This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I think i am infected by a virus or malware [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

This is my first post here so forgive me if i do anything wrong

It's been almost a week since i started suspecting my Pc. I think i am infected.

SYMPTOMS:

1. My PC is taking waaay to long than usual to boot

2. after running as administrator when there is a box? When i click yes it just sits there with a darkened screen and after 2 mins the program opens

3. Certain programs randomly stop working

4. The Major problem. The mouse and the keyboard freeze as well as the PC. If i leave then for a while then suddenly everything works sometimes the mouse functions but it and th pc freezes after a few clicks

5. Everything takes too long to respond and now i've become familiar with the words "Not Responding"

6. It just came up today but now randomly there's this pop-up "Adobe Reader has stopped working" even though im not using it

 

And I feel like this is important but in this period i have encountered 2 Blue Screens Of Death

I ran a few scans but nothing came up but im pretty sure I am infected

 

And Here's the FRST thingy

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-05-2015
Ran by [removed] (administrator) on HP-PC on 05-05-2015 16:20:14
Running from C:\Users\[removed]\Downloads\Programs
[removed]
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Tonec Inc.) C:\Program Files\Internet Download Manager\IDMan.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [978520 2015-01-30] (Microsoft Corporation)
HKLM\…\Run: [LogMeIn Hamachi Ui] => C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [3978600 2015-03-30] (LogMeIn Inc.)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKU\S-1-5-21-2657731079-1550909148-2805667205-1000\…\Run: [Google Update] => C:\Users\hp\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-09-18] (Google Inc.)
HKU\S-1-5-21-2657731079-1550909148-2805667205-1000\…\Run: [Steam] => C:\Program Files\Steam\steam.exe [2889408 2015-04-14] (Valve Corporation)
HKU\S-1-5-21-2657731079-1550909148-2805667205-1000\…\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [4556048 2015-02-27] (Disc Soft Ltd)
HKU\S-1-5-21-2657731079-1550909148-2805667205-1000\…\MountPoints2: J - J:\setup.exe
HKU\S-1-5-21-2657731079-1550909148-2805667205-1000\…\MountPoints2: L - L:\setup.exe
HKU\S-1-5-18\…\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-08-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files\Internet Download Manager\IDMShellExt.dll [2012-02-08] (Tonec Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-05-04] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-04] (Oracle Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-03-27] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-03-27] (Microsoft Corporation)
ATTENTION: There are more than 99 Catalog9 entries. Turn off the whitelisting to see all the entries. You may check Device Manager for presence of unusual amount of "Microsoft 6to4 Adapter" devices.
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0533B46C-9F80-4C04-9AFD-783CC1F95C1C}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{1ADEC68A-CFFD-4320-9557-9AC9A47D6794}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{217695D6-A1E5-4CE1-827B-7EBFE0759ADE}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{238EC1DE-6C0B-4182-8132-87592608987C}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{3C55266A-82CB-4C72-AB15-20B34BC13018}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{5D0B2752-D0E8-4112-B383-21A70E36F5F0}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{88260D8D-7CF0-44EE-85D8-705829ACFCC3}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{9F2C82C5-DF23-4F9B-94FC-858C579C31D1}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{D7848C44-E0B2-4BE5-9597-FD625FAF1AC5}: [NameServer] 8.8.8.8,8.8.4.4
 
FireFox:
========
FF ProfilePath: C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\6zext2i4.default
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2012-03-17] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] ()
FF Plugin HKU\S-1-5-21-2657731079-1550909148-2805667205-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\hp\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-2657731079-1550909148-2805667205-1000: @talk.google.com/O1DPlugin -> C:\Users\hp\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-2657731079-1550909148-2805667205-1000: @tools.google.com/Google Update;version=3 -> C:\Users\hp\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-2657731079-1550909148-2805667205-1000: @tools.google.com/Google Update;version=9 -> C:\Users\hp\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-2657731079-1550909148-2805667205-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\hp\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-02-24] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Users\hp\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\hp\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF HKU\S-1-5-21-2657731079-1550909148-2805667205-1000\…\SeaMonkey\Extensions: [[removed]] - C:\Users\hp\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\hp\AppData\Roaming\IDM\idmmzcc5 [2014-10-07]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
 
Chrome: 
=======
CHR HomePage: Default -> https://www.google.co.in/
CHR StartupUrls: Default -> "https://www.google.co.in/"
CHR Profile: C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-27]
CHR Extension: (Google Docs) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-27]
CHR Extension: (Google Drive) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-04-27]
CHR Extension: (YouTube) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-04-27]
CHR Extension: (Google Search) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-27]
CHR Extension: (BetaFish Adblocker) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-04-27]
CHR Extension: (Bookmark Manager) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-27]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-28]
CHR Extension: (Into The Mist) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgihmkgobaljfehcadcckdggpeojaadh [2015-04-28]
CHR Extension: (Google Wallet) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-28]
CHR Extension: (Click&Clean; App) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-04-28]
CHR Extension: (Gmail) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-27]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1030928 2015-02-27] (Disc Soft Ltd)
R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1848168 2015-03-30] (LogMeIn Inc.)
R2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [411920 2015-03-30] (LogMeIn, Inc.)
S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation)
S3 TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [762320 2014-11-04] (Tunngle.net GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [25104 2015-03-11] (Disc Soft Ltd)
R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2015-05-04] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation)
R3 PPJoyBus; C:\Windows\System32\DRIVERS\PPJoyBus.sys [15936 2009-11-04] (Deon van der Westhuysen)
R3 PPortJoystick; C:\Windows\System32\DRIVERS\PPortJoy.sys [31808 2009-11-04] (Deon van der Westhuysen)
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [114376 2013-10-23] (Power Software Ltd)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [27136 2009-09-16] (Tunngle.net)
R3 vjoy; C:\Windows\System32\DRIVERS\vjoy.sys [41840 2015-01-05] (Shaul Eizikovich)
S3 hid8101; system32\drivers\hid8101.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-05-05 16:19 - 2015-05-05 16:20 - 00000000 ____D () C:\FRST
2015-05-05 15:26 - 2015-05-05 15:33 - 00000045 _____ () C:\Windows\system32\_WKERNEL.SYL
2015-05-05 15:26 - 2015-05-05 15:33 - 00000000 ____D () C:\Program Files\WinUtilities
2015-05-05 15:26 - 2015-05-05 15:26 - 00000990 _____ () C:\Users\Public\Desktop\WinUtilities.lnk
2015-05-05 15:26 - 2015-05-05 15:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinUtilities
2015-05-05 15:26 - 2010-07-25 22:23 - 01706800 _____ (Microsoft Corporation) C:\Windows\system32\gdiplus.dll
2015-05-05 15:26 - 2010-07-25 22:23 - 00544768 _____ (Stardock Corporation) C:\Windows\system32\wbocx.ocx
2015-05-05 15:26 - 2010-07-25 22:23 - 00258352 _____ (Microsoft Corporation) C:\Windows\system32\unicows.dll
2015-05-05 15:26 - 2010-07-25 22:23 - 00056496 _____ (Stardock.Net, Inc) C:\Windows\system32\wbhelp2.dll
2015-05-05 15:26 - 2010-07-25 22:23 - 00033968 _____ (Neil Banfield) C:\Windows\system32\anim.dll
2015-05-05 15:26 - 2010-07-25 22:23 - 00004608 _____ (Microsoft Corporation) C:\Windows\system32\W95INF32.DLL
2015-05-05 15:26 - 2010-07-25 22:23 - 00002272 _____ (Microsoft Corporation) C:\Windows\system32\W95INF16.DLL
2015-05-04 20:17 - 2015-05-04 21:45 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-04 20:17 - 2015-05-04 20:17 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-04 20:17 - 2015-05-04 20:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-04 20:17 - 2015-05-04 20:17 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-05-04 20:17 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-04 20:17 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-04 20:17 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-04 20:05 - 2015-05-04 20:05 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-05-04 19:27 - 2015-05-04 19:27 - 00000000 __SHD () C:\found.001
2015-05-04 16:02 - 2015-05-04 16:02 - 00001247 _____ () C:\Users\hp\Desktop\Plague Inc Evolved.lnk
2015-05-04 16:02 - 2015-05-04 16:02 - 00001222 _____ () C:\Users\hp\Desktop\Plague Inc Evolved-Scenario Creator.lnk
2015-05-04 16:01 - 2015-05-04 16:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\by Decepticon
2015-05-03 17:52 - 2015-05-04 15:54 - 00000000 ____D () C:\Program Files\by Decepticon
2015-05-03 17:43 - 2015-05-03 17:43 - 00000000 __SHD () C:\found.000
2015-05-03 15:13 - 2015-05-03 15:13 - 00015522 _____ () C:\Users\hp\Downloads\[kickass.to]plague.inc.evolved.0.8.4.2.rus.eng.multi.repack.by.decepticon.torrent
2015-05-03 14:53 - 2015-05-03 14:53 - 00016154 _____ () C:\Users\hp\Downloads\[kickass.to]plague.inc.evolved.v0.7.5.2.click.run.torrent
2015-05-01 15:22 - 2015-05-01 15:40 - 09811520 _____ () C:\Users\hp\Downloads\com.bestcoolfungames.antsmasher-7.73-APK4Fun.com.apk
2015-05-01 15:21 - 2015-05-01 15:21 - 00026943 _____ () C:\Users\hp\Downloads\file.html
2015-04-27 20:39 - 2015-04-27 20:39 - 00880208 _____ (Google Inc.) C:\Users\hp\Downloads\ChromeSetup.exe
2015-04-25 18:29 - 2015-04-25 18:29 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-25 18:04 - 2015-04-25 18:04 - 00011616 _____ () C:\Users\hp\Downloads\[kickass.to]malwarebytes.anti.malware.premium.2.0.2.1012.final.keys.atom.torrent
2015-04-25 17:23 - 2015-04-25 17:25 - 00000000 ____D () C:\AdwCleaner
2015-04-25 17:18 - 2015-04-25 17:21 - 02224640 _____ () C:\Users\hp\Downloads\adwcleaner_4.202.exe
2015-04-25 17:18 - 2015-04-25 17:18 - 00015731 _____ () C:\Users\hp\Downloads\A95J.html
2015-04-24 16:05 - 2015-05-05 15:37 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-24 16:05 - 2015-05-01 17:38 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-24 16:05 - 2015-05-01 17:38 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-24 16:02 - 2015-04-24 16:03 - 00940208 _____ (Adobe Systems Incorporated) C:\Users\hp\Downloads\flashplayer18_uninstall_win.exe
2015-04-24 15:59 - 2015-04-24 16:04 - 17348272 _____ (Adobe Systems Incorporated) C:\Users\hp\Downloads\flashplayer18_install_win_ppapi.exe
2015-04-21 20:51 - 2015-04-21 20:52 - 00858012 _____ () C:\Users\hp\Downloads\enlightenment-110516041102-phpapp02.pptx
2015-04-21 20:40 - 2015-04-21 20:41 - 02023936 _____ () C:\Users\hp\Downloads\Enlightenment and the French Revolution.ppt
2015-04-21 19:23 - 2015-04-21 19:24 - 01298976 _____ () C:\Users\hp\Downloads\H114e (1).PPT
2015-04-21 19:21 - 2015-04-21 19:21 - 00281119 _____ () C:\Users\hp\Downloads\demoTheFrenchRevolutionMagicPortraitLessonandPowerpoint.pptx
2015-04-20 21:44 - 2015-04-20 22:03 - 03453440 _____ () C:\Users\hp\Downloads\ZP922PP.ppt
2015-04-20 21:44 - 2015-04-20 21:45 - 01831936 _____ () C:\Users\hp\Downloads\H114e.PPT
2015-04-20 21:44 - 2015-04-20 21:45 - 00609280 _____ () C:\Users\hp\Downloads\ch20_sec1.ppt
2015-04-20 21:41 - 2015-04-20 21:41 - 00382464 _____ () C:\Users\hp\Downloads\French Revolution.ppt
2015-04-19 20:18 - 2015-04-19 20:18 - 00204496 _____ (Malwarebytes) C:\Users\hp\Downloads\startuplite-setup-1.07.exe
2015-04-15 16:24 - 2015-03-23 08:36 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 16:24 - 2015-03-23 08:36 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 16:24 - 2015-03-23 08:36 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 16:24 - 2015-03-23 08:36 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 16:24 - 2015-03-23 08:36 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 16:24 - 2015-03-23 08:36 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-15 16:24 - 2015-03-23 08:36 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 16:24 - 2015-03-23 08:29 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 15:02 - 2015-03-17 10:31 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-15 15:02 - 2015-03-17 10:31 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 15:02 - 2015-03-17 10:31 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 15:02 - 2015-03-17 10:31 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 15:02 - 2015-03-17 10:29 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 15:02 - 2015-03-17 10:27 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 15:02 - 2015-03-17 10:26 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 15:02 - 2015-03-17 10:26 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 15:02 - 2015-03-17 10:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 15:02 - 2015-03-17 10:26 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 15:02 - 2015-03-17 10:26 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 15:02 - 2015-03-17 10:26 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 15:02 - 2015-03-17 10:23 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 15:02 - 2015-03-17 10:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 15:02 - 2015-03-17 10:20 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 15:02 - 2015-03-17 10:20 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 15:02 - 2015-03-04 09:46 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 15:02 - 2015-03-04 09:40 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 15:00 - 2015-03-27 08:34 - 06030848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 15:00 - 2015-03-27 08:34 - 01267712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 15:00 - 2015-03-27 08:34 - 00981504 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 15:00 - 2015-03-27 08:34 - 00627712 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 15:00 - 2015-03-27 08:34 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2015-04-15 15:00 - 2015-03-27 08:34 - 00428544 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 15:00 - 2015-03-27 08:34 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-04-15 15:00 - 2015-03-27 08:34 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 15:00 - 2015-03-27 08:34 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-04-15 15:00 - 2015-03-27 08:34 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 15:00 - 2015-03-27 08:34 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-04-15 15:00 - 2015-03-27 08:33 - 11026944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 15:00 - 2015-03-27 08:33 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 15:00 - 2015-03-27 08:33 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 15:00 - 2015-03-27 08:33 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 15:00 - 2015-03-27 08:33 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 15:00 - 2015-03-27 08:33 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-04-15 15:00 - 2015-03-27 08:33 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 15:00 - 2015-03-27 08:33 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll
2015-04-15 15:00 - 2015-03-27 08:32 - 01466368 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 15:00 - 2015-03-27 08:32 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 15:00 - 2015-03-27 08:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-04-15 15:00 - 2015-03-27 08:32 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-04-15 15:00 - 2015-03-27 08:03 - 00386048 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 15:00 - 2015-03-27 07:44 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 14:59 - 2015-03-25 08:30 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 14:59 - 2015-03-25 08:30 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 14:59 - 2015-03-25 08:30 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-15 14:59 - 2015-03-25 08:30 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 14:59 - 2015-03-25 08:30 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 14:59 - 2015-03-25 08:30 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 14:59 - 2015-03-25 08:30 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 14:59 - 2015-03-25 08:30 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-15 14:59 - 2015-03-25 08:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 14:59 - 2015-03-25 08:30 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 14:59 - 2015-03-25 08:30 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 14:59 - 2015-03-05 09:36 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 14:57 - 2015-02-25 08:33 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 14:56 - 2015-03-10 08:38 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 14:56 - 2015-03-10 08:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-13 21:08 - 2015-04-13 21:09 - 04041984 _____ () C:\Users\hp\Downloads\ES File Explorer.apk
2015-04-12 15:59 - 2015-04-12 15:59 - 00000000 ____D () C:\Users\hp\AppData\Roaming\3909
2015-04-12 15:46 - 2015-04-12 15:46 - 00019371 _____ () C:\Users\hp\Downloads\[kickass.to]papers.please.v1.1.65.windows.viruz.torrent
2015-04-12 10:12 - 2015-04-12 10:22 - 29913730 _____ () C:\Users\hp\Downloads\com.yodo1.crossyroad-1.0.7-APK4Fun.com.apk
2015-04-12 10:02 - 2015-04-27 18:41 - 00000020 _____ () C:\Users\hp\AppData\Roaming\appdataFr3.bin
2015-04-11 19:41 - 2015-04-11 19:41 - 00008526 _____ () C:\Users\hp\Downloads\[kickass.to]asphalt.8.airborne.v1.8.0i.mod.money.more.android.zone.torrent
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-05-05 15:58 - 2014-08-28 08:55 - 00000000 ____D () C:\Program Files\Google
2015-05-05 15:54 - 2014-09-28 16:01 - 00000000 ____D () C:\Users\hp\AppData\Local\LogMeIn Hamachi
2015-05-05 15:39 - 2014-09-18 15:47 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2657731079-1550909148-2805667205-1000UA.job
2015-05-05 15:39 - 2014-09-09 15:30 - 00000000 ____D () C:\Users\hp\AppData\Roaming\TS3Client
2015-05-05 15:39 - 2014-09-09 15:18 - 00000000 ____D () C:\Users\hp\AppData\Roaming\IDM
2015-05-05 15:39 - 2014-08-30 03:52 - 00000000 ____D () C:\Program Files\Steam
2015-05-05 15:39 - 2014-08-29 03:15 - 00000000 ____D () C:\Users\hp\AppData\Roaming\uTorrent
2015-05-05 15:33 - 2014-08-26 22:17 - 00000000 ____D () C:\Windows\Panther
2015-05-05 15:32 - 2014-11-01 16:07 - 00000000 ____D () C:\Windows\Minidump
2015-05-05 15:32 - 2014-09-26 16:03 - 00000000 ____D () C:\Games
2015-05-05 15:02 - 2014-08-26 21:21 - 01476330 ____N () C:\Windows\WindowsUpdate.log
2015-05-05 14:51 - 2014-10-22 18:26 - 00000000 ____D () C:\Users\hp\AppData\Local\Deployment
2015-05-05 14:51 - 2014-10-22 18:26 - 00000000 ____D () C:\Users\hp\AppData\Local\Apps\2.0
2015-05-05 14:50 - 2009-07-14 10:04 - 00020480 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-05 14:50 - 2009-07-14 10:04 - 00020480 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-05 14:39 - 2009-07-14 10:23 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-04 20:10 - 2014-09-19 14:30 - 00000000 ____D () C:\ProgramData\Oracle
2015-05-04 20:09 - 2014-10-23 11:39 - 00000000 ____D () C:\Program Files\Java
2015-05-04 20:04 - 2014-10-23 11:39 - 00096352 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-05-04 18:39 - 2014-09-18 15:47 - 00000844 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2657731079-1550909148-2805667205-1000Core.job
2015-05-04 16:27 - 2014-09-09 15:18 - 00000000 ____D () C:\Users\hp\AppData\Roaming\DMCache
2015-05-04 15:48 - 2015-01-20 16:05 - 00000000 ___HD () C:\Windows\msdownld.tmp
2015-05-04 15:48 - 2014-11-06 11:14 - 00000000 ____D () C:\Windows\system32\directx
2015-05-03 15:00 - 2014-09-02 17:55 - 00000000 ____D () C:\Users\hp\AppData\Roaming\vlc
2015-04-27 21:01 - 2014-08-28 08:55 - 00000000 ____D () C:\Users\hp\AppData\Local\Google
2015-04-27 16:05 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\AppCompat
2015-04-27 15:54 - 2009-07-14 10:23 - 00032560 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-22 14:42 - 2014-08-30 03:32 - 00000000 ____D () C:\Users\hp\AppData\Roaming\Mozilla
2015-04-21 21:09 - 2014-08-26 21:28 - 00799482 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-19 22:39 - 2015-03-11 20:39 - 00000000 ____D () C:\Windows\rescache
2015-04-17 19:15 - 2014-09-05 20:21 - 00000000 ____D () C:\Users\hp\AppData\Local\Adobe
2015-04-15 20:01 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-15 19:04 - 2014-12-10 11:36 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-15 19:04 - 2014-08-29 03:33 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-15 17:11 - 2014-09-07 13:15 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-15 17:10 - 2014-09-04 18:51 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 17:01 - 2014-09-04 18:51 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-14 20:46 - 2014-09-09 15:18 - 00000000 ____D () C:\Users\hp\Downloads\Compressed
2015-04-14 19:41 - 2015-02-04 20:37 - 00000000 ____D () C:\Users\hp\Downloads\APK's
2015-04-14 19:07 - 2014-08-30 03:52 - 00000000 ____D () C:\Program Files\Common Files\Steam
2015-04-14 11:07 - 2014-08-31 01:19 - 00000000 ____D () C:\Users\hp\AppData\Roaming\Media Player Classic
2015-04-14 11:06 - 2015-03-22 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PPJoy Joystick Driver
2015-04-12 22:28 - 2014-12-03 20:40 - 00000000 ____D () C:\Users\hp\Desktop\Rajesh
 
==================== Files in the root of some directories =======
 
2015-04-12 10:02 - 2015-04-27 18:41 - 0000020 _____ () C:\Users\hp\AppData\Roaming\appdataFr3.bin
2015-02-26 20:21 - 2015-02-26 20:22 - 0004128 _____ () C:\Users\hp\AppData\Roaming\ICARE.LOG
2014-08-30 04:32 - 2015-03-30 17:52 - 0002043 _____ () C:\Users\hp\AppData\Roaming\SpeedRunnersLog.txt
2014-11-17 22:09 - 2014-11-17 22:09 - 0000000 ___SH () C:\Users\hp\AppData\Local\LumaEmu
2015-03-11 18:10 - 2015-03-11 18:10 - 0000017 _____ () C:\Users\hp\AppData\Local\resmon.resmoncfg
2015-04-15 16:57 - 2015-04-15 16:57 - 0011270 _____ () C:\Users\hp\AppData\Local\Temp-log.txt
2014-12-12 15:06 - 2014-12-12 15:06 - 0000000 _____ () C:\Users\hp\AppData\Local\{3E3F38B0-1539-4088-9AE2-4CE667219C01}
 
Files to move or delete:
====================
C:\Users\hp\WagonAdventure.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-05-04 18:15
 
==================== End Of Log ============================
 
 
 
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02-05-2015
Ran by [removed] at 2015-05-05 16:21:25
Running from C:\Users\[removed]\Downloads\Programs
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2657731079-1550909148-2805667205-500 - Administrator - Disabled)
Guest (S-1-5-21-2657731079-1550909148-2805667205-501 - Limited - Disabled)
hp (S-1-5-21-2657731079-1550909148-2805667205-1000 - Administrator - Enabled) => C:\Users\hp
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-2657731079-1550909148-2805667205-1000\…\uTorrent) (Version: 3.4.2.38913 - BitTorrent Inc.)
Adobe Flash Player 18 PPAPI (HKLM\…\Adobe Flash Player PPAPI) (Version: 18.0.0.107 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Battle.net (HKLM\…\Battle.net) (Version:  - Blizzard Entertainment)
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (Version:  - ) Hidden
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (Version: 1.6 - Activision) Hidden
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (Version:  - ) Hidden
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (Version: 1.7 - Activision) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 4.14 - Piriform)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM\…\DAEMON Tools Lite) (Version: 5.0.1.0406 - Disc Soft Ltd)
Don't Starve Together Beta (HKLM\…\Steam App 322330) (Version:  - Klei Entertainment)
Dota 2 (HKLM\…\Steam App 570) (Version:  - Valve)
FTL - Faster Than Light (HKLM\…\FTL - Faster Than Light_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, markfiter)
Google Talk Plugin (HKLM\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Hearthstone (HKLM\…\Hearthstone) (Version:  - Blizzard Entertainment)
Internet Download Manager (HKLM\…\Internet Download Manager) (Version:  - Tonec Inc.)
Java 8 Update 45 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
K-Lite Codec Pack 7.0.0 (Full) (HKLM\…\KLiteCodecPack_is1) (Version: 7.0.0 - )
LAME v3.99.3 (for Windows) (HKLM\…\LAME_is1) (Version:  - )
Life Is Strange (HKLM\…\Life Is Strange_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, spider91)
LogMeIn Hamachi (HKLM\…\LogMeIn Hamachi) (Version: 2.2.0.328 - LogMeIn, Inc.)
LogMeIn Hamachi (Version: 2.2.0.328 - LogMeIn, Inc.) Hidden
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM\…\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM\…\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM\…\{90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version:  - Microsoft)
Microsoft Office Standard 2010 (HKLM\…\Office14.STANDARD) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM\…\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\…\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM\…\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM\…\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Movie Maker (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
NVIDIA Graphics Driver 344.75 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.75 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.32.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.14.0702 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
One Finger Death Punch 1.0 (HKLM\…\One Finger Death Punch 1.0) (Version: 1.0 - Cat-A-Cat)
Parallel Port Joystick (HKLM\…\Parallel Port Joystick) (Version:  - )
Plague Inc Evolved (HKLM\…\Plague Inc Evolved_is1) (Version: 0.8.4.2 - Decepticon)
PowerISO (HKLM\…\PowerISO) (Version: 5.8 - Power Software Ltd)
PS TO PC CONVERTER (HKLM\…\{72FBAFB6-74AD-4F70-932D-5E67DA728430}) (Version: 2007.07.3 - )
SevenZip (HKLM\…\SevenZip) (Version: 9.20 - SevenZip)
Speccy (HKLM\…\Speccy) (Version: 1.28 - Piriform)
SpeedRunners (HKLM\…\Steam App 207140) (Version:  - DoubleDutch Games)
Steam (HKLM\…\Steam) (Version:  - Valve Corporation)
System Requirements Lab CYRI (HKLM\…\{705216C1-BA52-4B16-AFE4-4143B340D62D}) (Version: 6.0.12.6 - Husdawg, LLC)
System Requirements Lab Detection (HKLM\…\{A7905063-C018-44DD-BEF1-230906E95DC3}) (Version: 2.2.1.0 - Husdawg, LLC)
TeamSpeak 3 Client (HKLM\…\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
TeamViewer 9 (HKLM\…\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
The Binding of Isaac Rebirth 1.0 (HKLM\…\The Binding of Isaac Rebirth 1.0) (Version: 1.0 - Games on Cat-A-Cat.Net)
Transformice (HKLM\…\Steam App 335240) (Version:  - Atelier 801)
Tunngle version Tunngle (HKLM\…\Tunngle_is1) (Version: Tunngle - Tunngle.net GmbH)
Twin USB Gamepad (HKLM\…\{0AD1F05D-15F6-476D-A3BE-E3D5E3E0E023}) (Version: 1.00.0000 - yanglx)
Unity Web Player (HKU\S-1-5-21-2657731079-1550909148-2805667205-1000\…\UnityWebPlayer) (Version: 5.0.0f4 - Unity Technologies ApS)
Unturned (HKLM\…\Steam App 304930) (Version:  - Nelson Sexton)
Uplay (HKLM\…\Uplay) (Version: 4.8 - Ubisoft)
USB Vibration Joystick (HKLM\…\{4999B2F1-3E74-409A-B8B5-E94448AA9EA6}) (Version: 2007.08.17 - )
Vector 1.0.4 (HKLM\…\Vector 1.0.4) (Version: 1.0.4 - Cat-A-Cat)
vJoy Device Driver 0.2.0.5 (HKLM\…\{8E31F76F-74C3-47F1-9550-E041EEDC5FBB}_is1) (Version: 0.2.0.5 - Shaul Eizikovich)
VLC media player 2.0.1 (HKLM\…\VLC media player) (Version: 2.0.1 - VideoLAN)
Windows Live Essentials (HKLM\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.01 (32-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
WinUtilities Free Edition 11.23 (HKLM\…\{FC274982-5AAD-4C20-848D-4424A5043010}_is1) (Version: 11.23 - YL Computing, Inc)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
 
==================== Restore Points  =========================
 
04-05-2015 18:23:41 Scheduled Checkpoint
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 07:34 - 2009-06-11 03:09 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {02803212-5151-4EBE-ABA9-C2E3B1236516} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {130BA7A2-181E-4331-BFF9-9D0D86AB1B0E} - \AutoKMS No Task File <==== ATTENTION
Task: {1C62E800-6A52-4B44-9EA0-169EE8E4AD7D} - System32\Tasks\{21F98A66-A9FF-4B4B-9C68-B8F207E0C505} => pcalua.exe -a C:\Users\hp\Downloads\Speedrunners\Setup.exe -d C:\Users\hp\Downloads\Speedrunners
Task: {1F05DD43-4947-4649-8433-FE0160E89315} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {58935742-BA22-4FC7-98BC-7D8CED3BD3FC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-01] (Adobe Systems Incorporated)
Task: {64036C7A-E5B0-439D-84A1-914496C94B31} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2657731079-1550909148-2805667205-1000Core => C:\Users\hp\AppData\Local\Google\Update\GoogleUpdate.exe [2014-09-18] (Google Inc.)
Task: {917CB96F-3644-43F6-90FA-459AEDFBA923} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd)
Task: {B76626CD-8B45-45D2-9FDD-9CFAF0CB509B} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {BD2F95A9-B2C0-4EED-863F-4560FF036A3F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2657731079-1550909148-2805667205-1000UA => C:\Users\hp\AppData\Local\Google\Update\GoogleUpdate.exe [2014-09-18] (Google Inc.)
Task: {D6CBCCF5-B0C8-4BF5-A0F5-8176E631E02E} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {DBC01140-5922-45D3-AAF8-70FC3C4EB37E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {E130E020-3F74-44FF-84AD-A366982DB1D1} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {E92A6E68-BCFE-4402-8C09-11F8C80E917C} - System32\Tasks\Steam_x64-S-2-106-91 => C:\Users\hp\AppData\Roaming\NVIDIA\CODEXi\Steam [2014-12-28] () <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2657731079-1550909148-2805667205-1000Core.job => C:\Users\hp\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2657731079-1550909148-2805667205-1000UA.job => C:\Users\hp\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) ==============
 
2014-12-10 14:39 - 2014-11-13 03:13 - 00106824 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2657731079-1550909148-2805667205-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\hp\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
FirewallRules: [{2AFD853A-AA9E-4CAD-A5BF-703B7CDCE3F9}] => (Allow) C:\Users\hp\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{34A3D3BA-B8A1-476E-9264-2D991C9AC029}] => (Allow) C:\Users\hp\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{1799F1E8-716E-4FCB-85C7-6349ADECB725}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{D0DA8B44-65A0-4045-B512-6C9F0138B5A1}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{BE139DC6-E1A4-4073-9561-68DFFAD00395}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{BEE1C76C-6EE7-4C42-BF35-42302E585B8D}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [{CAD925DA-9023-4BDE-9A73-84EB316066F4}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{F692E5D7-C839-4E6F-A2AA-C3FD3B626094}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{D6945F84-81C2-41D4-A6FB-861530DBF5D1}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [{CB0D1AC6-14FE-4402-ADD4-5272280A6D82}] => (Allow) C:\Program Files\Steam\SteamApps\common\SpeedRunners\SpeedRunners.exe
FirewallRules: [{5C733FB5-DA63-4786-9800-B617DD41893E}] => (Allow) C:\Program Files\Steam\SteamApps\common\SpeedRunners\SpeedRunners.exe
FirewallRules: [{8CF652D4-265E-4B14-A03F-1029AAFCB35D}] => (Allow) C:\Program Files\Steam\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{DCA744A4-6EC7-4B50-BF53-98903E9F6E31}] => (Allow) C:\Program Files\Steam\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{1A0C53B5-9F71-4C2D-B0B4-6C6DB7EE81E3}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{D9A86907-613D-4EC3-9925-30113B098D57}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{B73EC019-FC00-480D-B576-FE2D21AA02F6}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{2813E21C-74A2-4DB1-A2A2-A27E5BF99A3A}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{81C02C6C-B248-4499-AFBB-4C2DF3CEAD64}] => (Allow) C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE
FirewallRules: [{6EEDB5FA-C568-49C3-8430-3190257C97D4}] => (Allow) C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE
FirewallRules: [{716E2A54-3F9B-40F5-8E3F-0C7BCC72BADC}] => (Allow) C:\Program Files\Microsoft Office\Office14\outlook.exe
FirewallRules: [{4C53FDE2-E03D-4B47-A119-1CBB33E9512F}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{F098875A-6E1E-4642-B6AD-7D53838B89FA}] => (Allow) C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{DB9C7DCB-5AAD-4D32-A92A-62FB057DEE84}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{29AB3576-F0FE-4DD3-B139-BDDE1B10BD90}] => (Allow) LPort=2869
FirewallRules: [{1EF92748-EBA5-4A00-A112-50ABD6942B37}] => (Allow) LPort=1900
FirewallRules: [{0817A80E-9D3A-4875-9B75-3091A1A854E9}] => (Allow) C:\Program Files\Tunngle\TnglCtrl.exe
FirewallRules: [{485EC67E-4F81-4B87-AEAF-6D454E90B193}] => (Allow) C:\Program Files\Tunngle\TnglCtrl.exe
FirewallRules: [{BA357C38-4FBF-4AEA-A769-0D4E01CFAE39}] => (Allow) C:\Program Files\Tunngle\Tunngle.exe
FirewallRules: [{148CF488-B1D2-4CBE-8690-0D3FE20A3DD9}] => (Allow) C:\Program Files\Tunngle\Tunngle.exe
FirewallRules: [TCP Query User{9A5B2102-C708-4685-9389-B9B35056E627}G:\battle chess\yang-0.91-win32\yang.exe] => (Allow) G:\battle chess\yang-0.91-win32\yang.exe
FirewallRules: [UDP Query User{42186863-A791-4E51-A73D-9881BB85111C}G:\battle chess\yang-0.91-win32\yang.exe] => (Allow) G:\battle chess\yang-0.91-win32\yang.exe
FirewallRules: [{EDD73B33-013A-451C-A350-76DF1B217A67}] => (Allow) C:\Program Files\Battle.net\Battle.net.exe
FirewallRules: [{777BFF45-8C17-4FDB-81DC-607EC6F393FB}] => (Allow) C:\Program Files\Battle.net\Battle.net.exe
FirewallRules: [{7804DECF-52C3-4427-9360-F1E9A430A41D}] => (Allow) C:\Program Files\Hearthstone\Hearthstone.exe
FirewallRules: [{6132E7E6-8793-4DE1-8A44-BAF0A51FF8C1}] => (Allow) C:\Program Files\Hearthstone\Hearthstone.exe
FirewallRules: [{C09A4F9C-CFC2-452C-AA5F-9050B20452D3}] => (Allow) C:\Program Files\Steam\SteamApps\common\Transformice\Transformice.exe
FirewallRules: [{9746578C-0714-430B-98E0-1EB7C4FB11D5}] => (Allow) C:\Program Files\Steam\SteamApps\common\Transformice\Transformice.exe
FirewallRules: [{7614864A-9AC5-44E8-A178-45DE62EC4AA2}] => (Allow) C:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe
FirewallRules: [{30524C79-364A-42B8-8313-2A3E699745CD}] => (Allow) C:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/05/2015 04:18:58 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1542) (User: NT AUTHORITY)
Description: Windows cannot load classes registry file.
 DETAIL - An I/O operation initiated by the registry failed unrecoverably. The registry could not read in, or write out, or flush, one of the files that contain the system's image of the registry.
 
Error: (05/05/2015 04:18:58 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT AUTHORITY)
Description: Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights. 
 
 DETAIL - An I/O operation initiated by the registry failed unrecoverably. The registry could not read in, or write out, or flush, one of the files that contain the system's image of the registry.
 for C:\Users\hp\AppData\Local\Microsoft\Windows\\UsrClass.dat
 
Error: (05/05/2015 04:18:04 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1542) (User: NT AUTHORITY)
Description: Windows cannot load classes registry file.
 DETAIL - An I/O operation initiated by the registry failed unrecoverably. The registry could not read in, or write out, or flush, one of the files that contain the system's image of the registry.
 
Error: (05/05/2015 04:18:04 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT AUTHORITY)
Description: Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights. 
 
 DETAIL - An I/O operation initiated by the registry failed unrecoverably. The registry could not read in, or write out, or flush, one of the files that contain the system's image of the registry.
 for C:\Users\hp\AppData\Local\Microsoft\Windows\\UsrClass.dat
 
Error: (05/05/2015 04:14:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AcroRd32.exe, version: 11.0.10.32, time stamp: 0x547e9779
Faulting module name: AcroRd32.dll, version: 11.0.10.32, time stamp: 0x547e9765
Exception code: 0xc0000005
Fault offset: 0x00019b85
Faulting process id: 0xed8
Faulting application start time: 0xAcroRd32.exe0
Faulting application path: AcroRd32.exe1
Faulting module path: AcroRd32.exe2
Report Id: AcroRd32.exe3
 
Error: (05/05/2015 04:13:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AcroRd32.exe, version: 11.0.10.32, time stamp: 0x547e9779
Faulting module name: AcroRd32.dll, version: 11.0.10.32, time stamp: 0x547e9765
Exception code: 0xc0000005
Fault offset: 0x00019b85
Faulting process id: 0x8a0
Faulting application start time: 0xAcroRd32.exe0
Faulting application path: AcroRd32.exe1
Faulting module path: AcroRd32.exe2
Report Id: AcroRd32.exe3
 
Error: (05/05/2015 04:12:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AcroRd32.exe, version: 11.0.10.32, time stamp: 0x547e9779
Faulting module name: AcroRd32.dll, version: 11.0.10.32, time stamp: 0x547e9765
Exception code: 0xc0000005
Fault offset: 0x00019b85
Faulting process id: 0xa44
Faulting application start time: 0xAcroRd32.exe0
Faulting application path: AcroRd32.exe1
Faulting module path: AcroRd32.exe2
Report Id: AcroRd32.exe3
 
Error: (05/05/2015 03:38:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AcroRd32.exe, version: 11.0.10.32, time stamp: 0x547e9779
Faulting module name: AcroRd32.dll, version: 11.0.10.32, time stamp: 0x547e9765
Exception code: 0xc0000005
Fault offset: 0x00019b85
Faulting process id: 0xee0
Faulting application start time: 0xAcroRd32.exe0
Faulting application path: AcroRd32.exe1
Faulting module path: AcroRd32.exe2
Report Id: AcroRd32.exe3
 
Error: (05/05/2015 03:37:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AcroRd32.exe, version: 11.0.10.32, time stamp: 0x547e9779
Faulting module name: AcroRd32.dll, version: 11.0.10.32, time stamp: 0x547e9765
Exception code: 0xc0000005
Fault offset: 0x00019b85
Faulting process id: 0xd98
Faulting application start time: 0xAcroRd32.exe0
Faulting application path: AcroRd32.exe1
Faulting module path: AcroRd32.exe2
Report Id: AcroRd32.exe3
 
Error: (05/05/2015 03:36:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AcroRd32.exe, version: 11.0.10.32, time stamp: 0x547e9779
Faulting module name: AcroRd32.dll, version: 11.0.10.32, time stamp: 0x547e9765
Exception code: 0xc0000005
Fault offset: 0x00019b85
Faulting process id: 0xb90
Faulting application start time: 0xAcroRd32.exe0
Faulting application path: AcroRd32.exe1
Faulting module path: AcroRd32.exe2
Report Id: AcroRd32.exe3
 
 
System errors:
=============
Error: (05/05/2015 04:18:58 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (05/05/2015 04:18:56 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (05/05/2015 04:18:54 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (05/05/2015 04:18:52 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (05/05/2015 04:18:50 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (05/05/2015 04:18:48 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (05/05/2015 04:18:46 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (05/05/2015 04:18:44 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (05/05/2015 04:18:41 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (05/05/2015 04:18:39 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
 
Microsoft Office Sessions:
=========================
Error: (05/05/2015 04:18:58 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1542) (User: NT AUTHORITY)
Description: An I/O operation initiated by the registry failed unrecoverably. The registry could not read in, or write out, or flush, one of the files that contain the system's image of the registry.
 
Error: (05/05/2015 04:18:58 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT AUTHORITY)
Description: An I/O operation initiated by the registry failed unrecoverably. The registry could not read in, or write out, or flush, one of the files that contain the system's image of the registry.
C:\Users\hp\AppData\Local\Microsoft\Windows\\UsrClass.dat
 
Error: (05/05/2015 04:18:04 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1542) (User: NT AUTHORITY)
Description: An I/O operation initiated by the registry failed unrecoverably. The registry could not read in, or write out, or flush, one of the files that contain the system's image of the registry.
 
Error: (05/05/2015 04:18:04 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT AUTHORITY)
Description: An I/O operation initiated by the registry failed unrecoverably. The registry could not read in, or write out, or flush, one of the files that contain the system's image of the registry.
C:\Users\hp\AppData\Local\Microsoft\Windows\\UsrClass.dat
 
Error: (05/05/2015 04:14:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AcroRd32.exe11.0.10.32547e9779AcroRd32.dll11.0.10.32547e9765c000000500019b85ed801d0872076ead41cC:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exeC:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.dllb4a5ae12-f313-11e4-bb70-0016e69f9538
 
Error: (05/05/2015 04:13:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AcroRd32.exe11.0.10.32547e9779AcroRd32.dll11.0.10.32547e9765c000000500019b858a001d08720495c2300C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exeC:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.dll8716fcf6-f313-11e4-bb70-0016e69f9538
 
Error: (05/05/2015 04:12:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AcroRd32.exe11.0.10.32547e9779AcroRd32.dll11.0.10.32547e9765c000000500019b85a4401d0872021bc7821C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exeC:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.dll5f775217-f313-11e4-bb70-0016e69f9538
 
Error: (05/05/2015 03:38:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AcroRd32.exe11.0.10.32547e9779AcroRd32.dll11.0.10.32547e9765c000000500019b85ee001d0871b7aeccfc3C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exeC:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.dllb8ac6e6d-f30e-11e4-bb70-0016e69f9538
 
Error: (05/05/2015 03:37:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AcroRd32.exe11.0.10.32547e9779AcroRd32.dll11.0.10.32547e9765c000000500019b85d9801d0871b4e143641C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exeC:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.dll8d003d37-f30e-11e4-bb70-0016e69f9538
 
Error: (05/05/2015 03:36:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AcroRd32.exe11.0.10.32547e9779AcroRd32.dll11.0.10.32547e9765c000000500019b85b9001d0871b1cc3f2bbC:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exeC:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.dll616ca241-f30e-11e4-bb70-0016e69f9538
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ 64 Processor 3500+
Percentage of memory in use: 52%
Total physical RAM: 2047.55 MB
Available physical RAM: 972.2 MB
Total Pagefile: 4095.11 MB
Available Pagefile: 2594.92 MB
Total Virtual: 2047.88 MB
Available Virtual: 1890.54 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:65.79 GB) (Free:16.87 GB) NTFS
Drive d: (LOCAL DISK) (Fixed) (Total:18.81 GB) (Free:1.84 GB) FAT32
Drive e: () (Fixed) (Total:24.43 GB) (Free:3.15 GB) FAT32
Drive f: () (Fixed) (Total:15.03 GB) (Free:7.84 GB) FAT32
Drive g: () (Fixed) (Total:14.37 GB) (Free:2.22 GB) NTFS
Drive h: (New Volume) (Fixed) (Total:10.48 GB) (Free:3.24 GB) NTFS
Drive k: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 13991398)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=65.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=72.7 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=10.5 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================

:welcome:

 

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Please Run this program only once
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
  • CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
    c:\program files\steam\steamapps\common\don't starve together beta\data\anim\nightmare_crack_ruins.zip
    c:\program files\steam\steamapps\common\don't starve together beta\data\anim\nightmare_crack_ruins_fx.zip
    c:\program files\steam\steamapps\common\don't starve together beta\data\anim\nightmare_crack_upper.zip
    c:\program files\steam\steamapps\common\don't starve together beta\data\anim\nightmare_crack_upper_fx.zip
    c:\program files\steam\steamapps\common\don't starve together beta\data\levels\textures\noise_cracked.tex
    c:\program files\steam\steamapps\common\don't starve together beta\data\scripts\components\wisecracker.lua
    scanner sequence 3.FI.11.VNNAFZ
     —– EOF —– 

    A couple of things to go over

     

    WinUtilities <–Sometimes using programs like this especially the registry cleaner can cause problems if you remove the wrong entry or entries, its best just to use the tools that are built into windows, there a lot safer

     

    The torrents and [kickass to] <– are the quickest way to infect your system , not all but the greater majority of files and programs downloaded this way are infected

     

    Lets clean you up some and go from there

     

     

     
    -AdwCleaner-by Xplode
     
    Click on this link to download : ADWCleaner To your Desktop
    Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
    Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
     
     
    Do not click on any links in the top Advertisment.
     
    [external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
     
    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Scan.
    • After the scan is complete click on "Clean"
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the content of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.
    •  
       
      ===============================================================================
       
       
      [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
      • Shut down your protection software now to avoid potential conflicts.
      • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
      • The tool will open and start scanning your system.
      • Please be patient as this can take a while to complete depending on your system's specifications.
      • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
      • Post the contents of JRT.txt into your next message.
      •  
         
         
        ===============================================================================
         
        Download Malwarebytes' Anti-Malware  to your desktop. <———
         
        • Windows XP : Double click on the icon to run it.
        • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
        •  
          [external image: MBAM2010601022_zpsyvzbaddn.jpg]
           
          • On the Dashboard click on Update Now
          • Go to the Setting Tab
          • Under Setting go to Detection and Protection
          • Under PUP and PUM make sure both are set to show Treat Detections as Malware
          • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
          • Then on the Dashboard click on Scan
          • Make sure to select THREAT SCAN
          • Then click on Scan
          • When the scan is finished and the log pops up…select Copy to Clipboard
          • Please paste the log back into this thread for review
          • Exit Malwarebytes
          • MALWAREBYTS SCAN

            Malwarebytes Anti-Malware
            www.malwarebytes.org
             
            Scan Date: 5/10/2015
            Scan Time: 1:46:29 PM
            Logfile: 
            Administrator: Yes
             
            Version: 2.01.6.1022
            Malware Database: v2015.05.10.02
            Rootkit Database: v2015.04.21.01
            License: Premium
            Malware Protection: Enabled
            Malicious Website Protection: Enabled
            Self-protection: Disabled
             
            OS: Windows 7 Service Pack 1
            CPU: x86
            File System: NTFS
            User: hp
             
            Scan Type: Threat Scan
            Result: Completed
            Objects Scanned: 303947
            Time Elapsed: 46 min, 42 sec
             
            Memory: Enabled
            Startup: Enabled
            Filesystem: Enabled
            Archives: Enabled
            Rootkits: Enabled
            Heuristics: Enabled
            PUP: Enabled
            PUM: Enabled
             
            Processes: 0
            (No malicious items detected)
             
            Modules: 0
            (No malicious items detected)
             
            Registry Keys: 0
            (No malicious items detected)
             
            Registry Values: 0
            (No malicious items detected)
             
            Registry Data: 0
            (No malicious items detected)
             
            Folders: 0
            (No malicious items detected)
             
            Files: 0
            (No malicious items detected)
             
            Physical Sectors: 0
            (No malicious items detected)
             
             

             

            (end)
             
            ADWARE CLEANER
            # AdwCleaner v4.203 - Logfile created 10/05/2015 at 11:10:59
            # Updated 30/04/2015 by Xplode
            # Database : 2015-04-30.2 [Local]
            # Operating system : Windows 7 Ultimate Service Pack 1 (x86)
            # Username : hp - HP-PC
            # Running from : C:\Users\hp\Downloads\adwcleaner_4.203.exe
            # Option : Cleaning
             
            ***** [ Services ] *****
             
             
            ***** [ Files / Folders ] *****
             
             
            ***** [ Scheduled tasks ] *****
             
             
            ***** [ Shortcuts ] *****
             
             
            ***** [ Registry ] *****
             
             
            ***** [ Web browsers ] *****
             
            -\\ Internet Explorer v8.0.7601.18806
             
             
            -\\ Mozilla Firefox v
             
             
            -\\ Google Chrome v42.0.2311.135
             
            [C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
            [C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
            [C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
             
            *************************
             
            AdwCleaner[R1].txt - [1189 bytes] - [10/05/2015 11:04:47]
            AdwCleaner[S1].txt - [1120 bytes] - [10/05/2015 11:10:59]
             
            ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1179  bytes] ##########
             
            JUNKWARE REMOVAL TOOL
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            Junkware Removal Tool (JRT) by Thisisu
            Version: 6.7.0 (05.09.2015:1)
            OS: Windows 7 Ultimate x86
            Ran by [removed] on Sun 05/10/2015 at 11:27:50.03
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
             
             
             
             
            ~~~ Services
             
             
             
            ~~~ Tasks
             
             
             
            ~~~ Registry Values
             
             
             
            ~~~ Registry Keys
             
             
             
            ~~~ Files
             
             
             
            ~~~ Folders
             
             
             
             
             
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            Scan was completed on Sun 05/10/2015 at 11:30:15.04
            End of JRT log
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
             

            Not much removed, thats good

             

            Running from C:\Users\[removed]\Downloads\Programs  <–our tools and scanners work more efficiently when run from the Desktop in lieu of being buried in some folder, so go to your Downloads folder and look for FRST, right click on it and select CUT, then come back to your Desktop and right click on a blank space and select PASTE, then we will have FRST exactly where we want it to be. 

             

            Download ComboFix from one of these locations:
             
            Link 1
            Link 2
             
             
            * IMPORTANT !!! Save ComboFix.exe to your Desktop
             
             
            • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
            • See this Link  for programs that need to be disabled and instruction on how to disable them.
            • Remember to re-enable them when we're done.
             
             
            • Double click on ComboFix.exe & follow the prompts.
             
            For Windows XP Users
             
            • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. 
             
             
            • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
            •  
             
            **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
             
             

            [external image: RC1.png]

             
             
            Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

            [external image: RC2-1.png]

             
            Click on Yes, to continue scanning for malware.
             
            When finished, it shall produce a log for you.  Please include the C:\ComboFix.txt in your next reply.
             
            *If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

            Wow It deleted almost 3Gb worth of files from my C drive. Hoping it is for the best. (Thank you by the way for sticking with me for so long :D)

             

            Here's the log

             

            ComboFix 15-05-09.01 - hp 05/10/2015  17:19:17.1.1 - x86
            Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.2048.1032 [GMT 5.5:30]
            Running from: c:\users\[removed]\Desktop\ComboFix.exe
            AV: Microsoft Security Essentials *Disabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
            SP: Microsoft Security Essentials *Disabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
            SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
            .
            .
            (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            c:\users\hp\AppData\Roaming\Love
            c:\users\hp\AppData\Roaming\Love\mari0\options.txt
            c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\6zext2i4.default\extensions\staged\[removed]
            c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\6zext2i4.default\extensions\staged\[removed]\bootstrap.js
            c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\6zext2i4.default\extensions\staged\[removed]\chrome.manifest
            c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\6zext2i4.default\extensions\staged\[removed]\content\bg.js
            c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\6zext2i4.default\extensions\staged\[removed]\install.rdf
            c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\6zext2i4.default\extensions\staged\[removed]
            c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\6zext2i4.default\extensions\staged\[removed]\bootstrap.js
            c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\6zext2i4.default\extensions\staged\[removed]\chrome.manifest
            c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\6zext2i4.default\extensions\staged\[removed]\content\bg.js
            c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\6zext2i4.default\extensions\staged\[removed]\install.rdf
            c:\users\hp\AppData\Roaming\SpeedRunnersLog.txt
            c:\windows\msdownld.tmp
            .
            .
            (((((((((((((((((((((((((   Files Created from 2015-04-10 to 2015-05-10  )))))))))))))))))))))))))))))))
            .
            .
            2015-05-10 12:00 . 2015-05-10 12:00 ——– d—–w- c:\users\Default\AppData\Local\temp
            2015-05-10 07:46 . 2015-05-10 08:16 119512 —-a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
            2015-05-10 07:45 . 2015-04-14 04:07 51928 —-a-w- c:\windows\system32\drivers\mwac.sys
            2015-05-10 07:45 . 2015-04-14 04:07 92888 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
            2015-05-10 07:45 . 2015-04-14 04:07 23256 —-a-w- c:\windows\system32\drivers\mbam.sys
            2015-05-10 07:45 . 2015-05-10 07:45 ——– d—–w- c:\program files\Malwarebytes Anti-Malware
            2015-05-10 06:44 . 2015-05-10 08:34 62576 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{07C6CCAB-5C75-4EEC-8DE3-4F4205C0AFE5}\offreg.dll
            2015-05-10 06:11 . 2015-04-04 06:39 9201616 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{07C6CCAB-5C75-4EEC-8DE3-4F4205C0AFE5}\mpengine.dll
            2015-05-10 05:57 . 2015-05-10 05:57 ——– d—–w- C:\RegBackup
            2015-05-10 05:34 . 2015-05-10 05:41 ——– d—–w- C:\AdwCleaner
            2015-05-09 06:47 . 2015-04-04 06:39 9201616 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
            2015-05-06 16:02 . 2015-05-06 16:02 ——– d—–w- C:\NVIDIA
            2015-05-05 10:49 . 2015-05-05 10:51 ——– d—–w- C:\FRST
            2015-05-05 09:56 . 2010-07-25 16:53 56496 —-a-w- c:\windows\system32\wbhelp2.dll
            2015-05-05 09:56 . 2010-07-25 16:53 544768 —-a-w- c:\windows\system32\wbocx.ocx
            2015-05-05 09:56 . 2010-07-25 16:53 258352 —-a-w- c:\windows\system32\unicows.dll
            2015-05-05 09:56 . 2010-07-25 16:53 33968 —-a-w- c:\windows\system32\anim.dll
            2015-05-05 09:56 . 2010-07-25 16:53 1706800 —-a-w- c:\windows\system32\gdiplus.dll
            2015-05-05 09:56 . 2010-07-25 16:53 4608 —-a-w- c:\windows\system32\W95INF32.DLL
            2015-05-05 09:56 . 2010-07-25 16:53 2272 —-a-w- c:\windows\system32\W95INF16.DLL
            2015-05-04 14:35 . 2015-05-04 14:35 ——– d—–w- c:\program files\Common Files\Java
            2015-05-04 13:57 . 2015-05-04 13:57 ——– d—–w- C:\found.001
            2015-05-03 12:22 . 2015-05-09 06:41 ——– d—–w- c:\program files\by Decepticon
            2015-05-03 12:13 . 2015-05-03 12:13 ——– d—–w- C:\found.000
            2015-04-25 12:59 . 2015-04-25 12:59 ——– d—–w- c:\programdata\Malwarebytes
            2015-04-24 10:35 . 2015-05-08 10:10 778416 —-a-w- c:\windows\system32\FlashPlayerApp.exe
            2015-04-24 10:35 . 2015-05-08 10:10 142512 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
            2015-04-15 10:54 . 2015-03-23 03:06 576000 —-a-w- c:\windows\system32\generaltel.dll
            2015-04-15 10:54 . 2015-03-23 03:06 860160 —-a-w- c:\windows\system32\appraiser.dll
            2015-04-15 10:54 . 2015-03-23 03:06 26112 —-a-w- c:\windows\system32\acmigration.dll
            2015-04-15 10:54 . 2015-03-23 02:59 896000 —-a-w- c:\windows\system32\aeinv.dll
            2015-04-15 10:54 . 2015-03-23 03:06 630784 —-a-w- c:\windows\system32\invagent.dll
            2015-04-15 10:54 . 2015-03-23 03:06 331264 —-a-w- c:\windows\system32\devinv.dll
            2015-04-15 10:54 . 2015-03-23 03:06 202752 —-a-w- c:\windows\system32\aepdu.dll
            2015-04-15 10:54 . 2015-03-23 03:06 159744 —-a-w- c:\windows\system32\aepic.dll
            2015-04-15 09:29 . 2015-03-05 04:06 305152 —-a-w- c:\windows\system32\gdi32.dll
            2015-04-15 09:29 . 2015-03-25 03:00 11776 —-a-w- c:\windows\system32\wu.upgrade.ps.dll
            2015-04-15 09:29 . 2015-03-25 03:00 33792 —-a-w- c:\windows\system32\wuapp.exe
            2015-04-15 09:29 . 2015-03-25 03:00 131584 —-a-w- c:\windows\system32\wuauclt.exe
            2015-04-15 09:29 . 2015-03-25 03:00 92672 —-a-w- c:\windows\system32\wudriver.dll
            2015-04-15 09:29 . 2015-03-25 03:00 35328 —-a-w- c:\windows\system32\wups2.dll
            2015-04-15 09:29 . 2015-03-25 03:00 3088384 —-a-w- c:\windows\system32\wucltux.dll
            2015-04-15 09:29 . 2015-03-25 03:00 29696 —-a-w- c:\windows\system32\wups.dll
            2015-04-15 09:29 . 2015-03-25 03:00 173056 —-a-w- c:\windows\system32\wuwebv.dll
            2015-04-15 09:29 . 2015-03-25 03:00 566784 —-a-w- c:\windows\system32\wuapi.dll
            2015-04-15 09:29 . 2015-03-25 03:00 50176 —-a-w- c:\windows\system32\WinSetupUI.dll
            2015-04-15 09:29 . 2015-03-25 03:00 2020864 —-a-w- c:\windows\system32\wuaueng.dll
            2015-04-15 09:27 . 2015-02-25 03:03 514560 —-a-w- c:\windows\system32\drivers\http.sys
            2015-04-15 09:26 . 2015-03-10 03:08 1237504 —-a-w- c:\windows\system32\msxml3.dll
            2015-04-15 09:26 . 2015-03-10 03:05 2048 —-a-w- c:\windows\system32\msxml3r.dll
            2015-04-12 10:29 . 2015-04-12 10:29 ——– d—–w- c:\users\hp\AppData\Roaming\3909
            2015-04-12 04:32 . 2015-04-27 13:11 20 —-a-w- c:\users\hp\AppData\Roaming\appdataFr3.bin
            .
            .
            .
            ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2015-05-04 14:34 . 2014-10-23 06:09 96352 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
            2015-03-30 09:55 . 2014-10-21 11:26 26176 —ha-w- c:\windows\system32\hamachi.sys
            2015-03-26 06:26 . 2015-03-31 11:49 908832 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1D5F0966-5A62-4BB2-AB00-48F6496D21CB}\gapaengine.dll
            2015-03-26 06:26 . 2014-08-30 03:09 908832 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
            2015-03-11 11:56 . 2015-03-11 11:56 25104 —-a-w- c:\windows\system32\drivers\dtlitescsibus.sys
            2015-03-03 13:16 . 2014-08-28 03:39 246920 ——w- c:\windows\system32\MpSigStub.exe
            2015-02-26 03:11 . 2015-03-11 10:11 2381312 —-a-w- c:\windows\system32\win32k.sys
            2015-02-20 04:13 . 2015-03-11 09:11 26624 —-a-w- c:\windows\system32\lpk.dll
            2015-02-20 04:13 . 2015-03-11 09:11 70656 —-a-w- c:\windows\system32\fontsub.dll
            2015-02-20 04:13 . 2015-03-11 09:11 10240 —-a-w-

            There should be more to the log, thats just part of it, post the entire log please

             

            Then lets check for a rootkit

             

            Please download TDSSKiller
            • Download TDSSKiller.exe to your desktop, if it is prevented from being downloaded than download the Zip version and extract it to your desktop
            • Double click TDSSKiller To start the program <– XP/Vista Users
            • Right Click TDSSKiller and select RUN AS ADMINISTRATOR <–Windows 7 and 8
            • Press Start Scan
            • Only if Malicious objects are found then ensure Cure is selected
            • Then click Continue > Reboot now
            • Copy and paste the log in your next reply
            • A copy of the log will be saved automatically to the root of the drive (typically C:\)
            • Oh sorry i didn't notice! Maybe it won't fit so here's the full log

              One more thing, remember when i said that when it asks me for administrator privileges it freezes? Well now it doesn't even appear and the program just starts itself without my consent. I don't know if that is good or bad……..

              Attachments:

              Logs look fine, thinking it may be all the games that you have installed and running, they take a lot of system resources and can bog some systems down. Nothing really bad has been found, nothing jumping out at me from the logs

               

               

              These are from Google, did you set them or maybe one of the games you installed has ??

               

              TCP: Interfaces\{0533B46C-9F80-4C04-9AFD-783CC1F95C1C}: NameServer = 8.8.8.8,8.8.4.4
              TCP: Interfaces\{1ADEC68A-CFFD-4320-9557-9AC9A47D6794}: NameServer = 8.8.8.8,8.8.4.4
              TCP: Interfaces\{217695D6-A1E5-4CE1-827B-7EBFE0759ADE}: NameServer = 8.8.8.8,8.8.4.4
              TCP: Interfaces\{238EC1DE-6C0B-4182-8132-87592608987C}: NameServer = 8.8.8.8,8.8.4.4
              TCP: Interfaces\{3C55266A-82CB-4C72-AB15-20B34BC13018}: NameServer = 8.8.8.8,8.8.4.4
              TCP: Interfaces\{5D0B2752-D0E8-4112-B383-21A70E36F5F0}: NameServer = 8.8.8.8,8.8.4.4
              TCP: Interfaces\{88260D8D-7CF0-44EE-85D8-705829ACFCC3}: NameServer = 8.8.8.8,8.8.4.4
              TCP: Interfaces\{9F2C82C5-DF23-4F9B-94FC-858C579C31D1}: NameServer = 8.8.8.8,8.8.4.4
              TCP: Interfaces\{D7848C44-E0B2-4BE5-9597-FD625FAF1AC5}: NameServer = 8.8.8.8,8.8.4.4

              From what i remember i DID change the default dns server to the google open dns. but that was a long time ago and i don't think this has anything to do with my sluggish PC anyway the freezing has lessened but the other symptoms are pretty much the same. There is one thing i noticed recently and that is whenever the Pc freezes or starts acting weird the light on the Cpu becomes solid red and when it becomes usable again it starts blinking again. So from what im thinking now it is probably a faulty Ram or hard drive. But what do i know it could be anything right? The boot time takes longer as usual, the icons become white the come back one by one. Hmmmm……

              Ask AI

              AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

              Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI