 00000000 ____D () C:\ProgramData\P4G2015-04-09 18:48 - 2008-03-04 19:57 - 00000338 _____ () C:\Windows\winshell.dat2015-04-08 11:55 - 2013-11-03 10:53 - 00000000 ____D () C:\Recovery2015-04-08 11:55 - 2009-07-14 10:20 - 00000000 ____D () C:\Windows\system32\Msdtc2015-04-07 21:00 - 2009-07-14 12:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD2015-04-05 19:00 - 2009-07-14 14:45 - 00000000 ___RD () C:\Users\Public\Recorded TV2015-04-05 13:12 - 2009-07-14 09:34 - 00000855 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_892015-04-05 12:38 - 2014-04-13 15:06 - 103931904 _____ () C:\Windows\system32\config\SOFTWARE.iodefrag.bak2015-04-05 12:38 - 2014-04-13 15:06 - 00446464 _____ () C:\Windows\system32\config\DEFAULT.iodefrag.bak2015-04-05 12:38 - 2014-04-13 15:06 - 00065536 _____ () C:\Windows\system32\config\SAM.iodefrag.bak2015-04-05 12:38 - 2014-04-13 15:06 - 00028672 _____ () C:\Windows\system32\config\SECURITY.iodefrag.bak2015-04-05 12:37 - 2013-11-09 13:35 - 00000000 ____D () C:\Windows\MSSecurityNi2015-04-05 01:13 - 2009-07-14 09:34 - 00001117 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_8392015-04-01 22:09 - 2013-11-03 17:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 32015-04-01 19:10 - 2013-11-04 18:00 - 00000000 ____D () C:\Program Files (x86)\Bluetooth Suite2015-04-01 06:52 - 2014-09-06 02:46 - 00001908 _____ () C:\Windows\diagwrn.xml2015-04-01 06:52 - 2014-09-06 02:46 - 00001908 _____ () C:\Windows\diagerr.xml2015-04-01 00:33 - 2013-11-05 16:41 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\Malwarebytes2015-03-31 18:59 - 2014-07-20 22:58 - 00000000 ____D () C:\Windows\pss2015-03-23 22:40 - 2013-11-03 11:03 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll2015-03-19 18:15 - 2013-11-24 23:57 - 00000000 ____D () C:\ProgramData\CanonIJPLM==================== Files in the root of some directories =======2013-02-17 10:27 - 2013-02-17 10:27 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll2014-04-12 23:59 - 2015-02-02 20:46 - 0000132 _____ () C:\Users\Defhawk\AppData\Roaming\Adobe PNG Format CC Prefs2013-11-05 02:24 - 2014-01-20 20:07 - 0000132 _____ () C:\Users\Defhawk\AppData\Roaming\Adobe PNG Format CS6 Prefs2014-06-20 19:04 - 2014-06-20 19:04 - 0000024 _____ () C:\Users\Defhawk\AppData\Roaming\temp.ini2014-01-24 21:49 - 2014-01-24 21:49 - 142848334 _____ () C:\Users\Defhawk\AppData\Local\ACCCx2_3_0_322.zip.aamdownload2014-01-24 21:49 - 2014-01-24 21:49 - 0001796 _____ () C:\Users\Defhawk\AppData\Local\ACCCx2_3_0_322.zip.aamdownload.aamd2014-01-20 16:57 - 2014-01-20 17:00 - 0001456 _____ () C:\Users\Defhawk\AppData\Local\Adobe Save for Web 13.0 Prefs2013-11-07 19:53 - 2013-11-07 19:53 - 0000001 _____ () C:\Users\Defhawk\AppData\Local\llftool.4.30.agreement2014-03-18 23:11 - 2014-06-24 23:08 - 0007607 _____ () C:\Users\Defhawk\AppData\Local\Resmon.ResmonCfg2013-11-03 12:51 - 2013-11-03 12:52 - 0009486 _____ () C:\Users\Defhawk\AppData\Local\WiDiSetupLog.20131103.125137.txt2013-11-04 01:00 - 2013-11-04 01:00 - 0010023 _____ () C:\Users\Defhawk\AppData\Local\WiDiSetupLog.20131104.010029.txt2014-03-14 18:49 - 2014-03-14 18:49 - 0000000 _____ () C:\ProgramData\DP45977C.lfl2014-10-02 21:45 - 2014-10-02 21:45 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bcFiles to move or delete:====================C:\Users\Defhawk\120415backup.regC:\Users\Defhawk\200714.regSome content of TEMP:====================C:\Users\Defhawk\AppData\Local\Temp\PidGenX.dllC:\Users\Defhawk\AppData\Local\Temp\Quarantine.exeC:\Users\Defhawk\AppData\Local\Temp\sqlite3.dll==================== Bamital & volsnap Check =================(There is no automatic fix for files that do not pass verification.)C:\Windows\System32\winlogon.exe => File is digitally signedC:\Windows\System32\wininit.exe => File is digitally signedC:\Windows\SysWOW64\wininit.exe => File is digitally signedC:\Windows\explorer.exe => File is digitally signedC:\Windows\SysWOW64\explorer.exe => File is digitally signedC:\Windows\System32\svchost.exe => File is digitally signedC:\Windows\SysWOW64\svchost.exe => File is digitally signedC:\Windows\System32\services.exe => File is digitally signedC:\Windows\System32\User32.dll => File is digitally signedC:\Windows\SysWOW64\User32.dll => File is digitally signedC:\Windows\System32\userinit.exe => File is digitally signedC:\Windows\SysWOW64\userinit.exe => File is digitally signedC:\Windows\System32\rpcss.dll => File is digitally signedC:\Windows\System32\Drivers\volsnap.sys => File is digitally signednointegritychecks: ==> Integrity Checks is disabled <===== ATTENTION!LastRegBack: 2015-04-14 06:20==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-04-2015 04Ran by [removed] at 2015-04-16 22:45:40Running from C:\Users\[removed]\DesktopBoot Mode: Normal============================================================================== Security Center ========================(If an entry is included in the fixlist, it will be removed.)AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}FW: ESET Personal firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}==================== Installed Programs ======================(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)µTorrent (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)Adobe Flash Player 17 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)AIMP3 (HKLM-x32\…\AIMP3) (Version: v3.60.1483, 27.02.2015 - AIMP DevTeam)Akamai NetSession Interface (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Akamai) (Version: - Akamai Technologies, Inc)ASUS Power4Gear Hybrid (HKLM\…\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.2 - ASUS)ASUS Screen Saver (HKLM\…\{0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2}) (Version: 1.0.1 - ASUS)Atheros Bluetooth Suite (64) (HKLM\…\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.150 - Atheros)Atheros Outlook Addin 2010 (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\BB108A893815B64BF41C4574C3324FB7371AA244) (Version: 1.0.0.0 - Microsoft)AutoCAD MEP 2015 Language Pack - English (Version: 7.7.49.0 - Autodesk) HiddenCanon iP2700 series Printer Driver (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2700_series) (Version: - )Canon MP230 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP230_series) (Version: 1.00 - Canon Inc.)CCleaner (HKLM\…\CCleaner) (Version: 5.04 - Piriform)cFosSpeed v10.00 (HKLM\…\cFosSpeed) (Version: 10.00 - cFos Software GmbH, Bonn)CGS17_Setup_x64 (Version: 17.0 - Corel Corporation) HiddenCorel Graphics - Windows Shell Extension (HKLM\…\_{4AB916EE-ABA8-4079-9889-745798B6D809}) (Version: 17.0.0.491 - Corel Corporation)Corel Graphics - Windows Shell Extension (Version: 17.0.491 - Corel Corporation) HiddenCorel Graphics - Windows Shell Extension 32 Bit (Version: 17.0.491 - Corel Corporation) HiddenCorel Graphics - Windows Shell Extension 64 Bit (Version: 16.1.843 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - Capture (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - Common (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - Connect (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - Custom Data (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - Draw (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - EN (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - Filters (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - FontNav (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - IPM Content (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - PHOTO-PAINT (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - Photozoom Plugin (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - Redist (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - Setup Files (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - VBA (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - VideoBrowser (x64) (Version: 17.0 - Corel Corporation) HiddenCorelDRAW Graphics Suite X7 - Writing Tools (x64) (Version: 17.0 - Corel Corporation) HiddenCPUID CPU-Z 1.67.1 (HKLM\…\CPUID CPU-Z_is1) (Version: - )CPUID HWMonitor Pro 1.16 (HKLM\…\CPUID HWMonitorPro_is1) (Version: - )Cyborg Telkomsel Mobile Broadband (HKLM\…\Cyborg Telkomsel Mobile Broadband_is1) (Version: - )Defraggler (HKLM\…\Defraggler) (Version: 2.18 - Piriform)Dropbox (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Dropbox) (Version: 3.4.3 - Dropbox, Inc.)ESET Smart Security (HKLM\…\{5E6F6CE8-1A35-4629-A550-376D4FF74F9B}) (Version: 7.0.317.4 - ESET, spol s r. o.)Google Chrome (HKLM-x32\…\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\…\{90F00673-A276-4A58-B675-B426D39D1E09}) (Version: 15.3.0.0398 - Intel Corporation)Intel® PROSet/Wireless WiFi Software (HKLM\…\{ECE5B218-A086-4E18-A362-D11181681457}) (Version: 15.03.1000.1637 - Intel Corporation)Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)Nitro Pro 9 (HKLM\…\{8C386164-8794-4684-8921-2218199E1020}) (Version: 9.5.1.12 - Nitro)NVIDIA GeForce Experience 2.2.2 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)NVIDIA Graphics Driver 344.11 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.11 - NVIDIA Corporation)NVIDIA HD Audio Driver 1.3.32.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)NVIDIA PhysX System Software 9.14.0702 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) HiddenPacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (Version: 11.0.51108 - Microsoft Corporation) HiddenPro Evolution Soccer 2015 (HKLM-x32\…\UHJvRXZvbHV0aW9uU29jY2VyMjAxNQ==_is1) (Version: 1 - )Revo Uninstaller Pro 3.1.2 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)SanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19755 - Gemalto N.V.)Share64 (Version: 14.1.0.150 - Corel Corporation) HiddenSHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) HiddenSHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) HiddenTeraCopy 2.3 (HKLM\…\TeraCopy_is1) (Version: - Code Sector)WD SmartWare (HKLM\…\{7AE43D6C-B3F1-448D-AD84-1CDC7AC6EBC7}) (Version: 2.4.6.3 - Western Digital Technologies, Inc.)Windows Driver Package - ASUS (ATP) Mouse (01/10/2013 1.0.0.170) (HKLM\…\4A9DE1E9EBC800B7F01739D4DE7363EF6751BDF5) (Version: 01/10/2013 1.0.0.170 - ASUS)WinRAR 5.01 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (Version: 11.0.51108 - Microsoft Corporation) Hidden==================== Custom CLSID (selected items): ==========================(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)CustomCLSID: HKU\S-1-5-21-3901189400-636743289-3933302658-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Defhawk\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)==================== Restore Points =========================15-04-2015 23:06:58 Revo Uninstaller Pro's restore point - Mirillis==================== Hosts content: ==========================(If needed Hosts: directive could be included in the fixlist to reset Hosts.)2009-07-14 09:34 - 2015-04-15 00:17 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts127.0.0.1 localhost==================== Scheduled Tasks (whitelisted) =============(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)Task: {009BBECF-4D78-4564-8F1E-F0F759E7D98F} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)Task: {028F0BEA-2EB0-4634-9C5A-C742BBEB76F4} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-04-16] (AsusTek)Task: {04CBF69D-AA8B-4CE9-B1B3-9BD20D0FE348} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)Task: {1296B0D2-42C3-4623-B9A1-4E90505D4046} - System32\Tasks\{D355A25F-ECA9-4762-B764-3F20E3109E6E} => Firefox.exe http://ui.skype.com/ui/0/6.5.0.158/en/go/help.faq.installer?LastError=1618Task: {1823FA51-0467-43BB-8134-F66123521DBB} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exeTask: {21969B38-4960-4D24-9C8E-D4FC7923C0E0} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-05-17] (ASUSTeK Computer Inc.)Task: {2323B362-6072-4667-9F6D-03380EA0698A} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exeTask: {23CB1AB5-EA73-4F6C-B3B1-AC2D73B58A47} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)Task: {2446A911-78EE-45E8-B33B-A1A2AB6ECBE7} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvcTask: {24EA35E8-6BD4-44F2-A43A-04EF083397C4} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2014-07-21] (Nero AG)Task: {28650E00-EF3E-4295-9668-766B94B05A1B} - System32\Tasks\{5C4A58BA-8354-4A6C-B5BA-5563FB8E2CFF} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P7.3 Self-installer.exe" -d C:\Users\Defhawk\DownloadsTask: {29A3E160-1D0F-4F1E-AC63-92F8DE11939C} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)Task: {36B05A08-31B2-47D7-A8E7-487C2F605BAF} - System32\Tasks\cFosSpeedTR => C:\Program Files\cFosSpeed\CFSTR.exe [2014-04-30] (BB)Task: {3868AD23-3468-4E2D-869F-21217684C3C0} - System32\Tasks\{CB9212D3-94DB-4220-81D8-6F30C28ADE44} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.0 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDMTask: {3BB2B98A-6C8A-402A-97F7-435C3A506140} - System32\Tasks\{56885AD1-C12F-47A4-8D23-F8D89DE66A2E} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.4 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDMTask: {3C9E538E-F64A-4668-A4F9-63D0DE563553} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)Task: {4643B852-23FB-409E-80AB-552789036A2A} - System32\Tasks\{3C92213F-4502-4D35-8B46-1A4E32F4BA49} => C:\Program Files (x86)\Nero\Nero 12\Nero ControlCenter\NCC.exeTask: {4D38440B-AF7B-4872-AA8F-FD15E3657395} - System32\Tasks\Process Lasso Core Engine Only => C:\Program Files\Process Lasso\processgovernor.exe [2014-09-22] (Bitsum LLC)Task: {59E0D626-4AD0-49A6-AA7D-F049B405F411} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-05-15] (ASUS)Task: {6A250B61-775C-4CE8-BB6C-C72F660B0A41} - System32\Tasks\ASUS InstantOn Config => C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [2012-09-24] (ASUS)Task: {7398C9F1-B7EE-485B-8232-331BDAD10A40} - System32\Tasks\{DFF6302E-B746-47CD-8BEE-51B20017A14D} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\Nero\Nero 12\Nero ControlCenter\NCC.exe"Task: {7830917E-F467-40BF-A4CC-28C5876001B1} - System32\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)Task: {7A19FF40-4CB2-4564-B657-91566652CAD0} - System32\Tasks\Process Lasso Management Console (GUI) => C:\Program Files\Process Lasso\processlasso.exe [2014-09-22] (Bitsum LLC)Task: {7BC53F15-B01F-48BE-B2F2-98BD572CE49D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)Task: {8ADC19A6-0DEF-4A99-95F0-47C63D9D103B} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-09-14] (ASUSTek Computer Inc.)Task: {91A3D505-22C3-4B90-B99B-C85C38D2E449} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-12] (Tweaking.com)Task: {A41D758C-732B-41C6-92AE-7DFC80D9AC0F} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2013-10-26] ()Task: {AAFF357B-3E9E-4420-A97D-4FCE425EB44A} - System32\Tasks\{A7CF406F-E389-4603-A99D-96DF4CF8E9F4} => pcalua.exe -a "C:\Users\Defhawk\Downloads\Programs\HoxHud P7.5 Self-installer.exe" -d C:\Users\Defhawk\AppData\Roaming\IDMTask: {B76D7C3A-0FC8-489A-8A0C-5ECB84B303D7} - System32\Tasks\smadav => C:\Program Files (x86)\Smadav\SMΔRTP.exe [2015-02-11] (Smadsoft)Task: {BD5CF776-01FC-4EDB-9D03-4CCC4F138181} - System32\Tasks\{6575FDB1-B2CA-4592-9E2A-89BF71F18C0E} => pcalua.exe -a C:\Users\Defhawk\AppData\Local\Temp\NeroInstallFiles\NERO20120813121238302\setup.exe -d C:\Users\Defhawk\AppData\Local\Temp\NeroInstallFiles\NERO20120813121238302Task: {C237C350-8497-403A-8D80-95FE0FD944D2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd)Task: {C5D6C676-CC24-4621-AD7B-9732B7B680F0} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.)Task: {CA07F7AC-6FE1-4499-98FE-154040652706} - System32\Tasks\{3681AD73-36EC-4764-AE5B-C1F3F90EA6EC} => pcalua.exe -a I:\INSTALL.EXE -d I:\Task: {CBDB467C-BCF1-4935-8BF8-067D5726872E} - \Microsoft Office 15 Sync Maintenance for Def-PC-Defhawk Def-PC No Task File <==== ATTENTIONTask: {CBFCB5FC-B3D6-4376-9A81-66CD907AD0F2} - System32\Tasks\{CB8B5CF1-985B-4406-ADAD-51EFADEEF487} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P6.4 Self-installer.exe" -d C:\Users\Defhawk\DownloadsTask: {CC088725-91F5-4E53-A0F8-03C294D4A9B7} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-01-09] (Realtek Semiconductor)Task: {CFCBA695-6977-4705-BD56-3C34EB5C2074} - System32\Tasks\AutoKMSCustom => C:\Windows\AutoKMS\AutoKMS.exeTask: {D4E9AFF7-C3F6-4145-BD58-3C00BE01063A} - System32\Tasks\Driver Booster SkipUAC (Defhawk) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exeTask: {D74126FC-77A0-46A8-8C0D-C932B95015EB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)Task: {DC3EA95E-CB26-4403-8692-EFCCE0BBFB71} - System32\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)Task: {E9B0D633-DE94-4608-9BAE-16CF90AD732F} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)Task: {F26FA818-8742-4E5E-A115-0AE9166E1AF6} - System32\Tasks\{A4D3F862-ECA0-4659-A604-FA6A3813E901} => pcalua.exe -a "C:\Users\Defhawk\Downloads\HoxHud P7.1 Self-installer.exe" -d C:\Users\Defhawk\DownloadsTask: {F45E28EE-2421-428B-B21B-C618B93C8E09} - System32\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)Task: {F4D0D822-F7C1-4193-A131-9CF4CE2E2BFA} - System32\Tasks\{1744B18A-8492-42F2-9C76-0E8897CEDBA8} => pcalua.exe -a "C:\Program Files (x86)\Xilisoft\Video Converter Ultimate\Uninstall.exe" -d "C:\Program Files (x86)\Xilisoft\Video Converter Ultimate"Task: {FA724455-DB75-41AB-B4C5-FE1150360F34} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)Task: {FBE9499D-F4DD-437E-A393-C21B10C9B005} - System32\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-20] (Google Inc.)Task: {FD95CA08-B3DD-4638-81DA-01076FFF67CE} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeTask: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf4d2df86cec0d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exeTask: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0413499ae19c5.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exeTask: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exeTask: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf4d2df947eaa6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exeTask: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d041349accfb57.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe==================== Loaded Modules (whitelisted) ==============2012-10-01 20:36 - 2012-10-01 20:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll2013-11-17 00:47 - 2012-01-20 14:55 - 00678400 _____ () C:\Program Files\TeraCopy\TeraCopyExt64.dll2013-11-24 23:57 - 2012-03-28 19:49 - 00140456 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE2013-11-03 12:29 - 2014-09-14 04:53 - 00116880 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll2012-10-01 20:36 - 2012-10-01 20:36 - 01286272 _____ () C:\Program Files\Microsoft Office\Office15\PPRESOURCES.DLL2012-10-01 18:56 - 2012-10-01 18:56 - 00240256 _____ () C:\Program Files\Microsoft Office\Office15\IEAWSDC.DLL2013-11-03 11:05 - 2014-09-14 06:48 - 00012104 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll2012-10-01 20:37 - 2012-10-01 20:37 - 06522480 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll2012-03-15 10:48 - 2012-03-15 10:48 - 00221184 _____ () C:\Program Files (x86)\ASUS\VirtualCamera\virtualCamera.ax2015-04-15 21:46 - 2015-04-14 04:55 - 01252680 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\libglesv2.dll2015-04-15 21:46 - 2015-04-14 04:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\libegl.dll2015-04-15 22:08 - 2015-04-15 22:08 - 00218112 _____ () C:\Program Files\AIMP3\System\libsoxr.dll2015-04-15 22:08 - 2015-04-15 22:08 - 00467968 _____ () C:\Program Files\AIMP3\System\Encoders\libFLAC.dll2015-04-15 22:08 - 2015-04-15 22:08 - 01733120 _____ () C:\Program Files\AIMP3\System\Encoders\aimp_libvorbis.dll2015-04-15 22:08 - 2015-04-15 22:08 - 00160840 _____ () C:\Program Files\AIMP3\Plugins\aimp_cdda\aimp_cdda.dll2015-04-15 22:08 - 2015-04-15 22:08 - 00159232 _____ () C:\Program Files\AIMP3\Plugins\aimp_sacd\libsacd.dll2015-04-15 22:08 - 2015-04-15 22:08 - 00026624 _____ () C:\Program Files\AIMP3\Plugins\Aorta\Aorta.dll2015-04-15 22:08 - 2015-04-15 22:08 - 00237568 _____ () C:\Program Files\AIMP3\Plugins\OptimFROG\OptimFROG.dll2015-04-15 22:08 - 2015-04-15 22:08 - 00152648 _____ () C:\Program Files\AIMP3\Plugins\PandemicAnalogMeter\PandemicAnalogMeter.dll==================== Alternate Data Streams (whitelisted) =========(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)AlternateDataStreams: C:\Windows:nlsPreferencesAlternateDataStreams: C:\ProgramData\TEMP:1CE11B51==================== Safe Mode (whitelisted) ===================(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)==================== EXE Association (whitelisted) ===============(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION!==================== Other Areas ============================(Currently there is no automatic fix for this section.)HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Defhawk\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpgDNS Servers: 192.168.43.1==================== MSCONFIG/TASK MANAGER disabled items ==(Currently there is no automatic fix for this section.)MSCONFIG\Services: eventlog => 2MSCONFIG\Services: Wecsvc => 3MSCONFIG\startupreg: EPSON_UD_START =>MSCONFIG\startupreg: Lync =>==================== Accounts: =============================Administrator (S-1-5-21-3901189400-636743289-3933302658-500 - Administrator - Disabled)Defhawk (S-1-5-21-3901189400-636743289-3933302658-1000 - Administrator - Enabled) => C:\Users\DefhawkGuest (S-1-5-21-3901189400-636743289-3933302658-501 - Limited - Disabled)HomeGroupUser$ (S-1-5-21-3901189400-636743289-3933302658-1002 - Limited - Enabled)==================== Faulty Device Manager Devices ================================= Event log errors: =========================Application errors:==================Error: (04/16/2015 10:33:41 PM) (Source: MsiInstaller) (EventID: 11316) (User: Def-PC)Description: Product: Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit – Error 1316. The specified account already exists.Error: (04/16/2015 10:15:06 PM) (Source: MsiInstaller) (EventID: 11706) (User: Def-PC)Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1706.No valid source could be found for product CorelDRAW Graphics Suite X7 - Draw (x64). The Windows Installer cannot continue.Error: (04/16/2015 10:08:48 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:34:48Z. Error Code: 0x80041321.Error: (04/16/2015 09:55:23 PM) (Source: Application Error) (EventID: 1000) (User: )Description: Faulting application name: NitroPDF.exe, version: 9.5.1.12, time stamp: 0x537e324cFaulting module name: NitroPDF.exe, version: 9.5.1.12, time stamp: 0x537e324cException code: 0xc0000005Fault offset: 0x00000000000d2e19Faulting process id: 0xbf4Faulting application start time: 0xNitroPDF.exe0Faulting application path: NitroPDF.exe1Faulting module path: NitroPDF.exe2Report Id: NitroPDF.exe3Error: (04/16/2015 09:15:07 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:35:07Z. Error Code: 0x80041321.Error: (04/16/2015 08:39:14 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:34:14Z. Error Code: 0x80041321.Error: (04/16/2015 08:20:32 PM) (Source: MsiInstaller) (EventID: 11706) (User: Def-PC)Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1706.No valid source could be found for product CorelDRAW Graphics Suite X7 - Draw (x64). The Windows Installer cannot continue.Error: (04/16/2015 08:19:22 PM) (Source: MsiInstaller) (EventID: 11704) (User: Def-PC)Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1704.An installation for Nero Update is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?Error: (04/16/2015 07:39:59 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )Description: Failed to schedule Software Protection service for re-start at 2015-05-15T16:34:59Z. Error Code: 0x80041321.Error: (04/16/2015 06:56:46 PM) (Source: Application Error) (EventID: 1000) (User: )Description: Faulting application name: PES2015.exe, version: 1.0.0.0, time stamp: 0x5450aba2Faulting module name: PES2015.exe, version: 1.0.0.0, time stamp: 0x5450aba2Exception code: 0xc0000005Fault offset: 0x0132b0b6Faulting process id: 0x148Faulting application start time: 0xPES2015.exe0Faulting application path: PES2015.exe1Faulting module path: PES2015.exe2Report Id: PES2015.exe3System errors:=============Error: (04/16/2015 09:18:47 PM) (Source: DCOM) (EventID: 10001) (User: )Description: "C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe" -Embedding193{5DC4F9AD-3A2B-4DF4-AC39-3FF5A19FCF4C}Error: (04/16/2015 07:40:55 PM) (Source: Service Control Manager) (EventID: 7032) (User: )Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Software Protection service, but this action failed with the following error:%%1056Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: )Description: The Windows Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )Description: The Nero Update service terminated unexpectedly. It has done this 1 time(s).Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: )Description: The Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: )Description: The Intel® Centrino® Wireless Bluetooth® + High Speed Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )Description: The Intel(R) Integrated Clock Controller Service - Intel(R) ICCS service terminated unexpectedly. It has done this 1 time(s).Error: (04/16/2015 07:38:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: )Description: The WD Backup service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.Error: (04/16/2015 07:38:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.Error: (04/16/2015 07:38:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: )Description: The WD Drive Manager service terminated unexpectedly. It has done this 1 time(s).Microsoft Office Sessions:=========================Error: (04/16/2015 10:33:41 PM) (Source: MsiInstaller) (EventID: 11316) (User: Def-PC)Description: Product: Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit – Error 1316. The specified account already exists.(NULL)(NULL)(NULL)(NULL)(NULL)Error: (04/16/2015 10:15:06 PM) (Source: MsiInstaller) (EventID: 11706) (User: Def-PC)Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1706.No valid source could be found for product CorelDRAW Graphics Suite X7 - Draw (x64). The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)Error: (04/16/2015 10:08:48 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )Description: 0x800413212015-05-15T16:34:48ZError: (04/16/2015 09:55:23 PM) (Source: Application Error) (EventID: 1000) (User: )Description: NitroPDF.exe9.5.1.12537e324cNitroPDF.exe9.5.1.12537e324cc000000500000000000d2e19bf401d078554ddc427aC:\PROGRA~1\Nitro\PRO9~1\NitroPDF.exeC:\PROGRA~1\Nitro\PRO9~1\NitroPDF.exe9b6834c3-e448-11e4-848f-2cd05ae83598Error: (04/16/2015 09:15:07 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )Description: 0x800413212015-05-15T16:35:07ZError: (04/16/2015 08:39:14 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )Description: 0x800413212015-05-15T16:34:14ZError: (04/16/2015 08:20:32 PM) (Source: MsiInstaller) (EventID: 11706) (User: Def-PC)Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1706.No valid source could be found for product CorelDRAW Graphics Suite X7 - Draw (x64). The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)Error: (04/16/2015 08:19:22 PM) (Source: MsiInstaller) (EventID: 11704) (User: Def-PC)Description: Product: CorelDRAW Graphics Suite X7 - Draw (x64) – Error 1704.An installation for Nero Update is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?(NULL)(NULL)(NULL)(NULL)(NULL)Error: (04/16/2015 07:39:59 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )Description: 0x800413212015-05-15T16:34:59ZError: (04/16/2015 06:56:46 PM) (Source: Application Error) (EventID: 1000) (User: )Description: PES2015.exe1.0.0.05450aba2PES2015.exe1.0.0.05450aba2c00000050132b0b614801d0783910ac1c74C:\Program Files (x86)\Pro Evolution Soccer 2015\PES2015.exeC:\Program Files (x86)\Pro Evolution Soccer 2015\PES2015.exea7b80b74-e42f-11e4-8f32-74d02b7463adCodeIntegrity Errors:===================================Date: 2015-04-12 18:17:22.761Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.Date: 2015-04-12 18:17:22.714Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.Date: 2015-04-12 18:17:22.683Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.Date: 2015-04-12 18:17:22.636Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.Date: 2015-04-12 18:06:22.402Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.Date: 2015-04-12 18:06:22.356Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Worksnow\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.==================== Memory info ===========================Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHzPercentage of memory in use: 62%Total physical RAM: 3981.59 MBAvailable physical RAM: 1480.73 MBTotal Pagefile: 7961.37 MBAvailable Pagefile: 5125.6 MBTotal Virtual: 8192 MBAvailable Virtual: 8191.84 MB==================== Drives ================================Drive c: () (Fixed) (Total:202.89 GB) (Free:44.29 GB) NTFSDrive d: (Hitam) (Fixed) (Total:202.67 GB) (Free:54.09 GB) NTFSDrive e: (Putih) (Fixed) (Total:60.1 GB) (Free:23.73 GB) NTFSDrive h: (Defrino) (Fixed) (Total:802.48 GB) (Free:178.88 GB) NTFSDrive k: (Gionaldo) (Fixed) (Total:129 GB) (Free:117.51 GB) NTFS==================== MBR & Partition Table ==========================================================================Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 16E7DD24)Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)Partition 2: (Not Active) - (Size=202.9 GB) - (Type=07 NTFS)Partition 3: (Not Active) - (Size=202.7 GB) - (Type=07 NTFS)Partition 4: (Not Active) - (Size=60.1 GB) - (Type=07 NTFS)========================================================Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 59DD4884)Partition 1: (Not Active) - (Size=802.5 GB) - (Type=07 NTFS)Partition 2: (Not Active) - (Size=129 GB) - (Type=07 NTFS)==================== End Of Log ============================
Hi Ken, sorry for late post.
Here are the logs :
MiniToolBox by Farbar Version: 14-04-2015Ran by [removed] (administrator) on 17-04-2015 at 20:09:47Running from "C:\Users\Defhawk\Desktop"Microsoft Windows 7 Ultimate Service Pack 1 (X64)Model: K46CB Manufacturer: ASUSTeK COMPUTER INC.Boot Mode: Normal***************************************************************************========================= Flush DNS: ===================================Windows IP ConfigurationSuccessfully flushed the DNS Resolver Cache."Reset IE Proxy Settings": IE Proxy Settings were reset."Reset FF Proxy Settings": Firefox Proxy settings were reset.**** End of log ****
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-04-2015 04Ran by [removed] at 2015-04-17 20:11:19 Run:1Running from C:\Users\[removed]\Desktop[removed]Boot Mode: Normal==============================================Content of fixlist:*****************StartCreateRestorePoint:CloseProcesses:HKU\S-1-5-21-3901189400-636743289-3933302658-1000\…\Run: [uTorrent] => C:\Users\Defhawk\AppData\Roaming\uTorrent\uTorrent.exe [1378304 2015-01-23] (BitTorrent Inc.)HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTIONHKU\S-1-5-21-3901189400-636743289-3933302658-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTIONSearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =FF Extension: No Name - C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\extensions\[removed] [Not Found]2015-04-14 00:45 - 2015-04-14 00:45 - 00000000 ____D () C:\Users\Default\AppData\Roaming\IObit2015-04-14 00:45 - 2015-04-14 00:45 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\IObit2015-03-23 22:46 - 2015-01-10 15:32 - 00128288 _____ (IObit) C:\Windows\system32\IObitSmartDefragExtension.dll2015-03-23 22:46 - 2014-06-04 15:17 - 00034080 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe2015-03-23 22:46 - 2014-06-04 15:17 - 00021184 _____ (IObit) C:\Windows\system32\Drivers\SmartDefragDriver.sys2015-04-16 19:35 - 2013-11-04 19:58 - 00000000 ____D () C:\Users\Defhawk\AppData\Roaming\uTorrent(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exeC:\Program Files (x86)\IObitTask: {0D9DE9B0-CAA3-4E98-A370-E4B4E42DA95A} - System32\Tasks\Uninstaller_SkipUac_Defhawk => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-11-04] (IObit)Task: {2323B362-6072-4667-9F6D-03380EA0698A} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-11-04] (IObit)Task: {3B22EFFE-7D8F-4879-A2C8-14794A75819D} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2014-12-17] (IObit)Task: {49A25C2A-9F8D-4CA2-A1BE-39B1F43EB723} - System32\Tasks\ASC8_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe [2014-11-07] (IObit)Task: {6310B5CD-0E05-4887-AF03-74012DE53E7C} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2014-12-09] (IObit)Task: C:\Windows\Tasks\Uninstaller_SkipUac_Defhawk.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exeCMD: ipconfig /flushdnsHosts:EmptyTemp:End*****************Restore point was successfully created.Processes closed successfully.HKU\S-1-5-21-3901189400-636743289-3933302658-1000\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => value deleted successfully."HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully."HKU\S-1-5-21-3901189400-636743289-3933302658-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.C:\Users\Defhawk\AppData\Roaming\Mozilla\Firefox\Profiles\tk839tcr.default\extensions\[removed] not found.C:\Users\Default\AppData\Roaming\IObit => Moved successfully."C:\Users\Default User\AppData\Roaming\IObit" => File/Directory not found.C:\Windows\system32\IObitSmartDefragExtension.dll => Moved successfully.C:\Windows\system32\SmartDefragBootTime.exe => Moved successfully.C:\Windows\system32\Drivers\SmartDefragDriver.sys => Moved successfully.C:\Users\Defhawk\AppData\Roaming\uTorrent => Moved successfully.C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe => No running process found"C:\Program Files (x86)\IObit" => File/Directory not found.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D9DE9B0-CAA3-4E98-A370-E4B4E42DA95A} => Key not found.C:\Windows\System32\Tasks\Uninstaller_SkipUac_Defhawk not found.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Defhawk => Key not found."HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2323B362-6072-4667-9F6D-03380EA0698A}" => Key deleted successfully."HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2323B362-6072-4667-9F6D-03380EA0698A}" => Key deleted successfully.C:\Windows\System32\Tasks\Uninstaller_SkipUac_Administrator => Moved successfully."HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Administrator" => Key deleted successfully.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B22EFFE-7D8F-4879-A2C8-14794A75819D} => Key not found.C:\Windows\System32\Tasks\Driver Booster Scan not found.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scan => Key not found.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{49A25C2A-9F8D-4CA2-A1BE-39B1F43EB723} => Key not found.C:\Windows\System32\Tasks\ASC8_PerformanceMonitor not found.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASC8_PerformanceMonitor => Key not found.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6310B5CD-0E05-4887-AF03-74012DE53E7C} => Key not found.C:\Windows\System32\Tasks\Driver Booster Update not found.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Update => Key not found.C:\Windows\Tasks\Uninstaller_SkipUac_Defhawk.job not found.========= ipconfig /flushdns =========Windows IP ConfigurationSuccessfully flushed the DNS Resolver Cache.========= End of CMD: =========C:\Windows\System32\Drivers\etc\hosts => Moved successfully.Hosts was reset successfully.EmptyTemp: => Removed 165.8 MB temporary data.The system needed a reboot.==== End of Fixlog 20:12:29 ====
Thank you for helping me out.
- Deff
Great, no need to quote the logs you post, it makes them look smaller and these old eyes need all the help they can get ![]()
Go ahead and open FRST, checkmark Additions , run a new scan and post the logs and let me take one final look
So sorry. Just want to make you easier to take a look.
Well, here they are :
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI