This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

slow during internet now, virus caught? [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Just lately, last few days, internet runs slowly.

Think caught a virus of some sort.

Hope you can help.

I tried to download frst but would send me to a geeksite? where frst was not at.

 

Here is the response from the first test requested. 

thank you.  hope you can help.

 

Ron

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-05-15 14:36:34
—————————–
14:36:34.735    OS Version: Windows x64 6.1.7601 Service Pack 1
14:36:34.735    Number of processors: 4 586 0x3A09
14:36:34.735    ComputerName: RONS-ALIENWARE  UserName: g
14:36:38.419    Initialize success
14:36:38.575    VM: initialized successfully
14:36:38.575    VM: Intel CPU supported 
14:37:35.955    VM: supported disk I/O ataport.SYS
14:39:17.622    AVAST engine defs: 15051501
14:39:34.133    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
14:39:34.148    Disk 0 Vendor: ST1000DM003-9YN162 CC4G Size: 953869MB BusType: 11
14:39:34.257    VM: Disk 0 MBR read successfully
14:39:34.257    Disk 0 MBR scan
14:39:34.273    Disk 0 unknown MBR code
14:39:34.273    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
14:39:34.289    Disk 0 scanning C:\Windows\system32\drivers
14:39:42.969    Service scanning
14:39:44.857    Service BHDrvx64 C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150506.001\BHDrvx64.sys **LOCKED** 5
14:39:47.899    Service IDSVia64 C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150514.001\IDSvia64.sys **LOCKED** 5
14:39:52.017    Service NAVENG C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150514.018\ENG64.SYS **LOCKED** 5
14:39:52.142    Service NAVEX15 C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150514.018\EX64.SYS **LOCKED** 5
14:40:00.232    Modules scanning
14:40:00.232    Disk 0 trace - called modules:
14:40:00.247    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys 
14:40:00.247    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007a41060]
14:40:00.263    3 CLASSPNP.SYS[fffff88001a6e43f] -> nt!IofCallDriver -> [0xfffffa800748f520]
14:40:00.263    5 ACPI.sys[fffff88000f9d7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa8007499060]
14:40:01.620    AVAST engine scan C:\Windows
14:40:03.523    AVAST engine scan C:\Windows\system32
14:44:03.425    AVAST engine scan C:\Windows\system32\drivers
14:44:48.640    AVAST engine scan C:\Users\g
16:11:36.337    AVAST engine scan C:\ProgramData
16:19:37.004    Disk 0 statistics 7688983/0/5 @ 0.89 MB/s
16:19:37.004    Scan finished successfully
16:39:07.733    Disk 0 MBR has been saved successfully to "C:\Users\g\Desktop\MBR.dat"
16:39:07.748    The log file has been saved successfully to "C:\Users\g\Desktop\aswMBR.txt"
 
 

:welcome:

 

I need to see those FRST logs so I can see whats going on, i am attaching FRST64 as it looks like your running the 64Bit version of Windows 7

 

Here are the instructions, I need to see both logs, FRST and Additions

 

 
Please download Farbar Recovery Scan Tool and save it to your DESKTOP
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  •  
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Please make sure All Users is checked
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
 

Attachments:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-05-2015 02
Ran by [removed] (administrator) on RONS-ALIENWARE on 16-05-2015 21:23:15
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Users\g\AppData\Local\Amazon Music\Amazon Music Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Elements 13 Organizer\PhotoshopElementsFileAgent.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFXWindowsService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\msi\ODD Monitor\ODD_Monitor.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\n360.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(SoftThinks SAS) C:\Program Files (x86)\AlienRespawn\SftService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(SoftThinks - Dell) C:\Program Files (x86)\AlienRespawn\Toaster.exe
() C:\Program Files (x86)\AlienRespawn\Components\Scheduler\STService.exe
(SoftThinks - Dell) C:\Program Files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\n360.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(CyberLink) C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Users\g\Desktop\aswMBR.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [] => [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\…\Run: [GoogleChromeAutoLaunch_AAAB1FF4F15714D16460E3D739F67343] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [812872 2015-05-04] (Google Inc.)
HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\…\MountPoints2: {6d809e70-ae66-11e4-ae2c-d4bed9fc8f7b} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\…\MountPoints2: {70a2b40b-6044-11e3-908d-d4bed9fc8f7b} - D:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\…\MountPoints2: {70a2b5f1-6044-11e3-908d-d4bed9fc8f7b} - D:\LiteAuto.exe
HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\…\MountPoints2: {77ce63d0-acf3-11e4-af4c-d4bed9fc8f7b} - F:\setup.exe -a
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [245872 2013-02-26] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [201576 2013-02-26] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.7.0.11\buShell.dll [2015-03-06] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.7.0.11\buShell.dll [2015-03-06] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.7.0.11\buShell.dll [2015-03-06] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-05-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-05-04] (Dropbox, Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}
HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-09-25] (Microsoft Corporation)
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-08-19] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2014-09-16] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-08-19] (Oracle Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-09-25] (Microsoft Corporation)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\IPS\IPSBHO.DLL [2015-03-04] (Symantec Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-11] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-22] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2014-09-16] (Microsoft Corporation)
BHO-x32: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile -> {D5233FCD-D258-4903-89B8-FB1568E7413D} -> C:\Windows\SysWOW64\mscoree.dll [2010-11-20] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-11] (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-04-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
FireFox:
========
FF ProfilePath: C:\Users\g\AppData\Roaming\Mozilla\Firefox\Profiles\q0x8jozo.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll [2013-08-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-08-19] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll [2014-06-24] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-11] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-09-25] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-01-18] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-01-18] (NVIDIA Corporation)
FF Plugin-x32: @spoon.net/Spoon Plugin 3.33 -> C:\Program Files (x86)\Spoon\3.33.6.270\npMozillaSpoonPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2014-09-25] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2015-05-15]
FF Extension: No Name - C:\Users\g\AppData\Roaming\Mozilla\Firefox\Profiles\q0x8jozo.default\extensions\[removed] [Not Found]
 
Chrome: 
=======
CHR HomePage: Default -> https://www.google.com/
CHR StartupUrls: Default -> "https://us-mg5.mail.yahoo.com/neo/launch?.rand=2u1ppv4slctkm","hxxp://www.yahoo.com/"
CHR DefaultSearchURL: Default -> http://www.google.com/search?q={searchTerms}
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR Profile: C:\Users\g\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Lucidchart Diagrams - Online) - C:\Users\g\AppData\Local\Google\Chrome\User Data\Default\Extensions\apboafhkiegglekeafbckfjldecefkhn [2015-05-04]
CHR Extension: (Google Drive) - C:\Users\g\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-03]
CHR Extension: (AVG Secure Search) - C:\Users\g\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2015-05-04]
CHR Extension: (Bookmark Manager) - C:\Users\g\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-25]
CHR Extension: (Kindle Cloud Reader) - C:\Users\g\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2015-05-04]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\g\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Sketchpad) - C:\Users\g\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkllajgbhondgjjnhmmgbjndmogapinp [2015-05-04]
CHR Extension: (Google Wallet) - C:\Users\g\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
CHR Extension: (TypingClub) - C:\Users\g\AppData\Local\Google\Chrome\User Data\Default\Extensions\obdbgibnhfcjmmpfijkpcihjieedpfah [2015-05-04]
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\Exts\Chrome.crx [2015-03-21]
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\Exts\Chrome.crx [2015-03-21]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 ACT! Scheduler; C:\Program Files (x86)\ACT\Act for Windows\Act.Scheduler.exe [81920 2008-07-31] (Sage Software, Inc.) [File not signed]
R2 AdobeActiveFileMonitor13.0; C:\Program Files\Adobe\Elements 13 Organizer\PhotoshopElementsFileAgent.exe [231120 2014-08-31] (Adobe Systems Incorporated)
R2 AlienFXWindowsService; C:\Program Files\Alienware\Command Center\AlienFXWindowsService.exe [13168 2012-06-18] (Alienware)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-06] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MSI_ODD_Service; c:\Program Files (x86)\msi\ODD Monitor\ODD_Monitor.exe [76800 2011-10-04] (Micro-Star Int'l Co., Ltd.) [File not signed]
R2 MSSQL$ACT7; C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\N360.exe [265000 2015-03-06] (Symantec Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [614664 2014-10-03] (CyberLink)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150506.001\BHDrvx64.sys [1639128 2015-05-01] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1507000.00B\ccSetx64.sys [162392 2013-09-25] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-11] (Symantec Corporation)
R1 ElRawDisk; C:\Windows\system32\drivers\rsdrvx64.sys [26024 2009-02-12] (EldoS Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-15] (Symantec Corporation)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-08] (QUALCOMM Incorporated)
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150515.001\IDSvia64.sys [671448 2015-03-27] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-16] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150516.003\ENG64.SYS [129752 2015-05-11] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150516.003\EX64.SYS [2137304 2015-05-11] (Symantec Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
R3 NTIOLib_X64; C:\Program Files (x86)\msi\ODD Monitor\NTIOLib_X64.sys [14136 2010-01-18] (MSI)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2013-09-03] (Corel Corporation)
R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [100352 2011-09-15] (Renesas Electronics Corporation)
R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [216064 2011-09-15] (Renesas Electronics Corporation)
R1 SRTSP; C:\Windows\System32\Drivers\N360x64\1507000.00B\SRTSP64.SYS [876248 2014-08-25] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1507000.00B\SRTSPX64.SYS [37592 2014-08-25] (Symantec Corporation)
S2 SSPORT; C:\Windows\SysWOW64\Drivers\SSPORT.sys [11576 2009-08-26] (Samsung Electronics)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1507000.00B\SYMDS64.SYS [493656 2013-09-09] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1507000.00B\SYMEFA64.SYS [1148120 2014-03-03] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-24] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1507000.00B\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1507000.00B\SYMNETS.SYS [593112 2014-02-17] (Symantec Corporation)
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-06-20] (Anchorfree Inc.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [34808 2014-09-23] ()
S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [X]
S3 MREMP50; \??\C:\PROGRA~2\COMMON~1\Motive\MREMP50.SYS [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50; \??\C:\PROGRA~2\COMMON~1\Motive\MRESP50.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
S4 NvStUSB; \SystemRoot\system32\drivers\nvstusb.sys [X]
U3 aswMBR; \??\C:\Users\g\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\g\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-05-16 21:23 - 2015-05-16 21:23 - 00026766 _____ () C:\Users\g\Desktop\FRST.txt
2015-05-16 21:22 - 2015-05-16 21:23 - 00000000 ____D () C:\FRST
2015-05-16 21:20 - 2015-05-16 21:20 - 02107392 _____ (Farbar) C:\Users\g\Downloads\frst64.exe
2015-05-16 21:20 - 2015-05-16 21:20 - 02107392 _____ (Farbar) C:\Users\g\Desktop\frst64.exe
2015-05-15 16:39 - 2015-05-15 16:39 - 00002611 _____ () C:\Users\g\Desktop\aswMBR.txt
2015-05-15 16:39 - 2015-05-15 16:39 - 00000512 _____ () C:\Users\g\Desktop\MBR.dat
2015-05-15 14:26 - 2015-05-15 14:25 - 05198336 _____ (AVAST Software) C:\Users\g\Desktop\aswMBR.exe
2015-05-15 14:25 - 2015-05-15 14:25 - 05198336 _____ (AVAST Software) C:\Users\g\Downloads\aswMBR.exe
2015-05-15 10:57 - 2015-05-15 10:57 - 14361783 _____ () C:\Users\g\Downloads\Attachments_2015515 (6).zip
2015-05-15 10:48 - 2015-05-15 10:48 - 14726744 _____ () C:\Users\g\Downloads\Attachments_2015515 (5).zip
2015-05-15 10:42 - 2015-05-15 10:42 - 11412763 _____ () C:\Users\g\Downloads\Attachments_2015515 (4).zip
2015-05-15 10:40 - 2015-05-15 10:41 - 02039667 _____ () C:\Users\g\Downloads\Attachments_2015515 (3).zip
2015-05-15 10:39 - 2015-05-15 10:40 - 09083999 _____ () C:\Users\g\Downloads\Attachments_2015515 (2).zip
2015-05-15 10:38 - 2015-05-15 10:38 - 06490696 _____ () C:\Users\g\Downloads\Attachments_2015515 (1).zip
2015-05-15 10:32 - 2015-05-15 10:32 - 05572012 _____ () C:\Users\g\Downloads\Attachments_2015515.zip
2015-05-13 21:38 - 2015-05-15 13:51 - 00000000 ___RD () C:\Users\g\Dropbox
2015-05-13 21:38 - 2015-05-13 21:38 - 00001139 _____ () C:\Users\g\Desktop\Dropbox.lnk
2015-05-13 21:36 - 2015-05-13 21:36 - 00000000 ____D () C:\Users\g\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-05-13 21:35 - 2015-05-15 13:51 - 00000000 ____D () C:\Users\g\AppData\Roaming\Dropbox
2015-05-13 21:35 - 2015-05-13 21:35 - 00356272 _____ (Dropbox, Inc.) C:\Users\g\Downloads\DropboxInstaller.exe
2015-05-12 12:55 - 2015-05-12 12:55 - 00002039 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2015-05-12 12:54 - 2015-05-12 12:54 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-05-12 12:01 - 2015-05-12 12:01 - 00067147 _____ () C:\Users\g\Downloads\WhatsApp Chat with sarita saiz (1).txt
2015-05-12 11:59 - 2015-05-12 11:59 - 00259893 _____ () C:\Users\g\Downloads\WhatsApp Chat with Sarita (13).txt
2015-05-12 11:53 - 2015-05-12 11:53 - 00141390 _____ () C:\Users\g\Downloads\WhatsApp Chat with Sarita (12).txt
2015-05-12 11:51 - 2015-05-12 11:51 - 00259893 _____ () C:\Users\g\Downloads\WhatsApp Chat with Sarita (11).txt
2015-05-12 11:49 - 2015-05-12 11:49 - 00148084 _____ () C:\Users\g\Downloads\WhatsApp Chat with Sarita (10).txt
2015-05-12 11:47 - 2015-05-12 11:47 - 00043808 _____ () C:\Users\g\Downloads\WhatsApp Chat with Sarita (9).txt
2015-05-12 11:45 - 2015-05-12 11:45 - 00044311 _____ () C:\Users\g\Downloads\WhatsApp Chat with Sarita (8).txt
2015-05-12 11:05 - 2015-05-12 11:05 - 02280394 _____ () C:\Users\g\Downloads\WhatsApp Chat with Sarita (7).txt
2015-05-05 15:00 - 2015-05-05 15:00 - 27952932 _____ () C:\Users\g\Downloads\Attachments_201555 (4).zip
2015-05-05 15:00 - 2015-05-05 15:00 - 00000000 ____D () C:\Users\g\Downloads\Attachments_201555 (4)
2015-05-05 14:57 - 2015-05-05 15:01 - 00000000 ____D () C:\Users\g\Downloads\Attachments_201555 (3)
2015-05-05 14:56 - 2015-05-05 14:57 - 25457860 _____ () C:\Users\g\Downloads\Attachments_201555 (3).zip
2015-05-05 14:56 - 2015-05-05 14:56 - 00000000 ____D () C:\Users\g\Downloads\Attachments_201555 (2)
2015-05-05 14:55 - 2015-05-05 14:55 - 28866325 _____ () C:\Users\g\Downloads\Attachments_201555 (2).zip
2015-05-05 14:50 - 2015-05-05 14:50 - 27952932 _____ () C:\Users\g\Downloads\Attachments_201555 (1).zip
2015-05-05 14:41 - 2015-05-05 14:41 - 00000000 ____D () C:\Users\g\Downloads\Attachments_201555
2015-05-05 14:39 - 2015-05-05 14:40 - 29496547 _____ () C:\Users\g\Downloads\Attachments_201555.zip
2015-05-03 20:23 - 2015-05-03 20:23 - 00000000 ____D () C:\Users\g\Downloads\Attachments_201553 (1)
2015-05-03 20:22 - 2015-05-03 20:22 - 07021798 _____ () C:\Users\g\Downloads\Attachments_201553 (1).zip
2015-05-03 16:23 - 2015-05-03 16:23 - 00000000 ____D () C:\Users\g\Downloads\Attachments_201553
2015-05-03 16:22 - 2015-05-03 16:23 - 29639756 _____ () C:\Users\g\Downloads\Attachments_201553.zip
2015-05-01 08:47 - 2015-05-01 08:47 - 00001474 _____ () C:\Users\g\Downloads\insight_9GuvheFk6-A_85wW5cSOsn60pB09PZRzeg_2015-04-02-2015-04-29_world.zip
2015-04-29 19:31 - 2015-04-29 19:31 - 00000000 ____D () C:\Users\g\Downloads\Attachments_2015429
2015-04-29 19:24 - 2015-04-29 19:24 - 05213706 _____ () C:\Users\g\Downloads\Attachments_2015429.zip
2015-04-29 16:19 - 2015-04-29 16:19 - 04435968 _____ () C:\Users\g\Desktop\Ron Quicken-2015-04-29.QDF-backup
2015-04-25 14:34 - 2015-05-15 12:33 - 00000000 ____D () C:\Users\g\Documents\Peru
2015-04-25 12:49 - 2015-04-25 12:50 - 00000000 ____D () C:\Users\g\Downloads\Attachments_2015425 (6)
2015-04-25 12:48 - 2015-04-25 12:48 - 08607978 _____ () C:\Users\g\Downloads\Attachments_2015425 (6).zip
2015-04-25 12:12 - 2015-04-25 12:12 - 00000000 ____D () C:\Users\g\Downloads\Attachments_2015425 (5)
2015-04-25 12:11 - 2015-04-25 12:11 - 07212722 _____ () C:\Users\g\Downloads\Attachments_2015425 (5).zip
2015-04-25 11:42 - 2015-04-25 11:42 - 00000000 ____D () C:\Users\g\Downloads\Attachments_2015425 (4)
2015-04-25 11:41 - 2015-04-25 11:42 - 05324929 _____ () C:\Users\g\Downloads\Attachments_2015425 (4).zip
2015-04-25 11:22 - 2015-04-25 11:22 - 06441549 _____ () C:\Users\g\Downloads\Attachments_2015425 (3).zip
2015-04-25 11:22 - 2015-04-25 11:22 - 00000000 ____D () C:\Users\g\Downloads\Attachments_2015425 (3)
2015-04-25 11:08 - 2015-04-25 11:08 - 00000000 ____D () C:\Users\g\Downloads\Attachments_2015425 (2)
2015-04-25 11:07 - 2015-04-25 11:08 - 06711490 _____ () C:\Users\g\Downloads\Attachments_2015425 (2).zip
2015-04-25 09:34 - 2015-04-25 09:34 - 00000000 ____D () C:\Users\g\Downloads\Attachments_2015425 (1)
2015-04-25 09:33 - 2015-04-25 09:33 - 09994519 _____ () C:\Users\g\Downloads\Attachments_2015425 (1).zip
2015-04-25 09:28 - 2015-04-25 09:28 - 09994519 _____ () C:\Users\g\Downloads\Attachments_2015425.zip
2015-04-24 10:14 - 2015-04-24 10:14 - 115949568 _____ () C:\Users\g\Desktop\lindas current-2015-04-24.QDF-backup
2015-04-22 16:37 - 2015-04-22 16:38 - 00000000 ____D () C:\Program Files (x86)\K-Lite Codec Pack
2015-04-22 16:37 - 2015-04-22 16:37 - 00001340 _____ () C:\Users\Public\Desktop\Free MPG To AVI Converter.lnk
2015-04-22 16:37 - 2015-04-22 16:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2015-04-22 16:37 - 2015-04-22 16:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Converting
2015-04-22 16:37 - 2015-04-22 16:37 - 00000000 ____D () C:\Program Files (x86)\Free Converting
2015-04-22 16:37 - 2011-03-02 03:43 - 00175616 _____ () C:\Windows\SysWOW64\unrar.dll
2015-04-22 16:36 - 2015-04-22 16:36 - 12934805 _____ (Free Converting (http://www.freeconverting.com) ) C:\Users\g\Downloads\mpgtoavi_setup.exe
2015-04-20 19:10 - 2015-04-20 19:10 - 00000000 ____D () C:\Users\g\Downloads\Attachments_2015420
2015-04-20 19:09 - 2015-04-20 19:09 - 04714790 _____ () C:\Users\g\Downloads\Attachments_2015420.zip
2015-04-17 19:00 - 2015-04-17 19:00 - 00000000 ____D () C:\Users\g\Downloads\Attachments_2015417
2015-04-17 18:49 - 2015-04-17 18:49 - 08488478 _____ () C:\Users\g\Downloads\Attachments_2015417.zip
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-05-16 21:05 - 2012-09-14 18:15 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-16 20:42 - 2012-10-26 22:27 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-16 17:10 - 2012-09-14 18:34 - 00000000 ____D () C:\Program Files (x86)\AlienRespawn
2015-05-16 15:19 - 2015-02-03 10:28 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-16 15:19 - 2012-09-14 20:09 - 01997494 _____ () C:\Windows\WindowsUpdate.log
2015-05-16 05:42 - 2012-10-26 22:27 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-16 02:00 - 2012-12-08 23:54 - 00000000 ____D () C:\Users\g\AppData\Local\Adobe
2015-05-15 23:14 - 2013-07-20 00:31 - 00000099 _____ () C:\Users\Public\LMDebug.log
2015-05-15 16:23 - 2015-04-10 12:19 - 00003528 _____ () C:\Windows\setupact.log
2015-05-15 14:25 - 2009-07-13 21:45 - 00028352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-15 14:25 - 2009-07-13 21:45 - 00028352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-15 14:16 - 2012-09-14 18:40 - 00000000 ____D () C:\Users\Default\AppData\Local\SoftThinks
2015-05-15 14:16 - 2012-09-14 18:40 - 00000000 ____D () C:\Users\Default User\AppData\Local\SoftThinks
2015-05-15 14:15 - 2012-12-26 21:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-15 14:15 - 2009-07-13 22:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-15 14:00 - 2015-02-03 10:28 - 00001126 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-15 14:00 - 2015-02-03 10:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-15 14:00 - 2014-09-21 20:06 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-15 13:49 - 2015-04-10 12:19 - 00122396 _____ () C:\Windows\PFRO.log
2015-05-15 13:47 - 2015-01-08 12:51 - 00000000 ____D () C:\Users\g\AppData\Roaming\Skype
2015-05-15 12:34 - 2013-10-01 21:15 - 00000000 ____D () C:\Users\g\Documents\TurboTax
2015-05-15 05:37 - 2012-10-26 22:27 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-15 05:37 - 2012-10-26 22:27 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-13 21:38 - 2012-12-08 23:53 - 00000000 ____D () C:\Users\g
2015-05-13 21:20 - 2013-07-31 16:11 - 00000000 ____D () C:\Users\g\AppData\Local\CrashDumps
2015-05-12 12:55 - 2012-09-14 18:37 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2015-05-04 13:34 - 2013-07-23 22:49 - 00000000 ____D () C:\Users\g\AppData\Local\CutePDF Writer
2015-05-04 09:09 - 2013-07-26 21:05 - 00000000 ____D () C:\Users\g\Documents\Quicken
2015-05-01 23:01 - 2009-07-13 22:13 - 00853262 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-30 13:55 - 2014-05-16 15:15 - 00000000 ____D () C:\Users\g\Documents\Divorce backup
2015-04-30 12:31 - 2013-07-18 10:54 - 00000952 ___SH () C:\ProgramData\KGyGaAvL.sys
2015-04-29 16:16 - 2015-01-19 17:34 - 00000000 ____D () C:\Users\g\Documents\Tee School paper work
2015-04-25 17:45 - 2014-11-27 15:50 - 00000000 ____D () C:\Users\g\Desktop\Removable Disk
2015-04-25 17:42 - 2009-10-13 07:38 - 00000000 ____D () C:\Users\g\Desktop\Adobe
2015-04-25 17:40 - 2009-01-20 18:38 - 00000000 ____D () C:\Users\g\Desktop\Ron and Family
2015-04-25 17:29 - 2015-03-07 15:16 - 00000000 ____D () C:\Users\g\Desktop\Tee Bandworks show Jan 2015
2015-04-25 17:20 - 2015-03-07 10:00 - 00000000 ____D () C:\Users\g\Desktop\In The Heights Rehersal 3 4 15
2015-04-25 16:58 - 2015-01-19 21:15 - 00000000 ____D () C:\Users\g\Documents\Outlook Files
2015-04-25 16:56 - 2013-08-19 07:52 - 00178688 ___SH () C:\Users\g\Thumbs.db
2015-04-25 16:11 - 2014-06-03 23:48 - 00000000 ____D () C:\Photos
2015-04-25 14:14 - 2015-04-13 15:07 - 00000000 ____D () C:\Users\g\Documents\Covered CA
 
==================== Files in the root of some directories =======
 
2014-12-17 10:32 - 2014-12-17 10:32 - 0012987 _____ () C:\Program Files (x86)\Uninstal.log
2013-07-18 10:54 - 2013-07-18 10:54 - 0000000 ____H () C:\Users\g\AppData\Roaming\ActUpdate.log
2014-04-28 19:11 - 2014-07-27 22:25 - 0558080 _____ () C:\Users\g\AppData\Roaming\SharedSettings.ccs
2014-07-25 20:06 - 2014-07-29 06:10 - 0001456 _____ () C:\Users\g\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-02-14 17:45 - 2015-03-26 15:34 - 0003584 _____ () C:\Users\g\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-07-18 10:54 - 2013-07-18 11:03 - 0000088 __RSH () C:\ProgramData\6F97874B3A.sys
2013-07-18 10:54 - 2015-04-30 12:31 - 0000952 ___SH () C:\ProgramData\KGyGaAvL.sys
2013-10-01 13:20 - 2015-02-02 17:10 - 0001225 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2015-03-10 23:16 - 2015-03-10 23:16 - 0000070 _____ () C:\ProgramData\StreamingMediaTechnologyLog.txt
2013-07-23 08:06 - 2013-07-23 08:06 - 0000854 _____ () C:\ProgramData\trva.cmd
 
Some content of TEMP:
====================
C:\Users\g\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpa0iehh.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-05-14 00:44
 
==================== End Of Log ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-05-2015 02
Ran by [removed] at 2015-05-16 21:23:57
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-4093186601-1063034090-4258288859-500 - Administrator - Disabled)
g (S-1-5-21-4093186601-1063034090-4258288859-1002 - Administrator - Enabled) => C:\Users\g
Guest (S-1-5-21-4093186601-1063034090-4258288859-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-4093186601-1063034090-4258288859-1005 - Limited - Enabled)
UpdatusUser (S-1-5-21-4093186601-1063034090-4258288859-1003 - Limited - Enabled) => C:\Users\UpdatusUser
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Norton 360 (Enabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton 360 (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton 360 (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
ACT! by Sage 2009 (11.0) (HKLM-x32\…\InstallShield_{1A4FE289-8B58-4FC5-8CE8-109A542CE0A7}) (Version: 11.0.0.0 - Sage Software, Inc.)
ACT! by Sage 2009 (11.0) (x32 Version: 11.0.0.0 - Sage Software, Inc.) Hidden
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 16.0.0.273 - Adobe Systems Incorporated)
Adobe Content Viewer (HKLM-x32\…\com.adobe.dmp.contentviewer) (Version: 1.4.0 - Adobe Systems Incorporated)
Adobe Creative Suite 6 Master Collection (HKLM-x32\…\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Premiere Elements 13 (HKLM-x32\…\{E76173BC-DC9A-49C3-9B9F-FD7814FC3308}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Premiere Pro CS6 Functional Content (HKLM-x32\…\{614020C8-2E16-4E16-A5F0-04DE2AB96097}) (Version: 6.0.0 - Adobe Systems Incorporated)
Adobe Reader X (10.1.14) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.14 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.3.153 - Adobe Systems, Inc.)
Adobe Story (HKLM-x32\…\com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.0.571 - Adobe Systems Incorporated)
Adobe Widget Browser (HKLM-x32\…\com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1) (Version: 2.0 Build 230 - Adobe Systems Incorporated.)
Akamai NetSession Interface (HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\…\Akamai) (Version:  - Akamai Technologies, Inc)
AlienAutopsy (HKLM\…\PC-Doctor for Windows) (Version: 3.2.6032.102 - PC-Doctor, Inc.)
AlienRespawn - Support Software (HKLM-x32\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.67 - Alienware)
AlienRespawn (HKLM-x32\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.67 - Alienware)
Alienware Command Center (HKLM-x32\…\InstallShield_{ACBE8264-9018-49B8-9041-3A74E2596BF3}) (Version: 2.8.9.0 - Alienware Corp.)
Alienware Command Center (Version: 2.8.9.0 - Alienware Corp.) Hidden
Alienware Customer Surveys (HKLM-x32\…\{9AAA35D1-B21D-4610-BBAE-18FE2D00C3E0}) (Version: 1.0.5 - Dell Inc.)
Alienware Product Registration (HKLM-x32\…\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.1.3 - Dell Inc.)
Amazon Music (HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\…\Amazon Amazon Music) (Version: 3.6.0.671 - Amazon Services LLC)
Audacity 2.0.6 (HKLM-x32\…\Audacity_is1) (Version: 2.0.6 - Audacity Team)
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
BookSmart® 3.4.5 3.4.5 (HKLM-x32\…\BookSmart® 3.4.5 3.4.5) (Version:  - Blurb, Inc)
CCleaner (HKLM\…\CCleaner) (Version: 4.08 - Piriform)
CoffeeCup Free FTP (HKLM-x32\…\{66F43DBE-6D46-4BCE-831D-0D4C13639BE8}) (Version: 4.5.20 - CoffeeCup Software Inc.)
CutePDF Writer 3.0 (HKLM\…\CutePDF Writer Installation) (Version:  3.0 - CutePDF.com)
CyberLink PhotoDirector 5 (HKLM-x32\…\InstallShield_{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01}) (Version: 5.0.6213.0 - CyberLink Corp.)
CyberLink PhotoDirector 5 (Version: 5.0.6213.0 - CyberLink Corp.) Hidden
CyberLink PowerDirector 13 (HKLM-x32\…\{BA385AFC-00B1-417C-8C20-74B996EF3AF0}) (Version: 13.0.2604.0 - CyberLink Corp.)
Direct WAV MP3 Splitter version 3.0.0.0 (HKLM-x32\…\Direct WAV MP3 Splitter_is1) (Version: 3.0.0.0 - Piston Software)
Dropbox (HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\…\Dropbox) (Version: 3.4.6 - Dropbox, Inc.)
EPSON Artisan 720 Series Printer Uninstall (HKLM\…\EPSON Artisan 720 Series) (Version:  - SEIKO EPSON Corporation)
Epson Copy Utility 3.5 (HKLM-x32\…\{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}) (Version: 3.5.0.0 - )
Epson Event Manager (HKLM-x32\…\{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}) (Version: 2.40.0001 - SEIKO EPSON CORPORATION)
EPSON Perfection V600 Photo Scanner Driver Update (HKLM-x32\…\{EBBE3D90-9344-43A7-A548-91BA02B3B7CD}) (Version:  - )
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
FastStone Image Viewer 5.1 (HKLM-x32\…\FastStone Image Viewer) (Version: 5.1 - FastStone Soft)
Free MPG To AVI Converter (HKLM-x32\…\Free MPG To AVI Converter_is1) (Version: 1.0.0.0 - Free Converting)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 42.0.2311.152 - Google Inc.)
Google Earth (HKLM-x32\…\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\…\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
ImgBurn (HKLM-x32\…\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.4.1441 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version:  - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\…\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
IPTInstaller (HKLM-x32\…\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC)
iSEEK AnswerWorks English Runtime (HKLM-x32\…\{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}) (Version: [removed] - Vantage Linguistics)
Java 7 Update 25 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417025FF}) (Version: 7.0.250 - Oracle)
Java 7 Update 65 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.650 - Oracle)
K-Lite Codec Pack 7.2.0 (Basic) (HKLM-x32\…\KLiteCodecPack_is1) (Version: 7.2.0 - )
Maintenance Samsung ML-2525W Series (HKLM-x32\…\Samsung ML-2525W Series) (Version:  - Samsung Electronics CO.,LTD)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Games for Windows - LIVE  (HKLM-x32\…\{4D243BA7-9AC4-46D1-90E5-EEB88974F501}) (Version: 2.0.687.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\…\{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}) (Version: 2.0.687.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 (HKLM-x32\…\Microsoft SQL Server 2005) (Version:  - Microsoft Corporation)
Microsoft SQL Server Native Client (HKLM\…\{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server Setup Support Files (English) (HKLM-x32\…\{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\…\{B636C9B9-A3F2-4DCE-ADCC-72E095018385}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\…\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
MovieTracer (HKLM-x32\…\{A4879FAF-1A81-4189-91FB-9D2109EB49B4}) (Version: 1.3.00.14020 - Sony Corporation)
Mozilla Firefox 30.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 30.0 (x86 en-US)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
MSI ODD Monitor (HKLM-x32\…\InstallShield_{B7D9BAAA-F068-4BF8-B929-462C3A8AB677}) (Version: 1.0.0.5 - Micro-Star Int'l Co., Ltd.)
MSI ODD Monitor (x32 Version: 1.0.0.5 - Micro-Star Int'l Co., Ltd.) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\…\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
NewBlue Video Essentials for Windows (HKLM-x32\…\NewBlue Video Essentials for Windows) (Version: 3.0 - NewBlue)
Norton 360 (HKLM-x32\…\N360) (Version: 21.7.0.11 - Symantec Corporation)
NVIDIA 3D Vision Controller Driver 310.90 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 310.90 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 311.06 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation)
NVIDIA Graphics Driver 311.06 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.18.0 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.18.0 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.1031 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA Update 1.11.3 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation)
OLYMPUS Digital Camera Updater (HKLM-x32\…\{D18925CE-5AF9-4394-8EF7-1081FFE7E98B}) (Version: 1.2.0 - OLYMPUS IMAGING CORP.)
OLYMPUS Viewer 2 (HKLM-x32\…\{797808CA-1563-4EA0-A280-1371AC2F2310}) (Version: 1.3.0 - OLYMPUS IMAGING CORP.)
Origin (HKLM-x32\…\Origin) (Version: 9.0.15.65 - Electronic Arts, Inc.)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
PMB (HKLM-x32\…\{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}) (Version: 5.8.02.10270 - Sony Corporation)
PowerISO (HKLM-x32\…\PowerISO) (Version: 4.8 - PowerISO Computing, Inc.)
PxMergeModule (x32 Version: 1.00.0000 - Your Company Name) Hidden
Quicken 2013 (HKLM-x32\…\{034DD4BB-F0D6-4ECF-B064-8E39E3EF7076}) (Version: 22.1.12.7 - Intuit)
QuickTime 7 (HKLM-x32\…\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Razer Synapse 2.0 (HKLM-x32\…\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.5.18 - Razer USA Ltd.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6494 - Realtek Semiconductor Corp.)
Resident Evil 4 1.10 (HKLM-x32\…\Resident Evil 4_is1) (Version:  - )
RMS Coach (HKLM-x32\…\RMS Coach) (Version:  - )
Safari (HKLM-x32\…\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
SeaTools for Windows (HKLM-x32\…\SeaTools for Windows) (Version:  - Seagate Technology)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\…\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version:  - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version:  - Microsoft) Hidden
SIGMA Photo Pro 5 (HKLM-x32\…\{B99C3D18-BA4B-4D65-A500-D364E3D2A8A3}) (Version: 5.5.3 - SIGMA)
SiteSpinner Pro V2 (HKLM-x32\…\{DEB1AE2C-AFE6-480F-B3A6-A20FF10941F9}) (Version: 2.92.15 - Virtual Mechanics)
Skype™ 7.3 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TurboTax 2012 (HKLM-x32\…\TurboTax 2012) (Version: 2012.0 - Intuit, Inc)
TurboTax 2013 (HKLM-x32\…\TurboTax 2013) (Version: 2013.0 - Intuit, Inc)
TurboTax 2014 (HKLM-x32\…\TurboTax 2014) (Version: 2014.0 - Intuit, Inc)
Windows Driver Package - OLYMPUS IMAGING CORP. Camera Communication Driver Package (09/09/2009 1.0.0.0) (HKLM\…\2C1C2F29FADF39F533CEEE67B90F07A5306A4BDB) (Version: 09/09/2009 1.0.0.0 - OLYMPUS IMAGING CORP.)
WinPcap 4.1.2 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
WinRAR 4.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\g\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\g\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
 
==================== Restore Points  =========================
 
02-05-2015 00:23:35 Scheduled Checkpoint
10-05-2015 12:39:48 Scheduled Checkpoint
14-05-2015 12:12:41 Norton 360 Registry Clean
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {070698C1-A4AE-4327-A3C5-04B43C749951} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {0DBEAA6E-5D63-4DBD-BFDD-F97FA67A64B1} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {140B22B6-8D4A-471A-8934-250461BAA7E4} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {205B7B6B-E48F-4AA3-8F37-5E6BF37FDDE1} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {2A93D5EE-5BCF-4016-ABF9-DB9F7C412F46} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {2F423C0F-6A6D-45F1-96B5-299403A7819E} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\WSCStub.exe [2015-03-06] (Symantec Corporation)
Task: {3551A5FD-70C3-480B-B0FA-ACE5C47CA3B3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-14] (Adobe Systems Incorporated)
Task: {364333F3-918C-4C14-B37D-BAC8E786BC65} - System32\Tasks\IHSelfDeleteTASK => CMD
Task: {36B86D75-27C4-44D2-961E-4B05F9676522} - System32\Tasks\{96D74858-05F7-4B2A-8C2A-689DAC89985E} => pcalua.exe -a E:\Install.exe -d E:\
Task: {4BBC8363-B8C6-4A55-A0C2-BE1378E871EE} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {6A7F009B-D50B-4925-94D8-F983D8161FD3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd)
Task: {7D66FD2A-FD2F-4E14-AF21-3783E0F76D00} - System32\Tasks\AdobeAAMUpdater-1.0-Titus-PC-g => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-02-03] (Adobe Systems Incorporated)
Task: {8A2494F1-E33E-42C4-975D-7C84AE4A564D} - System32\Tasks\PCDEventLauncher => C:\Program Files\AlienAutopsy\sessionchecker.exe [2012-11-29] (PC-Doctor, Inc.)
Task: {A9D59523-3D72-4A8D-BA8A-F7129BB72445} - System32\Tasks\{7B55BAAA-95D9-413D-A0BD-63320F668EE5} => pcalua.exe -a "C:\Users\g\Downloads\converter (1).exe" -d C:\Users\g\Downloads
Task: {AC42FE3B-8049-457C-A1D6-9CA85BCAFC52} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\AlienAutopsy\uaclauncher.exe [2012-11-29] (PC-Doctor, Inc.)
Task: {B076589C-F3AF-460B-8F26-BC61B619DB83} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-26] (Google Inc.)
Task: {C9E85C7F-1ED1-490C-8C33-BBDAB21EDF33} - System32\Tasks\IHUninstallTrackingTASK => CMD
Task: {DD2F1EBF-3B04-486B-856A-43579301EA79} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-26] (Google Inc.)
Task: {E6F841AA-C51D-42A8-AA68-86CB8528FD0F} - System32\Tasks\Amazon Music Helper => C:\Users\g\AppData\Local\Amazon Music\Amazon Music Helper.exe [2014-10-14] ()
Task: {F59C3498-BDA0-424B-93CC-4BF764F4C2D6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {FA5B9E6C-F138-4548-B63A-71AA20C04147} - System32\Tasks\XboxStatTask => C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2012-12-26 21:52 - 2013-01-18 08:00 - 00087328 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-07-23 22:40 - 2012-10-04 19:49 - 00087152 _____ () C:\Windows\System32\cpwmon64.dll
2011-06-22 09:48 - 2011-06-22 09:48 - 00034304 _____ () C:\Windows\System32\ssp6ml6.dll
2014-09-16 13:52 - 2014-09-16 13:52 - 08896160 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-11-03 19:05 - 2014-10-14 22:35 - 06281024 _____ () C:\Users\g\AppData\Local\Amazon Music\Amazon Music Helper.exe
2013-10-17 16:27 - 2013-10-17 16:27 - 00166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
2012-09-14 18:34 - 2012-01-26 19:49 - 02751808 ____N () C:\Program Files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE
2011-06-22 09:47 - 2011-06-22 09:47 - 00826880 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\ssp6mdu.dll
2014-09-16 13:53 - 2014-09-16 13:53 - 08896160 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-05-14 02:51 - 2015-05-04 21:06 - 01252680 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.152\libglesv2.dll
2015-05-14 02:51 - 2015-05-04 21:06 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.152\libegl.dll
2012-09-14 18:28 - 2012-03-06 12:27 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-05-14 02:51 - 2015-05-04 21:06 - 14982472 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.152\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\Program Files\Common Files\System:6qB2V6wRzQ7nbRv51sLM1xz
AlternateDataStreams: C:\Program Files\Common Files\System:HIOCjsyAtFjNnwleU7chCQ
AlternateDataStreams: C:\ProgramData\Microsoft:PQiZWSefGLhqiycDJOM
AlternateDataStreams: C:\ProgramData\Microsoft:XH4bPOKnlGlJjJ7ZRmluxFr8AW
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
AlternateDataStreams: C:\ProgramData\TEMP:89FAC91C
AlternateDataStreams: C:\ProgramData\TEMP:A3E1F4EF
AlternateDataStreams: C:\ProgramData\TEMP:AD768A7E
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\…\samsungsetup.com -> hxxp://www.samsungsetup.com
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-4093186601-1063034090-4258288859-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\g\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
FirewallRules: [{3D181002-2EC9-462A-BAB0-3D6BEE558CD0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe
FirewallRules: [{6C335B9A-C6B1-43B9-9B7B-17FE07271F96}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe
FirewallRules: [{F161DCBD-91E3-42B4-8DEF-694441F31AB0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe
FirewallRules: [{97AF95F9-D990-4100-A60B-13D3903C4514}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe
FirewallRules: [{E461C588-72E2-4182-AAFB-9CAC1C7F6A16}] => (Allow) C:\Program Files (x86)\Capcom\RESIDENT EVIL 5\RE5DX9.EXE
FirewallRules: [{03E34845-BE97-4574-9C5D-1F8F6295657E}] => (Allow) C:\Program Files (x86)\Capcom\RESIDENT EVIL 5\RE5DX9.EXE
FirewallRules: [{67453EF3-E677-4775-8BA0-02D0CF5B8784}] => (Allow) C:\Program Files (x86)\Capcom\RESIDENT EVIL 5\RE5DX10.EXE
FirewallRules: [{76FDB158-27A5-4A9E-8883-9672EC4B8E14}] => (Allow) C:\Program Files (x86)\Capcom\RESIDENT EVIL 5\RE5DX10.EXE
FirewallRules: [{9DC1054E-410F-44DB-81C9-EE85204DECCD}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{196E50E8-3868-4540-BEC2-6A8BEC264C5A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [TCP Query User{37AD690B-7AAB-4F0D-9B63-13048E4ECBC5}C:\program files (x86)\black_box\batman arkham city\binaries\win32\batmanac.exe] => (Allow) C:\program files (x86)\black_box\batman arkham city\binaries\win32\batmanac.exe
FirewallRules: [UDP Query User{F51B7CE0-C57D-4773-AD56-F71D6D424C58}C:\program files (x86)\black_box\batman arkham city\binaries\win32\batmanac.exe] => (Allow) C:\program files (x86)\black_box\batman arkham city\binaries\win32\batmanac.exe
FirewallRules: [{FBC2B823-AD05-4941-8F3B-499C4BECC318}] => (Allow) C:\Windows\System32\migwiz\migwiz.exe
FirewallRules: [{268DEE39-AC9A-4FCD-8DD4-FFE63A258E5B}] => (Allow) C:\Windows\System32\migwiz\migwiz.exe
FirewallRules: [{9D77EEEA-537D-4E51-AE68-05D33B62637D}] => (Allow) LPort=7000
FirewallRules: [{95C73C8B-28EA-465B-9D30-6B125E357F11}] => (Allow) LPort=7000
FirewallRules: [{FCCB42B0-8E75-405E-8CE1-812EC9582C58}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{B3074082-B2FB-44E6-A819-9ABF03113CEE}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{60BF0299-C044-4733-9179-E87F445574B7}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{D964DDB6-FE33-4930-89AA-F30B9E6ADF96}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{5F92BE14-D992-4570-9B0C-99FDB185599B}] => (Allow) C:\Program Files (x86)\Common Files\Motive\pcServiceHost.exe
FirewallRules: [{AC86FC1E-FB1C-40E1-8167-775D62E9B26F}] => (Allow) C:\Program Files (x86)\Common Files\Motive\pcServiceHost.exe
FirewallRules: [{006E31C7-1ABA-4158-8794-7B7287900819}] => (Allow) C:\Program Files (x86)\Lightworks\ntcardvt.exe
FirewallRules: [{8E0DC5A3-BB1E-4130-A352-EA7529C1FAF5}] => (Allow) C:\Program Files (x86)\Lightworks\ntcardvt.exe
FirewallRules: [{74089630-2CD0-41D2-90B0-42EFC817A0C3}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{32B5BF7C-59B8-4870-8DD9-D4445A08D77A}] => (Allow) C:\Program Files (x86)\Common Files\Motive\pcServiceHost.exe
FirewallRules: [{E2FC7B6B-18DA-4992-99A3-7CEDC2846710}] => (Allow) C:\Program Files (x86)\Common Files\Motive\pcServiceHost.exe
FirewallRules: [{FA81E130-4952-4943-BA14-98703133954E}] => (Allow) LPort=49172
FirewallRules: [{7B711634-E37B-4330-904E-6A71949CAAB9}] => (Allow) LPort=5000
FirewallRules: [{AC0F3547-596D-4389-B427-64253FA8797F}] => (Allow) C:\Program Files\CyberLink\PowerDirector13\PDR10.EXE
FirewallRules: [{0CC84D72-3B89-4DD0-94B8-15D1CBE44FE4}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{7AD51CEF-9D58-43D2-A8F4-FF16B64BDDA4}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{015EB52E-D6AD-4D3C-9A7C-49512A5AE658}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{D2D45B9A-C044-4E97-B657-3A0D8C66BAB6}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{1FB98747-C5CA-4780-8FEC-52A785931061}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{06BFB136-E94E-42B1-B479-9E27382792A1}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{E3BE820F-A101-4DA1-8ECE-8D161D73996B}] => (Allow) C:\Users\g\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B090E622-E136-4CA8-86E0-C77E4D8B565E}] => (Allow) C:\Users\g\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{A8F463B0-56EE-408B-911A-5B5871128A26}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/16/2015 02:10:56 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "PDR.X,type="win32",version="1.0.0.0"1".
Dependent Assembly PDR.X,type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (05/16/2015 02:10:56 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "PDR.X,type="win32",version="1.0.0.0"1".
Dependent Assembly PDR.X,type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (05/16/2015 02:04:18 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (05/16/2015 01:03:10 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "PDR.X,type="win32",version="1.0.0.0"1".
Dependent Assembly PDR.X,type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (05/16/2015 01:03:10 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "PDR.X,type="win32",version="1.0.0.0"1".
Dependent Assembly PDR.X,type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (05/15/2015 02:17:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/15/2015 02:15:57 PM) (Source: ACT! Scheduler) (EventID: 0) (User: )
Description: Service cannot be started. System.Exception: Unable to start scheduler service. Missing server configuration information.
   at Act.Scheduler.SchedulerService.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (05/15/2015 01:51:05 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/15/2015 01:50:01 PM) (Source: ACT! Scheduler) (EventID: 0) (User: )
Description: Service cannot be started. System.Exception: Unable to start scheduler service. Missing server configuration information.
   at Act.Scheduler.SchedulerService.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (05/15/2015 11:07:02 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 2adc
 
Start Time: 01d08dffbf920446
 
Termination Time: 417
 
Application Path: C:\Windows\explorer.exe
 
Report Id: 2abe74df-fb2d-11e4-9e15-d4bed9fc8f7b
 
 
System errors:
=============
Error: (05/15/2015 11:14:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SSPORT service failed to start due to the following error: 
%%2
 
Error: (05/15/2015 11:14:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SSPORT service failed to start due to the following error: 
%%2
 
Error: (05/15/2015 11:14:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SSPORT service failed to start due to the following error: 
%%2
 
Error: (05/15/2015 02:19:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
%%1069
 
Error: (05/15/2015 02:19:00 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
%%1330
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (05/15/2015 02:16:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SSPORT service failed to start due to the following error: 
%%2
 
Error: (05/15/2015 02:15:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The DgiVecp service failed to start due to the following error: 
%%2
 
Error: (05/15/2015 01:55:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
%%1069
 
Error: (05/15/2015 01:55:12 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
%%1330
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (05/15/2015 01:50:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SSPORT service failed to start due to the following error: 
%%2
 
 
Microsoft Office Sessions:
=========================
Error: (05/16/2015 02:10:56 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: PDR.X,type="win32",version="1.0.0.0"c:\program files\cyberlink\photodirector5\Kernel\CES\CES_CacheAgent.exe.Manifest
 
Error: (05/16/2015 02:10:56 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: PDR.X,type="win32",version="1.0.0.0"c:\program files\cyberlink\photodirector5\Kernel\CES\CES_AudioCacheAgent.exe.Manifest
 
Error: (05/16/2015 02:04:18 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (05/16/2015 01:03:10 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: PDR.X,type="win32",version="1.0.0.0"c:\program files\cyberlink\photodirector5\Kernel\CES\CES_CacheAgent.exe.Manifest
 
Error: (05/16/2015 01:03:10 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: PDR.X,type="win32",version="1.0.0.0"c:\program files\cyberlink\photodirector5\Kernel\CES\CES_AudioCacheAgent.exe.Manifest
 
Error: (05/15/2015 02:17:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/15/2015 02:15:57 PM) (Source: ACT! Scheduler) (EventID: 0) (User: )
Description: Service cannot be started. System.Exception: Unable to start scheduler service. Missing server configuration information.
   at Act.Scheduler.SchedulerService.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (05/15/2015 01:51:05 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/15/2015 01:50:01 PM) (Source: ACT! Scheduler) (EventID: 0) (User: )
Description: Service cannot be started. System.Exception: Unable to start scheduler service. Missing server configuration information.
   at Act.Scheduler.SchedulerService.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (05/15/2015 11:07:02 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: explorer.exe6.1.7601.175672adc01d08dffbf920446417C:\Windows\explorer.exe2abe74df-fb2d-11e4-9e15-d4bed9fc8f7b
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-3450 CPU @ 3.10GHz
Percentage of memory in use: 60%
Total physical RAM: 8090.25 MB
Available physical RAM: 3159.05 MB
Total Pagefile: 16178.69 MB
Available Pagefile: 10255.55 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
 
==================== Drives ================================
 
Drive c: (C Drive on Alienware) (Fixed) (Total:921.83 GB) (Free:274.59 GB) NTFS
Drive f: (Seagate Backup Plus Drive) (Fixed) (Total:1863.02 GB) (Free:300.49 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 038156C0)
 
Partition: GPT Partition Type.
 
========================================================
Disk: 1 (Size: 1863 GB) (Disk ID: 1A8447C7)
Partition 1: (Active) - (Size=1863 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================

Good Morning,

 

Nothing earth shattering jumping out at me. You have Malwarebytes installed, lets make sure its the latest version, open it , it should be version 2.1.6.1022, if not download the latest version, here are the instructions

 

  • Download and run their removal utility HERE
  • It will ask to restart your computer (please allow it to).
  • Then download Malwarebytes' Anti-Malware Version 2.1.6 from HERE
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Threat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished and the log pops up…select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
  • Malwarebytes Anti-Malware
    www.malwarebytes.org
     
    Scan Date: 5/17/2015
    Scan Time: 9:57:17 AM
    Logfile: 
    Administrator: Yes
     
    Version: 2.01.6.1022
    Malware Database: v2015.05.17.03
    Rootkit Database: v2015.05.16.01
    License: Trial
    Malware Protection: Enabled
    Malicious Website Protection: Enabled
    Self-protection: Disabled
     
    OS: Windows 7 Service Pack 1
    CPU: x64
    File System: NTFS
    User: g
     
    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 422882
    Time Elapsed: 10 min, 56 sec
     
    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled
     
    Processes: 0
    (No malicious items detected)
     
    Modules: 0
    (No malicious items detected)
     
    Registry Keys: 0
    (No malicious items detected)
     
    Registry Values: 0
    (No malicious items detected)
     
    Registry Data: 0
    (No malicious items detected)
     
    Folders: 0
    (No malicious items detected)
     
    Files: 0
    (No malicious items detected)
     
    Physical Sectors: 0
    (No malicious items detected)
     
     
    (end)

    Looking good so far, what are you experiencing to make you think your infected ?  Are your browsers being redirected to sites you dont want, are you getting unwanted pop up windows ?

    To be sure nothing is amiss, if you have time run this free online virus scanner.  By the way the geek site the download took you to was geekstogo, our sister site 

     

    ESET Online Scanner
    I'd like us to scan your machine with ESET OnlineScan
     
    *Note
    It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
    Please don't go surfing while your resident protection is disabled!
    Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
     
    1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    2. ESET OnlineScan
    3. Click the [external image: esetOnline.png] button.
    4. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      1. Click on [external image: esetSmartInstall.png] to download the ESET Smart Installer. Save it to your desktop.
      2. Double click on the [external image: esetSmartInstallDesktopIcon.png] icon on your desktop.
      3. Check [external image: esetAcceptTerms.png]
      4. Click the [external image: esetStart.png] button.
      5. Accept any security warnings from your browser.
      6. Check [external image: esetScanArchives.png]
      7. Make sure that the option "Remove found threats" is Unchecked
      8. Push the Start button.
      9. ESET will then download updates for itself, install itself, and begin
      10. scanning your computer. Please be patient as this can take some time.
      11. When the scan completes, push [external image: esetListThreats.png]
      12. Push [external image: esetExport.png], and save the file to your desktop using a unique name, such as
      13. ESETScan. Include the contents of this report in your next reply.
      14. Push the [external image: esetBack.png] button.
      15. Push [external image: esetFinish.png]
      16. Please make sure you include the following items in your next post:
        The log that was produced after running ESET Online Scanner.
        C:\Photos\peru\downloads\cbsidlm-cbsi176-Direct_WAV_MP3_Splitter-ORG-10354816.exe a variant of Win32/CNETInstaller.B potentially unwanted application
        C:\Users\g\Desktop\Removable Disk\super one click\Exploits\psneuter Android/Exploit.Lotoor.AK trojan
        C:\Users\g\Desktop\Removable Disk\super one click\Exploits\zergRush Android/Exploit.Lotoor.AV trojan
        C:\Users\g\Downloads\lightworks-setup.exe Win32/DownloadAdmin.G potentially unwanted application
        C:\Users\g\Downloads\Win8StartButtonSetup.exe a variant of Win32/Toolbar.SearchSuite.W potentially unwanted application
        C:\Users\g\Downloads\Removable Disk\super one click\Exploits\psneuter Android/Exploit.Lotoor.AK trojan
        C:\Users\g\Downloads\Removable Disk\super one click\Exploits\zergRush Android/Exploit.Lotoor.AV trojan

        I would remove these

         

        C:\Photos\peru\downloads <– Go into the downloads folder and delete it all but not the downloads folder itself

         

        C:\Users\g\Downloads <– Go into the downloads folder and delete it all but not the downloads folder itself

         

        C:\Users\g\Desktop\Removable Disk\super one click <–This 

        Ask AI

        AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

        Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI